Live data from Hacker News

DOJ seizes $2.3M in cryptocurrency paid to the ransomware extortionists Darkside

justice.gov

41–50 of 296 posts

Re: DOJ seizes $2.3M in cryptocurrency paid to the ransomware extortionists Darkside

#41
post #35

Earlier quoted context omitted.

It always struck me as improbable that all these high profile (and notoriously hard/impossible to attribute) attacks on “critical infrastructure” or whatever are always instantly and authoritatively pinned (by US authorities) on groups operating in the US’s geopolitical enemies. “Russian hackers” once again, eh?

You find it improbable that geopolitical enemies tend to be the ones that attack us? Feels like saying "I find it weird that people I insult disproportionately punch me in the face".

I think you are assigning too much “us vs them” to the ransomware marketplace.

With ransomware criminals, “us” is the attacker, and “them” is everyone with a computer who might pay. Political boundaries don’t factor in to it at all. It is by nature an anonymous attack, hence the term “ransom”.

It is strange to me that almost all high-profile ransomware attacks that have been publicized in the US are claimed by the FBI to be Russian or Chinese. There are plenty of other countries with greedy criminals that know software, too.

Re: DOJ seizes $2.3M in cryptocurrency paid to the ransomware extortionists Darkside

#42

Earlier quoted context omitted.

No, they’re not elite, they’re just script kiddies with a payout mechanism.

"Script kiddies" got their name because 20 years ago any kid could download some code and create a DDoS attack by running a pre-written script. Ransomware hacks seem a bit more sophisticated, even with today's highly modular malware. I think it is an interesting proposal: a fake attack as shown by the disparity in savvy between the attack and the payment, or a really dumb screw up. EDIT: as "koheripbal" says below, m…

How much sophistication does it take to attack a computer system running software that hasn’t been patched in years?

Re: DOJ seizes $2.3M in cryptocurrency paid to the ransomware extortionists Darkside

#43
post #39

Earlier quoted context omitted.

The press release specifically mentions that the cryptocurrency was seized through FBI having posession of the private key.

As someone who has been on the receiving end of federal seizure orders for cryptocurrency private keys, they were in my case satisfied by publishing a transfer (signature) to a USG address, not actual disclosure of private key material, despite that being explicitly stated in the order.

This indicates a level of US Fed LEO technical sophistication I’m somewhat pleased to hear exists.

Re: DOJ seizes $2.3M in cryptocurrency paid to the ransomware extortionists Darkside

#44
post #6

Earlier quoted context omitted.

Netsec Twitter's theory is that the attacker(s) had a VPS operating in the US that the FBI was able to access and which contained the key to the wallet where the final payment ended up.

I am by far no ransomware expert, but it really seems like amateur hour if they were running a Linux based Bitcoin full node using the mainline CLI daemon and client, with a wallet, on some hosting company geographically within the United States. Why would it need to be in the US?

I only know a few criminal hackers, but within that sample their skillset is really niche. They know what they know well, but otherwise they're just trying to solve problems like any engineer.

Kinda like data scientists - they can be masters with a couple of libraries and concepts, but if you have a data science team you also are more or less guaranteed to have a jupyter notebook open to the world, or something along those lines.

Re: DOJ seizes $2.3M in cryptocurrency paid to the ransomware extortionists Darkside

#45
post #39

Earlier quoted context omitted.

As someone who has been on the receiving end of federal seizure orders for cryptocurrency private keys, they were in my case satisfied by publishing a transfer (signature) to a USG address, not actual disclosure of private key material, despite that being explicitly stated in the order.

This indicates a level of US Fed LEO technical sophistication I’m somewhat pleased to hear exists.

Either that or they just approached it like a bank account and simply wanted the money and didn’t care about the cryptographic specifics whatsoever.

Re: DOJ seizes $2.3M in cryptocurrency paid to the ransomware extortionists Darkside

#46
post #41

Earlier quoted context omitted.

You find it improbable that geopolitical enemies tend to be the ones that attack us? Feels like saying "I find it weird that people I insult disproportionately punch me in the face".

I think you are assigning too much “us vs them” to the ransomware marketplace. With ransomware criminals, “us” is the attacker, and “them” is everyone with a computer who might pay. Political boundaries don’t factor in to it at all. It is by nature an anonymous attack, hence the term “ransom”. It is strange to me that almost all high-profile ransomware attacks that have been publicized in the US are claimed by the FB…

When your government greenlights criminal activities against their enemies it helps a lot. Many* cyber criminals act as mercs for hire, and are in fact hired for official government operations against the US.

It's simply not true that political boundaries don't factor in. They're a massive part - most obviously, consider extradition or whether the attacker's government will cooperate with the US.

* I say many, but it's more like "it happens", but it feels important to point out.

Re: DOJ seizes $2.3M in cryptocurrency paid to the ransomware extortionists Darkside

#47
post #24

This story makes absolutely no sense at all. The errors present by these hackers are so comical it's simply unbelievable. I'm supposed to believe some elite Russian hacking group keeps their crypto wallets running on a US host where the FBI just logs right in and snatches the private key? I'm starting to entertain the conspiracies that the future of commodities price manipulation is fake ransomware attacks. There nee…

This could have been far downstream from the hackers themselves. They might just have been monitoring the bitcoins and waiting for some to land in one of many addresses for which they have the private key. Presumably FBI is continuously scooping up whatever private keys they can.

Re: DOJ seizes $2.3M in cryptocurrency paid to the ransomware extortionists Darkside

#48
post #28
post #24

This story makes absolutely no sense at all. The errors present by these hackers are so comical it's simply unbelievable. I'm supposed to believe some elite Russian hacking group keeps their crypto wallets running on a US host where the FBI just logs right in and snatches the private key? I'm starting to entertain the conspiracies that the future of commodities price manipulation is fake ransomware attacks. There nee…

I was reading the article in utter confusion too. I personally think it's the authorities trying to save face, as I don't think even a computer-literate high school kid would make these mistakes.

"Save face" for whom? It wasn't the US gov who got hacked or paid the ransom, it was the Colonial Pipeline Company.

Re: DOJ seizes $2.3M in cryptocurrency paid to the ransomware extortionists Darkside

#49
post #24

This story makes absolutely no sense at all. The errors present by these hackers are so comical it's simply unbelievable. I'm supposed to believe some elite Russian hacking group keeps their crypto wallets running on a US host where the FBI just logs right in and snatches the private key? I'm starting to entertain the conspiracies that the future of commodities price manipulation is fake ransomware attacks. There nee…

They can’t be very elite if even I know the following would absolutely work.

Run bitcoin through tumbler -> convert to Monero -> run through tumbler again -> convert to eth -> cash out

Re: DOJ seizes $2.3M in cryptocurrency paid to the ransomware extortionists Darkside

#50
post #48
post #28

Earlier quoted context omitted.

I was reading the article in utter confusion too. I personally think it's the authorities trying to save face, as I don't think even a computer-literate high school kid would make these mistakes.

"Save face" for whom? It wasn't the US gov who got hacked or paid the ransom, it was the Colonial Pipeline Company.

The US Judicial system which tries to flex its "unlimited" reach.
Post reply on HN