Live data from Hacker News

DarkSide ransomware gang quits after servers, Bitcoin stash seized

krebsonsecurity.com

181–190 of 623 posts

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#181

I'm interested to understand the psychology of ransomware types who go after these enormous and important targets. That includes the pipeline, which obviously claimed at least a few lives of its own via people not being able to drive to get medical care, etc. Are they armchair criminal masterminds who don't really have a visceral understanding of how much damage they're doing? Or just straight up psychopaths? I can't…

They've learned from this, from the article:

"The REvil representative said its program was introducing new restrictions on the kinds of organizations that affiliates could hold for ransom, and that henceforth it would be forbidden to attack those in the “social sector” (defined as healthcare and educational institutions) and organizations in the “gov-sector” (state) of any country. Affiliates also will be required to get approval before infecting victims."

They aren't trying to cause this kind of harm.

Additionally: "DarkSide organizers also said they were releasing decryption tools for all of the companies that have been ransomed but which haven’t yet paid."

This people have more morals then most rich businessman, IMO.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#182
post #2

Feels like a nation-state response. US Cyber Command? Either way, a chilling warning to organized hacking groups.

hopefully this isn't the last of it. These people need to be found and imprisoned

Imprisonment seems generous. Perhaps a very small prison 6’ down would be more suitable.

I’m mildly surprised they survived this long

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#183
post #77

Earlier quoted context omitted.

I think you're spot-on here - the ransom is seen as a "cost of doing business", and until recently security was seen as "a problem that happens to other people". Sadly my experience is that organisations like this will take their $5m ransom (or other remediation cost), assume it's a one-off, then divide it by their number of ransom-free years, and proclaim it was better value for money than hiring 2 or 3 senior secur…

Well, sometimes they're right. The hit company will likely call in some consultancy to institute a bunch of newer and better security protocols, then call it a day. If they really aren't hit again for another decade and staffing a department would cost $500k a year or more, were they wrong? It's a gamble. It's easy to point fingers at the company that was caught out, but for the hundreds or thousands that aren't rans…

They paid $5 million, if "it was cheaper for them," that's solid math that ignores some really important stuff though, LOL. What is the externalized cost of this crisis on the entire country? The $5 million dollar ransom is a worse deal if you can convince your board to consider that externality.

The criminal penalties for executives in leadership and board positions (and I'm not saying this is my preferred approach) would certainly go a long way toward changing the calculus of this exchange.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#184
post #72
post #15

Can crypto actually be non-traceable? I remember currencies like Monero or ZCash advertising privacy from the last crypto craze. I mean if you have 100M in some account, can you actually run it trough "private" currencies to remove traces? BTC, ETH etc. all seems super traceable, even more so than in regular banking. Also how are criminals getting their money out with no one noticing, does Panama/Malta etc. have Krak…

These groups will often use bitcoin tumblers/mixers to anonymize their btc. This is a solid explanation https://www.deepwebsiteslinks.com/wp-content/uploads/2017/10...

Is there a technical reason that makes use of a tumbler legally safe? My concern would be that putting in a clean bitcoin would result in me getting a fraction of a stolen bitcoin and I would be receiving stolen property. The fact that they are fully traceable means that it would be easy for someone innocent to be caught up in something like that.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#185
post #43

> The REvil representative said its program was introducing new restrictions on the kinds of organizations that affiliates could hold for ransom, and that henceforth it would be forbidden to attack those in the “social sector” (defined as healthcare and educational institutions) and organizations in the “gov-sector” (state) of any country. Affiliates also will be required to get approval before infecting victims. Sta…

> “We are apolitical, we do not participate in geopolitics, do not need to tie us with a defined government and look for other our motives [sic],” reads an update to the DarkSide Leaks blog. “Our goal is to make money, and not creating problems for society. From today we introduce moderation and check each company that our partners want to encrypt to avoid social consequences in the future.”[1] [1] https://krebsonsec…

Sounds like they're about to get rolled up by law enforcement as well. As someone who's had the full force of a three letter agency come down on me, this is not something you want to deal with on any level. I was lucky. I was young and dumb and got a slap on the wrist.

Times have changed and when govt agencies see this as an attack on critical infrastructure, you're looking at some serious jail time. I would say its only a matter of time until they're tracked down. When you're being hunted like that, the govt works 24/7 and never stops. People on the run don't have that luxury.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#186
post #69

Earlier quoted context omitted.

I think the question is, how come an attack on a hospital does not have the optics of an attack on infrastructure? (It almost seems oil does not require infrastructure - you can, theoretically, prep for an oil infrastructure outage by storing it containers, same as you do with water and food. But you can't really prep for a medical infrastructure outage. Is it just that, as a result, there were no photos of people ho…

Critical Infrastructure as Govt defines it https://www.cisa.gov/critical-infrastructure-sectors

I'm not sure what point this comment is trying to make, according to CISA emergency services are a critical infrastructure sector. Therefore attacks on hospitals are attacks on critical infrastructure just like a pipeline.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#187

Why should I believe this? They can shut down their servers, move their crypto to different wallets, and pop up again in a few weeks, right?

It's plausible that this is all a scheme to evade capture. Disband the current organization, (get rid of a few people who you've wanted to jettison anyway), and then set up shop afresh elsewhere. It sends the message to whoever's looking for you that the whole thing has been burned to the ground and there's nothing to raid or seize or shut down.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#188
post #50

DarkSide's English is incredibly good for some supposed Russians. It even has the correct use of the apostrophe in "clients'". I know nothing, but my hunch is that this was written by a well-educated person who grew up in the US or Canada.

I've noticed that central Europeans have pretty stellar grammar in general. I was doing some work on an open source project created by a Polish team and was surprised by how many obscure grammar rules they obeyed. Might have something to do with many of these rules being derived from Latin and their native language is probably closer in structure to Latin than English is.

[deleted]

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#189
post #143
post #95

Earlier quoted context omitted.

TBH I was shocked $5 million was all it cost.

I imagine it went something like this "OK, now that you have our attention, and the eyes of the entire international media apparatus are on us, here's how we're going to do this. We're going to send some integer number of million money dollars down this pipe, and you're going to turn that gas pipe back on like you said you would. Then here's what happens next... we're going to give you an integer number of minutes ru…

There is basically a zero percent chance that the US knew where they were physically.

The servers that were claimed to be seized were on cloud platforms.

And even then, we don't know if this is true or if it's just an exit strategy.

Post reply on HN