I found it interesting none of these sites actually provided the alleged bitcoin wallet address. I found it @ https://www.blockchain.com/btc/address/13nmJ3SsNB5pSyQrmX3e6...
US travel firm $4.5M ransom negotiation open chat
211–220 of 480 posts
Re: US travel firm $4.5M ransom negotiation open chat
#212Earlier quoted context omitted.
Isn't this likely short sighted in the same way that people talk about draconic enforcement of immigration laws? Criminalizing ransoms will result in victims doing it in secret, not in the elimination of ransoms. People won't be able to share information, and the financial incentive will continue to exist.
If you were a corporate executive would you risk hard prison time just to save your employer from taking a loss? The whole point of imposing draconian penalties is to make such attacks unprofitable. If the attackers know they won't be able to extract any money from victims then they'll move on to some other scheme.
Uh, have you looked at all the corporate scandals of the last, say, 40 years?
White collar execs never do hard time anyway. At the absolute worst they get 6 months at some cushy minimum security... aka Club Fed.
Re: US travel firm $4.5M ransom negotiation open chat
#213Earlier quoted context omitted.
I'm just looking at how it is currently used. If after all these years there isn't a positive use-case to offset it, there might not be one at all.
That's because you live in a country with a functioning currency.
Most of these countries barely have a stable internet connection or even stable electrical power, so I wouldn't surprised if these 'currencies' aren't so helpful in practice.
* Note that use by corrupt politicians to launder their ill-gotten gains is not a positive.
Re: US travel firm $4.5M ransom negotiation open chat
#214Earlier quoted context omitted.
Do you not tie yourself to your Bitcoin when you try to use it for something physical like turning it into cash or buying a physical asset? Can you not track all Bitcoins going in and out of a mixer?
If you understand enough about Bitcoin to know how the immutable ledger works, your questions feel bad faith. One of the biggest “selling points” early on was obviously anonymity.
Re: US travel firm $4.5M ransom negotiation open chat
#215Earlier quoted context omitted.
When you use a mixer, there’s a delay between when you put your money in and when it comes back out. The mixing service randomly splits up the transaction into batches and sends them out at different times. So even if you know that somebody sent to a mixer (perhaps as an investigator you could find out mixer addresses by sending lots of transactions to the mixer service yourself), you wouldn’t be able to associate th…
Wouldn't using multiple mixers increase the risk? You only need to be traced once.
Re: US travel firm $4.5M ransom negotiation open chat
#216Earlier quoted context omitted.
>This kind of attack would be almost impossible in the pre-bitcoin era. Is it? VIPs are regularly held for ransom in unstable countries, so much so that ransom insurance is a thing[1]. If those ransoms can be safely received, why can't it be the case for ransomware ransoms? [1] https://en.wikipedia.org/wiki/Kidnap_and_ransom_insurance
I don't see how the two are similar, because traditional kidnapping/ransom requires someone to somehow take physical delivery of a ransom in cash or highly portable, dense valuables (gold bars etc), which is risky. They're certainly not going to do it by ACH or SWIFT. The bitcoin part makes it non tangible and could be done from anywhere in the world.
It streamslines it, yes, but it doesn't make it "almost impossible" to pull off like gp claims. Russia is listed as a "high risk" area in the wikipedia article for ransoms, so if they can pull off a ransom exchange (with human hostages) there, I can totally imagine russian hackers being able to pull off a ransom exchange with cryptographic keys. If anything, it's probably easier to pull off than a regular ransom because you don't have to contend with a human hostage.
Also, a quick skim of wikipedia[1] suggests that buying/selling of stolen credit card info predates the creation of cryptocurrency. If cybercriminals were able to find ways of transferring money back then, I'm sure ransomware authors can use the same methods to transfer money today.
[1] https://en.wikipedia.org/wiki/Credit_card_fraud -> https://en.wikipedia.org/wiki/Albert_Gonzalez -> https://en.wikipedia.org/wiki/ShadowCrew
Re: US travel firm $4.5M ransom negotiation open chat
#217Re: US travel firm $4.5M ransom negotiation open chat
#218Earlier quoted context omitted.
Wouldn't using multiple mixers increase the risk? You only need to be traced once.
I would not split your transaction between mixers, but instead mix your entire amount through one, then mix all of the outputs through others. Use multiple mixers in series, not in parallel. Compromising one mixer there would associate the inputs and outputs of that step but wouldn’t associate your initial input with your final output. You’d also want to conceal your ip at every step so you don’t get compromised that…
Perhaps they might do this if the saw keeping the entire 4m as much more lucrative than many years of taking the percentage skimmed off the top from a number of smaller transactions, and just going into "retirement".
Re: US travel firm $4.5M ransom negotiation open chat
#219Earlier quoted context omitted.
Take backups, practice restoring them, invest in a security program.
Just having backups isn't enough. It's ransomware 101 to wait and try to encrypt all of their online backups and any recent offline backups. You really need comprehensive, air-gapped backups that date to years back.
Re: US travel firm $4.5M ransom negotiation open chat
#220Earlier quoted context omitted.
https://en.wikipedia.org/wiki/Cryptocurrency_tumbler
What happens when crypto tumblers run away with the money