Close Menu
Edu Expertise Hub
    Facebook X (Twitter) Instagram
    Friday, May 9
    • About us
    • Contact
    • Submit Coupon
    Facebook X (Twitter) Instagram YouTube
    Edu Expertise Hub
    • Home
    • Udemy Coupons
    • Best Online Courses and Software Tools
      • Business & Investment
      • Computers & Internet
      • eBusiness and eMarketing
    • Reviews
    • Jobs
    • Latest News
    • Blog
    • Videos
    Edu Expertise Hub
    Home » Latest News » Ransomware: from REvil to Black Basta, what do we know about Tramp?
    Latest News

    Ransomware: from REvil to Black Basta, what do we know about Tramp?

    TeamBy TeamMarch 2, 2025No Comments11 Mins Read5 Views
    Facebook Twitter Pinterest LinkedIn Telegram Tumblr Email
    Ransomware: from REvil to Black Basta, what do we know about Tramp?
    Share
    Facebook Twitter LinkedIn Pinterest Email


    September 2020: An affiliate of the ransomware company REvil reveals the details of a cyber attack he carried out a few months earlier against the French company Elior. At the time, ransomware was already a significant threat, but nowhere near the scale it was about to take on. It was at this time, however, that journalists at Computer Weekly’s French sister site, LeMagIT, began to monitor developments on a monthly basis.

    Some of the major players in this threat who are active today were already active at that time. The following account sheds new light on how they are likely to profit from their gains, as well as the level of protection they can claim – rightly or wrongly – to escape justice.

    Yerevan, June 2024

    On Friday 21 June 2024, on American Street in Yerevan, the adventure is about to take an unexpected turn for the man who appears to be one of them.

    Oleg Nefedov was arrested by the local police at 11am on the street in the Armenian capital that leads to the US embassy and runs alongside the river Hrazdan.

    At 1.30pm the next day, the public prosecutor requested that he be remanded in custody. In the meantime, Armenia had obtained and had translated the documents required for his extradition. He was the subject of an Interpol Red Notice – which was not made public.

    The hearing is scheduled for Monday 24 June at 10am. Sufficient, in theory. The Armenian media site 168.am, which reported the events, explains that the decision to remand him in custody must be made within 72 hours of the arrest – before 11am on 24 June. But the deadline was missed, for reasons that were not specified. At 4pm, Oleg Nefedov was released. The Prosecutor General’s Office confirmed the facts in a press release dated 20 September.

    The news passed almost unnoticed. On 16 December 2024, a source contacted LeMagIT. He was positive that the man who used the pseudonym Tramp – a former member of the late Conti and one of the leaders of the Black Basta ransomware gang – was the same Oleg Nefedov who had been arrested in Yerevan at the end of the previous June: “I also know Tramp under the name Oleg Y. Nefedov”, he says, adding that he used to work with him.

    “He has the best protection in Russia. He has friends in the security services. He even pays the FSB and the GRU”, this source explains. These are the Russian intelligence services. “Nobody has that kind of money or that level of security anymore,” the source added.

    This is indeed what Tramp, also known by the pseudonyms AA and GG, told one of his partners, dd, on 14 November 2022: “I have guys from Lubyanka [FSB headquarters in Moscow] and the GRU, I’ve been feeding them for a long time,” according to a log of private exchanges that probably took place on the encrypted messaging service Tox. These exchanges were provided to LeMagIT on 30 December 2024, as well as to colleagues at German magazine Der Spiegel (see image, below).

    LeMagIT

    Tramp boasts contacts with the FSB and GRU.

    But is Tramp really Oleg? Other sources have said so, on condition of anonymity. There is plenty of evidence to support these assertions.

    Tramp questioned

    An analysis of the activity associated with the pseudonym GG in exchanges on the Matrix instance of Black Basta is troubling – it shows a total absence of activity from 21 June 2024 to 2 July inclusive.

    When Tramp came back online on 3 July, he said he had a new computer and had changed his Telegram account. He explained that he had lost his previous computer, “and not just that. It’s a long story”, he says: “it’s been difficult in real life. I don’t know where to start…”

    But, as researcher and human intelligence specialist Liontamer pointed out, Tramp confided in gang member Chuck, whom he had known for “so many years”, a few hours later: “The cops caught me”. He mentions a reward for “information on TR [potentially Trickbot, but the pseudonym Tramp has also been openly designated by the American justice system]. 10 million”. He goes on to say that he had seen his file, “but they didn’t show me everything”. He had to be extradited.

    tramp escape mobile Ransomware: from REvil to Black Basta, what do we know about Tramp? Edu Expertise Hub

    LeMagIT

    Tramp says he called on high-level support to avoid extradition to the United States.

