Live data from Hacker News

DarkSide ransomware gang quits after servers, Bitcoin stash seized

krebsonsecurity.com

481–490 of 623 posts

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#481
post #45

It was a mistake to attack the business side of the oil company, because it created what could be sold as reasonable doubt to shut down the pipeline. As a result, the ransom had the optics of an attack on infrastructure. As evidenced by the coverage of Americans desperately filling up containers. This created the impetus for the US to treat this as an incident far and above the ambient ransomware activities leading u…

I got downvoted for saying that maybe it's time to treat serious ransomware attacks (infrastructure, security, health, etc.) as terrorism - as in the sense that they're a threat to the national security. But this kinda shows the response I was referencing to. A lot of people like to think of ransomware attacks as the ultimate stress test as far as security goes, and thus a good thing - but let's not get too blinded b…

"terrorism" is an inconsistent categorization of things that we should just stop using.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#482
post #79

Earlier quoted context omitted.

Until someone cracks it, that is. If it becomes the crypto of choice for some of the bigger fish, you can bet the government will find a way to trace it.

There is at least $625,000[1] on the table already. Not to mention how many blockchain analytics companies and other actors would pay millions to have such a capability. [1] https://www.forbes.com/sites/kellyphillipserb/2020/09/14/irs...

The main reason I bring this up is this is the same promise Tor brought- “completely private” etc. And we all know how that went down: https://www.vice.com/en/article/4x3qnj/how-the-nsa-or-anyone...

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#483
post #69

Earlier quoted context omitted.

I think the question is, how come an attack on a hospital does not have the optics of an attack on infrastructure? (It almost seems oil does not require infrastructure - you can, theoretically, prep for an oil infrastructure outage by storing it containers, same as you do with water and food. But you can't really prep for a medical infrastructure outage. Is it just that, as a result, there were no photos of people ho…

Destroying logistic infrastructure is how you defeat a country. Petroleum is critical to the functioning of modern economies, if you cut that off things go badly. They really kicked the hornets nest on this one.

Indeed: I have to think it was not a planned or desirable outcome to anybody.

If the intended situation is to be able to (for instance) set up a coup attempt on the target country, have it come off well enough to produce chaos, and THEN have your tame cybercriminals knock out key infrastructure, that would be an extremely effective act of war.

Freaking people out while not destroying the target country is a bad, bad misstep. They did indeed kick the hornets' nest, but so ineffectively that the best response would be to try and cover the whole thing up and pretend it was nothing. Might work for some, but I doubt the US government is amused.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#484
post #458

Earlier quoted context omitted.

These guys retweeted the story. They didn’t claim responsibility but it’s a tacit acknowledgment of their involvement. https://en.m.wikipedia.org/wiki/780th_Military_Intelligence_... https://mobile.twitter.com/TheRecord_Media/status/1393192862...

Wow, their motto is “ubique et semper in pugna” - everywhere and always fighting. Scary platform.

Pretty sure they're not the only ones out there doing that

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#485
post #45

It was a mistake to attack the business side of the oil company, because it created what could be sold as reasonable doubt to shut down the pipeline. As a result, the ransom had the optics of an attack on infrastructure. As evidenced by the coverage of Americans desperately filling up containers. This created the impetus for the US to treat this as an incident far and above the ambient ransomware activities leading u…

I got downvoted for saying that maybe it's time to treat serious ransomware attacks (infrastructure, security, health, etc.) as terrorism - as in the sense that they're a threat to the national security. But this kinda shows the response I was referencing to. A lot of people like to think of ransomware attacks as the ultimate stress test as far as security goes, and thus a good thing - but let's not get too blinded b…

No imagination required; this cyberattack on infrastructure masqueraded as ransomware: https://en.wikipedia.org/wiki/Petya_(malware)

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#486
post #148

Earlier quoted context omitted.

Russia allows their FSB operatives to moonlight on the side. Darkside hackers could be government operatives and an attack on critical infrastructure is an act of war. It is the same as bombing the pipeline if infrastructure is disabled. I am sure the cyber insurance provider won’t pay and say it was an act of war by a foreign government. It always a grey area.

Do you have any extraordinary evidence for these extraordinary claims?

Why have them moonlight as hackers when you can get third parties to do what you want? I don't believe for a second that it's an elaborate conspiratorial scheme directed from the top.

It's the same as domestic operations here in the USA: GRU comes up with ways to run loosely controlled groups that are accomplishing roughly the same ends. It's about making the battle space more confusing and unpredictable, and it's been going on for quite some time, very successfully. The soldiers don't report back to central control: they're NOT controlled, they're just loosely directed.

This would be the same. The hackers doing this don't have to be direct agents here, they're sheltered by the Russian state and only need to have some indication of where and what to strike. It's one-way communication, and it's possible to get the desired feedback through things like Facebook and Google Analytics (by paying for it like any ordinary customer).

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#487

Earlier quoted context omitted.

I got downvoted for saying that maybe it's time to treat serious ransomware attacks (infrastructure, security, health, etc.) as terrorism - as in the sense that they're a threat to the national security. But this kinda shows the response I was referencing to. A lot of people like to think of ransomware attacks as the ultimate stress test as far as security goes, and thus a good thing - but let's not get too blinded b…

No imagination required; this cyberattack on infrastructure masqueraded as ransomware: https://en.wikipedia.org/wiki/Petya_(malware)

I will never understand why people link to paid articles in a public forum. There are too many other reliable sources for that exact info for anyone who isn’t wealthy to pay for dumb sites like that.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#488
post #45

It was a mistake to attack the business side of the oil company, because it created what could be sold as reasonable doubt to shut down the pipeline. As a result, the ransom had the optics of an attack on infrastructure. As evidenced by the coverage of Americans desperately filling up containers. This created the impetus for the US to treat this as an incident far and above the ambient ransomware activities leading u…

I got downvoted for saying that maybe it's time to treat serious ransomware attacks (infrastructure, security, health, etc.) as terrorism - as in the sense that they're a threat to the national security. But this kinda shows the response I was referencing to. A lot of people like to think of ransomware attacks as the ultimate stress test as far as security goes, and thus a good thing - but let's not get too blinded b…

I'd say ransomware is much closer to "piracy" than terrorism, but totally agree that this incident shows there's not much distance between this and cyber terrorism. (Even if it's just criminals accidentally throwing themselves into the spotlight.)

For say a nation engaging in cyber war, this could be flipped around: attacking basic infrastructure but disguising it as smaller groups of criminals trying to make a buck. Not sure how effective the disguise would be, but it could obviously do some serious damage.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#489
post #266

Earlier quoted context omitted.

Terrorism is a non-state use of violence for political aims. Ransomware is non-state, not violent, and is done for economic, not political aims.

Ransomware is non-state Are there no ransomware operations linked to North Korea? I was under the impression that there was some level of activity there to maintain supplies of globally-usable currency.

North Korea is... A special case, and it is still quite unlike any other country in the world.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#490

Earlier quoted context omitted.

The fact that their coins were apparently easily stolen also debunks another favourite talking point of the crypto people that it secures your money from government access. Clearly, ways and means have been developed to do just that if necessary.

Or one of the members of the criminal gang ran off with all the cryptocurrency and then made a public post claiming some form of law enforcement seized the crypto.

Haha, exactly this. The crypto meme is "I lost it all in a boating accident".
Post reply on HN