Why should I believe this? They can shut down their servers, move their crypto to different wallets, and pop up again in a few weeks, right?
They know that they can and will be found, and are running scared. In general ransomware works because it takes a lot of resources to find the criminals behind it. And generally there's not enough resources to do this. But once it hits a level where it creates a widespread national problem, it becomes more of an act of war. Then you get people involved that aren't just law enforcement and have tools that aren't avail…
DarkSide ransomware gang quits after servers, Bitcoin stash seized
371–380 of 623 posts
Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized
#372Once I had the fortune of seeing the three cups and a ball scam live, on the street. One guy does the trick, another encourages the victim, and a third one watches the crowd disguised as a random onlooker. If something makes the onlooker nervous, he will signal the others and they will grab their things and disappear in less seconds than your hand has fingers. This sudden quit seems similar, specially with the withdr…
Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized
#373Earlier quoted context omitted.
If I'd just collected enough ransom to retire and never work again, I'd also put out a press release announcing I was out of business and someone seized all my shit and etc.
Darkside was a legit business. They routinely collected ransoms ten or twenty times larger than what they got from Colonial. if they were going to retire, they would have done it a long time ago
Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized
#374Earlier quoted context omitted.
There is no sense to your comparison when you’re putting a criminal enterprise (which exists to do harm and harm only) and legitimate business into the same bucket.
A 'legitimate business' that occasionally dabbles in murder is also a criminal enterprise.
Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized
#375Earlier quoted context omitted.
Depends if the DOJ issues arrest warrants for the members in a couple weeks.
Since they aren't in the US, it is probably more of a proactive step by the DOJ to build a case for sanctions. Assuming they know what country the perps are from, which doesn't seem all that clear.
That is why people bring up Russia and North Korea. Those are the two most likely countries that wouldn't. There are a few others, but not many.
Even China which in general I wouldn't trust would in this case. If China did an attack like this it would be much more targeted and they wouldn't be looking for ransom money - See the attacks on the Iran nuclear program for example: attack a target that actually matters. (those attacks were probably US or Israel, but it is the type of thing China might do).
Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized
#376Earlier quoted context omitted.
I could see 10 developers costing that much
$500,000 salary? Let me know where these jobs are because I'd like to submit my resume.
Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized
#377Just like the mob there are some targets that just aren't worth it because they bring too much heat. They are learning this is bad for business all around so they are stepping back and encouraging others to do the same.
This is it. Governments have cyber abilities that far outstrip individual organizations. And when cyber fails, there are still other diplomatic and less diplomatic tools. I wouldn't be surprised if the US Government here reached out to foreign governments for assistance in dismantling their infrastructure (it almost certainly was not on US soil). An individual hospital probably couldn't garner that kind of backing, b…
Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized
#378Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized
#379Earlier quoted context omitted.
Well, sometimes they're right. The hit company will likely call in some consultancy to institute a bunch of newer and better security protocols, then call it a day. If they really aren't hit again for another decade and staffing a department would cost $500k a year or more, were they wrong? It's a gamble. It's easy to point fingers at the company that was caught out, but for the hundreds or thousands that aren't rans…
They paid $5 million, if "it was cheaper for them," that's solid math that ignores some really important stuff though, LOL. What is the externalized cost of this crisis on the entire country? The $5 million dollar ransom is a worse deal if you can convince your board to consider that externality. The criminal penalties for executives in leadership and board positions (and I'm not saying this is my preferred approach)…
One natural solution would be to subsidize cyberdefense. The political difficulty is that a rational subsidy would be proportional to the harm of an attack, which would mean giving the most money to the biggest corporations.
The best solution would be for the firm to raise their prices the very small amount necessary to cover the expense, and for consumers to tolerate the expense because they know it's worth it. But a pipeline is a natural monopoly, presumably charging a monopoly-optimal price that (correctly) assumes a populace ignorant of such concerns until it's too late.
Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized
#380Earlier quoted context omitted.
I got downvoted for saying that maybe it's time to treat serious ransomware attacks (infrastructure, security, health, etc.) as terrorism - as in the sense that they're a threat to the national security. But this kinda shows the response I was referencing to. A lot of people like to think of ransomware attacks as the ultimate stress test as far as security goes, and thus a good thing - but let's not get too blinded b…
Terrorism is a non-state use of violence for political aims. Ransomware is non-state, not violent, and is done for economic, not political aims.
Are there no ransomware operations linked to North Korea? I was under the impression that there was some level of activity there to maintain supplies of globally-usable currency.