Live data from Hacker News

DarkSide ransomware gang quits after servers, Bitcoin stash seized

krebsonsecurity.com

101–110 of 623 posts

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#101
post #60

Earlier quoted context omitted.

Until someone cracks it, that is. If it becomes the crypto of choice for some of the bigger fish, you can bet the government will find a way to trace it.

>Until someone cracks it This is certainly not a given. The government isn’t going to be cracking signal messages within any reasonable timeframe either.

Obligitory XKCD: https://xkcd.com/538/

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#102
post #19

Just like the mob there are some targets that just aren't worth it because they bring too much heat. They are learning this is bad for business all around so they are stepping back and encouraging others to do the same.

One thing that impressed me about this situation was the speed at which this was dealt with. A few hours after the attack, an executive order was signed reducing regulations around truck transport of fuel. But the next day, service was being restored. And by the end of the week, the attackers were disbanded and their assets seized.

There's a pretty clear message here that the US isn't fucking around.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#103
post #15

Can crypto actually be non-traceable? I remember currencies like Monero or ZCash advertising privacy from the last crypto craze. I mean if you have 100M in some account, can you actually run it trough "private" currencies to remove traces? BTC, ETH etc. all seems super traceable, even more so than in regular banking. Also how are criminals getting their money out with no one noticing, does Panama/Malta etc. have Krak…

Yes, up to a limit.

It's super trivial to withdraw, say, 1M. You can use https://tornado.cash/ to mix 100 ETH, there's currently around 10k such deposits, so you could do that 2-3 times to move 1M in ETH to an address that can't be tied to your previous addresses.

It's possible but no longer trivial to withdraw 10M. You could use the above method over a period of time, and some other methods.

It becomes much more difficult at much higher values. You could probably get 100M out disguised as trading profits or something. If I spent a few days thinking about it I could probably figure out ways to mix that much money on ETH, filter through DeFi apps, etc. Seems doable.

You could also just work with large exchanges that don't care. I don't know which ones are like that now, probably fewer than years ago.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#104
post #43

> The REvil representative said its program was introducing new restrictions on the kinds of organizations that affiliates could hold for ransom, and that henceforth it would be forbidden to attack those in the “social sector” (defined as healthcare and educational institutions) and organizations in the “gov-sector” (state) of any country. Affiliates also will be required to get approval before infecting victims. Sta…

> seem to point to ransomware activities being far more coordinated and "business-like" than they often get credit for.

This is a business that actually provides better support than a regular business.

From conversations with friends in the Infragard side of this, and the agencies that collaborate, they have 24/7 English support available before and after payment, as well as decryption remote support if you can't get your files decrypted... there are also instances of refunds if they can't decrypt your files due to technical issues.

Unlike regular businesses, support is a sales channel since it's the way to ensure you get paid so a lot of resources go to support activities in these "organizations".

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#105
post #43

> The REvil representative said its program was introducing new restrictions on the kinds of organizations that affiliates could hold for ransom, and that henceforth it would be forbidden to attack those in the “social sector” (defined as healthcare and educational institutions) and organizations in the “gov-sector” (state) of any country. Affiliates also will be required to get approval before infecting victims. Sta…

That's not really reasonable - what about replacing hacking with murder? It's illegal for a reason - and not because it's too costly to do.

I was thinking replacing hacker with scammer. After all, Scammers scamming old folks are just showing a gap in online education and regulations.

Ransomware gangs aren't the vigilante heroes/embodiment of the undervalued IT security worker. They're a group of people looking to make a quick buck and don't give a damn about the harm they cause or who they cause it to.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#106
post #55

Earlier quoted context omitted.

When I heard that this pipeline company started advertising a job opening for CyberSecurity Advisor in the last few days, and heard today the ransom of about $5 million was paid, my first reaction was to say "I bet the salary for that position is a lot less than $5 million, and I bet the budget for that department will be less, too..."

Well, if it's more expensive to prevent the attack than to pay the ransom, what's the point? ;)

Now that they've outed themselves as an easy mark, should be simple to hit them again and demand more money. At some point it'll be less expensive to improve their security infrastructure.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#107
Critical Infrastructure Sectors as defined by CISA

https://www.cisa.gov/critical-infrastructure-sectors

Pretty easy to identify what is Critical Infrastructure.

The bigger reason for more coverage is optics. People take money out of their wallet on a regular basis to pay for gas. Gas gets them to their job, where they can then make more money to pay for gas, food, and so on. If Gas is affected, their job, their routine and their wallet is affected.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#109

Earlier quoted context omitted.

Oil does require infrastructure. What you put in your car is several steps removed from what is pumped out of the ground.

I think the parent's point was that if oil infrastructure is completely disrupted, consumers won't even be affected for a few days and the short-term consequences will be somewhat minor (some percentage of drivers won't be able to drive, deliveries may be delayed). If a hospital is shut down, then people will start dying immediately. The consequences are much more direct and severe.

I think this is simplistic and overlooks logistics and flexibility.

If a hospital closes, patients can be moved. If there's no gas, patients can't get to any hospital.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#110
post #3
post #2

Feels like a nation-state response. US Cyber Command? Either way, a chilling warning to organized hacking groups.

Feels like an inside job. “Oops. We lost all the money of our affiliates. Our money is gone too. No we didn’t take it.” Sure you didn’t.

That doesn't make a lot of sense. If they thought that they could take a golden exit, they wouldn't be continuing to setup the business again under new rules to avoid government scrutiny.

They'd just take the money and disappear. The fact that they are continuing means that they want to continue the business.

And if they are doing that, then why would they suddenly break all existing contracts? Surely that would ruin a lot of their reputation, and hurt their ability to get clients. Can you imagine what kind of amazing free PR they would be getting if they continued the attack? Surely other criminals would be amazed at their ability to resist counter hacks. That would mean more clients and more money.

No, no. While I'm sure there is theft in the ransomware world, I don't think you make this kind of play from a position of strength.

Post reply on HN