Live data from Hacker News

DOJ seizes $2.3M in cryptocurrency paid to the ransomware extortionists Darkside

justice.gov

191–200 of 296 posts

Re: DOJ seizes $2.3M in cryptocurrency paid to the ransomware extortionists Darkside

#191

I am guessing that the key pair generation process was faulty. The FBI found an exploit in a wallet used by the hackers allowing the private key to be predicted. The prefix is bc1,which is uncommon. A few weeks ago there was such a vulnerability with Cake Wallet. Or they installed malware on the hacker's computers and were able to log the private key as it was generated. Or the hackers foolishly stored the key pairs…

bc1 isn't an uncommon prefix, its a bech32 native segwit address that's been in use for years now (IIRC 1 and 3 are the other prefixes, 1 being the first and most popular and 3 being a backwards compatible segwit address, i.e. non native). Stats: https://txstats.com/dashboard/db/bech32-statistics?orgId=1

faulty key pairs being generated is a well known issue with poorly developed wallets, not with Bitcoin itself. None of the popular wallets have this issue so it doesn't undermine Bitcoin.

Re: DOJ seizes $2.3M in cryptocurrency paid to the ransomware extortionists Darkside

#193
post #149

Here is the FBI controlled address, presumably a Coinbase deposit address https://www.blockchain.com/btc/address/bc1qq2euq8pw950klpjca... Which got funds from https://www.blockchain.com/btc/address/3EYkxQSUv2KcuRTnHQA8t... This is the wallet explorer used for clustering the wallet https://www.walletexplorer.com/wallet/123085fff68ee703/addre... I have no idea why they censored out parts of the bitcoin addresses as goo…

Nope https://twitter.com/SecurityGuyPhil/status/14020799720601313...

Re: DOJ seizes $2.3M in cryptocurrency paid to the ransomware extortionists Darkside

#195
post #102

Earlier quoted context omitted.

I'm guessing the rest was fees/etc coming out of the crypto tumblers they used?

They didn't use any tumblers, that's how they got caught. edit: it says so in the article: As alleged in the supporting affidavit, by reviewing the Bitcoin public ledger, law enforcement was able to track multiple transfers of bitcoin and identify that approximately 63.7 bitcoins, representing the proceeds of the victim’s ransom payment, had been transferred to a specific address

They could also get caught if say, authorities hacked the computers they were using to execute the Bitcoin tumbler "trades" (or whatever the terminology is)... or used similar means to gain access to a list of crypto wallets they owned along with their passwords.

Re: DOJ seizes $2.3M in cryptocurrency paid to the ransomware extortionists Darkside

#196
post #41

Earlier quoted context omitted.

I think you are assigning too much “us vs them” to the ransomware marketplace. With ransomware criminals, “us” is the attacker, and “them” is everyone with a computer who might pay. Political boundaries don’t factor in to it at all. It is by nature an anonymous attack, hence the term “ransom”. It is strange to me that almost all high-profile ransomware attacks that have been publicized in the US are claimed by the FB…

That might be easier to believe if these ransomware strains didn't do things like automatically disable themselves on computers with Russian language support installed.

Yes, nobody in the west using a compromised russian box for c&c would ever put such code in their ransomware payload. That would obfuscate its origin, and we all know criminals aren't clever enough for that sort of thing.

There can only be one explanation: russian hackers operating with Putin's tacit approval. Us in the west should add this to the mounting pile of "evidence" supporting going into another cold war, because that will surely improve the entire situation. Attributing the unattributable to our preconceived enemies to escalate a conflict always ends well.

Snark aside, on a technical, factual level, this simply isn't evidence of origin, not even a little bit. "russian hackers" is such a tired punchline now that if I, being in the west, were to suddenly jump the fence after 3 decades and choose A Life Of Crime, using russian configuration file names, UTC+3 daytime operating hours, russian-hosted c&c IPs (or, better yet, russia-controlled but plausibly deniable ones like belarus or kazakhstan), and silly stuff like skipping infection of ru-locale machines would be obvious things I would be doing to fuel this existing narrative sailwind. It's utterly silly to think that this in any way suggests origin.

Re: DOJ seizes $2.3M in cryptocurrency paid to the ransomware extortionists Darkside

#197
post #24

This story makes absolutely no sense at all. The errors present by these hackers are so comical it's simply unbelievable. I'm supposed to believe some elite Russian hacking group keeps their crypto wallets running on a US host where the FBI just logs right in and snatches the private key? I'm starting to entertain the conspiracies that the future of commodities price manipulation is fake ransomware attacks. There nee…

The Occam Razor principle [1], likely needs to be completely reversed when dealing with Instutitional Propaganda sources.

Meaning that the typical interpretation of the principle that the 'most simple explanation' is probably correct -- needs to be reversed.

Meaning that when reading the propaganda agencies -- the view should be, the 'simple most straightforward explanation of highly visible events -- is probably not the right explanation'

In this case, you have to decide if the sources you are hearing the info from are the 'Institutional Propaganda' sources or not.

With regards to bitcoin, I think its present aquired value -- is in the safety and correctness of the system -- without any human law enforcement and judicial arbitration. If the above premises are broken -- it would loose its value.

[1] https://en.wikipedia.org/wiki/Occam%27s_razor

Re: DOJ seizes $2.3M in cryptocurrency paid to the ransomware extortionists Darkside

#198

Earlier quoted context omitted.

Hacker gangs also apparently lose 2.4 million dollars at the drop of a hat, which is something that no security consultant ever has to worry about.

> which is something that no security consultant ever has to worry about There's enough self-styled cypherpunk infosec experts that might insist on being paid only in BTC and then lose their decrypted wallet...

They could also be paid in cash, use that to buy BTC and then lose their wallet. It's a random problem, not related to receiving valid payment for legitimate work.

Re: DOJ seizes $2.3M in cryptocurrency paid to the ransomware extortionists Darkside

#200

Looks like the criminals used CoinBase: https://twitter.com/thisisbullish/status/1402056137340604418... How amateur is that…

That refers to the concept of coinbase, not coinbase the company. It's a technical term on the blockchain for the coins dispensed to the miner.
Post reply on HN