Live data from Hacker News

DOJ seizes $2.3M in cryptocurrency paid to the ransomware extortionists Darkside

justice.gov

11–20 of 296 posts

Re: DOJ seizes $2.3M in cryptocurrency paid to the ransomware extortionists Darkside

#11
post #6
post #4

There are more technical details in the linked affidavit (page 6 and 7): https://www.justice.gov/opa/press-release/file/1402056/downl... They kept following transactions on the blockchain, but it's not clear how the private key became in the posession of the FBI.

Netsec Twitter's theory is that the attacker(s) had a VPS operating in the US that the FBI was able to access and which contained the key to the wallet where the final payment ended up.

How? A keylogger? Cache somewhere?

Re: DOJ seizes $2.3M in cryptocurrency paid to the ransomware extortionists Darkside

#12
post #6
post #4

There are more technical details in the linked affidavit (page 6 and 7): https://www.justice.gov/opa/press-release/file/1402056/downl... They kept following transactions on the blockchain, but it's not clear how the private key became in the posession of the FBI.

Netsec Twitter's theory is that the attacker(s) had a VPS operating in the US that the FBI was able to access and which contained the key to the wallet where the final payment ended up.

I am by far no ransomware expert, but it really seems like amateur hour if they were running a Linux based Bitcoin full node using the mainline CLI daemon and client, with a wallet, on some hosting company geographically within the United States. Why would it need to be in the US?

Re: DOJ seizes $2.3M in cryptocurrency paid to the ransomware extortionists Darkside

#14
post #8

The most interesting and unknown question is how the DOJ/FBI came to be in possession of the private key.

A private key is not needed if the funds are on an exchange. Apparently there is a warrant to seize property on Northern California so I guess it might be Coinbase.

And yeah... if the crackers sent the funds to an exchange they were comically dumb.

Re: DOJ seizes $2.3M in cryptocurrency paid to the ransomware extortionists Darkside

#15
post #14
post #8

The most interesting and unknown question is how the DOJ/FBI came to be in possession of the private key.

A private key is not needed if the funds are on an exchange. Apparently there is a warrant to seize property on Northern California so I guess it might be Coinbase. And yeah... if the crackers sent the funds to an exchange they were comically dumb.

The press release specifically mentions that the cryptocurrency was seized through FBI having posession of the private key.

Re: DOJ seizes $2.3M in cryptocurrency paid to the ransomware extortionists Darkside

#16
post #14
post #8

The most interesting and unknown question is how the DOJ/FBI came to be in possession of the private key.

A private key is not needed if the funds are on an exchange. Apparently there is a warrant to seize property on Northern California so I guess it might be Coinbase. And yeah... if the crackers sent the funds to an exchange they were comically dumb.

The warrant does not imply that the coins were on an exchange. The warrant only indicates that they needed legal authority to seize coins, wherever they are.

It seem more likely that the FBI/NSA had and gained some access to the gang's infrastructure and seized the money.

Transmitting ransom money to an exchange without any type of tumbler or atomic swapping, that it's not a realistic scenario.

Maybe they tried to use an ineffective tumbler?

Re: DOJ seizes $2.3M in cryptocurrency paid to the ransomware extortionists Darkside

#17
post #6
post #4

There are more technical details in the linked affidavit (page 6 and 7): https://www.justice.gov/opa/press-release/file/1402056/downl... They kept following transactions on the blockchain, but it's not clear how the private key became in the posession of the FBI.

Netsec Twitter's theory is that the attacker(s) had a VPS operating in the US that the FBI was able to access and which contained the key to the wallet where the final payment ended up.

So many questions. Why are they running a bitcoin node on a vps? do they need to make automated payments or something? it's very easy to run a bitcoin node locally, or even airgap the signing keys.

Re: DOJ seizes $2.3M in cryptocurrency paid to the ransomware extortionists Darkside

#18
post #6

Earlier quoted context omitted.

Netsec Twitter's theory is that the attacker(s) had a VPS operating in the US that the FBI was able to access and which contained the key to the wallet where the final payment ended up.

I am by far no ransomware expert, but it really seems like amateur hour if they were running a Linux based Bitcoin full node using the mainline CLI daemon and client, with a wallet, on some hosting company geographically within the United States. Why would it need to be in the US?

Don't underestimate the stupidity/incompetence of these ransomware devs. Many cybercriminals have been caught for unbelievably dumb reasons.

Re: DOJ seizes $2.3M in cryptocurrency paid to the ransomware extortionists Darkside

#19
post #14

Earlier quoted context omitted.

A private key is not needed if the funds are on an exchange. Apparently there is a warrant to seize property on Northern California so I guess it might be Coinbase. And yeah... if the crackers sent the funds to an exchange they were comically dumb.

The press release specifically mentions that the cryptocurrency was seized through FBI having posession of the private key.

It's not an either/or thing though, right? IMHO, it seems plausible for the FBI to get a private key from a cooperating exchange?
Post reply on HN