Live data from Hacker News

DarkSide ransomware gang quits after servers, Bitcoin stash seized

krebsonsecurity.com

151–160 of 623 posts

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#151
post #103

Earlier quoted context omitted.

Yes, up to a limit. It's super trivial to withdraw, say, 1M. You can use https://tornado.cash/ to mix 100 ETH, there's currently around 10k such deposits, so you could do that 2-3 times to move 1M in ETH to an address that can't be tied to your previous addresses. It's possible but no longer trivial to withdraw 10M. You could use the above method over a period of time, and some other methods. It becomes much more dif…

You don't need to. You can send the ETH to tornado.cash. Their anonymity set is such that 100 million would take a long time, but on the order of months to withdraw. Tornado.cash has millions in total locked value in different ETH denominated pools.

Yeah I guess, as long as ETH stays around the current level.

But if you do hundreds of withdrawals from tornado, it's less anonymous, because the set of people that have deposited that range to tornado is much smaller than the set of people who did a handful of deposits. Instead of 10k, you might be one of a few dozen or less.

You could always send a million to a friend (through tornado) and have them cash out for a cut, and repeat that 100 times, if you have 100 friends. That would kill on-chain analysis.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#152
post #19

Just like the mob there are some targets that just aren't worth it because they bring too much heat. They are learning this is bad for business all around so they are stepping back and encouraging others to do the same.

One thing that impressed me about this situation was the speed at which this was dealt with. A few hours after the attack, an executive order was signed reducing regulations around truck transport of fuel. But the next day, service was being restored. And by the end of the week, the attackers were disbanded and their assets seized. There's a pretty clear message here that the US isn't fucking around.

If I'd just collected enough ransom to retire and never work again, I'd also put out a press release announcing I was out of business and someone seized all my shit and etc.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#153
post #80

I think this roughly answers a question that I've been wondering about: Why don't cyber criminals hack into the energy grid, water, or other utilities? Surely their cyber security is outdated right? Well, their cyber security may not be the most advanced, but traditional security (i.e. military strength) likely dissuades criminals from choosing those targets that are likely to put them on the short list.

I think DarkSide addressed this. They don't want to be viewed as a threat to society. They are thieves, they go after soft targets with deep pockets and ideally insurance, and they don't want to have the public or nation-states interested in them.

The game changed when the valves to the pipeline were closed as a precaution. They just went from thief to threat.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#154
post #15

Can crypto actually be non-traceable? I remember currencies like Monero or ZCash advertising privacy from the last crypto craze. I mean if you have 100M in some account, can you actually run it trough "private" currencies to remove traces? BTC, ETH etc. all seems super traceable, even more so than in regular banking. Also how are criminals getting their money out with no one noticing, does Panama/Malta etc. have Krak…

One (of many) ways: Monero -> bitcoin -> localbitcoins with stolen identity. Each localbitcoins account can trade up to $200k a year without any kind of in-person verification. Also a lot of exchanges let you cash out via western union so... you could theorically send yourself say 10k or 20k a a month with that, there's no need to just withdraw it all at once.

But if you get BTC through a mixer chances are they are tainted and you get yourself in trouble when withdrawing.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#155
post #77
post #55

Earlier quoted context omitted.

When I heard that this pipeline company started advertising a job opening for CyberSecurity Advisor in the last few days, and heard today the ransom of about $5 million was paid, my first reaction was to say "I bet the salary for that position is a lot less than $5 million, and I bet the budget for that department will be less, too..."

I think you're spot-on here - the ransom is seen as a "cost of doing business", and until recently security was seen as "a problem that happens to other people". Sadly my experience is that organisations like this will take their $5m ransom (or other remediation cost), assume it's a one-off, then divide it by their number of ransom-free years, and proclaim it was better value for money than hiring 2 or 3 senior secur…

Well, sometimes they're right. The hit company will likely call in some consultancy to institute a bunch of newer and better security protocols, then call it a day. If they really aren't hit again for another decade and staffing a department would cost $500k a year or more, were they wrong?

It's a gamble. It's easy to point fingers at the company that was caught out, but for the hundreds or thousands that aren't ransomed and aren't paying the extra money for security, they took that gamble and so far they've come out ahead not having spent all that money on prevention.

I'm not advocating that these companies to have less security or not do better on security, but the fact is a lot of them have made the objectively correct decision for themselves, which will continue to be correct right up until they're hit, if they ever are. The whole situation is analogous to health insurance in a way, and the same incentives are at play, along with similar consequences for individual companies and all of us as a whole, as providing easy targets for these groups allows them to thrive and grow and target others.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#156

Earlier quoted context omitted.

> seem to point to ransomware activities being far more coordinated and "business-like" than they often get credit for. This is a business that actually provides better support than a regular business. From conversations with friends in the Infragard side of this, and the agencies that collaborate, they have 24/7 English support available before and after payment, as well as decryption remote support if you can't get…

Yeah apparently in addition to their white label ransomware software, if you licensed their software you could also have DarkSide handle negotiations for you. 10%-25% of the ransom and in exchange you get people who have real experience handling the negotiations and have the infra in place already to remain anonymous while supporting 24/7 English language service.

Ransomware-As-A-Platform. I wonder if they got the criminal-underground equivalent of VC-funding, or if they have something like Y-combinator to fund innovative criminal approaches and promote networking -- like evil-Kirk from the mirror universe, there could be a Saul Graham with a mustache writing essays about unlocking value and what you are not allowed to say in the ransomware community.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#157

Why should I believe this? They can shut down their servers, move their crypto to different wallets, and pop up again in a few weeks, right?

Agreed, except why bother pop up again? They just got a big fat payment of $5m. Plenty to split with a small team. It's a good time to cash out and disappear.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#158
post #7

why are ransomware groups transacting in BTC, which can be easily traced?

It's easier to launder and transfer the BTC than to do the same with real money. According to the article, the people behind Darkside were also behind a bitcoin "mixing" service that was recently shut down.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#159
post #131

Earlier quoted context omitted.

One (of many) ways: Monero -> bitcoin -> localbitcoins with stolen identity. Each localbitcoins account can trade up to $200k a year without any kind of in-person verification. Also a lot of exchanges let you cash out via western union so... you could theorically send yourself say 10k or 20k a a month with that, there's no need to just withdraw it all at once.

There is no way to exchange Monero for Bitcoin or vice-versa without the risk of being tracked. LocalBitcoins has been doing KYC/AML since 2018.

Transactions between monero accounts can't be tracked, or at least there's no evidence that they can be tracked.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#160
I'm interested to understand the psychology of ransomware types who go after these enormous and important targets. That includes the pipeline, which obviously claimed at least a few lives of its own via people not being able to drive to get medical care, etc.

Are they armchair criminal masterminds who don't really have a visceral understanding of how much damage they're doing? Or just straight up psychopaths? I can't think of any other options.

Post reply on HN