Live data from Hacker News

DarkSide ransomware gang quits after servers, Bitcoin stash seized

krebsonsecurity.com

581–590 of 623 posts

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#581

Earlier quoted context omitted.

The fact that their coins were apparently easily stolen also debunks another favourite talking point of the crypto people that it secures your money from government access. Clearly, ways and means have been developed to do just that if necessary.

Or one of the members of the criminal gang ran off with all the cryptocurrency and then made a public post claiming some form of law enforcement seized the crypto.

Oh, somehow failed to see your post before writing mine. The perpetrator of the "all for myself" starting the state actor claim themselves makes even more sense! Why anger your partners when you can just point a finger elsewhere?

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#582

Earlier quoted context omitted.

On the high seas of the Internet there is a thin line between pirates and state actors. There could even be "privateer" ( https://en.wikipedia.org/wiki/Privateer ) attackers who work for a nation and for profit at the same time. From the victim's perspective it matters less who is attacking you or why they are attacking you and much more what the results of the attack are, how you can mitigate and recover from the da…

Just causing terror doesn't make it terrorism. Causing terror as a means to further some political (or religious) goal would make it terrorism.

You could call it unintentional terrorism I suppose. The timing with what's going on in Ukraine along with Putin's repeated threats makes it look political even if it wasn't. It's entirely possible they just happened to be a group of Russians who picked the wrong target at the wrong time. It's also entirely possible they were doing the Kremlin's work and just not announcing it publicly because that's not really how Putin plays the game.

I have to believe that played a role in the response they received as well.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#583
post #259

Earlier quoted context omitted.

Maybe people didn't like your use of the term "terrorism" for national security threats? A common understanding is that terrorism is intended to frighten people or make them feel unsafe, while various official definitions of terrorism include the idea that it's intended to coercively achieve some particular political goal. If attackers just intend to get money, they're probably well-described as extortionists (or in…

They may have just intended to get money, but they definitely spread terror. I had to have like an hour long phone call with my mother on Monday explaining why she had to go to 4 gas stations before she could get any gas, and that no the pipeline was not going to explode.

Could it perhaps have been the use of the word 'terrorism' in news reports that prompted her fear of the pipeline exploding?

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#584
post #561
post #143

Earlier quoted context omitted.

I imagine it went something like this "OK, now that you have our attention, and the eyes of the entire international media apparatus are on us, here's how we're going to do this. We're going to send some integer number of million money dollars down this pipe, and you're going to turn that gas pipe back on like you said you would. Then here's what happens next... we're going to give you an integer number of minutes ru…

This is a huge fantasy. The attackers are likely not in the US. The USA threatening to rain drones on Russia is just going to get laughed at. Nuclear war isn't breaking out over darkside.

Yeah yeah, and if you are the one on that phone call at that time, then you are welcome to call the bluff. Gulp

Putin already denied responsibility and Biden apparently accepted that, so we wouldn't be attacking the Russian government. Wink

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#585
post #190

I still can't wrap my head around how can such a critical infrastructre is not air gapped. This is just so... basic. You will never be secure enough, this is not what internet is for.

It probably is, their billing systems aren’t though. I believe they shut down the pipeline because they were unable to bill.

This is an extremely important detail which seems overlooked.

The pipeline did not need to be shutdown because of a danger to infrastructure, it was a corporate management decision to protect the company’s interests.

Colonial used a ransomeware attack on their company to do their own form of retaliatory blackmail on the entire southeast US to get a state level response and avoid the payout.

The above is not a defense of ransomeware, and I understand why Colonial acted as they did/it seems to have worked. They likely would not have gotten state level help had they not shut down the pipeline. But they have a larger level of responsibility for the damage caused by the pipeline shutdown than is being portrayed.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#586

Earlier quoted context omitted.

The fact that their coins were apparently easily stolen also debunks another favourite talking point of the crypto people that it secures your money from government access. Clearly, ways and means have been developed to do just that if necessary.

This is the most puzzling part of the story. These guys were evidently pretty skilled. I can see their servers being seized but I am struggling to figure out how they lost their currency. Did the Kremlin put a gun to their head and say “unlock the wallet”? This seems especially fishy.

It takes less skill than you might imagine to buy ransomware on the black market and deploy it. You don’t need to write it yourself, you just need to handle the extortion side of things.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#587
post #574
post #572

Earlier quoted context omitted.

I mean it doesn’t require ASICS, it’s just inefficient not to, right? Shouldn’t it be theoretically possible to mount a 51% attack with conventional CPUs (or GPUs), just a lot more of them? I have no idea what kind of computing resources various major states have, but I wouldn’t completely write off the possibility that they have enough CPUs to throw at the problem.

Bitcoin is currently 170 exahashes per second, or 170 x 10^18. The latest and greatest Intel i7 can do maybe 30 mh/s. You would need more than all cpus produced in history. I can believe G7 secretly having a third of total known CPU compute. I can't believe G7 secretly having multiples of all known CPU compute.

And be wanting to reserve it all for a longer period of time to disrupt the Bitcoin network.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#588

Earlier quoted context omitted.

Would the same apply for someone who physically took something essential to national security hostage and then demanded money? Would that change if they, for example, demanded the release of prisoners of a specific political persuasion?

Terrorism has to have some ideological agenda, which is what makes it dangerous - I doubt you'll see suicide bombers for hire.

Money can certainly help influence someone to wear a bomb vest, they don't need to actually believe in the cause. There could be someone out there that specializes in finding people in vulnerable financial situations that wouldn't mind blowing themselves up if it meant that their family was well taken care of.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#589

Earlier quoted context omitted.

I got downvoted for saying that maybe it's time to treat serious ransomware attacks (infrastructure, security, health, etc.) as terrorism - as in the sense that they're a threat to the national security. But this kinda shows the response I was referencing to. A lot of people like to think of ransomware attacks as the ultimate stress test as far as security goes, and thus a good thing - but let's not get too blinded b…

FWIW in June of 2011 the Pentagon issued a report that defined how 'cyber attacks' can be classified as an act of war. Part of the defense department review of threats against the US. However, they have to be plausibly tied to a state actor such as Russia or North Korea (to give two examples) The net result was that the Pentagon considers military response (both kinetic and cyber) as legal and sanctioned ways to resp…

In the book Ghost Fleet, a billionaire obtains a letter of marque to go hijack a Chinese space station that is shooting down US satellites.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#590

Earlier quoted context omitted.

I got downvoted for saying that maybe it's time to treat serious ransomware attacks (infrastructure, security, health, etc.) as terrorism - as in the sense that they're a threat to the national security. But this kinda shows the response I was referencing to. A lot of people like to think of ransomware attacks as the ultimate stress test as far as security goes, and thus a good thing - but let's not get too blinded b…

No imagination required; this cyberattack on infrastructure masqueraded as ransomware: https://en.wikipedia.org/wiki/Petya_(malware)

You need to consider the motivation. Were the hackers just looking for a victim with deep pockets that would want to just hand over the money as soon as possible or were they actually looking to bring down a major pipeline? Giving the victim the chance to recover once the ransom is paid seems like it was more about the money. The attack could just have easily deleted everything from the network and totally crippled Colonial.
Post reply on HN