Live data from Hacker News

DarkSide ransomware gang quits after servers, Bitcoin stash seized

krebsonsecurity.com

81–90 of 623 posts

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#81
post #69
post #45

It was a mistake to attack the business side of the oil company, because it created what could be sold as reasonable doubt to shut down the pipeline. As a result, the ransom had the optics of an attack on infrastructure. As evidenced by the coverage of Americans desperately filling up containers. This created the impetus for the US to treat this as an incident far and above the ambient ransomware activities leading u…

I think the question is, how come an attack on a hospital does not have the optics of an attack on infrastructure? (It almost seems oil does not require infrastructure - you can, theoretically, prep for an oil infrastructure outage by storing it containers, same as you do with water and food. But you can't really prep for a medical infrastructure outage. Is it just that, as a result, there were no photos of people ho…

Oil does require infrastructure. What you put in your car is several steps removed from what is pumped out of the ground.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#82
post #69
post #45

It was a mistake to attack the business side of the oil company, because it created what could be sold as reasonable doubt to shut down the pipeline. As a result, the ransom had the optics of an attack on infrastructure. As evidenced by the coverage of Americans desperately filling up containers. This created the impetus for the US to treat this as an incident far and above the ambient ransomware activities leading u…

I think the question is, how come an attack on a hospital does not have the optics of an attack on infrastructure? (It almost seems oil does not require infrastructure - you can, theoretically, prep for an oil infrastructure outage by storing it containers, same as you do with water and food. But you can't really prep for a medical infrastructure outage. Is it just that, as a result, there were no photos of people ho…

> I think the question is, how come an attack on a hospital does not have the optics of an attack on infrastructure?

An attack on a hospital affects someone if they work there or are using that hospital. A pipeline attack affects people who drive cars places and need gas. The latter group is much larger than the former.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#83
post #43

> The REvil representative said its program was introducing new restrictions on the kinds of organizations that affiliates could hold for ransom, and that henceforth it would be forbidden to attack those in the “social sector” (defined as healthcare and educational institutions) and organizations in the “gov-sector” (state) of any country. Affiliates also will be required to get approval before infecting victims. Sta…

That's not really reasonable - what about replacing hacking with murder? It's illegal for a reason - and not because it's too costly to do.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#84

Seems like they should invest more into cybersecurity, if someone was able to “steal” their Bitcoin and take over their infrastructure ;). But honestly, this only shows that IT systems are nowadays so complex that you cannot get them right and be able to truly protect you, no matter if you’re good or bad guy.

I doubt anyone stole their bitcoins though. I assume they just transferred it out themselves and will cash out later.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#85
post #15

Can crypto actually be non-traceable? I remember currencies like Monero or ZCash advertising privacy from the last crypto craze. I mean if you have 100M in some account, can you actually run it trough "private" currencies to remove traces? BTC, ETH etc. all seems super traceable, even more so than in regular banking. Also how are criminals getting their money out with no one noticing, does Panama/Malta etc. have Krak…

it can be harder to trace, but the bigger problem is trying to turn it into cash, which is hard to do anonymously regardless of the currency used (BTc, XMR, etc). THe FBI,Secret Service, are mostly focused on the conversion of crypto to cash, not the intermediary steps.

doesn't work if the fiat converted to is in another jurisdiction

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#86
post #55

Earlier quoted context omitted.

When I heard that this pipeline company started advertising a job opening for CyberSecurity Advisor in the last few days, and heard today the ransom of about $5 million was paid, my first reaction was to say "I bet the salary for that position is a lot less than $5 million, and I bet the budget for that department will be less, too..."

Well, if it's more expensive to prevent the attack than to pay the ransom, what's the point? ;)

I think you're right - as I said on a sibling comment, if beans are all you count, and bean-counters rule the roost, you can write this off as a one-off, and point out you had 30 years without a ransomware, and therefore we don't need to do anything...

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#87
post #55

Earlier quoted context omitted.

When I heard that this pipeline company started advertising a job opening for CyberSecurity Advisor in the last few days, and heard today the ransom of about $5 million was paid, my first reaction was to say "I bet the salary for that position is a lot less than $5 million, and I bet the budget for that department will be less, too..."

Well, if it's more expensive to prevent the attack than to pay the ransom, what's the point? ;)

Until the attacks get more expensive. Some companies never settle law suits even when it is obvious they will lose in court. As a result they only have to deal with courts in cases where it is obvious they will lose since no lawyer will bother a with a case that isn't obvious. (the end result is about the same lost overall - when they lose they tend to be punished in court for not settling)

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#88
post #15

Can crypto actually be non-traceable? I remember currencies like Monero or ZCash advertising privacy from the last crypto craze. I mean if you have 100M in some account, can you actually run it trough "private" currencies to remove traces? BTC, ETH etc. all seems super traceable, even more so than in regular banking. Also how are criminals getting their money out with no one noticing, does Panama/Malta etc. have Krak…

One (of many) ways: Monero -> bitcoin -> localbitcoins with stolen identity.

Each localbitcoins account can trade up to $200k a year without any kind of in-person verification.

Also a lot of exchanges let you cash out via western union so... you could theorically send yourself say 10k or 20k a a month with that, there's no need to just withdraw it all at once.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#89

Earlier quoted context omitted.

Nope. Monero is actually private and untraceable.

Until someone cracks it, that is. If it becomes the crypto of choice for some of the bigger fish, you can bet the government will find a way to trace it.

I did a deep dive with a friend of mine (we’re both OS engineers) and its going to be a hell of a cookie to crack.

There is a literal virtual tumbler built into the transaction protocol called ring signatures.

Stealth addresses (an additional crypto key pair) obfuscate senders and receivers.

They also hide the amount transferred which blew my mind.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#90
post #77
post #55

Earlier quoted context omitted.

When I heard that this pipeline company started advertising a job opening for CyberSecurity Advisor in the last few days, and heard today the ransom of about $5 million was paid, my first reaction was to say "I bet the salary for that position is a lot less than $5 million, and I bet the budget for that department will be less, too..."

I think you're spot-on here - the ransom is seen as a "cost of doing business", and until recently security was seen as "a problem that happens to other people". Sadly my experience is that organisations like this will take their $5m ransom (or other remediation cost), assume it's a one-off, then divide it by their number of ransom-free years, and proclaim it was better value for money than hiring 2 or 3 senior secur…

Even better, they will take the cost of their Insurance Deductible, and then do those calculations. Most businesses have insurance for this stuff.
Post reply on HN