Live data from Hacker News

German police name alleged leaders of GandCrab and REvil ransomware groups

krebsonsecurity.com

151–160 of 175 posts

Re: German police name alleged leaders of GandCrab and REvil ransomware groups

#151
post #85

So apparently some CCC-connected hackers already unmasked one of them years ago (as reported in the update, which could have also just linked to the talk here: https://media.ccc.de/v/37c3-12134-hirne_hacken_hackback_edit... ) Makes you wonder if the investigators discovered this independently, or decided to maybe ask the hackers already involved in defending against them for help...

I'm not deep into the topic, but AFAIK there generally isn't a warm connection between the CCC and the BND in Germany (in the recent years mostly due to the BNDs involvement ins spying on German citizens, but I think there is also deeper history there). If a hacker collaborates with the BND they do run a risk of many of their peers not wanting to collaborate with them anymore.

>There (...) isn't a warm connection between the CCC and the BND in Germany

Fun fact: In the 1990s, the CCC e.V. was declared a terrorist organization by the BND. Also, a lot of members have been sued for Landesverrat (high treason) for disclosing found vulnerabilities and/or doing journalistic work.

For example, the netzpolitik guys have been sued for high treason twice.

Just as a side note on how competent the German state is to use their existing talent to work on issues in cyber security.

> If a hacker collaborates with the BND they do run a risk of many of their peers not wanting to collaborate with them anymore.

Another fun fact: There is no effective witness protection program in Germany. You have to have been attacked almost murdered twice (with legal cases leading to prosecution) before you can apply for the witness protection program.

And they're asking themselves why all the witnesses in high profile cases from Europol/Interpol keep disappearing ...

Re: German police name alleged leaders of GandCrab and REvil ransomware groups

#152

How is "this is the name of the formerly anonymous extortionist" doxxing? Unless there's something not covered in the article, his current address, family members, phone, etc were not listed. That's not doxxing; that's "here's a guy were want to arrest."

It seems to me that the meaning of the word "doxxing" has slowly drifted to mean "revealing information about somebody without their consent", be it by state actor, a company or an individual. BTW, what do you think will happen when people find out that their neighbor is secretly a pretty wealthy criminal? Attempts of theft, robbery and extortion have happened in the wake of such announcements. There was even a case…

> what do you think will happen when people find out that their neighbor is secretly a pretty wealthy criminal?

Call the police? Isn't this the point?

Re: German police name alleged leaders of GandCrab and REvil ransomware groups

#153
post #80

Earlier quoted context omitted.

[flagged]

The wildfire industry brings growth but it would be a whole lot better if we didn't have wildfires. The same thing is true with computers. Imagine all the nice things we could have if we didn't have to worry about people abusing the systems we build.

Get down to earth. That can never happen nor does it need to.

Re: German police name alleged leaders of GandCrab and REvil ransomware groups

#154
post #138

... and "leading security website" cuts off any traffic from VPNs. What an irony. What's next, ads?

Eh, being a high profile security website, VPNs are where the harassing traffic comes from, and I'm sure there's no lack of it. VPN "security" is a bit of a joke because why would I trust some VPN provider any more than my ISP? Everything is HTTPS these days anyway.

Re: German police name alleged leaders of GandCrab and REvil ransomware groups

#155
post #137
post #85

Earlier quoted context omitted.

I'm not deep into the topic, but AFAIK there generally isn't a warm connection between the CCC and the BND in Germany (in the recent years mostly due to the BNDs involvement ins spying on German citizens, but I think there is also deeper history there). If a hacker collaborates with the BND they do run a risk of many of their peers not wanting to collaborate with them anymore.

>but AFAIK there generally isn't a warm connection between the CCC and the BND nor should there be. Similar to how us American hackers have a huge dislike and distrust of the FBI. Your own law enforcement agency will lie to you, manipulate you, raid you, extort you, and imprison you over bullshit.

"Your own law enforcement agency will lie to you, manipulate you, raid you, extort you, and imprison you over bullshit."

But this is not, how it should be. And not all law enforcement agencies are like this.

Re: German police name alleged leaders of GandCrab and REvil ransomware groups

#156
post #85

So apparently some CCC-connected hackers already unmasked one of them years ago (as reported in the update, which could have also just linked to the talk here: https://media.ccc.de/v/37c3-12134-hirne_hacken_hackback_edit... ) Makes you wonder if the investigators discovered this independently, or decided to maybe ask the hackers already involved in defending against them for help...

