Live data from Hacker News

DarkSide ransomware gang quits after servers, Bitcoin stash seized

krebsonsecurity.com

441–450 of 623 posts

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#441

Earlier quoted context omitted.

The fact that their coins were apparently easily stolen also debunks another favourite talking point of the crypto people that it secures your money from government access. Clearly, ways and means have been developed to do just that if necessary.

so which is it then? "BTC is bad cause it can be used by drug dealers to launder money" "BTC is not even secure from government access" Surely someone will point out both can be true but the point is the anti-btc folks seem to be talking out both sides of the mouth

I think it's both: people who have something to hide for the government can make it pretty hard (but not impossible) for the authorities to track them down. On the other hand average people who don't have "anything to hide" have no reason to bother implementing these counter-measures, making it fairly easy to track their transactions on the public blockchain.

In this case even the pros messed it up, but this is a very high profile case with undoubtedly a massive amount of manpower thrown at it in various agencies. You don't mess with USA's oil.

And even then it's unclear if the money was actually confiscated.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#442
post #45

It was a mistake to attack the business side of the oil company, because it created what could be sold as reasonable doubt to shut down the pipeline. As a result, the ransom had the optics of an attack on infrastructure. As evidenced by the coverage of Americans desperately filling up containers. This created the impetus for the US to treat this as an incident far and above the ambient ransomware activities leading u…

I got downvoted for saying that maybe it's time to treat serious ransomware attacks (infrastructure, security, health, etc.) as terrorism - as in the sense that they're a threat to the national security. But this kinda shows the response I was referencing to. A lot of people like to think of ransomware attacks as the ultimate stress test as far as security goes, and thus a good thing - but let's not get too blinded b…

Serious side effects, yes. I am homeless and live in my van in North Carolina and having to ration my gasoline waiting for the idiots to stop hoarding.

These people thought they were sticking it to the man but they were actually sticking it to people like me.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#443
post #438

I would wager a foolish sum that Colonial had a complete shit security posture and had many opportunities to improve but chose to accept this risk at the executive level. I have zero sympathy for Colonial.

LOL:

“Tech audit of Colonial Pipeline found ‘glaring’ problems”

https://apnews.com/article/va-state-wire-technology-business...

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#444
post #431

Earlier quoted context omitted.

> On top of that, there is a fair amount of forensic data indicating shared resources between hacker groups and GRU operatives. Go on

You could start to look at the spread of Diskcoder.C across several attacks and the shared code with ExPetr and NotPetya... This forms the basis for the DOJ indictment against 6 officers of GRU Unit 74455. There is much more if you care to go down that rabbit hole.

Oh nonsense, that was well established to be an edit of the binary. It’s obvious the GRU didn’t have the source code. The idea that this was an example of the GRU working with criminal hackers is plainly ridiculous.

https://blog.malwarebytes.com/threat-analysis/2017/06/eterna...

Why call it diskcoder.c anyway? It’s Petya

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#445

Earlier quoted context omitted.

> This is a business that actually provides better support than a regular business. The thing I find fascinating from a sociology perspective about ransomware is that they have to. To be a successful ransomware company, you have to simultaneously be: 1. Completely immoral enough to attack companies, hold their data ransom and potentially put them out of business and reveal the private details of thousands of people.…

In a cynical telling this is how you start a government or any organization with a monopoly on violence, ala mafia. First you make it clear that you can cause damage, then you make it clear that tax payers are safe. The next step for ransomware companies is to offer cyber security services, whether you want them or not. We've hacked you. We fixed your crappy unpatched software, if you try to remove us you lose all yo…

or any self-identified 'disruptive' business model really.

step 1: "join my disruptor gang and we'll protect your lifestyle/income/status in exchange for tribute, or at least not becoming a disruptee yourself."

step 2: end up eventually recapitulating the exact same system you disrupted, but now you get all the spoils of the incumbent power

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#446
post #262

> “There’s too much publicity,” the XSS administrator explained. “Ransomware has gathered a critical mass of nonsense, bullshit, hype, and fuss around it. The word ‘ransomware’ has been put on a par with a number of unpleasant phenomena, such as geopolitical tensions, extortion, and government-backed hacks. This word has become dangerous and toxic.” I am... flabbergasted. What? Ransomware has always been a brand of e…

I'm interpreting the statement to mean that ransomware very rapidly lost its reputation as a nuisance-crime this week. Misplaced ransomware runs a far more substantial risk of triggering enforcement action now. Or at least that's the perception I'm deriving from the quote.