    The same day, Chuck says he wants a holiday: “Don’t go anywhere. Stay at home”, Tramp advises him. Chuck says he has booked tickets to Kaliningrad. Tramp insists: “We have to protect everyone now”. Chuck finally gives up his plans: “I’m cancelling; I’m going to Karelia”. Tramp explains that he has seen all the pseudonyms of the members of Black Basta in the file presented to him.

    He says he benefited from very high-level protection, “at the level of our number 1”: “I managed to call. I just asked for a pass. They immediately took off for me”.

    Highly placed relations

    Any further details? “I can’t say anything about how I got out and who helped. But I’ve been told that the number 1 knows me and that, without his agreement, they wouldn’t have done anything,” assures Tramp. Chuck then asked: “Putin, right?” Tramp would say no more.

    Lubyanka Building half column mobile Ransomware: from REvil to Black Basta, what do we know about Tramp? Edu Expertise Hub

    A.Savin – travail personnel, CC BY-SA 3.0

    The Lubyanka building, headquarters of the FSB in Moscow.

    On 7 July, however, he became more talkative, indicating that his phone had been seized. He said that an unspecified “they” had “total access to Apple. They are connected to the whole planet. They know everything”. As a result, “Apple is dead. […] We have to clean everything up over there”.

    But Chuck is worried: someone has told him that he is wanted by the US law enforcement agencies. Someone he pays every month to protect him in case the FSB come looking for him. He fears that the Russian services will “start to extort [them] or force [them] to work for them, in exchange for protection”. He may have a point.

    On 16 September 2024, YY called Tramp. In doing so, he revealed an alias under which he was known for his activities with the late Conti: “Hi Tramp, it’s bio. I’ve been released, sorry I couldn’t warn you. The masked raiders nearly broke every bone in my body when they came in, but luckily I had time to disconnect from the server.

    tramp bio arrest mobile Ransomware: from REvil to Black Basta, what do we know about Tramp? Edu Expertise Hub

    LeMagIT

    Bio, an ex-Conti member, talks to Tramp about his run-ins with the police.

    According to him, it was a cryptocurrency exchange that betrayed him: “They couldn’t find anything other than my last three transactions (around 3 btc). In short, they kept me in pre-trial detention and then released me. For the time being, I feel I’m being watched, so I’m keeping a low profile. It’s a shame they confiscated the car and seized the house […], but I hope to get them back soon.

    Bio will then request several payments of a few hundred dollars from Tramp. On 10 November 2024, he will consolidate 20 bitcoins at Kraken.

    A lavish lifestyle

    Oleg will shortly be celebrating his 35th birthday. He comes from Iochkar-Ola, a town of over 260,000 inhabitants 850km east of Moscow and 60km from the Volga, capital of the Mari Republic.

    Yoshkar Ola half column mobile Ransomware: from REvil to Black Basta, what do we know about Tramp? Edu Expertise Hub

    Alexxx1979 – travail personnel, CC BY-SA 4.0

    Ioshcar-Ola, capital of the Mari Republic.

    He appears to have long had a keen interest in cryptocurrencies. An account on btc-e.com has been associated with him. This foreign exchange service suffered a data breach in 2014.

    In 2017, he worked at Bitsoft, which then presented itself as “the largest Russian company in the field of cloud-mining of Ethereum, Litecoin, and Zcash”. He registered several domain names, including one in July 2017. LeMagIT tracked them down using historical Whois data and a phone number. The address? Iochkar-Ola.

    From this data, LeMagIT also found a telephone number that was, for a time, directly linked to the name “Mr Tramp” in TrueCaller, but also listed elsewhere as Oleg Nefedov, as well as the address associated with his Apple iCloud account.

    Oleg declares income from Bitsoft until 2021. Over the period, this income is hardly impressive: 60,000 roubles in 2017 and 2018, or around €900 a year. It’s a little better in 2019, with more than 261,000 roubles, or around €3,600 at the average exchange rate for that year. After that, he will receive income from Polis, a company that will be wound up at the end of 2023. Bitsoft will suffer the same fate in August 2024.

    Mercedes Benz G63 AMG half column mobile Ransomware: from REvil to Black Basta, what do we know about Tramp? Edu Expertise Hub

    DAIMLER AG

    Mercedes-Benz G 63 AMG, an SUV for over €80,000.

    That didn’t stop him from driving a BMW X6 M50D in 2019. In 2021, he was caught speeding in a Mercedes AMG S63 4MATIC – more than 60km/h over the limit. He also drove a Porsche Macan.

