Live data from Hacker News

DarkSide ransomware gang quits after servers, Bitcoin stash seized

krebsonsecurity.com

131–140 of 623 posts

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#131
post #15

Can crypto actually be non-traceable? I remember currencies like Monero or ZCash advertising privacy from the last crypto craze. I mean if you have 100M in some account, can you actually run it trough "private" currencies to remove traces? BTC, ETH etc. all seems super traceable, even more so than in regular banking. Also how are criminals getting their money out with no one noticing, does Panama/Malta etc. have Krak…

One (of many) ways: Monero -> bitcoin -> localbitcoins with stolen identity. Each localbitcoins account can trade up to $200k a year without any kind of in-person verification. Also a lot of exchanges let you cash out via western union so... you could theorically send yourself say 10k or 20k a a month with that, there's no need to just withdraw it all at once.

There is no way to exchange Monero for Bitcoin or vice-versa without the risk of being tracked. LocalBitcoins has been doing KYC/AML since 2018.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#132
post #84

Seems like they should invest more into cybersecurity, if someone was able to “steal” their Bitcoin and take over their infrastructure ;). But honestly, this only shows that IT systems are nowadays so complex that you cannot get them right and be able to truly protect you, no matter if you’re good or bad guy.

I doubt anyone stole their bitcoins though. I assume they just transferred it out themselves and will cash out later.

I was thinking the same. But it would be hard to cover such a conspiracy.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#133
post #69
post #45

It was a mistake to attack the business side of the oil company, because it created what could be sold as reasonable doubt to shut down the pipeline. As a result, the ransom had the optics of an attack on infrastructure. As evidenced by the coverage of Americans desperately filling up containers. This created the impetus for the US to treat this as an incident far and above the ambient ransomware activities leading u…

I think the question is, how come an attack on a hospital does not have the optics of an attack on infrastructure? (It almost seems oil does not require infrastructure - you can, theoretically, prep for an oil infrastructure outage by storing it containers, same as you do with water and food. But you can't really prep for a medical infrastructure outage. Is it just that, as a result, there were no photos of people ho…

Critical Infrastructure as Govt defines it

https://www.cisa.gov/critical-infrastructure-sectors

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#135
post #70
post #19

Just like the mob there are some targets that just aren't worth it because they bring too much heat. They are learning this is bad for business all around so they are stepping back and encouraging others to do the same.

This is it. Governments have cyber abilities that far outstrip individual organizations. And when cyber fails, there are still other diplomatic and less diplomatic tools. I wouldn't be surprised if the US Government here reached out to foreign governments for assistance in dismantling their infrastructure (it almost certainly was not on US soil). An individual hospital probably couldn't garner that kind of backing, b…

yup. In popular parlance, "fucked around, found out"

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#136
post #45

It was a mistake to attack the business side of the oil company, because it created what could be sold as reasonable doubt to shut down the pipeline. As a result, the ransom had the optics of an attack on infrastructure. As evidenced by the coverage of Americans desperately filling up containers. This created the impetus for the US to treat this as an incident far and above the ambient ransomware activities leading u…

>It also gave the US an opportunity to show how effective it could be when it had the political cover to do so.

Not sure what you mean, what did the US do exactly?

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#137
post #103
post #15

Can crypto actually be non-traceable? I remember currencies like Monero or ZCash advertising privacy from the last crypto craze. I mean if you have 100M in some account, can you actually run it trough "private" currencies to remove traces? BTC, ETH etc. all seems super traceable, even more so than in regular banking. Also how are criminals getting their money out with no one noticing, does Panama/Malta etc. have Krak…

Yes, up to a limit. It's super trivial to withdraw, say, 1M. You can use https://tornado.cash/ to mix 100 ETH, there's currently around 10k such deposits, so you could do that 2-3 times to move 1M in ETH to an address that can't be tied to your previous addresses. It's possible but no longer trivial to withdraw 10M. You could use the above method over a period of time, and some other methods. It becomes much more dif…

You don't need to. You can send the ETH to tornado.cash. Their anonymity set is such that 100 million would take a long time, but on the order of months to withdraw. Tornado.cash has millions in total locked value in different ETH denominated pools.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#138
post #90
post #77

Earlier quoted context omitted.

I think you're spot-on here - the ransom is seen as a "cost of doing business", and until recently security was seen as "a problem that happens to other people". Sadly my experience is that organisations like this will take their $5m ransom (or other remediation cost), assume it's a one-off, then divide it by their number of ransom-free years, and proclaim it was better value for money than hiring 2 or 3 senior secur…

Even better, they will take the cost of their Insurance Deductible, and then do those calculations. Most businesses have insurance for this stuff.

And DarkSide has stated they target businesses with that insurance. It's smart. They were hosed the moment Colonial's infosec (or whomever) recommended closing the valves on the pipelines. Until that moment they'd been doing reasonably well (for criminal scum).

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#139
post #80

I think this roughly answers a question that I've been wondering about: Why don't cyber criminals hack into the energy grid, water, or other utilities? Surely their cyber security is outdated right? Well, their cyber security may not be the most advanced, but traditional security (i.e. military strength) likely dissuades criminals from choosing those targets that are likely to put them on the short list.

For some reason, this comment immediately made me think of an alternate history where ransomware groups hack infrastructure and then improve and monitor their security for them.

"Look guys, yeah, it's really easy to hack the power plants that supply electricity to the white house, but then we'll all have military ninjas showing up in our bedrooms at 3 in the morning. So if you try that little stunt again, then we're going to get our own ninjas to give you a visit. Go hack a cereal company or something."

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#140
post #43

> The REvil representative said its program was introducing new restrictions on the kinds of organizations that affiliates could hold for ransom, and that henceforth it would be forbidden to attack those in the “social sector” (defined as healthcare and educational institutions) and organizations in the “gov-sector” (state) of any country. Affiliates also will be required to get approval before infecting victims. Sta…

> “We are apolitical, we do not participate in geopolitics, do not need to tie us with a defined government and look for other our motives [sic],” reads an update to the DarkSide Leaks blog. “Our goal is to make money, and not creating problems for society. From today we introduce moderation and check each company that our partners want to encrypt to avoid social consequences in the future.”[1] [1] https://krebsonsec…

This is better then most rich businessman, actually. Many don't care if they create problems for society, if it means more money for them.
Post reply on HN