Live data from Hacker News

DarkSide ransomware gang quits after servers, Bitcoin stash seized

krebsonsecurity.com

231–240 of 623 posts

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#231
post #15

Can crypto actually be non-traceable? I remember currencies like Monero or ZCash advertising privacy from the last crypto craze. I mean if you have 100M in some account, can you actually run it trough "private" currencies to remove traces? BTC, ETH etc. all seems super traceable, even more so than in regular banking. Also how are criminals getting their money out with no one noticing, does Panama/Malta etc. have Krak…

You dont do it that way. Just drop it in Tornado.cash and a few days later withdraw to a virgin crypto address. The virgin crypto address just pumps a token that you bought in another clean address with clean money prior.

You sell the token in the clean address at a massive profit and cash out under your real name and ID and even pay taxes.

Go look at any highly pumped token on Uniswap/Sushiswap/Pancakeswap and you’ll find plenty of addresses that either bought or added to the liquidity pool using funds that begin with Tornado.cash, there is no way to distinguish the nature of the transaction from simple observation. All blockchain technology is heading to parity with the privacy afforded by traditional banking, without the financial intermediary to question anything for the state.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#232
post #45

It was a mistake to attack the business side of the oil company, because it created what could be sold as reasonable doubt to shut down the pipeline. As a result, the ransom had the optics of an attack on infrastructure. As evidenced by the coverage of Americans desperately filling up containers. This created the impetus for the US to treat this as an incident far and above the ambient ransomware activities leading u…

>It also gave the US an opportunity to show how effective it could be when it had the political cover to do so. Not sure what you mean, what did the US do exactly?

These guys retweeted the story. They didn’t claim responsibility but it’s a tacit acknowledgment of their involvement. https://en.m.wikipedia.org/wiki/780th_Military_Intelligence_...

https://mobile.twitter.com/TheRecord_Media/status/1393192862...

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#233
post #43

> The REvil representative said its program was introducing new restrictions on the kinds of organizations that affiliates could hold for ransom, and that henceforth it would be forbidden to attack those in the “social sector” (defined as healthcare and educational institutions) and organizations in the “gov-sector” (state) of any country. Affiliates also will be required to get approval before infecting victims. Sta…

> ransomware activities being far more coordinated and "business-like" than they often get credit for.

This is the "organized" in organized crime. It's not lone bored teenagers doing this stuff.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#234
post #204
post #45

It was a mistake to attack the business side of the oil company, because it created what could be sold as reasonable doubt to shut down the pipeline. As a result, the ransom had the optics of an attack on infrastructure. As evidenced by the coverage of Americans desperately filling up containers. This created the impetus for the US to treat this as an incident far and above the ambient ransomware activities leading u…

It was a mistake to attack overtly . I believe $5 million can be easily drained covertly and inconspicuously from megacorporations. I'm pretty sure it's actually happening we just don't hear about it.

There’s a huge network of financial controls to prevent and detect this sort of thing, it’s one of the foundations of the fields of accounting. Often there are departments looking for fraud regularly.

I suspect small or medium organizations rather then megacorps would be easier targets if they haven’t invested money in accounting controls.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#235

Earlier quoted context omitted.

> I think the question is, how come an attack on a hospital does not have the optics of an attack on infrastructure? An attack on a hospital affects someone if they work there or are using that hospital. A pipeline attack affects people who drive cars places and need gas. The latter group is much larger than the former.

More apt comparison would be: Hospital affects workers who work there and people using that hospital VS Pipeline affects workers who work there and people currently refilling their cars with gas from there Or Hospital affects workers who work there and everyone within a radius who could need it at any moment VS Pipeline affects works who work there and people who generally rely on that gas to drive Suddenly the group…

I mean, the pipeline in question provides half of the gas to the US East coast. You don’t have to love oil to see that losing 40% of the supply to more than 100m people overnight would be a public safety (what if emergency vehicles can’t buy fuel?) and economic risk.

The number of people reliant on this pipeline is several orders of magnitude greater than would be impacted by taking a single hospital offline. You’d need to have many hospitals impacted to create a similar level of risk. The only big difference is that taking out hospital infrastructure can kill people immediately whereas the impact of a pipeline failure won’t generally be felt for days or weeks.

Edit: Based on your other response it sounds like we are on the same page.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#237

Earlier quoted context omitted.

> business side of the oil company What are the sides of any company other than "business"?

I think parent may mean infrastructure side. If it had just attacked the office side of things, it would be the usual 'company infected with ransomware' story without affecting the public.

The truly cynical take is that they managed to take down Colonial's billing. In response, Colonial shut down the pipeline - because obviously delivering oil without getting paid is out of the question.

Yes, it's guesswork and pretty extreme conjecture but it has just the right amount of coldheartedness to it: https://zetter.substack.com/p/biden-declares-state-of-emerge...

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#238

Earlier quoted context omitted.

More apt comparison would be: Hospital affects workers who work there and people using that hospital VS Pipeline affects workers who work there and people currently refilling their cars with gas from there Or Hospital affects workers who work there and everyone within a radius who could need it at any moment VS Pipeline affects works who work there and people who generally rely on that gas to drive Suddenly the group…

I mean, the pipeline in question provides half of the gas to the US East coast. You don’t have to love oil to see that losing 40% of the supply to more than 100m people overnight would be a public safety (what if emergency vehicles can’t buy fuel?) and economic risk. The number of people reliant on this pipeline is several orders of magnitude greater than would be impacted by taking a single hospital offline. You’d n…

Yeah, I understand this and agree with you. Compare one of the biggest oil pipelines in the country with one hospital, of course one will be worse than the other.

But if you instead compare 40% of the hospitals going offline VS 40% loosing access to gas, with similar conditions, I think the mortality will be higher by attacking hospitals. I think the government could probably somehow logistically ration oil if shit really hits the pan too, so essentials can keep running. Probably worse situation with hospitals, even though the military could probably help out there a bit.

That's why it's weird to not react when people are attacking hospitals, vs oil pipelines. But as said before in my other comment, maybe not too weird.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#239

Why should I believe this? They can shut down their servers, move their crypto to different wallets, and pop up again in a few weeks, right?

Depends if the DOJ issues arrest warrants for the members in a couple weeks.

Since they aren't in the US, it is probably more of a proactive step by the DOJ to build a case for sanctions. Assuming they know what country the perps are from, which doesn't seem all that clear.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#240

Why should I believe this? They can shut down their servers, move their crypto to different wallets, and pop up again in a few weeks, right?

Agreed, except why bother pop up again? They just got a big fat payment of $5m. Plenty to split with a small team. It's a good time to cash out and disappear.

Seriously! It's FIVE MILLION. That's "I don't ever have to work again" money. What is wrong with people! Probably they want Mercedes, and Rolexes, and Mont Blanc pens and all that showy consumer garbage.
Post reply on HN