Live data from Hacker News

DarkSide ransomware gang quits after servers, Bitcoin stash seized

krebsonsecurity.com

161–170 of 623 posts

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#161

So taking down hospitals and healthcare facilities was fair game. But messing with Big Oil was just a step too far.

That shouldn't be a much of a surprise; the US has always aligned itself with protecting it's oil supply.

Everyone freaks out about oil. Japan attacked the United States in World War 2 because the United States stopped exporting oil to Japan. It was the primary motivator behind Pearl Harbor.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#162

Earlier quoted context omitted.

Well, if it's more expensive to prevent the attack than to pay the ransom, what's the point? ;)

Now that they've outed themselves as an easy mark, should be simple to hit them again and demand more money. At some point it'll be less expensive to improve their security infrastructure.

Ransoming Colonial basically put Darkside out of business. no one is going to hit them again

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#163
Re-posted comment from a previous thread[0]

Still relevant

[0] https://news.ycombinator.com/item?id=27097966

___________________

There is a theory floating about that some ransomware attacks were done purely to damage a country's infra and making money was a bonus, but not the main aim. So the perpetrators used ransomware as a front and the real goal is to destroy and disrupt a country's computer infra.

But then we could argue ransomware is just going to bolster and make our systems antifragile and resilient against such attacks in the future, so the ransomware attacks could backfire since in the future it would be much harder to attack the US for example with other types of malware.

It also means people are going to be storing mission critical and crown-jewels type data in airgapped systems and making filesystems read-only. The data would also be encrypted and compartmented into separate containers so attacks can't affect the whole filesystem if the airgap was breached.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#164
post #85

Earlier quoted context omitted.

it can be harder to trace, but the bigger problem is trying to turn it into cash, which is hard to do anonymously regardless of the currency used (BTc, XMR, etc). THe FBI,Secret Service, are mostly focused on the conversion of crypto to cash, not the intermediary steps.

doesn't work if the fiat converted to is in another jurisdiction

There are few jurisdictions where the US Government can't easily get at you, either physically or financially. China, Venezuela, North Korea, Russia the list is super thin and almost exclusively places you either don't want to be or where you better be a protected local (otherwise they'll just hang you out to dry for their own benefit or amusement).

Most authorities around the world will want to nail you - and or your money - in cooperation with the US authorities (or otherwise for their own benefit). Once they know the US wants you, you become a toy to be used to some end, you're toast, your life is over.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#165
post #45

It was a mistake to attack the business side of the oil company, because it created what could be sold as reasonable doubt to shut down the pipeline. As a result, the ransom had the optics of an attack on infrastructure. As evidenced by the coverage of Americans desperately filling up containers. This created the impetus for the US to treat this as an incident far and above the ambient ransomware activities leading u…

> business side of the oil company

What are the sides of any company other than "business"?

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#166
post #50

DarkSide's English is incredibly good for some supposed Russians. It even has the correct use of the apostrophe in "clients'". I know nothing, but my hunch is that this was written by a well-educated person who grew up in the US or Canada.

Or they used something like Grammarly...

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#167
post #50

DarkSide's English is incredibly good for some supposed Russians. It even has the correct use of the apostrophe in "clients'". I know nothing, but my hunch is that this was written by a well-educated person who grew up in the US or Canada.

As a native Russian speaker living in New York, I concur. I work in Ad Tech and deal with clients from Eastern Europe quite often. Russians' English is _always_ recognizable.

Is this sarcastic? Because you’re a native Russian speaker and yet your English isn’t recognizably Russian…

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#168
post #52

Seems like they should invest more into cybersecurity, if someone was able to “steal” their Bitcoin and take over their infrastructure ;). But honestly, this only shows that IT systems are nowadays so complex that you cannot get them right and be able to truly protect you, no matter if you’re good or bad guy.

It just takes one agent or informant on the inside to bring the whole house down.

If you have single point of failure, either on technical or human level, you aren’t doing it correctly.

But it’s really hard to build systems and organizations like that.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#169
post #148
post #45

It was a mistake to attack the business side of the oil company, because it created what could be sold as reasonable doubt to shut down the pipeline. As a result, the ransom had the optics of an attack on infrastructure. As evidenced by the coverage of Americans desperately filling up containers. This created the impetus for the US to treat this as an incident far and above the ambient ransomware activities leading u…

Russia allows their FSB operatives to moonlight on the side. Darkside hackers could be government operatives and an attack on critical infrastructure is an act of war. It is the same as bombing the pipeline if infrastructure is disabled. I am sure the cyber insurance provider won’t pay and say it was an act of war by a foreign government. It always a grey area.

Do you have any extraordinary evidence for these extraordinary claims?

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#170
Idiots. They have every arm-chair analyst saying “cryptocureency is the cause of ransomware!” and they don't even use multisig to leverage the cryptocurrency technology preventing that prevents its unilateral seizure?

Looking forward to the day when someone proves there is nothing the state can do. But for now we have to watch these lackadaisical shit shows.

Post reply on HN