    In early 2024, he had the papers replaced on his Mercedes V-class van. At that time, he also had a Mercedes GLE 400 D 4MATIC. A few months earlier, he had the address changed for his G-Class AMG G63 SUV.

    Since at least 2022, Oleg has been investing in top-of-the-range lounges under a brand in which it owns a share of the intellectual property. The brand is present all over the world, from Dubai and Abu Dhabi to Baku, Moscow and Bali. At the end of August 2024, he founded a charity called Rodina – Motherland in Russian.

    Tramp, golden boy of ransomware

    According to LeMagIT analysis, Tramp has at least 20 bitcoins to his name and controlled at least 2,000 in January 2023 – half a surprise. In autumn 2021, LeMagIT had tracked the millions of dollars in ransomware payments obtained by Conti over the preceding months. In November 2023, Elliptic and Corvus Insurance estimated that Black Basta had done no worse, collecting more than $100m in ransom payments in almost two years of activity.

    In France, Black Basta attacked Oralia in April 2022, followed by H-Tube, Villa Florek, Envea, Dupont Restauration and Baccarat. In all, more than 520 victims of Black Basta are publicly known, compared with more than 350 for Conti.

    In the exchanges provided at the end of December last year, Tramp was asked twice to make payments in bitcoins. At least one of the payments came from an address known to be controlled by Tramp.

    But Tramp, who is also known by the pseudonym “p1ja”, didn’t arrive in the world of ransomware with the appearance of Conti, the cyber-extortion business that fell apart in 2022, shortly after Russia invaded Ukraine.

    According to LeMagIT’s information, he has been involved in such activities for much longer. In extracts from private discussions between Tramp and ssd, in November 2022, there is a reference to a Windows system name: WIN-7PV24JSN83C.

    Red Hot Cyber noted this machine name in August 2022. LeMagIT observed it for 28 victims claiming to be LockBit – 2.0 and 3.0 – throughout that same year. Presumably corresponding to a hosted virtual machine, this name was not very widespread at the time – in August 2022, the specialist search engine Shodan counted around 200 occurrences, including more than 190 on IP addresses geolocated in Russia.

    A conflict with REvil

    And that’s not all. Whether in the exchanges disclosed in February 2025 or in those sent at the end of December 2024, Tramp appears to regularly use the password 123123 to protect files that are relatively insensitive or only temporarily available. And it’s pretty much the only one.

    LeMagIT observed this behaviour in two negotiations under the REvil banner at the beginning of 2021, then two more under the Conti brand a few months later. Prior to this, the Crysis 3 source code leaked by Egregor in 2020 had been in an archive protected by the same password.

    tramp revil mobile Ransomware: from REvil to Black Basta, what do we know about Tramp? Edu Expertise Hub

    LeMagIT

    When Tramp worked with REvil.

    In May 2021, on one of the forums well known to be frequented by cyber criminals, p1ja requested arbitration for a dispute with another user: “I’m a pentester and I worked with the REvil affiliate programme”. His access to the negotiation interface with his victims had just been withdrawn.

    On this same forum, Tramp was also active under the pseudonym “washingt0n32”. He registered there in August 2020. At the time he claimed to have “more than 10 years” experience in penetration testing.

    LeMagIT and Der Spiegel jointly sought comment from Oleg Nefedov, without success. The Black Basta website and trading interface have been inaccessible for almost two weeks at the time of publication. According to corroborating sources, some members of the group have already moved on to Akira and Cactus, among others.

    This post is exclusively published on eduexpertisehub.com

    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Team

      Related Posts

      US tells CNI orgs to stop connecting OT kit to the web

      May 8, 2025

      Pre-K Spending and Enrollment Reach All-Time High, But Quality Concerns Remain

      May 8, 2025

      Ignite Reading Partners with UF Lastinger Center’s Florida Tutoring Advantage

      May 7, 2025

      UK hands Indian IT suppliers competitive boost in trade deal

      May 7, 2025

      Every Student Deserves High-Quality Computer Science Education

      May 7, 2025

      With VR goggles, students in detention centers gain career training

      May 6, 2025
      Courses and Software Tools

      Extreme Privacy: What It Takes to Disappear

      August 24, 202436 Views

      Modern C++ Programming Cookbook: Master Modern C++ with comprehensive solutions for C++23 and all previous standards

      September 18, 202423 Views

      Meebook E-Reader M7 | 6.8′ Eink Carta Screen | 300PPI Smart Light | Android 11 | Ouad Core Processor | Out Speaker | Support Google Play Store | 3GB+32GB Storage | Micro-SD Slot | Gray