Others seem to suspect that this is a ploy. It does kinda fit the melodrama on display...

Otoh, as a kid I was into small-time mischief (pilfering candy from teacher's desk kinda stuff). I had a good sense of what would go unnoticed, but I was a bit too trusting of my friends. They'd go overboard, get caught, and I'd take the blame. So, I can sympathise with this a bit

Without external proof, I wouldn't hazard a guess as to which it is

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#447
post #45

It was a mistake to attack the business side of the oil company, because it created what could be sold as reasonable doubt to shut down the pipeline. As a result, the ransom had the optics of an attack on infrastructure. As evidenced by the coverage of Americans desperately filling up containers. This created the impetus for the US to treat this as an incident far and above the ambient ransomware activities leading u…

The fact that their coins were apparently easily stolen also debunks another favourite talking point of the crypto people that it secures your money from government access. Clearly, ways and means have been developed to do just that if necessary.

I don't see anywhere that the coins where stolen by the government. It could have been done by an insider from the group who had access to the wallet and 1. transferred to himself or 2. the damage and attention was to much for one of them and some ethics kicked in and ratted out the group to government. gave them his access. 3. the group got scared from the attention and stopped their operation and lying about the seizure, because at this point we don't even know if anything was seized at all, that info comes from the criminals which is hard to trust and wasn't confirmed by official reports yet.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#448

Earlier quoted context omitted.

$500,000 salary? Let me know where these jobs are because I'd like to submit my resume.

More like a $250,000 salary + benefits. Medical coverage is hideously expensive for example. Plus retirement, dental, insurance, and taxes. Still a cushy salary for a dev, but not completely out of the realm of reason.

That's definitely a high salary except for the biggest companies in the richest parts of the richest countries.

I do thin the parent's point still stands though, my current salary is not nearly that high but you'd have to pay me a lot more than $500k for me to risk hacking an American pipeline. That's an insane amount of risk for a few years worth of salary (that I'll probably have to be very careful laundering if I don't want to raise suspicions).

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#449
post #45

It was a mistake to attack the business side of the oil company, because it created what could be sold as reasonable doubt to shut down the pipeline. As a result, the ransom had the optics of an attack on infrastructure. As evidenced by the coverage of Americans desperately filling up containers. This created the impetus for the US to treat this as an incident far and above the ambient ransomware activities leading u…

I got downvoted for saying that maybe it's time to treat serious ransomware attacks (infrastructure, security, health, etc.) as terrorism - as in the sense that they're a threat to the national security. But this kinda shows the response I was referencing to. A lot of people like to think of ransomware attacks as the ultimate stress test as far as security goes, and thus a good thing - but let's not get too blinded b…

The definition of terrorism isn't a "threat to national security". For example, your country could do something evil and wrong, grievously and unjustifiably violating the interests of an entity with a military, and be deservedly subject to military action, constituting a threat to national security. That wouldn't be "terrorism", it would just be "military action".

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#450

Earlier quoted context omitted.

Agreed, except why bother pop up again? They just got a big fat payment of $5m. Plenty to split with a small team. It's a good time to cash out and disappear.

Seriously! It's FIVE MILLION. That's "I don't ever have to work again" money. What is wrong with people! Probably they want Mercedes, and Rolexes, and Mont Blanc pens and all that showy consumer garbage.

$5million spread between an unknown number of people and that need to be laundered before it's turned into Rolexes and Mercedeses. Given the high risks it doesn't sound like a great deal to me especially since competent hackers can usually command a fairly high salary in legit companies.
Post reply on HN