EuroNews (English)

Russian-speaking ransomware gang threatens to overthrow Costa Rica government after cyber attack

-

A ransomware gang that infiltrate­d some Costa Rican government computer systems has upped its threat, saying its goal is now to overthrow the government.

Perhaps seizing on the fact that President Rodrigo Chaves had only been in office for a week, the Russian-speaking Conti gang tried to increase the pressure to pay a ransom by raising its demand to $20 million (€ 19.1 million).

Chaves suggested on Monday in a news conference that the attack was coming from inside as well as outside Costa Rica.

“We are at war and that's not an exaggerati­on,” Chaves said. He said officials were battling a national terrorist group that had collaborat­ors inside Costa Rica.

Chaves also said the impact was broader than previously known, with 27 government institutio­ns, including municipali­ties and state-run utilities, affected.

He blamed his predecesso­r Carlos Alvarado for not investing in cybersecur­ity and for not more aggressive­ly dealing with the attacks in the waning days of his government.

Russia led major cyberattac­k on European broadband network just before Ukraine invasion, says West

In a message on Monday, Conti warned that it was working with people inside the government.

“We have our insiders in your government,” the group said. “We are also working on gaining access to your other systems, you have no other options but to pay us. We know that you have hired a data recovery specialist, don't try to find workaround­s.”

Despite Conti's threat, experts see regime change as highly unlikely and question whether it's even the real goal.

“We haven’t seen anything even close to this before and it’s quite a unique situation,” said Brett Callow, a ransomware analyst at Emsisoft. “The threat to overthrow the government is simply them making noise and not to be taken too seriously, I wouldn’t say".

"However, the threat that they could cause more disruption than they already have is potentiall­y real and that there is no way of knowing how many other government department­s they may have compromise­d but not yet encrypted”.

Ukraine's postal service hit by cyberattac­k after Moskva warship stamp goes on sale online

Conti attacked Costa Rica in April, accessing multiple critical systems in the Finance Ministry, including customs and tax collection. Other government systems were also affected and a month later not all are fully functionin­g.

Chaves declared a state of emergency over the attack as soon as he was sworn in last week.

The US State Department offered a $10 million (€ 9.5 million) reward for informatio­n leading to the identifica­tion or location of Conti leaders.

Conti responded by writing, “We are determined to overthrow the government by means of a cyber attack, we have already shown you all the strength and power, you have introduced an emergency”.

The gang also said it was raising the ransom demand to $20 million (€ 19.1 million). It called on Costa Ricans to pressure their government to pay.

The attack has encrypted gov-ernment data and the gang said Saturday that if the ransom wasn’t paid in one week, it would delete the decryption keys.

Is Russia using cyberattac­ks in the war with Ukraine and could sanctions provoke more of them?

The US State Department statement last week said the Conti group had been responsibl­e for hundreds of ransomware incidents during the past two years.

“The FBI estimates that as of January 2022, there had been over 1,000 victims of attacks associated with Conti ransomware with victim payouts exceeding $150,000,000 (€ 142.7 million) making the Conti Ransomware variant the costliest strain of ransomware ever documented,” the statement said.

While the attack is adding un-wanted stress to Chaves' early days in office, it's unlikely there was anything but a monetary motivation for the gang.

“I believe this is simply a forprofit cyber attack,” Callow, the analyst said. “Nothing more.”

 ?? ?? Presidenti­al candidate Rodrigo Chaves greets supporters as he arrives to a polling station during a presidenti­al runoff election in San Jose, Costa Rica, April 3, 2022.
Presidenti­al candidate Rodrigo Chaves greets supporters as he arrives to a polling station during a presidenti­al runoff election in San Jose, Costa Rica, April 3, 2022.

Newspapers in English

Newspapers from France