Live data from Hacker News

DarkSide ransomware gang quits after servers, Bitcoin stash seized

krebsonsecurity.com

221–230 of 623 posts

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#221
post #212

> The crime gang announced it was closing up shop after its servers were seized and someone drained the cryptocurrency from an account the group uses to pay affiliates. If so, this is either: 1. one heckuva Mickey Mouse operation 2. a smokescreen The statement never mentions Bitcoin, but let's assume that this is the "cryptocurrency" being referred to. That Bitcoin private keys were being stored on a "server" strains…

Ironically, it plays off of ignorance in either option.

The DOJ could bolster credibility of itself to the ignorant by saying “thats right criminals you cant hide” even if the DOJ never got anything.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#222

Earlier quoted context omitted.

> “We are apolitical, we do not participate in geopolitics, do not need to tie us with a defined government and look for other our motives [sic],” reads an update to the DarkSide Leaks blog. “Our goal is to make money, and not creating problems for society. From today we introduce moderation and check each company that our partners want to encrypt to avoid social consequences in the future.”[1] [1] https://krebsonsec…

Sounds like they're about to get rolled up by law enforcement as well. As someone who's had the full force of a three letter agency come down on me, this is not something you want to deal with on any level. I was lucky. I was young and dumb and got a slap on the wrist. Times have changed and when govt agencies see this as an attack on critical infrastructure, you're looking at some serious jail time. I would say its…

Thanks for sharing your experience. Not to dig too deep into details, but what would you say your primary motivation was in your 'young and dumb' days? Were you curious about it, was it a statement, was there an allure?

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#223

Statements like "money of advertisers and founders was transferred to an unknown account" don't make sense to me. Why is the money held on a server at all? Surely it's more secure to keep wallets receiving money locally on a laptop or in a paper wallet, no? Why would they put the gold in the munitions depot if they don't have to?

I'm seeing statements about the payments server and the money associated with the payments server, but (at the risk of using an analogy) it seems like they've lost their "petty cash" box, not their main account. Surely they were wise enough to only put a small amount of money in the payments server. The bulk of their cash would be in a separate account (which wasn't lost).

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#224

Earlier quoted context omitted.

I can’t decide if it’s worse to imply that Russians can’t learn English or to think that the anglosphere only exists in North America.

I am just saying that it is idiomatic North American English. I, for instance, could not write in idiomatic British English if I tried. For instance, your use of "state" in your username and "anglosphere" in your one sentence strongly hints to me that your English is not purely North American. (I see your profile, too.) The vast majority of Americans would use different terms.

Looking only at the parts quoted in krebs’s post, it doesn’t really stick out to me as either American or British English. They use double quotation marks, for example - American - but leave the trailing comma outside, which is British.

Other than that, there are no giveaway spellings or idioms. It could just as easily be someone whose exposure to English is dominated by technical documentation, which tends to use mostly American style.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#225
post #151

Earlier quoted context omitted.

You don't need to. You can send the ETH to tornado.cash. Their anonymity set is such that 100 million would take a long time, but on the order of months to withdraw. Tornado.cash has millions in total locked value in different ETH denominated pools.

Yeah I guess, as long as ETH stays around the current level. But if you do hundreds of withdrawals from tornado, it's less anonymous, because the set of people that have deposited that range to tornado is much smaller than the set of people who did a handful of deposits. Instead of 10k, you might be one of a few dozen or less. You could always send a million to a friend (through tornado) and have them cash out for a…

The fact that everyone's first answer when prompted "how do we wind down this huge pile of cryptocurrency?" is convert it to fiat makes me skeptical on all the long-term ambitions from promoters.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#226
post #90
post #77

Earlier quoted context omitted.

I think you're spot-on here - the ransom is seen as a "cost of doing business", and until recently security was seen as "a problem that happens to other people". Sadly my experience is that organisations like this will take their $5m ransom (or other remediation cost), assume it's a one-off, then divide it by their number of ransom-free years, and proclaim it was better value for money than hiring 2 or 3 senior secur…

Even better, they will take the cost of their Insurance Deductible, and then do those calculations. Most businesses have insurance for this stuff.

[deleted]

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#227
post #143

Earlier quoted context omitted.

I imagine it went something like this "OK, now that you have our attention, and the eyes of the entire international media apparatus are on us, here's how we're going to do this. We're going to send some integer number of million money dollars down this pipe, and you're going to turn that gas pipe back on like you said you would. Then here's what happens next... we're going to give you an integer number of minutes ru…

There is basically a zero percent chance that the US knew where they were physically. The servers that were claimed to be seized were on cloud platforms. And even then, we don't know if this is true or if it's just an exit strategy.

It's easy to say "basically zero chance" when we're armchair quarterbacks and not the ones in the hot seat.

I'm inclined to agree that our cyber-security apparatus is not up to the task, but it's also true that nobody has perfect OpSec, (and I'd guess there are few out there have deeper pockets to track down and make sure the perpetrators regret this, than the combination of US government + oil companies.)

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#228
post #69
post #45

It was a mistake to attack the business side of the oil company, because it created what could be sold as reasonable doubt to shut down the pipeline. As a result, the ransom had the optics of an attack on infrastructure. As evidenced by the coverage of Americans desperately filling up containers. This created the impetus for the US to treat this as an incident far and above the ambient ransomware activities leading u…

I think the question is, how come an attack on a hospital does not have the optics of an attack on infrastructure? (It almost seems oil does not require infrastructure - you can, theoretically, prep for an oil infrastructure outage by storing it containers, same as you do with water and food. But you can't really prep for a medical infrastructure outage. Is it just that, as a result, there were no photos of people ho…

Hospitals themselves aren't really "infrastructure." All hospitals can operate independently from each other, so holding one for ransom only affects the one. If you can actually shut down a pipeline, you affect everywhere it ships to.

Hospitals obviously do rely on infrastructure, so you'd see much more panic if someone could disrupt a national supply of blood plasma or insulin or something.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#229
post #204
post #45

It was a mistake to attack the business side of the oil company, because it created what could be sold as reasonable doubt to shut down the pipeline. As a result, the ransom had the optics of an attack on infrastructure. As evidenced by the coverage of Americans desperately filling up containers. This created the impetus for the US to treat this as an incident far and above the ambient ransomware activities leading u…

It was a mistake to attack overtly . I believe $5 million can be easily drained covertly and inconspicuously from megacorporations. I'm pretty sure it's actually happening we just don't hear about it.

I don’t think the criminals wanted it overt. They weren’t expecting the pipeline to be shut down which is what made everything public.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#230

Earlier quoted context omitted.

More apt comparison would be: Hospital affects workers who work there and people using that hospital VS Pipeline affects workers who work there and people currently refilling their cars with gas from there Or Hospital affects workers who work there and everyone within a radius who could need it at any moment VS Pipeline affects works who work there and people who generally rely on that gas to drive Suddenly the group…

Sure it's "nice to have" unless it does go on longer and suddenly nobody can get to the stores to buy food and the stores don't have any food to sell because the trucks that deliver it can't get fuel.

Thanks for expanding, that was exactly what I meant. Ok for smaller duration, while a hospital without functioning equipment is almost useless (compared to it's original status) immediately.
Post reply on HN