Live data from Hacker News

DarkSide ransomware gang quits after servers, Bitcoin stash seized

krebsonsecurity.com

111–120 of 623 posts

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#111
post #50

DarkSide's English is incredibly good for some supposed Russians. It even has the correct use of the apostrophe in "clients'". I know nothing, but my hunch is that this was written by a well-educated person who grew up in the US or Canada.

I've noticed that central Europeans have pretty stellar grammar in general. I was doing some work on an open source project created by a Polish team and was surprised by how many obscure grammar rules they obeyed.

Might have something to do with many of these rules being derived from Latin and their native language is probably closer in structure to Latin than English is.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#112
post #69
post #45

It was a mistake to attack the business side of the oil company, because it created what could be sold as reasonable doubt to shut down the pipeline. As a result, the ransom had the optics of an attack on infrastructure. As evidenced by the coverage of Americans desperately filling up containers. This created the impetus for the US to treat this as an incident far and above the ambient ransomware activities leading u…

I think the question is, how come an attack on a hospital does not have the optics of an attack on infrastructure? (It almost seems oil does not require infrastructure - you can, theoretically, prep for an oil infrastructure outage by storing it containers, same as you do with water and food. But you can't really prep for a medical infrastructure outage. Is it just that, as a result, there were no photos of people ho…

Because when you attack oil it will be considered as an act of war and they will counter with their war powers. Which they did. No civilian police action against Sergey followed, but military style seizures, bitmix closure and Bitcoin retrieval. This was not the FBI, but their criminal higher ups. Military style, with no civilian oversight.

Which is somewhat disturbing, because first the industry is still considered more important than civil services (city councils, hospitals). And second they will still continue using Windows services in their backbones. I have nothing against using Windows as frontends, but in the backbone of a critical company it's criminal negligence. Easy to hack, no backups, untrained admins with no idea about security. Wasting billions on money on theatre, and not working servers, groupware and email.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#113
post #55
post #43

> The REvil representative said its program was introducing new restrictions on the kinds of organizations that affiliates could hold for ransom, and that henceforth it would be forbidden to attack those in the “social sector” (defined as healthcare and educational institutions) and organizations in the “gov-sector” (state) of any country. Affiliates also will be required to get approval before infecting victims. Sta…

When I heard that this pipeline company started advertising a job opening for CyberSecurity Advisor in the last few days, and heard today the ransom of about $5 million was paid, my first reaction was to say "I bet the salary for that position is a lot less than $5 million, and I bet the budget for that department will be less, too..."

[deleted]

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#114
post #86

Earlier quoted context omitted.

Well, if it's more expensive to prevent the attack than to pay the ransom, what's the point? ;)

I think you're right - as I said on a sibling comment, if beans are all you count, and bean-counters rule the roost, you can write this off as a one-off, and point out you had 30 years without a ransomware, and therefore we don't need to do anything...

[deleted]

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#115
post #43

> The REvil representative said its program was introducing new restrictions on the kinds of organizations that affiliates could hold for ransom, and that henceforth it would be forbidden to attack those in the “social sector” (defined as healthcare and educational institutions) and organizations in the “gov-sector” (state) of any country. Affiliates also will be required to get approval before infecting victims. Sta…

> business-like

Reminds me of this negotiation: https://www.reuters.com/article/us-cyber-cwt-ransom/payment-...

Previously discussed here: https://news.ycombinator.com/item?id=24032779

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#116
post #3
post #2

Feels like a nation-state response. US Cyber Command? Either way, a chilling warning to organized hacking groups.

Feels like an inside job. “Oops. We lost all the money of our affiliates. Our money is gone too. No we didn’t take it.” Sure you didn’t.

100%

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#118
post #60

Earlier quoted context omitted.

>Until someone cracks it This is certainly not a given. The government isn’t going to be cracking signal messages within any reasonable timeframe either.

Obligitory XKCD: https://xkcd.com/538/

Rubberhose cryptanalysis does not work with Monero because you don’t know who to whack.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#120
post #43

> The REvil representative said its program was introducing new restrictions on the kinds of organizations that affiliates could hold for ransom, and that henceforth it would be forbidden to attack those in the “social sector” (defined as healthcare and educational institutions) and organizations in the “gov-sector” (state) of any country. Affiliates also will be required to get approval before infecting victims. Sta…

> seem to point to ransomware activities being far more coordinated and "business-like" than they often get credit for. This is a business that actually provides better support than a regular business. From conversations with friends in the Infragard side of this, and the agencies that collaborate, they have 24/7 English support available before and after payment, as well as decryption remote support if you can't get…

Yeah apparently in addition to their white label ransomware software, if you licensed their software you could also have DarkSide handle negotiations for you. 10%-25% of the ransom and in exchange you get people who have real experience handling the negotiations and have the infra in place already to remain anonymous while supporting 24/7 English language service.
Post reply on HN