Live data from Hacker News

DarkSide ransomware gang quits after servers, Bitcoin stash seized

krebsonsecurity.com

251–260 of 623 posts

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#251
post #43

> The REvil representative said its program was introducing new restrictions on the kinds of organizations that affiliates could hold for ransom, and that henceforth it would be forbidden to attack those in the “social sector” (defined as healthcare and educational institutions) and organizations in the “gov-sector” (state) of any country. Affiliates also will be required to get approval before infecting victims. Sta…

I think you're on to something in the context of globalization. There are many incredibly talented tech workers globally who can't get paid what they're worth because they lack access to employment with the wealthiest employers (because of strict border policies and the lack of visa sponsorship). If they had the freedom to migrate, then they might choose to seek employment in another country with a supply shortage, rather than enter the black market.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#253

Statements like "money of advertisers and founders was transferred to an unknown account" don't make sense to me. Why is the money held on a server at all? Surely it's more secure to keep wallets receiving money locally on a laptop or in a paper wallet, no? Why would they put the gold in the munitions depot if they don't have to?

I'm seeing statements about the payments server and the money associated with the payments server, but (at the risk of using an analogy) it seems like they've lost their "petty cash" box, not their main account. Surely they were wise enough to only put a small amount of money in the payments server. The bulk of their cash would be in a separate account (which wasn't lost).

Oh well then I take it these guys will be back in some form or another in the coming weeks. With enough cash and time they can replace their seized infrastructure without too much effort. Probably with a non-American target next time. I don't understand why so many hackers target America when the USA has the strongest offensive cyber capabilities of any nation on earth. Surely there is less blowback from hacking an Argentinian pipeline.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#254
post #45

It was a mistake to attack the business side of the oil company, because it created what could be sold as reasonable doubt to shut down the pipeline. As a result, the ransom had the optics of an attack on infrastructure. As evidenced by the coverage of Americans desperately filling up containers. This created the impetus for the US to treat this as an incident far and above the ambient ransomware activities leading u…

The fact that their coins were apparently easily stolen also debunks another favourite talking point of the crypto people that it secures your money from government access. Clearly, ways and means have been developed to do just that if necessary.

Or one of the members of the criminal gang ran off with all the cryptocurrency and then made a public post claiming some form of law enforcement seized the crypto.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#255

Earlier quoted context omitted.

The fact that their coins were apparently easily stolen also debunks another favourite talking point of the crypto people that it secures your money from government access. Clearly, ways and means have been developed to do just that if necessary.

If you store your coins on a hard drive there's nothing the government can do to get them right? They would need your private key and your hard drive?

If you anger a sufficiently powerful nation-state, you should assume all options are on the table for recovering you, your hard drives, and your keys.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#256
post #212

> The crime gang announced it was closing up shop after its servers were seized and someone drained the cryptocurrency from an account the group uses to pay affiliates. If so, this is either: 1. one heckuva Mickey Mouse operation 2. a smokescreen The statement never mentions Bitcoin, but let's assume that this is the "cryptocurrency" being referred to. That Bitcoin private keys were being stored on a "server" strains…

$5 million is 1/10 the annual salary of some developers?

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#257
post #183

Earlier quoted context omitted.

Well, sometimes they're right. The hit company will likely call in some consultancy to institute a bunch of newer and better security protocols, then call it a day. If they really aren't hit again for another decade and staffing a department would cost $500k a year or more, were they wrong? It's a gamble. It's easy to point fingers at the company that was caught out, but for the hundreds or thousands that aren't rans…

They paid $5 million, if "it was cheaper for them," that's solid math that ignores some really important stuff though, LOL. What is the externalized cost of this crisis on the entire country? The $5 million dollar ransom is a worse deal if you can convince your board to consider that externality. The criminal penalties for executives in leadership and board positions (and I'm not saying this is my preferred approach)…

Which is also why they need a $15-50 million dollar fine on top this

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#258
post #204
post #45

It was a mistake to attack the business side of the oil company, because it created what could be sold as reasonable doubt to shut down the pipeline. As a result, the ransom had the optics of an attack on infrastructure. As evidenced by the coverage of Americans desperately filling up containers. This created the impetus for the US to treat this as an incident far and above the ambient ransomware activities leading u…

It was a mistake to attack overtly . I believe $5 million can be easily drained covertly and inconspicuously from megacorporations. I'm pretty sure it's actually happening we just don't hear about it.

It didn't work in Office Space.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#259
post #45

It was a mistake to attack the business side of the oil company, because it created what could be sold as reasonable doubt to shut down the pipeline. As a result, the ransom had the optics of an attack on infrastructure. As evidenced by the coverage of Americans desperately filling up containers. This created the impetus for the US to treat this as an incident far and above the ambient ransomware activities leading u…

I got downvoted for saying that maybe it's time to treat serious ransomware attacks (infrastructure, security, health, etc.) as terrorism - as in the sense that they're a threat to the national security. But this kinda shows the response I was referencing to. A lot of people like to think of ransomware attacks as the ultimate stress test as far as security goes, and thus a good thing - but let's not get too blinded b…

Maybe people didn't like your use of the term "terrorism" for national security threats?

A common understanding is that terrorism is intended to frighten people or make them feel unsafe, while various official definitions of terrorism include the idea that it's intended to coercively achieve some particular political goal.

If attackers just intend to get money, they're probably well-described as extortionists (or in some cases, as you said, akin to pirates). If they just intend to damage a particular society without demanding anything from it or getting it to change its behavior, they might be saboteurs.

Attacks with these motives or that pretend to have these motives could still be considered national security threats (and taken very seriously), but maybe shouldn't be described specifically as terrorism.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#260

Earlier quoted context omitted.

Well, if it's more expensive to prevent the attack than to pay the ransom, what's the point? ;)

I know you're saying this in jest, but that's the calculus. The outcome here shows that executives made the right call. The $5MM fee was easily paid, less than the costs of security, and the insurance company will probably cover it anyway. And the government/people were so outraged that the attackers were met with fucking swift justice. The company will probably get some grants or something to cover the cost of "secu…

Which is why the company needs a significant fine for failing to secure infrastructure.
Post reply on HN