Ransomware gang apologizes after affiliate infects CIS target
TL;DR. The RAlord ransomware group issued an apology and banned an affiliate for infecting Eriell Group, an oilfield services company in Uzbekistan and Moscow. - The affiliate violated a standing rule in the ransomware community against attacking targets within CIS countries. - RAlord promised to help Eriell with recovery free of charge and not to leak stolen data. - This incident highlights unofficial geopolitical rules governing some cybercriminal operations.
- Ransomware affiliate infected a company in CIS territory, violating an unwritten cybercrime rule.
- RAlord group apologized to the victim, Eriell Group, and offered free recovery assistance.
- The responsible affiliate was banned by RAlord for the transgression.
- The incident underscores the geopolitical lines observed by some ransomware gangs to avoid state retaliation.
Sources
- 'Dumbass' criminal breaks the 'first rule of ransomware club' — theregister.com