Live data from Hacker News

DarkSide ransomware gang quits after servers, Bitcoin stash seized

krebsonsecurity.com

401–410 of 623 posts

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#401

Earlier quoted context omitted.

I got downvoted for saying that maybe it's time to treat serious ransomware attacks (infrastructure, security, health, etc.) as terrorism - as in the sense that they're a threat to the national security. But this kinda shows the response I was referencing to. A lot of people like to think of ransomware attacks as the ultimate stress test as far as security goes, and thus a good thing - but let's not get too blinded b…

IMO terrorism is a "waffle word" that doesn't really have any meaning anymore. Originally a use of violence and intimidation against civilians in pursuit of political ideology, it's come to mean "people we don't like, who aren't state actors and don't fit conventional organized crime narratives." I don't think it's necessary to staple the term to the action in order to take it seriously. It should, however, be taken…

Original definition did not required target to be civilians. Suicide attacks against military were called terrorism too.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#402

Earlier quoted context omitted.

I think it's still just pseudo-anonymity, even for monero. Which means, practically, that I don't think it would have done more for these guys than just delay the seizure.

Nope. Monero is actually private and untraceable.

Is getting in and out of Monero private and untraceable?

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#403

Earlier quoted context omitted.

Do you have any extraordinary evidence for these extraordinary claims?

Very few doubt that FSB and Russian mafia are one.

those few are all here downvoting you?

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#404
post #259

Earlier quoted context omitted.

Maybe people didn't like your use of the term "terrorism" for national security threats? A common understanding is that terrorism is intended to frighten people or make them feel unsafe, while various official definitions of terrorism include the idea that it's intended to coercively achieve some particular political goal. If attackers just intend to get money, they're probably well-described as extortionists (or in…

On the high seas of the Internet there is a thin line between pirates and state actors. There could even be "privateer" ( https://en.wikipedia.org/wiki/Privateer ) attackers who work for a nation and for profit at the same time. From the victim's perspective it matters less who is attacking you or why they are attacking you and much more what the results of the attack are, how you can mitigate and recover from the da…

Just causing terror doesn't make it terrorism. Causing terror as a means to further some political (or religious) goal would make it terrorism.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#405

Once I had the fortune of seeing the three cups and a ball scam live, on the street. One guy does the trick, another encourages the victim, and a third one watches the crowd disguised as a random onlooker. If something makes the onlooker nervous, he will signal the others and they will grab their things and disappear in less seconds than your hand has fingers. This sudden quit seems similar, specially with the withdr…

How does the scam work ? You got me curious...

Ball gets placed under one of three cups. Cups get mixed around and people guess where the ball is for money. The ball isn’t under any of them though. The scammer palmed it.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#406
post #156

Earlier quoted context omitted.

Yeah apparently in addition to their white label ransomware software, if you licensed their software you could also have DarkSide handle negotiations for you. 10%-25% of the ransom and in exchange you get people who have real experience handling the negotiations and have the infra in place already to remain anonymous while supporting 24/7 English language service.

Ransomware-As-A-Platform. I wonder if they got the criminal-underground equivalent of VC-funding, or if they have something like Y-combinator to fund innovative criminal approaches and promote networking -- like evil-Kirk from the mirror universe, there could be a Saul Graham with a mustache writing essays about unlocking value and what you are not allowed to say in the ransomware community.

From my (admittedly shallow) understanding, all of that does kind of exist and has for at least a few years, now. It's also existed for longer for the DDoS-as-a-Service industry. Most of it's in Russian and takes place on private and semi-private Russian forums and chat rooms/groups.

There's definitely a hierarchy to it. Any particular group may not necessarily develop or own the software or infrastructure they're using. You can probably liken it to drug markets, where there are some top-level central players and many tiers below that make up the whole supply and distribution chain. (And potentially, the absolute top-level / "The Commission" may be certain elements of certain nations' governments, in some cases, or at least closely associated with them, which further complicates matters.)

