Live data from Hacker News

DarkSide ransomware gang quits after servers, Bitcoin stash seized

krebsonsecurity.com

191–200 of 623 posts

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#191
post #156

Earlier quoted context omitted.

Yeah apparently in addition to their white label ransomware software, if you licensed their software you could also have DarkSide handle negotiations for you. 10%-25% of the ransom and in exchange you get people who have real experience handling the negotiations and have the infra in place already to remain anonymous while supporting 24/7 English language service.

Ransomware-As-A-Platform. I wonder if they got the criminal-underground equivalent of VC-funding, or if they have something like Y-combinator to fund innovative criminal approaches and promote networking -- like evil-Kirk from the mirror universe, there could be a Saul Graham with a mustache writing essays about unlocking value and what you are not allowed to say in the ransomware community.

There is investment infrastructure. Mostly informal and enforced via smart contract and multisignature transactions. Organized on forums and chat rooms.

Not much capital is needed though and the affiliate and licensing model is better, which also just means an address is hardcoded that splits payment, or a server controls the private key (or master private key for infinite unique address creation) to addresses and automatically splits received payments to the RaaS service

I get that was supposed to be a joke, its exactly the same or even more streamlined than the licit economy. There is no major distinction except the kinds of “risk factors” one might list.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#192
post #148

Earlier quoted context omitted.

Russia allows their FSB operatives to moonlight on the side. Darkside hackers could be government operatives and an attack on critical infrastructure is an act of war. It is the same as bombing the pipeline if infrastructure is disabled. I am sure the cyber insurance provider won’t pay and say it was an act of war by a foreign government. It always a grey area.

Do you have any extraordinary evidence for these extraordinary claims?

Very few doubt that FSB and Russian mafia are one.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#193

Earlier quoted context omitted.

One thing that impressed me about this situation was the speed at which this was dealt with. A few hours after the attack, an executive order was signed reducing regulations around truck transport of fuel. But the next day, service was being restored. And by the end of the week, the attackers were disbanded and their assets seized. There's a pretty clear message here that the US isn't fucking around.

If I'd just collected enough ransom to retire and never work again, I'd also put out a press release announcing I was out of business and someone seized all my shit and etc.

Darkside was a legit business. They routinely collected ransoms ten or twenty times larger than what they got from Colonial. if they were going to retire, they would have done it a long time ago

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#194

A far fetched scenario: If I were these guys (I am glad I am not), You have just brought down far more interest and heat from now just law enforcement but probably at least a couple of intelligence services. Arranging your own death would seem like a reasonable thing to do. All our money is gone, stolen. All our servers are gone, grabbed by law enforcement. We have nothing left. Bye. It would be interesting to follow…

Having done something so idiotic as inadvertently taking down critical infrastructure for a superpower with global military & espionage capabilities (that nearly all nations will cooperate with) - the problem is, the people chasing you do not give a shit about your money and whether it's gone, and they do not care about your servers. Bye won't work, and faking your death won't be believable. If you're these people, you're going to be hunted to the ends of the planet and most likely they're royally screwed with no way out (unless they're under the direct protection of eg China or Russia).

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#195

I'm interested to understand the psychology of ransomware types who go after these enormous and important targets. That includes the pipeline, which obviously claimed at least a few lives of its own via people not being able to drive to get medical care, etc. Are they armchair criminal masterminds who don't really have a visceral understanding of how much damage they're doing? Or just straight up psychopaths? I can't…

It is not obvious that this claimed any lives as fuel shortages weren't really there because of the quick payment of ransom. About 1% of gas stations in the Southeast ran out of fuel for like a day.

By the standard you are applying almost everything can cost lives.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#196
post #66

Seems like they should invest more into cybersecurity, if someone was able to “steal” their Bitcoin and take over their infrastructure ;). But honestly, this only shows that IT systems are nowadays so complex that you cannot get them right and be able to truly protect you, no matter if you’re good or bad guy.

