Live data from Hacker News

DarkSide ransomware gang quits after servers, Bitcoin stash seized

krebsonsecurity.com

421–430 of 623 posts

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#421
post #397
post #349

Earlier quoted context omitted.

I actually laughed out loud reading this, These guys are giving ransomware a bad name , ahahaha, what?!

I read it as more of a “they’ve ruined it for the rest of us” whinge.

It's absolutely that, yeah. These guys were making fat stacks licensing out their Ransomware-as-a-Service package; now, since a customer flew too close to the sun/U.S. government, they're fucked.

Tragedy of the commons? Sort of? Not really?

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#422
post #43

> The REvil representative said its program was introducing new restrictions on the kinds of organizations that affiliates could hold for ransom, and that henceforth it would be forbidden to attack those in the “social sector” (defined as healthcare and educational institutions) and organizations in the “gov-sector” (state) of any country. Affiliates also will be required to get approval before infecting victims. Sta…

>I do wonder if ransomware is (in a strange way) a(n illegal) free-market response to what is perceived to be an under-valuation of tech skills - aggrieved people who can carry out attacks and gain access to deploy ransomware are likely to be able to earn more through this route, even factoring in their "risk of being caught".

Almost all crime syndicates work this way. There is a balancing point where the crime you do does enough damage to make you money, but not so much money that the government dedicates elites to come knocking on your door. What DarkSide did was veer too far in the wrong direction.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#423

Earlier quoted context omitted.

How does the scam work ? You got me curious...

Ball gets placed under one of three cups. Cups get mixed around and people guess where the ball is for money. The ball isn’t under any of them though. The scammer palmed it.

Each round is double or nothing. The victim wins the first few rounds, but he starts losing after the scammer starts hiding the ball instead of putting it under a cup. The victim keeps doubling on, thinking they will eventually win, but it never happens.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#424

Earlier quoted context omitted.

There is billions of dollars of value in BTC sitting in wallets as an open bounty for anyone who can hack private keys. So which of the following is most likely: - the government has a tool that can break private key encryption and used it to confiscate a hacker groups funds OR - whoever controls the groups wallet transferred it out and is on the run

OR Someone got a little sloppy on their payment processing server (also seized) or with maintaining separate wallets and control of that server allowed sending of payments to an account specified by whoever was in control - likely since the server was for paying affiliates.

Right, which has nothing to do with blockchain security itself, and more to do with implementation of private keys.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#425

Earlier quoted context omitted.

Its been said before: "When the system fails you, you create your own system." Which relates to what you're saying. When clever, intelligent people are ostracized and marginalized, they then use those skills to get illegally what society has prevented them from getting legally. At some point, the idea of getting caught doesn't even register anymore.

Were these people ostracized and marginalized? If we just paid engineers more would this type of crime disappear? Or is greed, ego, arrogance also a part of their actions?

>> Were these people ostracized and marginalized?

We probably will never know. A lot of hackers turn to hacking because of various reasons - some ideological, others because they felt they didn't fit in anywhere else.

>> If we just paid engineers more would this type of crime disappear?

Probably not. You cannot get rid of one type of crime by simply paying people NOT to do it. It is what is - at no time in human history has any civilization had zero crime. That's regardless of punishments and financial incentives.

>> Or is greed, ego, arrogance also a part of their actions?

I think its different things at different times. When I was hacking, it was arrogance, thinking I was smarter than others and trying to prove it. That leads to thinking you are beyond law enforcement when you get away with it (ego). If you're into it solely for financial gain, then the other two feed your greed. Get one nice payout for your ransomware and now you think its easy to do and you'll never be caught - increasing your greed to get more.

They all kind of play into each other:

arrogance: "I'll never get caught."

ego: "They'll never catch me, my ops sec is too good for law enforcement."

greed: "This was too easy, next time I'll target a bigger company for a bigger payout."

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#426

Earlier quoted context omitted.

On the high seas of the Internet there is a thin line between pirates and state actors. There could even be "privateer" ( https://en.wikipedia.org/wiki/Privateer ) attackers who work for a nation and for profit at the same time. From the victim's perspective it matters less who is attacking you or why they are attacking you and much more what the results of the attack are, how you can mitigate and recover from the da…

Just causing terror doesn't make it terrorism. Causing terror as a means to further some political (or religious) goal would make it terrorism.

Not sure why you're getting downvoted. That's literally the Oxford dictionary definition.

https://www.google.com/search?q=define+terrorism

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#427

Earlier quoted context omitted.

> seem to point to ransomware activities being far more coordinated and "business-like" than they often get credit for. This is a business that actually provides better support than a regular business. From conversations with friends in the Infragard side of this, and the agencies that collaborate, they have 24/7 English support available before and after payment, as well as decryption remote support if you can't get…

> This is a business that actually provides better support than a regular business. The thing I find fascinating from a sociology perspective about ransomware is that they have to. To be a successful ransomware company, you have to simultaneously be: 1. Completely immoral enough to attack companies, hold their data ransom and potentially put them out of business and reveal the private details of thousands of people.…

In a cynical telling this is how you start a government or any organization with a monopoly on violence, ala mafia. First you make it clear that you can cause damage, then you make it clear that tax payers are safe. The next step for ransomware companies is to offer cyber security services, whether you want them or not. We've hacked you. We fixed your crappy unpatched software, if you try to remove us you lose all your data, so now we're your cyber security partners.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#428

Earlier quoted context omitted.

You could even send ETH to the Secret Network and perform token swaps and then send it back to a clean address.

Yes, even better because the smart contract execution is private and all the variables (receiver, quantity) are only temporarily stored with the validator’s SGX chips and not onchain. Less liquidity there, for now. Meaning the exits would more likely be the same beneficial owner, but definitely an additional route for liquidity. Similarly, I think there should be a version of Tornado.cash that stores notes in SGX and…

Also note: I would still say having a record of trading gains would still be better whether using an EVM+Tornado or Secret Network, as this is much easier to account for than never accounting for the obfuscated funds or trying to further obfuscate and reintegrate with front businesses

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#429

Earlier quoted context omitted.

Critical Infrastructure as Govt defines it https://www.cisa.gov/critical-infrastructure-sectors

I'm not sure what point this comment is trying to make, according to CISA emergency services are a critical infrastructure sector. Therefore attacks on hospitals are attacks on critical infrastructure just like a pipeline.

  Five distinct disciplines compose the ESS, encompassing a wide range of emergency response functions and roles:
* Law Enforcement

* Fire and Rescue Services

* Emergency Medical Services

* Emergency Management

* Public Works

Emergency Medical Services ≠ Hospital

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#430

Earlier quoted context omitted.

Just causing terror doesn't make it terrorism. Causing terror as a means to further some political (or religious) goal would make it terrorism.

With that definition this is explicitly not terrorism, because it was for money not for political or religious reasons?

Yes. Its an important distinction because they are fundamentally different motives. If the motive is money, various strategies can drive up the cost until the behavior is no longer profitable and the bad actors stop. Religion and ideology are completely different beasts and most strategies that work on profiteers only entrench the others.
Post reply on HN