Live data from Hacker News

DarkSide ransomware gang quits after servers, Bitcoin stash seized

krebsonsecurity.com

211–220 of 623 posts

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#211
post #148

Earlier quoted context omitted.

Russia allows their FSB operatives to moonlight on the side. Darkside hackers could be government operatives and an attack on critical infrastructure is an act of war. It is the same as bombing the pipeline if infrastructure is disabled. I am sure the cyber insurance provider won’t pay and say it was an act of war by a foreign government. It always a grey area.

Do you have any extraordinary evidence for these extraordinary claims?

It's not possible to bring "extraordinary" evidence of a 3 letter agency doing this kind of shit the way some HN user would want without ending up as a political prisoner somewhere learning all about the meaning of the word "pain". Never-the-less, I have no doubt that FSB operatives are allowed to moonlight.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#212
> The crime gang announced it was closing up shop after its servers were seized and someone drained the cryptocurrency from an account the group uses to pay affiliates.

If so, this is either:

1. one heckuva Mickey Mouse operation

2. a smokescreen

The statement never mentions Bitcoin, but let's assume that this is the "cryptocurrency" being referred to.

That Bitcoin private keys were being stored on a "server" strains credulity. There's very little reason to do so, and every reason not to.

Payments can be received and orders fulfilled by a server - without private keys. Multiple addresses can be watched in read-only mode.

The only reason for a server to hold private keys is if that server is capable of making automated payments, and that capability is a crucial part of the operation.

Bitcoin's history is littered with the corpses of people who messed up the management of their own cryptographic keys. Any reasonably competent operator would know about them and would never, under any circumstances hold private keys on a server.

Which leaves Option 2. Smokescreen. Make it look like all the loot was lost, try to throw investigators off the trail.

If so, it's a lame attempt.

One other possibility comes to mind. The ransom itself was the smokescreen.

The amount of the ransom was nothing for a company the size of Colonial. And it's about 1/10 of the annual salary of some developers. Why risk the prospect of life in prison for such as small payoff?

The reason is, of course, to make this operation look like something it's not. A Mickey Mouse band of idiots who can't manage their own private keys or servers. Lots of reasons to do this, starting with the notion that the attackers are trying to conceal their identities. And maybe that this was a test operation. Throw in the trinkets of ransom to make it look believable to the public.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#213
post #69
post #45

It was a mistake to attack the business side of the oil company, because it created what could be sold as reasonable doubt to shut down the pipeline. As a result, the ransom had the optics of an attack on infrastructure. As evidenced by the coverage of Americans desperately filling up containers. This created the impetus for the US to treat this as an incident far and above the ambient ransomware activities leading u…

I think the question is, how come an attack on a hospital does not have the optics of an attack on infrastructure? (It almost seems oil does not require infrastructure - you can, theoretically, prep for an oil infrastructure outage by storing it containers, same as you do with water and food. But you can't really prep for a medical infrastructure outage. Is it just that, as a result, there were no photos of people ho…

In addition to the other comments, there's a difference in scale here. Shutting down _a_ hospital would be like shutting down, say, several dozen gas stations in one part of a city. That would not have a lot of national visibility either. If they simultaneously shut down every hospital between Texas and New Jersey, it would have national optics.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#214

Earlier quoted context omitted.

Do you have any extraordinary evidence for these extraordinary claims?

Very few doubt that FSB and Russian mafia are one.

Even if it's true that very few doubt it, that doesn't mean it's true that they are.

See also: https://en.m.wikipedia.org/wiki/Argumentum_ad_populum

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#215
post #109

Earlier quoted context omitted.

I think the parent's point was that if oil infrastructure is completely disrupted, consumers won't even be affected for a few days and the short-term consequences will be somewhat minor (some percentage of drivers won't be able to drive, deliveries may be delayed). If a hospital is shut down, then people will start dying immediately. The consequences are much more direct and severe.

I think this is simplistic and overlooks logistics and flexibility. If a hospital closes, patients can be moved. If there's no gas, patients can't get to any hospital.

At least in the cities I've lived in, there tends to be a lot of internetworking in the local hospitals. If my local hospital, CRMC, were to be hit by ransomware or otherwise taken down it's likely that a good chunk of the city's health infra would be out or at least at risk too. Not to mention the damage an attacker could do to the data stored in an EHR system like Epic.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#216

Earlier quoted context omitted.

> I think the question is, how come an attack on a hospital does not have the optics of an attack on infrastructure? An attack on a hospital affects someone if they work there or are using that hospital. A pipeline attack affects people who drive cars places and need gas. The latter group is much larger than the former.

More apt comparison would be: Hospital affects workers who work there and people using that hospital VS Pipeline affects workers who work there and people currently refilling their cars with gas from there Or Hospital affects workers who work there and everyone within a radius who could need it at any moment VS Pipeline affects works who work there and people who generally rely on that gas to drive Suddenly the group…

Sure it's "nice to have" unless it does go on longer and suddenly nobody can get to the stores to buy food and the stores don't have any food to sell because the trucks that deliver it can't get fuel.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#217

The way the article talks about these cybercrime gangs makes them sound like a benevolent government or non profit. They're putting up restrictions? Gang representatives are talking to the press? What kind of world is this?

The idea is to narrow who's going to chase after you, based on how you're perceived in terms of being a threat.

They want a certain type of police/authority chasing them for financial crimes, not special forces cutting their throats in the middle of the night because they're perceived to be terrorists attacking a superpower's critical infrastructure and trying to harm large numbers of people.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#218
post #49

If this is the US taking action, they should go after distributed denial of secrets next ( https://en.m.wikipedia.org/wiki/Distributed_Denial_of_Secret... ). This group is doxxing people for their donations, which isn’t “hacktivism” - it’s just a criminal breach of privacy. Crime doesn’t become a non-crime just because it is left-biased. Enough with the unchecked rise of cyber crimes.

So they have a public representative living in the US and are associated with Harvard University. I don‘t think there‘s much shadowy cybercrime to investigate there. How do you feel about Wikileaks and the prosecution of Julian Assange?

Having a "Harvard affiliation" doesn't legitimize illegal activities. Leaking private messages, passwords, and so on from social networks is an unacceptable breach of privacy. Exposing people's private donations is also unacceptable. This is a group looking to create a chilling effect on others' speech, particularly moderates and conservatives, through illegal cyber crimes. I am not sure how you can possibly see that as anything other than "shadowy cyberycrime" given their identities are anonymous and they're committing cyber crimes.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#219
post #148

Earlier quoted context omitted.

Russia allows their FSB operatives to moonlight on the side. Darkside hackers could be government operatives and an attack on critical infrastructure is an act of war. It is the same as bombing the pipeline if infrastructure is disabled. I am sure the cyber insurance provider won’t pay and say it was an act of war by a foreign government. It always a grey area.

Do you have any extraordinary evidence for these extraordinary claims?

The entirety of the Cold War between the USA and USSR?

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#220
> “There’s too much publicity,” the XSS administrator explained. “Ransomware has gathered a critical mass of nonsense, bullshit, hype, and fuss around it. The word ‘ransomware’ has been put on a par with a number of unpleasant phenomena, such as geopolitical tensions, extortion, and government-backed hacks. This word has become dangerous and toxic.”

You've finally figured out that extortion is bad, well done.

Post reply on HN