> like they should invest more into cybersecurity I would say invest more thought, less money. For example, use open source more. Minimize the amount of data and information you have that needs to be closed source. Avoid Windows. Use Gmail over Outlook. Have offline backups with sneakernet disaster planning. Get a cheap safety deposit box for storing keys. Use 2FA. There are lots of free/low cost ways to have better…

It’s not 2001 anymore. You can have both secure windows and Linux infrastructure.

Telling people to just use Linux as a remedy doesn’t help. If you don’t invest into securing your Windows infra, your Linux infra will be also full of holes.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#197
post #69

Earlier quoted context omitted.

I think the question is, how come an attack on a hospital does not have the optics of an attack on infrastructure? (It almost seems oil does not require infrastructure - you can, theoretically, prep for an oil infrastructure outage by storing it containers, same as you do with water and food. But you can't really prep for a medical infrastructure outage. Is it just that, as a result, there were no photos of people ho…

> I think the question is, how come an attack on a hospital does not have the optics of an attack on infrastructure? An attack on a hospital affects someone if they work there or are using that hospital. A pipeline attack affects people who drive cars places and need gas. The latter group is much larger than the former.

More apt comparison would be:

Hospital affects workers who work there and people using that hospital VS Pipeline affects workers who work there and people currently refilling their cars with gas from there

Or

Hospital affects workers who work there and everyone within a radius who could need it at any moment VS Pipeline affects works who work there and people who generally rely on that gas to drive

Suddenly the groups seems much similarly sized, while one being important for staying alive VS the other being a nice-to-have, if we consider it being offline for a week or two only.

I know which one I would consider being worse if I was a country. But then we're also talking about a country who's fascination for oil is like no other, so this is hardly surprising.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#198
post #148
post #45

It was a mistake to attack the business side of the oil company, because it created what could be sold as reasonable doubt to shut down the pipeline. As a result, the ransom had the optics of an attack on infrastructure. As evidenced by the coverage of Americans desperately filling up containers. This created the impetus for the US to treat this as an incident far and above the ambient ransomware activities leading u…

Russia allows their FSB operatives to moonlight on the side. Darkside hackers could be government operatives and an attack on critical infrastructure is an act of war. It is the same as bombing the pipeline if infrastructure is disabled. I am sure the cyber insurance provider won’t pay and say it was an act of war by a foreign government. It always a grey area.

Remember when Emotet was believed to be connected to Russia? Until January of this year, when it turned out it was actually Ukrainian.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#199
post #122
post #43

> The REvil representative said its program was introducing new restrictions on the kinds of organizations that affiliates could hold for ransom, and that henceforth it would be forbidden to attack those in the “social sector” (defined as healthcare and educational institutions) and organizations in the “gov-sector” (state) of any country. Affiliates also will be required to get approval before infecting victims. Sta…

> I do wonder if ransomware is (in a strange way) a(n illegal) free-market response to what is perceived to be an under-valuation of tech skills - aggrieved people who can carry out attacks and gain access to deploy ransomware are likely to be able to earn more through this route, even factoring in their "risk of being caught". Sure. In the same way the mugging people is a response to undervaluing “beating the crap o…

Its been said before:

"When the system fails you, you create your own system."

Which relates to what you're saying. When clever, intelligent people are ostracized and marginalized, they then use those skills to get illegally what society has prevented them from getting legally.

At some point, the idea of getting caught doesn't even register anymore.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#200

Earlier quoted context omitted.

> business side of the oil company What are the sides of any company other than "business"?

I think parent may mean infrastructure side. If it had just attacked the office side of things, it would be the usual 'company infected with ransomware' story without affecting the public.

My understanding is they did limit the attack to the office side:

> After Colonial Pipeline reported that its corporate computer networks were hit by the ransomware attack, the company shut down the pipeline as a precaution due to a concern that the hackers might have obtained information allowing them to carry out further attacks on vulnerable parts of the pipeline.

https://en.wikipedia.org/wiki/Colonial_Pipeline_cyberattack

Post reply on HN