The New York Times journalists gained access to a program used by the DarkSide hacker group, which, according to the FBI, is behind the hacking of the systems of the American pipeline company Colonial Pipeline. Employees of the publication found that the program can be switched to Russian.
The journalists also published a screenshot showing the "Rules of Operation" on the DarkSide website, available in Russian. According to the rules, DarkSide resources are prohibited from being used against medical and educational institutions, funeral services, public sector organizations and charitable organizations. In addition, the list of rules notes that it is forbidden to work in the CIS countries.
The NYT emphasizes that the DarkSide control system worked until May 20, although the group announced a closure a week earlier.
As The Wall Street Journal wrote, citing FireEye, a computer security company, hackers allegedly lost access to IT infrastructure due to pressure from law enforcement agencies and the United States.
Earlier, the FBI said that the DarkSide group was behind the attack on the American pipeline company Colonial Pipeline. US President Joe Biden claimed that the organizers of the cyber attack could be in Russia. However, according to the press secretary of the President of the Russian Federation Dmitry Peskov, Russia has nothing to do with the hacking. The Russian diplomatic mission in Washington also denies Moscow's involvement.
A hacker attack on the IT infrastructure of Colonial Pipeline was carried out on May 7th. Because of the incident, the company was forced to stop the operation of the fuel pipeline, and in 19 states declared a state of emergency. Bloomberg wrote that Colonial Pipeline paid hackers about $5 million to restore access to the hacked IT infrastructure and resume the supply of gasoline and diesel.
Colonial Pipeline provides fuel for about 45% of the East Coast of the United States. It transports 2.5 million barrels of gasoline, diesel fuel, jet fuel and fuel oil per day.