• Login
Whats Current In
No Result
View All Result
  • Blockchain
  • Cyber Security
  • Gadgets & Hardware
  • Startups
    • Angel investing
    • Venture Capital
  • More Tech News
    • AI
    • App Development
    • Cloud & SaaS
    • Gaming
    • Web Development
  • Blockchain
  • Cyber Security
  • Gadgets & Hardware
  • Startups
    • Angel investing
    • Venture Capital
  • More Tech News
    • AI
    • App Development
    • Cloud & SaaS
    • Gaming
    • Web Development
No Result
View All Result
Whats Current In
No Result
View All Result
Home Cyber Security

Ransomware hits Technion university, protests tech layoffs and Israel

Ax Sharma by Ax Sharma
February 13, 2023
Reading Time: 3 mins read
0
Ransomware hits Technion university, protests tech layoffs and Israel

Israel Palestine protest flags

RELATED POSTS

New Horabot campaign takes over victim’s Gmail, Outlook accounts

Windows 11 will let you view phone photos in File Explorer

Harvard Pilgrim Health Care ransomware attack hits 2.5 million people

A new ransomware group going by the name ‘DarkBit’ has hit Technion – Israel Institute of Technology, one of Israel’s leading research universities.

The ransom note posted by DarkBit is littered with messaging protesting tech layoffs and promoting anti-Israel rhetoric, as well as the group demanding a $1.7 million payment.

Technion Institute is battling cyber attack

Technion Institute of Technology, one of the Israel’s leading public research universities, has been hit by a cyber attack this week.

The Haifa-based academic institution is currently carrying out incident response activities to determine the scope and cause of the incident.

“The Technion is under a cyber attack. The scope and nature of the attack are under investigation,” the university said in a statement released in Hebrew.

“To carry out the process of collecting the information and handling it, we use the best experts in the field, both within The Technion and outside, and coordinate with the relevant authorities. The Technion has proactively blocked all communication networks at this stage.”

Buy JNews
ADVERTISEMENT

A ransom note from the new ‘DarkBit’ ransomware group was left on the university’s systems, where the attackers demanded 80 Bitcoin or roughly US$ 1,745,200 to release the decryptor to the university.

The date seen on the PC in the image above indicates the attack occurred on or before February 12th, 2023.

BleepingComputer also observed, at this stage, the Institute’s websites are inaccessible—likely after the university blocked all network access amid the attack.

Technion website down
Technion Israel’s website down as it investigates cyber attack (BleepingComputer)

While Technion’s cyber systems may be impacted, the university’s campus operations continue as normal.

“The work day tomorrow on campus will proceed as usual, with the exception of the postponed exams,” says the Institute. 

“The instructions published in the morning regarding participation in public activities due to a day off remain unchanged. We will continue to update when we have more information.”

Who is ‘DarkBit’ anyway?

A threat actor, disgruntled employee, pro-Palestinian activist, or all of these? 

The unheard of ‘DarkBit’ gang has sprung up this week and its whereabouts are yet to be known. The attackers, however, drop a few hints about their objectives in both the ransom note, and their Twitter and Telegram channels.

DarkBit onion website
DarkBit’s Tor (.onion) website (BleepingComputer)

DarkBit’s stance against “racism, fascism and apartheid” may cause their activities to be considered hacktivism at a first glance but the group’s motives seem multi-faceted.

From the use of #HackForGood hashtag in its Twitter bio to anti-Israel messages seen in the ransom note, as well as the group calling out tech layoffs, it’s hard to categorize DarkBit just yet.

DarkBit Twitter
DarkBit’s Twitter account with #HackForGood tag and tweets criticising layoffs ​​​​​​

While attacking Israel for being an “aparheid regime,” DarkBit attackers want to make them pay for “war crimes against humanity” and “firing high-skilled experts.”

“A kindly advice to the hight-tech companies: From now on, be more careful when you decide to fire your employees, specially the geek ones [sic],” DarkBit said in a subsequent tweet.

