Live data from Hacker News

DarkSide ransomware gang quits after servers, Bitcoin stash seized

krebsonsecurity.com

361–370 of 623 posts

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#361
post #2

Feels like a nation-state response. US Cyber Command? Either way, a chilling warning to organized hacking groups.

Yes. I doubt any other organization has the capabilities to break Tor anonymity. They don't want to reveal their hand so you will only see their tools used in extreme circumstances. At most we will get some official parallel construction nonsense.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#362

Earlier quoted context omitted.

The fact that their coins were apparently easily stolen also debunks another favourite talking point of the crypto people that it secures your money from government access. Clearly, ways and means have been developed to do just that if necessary.

Or one of the members of the criminal gang ran off with all the cryptocurrency and then made a public post claiming some form of law enforcement seized the crypto.

They seem to be trying to operate under new rules.

That's not what you do if you just stole everyone's money / should run...

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#363

Earlier quoted context omitted.

For me it was about making a statement. I had gotten into an argument with a professor on a discussion board. He used derogatory terms to refer to me, which pissed me off. I sent him a virus that was supposed to just damage files and delete some random files. It turns out it propagated onto their main network and crashed the entire universities network. Suddenly, you feel untouchable (even though the virus had gotten…

> It turns out it propagated onto their main network > the virus had gotten out of control, which I didn't mean it to do This isn't just a whoops, how do you "accidentally" create a virus that leaves the boundaries of the computer and traverses their network?

Already-mounted SMB?

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#364
Once I had the fortune of seeing the three cups and a ball scam live, on the street. One guy does the trick, another encourages the victim, and a third one watches the crowd disguised as a random onlooker. If something makes the onlooker nervous, he will signal the others and they will grab their things and disappear in less seconds than your hand has fingers.

This sudden quit seems similar, specially with the withdrawal of funds to an "unknown address", as if they closed shop and disappeared.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#365
post #307

Earlier quoted context omitted.

There's also a well-known phenomena of large nations harboring multi-national corporations that break the law in other nations they operate in. That doesn't mean that the large, developed nations in question are engaging in organized crime. Taking advantage of regulatory arbitrage does not mean that their government is in collusion with them. If it did, then we could pile a lot of crimes at the feet of Western govern…

There is no sense to your comparison when you’re putting a criminal enterprise (which exists to do harm and harm only) and legitimate business into the same bucket.

A 'legitimate business' that occasionally dabbles in murder is also a criminal enterprise.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#366

Earlier quoted context omitted.

For me it was about making a statement. I had gotten into an argument with a professor on a discussion board. He used derogatory terms to refer to me, which pissed me off. I sent him a virus that was supposed to just damage files and delete some random files. It turns out it propagated onto their main network and crashed the entire universities network. Suddenly, you feel untouchable (even though the virus had gotten…

> It turns out it propagated onto their main network > the virus had gotten out of control, which I didn't mean it to do This isn't just a whoops, how do you "accidentally" create a virus that leaves the boundaries of the computer and traverses their network?

A stupid mistake a script kiddie makes when playing with malware you're not familiar with.

I copied an existing virus someone had given me. The last part of the virus was to multiply and seek out any other computers attached to the network and delete and damage the files on those computers as well. I didn't know that. When it damaged the professors PC, he was using it on his home network, so he said there was only one PC it infected.

When he got back to campus, he sent the email to the network team (a group of students and professors) and they tried testing it out on a group of PC's. They thought the PC's were sandboxed. Turns out they weren't. The next 24 hours the virus rampaged and pillaged PC's attached all over the network. I'm still not sure how it eventually crashed the network. All the people involved refused to tell me exactly how it crashed their network - they said they didn't want me encouraging others to do it, so I was never told the full story.

To this day, I'm still not sure what happened, but it had to be bad enough to call in the Feds, right?

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#367
post #72

Earlier quoted context omitted.

These groups will often use bitcoin tumblers/mixers to anonymize their btc. This is a solid explanation https://www.deepwebsiteslinks.com/wp-content/uploads/2017/10...

Is there a technical reason that makes use of a tumbler legally safe? My concern would be that putting in a clean bitcoin would result in me getting a fraction of a stolen bitcoin and I would be receiving stolen property. The fact that they are fully traceable means that it would be easy for someone innocent to be caught up in something like that.

[deleted]

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#368

Why should I believe this? They can shut down their servers, move their crypto to different wallets, and pop up again in a few weeks, right?

It's plausible that this is all a scheme to evade capture. Disband the current organization, (get rid of a few people who you've wanted to jettison anyway), and then set up shop afresh elsewhere. It sends the message to whoever's looking for you that the whole thing has been burned to the ground and there's nothing to raid or seize or shut down.

Possible, but there is too much a chance that the cops already know who you are and just need to gather evidence in a form they can take to court. By shutting down they ensure that no more evidence is gathered. By starting a new organization they can't be sure that they aren't still being watched.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#369
post #259

Earlier quoted context omitted.

I got downvoted for saying that maybe it's time to treat serious ransomware attacks (infrastructure, security, health, etc.) as terrorism - as in the sense that they're a threat to the national security. But this kinda shows the response I was referencing to. A lot of people like to think of ransomware attacks as the ultimate stress test as far as security goes, and thus a good thing - but let's not get too blinded b…

Maybe people didn't like your use of the term "terrorism" for national security threats? A common understanding is that terrorism is intended to frighten people or make them feel unsafe, while various official definitions of terrorism include the idea that it's intended to coercively achieve some particular political goal. If attackers just intend to get money, they're probably well-described as extortionists (or in…

Would the same apply for someone who physically took something essential to national security hostage and then demanded money?

Would that change if they, for example, demanded the release of prisoners of a specific political persuasion?

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#370
post #45

It was a mistake to attack the business side of the oil company, because it created what could be sold as reasonable doubt to shut down the pipeline. As a result, the ransom had the optics of an attack on infrastructure. As evidenced by the coverage of Americans desperately filling up containers. This created the impetus for the US to treat this as an incident far and above the ambient ransomware activities leading u…

The fact that their coins were apparently easily stolen also debunks another favourite talking point of the crypto people that it secures your money from government access. Clearly, ways and means have been developed to do just that if necessary.

There is billions of dollars of value in BTC sitting in wallets as an open bounty for anyone who can hack private keys.

So which of the following is most likely:

- the government has a tool that can break private key encryption and used it to confiscate a hacker groups funds

OR

- whoever controls the groups wallet transferred it out and is on the run

Post reply on HN