This story makes absolutely no sense at all. The errors present by these hackers are so comical it's simply unbelievable. I'm supposed to believe some elite Russian hacking group keeps their crypto wallets running on a US host where the FBI just logs right in and snatches the private key? I'm starting to entertain the conspiracies that the future of commodities price manipulation is fake ransomware attacks. There nee…
It always struck me as improbable that all these high profile (and notoriously hard/impossible to attribute) attacks on “critical infrastructure” or whatever are always instantly and authoritatively pinned (by US authorities) on groups operating in the US’s geopolitical enemies. “Russian hackers” once again, eh?
DOJ seizes $2.3M in cryptocurrency paid to the ransomware extortionists Darkside
171–180 of 296 posts
Re: DOJ seizes $2.3M in cryptocurrency paid to the ransomware extortionists Darkside
#172Earlier quoted context omitted.
Colonial paid 75 BTC, and they recovered 63.7 BTC.
I'm guessing the rest was fees/etc coming out of the crypto tumblers they used?
Re: DOJ seizes $2.3M in cryptocurrency paid to the ransomware extortionists Darkside
#173https://twitter.com/thisisbullish/status/1402056137340604418...
How amateur is that…
Re: DOJ seizes $2.3M in cryptocurrency paid to the ransomware extortionists Darkside
#174Earlier quoted context omitted.
I don’t think it’s an understatement to say that their reach kind of is. If sanctioned the US government could almost certainly 51% attack any given crypto and redirect funds to whoever they want. This isn’t what happened but it’s laughable to think the US government isn’t capable of tracking down the account and seizing coins.
I doubt they could 51% Bitcoin with any sort of haste. Perhaps with a few year plan. Simply put it’s a procurement issue. There are limited ASICS and they are distributed among many operators, mostly foreign. There aren’t massive ASIC stockpiles in the US just waiting to be purchased. A government 51% attack would probably involve doing a private chip run.
From when they planned for the capacity, probably not. But how do we, at any time, know that hasn’t happened in the past?
> A government 51% attack would probably involve doing a private chip run.
Sure, and when that classified capacity is acquired via, say, the NSA’s black budget, we’ll all know before (or, heck, even after, until they decide to something disruptive with it) they decide to light up the capacity...how?
OTOH, any attack won’t just be to redirect funds, because that can’t be done without broader disruption that would make it pointless for that purpose.
Re: DOJ seizes $2.3M in cryptocurrency paid to the ransomware extortionists Darkside
#175Earlier quoted context omitted.
hacker gangs can make tens of millions dollars. No security consultant makes that much.
Hacker gangs also apparently lose 2.4 million dollars at the drop of a hat, which is something that no security consultant ever has to worry about.
There's enough self-styled cypherpunk infosec experts that might insist on being paid only in BTC and then lose their decrypted wallet...
Re: DOJ seizes $2.3M in cryptocurrency paid to the ransomware extortionists Darkside
#176Earlier quoted context omitted.
hacker gangs can make tens of millions dollars. No security consultant makes that much.
Gangs are multiple people, they have higher expenses (can’t go to a normal bank, have to pay off local police, etc.), and the long-term prospects are risky so they need to get rich and find safe places to store the money after laundering it. Plus every so often you get on the wrong side of someone nasty and end up involved in something much riskier or dead. Even if you’re completely amoral, getting a hefty paycheck,…
Re: DOJ seizes $2.3M in cryptocurrency paid to the ransomware extortionists Darkside
#177Earlier quoted context omitted.
In crypto „seizing” means getting access to the wallet and sending funds to the one that gov’t has under it’s sole control
How do they get access to the wallet, assuming the dude won't tell them? With fiat they can do it with force, that's the difference. If the dude won't tell them they have no way to get access to it, other than the $5 wrench.
This assumes perfect opsec: the guy is unphishable, has a quick-response switch to wipe their computers when their house is raided, etc. They get a lot of people through simple gaps: bust the door down when the target is in the bathroom, grab the unlocked computer in a public setting, etc.
The other big assumption is that the only copy of the key belonged to someone in the gang who is a high-value target. If it’s an exchange, they need to make an official request. Someone offering laundering services or a lower-value person in the gang, the offer is likely going to be offered a plea bargain for cooperating to get bigger fish versus a much longer sentence.
Even if it is the most culpable member of the gang, the prospect of a very long prison sentence versus something shorter is going to weigh heavily — especially if you know that they’re just going to leave you in jail until you give them the key anyway.
Re: DOJ seizes $2.3M in cryptocurrency paid to the ransomware extortionists Darkside
#178Don't they mean Putin in an agreement with the Biden administration made Darkside give some money back as a way of easing American public tensions and political fallout ahead of the summit?
If that is what they did, that's a fantastic diplomatic success story
I doubt Russia is too crazy about the idea of pipelines=targets. Especially one that doesn't even compete with them. 2x especially the billing! 64% of Russian exports are gas and oil.
https://commons.wikimedia.org/wiki/File:Russia_Export_Treema...
Re: DOJ seizes $2.3M in cryptocurrency paid to the ransomware extortionists Darkside
#179Earlier quoted context omitted.
That’s my prediction: these guys are like bike thieves who found out the hard way that they just stole a bike belonging to the police chief and so it’s actually being investigated rather than written off. I don’t think they were remotely prepared for this level of scrutiny.
My thoughts exactly. Isn't the tactic to phish multiple potential victims and then they just get email responses from the victims whose data was caught? From the attackers' perspective they could have accidentally made a big catch instead of "targeted critical national infrastructure".
Re: DOJ seizes $2.3M in cryptocurrency paid to the ransomware extortionists Darkside
#180Looks like the criminals used CoinBase: https://twitter.com/thisisbullish/status/1402056137340604418... How amateur is that…
This is one of several pieces I’ve seen claiming things about Coinbase and embedding documents or other evidence that doesn’t seem to come close to supporting the conclusion.
I’m not saying Coinbase wasn’t used and that that didn't have something to do with the seizure, but its being repeatedly claimed with the same kind of evidence presentation that tends to accompany conspiracy theories.