Depending on how one interprets the wording, the attack seems to be DarkBit’s way of taking revenge for layoffs that may have involved its members.

The threat actors seem to imply that laying off highly technical employees without doing due diligence could pose a threat to an organization’s security posture. Some laid off (and disgruntled) employees may have insider knowledge enabling them to acquire easier access to an organization’s computer networks even after termination.

“DarkBit has gone from hacktivist, to ransomware group now to a disgruntled former employee all in one day,” comments cybersecurity analyst Dominic Alvieri.

The group has threatened to impose a 30% penalty on top of an already-significant ransom demand should the university not agree to pay up. Additionally, the attackers warn they’d be putting up any stolen data for sale after five days.

BleepingComputer continues to monitor the situation and we will post updates as the development progresses.

Share54Tweet34Pin12
Ax Sharma

Ax Sharma

Related Posts

Beware: Hackers now use OneNote attachments to spread malware
Cyber Security

New Horabot campaign takes over victim’s Gmail, Outlook accounts

June 1, 2023
Windows 11 will let you view phone photos in File Explorer
Cyber Security

Windows 11 will let you view phone photos in File Explorer

June 1, 2023
Latitude cyberattack leads to data theft at two service providers
Cyber Security

Harvard Pilgrim Health Care ransomware attack hits 2.5 million people

June 1, 2023
Apple fixes recently disclosed zero-days on older iPhones and iPads
Cyber Security

Russia says US hacked thousands of iPhones in iOS zero-click attacks

June 1, 2023
Hackers turn to Google search ads to push info-stealing malware
Cyber Security

Google triples rewards for Chrome sandbox escape chain exploits

June 1, 2023
OSV and the Vulnerability Life Cycle
Cyber Security

Announcing the Chrome Browser Full Chain Exploit Bonus

June 1, 2023

Recommended Stories

Exploit released for critical Windows CryptoAPI spoofing bug

Microsoft fixes Windows zero-day exploited in ransomware attacks

March 14, 2023
Polygon NFTs: After DeGods, y00ts, and Trump, where will the network head next

Polygon NFTs: After DeGods, y00ts, and Trump, where will the network head next

May 8, 2023
Terra LUNA Classic [LUNC] Price Prediction 2025-2030: LUNC’s price fortunes depend on…

Terra LUNA Classic [LUNC] Price Prediction 2025-2030: LUNC’s price fortunes depend on…

March 12, 2023

Popular Stories

  • New Python malware backdoors VMware ESXi servers for remote access

    Massive ESXiArgs ransomware attack targets VMware ESXi servers worldwide

    137 shares
    Share 55 Tweet 34
  • Facts and myths about the warriors who raided Europe and explored the New World

    137 shares
    Share 55 Tweet 34
  • Exploit released for actively abused ProxyNotShell Exchange bug

    137 shares
    Share 55 Tweet 34
  • New Windows Server updates cause domain controller freezes, restarts

    136 shares
    Share 54 Tweet 34
  • Bing Chat’s secret modes turn it into a personal assistant or friend

    136 shares
    Share 54 Tweet 34
Whats Current In

We bring you the best Premium WordPress Themes that perfect for news, magazine, personal blog, etc. Visit our landing page to see all features & demos.

LEARN MORE »

Recent Posts

  • How Ethereum’s falling gas fees affect the network
  • Here’s what Solana can expect next
  • XRP traders, know this about the ‘golden pocket’

Categories

  • Apple Computer
  • Blockchain
  • Cyber Security
  • Tech News
  • Venture Capital

© 2023 JNews - Premium WordPress news & magazine theme by Jegtheme.

No Result
View All Result
  • Blockchain
  • Cyber Security
  • Gadgets & Hardware
  • Startups
    • Angel investing
    • Venture Capital
  • More Tech News
    • AI
    • App Development
    • Cloud & SaaS
    • Gaming
    • Web Development

© 2023 JNews - Premium WordPress news & magazine theme by Jegtheme.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?