Live data from Hacker News

DOJ seizes $2.3M in cryptocurrency paid to the ransomware extortionists Darkside

justice.gov

31–40 of 296 posts

Re: DOJ seizes $2.3M in cryptocurrency paid to the ransomware extortionists Darkside

#31
post #24

This story makes absolutely no sense at all. The errors present by these hackers are so comical it's simply unbelievable. I'm supposed to believe some elite Russian hacking group keeps their crypto wallets running on a US host where the FBI just logs right in and snatches the private key? I'm starting to entertain the conspiracies that the future of commodities price manipulation is fake ransomware attacks. There nee…

No, they’re not elite, they’re just script kiddies with a payout mechanism.

"Script kiddies" got their name because 20 years ago any kid could download some code and create a DDoS attack by running a pre-written script. Ransomware hacks seem a bit more sophisticated, even with today's highly modular malware. I think it is an interesting proposal: a fake attack as shown by the disparity in savvy between the attack and the payment, or a really dumb screw up.

EDIT: as "koheripbal" says below, maybe their tumbler is a boob (paraphrased).

Re: DOJ seizes $2.3M in cryptocurrency paid to the ransomware extortionists Darkside

#32
post #14

Earlier quoted context omitted.

A private key is not needed if the funds are on an exchange. Apparently there is a warrant to seize property on Northern California so I guess it might be Coinbase. And yeah... if the crackers sent the funds to an exchange they were comically dumb.

The warrant does not imply that the coins were on an exchange. The warrant only indicates that they needed legal authority to seize coins, wherever they are. It seem more likely that the FBI/NSA had and gained some access to the gang's infrastructure and seized the money. Transmitting ransom money to an exchange without any type of tumbler or atomic swapping, that it's not a realistic scenario. Maybe they tried to us…

The warrant is for a location in Northern California and they needed a warrant to get it.

Use your head man, this means they literally went to a Federal Judge and said "hey we have probable cause that this address is on Coinbase" and the Judge was like "wow that is pretty probable" and then they took the warrant to Coinbase who was like "oh damn that's legit ..... can we squirm out of dealing with this .... no ... oh wow that is our address too, okay here is the private key" and then the FBI transferred it

Re: DOJ seizes $2.3M in cryptocurrency paid to the ransomware extortionists Darkside

#33
post #14

Earlier quoted context omitted.

A private key is not needed if the funds are on an exchange. Apparently there is a warrant to seize property on Northern California so I guess it might be Coinbase. And yeah... if the crackers sent the funds to an exchange they were comically dumb.

The press release specifically mentions that the cryptocurrency was seized through FBI having posession of the private key.

To the previous poster's point: it didn't say which private key. There can be multiple with cloud storage.

Re: DOJ seizes $2.3M in cryptocurrency paid to the ransomware extortionists Darkside

#34
post #4

There are more technical details in the linked affidavit (page 6 and 7): https://www.justice.gov/opa/press-release/file/1402056/downl... They kept following transactions on the blockchain, but it's not clear how the private key became in the posession of the FBI.

>Based on ... I have probable cause to believe that the aforementioned property may be seized...

Forgive me if this is a dumb question; I have not used a blockchain explorer for anything consequential. Isn't that wallet just the last place it ended up? So, you have chain of custody but does that prove that the owner of that wallet is the "target"?

Re: DOJ seizes $2.3M in cryptocurrency paid to the ransomware extortionists Darkside

#35
post #24

This story makes absolutely no sense at all. The errors present by these hackers are so comical it's simply unbelievable. I'm supposed to believe some elite Russian hacking group keeps their crypto wallets running on a US host where the FBI just logs right in and snatches the private key? I'm starting to entertain the conspiracies that the future of commodities price manipulation is fake ransomware attacks. There nee…

It always struck me as improbable that all these high profile (and notoriously hard/impossible to attribute) attacks on “critical infrastructure” or whatever are always instantly and authoritatively pinned (by US authorities) on groups operating in the US’s geopolitical enemies.

“Russian hackers” once again, eh?

Re: DOJ seizes $2.3M in cryptocurrency paid to the ransomware extortionists Darkside

#36
post #6

Earlier quoted context omitted.

Netsec Twitter's theory is that the attacker(s) had a VPS operating in the US that the FBI was able to access and which contained the key to the wallet where the final payment ended up.

The FBI doesn't need the VPS to be in the United States for that The FBI specifically has had expanded Congressional authority for like 10 years to operate extraterritorially on cyber matters FBI agents will show up physically in any country and request cooperation from local municipal police (maybe) to seize electronic property as well as affect arrests in a way compliant with both jurisdictions. Given that private…

I want to see hoe "FBI agents will show up" in Russia. Or China. I giggled.

Re: DOJ seizes $2.3M in cryptocurrency paid to the ransomware extortionists Darkside

#37
post #24

This story makes absolutely no sense at all. The errors present by these hackers are so comical it's simply unbelievable. I'm supposed to believe some elite Russian hacking group keeps their crypto wallets running on a US host where the FBI just logs right in and snatches the private key? I'm starting to entertain the conspiracies that the future of commodities price manipulation is fake ransomware attacks. There nee…

Also completely baffled how the feds got access to the private key and why an elite Russian hacking group would store their crypto on a US based server.

At the same time, the obvious tin foil hat answer of it was the feds who concocked the entire scheme also doesn't add up. If the NSA/CIA was behind it, they would be smart enough to not use a US based server / wallet. That makes the story inconsistent, and brings up the questions I am asking here. Instead, they would just use a clean wallet (preferably out of Russia). I.E. the misdirection and misinformation does not add up if it was an "inside job" by the US government.

Re: DOJ seizes $2.3M in cryptocurrency paid to the ransomware extortionists Darkside

#38
post #24

This story makes absolutely no sense at all. The errors present by these hackers are so comical it's simply unbelievable. I'm supposed to believe some elite Russian hacking group keeps their crypto wallets running on a US host where the FBI just logs right in and snatches the private key? I'm starting to entertain the conspiracies that the future of commodities price manipulation is fake ransomware attacks. There nee…

Who says they're elite? I know that ironically many hackers have poor security practices themselves.

Re: DOJ seizes $2.3M in cryptocurrency paid to the ransomware extortionists Darkside

#39
post #14

Earlier quoted context omitted.

A private key is not needed if the funds are on an exchange. Apparently there is a warrant to seize property on Northern California so I guess it might be Coinbase. And yeah... if the crackers sent the funds to an exchange they were comically dumb.

The press release specifically mentions that the cryptocurrency was seized through FBI having posession of the private key.

As someone who has been on the receiving end of federal seizure orders for cryptocurrency private keys, they were in my case satisfied by publishing a transfer (signature) to a USG address, not actual disclosure of private key material, despite that being explicitly stated in the order.

Re: DOJ seizes $2.3M in cryptocurrency paid to the ransomware extortionists Darkside

#40
post #35
post #24

This story makes absolutely no sense at all. The errors present by these hackers are so comical it's simply unbelievable. I'm supposed to believe some elite Russian hacking group keeps their crypto wallets running on a US host where the FBI just logs right in and snatches the private key? I'm starting to entertain the conspiracies that the future of commodities price manipulation is fake ransomware attacks. There nee…

It always struck me as improbable that all these high profile (and notoriously hard/impossible to attribute) attacks on “critical infrastructure” or whatever are always instantly and authoritatively pinned (by US authorities) on groups operating in the US’s geopolitical enemies. “Russian hackers” once again, eh?

You find it improbable that geopolitical enemies tend to be the ones that attack us? Feels like saying "I find it weird that people I insult disproportionately punch me in the face".
Post reply on HN