You might find this 2020 interview with a ransomware operator interesting: https://talos-intelligence-site.s3.amazonaws.com/production/...

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#407
post #45

It was a mistake to attack the business side of the oil company, because it created what could be sold as reasonable doubt to shut down the pipeline. As a result, the ransom had the optics of an attack on infrastructure. As evidenced by the coverage of Americans desperately filling up containers. This created the impetus for the US to treat this as an incident far and above the ambient ransomware activities leading u…

I got downvoted for saying that maybe it's time to treat serious ransomware attacks (infrastructure, security, health, etc.) as terrorism - as in the sense that they're a threat to the national security. But this kinda shows the response I was referencing to. A lot of people like to think of ransomware attacks as the ultimate stress test as far as security goes, and thus a good thing - but let's not get too blinded b…

FWIW in June of 2011 the Pentagon issued a report that defined how 'cyber attacks' can be classified as an act of war. Part of the defense department review of threats against the US. However, they have to be plausibly tied to a state actor such as Russia or North Korea (to give two examples) The net result was that the Pentagon considers military response (both kinetic and cyber) as legal and sanctioned ways to respond to cyber attacks.

Generally though, the Justice department defines terrorism to be "the unlawful use of force and violence against persons or property to intimidate or coerce a government, the civilian population, or any segment thereof, in furtherance of political or social objectives"

These ransomware attacks fall in the middle. They are 'deniable' by state actors as just crooks who happen to be within their borders. They certainly don't push any social objective other than to enrich the criminals. So that leaves them under the jurisdiction of law enforcement.

I have read anecdotal evidence that there are the equivalent to "Letters of Marque"[1] for Russian criminals who attack enemies of the Kremlin. They wouldn't completely qualify as the Russians aren't actually in a declared state of war (this works fine for North Korea) but conceptually if you accept that criminals are gonna crim, then pointing them at people you don't like at least keeps the damage outside of your area of concern.

In this particular case, the fairly rapid take down of these guys gives me pause. One wonders if the FBI and Interpol had Colonial pay with Bitcoin that they then traced to the destination wallets. And then working backward from there to the server infrastructure. That would be an interesting capability if it exists.

[1] https://en.wikipedia.org/wiki/Letter_of_marque

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#408

Once I had the fortune of seeing the three cups and a ball scam live, on the street. One guy does the trick, another encourages the victim, and a third one watches the crowd disguised as a random onlooker. If something makes the onlooker nervous, he will signal the others and they will grab their things and disappear in less seconds than your hand has fingers. This sudden quit seems similar, specially with the withdr…

How does the scam work ? You got me curious...

https://www.youtube.com/watch?v=hGAfimeeCD8

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#409
post #259

Earlier quoted context omitted.

Maybe people didn't like your use of the term "terrorism" for national security threats? A common understanding is that terrorism is intended to frighten people or make them feel unsafe, while various official definitions of terrorism include the idea that it's intended to coercively achieve some particular political goal. If attackers just intend to get money, they're probably well-described as extortionists (or in…

Would the same apply for someone who physically took something essential to national security hostage and then demanded money? Would that change if they, for example, demanded the release of prisoners of a specific political persuasion?

Terrorism has to have some ideological agenda, which is what makes it dangerous - I doubt you'll see suicide bombers for hire.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#410
post #259

Earlier quoted context omitted.

Maybe people didn't like your use of the term "terrorism" for national security threats? A common understanding is that terrorism is intended to frighten people or make them feel unsafe, while various official definitions of terrorism include the idea that it's intended to coercively achieve some particular political goal. If attackers just intend to get money, they're probably well-described as extortionists (or in…

Would the same apply for someone who physically took something essential to national security hostage and then demanded money? Would that change if they, for example, demanded the release of prisoners of a specific political persuasion?

> Would that change if they, for example, demanded the release of prisoners of a specific political persuasion?

How would that not be classified as a political motive?

Post reply on HN