Garmin Could Face Sanctions if $10M Ransom is Paid

Published at: July 27, 2020

Garmin, a multinational tech company, has been operating at less than full capacity following a ransomware attack launched by the Russian cybergang, Evil Corp. Garmin is being extorted for a $10 million ransom, to be paid in cryptocurrency.

According to a report published by Bleeping Computer, an unidentified Garmin employee confirmed that the WastedLocker ransomware took down the company’s customer support services, navigation solutions, and other aspects of the U.S.-based firm.

The leader of the cybercriminal group is a Russian individual named Maksim Yakubets. A known criminal, Yakubets was indicted by the U.S. Department of Justice in 2019. He was also listed in the FBI “Most Wanted” list with a reward set at $5 million – the highest reward amount offered by the authorities for the arrest of a cybercriminal.

Evil Corp members sanctioned in 2019 by the U.S.

Due to the sanctions against the criminals behind the attack, if Garmin proceeds to pay for the ransom, they could be in trouble with the U.S. government.

Speaking with Cointelegraph, Brett Callow, threat analyst at malware lab, Emsisoft, commented on the Garmin’s dilemma:

“This would seem to create a legal minefield. Payment may be the only way for a company to avoid a catastrophic loss of data, but it may be illegal for the company to make that payment.”

The listing says that Yakubets, known with the alias “Aqua,” is wanted for his involvement with computer malware that infected tens of thousands of computers in both North America and Europe. These resulted in actual financial losses worth around $100 million.

Cybercriminal gang reportedly provided assistance to the Russian government

The U.S. government also accused Yakubets, and his partner, Igor Tursashev, of providing “direct assistance to the Russian government” by helping the FSB security agency.

As of press time, the head of Evil Corp and the co-admin are still at large, though authorities believe them to be in Moscow.

A study published by the cybersecurity firm Fox-IT recently stated that Evil Corp has developed the WastedLocker ransomware. They have been actively using this ransomware to launch attacks since May 2020.

There are reports that the group has asked for a combined total of $10 million from a number of U.S.-based companies.

Tags
Related Posts
Researchers Say Ransomware Attacks on the Rise as More People Work From Home
A study published by cybersecurity firm, Proofpoint, shows an increase in email-based phishing attacks used to deliver ransomware over the last few months. According to the report, first-stage deployments of ransomware are reportedly on the rise and have mostly been targeting the United States, France, Germany, Greece, and Italy. The attacks appear to be capitalizing on the influx of people now working from home amid the COVID-19 pandemic. Research additionally indicates that the ransom demands are very low compared to the amounts usually seen in these attacks. Lower than average ransoms A ransomware application called “Mr. Robot” has mostly targeted …
Technology / June 29, 2020
Ransomware Gang Failed to Deploy an Attack Against 30 US Firms
Cybersecurity firm Symantec blocked a ransomware attack by a group known for demanding payment in Bitcoin (BTC) directed at 30 U.S.-based firms and Fortune 500 companies. The announcement published by the cybersecurity firm claims that the Evil Group, the malware gang behind the attacks, targeted the IT infrastructures of the firms. Still, the companies were alerted in time to prevent deployment of the ransomware. The group used the ransomware WastedLocker and managed to breach the security of the victims' networks and unsuccessfully attempted to laying the ground for staging the attacks. Gang asks for million-dollar payments Cointelegraph reported recently a …
Technology / June 28, 2020
Celebrities May Have Their Dirty Secrets Exposed if Crypto Ransom Is Unpaid
The REvil ransomware gang says that they will auction over 1TB of data stolen from New York-based entertainment law firm, Grubman Shire Meiselas & Sacks. This data allegedly contains the “dirty” secrets of a number of celebrities. REvil claims that the contents involve sex scandals, drugs, and treachery. Nicki Minaj, LeBron James, and Mariah Carey among the alleged victims In a blog post, the ransomware group says they will begin the auction on July 1, noting that the first round will contain information from Nicki Minaj, Mariah Carey, and LeBron James. The price for each dataset is $600,000. Two days …
Technology / June 24, 2020
Ransomware Gang Seeks Million Dollar PayDay
A malware group called Evil Corp is reportedly back in action, having recently launched a new ransomware which asks its victims to pay a million dollar ransom. The group had previously gone quiet after the U.S. Department of Justice charged some of its members in December 2019. According to a report published on June 23 by the cybersecurity firm Fox-IT, a division of NCC Group, Evil Corp has been active since 2007 — the group is considered to be one of the biggest cybercrime teams on the internet. They are known for using the Dridex malware and BitPaymet ransomware. U.S. …
Technology / June 23, 2020
Hackers Use Fraudulent Unemployment Claims to Siphon Funds
A study by risk solutions provider, Kroll, indicated that a group of hackers from Russia managed to file fraudulent unemployment claims with the Washington State Employment Security Department, or ESD, through a ransomware attack against a healthcare provider in the US. According to research published on June 17, the firm investigated browser history logs that the cybercriminals reportedly navigated to various Gmail accounts. They then activated two profiles on the ESD site using these email addresses. International organized cybercrime groups appearing in the scene The ransomware attack, launched on May 12, is a Mamba category exploit which uses full disk …
Technology / June 18, 2020