I'm not deep into the topic, but AFAIK there generally isn't a warm connection between the CCC and the BND in Germany (in the recent years mostly due to the BNDs involvement ins spying on German citizens, but I think there is also deeper history there). If a hacker collaborates with the BND they do run a risk of many of their peers not wanting to collaborate with them anymore.

Sadly, there is a rift now since quite a few hackers are left leaning and therefore are by definition activists.

80th, 90th were the last time were hacking was a means to an end. C64 and Amiga scene had skindheads showing up at copy parties but no one cared really.

Some were a bit unsure but the moment they talked about their craft there was no divide but hacker spirit.

In recent years this would be unimaginable. And guess what? Talking to each other made the skins disappear.

It was more of a niche expression without doing harm. Popper, Goths, Ted’s, Rockers - in comparison to today there was more unity than today.

Hooligans were the same. Many local groups that fought each other due to political stances befriended each other later because it was more of a ritual than ideology.

It is a bit sad because politics doesn’t belong to hacking, and never did.

Hacking is Boolean only in the sense of it either works or it doesn’t. Or does a computer care about left or right?

And BtW that’s why I find local attempts in Europe for “Go EU” pathetic. It is about ideology, not improvement.

Re: German police name alleged leaders of GandCrab and REvil ransomware groups

#157
post #85

Earlier quoted context omitted.

I'm not deep into the topic, but AFAIK there generally isn't a warm connection between the CCC and the BND in Germany (in the recent years mostly due to the BNDs involvement ins spying on German citizens, but I think there is also deeper history there). If a hacker collaborates with the BND they do run a risk of many of their peers not wanting to collaborate with them anymore.

Sadly, there is a rift now since quite a few hackers are left leaning and therefore are by definition activists. 80th, 90th were the last time were hacking was a means to an end. C64 and Amiga scene had skindheads showing up at copy parties but no one cared really. Some were a bit unsure but the moment they talked about their craft there was no divide but hacker spirit. In recent years this would be unimaginable. And…

Computers don't care whether they are used for good or for evil. I would rather have a culture that encourages using computers for good, and there is nothing sad about such culture existing. Computers are already used for evil on a much larger scale by meta, palantir, etc.

Re: German police name alleged leaders of GandCrab and REvil ransomware groups

#158
post #138

... and "leading security website" cuts off any traffic from VPNs. What an irony. What's next, ads?

Eh, being a high profile security website, VPNs are where the harassing traffic comes from, and I'm sure there's no lack of it. VPN "security" is a bit of a joke because why would I trust some VPN provider any more than my ISP? Everything is HTTPS these days anyway.

> [...] why would I trust some VPN provider any more than my ISP [...]

Of course, whether or not to use a VPN always depends on the specifics. (threat model, circumstances, VPN provider, etc.)

I am with the biggest telecoms provider in Germany, and I trust them about as far as I can throw them.

They are known for censoring their DNS servers, being opaque about government requests, and creating artificial bottlenecks to extort money from companies in order to avoid throttling.

Re: German police name alleged leaders of GandCrab and REvil ransomware groups

#159
post #135

These groups typically exploit unpatched vulnerabilities and exposed credentials. Most companies don't discover they're vulnerable until after a breach. Regular security audits are the only real defense.

ugh, strong ai slop vibes with comments like this

Because they actually use capitalization and punctuation?

Re: German police name alleged leaders of GandCrab and REvil ransomware groups

#160
post #6

Earlier quoted context omitted.

Found his record in Russia's official company registry. This is what he officially does as an entepreneur: 56.10 — Restaurant activities and food delivery services 47.23 — Retail sale of fish, crustaceans, and mollusks in specialized stores 47.25.12 — Retail sale of beer in specialized stores 47.25.2 — Retail sale of soft drinks in specialized stores 47.29.39 — Retail sale of other food products in specialized stores…

His first, middle and last names are among the more popular, chances are you found a namesake.

Schukin isn't a very common last name (definitely not Ivanov-tier). The first name, the patronymic (his father is Maksim) and the last name all match, as well as the city (the article says he lives in Krasnodar). In fact, this Krasnodar-based entrepreneur is the only person that shows up in the search at all for "Daniil Maksimovich Schukin". Not to say the business was registered right when the ransoms started (2019). Too many coincidences if it's just a namesake.
Post reply on HN