Live data from Hacker News

DarkSide ransomware gang quits after servers, Bitcoin stash seized

krebsonsecurity.com

281–290 of 623 posts

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#281
post #151

Earlier quoted context omitted.

Yeah I guess, as long as ETH stays around the current level. But if you do hundreds of withdrawals from tornado, it's less anonymous, because the set of people that have deposited that range to tornado is much smaller than the set of people who did a handful of deposits. Instead of 10k, you might be one of a few dozen or less. You could always send a million to a friend (through tornado) and have them cash out for a…

The fact that everyone's first answer when prompted "how do we wind down this huge pile of cryptocurrency?" is convert it to fiat makes me skeptical on all the long-term ambitions from promoters.

Well you could take the ETH and stake in the beaconchain and get 8% more ETH per year (depending on staking rates). Or you could use the ETH to get a loan in DAI on Compound or Maker. Or you cn buy synthetic assets like stocks on Synthetix. Plenty of things to do in the Ethereum ecosystem.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#282

Earlier quoted context omitted.

Agreed, except why bother pop up again? They just got a big fat payment of $5m. Plenty to split with a small team. It's a good time to cash out and disappear.

Seriously! It's FIVE MILLION. That's "I don't ever have to work again" money. What is wrong with people! Probably they want Mercedes, and Rolexes, and Mont Blanc pens and all that showy consumer garbage.

The median lifetime earnings in the US is 1.7 million, and that’s equivalent to... $20 an hour or so. 5 million is “never work again” money for a couple of people who want middle class incomes the rest of their lives... it is not really that much when spread over more than a few people.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#283
post #148

Earlier quoted context omitted.

Russia allows their FSB operatives to moonlight on the side. Darkside hackers could be government operatives and an attack on critical infrastructure is an act of war. It is the same as bombing the pipeline if infrastructure is disabled. I am sure the cyber insurance provider won’t pay and say it was an act of war by a foreign government. It always a grey area.

Do you have any extraordinary evidence for these extraordinary claims?

It's pretty clear that the Russian Gov is not actively prosecuting cyber criminals, provided they attack foreign competition. On top of that, there is a fair amount of forensic data indicating shared resources between hacker groups and GRU operatives.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#284
post #256

Earlier quoted context omitted.

$5 million is 1/10 the annual salary of some developers?

I could see 10 developers costing that much

$500,000 salary? Let me know where these jobs are because I'd like to submit my resume.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#285
post #183

Earlier quoted context omitted.

Well, sometimes they're right. The hit company will likely call in some consultancy to institute a bunch of newer and better security protocols, then call it a day. If they really aren't hit again for another decade and staffing a department would cost $500k a year or more, were they wrong? It's a gamble. It's easy to point fingers at the company that was caught out, but for the hundreds or thousands that aren't rans…

They paid $5 million, if "it was cheaper for them," that's solid math that ignores some really important stuff though, LOL. What is the externalized cost of this crisis on the entire country? The $5 million dollar ransom is a worse deal if you can convince your board to consider that externality. The criminal penalties for executives in leadership and board positions (and I'm not saying this is my preferred approach)…

> What is the externalized cost of this crisis on the entire country?

If a business externalizes the cost, does it matter to them?

Civil penalties levied by regulators will drive the change that matters.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#286

Why should I believe this? They can shut down their servers, move their crypto to different wallets, and pop up again in a few weeks, right?

They know that they can and will be found, and are running scared. In general ransomware works because it takes a lot of resources to find the criminals behind it. And generally there's not enough resources to do this. But once it hits a level where it creates a widespread national problem, it becomes more of an act of war. Then you get people involved that aren't just law enforcement and have tools that aren't avail…

Not to mention diplomatic channels to apply pressure on local governments that may have previously lacked the impetus to do anything about these groups.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#287
post #262

> “There’s too much publicity,” the XSS administrator explained. “Ransomware has gathered a critical mass of nonsense, bullshit, hype, and fuss around it. The word ‘ransomware’ has been put on a par with a number of unpleasant phenomena, such as geopolitical tensions, extortion, and government-backed hacks. This word has become dangerous and toxic.” I am... flabbergasted. What? Ransomware has always been a brand of e…

I'm interpreting the statement to mean that ransomware very rapidly lost its reputation as a nuisance-crime this week.

Misplaced ransomware runs a far more substantial risk of triggering enforcement action now. Or at least that's the perception I'm deriving from the quote.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#288
post #237

Earlier quoted context omitted.

I think parent may mean infrastructure side. If it had just attacked the office side of things, it would be the usual 'company infected with ransomware' story without affecting the public.

The truly cynical take is that they managed to take down Colonial's billing . In response, Colonial shut down the pipeline - because obviously delivering oil without getting paid is out of the question. Yes, it's guesswork and pretty extreme conjecture but it has just the right amount of coldheartedness to it: https://zetter.substack.com/p/biden-declares-state-of-emerge...

The Colonial Pipeline Is Finally Back Online and Pumping Gas https://www.thedrive.com/news/40583/the-colonial-pipeline-is...

> New details from within Colonial Pipeline have come to light surrounding the decision to shut off supply. Those briefed on the matter have suggested that fuel flows were shut down due to the company's billing system being compromised. Company officials were reportedly concerned that they would not be able to accurately bill customers for fuel delivered, and chose to stop delivery instead.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#289

Earlier quoted context omitted.

Seriously! It's FIVE MILLION. That's "I don't ever have to work again" money. What is wrong with people! Probably they want Mercedes, and Rolexes, and Mont Blanc pens and all that showy consumer garbage.

The median lifetime earnings in the US is 1.7 million, and that’s equivalent to... $20 an hour or so. 5 million is “never work again” money for a couple of people who want middle class incomes the rest of their lives... it is not really that much when spread over more than a few people.

Darkside is likely based in Russia, where lifetime median earnings are much lower.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#290
post #266

Earlier quoted context omitted.

I got downvoted for saying that maybe it's time to treat serious ransomware attacks (infrastructure, security, health, etc.) as terrorism - as in the sense that they're a threat to the national security. But this kinda shows the response I was referencing to. A lot of people like to think of ransomware attacks as the ultimate stress test as far as security goes, and thus a good thing - but let's not get too blinded b…

Terrorism is a non-state use of violence for political aims. Ransomware is non-state, not violent, and is done for economic, not political aims.

> non-state > economic, not political

There’s a well known phenonenom of a certain large nation harbouring cybercrime gangs and keeping them on the government leash. Their economic activity benefits the governments political agenda. Ergo all conditions are true.

Post reply on HN