Live data from Hacker News

DarkSide ransomware gang quits after servers, Bitcoin stash seized

krebsonsecurity.com

241–250 of 623 posts

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#241

Earlier quoted context omitted.

Do you have any extraordinary evidence for these extraordinary claims?

It's not possible to bring "extraordinary" evidence of a 3 letter agency doing this kind of shit the way some HN user would want without ending up as a political prisoner somewhere learning all about the meaning of the word "pain". Never-the-less, I have no doubt that FSB operatives are allowed to moonlight.

The United States Department of Justice has not exactly been shy about charging operatives of foreign governments for their illegal activities online (e.g. OlympicDestroyer, Solarigate). As far as I've been able to determine, neither their prosecutors nor the FBI agents doing the investigating have had the problems you so colorfully describe. If it were the case that this type of moonlighting was happening, I think the FBI would have been bringing cases to court. That would constitute evidence.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#243
post #109

Earlier quoted context omitted.

I think the parent's point was that if oil infrastructure is completely disrupted, consumers won't even be affected for a few days and the short-term consequences will be somewhat minor (some percentage of drivers won't be able to drive, deliveries may be delayed). If a hospital is shut down, then people will start dying immediately. The consequences are much more direct and severe.

I think this is simplistic and overlooks logistics and flexibility. If a hospital closes, patients can be moved. If there's no gas, patients can't get to any hospital.

What if you attack the hospital in the middle of, lets say a covid outbreak, where no excess capacity is available. Now you've likely caused a significant number of deaths.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#244
post #55
post #43

> The REvil representative said its program was introducing new restrictions on the kinds of organizations that affiliates could hold for ransom, and that henceforth it would be forbidden to attack those in the “social sector” (defined as healthcare and educational institutions) and organizations in the “gov-sector” (state) of any country. Affiliates also will be required to get approval before infecting victims. Sta…

When I heard that this pipeline company started advertising a job opening for CyberSecurity Advisor in the last few days, and heard today the ransom of about $5 million was paid, my first reaction was to say "I bet the salary for that position is a lot less than $5 million, and I bet the budget for that department will be less, too..."

The cost of shutting down this pipeline for a week is a lot more than 5 million. At 3 million barrels per day going through it, in 6 days that's 18 million barrels. At $65/barrel that's 195 million worth of oil that didn't transit and it probably has huge knock-on effects throughout the affected regions (things that didn't ship, trips not taken, etc).

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#245
post #45

It was a mistake to attack the business side of the oil company, because it created what could be sold as reasonable doubt to shut down the pipeline. As a result, the ransom had the optics of an attack on infrastructure. As evidenced by the coverage of Americans desperately filling up containers. This created the impetus for the US to treat this as an incident far and above the ambient ransomware activities leading u…

The fact that their coins were apparently easily stolen also debunks another favourite talking point of the crypto people that it secures your money from government access. Clearly, ways and means have been developed to do just that if necessary.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#246

Earlier quoted context omitted.

Do you have any extraordinary evidence for these extraordinary claims?

The entirety of the Cold War between the USA and USSR?

There's plenty of evidence that the USSR engaged in espionage activities. There's plenty of evidence that the Russian Federation has engaged in the same thing. Neither of those is what is being alleged here.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#247
post #227

Earlier quoted context omitted.

There is basically a zero percent chance that the US knew where they were physically. The servers that were claimed to be seized were on cloud platforms. And even then, we don't know if this is true or if it's just an exit strategy.

It's easy to say "basically zero chance" when we're armchair quarterbacks and not the ones in the hot seat. I'm inclined to agree that our cyber-security apparatus is not up to the task, but it's also true that nobody has perfect OpSec, (and I'd guess there are few out there have deeper pockets to track down and make sure the perpetrators regret this, than the combination of US government + oil companies.)

> nobody has perfect OpSec

Yep. Compromised people on the inside, informants, "intensive interrogation" etc. are more likely the way, as has always been the case.

Also the agencies that would know who these people are would not want to reveal what they know in order to save random XYZ Corp's bacon. With this being seen as a "critical infrastructure" attack and something closer to an act of war/terrorism, the stakes got higher.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#248
post #45

It was a mistake to attack the business side of the oil company, because it created what could be sold as reasonable doubt to shut down the pipeline. As a result, the ransom had the optics of an attack on infrastructure. As evidenced by the coverage of Americans desperately filling up containers. This created the impetus for the US to treat this as an incident far and above the ambient ransomware activities leading u…

The fact that their coins were apparently easily stolen also debunks another favourite talking point of the crypto people that it secures your money from government access. Clearly, ways and means have been developed to do just that if necessary.

If you store your coins on a hard drive there's nothing the government can do to get them right? They would need your private key and your hard drive?

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#249
post #49

Earlier quoted context omitted.

So they have a public representative living in the US and are associated with Harvard University. I don‘t think there‘s much shadowy cybercrime to investigate there. How do you feel about Wikileaks and the prosecution of Julian Assange?

Having a "Harvard affiliation" doesn't legitimize illegal activities. Leaking private messages, passwords, and so on from social networks is an unacceptable breach of privacy. Exposing people's private donations is also unacceptable. This is a group looking to create a chilling effect on others' speech, particularly moderates and conservatives, through illegal cyber crimes. I am not sure how you can possibly see that…

As far as I can tell from wikipedia they are not anonymous (at least the leader) and not working in the shadows (bc they are working together with serious public organizations).

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#250

I'm interested to understand the psychology of ransomware types who go after these enormous and important targets. That includes the pipeline, which obviously claimed at least a few lives of its own via people not being able to drive to get medical care, etc. Are they armchair criminal masterminds who don't really have a visceral understanding of how much damage they're doing? Or just straight up psychopaths? I can't…

They've learned from this, from the article: "The REvil representative said its program was introducing new restrictions on the kinds of organizations that affiliates could hold for ransom, and that henceforth it would be forbidden to attack those in the “social sector” (defined as healthcare and educational institutions) and organizations in the “gov-sector” (state) of any country. Affiliates also will be required t…

Well, maybe they learned they did the wrong thing. Other reasons seem plausible: maybe they just thought it would make them look better if they're caught. Maybe they wanted to look better to their clients/allies who are currently like "whoa Nelly, these guys are basically Gus Fring. Maybe we'll work with someone a little less evil."

I don't know nearly enough to guess, but it doesn't seem cut-and-dried to me that this is a case of them realizing what they did was wrong.

In any case, the same question still applies for what happened before: why were they in a psychological state that made them try this in the first place?

Even if we grant that they've changed their tune for moral reasons, that would rule out straight psychopaths, but would include people who had severe antisocial traits but still started to have some feelings about it once they saw the real-life consequences. We see this with repentant murderers.

As far as rich businessmen who do evil stuff, there's a literature on that, and it seems to be a complicated mix. There's "just filling my role" (for those not at the very top of their organizations), thinking you'd be replaced by someone else doing the same thing, dissociation/denial about what you're doing, and -- yeah -- straight up antisocial/psychopath types. And more. It's a fascinating topic.

Post reply on HN