Live data from Hacker News

DarkSide ransomware gang quits after servers, Bitcoin stash seized

krebsonsecurity.com

371–380 of 623 posts

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#371

Why should I believe this? They can shut down their servers, move their crypto to different wallets, and pop up again in a few weeks, right?

They know that they can and will be found, and are running scared. In general ransomware works because it takes a lot of resources to find the criminals behind it. And generally there's not enough resources to do this. But once it hits a level where it creates a widespread national problem, it becomes more of an act of war. Then you get people involved that aren't just law enforcement and have tools that aren't avail…

Running scared though? I see this as the dash from 2nd plate to 3rd. If you're going to ditch your servers and wash your coins you might as well make it seem like you were compromised. I don't think there's any fear here as they surely must have anticipated the consequences.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#372

Once I had the fortune of seeing the three cups and a ball scam live, on the street. One guy does the trick, another encourages the victim, and a third one watches the crowd disguised as a random onlooker. If something makes the onlooker nervous, he will signal the others and they will grab their things and disappear in less seconds than your hand has fingers. This sudden quit seems similar, specially with the withdr…

How does the scam work ? You got me curious...

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#373

Earlier quoted context omitted.

If I'd just collected enough ransom to retire and never work again, I'd also put out a press release announcing I was out of business and someone seized all my shit and etc.

Darkside was a legit business. They routinely collected ransoms ten or twenty times larger than what they got from Colonial. if they were going to retire, they would have done it a long time ago

Didn't Colonial pay $5m? I don't think Darkside ever received a $50m-$100m ransom. Do you have any more details?

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#374
post #365

Earlier quoted context omitted.

There is no sense to your comparison when you’re putting a criminal enterprise (which exists to do harm and harm only) and legitimate business into the same bucket.

A 'legitimate business' that occasionally dabbles in murder is also a criminal enterprise.

Agree to a certain extent - executives in such companies need to pay the price on their actions, whether involed directly or via a proxy

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#375

Earlier quoted context omitted.

Depends if the DOJ issues arrest warrants for the members in a couple weeks.

Since they aren't in the US, it is probably more of a proactive step by the DOJ to build a case for sanctions. Assuming they know what country the perps are from, which doesn't seem all that clear.

There are only a handful of countries that won't accept the US arrest warrants and turn over whoever. A few countries will demand something first, but this means no death penalty, not something that is in anyway a big deal for the other country. It is semi-routine for most countries to capture and turn over criminals within the borders to another country.

That is why people bring up Russia and North Korea. Those are the two most likely countries that wouldn't. There are a few others, but not many.

Even China which in general I wouldn't trust would in this case. If China did an attack like this it would be much more targeted and they wouldn't be looking for ransom money - See the attacks on the Iran nuclear program for example: attack a target that actually matters. (those attacks were probably US or Israel, but it is the type of thing China might do).

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#376

Earlier quoted context omitted.

I could see 10 developers costing that much

$500,000 salary? Let me know where these jobs are because I'd like to submit my resume.

For experienced seniors and principal/staff engineers, this is pretty close if not below market rate. But presumably most of these engineers are globally distributed and 500k for eastern Europe is an immense sum.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#377
post #70
post #19

Just like the mob there are some targets that just aren't worth it because they bring too much heat. They are learning this is bad for business all around so they are stepping back and encouraging others to do the same.

This is it. Governments have cyber abilities that far outstrip individual organizations. And when cyber fails, there are still other diplomatic and less diplomatic tools. I wouldn't be surprised if the US Government here reached out to foreign governments for assistance in dismantling their infrastructure (it almost certainly was not on US soil). An individual hospital probably couldn't garner that kind of backing, b…

Small countries routinely help out for cases like this. I expect the US has reached out to whatever ones were involved long ago - it is just that until now things were still in the evidence gathering stage. While the police are sometimes willing to make an example of the wrong guy - that is the exception - most of the time they try to be right which means long investigations over many attacks.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#379
post #183

Earlier quoted context omitted.

Well, sometimes they're right. The hit company will likely call in some consultancy to institute a bunch of newer and better security protocols, then call it a day. If they really aren't hit again for another decade and staffing a department would cost $500k a year or more, were they wrong? It's a gamble. It's easy to point fingers at the company that was caught out, but for the hundreds or thousands that aren't rans…

They paid $5 million, if "it was cheaper for them," that's solid math that ignores some really important stuff though, LOL. What is the externalized cost of this crisis on the entire country? The $5 million dollar ransom is a worse deal if you can convince your board to consider that externality. The criminal penalties for executives in leadership and board positions (and I'm not saying this is my preferred approach)…

> What is the externalized cost of this crisis on the entire country?

One natural solution would be to subsidize cyberdefense. The political difficulty is that a rational subsidy would be proportional to the harm of an attack, which would mean giving the most money to the biggest corporations.

The best solution would be for the firm to raise their prices the very small amount necessary to cover the expense, and for consumers to tolerate the expense because they know it's worth it. But a pipeline is a natural monopoly, presumably charging a monopoly-optimal price that (correctly) assumes a populace ignorant of such concerns until it's too late.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#380
post #266

Earlier quoted context omitted.

I got downvoted for saying that maybe it's time to treat serious ransomware attacks (infrastructure, security, health, etc.) as terrorism - as in the sense that they're a threat to the national security. But this kinda shows the response I was referencing to. A lot of people like to think of ransomware attacks as the ultimate stress test as far as security goes, and thus a good thing - but let's not get too blinded b…

Terrorism is a non-state use of violence for political aims. Ransomware is non-state, not violent, and is done for economic, not political aims.

Ransomware is non-state

Are there no ransomware operations linked to North Korea? I was under the impression that there was some level of activity there to maintain supplies of globally-usable currency.

Post reply on HN