Earlier quoted context omitted.
Until someone cracks it, that is. If it becomes the crypto of choice for some of the bigger fish, you can bet the government will find a way to trace it.
>Until someone cracks it This is certainly not a given. The government isn’t going to be cracking signal messages within any reasonable timeframe either.
DarkSide ransomware gang quits after servers, Bitcoin stash seized
101–110 of 623 posts
Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized
#102Just like the mob there are some targets that just aren't worth it because they bring too much heat. They are learning this is bad for business all around so they are stepping back and encouraging others to do the same.
There's a pretty clear message here that the US isn't fucking around.
Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized
#103Can crypto actually be non-traceable? I remember currencies like Monero or ZCash advertising privacy from the last crypto craze. I mean if you have 100M in some account, can you actually run it trough "private" currencies to remove traces? BTC, ETH etc. all seems super traceable, even more so than in regular banking. Also how are criminals getting their money out with no one noticing, does Panama/Malta etc. have Krak…
It's super trivial to withdraw, say, 1M. You can use https://tornado.cash/ to mix 100 ETH, there's currently around 10k such deposits, so you could do that 2-3 times to move 1M in ETH to an address that can't be tied to your previous addresses.
It's possible but no longer trivial to withdraw 10M. You could use the above method over a period of time, and some other methods.
It becomes much more difficult at much higher values. You could probably get 100M out disguised as trading profits or something. If I spent a few days thinking about it I could probably figure out ways to mix that much money on ETH, filter through DeFi apps, etc. Seems doable.
You could also just work with large exchanges that don't care. I don't know which ones are like that now, probably fewer than years ago.
Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized
#104> The REvil representative said its program was introducing new restrictions on the kinds of organizations that affiliates could hold for ransom, and that henceforth it would be forbidden to attack those in the “social sector” (defined as healthcare and educational institutions) and organizations in the “gov-sector” (state) of any country. Affiliates also will be required to get approval before infecting victims. Sta…
This is a business that actually provides better support than a regular business.
From conversations with friends in the Infragard side of this, and the agencies that collaborate, they have 24/7 English support available before and after payment, as well as decryption remote support if you can't get your files decrypted... there are also instances of refunds if they can't decrypt your files due to technical issues.
Unlike regular businesses, support is a sales channel since it's the way to ensure you get paid so a lot of resources go to support activities in these "organizations".
Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized
#105> The REvil representative said its program was introducing new restrictions on the kinds of organizations that affiliates could hold for ransom, and that henceforth it would be forbidden to attack those in the “social sector” (defined as healthcare and educational institutions) and organizations in the “gov-sector” (state) of any country. Affiliates also will be required to get approval before infecting victims. Sta…
That's not really reasonable - what about replacing hacking with murder? It's illegal for a reason - and not because it's too costly to do.
Ransomware gangs aren't the vigilante heroes/embodiment of the undervalued IT security worker. They're a group of people looking to make a quick buck and don't give a damn about the harm they cause or who they cause it to.
Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized
#106Earlier quoted context omitted.
When I heard that this pipeline company started advertising a job opening for CyberSecurity Advisor in the last few days, and heard today the ransom of about $5 million was paid, my first reaction was to say "I bet the salary for that position is a lot less than $5 million, and I bet the budget for that department will be less, too..."
Well, if it's more expensive to prevent the attack than to pay the ransom, what's the point? ;)
Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized
#107https://www.cisa.gov/critical-infrastructure-sectors
Pretty easy to identify what is Critical Infrastructure.
The bigger reason for more coverage is optics. People take money out of their wallet on a regular basis to pay for gas. Gas gets them to their job, where they can then make more money to pay for gas, food, and so on. If Gas is affected, their job, their routine and their wallet is affected.
Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized
#108Just goes to show how unsophisticated they are and how low ransomware game barrier of entry really is.
Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized
#109Earlier quoted context omitted.
Oil does require infrastructure. What you put in your car is several steps removed from what is pumped out of the ground.
I think the parent's point was that if oil infrastructure is completely disrupted, consumers won't even be affected for a few days and the short-term consequences will be somewhat minor (some percentage of drivers won't be able to drive, deliveries may be delayed). If a hospital is shut down, then people will start dying immediately. The consequences are much more direct and severe.
If a hospital closes, patients can be moved. If there's no gas, patients can't get to any hospital.
Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized
#110Feels like a nation-state response. US Cyber Command? Either way, a chilling warning to organized hacking groups.
Feels like an inside job. “Oops. We lost all the money of our affiliates. Our money is gone too. No we didn’t take it.” Sure you didn’t.
They'd just take the money and disappear. The fact that they are continuing means that they want to continue the business.
And if they are doing that, then why would they suddenly break all existing contracts? Surely that would ruin a lot of their reputation, and hurt their ability to get clients. Can you imagine what kind of amazing free PR they would be getting if they continued the attack? Surely other criminals would be amazed at their ability to resist counter hacks. That would mean more clients and more money.
No, no. While I'm sure there is theft in the ransomware world, I don't think you make this kind of play from a position of strength.