Live data from Hacker News

DarkSide ransomware gang quits after servers, Bitcoin stash seized

krebsonsecurity.com

71–80 of 623 posts

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#71
post #55
post #43

> The REvil representative said its program was introducing new restrictions on the kinds of organizations that affiliates could hold for ransom, and that henceforth it would be forbidden to attack those in the “social sector” (defined as healthcare and educational institutions) and organizations in the “gov-sector” (state) of any country. Affiliates also will be required to get approval before infecting victims. Sta…

When I heard that this pipeline company started advertising a job opening for CyberSecurity Advisor in the last few days, and heard today the ransom of about $5 million was paid, my first reaction was to say "I bet the salary for that position is a lot less than $5 million, and I bet the budget for that department will be less, too..."

Well, if it's more expensive to prevent the attack than to pay the ransom, what's the point? ;)

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#72
post #15

Can crypto actually be non-traceable? I remember currencies like Monero or ZCash advertising privacy from the last crypto craze. I mean if you have 100M in some account, can you actually run it trough "private" currencies to remove traces? BTC, ETH etc. all seems super traceable, even more so than in regular banking. Also how are criminals getting their money out with no one noticing, does Panama/Malta etc. have Krak…

These groups will often use bitcoin tumblers/mixers to anonymize their btc. This is a solid explanation https://www.deepwebsiteslinks.com/wp-content/uploads/2017/10...

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#73

So taking down hospitals and healthcare facilities was fair game. But messing with Big Oil was just a step too far.

Oil shortages and long lines make for good/bad TV. Fear of bad media coverage energized the Govt. to act.

I'd guess that it's entirely the other way around - govt wanted to act, so they drummed up the bad media coverage to justify removing any restrictions they had to (re)act quickly, instead of through the usual law enforcement process which takes months or years.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#75
post #50

DarkSide's English is incredibly good for some supposed Russians. It even has the correct use of the apostrophe in "clients'". I know nothing, but my hunch is that this was written by a well-educated person who grew up in the US or Canada.

I can’t decide if it’s worse to imply that Russians can’t learn English or to think that the anglosphere only exists in North America.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#76

So taking down hospitals and healthcare facilities was fair game. But messing with Big Oil was just a step too far.

That shouldn't be a much of a surprise; the US has always aligned itself with protecting it's oil supply.

Why are you being down voted? Every major war and international crisis in my lifetime has been directly or indirectly related to US prioritizing oil above pretty much all else. From the Iranian revolution to the Gulf wars, to the terrorism our involvement in the middle east has caused, to the climate crisis and our lack of efforts to reduce consumption.

Whoever called this an insult isn't paying attention.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#77
post #55
post #43

> The REvil representative said its program was introducing new restrictions on the kinds of organizations that affiliates could hold for ransom, and that henceforth it would be forbidden to attack those in the “social sector” (defined as healthcare and educational institutions) and organizations in the “gov-sector” (state) of any country. Affiliates also will be required to get approval before infecting victims. Sta…

When I heard that this pipeline company started advertising a job opening for CyberSecurity Advisor in the last few days, and heard today the ransom of about $5 million was paid, my first reaction was to say "I bet the salary for that position is a lot less than $5 million, and I bet the budget for that department will be less, too..."

I think you're spot-on here - the ransom is seen as a "cost of doing business", and until recently security was seen as "a problem that happens to other people".

Sadly my experience is that organisations like this will take their $5m ransom (or other remediation cost), assume it's a one-off, then divide it by their number of ransom-free years, and proclaim it was better value for money than hiring 2 or 3 senior security gurus on $300k /yr with 60 vacation days, and letting them bring in a team to deliver meaningful security.

Beyond taking security out of the hands of bean-counters though, I'm not sure how you address this. Pursuing organisations that pay ransoms and prosecuting senior CEO/CFO-type executives for conspiracy to commit money laundering (and pushing for criminal convictions) could discourage paying ransoms. If it's left to businesses as something they can write down as a "cost", I don't see it getting better - there has to be a risk to the liberty of the CEO/CFO before they'll take security seriously in my experience. 90 days in federal prison would certainly sharpen their focus in future.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#78
post #15

Can crypto actually be non-traceable? I remember currencies like Monero or ZCash advertising privacy from the last crypto craze. I mean if you have 100M in some account, can you actually run it trough "private" currencies to remove traces? BTC, ETH etc. all seems super traceable, even more so than in regular banking. Also how are criminals getting their money out with no one noticing, does Panama/Malta etc. have Krak…

As far as I understand it, Monero (XMR) is private and untraceable.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#79

Earlier quoted context omitted.

Nope. Monero is actually private and untraceable.

Until someone cracks it, that is. If it becomes the crypto of choice for some of the bigger fish, you can bet the government will find a way to trace it.

There is at least $625,000[1] on the table already. Not to mention how many blockchain analytics companies and other actors would pay millions to have such a capability.

[1] https://www.forbes.com/sites/kellyphillipserb/2020/09/14/irs...

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#80
I think this roughly answers a question that I've been wondering about: Why don't cyber criminals hack into the energy grid, water, or other utilities? Surely their cyber security is outdated right?

Well, their cyber security may not be the most advanced, but traditional security (i.e. military strength) likely dissuades criminals from choosing those targets that are likely to put them on the short list.

Post reply on HN