Staying Legit
IS CHINA OR NORTH KOREA BEHIND ONLINE GAMBLING RANSOMWARE ATTACKS?
Are Chinese or North Korean state-sponsored hackers targeting online gambling firms?
According to reports from several cybersecurity companies, including Profero and Security Joes, in 2020 at least five unidentified online gambling operators were hit by ransomware attacks, most likely by a group known as Advanced Persistent Threat 27 (APT27) or Emissary Panda.
In the attacks, hackers demanded a total of $100M USD worth of Bitcoin (BTC) to unlock their servers. However, thanks to diligent security measures and backups, no ransom was paid, and the companies involved managed to mitigate the damage and restore data from backups.
Although the Chinese government is well known for using hackers to target enemies, its efforts are usually focused on corporate or defence espionage, rather than pure financial gain, and analysts are well versed on the tactics and methods employed by the main Chinese groups.
Prime suspect: North Korea
Because of this, many suspect the culprit to be North Korea. For years, the North Korean government has courted hackers from around the world, using them to target financial institutions, and increasingly, cryptoexchanges, to help fund the country’s secret weapons programs.
The country has gone as far as establishing its own network of shady gambling sites, using them to funnel money into state coffers, and has even held what it portrays as legitimate international blockchain and crypto ‘trade expos’ in its dystopian capital city, Pyongyang, in an effort to attract tech geeks.

Of course, given the way China has been trying to shut down the regional gambling industry, there is always the possibility that the operations targeting gambling operators are part of an effort to disrupt the industry – and prevent sites from accepting bets from Chinese residents (gambling is illegal in mainland China).
Online gambling operators fare better than others
On the plus side, the fact that the gambling companies hit by the 2020 ransomware attacks managed to recover without paying up reflects very well on the industry’s preparedness compared to other sectors.
For example, in September 2020, one of Chile’s biggest banks, Banco Estado, was forced to shut down operations nationwide after suffering a major ransomware attack from the REvil gang. While, in July, Evil Corp hackers attacked multinational tech company Garmin, with reports suggesting it was forced to pay $10M to regain its data. In the same month, US travel firm CWT confirmed it had negotiated a Bitcoin ransom down from $10M to $4M to regain control of its systems.
And, in late August, what had the potential to be the most dramatic attack of all, against Tesla, was only foiled because of a loyal employee who turned down a $1M bribe to help facilitate a major crypto ransomware hack.
Whoever was behind the attacks of 2020, and whatever their reasons, as we start 2021 it’s a reminder for online gambling operators to maintain vigilance and ensure their security systems are well-tested and up-to-date.

All original content featured on this site is © Pentagon Digital Limited, 2019-2021.