DarkSide ransomware gang quits after servers, Bitcoin stash seized
141–150 of 623 posts
Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized
#142It was a mistake to attack the business side of the oil company, because it created what could be sold as reasonable doubt to shut down the pipeline. As a result, the ransom had the optics of an attack on infrastructure. As evidenced by the coverage of Americans desperately filling up containers. This created the impetus for the US to treat this as an incident far and above the ambient ransomware activities leading u…
Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized
#143Earlier quoted context omitted.
When I heard that this pipeline company started advertising a job opening for CyberSecurity Advisor in the last few days, and heard today the ransom of about $5 million was paid, my first reaction was to say "I bet the salary for that position is a lot less than $5 million, and I bet the budget for that department will be less, too..."
TBH I was shocked $5 million was all it cost.
"OK, now that you have our attention, and the eyes of the entire international media apparatus are on us, here's how we're going to do this. We're going to send some integer number of million money dollars down this pipe, and you're going to turn that gas pipe back on like you said you would.
Then here's what happens next... we're going to give you an integer number of minutes running head start before the drone strikes start raining down on these 12 sites we've identified as likely candidates for your location, ... now how many millions was it that you were asking for from us again?"
Doesn't really matter how much it was, either, if it has really been seized already in less than 24 hours. Was it enough to convince the boss guy or gal to take the bait and risk revealing themselves? (Probably not, but IMHO that wasn't likely to happen anyway, at least not since the heat started getting turned up on them all.)
Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized
#144> The REvil representative said its program was introducing new restrictions on the kinds of organizations that affiliates could hold for ransom, and that henceforth it would be forbidden to attack those in the “social sector” (defined as healthcare and educational institutions) and organizations in the “gov-sector” (state) of any country. Affiliates also will be required to get approval before infecting victims. Sta…
> seem to point to ransomware activities being far more coordinated and "business-like" than they often get credit for. This is a business that actually provides better support than a regular business. From conversations with friends in the Infragard side of this, and the agencies that collaborate, they have 24/7 English support available before and after payment, as well as decryption remote support if you can't get…
I would like to hear more about this, that sounds kind of hilarious. "Ah, apologies, we'll get that back to you within 3 business days. Have a nice day, I hope you had backups"
Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized
#145Can crypto actually be non-traceable? I remember currencies like Monero or ZCash advertising privacy from the last crypto craze. I mean if you have 100M in some account, can you actually run it trough "private" currencies to remove traces? BTC, ETH etc. all seems super traceable, even more so than in regular banking. Also how are criminals getting their money out with no one noticing, does Panama/Malta etc. have Krak…
I think it's still just pseudo-anonymity, even for monero. Which means, practically, that I don't think it would have done more for these guys than just delay the seizure.
Nope.
Monero, ZCash, and mimblewimble-based cryptos (grin, beam) are certainly not pseudo-anonymous, and tracking is darn near impossible if the users don't do anything stupid.
Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized
#146Earlier quoted context omitted.
When I heard that this pipeline company started advertising a job opening for CyberSecurity Advisor in the last few days, and heard today the ransom of about $5 million was paid, my first reaction was to say "I bet the salary for that position is a lot less than $5 million, and I bet the budget for that department will be less, too..."
Well, if it's more expensive to prevent the attack than to pay the ransom, what's the point? ;)
Maybe now utilities going to the US for a similar reason will be in everyone's DR/IR plan (even if Colonial didn't reach out to the US admin).
Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized
#147If I were these guys (I am glad I am not), You have just brought down far more interest and heat from now just law enforcement but probably at least a couple of intelligence services.
Arranging your own death would seem like a reasonable thing to do.
All our money is gone, stolen. All our servers are gone, grabbed by law enforcement. We have nothing left. Bye.
It would be interesting to follow the Bitcoins traversal around the network.
Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized
#148It was a mistake to attack the business side of the oil company, because it created what could be sold as reasonable doubt to shut down the pipeline. As a result, the ransom had the optics of an attack on infrastructure. As evidenced by the coverage of Americans desperately filling up containers. This created the impetus for the US to treat this as an incident far and above the ambient ransomware activities leading u…
Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized
#149Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized
#150> The REvil representative said its program was introducing new restrictions on the kinds of organizations that affiliates could hold for ransom, and that henceforth it would be forbidden to attack those in the “social sector” (defined as healthcare and educational institutions) and organizations in the “gov-sector” (state) of any country. Affiliates also will be required to get approval before infecting victims. Sta…
It's just digital Privateering - Francis Drake with a laptop.
> If a market correction occurs...
The English solved it by expanding their Navy and enlisting those who would otherwise pirate. Seems like as good a solution as any here.