      August 19, 202421 Views

      Coders at Work: Reflections on the Craft of Programming

      April 19, 202516 Views

      Bigme inkNote Color + Lite Eink Tablet 10.3″ eBook Reader 4G 64GB eReader for Reading and Writing ePaper Tablet Digital Notepad with Stylus and Cover

      June 13, 202413 Views
      Reviews

      Model Context Protocol(MCP) Implementation in C# | Udemy Coupons 2025

      May 9, 2025

      Locum Physician (MD/DO) – Anesthesiology in Bemidji, MN

      May 9, 2025

      The Basics of Process Improvement

      May 9, 2025

      Improve Your Social Skills

      May 9, 2025

      Motorola Edge + |2022| 4800mAh Battery | Unlocked | Made for US 8/512GB | 50MP Camera | Cosmos Blue

      May 9, 2025
      Stay In Touch
      • Facebook
      • YouTube
      • TikTok
      • WhatsApp
      • Twitter
      • Instagram
      Latest News

      US tells CNI orgs to stop connecting OT kit to the web

      May 8, 2025

      Pre-K Spending and Enrollment Reach All-Time High, But Quality Concerns Remain

      May 8, 2025

      Ignite Reading Partners with UF Lastinger Center’s Florida Tutoring Advantage

      May 7, 2025

      UK hands Indian IT suppliers competitive boost in trade deal

      May 7, 2025

      Every Student Deserves High-Quality Computer Science Education

      May 7, 2025
      Latest Videos

      Cybersecurity has high scope in government jobs! (Tamil) | cyber security career

      May 8, 2025

      Why Pursue A Career In Digital Marketing?

      May 7, 2025

      Want to be a Certified Ethical Hacker? #ethicalhackingtraining#cybersecuritycourses #ethicalhacking

      May 6, 2025

      4 Best Courses to do before pursuing a Career in Finance

      May 5, 2025

      Kaunsa Course Sahi? #shortvideo #digitalmarketing #career

      May 4, 2025
      Latest Jobs

      Locum Physician (MD/DO) – Anesthesiology in Bemidji, MN

      May 9, 2025

      Registered Behavioral Technician (RBT) – Audubon School

      May 9, 2025

      Administrative Coordinator II

      May 8, 2025

      AICS Valuations, AVP

      May 8, 2025

      Testing Technical Project Manager

      May 8, 2025
      Legal
      • Home
      • Privacy Policy
      • Cookie Policy
      • Terms and Conditions
      • Disclaimer
      • Affiliate Disclosure
      • Amazon Affiliate Disclaimer
      Latest Udemy Coupons

      Mastering Maxon Cinema 4D 2024: Complete Tutorial Series | Udemy Coupons 2025

      August 22, 202434 Views

      Advanced Program in Human Resources Management | Udemy Coupons 2025

      April 5, 202530 Views

      Diploma in Aviation, Airlines, Air Transportation & Airports | Udemy Coupons 2025

      March 21, 202528 Views

      Time Management and Timeboxing in Business, Projects, Agile | Udemy Coupons 2025

      April 2, 202521 Views

      Digital Platforms and Ecosystems Business and Partnership | Udemy Coupons 2025

      March 29, 202520 Views
      Blog

      4 Phrases To Never Include On Your Resume

      May 8, 2025

      How To Start A Conversation With A LinkedIn Connection

      May 7, 2025

      8 Mistakes Companies Make During Layoffs

      May 4, 2025

      How To End Your Week On A Positive Note

      May 3, 2025

      How To Optimize Your LinkedIn Profile For Job Search Success

      May 2, 2025
      Facebook X (Twitter) Instagram Pinterest YouTube Dribbble
      © 2025 All rights reserved!

      Type above and press Enter to search. Press Esc to cancel.

      We use cookies on our website to give you the most relevant experience by remembering your preferences and repeat visits. By clicking “Accept”, you consent to the use of ALL the cookies.
      .
      SettingsAccept
      Privacy & Cookies Policy

      Privacy Overview

      This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
      Necessary
      Always Enabled
      Necessary cookies are absolutely essential for the website to function properly. This category only includes cookies that ensures basic functionalities and security features of the website. These cookies do not store any personal information.
      Non-necessary
      Any cookies that may not be particularly necessary for the website to function and is used specifically to collect user personal data via analytics, ads, other embedded contents are termed as non-necessary cookies. It is mandatory to procure user consent prior to running these cookies on your website.
      SAVE & ACCEPT