Live data from Hacker News

DOJ seizes $2.3M in cryptocurrency paid to the ransomware extortionists Darkside

justice.gov

91–100 of 296 posts

Re: DOJ seizes $2.3M in cryptocurrency paid to the ransomware extortionists Darkside

#91
post #24

This story makes absolutely no sense at all. The errors present by these hackers are so comical it's simply unbelievable. I'm supposed to believe some elite Russian hacking group keeps their crypto wallets running on a US host where the FBI just logs right in and snatches the private key? I'm starting to entertain the conspiracies that the future of commodities price manipulation is fake ransomware attacks. There nee…

Who says they're elite? I know that ironically many hackers have poor security practices themselves.

I encountered this myself. I was hit by a browse-and-get-owned zero day. I found out one day later from a blog post, where an anonymous person had hacked the command and control server and wiped the hacker's database in a remarkably brief time. Clearly, their skills were not on par.

The responsible vulnerability was in Java applets, which I had disabled for security reasons. But Java secretly re-enabled itself after updating. I kept Java uninstalled for a long time after that.

Re: DOJ seizes $2.3M in cryptocurrency paid to the ransomware extortionists Darkside

#92
post #4

There are more technical details in the linked affidavit (page 6 and 7): https://www.justice.gov/opa/press-release/file/1402056/downl... They kept following transactions on the blockchain, but it's not clear how the private key became in the posession of the FBI.

This is why all these gangs will now switch to Monero the moment they get BTC paid.

Re: DOJ seizes $2.3M in cryptocurrency paid to the ransomware extortionists Darkside

#93
post #14

Earlier quoted context omitted.

A private key is not needed if the funds are on an exchange. Apparently there is a warrant to seize property on Northern California so I guess it might be Coinbase. And yeah... if the crackers sent the funds to an exchange they were comically dumb.

The warrant does not imply that the coins were on an exchange. The warrant only indicates that they needed legal authority to seize coins, wherever they are. It seem more likely that the FBI/NSA had and gained some access to the gang's infrastructure and seized the money. Transmitting ransom money to an exchange without any type of tumbler or atomic swapping, that it's not a realistic scenario. Maybe they tried to us…

Why not?

Why would you assume an attacker uses all of the best cloaking tactics?

This doesn't seem like a complex attack at all: monitor common 0 day vuln feeds, attack, install off the shelf ransomware sold by 5$.

It might as well have been a script kiddie.

Re: DOJ seizes $2.3M in cryptocurrency paid to the ransomware extortionists Darkside

#94
post #42

Earlier quoted context omitted.

"Script kiddies" got their name because 20 years ago any kid could download some code and create a DDoS attack by running a pre-written script. Ransomware hacks seem a bit more sophisticated, even with today's highly modular malware. I think it is an interesting proposal: a fake attack as shown by the disparity in savvy between the attack and the payment, or a really dumb screw up. EDIT: as "koheripbal" says below, m…

How much sophistication does it take to attack a computer system running software that hasn’t been patched in years?

Many so called "professionals" are still running operations with 5+ year old distributions that haven't been patched in almost as many years, and servers that people are afraid to reboot. I was once contracted by a company that was literally afraid to have any employees reboot a server because they had no idea how it worked, if it would come back up, and what to do if something didn't restart. They wanted an outside guy to take the blame.

Re: DOJ seizes $2.3M in cryptocurrency paid to the ransomware extortionists Darkside

#95
post #6
post #4

There are more technical details in the linked affidavit (page 6 and 7): https://www.justice.gov/opa/press-release/file/1402056/downl... They kept following transactions on the blockchain, but it's not clear how the private key became in the posession of the FBI.

Netsec Twitter's theory is that the attacker(s) had a VPS operating in the US that the FBI was able to access and which contained the key to the wallet where the final payment ended up.

The connections need to pass through the US just once in order to give the US a chance to attack it.

Since they created the internet, they have field advantage. It's almost impossible not to use a US based provider, it goes as deep as ipv4 distribution.

Re: DOJ seizes $2.3M in cryptocurrency paid to the ransomware extortionists Darkside

#96
post #90
post #24

This story makes absolutely no sense at all. The errors present by these hackers are so comical it's simply unbelievable. I'm supposed to believe some elite Russian hacking group keeps their crypto wallets running on a US host where the FBI just logs right in and snatches the private key? I'm starting to entertain the conspiracies that the future of commodities price manipulation is fake ransomware attacks. There nee…

Also, how exactly do you "seize" cryptocurrency without hard forking it?

They send it to another wallet/account that they control. Not hard to understand.

Re: DOJ seizes $2.3M in cryptocurrency paid to the ransomware extortionists Darkside

#97
post #76
post #68

Earlier quoted context omitted.

I wondered the same thing, so I went looking for answers and found this excellent video by 3Blue1Brown: How secure is 256 bit security? : https://www.youtube.com/watch?v=S9JGmA5_unY

Really informative video but this is talking about hashing functions. Private keys are created differently using (some) shared information between the private and public keys. If there was one area I could see the us investing their time and effort since RSA came out it's here. Don't get me wrong, it would be out there if they could crack even one key but like I said, if anyone can it's them.

No. If anyone had the ability to crack bitcoin addresses, they would not spend that technology on something as inconsequential as this. It would be saved for national defense issues

Re: DOJ seizes $2.3M in cryptocurrency paid to the ransomware extortionists Darkside

#98

Don't they mean Putin in an agreement with the Biden administration made Darkside give some money back as a way of easing American public tensions and political fallout ahead of the summit?

That's some schizo shit right there

Re: DOJ seizes $2.3M in cryptocurrency paid to the ransomware extortionists Darkside

#99
post #24

This story makes absolutely no sense at all. The errors present by these hackers are so comical it's simply unbelievable. I'm supposed to believe some elite Russian hacking group keeps their crypto wallets running on a US host where the FBI just logs right in and snatches the private key? I'm starting to entertain the conspiracies that the future of commodities price manipulation is fake ransomware attacks. There nee…

People overestimate criminals. The ones that get caught, especially. What would you do if you were a foreign intelligence service? Participate in attacks yourself? No! You would drop hints and supply tools sideways to sloppy groups of idiots enabling them to be destructive, maybe acquiring some funds, and keeping your hands as clean as possible. Then when it comes out that "elite russian hackers" were incompetent idi…

I think it was the RSA hack where the second (and presumed more elite) team had gained access to the first group of hackers and just followed their APTs. Noone really found out about the second group when the story was reported on.

Re: DOJ seizes $2.3M in cryptocurrency paid to the ransomware extortionists Darkside

#100
Plausible theory on how they did this here: https://twitter.com/brucedkleinman/status/140204474591697305...

tl;dr: The hackers used the same full node wallet more than once, and the FBI was able to narrow in on an IP address because the first relay of the transactions was the same across multiple transactions. This server was in California, which allowed the FBI to seize it.

Post reply on HN