Global ‘Wana’ Ransomware Outbreak Earned Perpetrators $26k So Far
krebsonsecurity.com
krebsonsecurity.com
Turns out that for a lot of victims wiping their old computer was deemed less expensive than the cost, nuisance, and risk of paying criminals through some shady internet fake money thing to possibly avoid having to wipe their computer.
For anyone with a recent backup of their data, I can't think of why they'd pay.
HN'ers might, but HN would not be a representative sample.
Problem -> Reaction -> Solution.
I wonder how many people facing a locked computer would sigh, say a few choice swearwords, and dig out their cards had it been a relatively low amount.
Well. I guess it's good that there's not a more convenient way to give in to the criminals' demands!
One interesting counter point here is that the money hasn't disappeared. Literally every cent that has been paid to one of these Bitcoin addresses can be traced through all future purchases by anyone on the internet. The money will, of course, be combined with other amounts as transactions occur but that doesn't kill the trail. If any of it does end up in a wallet which a government can tie to a real person, an investigator can start working backwards. This is no different from marked bills in a more traditional ransom payment. Not perfect, but proven effective.
Checks and money orders have to be cashed...
Im not ranting against anything, just a curiosity...
[...]
By August 2012, a new variant of Reveton began to spread in the United States, claiming to require the payment of a $200 fine to the FBI using a MoneyPak card.
[...]
Rather surprisingly, Fusob suggests using iTunes gift cards for payment." https://en.wikipedia.org/wiki/Ransomware
Apparently at least Ukash, Paysafecard, MoneyPak card, and iTunes gift cards have all been used.
edit:
>any number of ways
what about zero?
It's entered meatspace, with players like the FBI, FSB, China (not sure about their acronyms), and anyone else who feels they have a stake.
If you aren't state-sponsored and protected (by a competent state, however corrupt), you aren't going to win against them. Not when you have a physical body, family, and friends to protect.
(And even if you aren't state-sponsored, do you want to be on high-vigilance for 10+ years? No trips abroad? And how do you stay useful enough to maintain that protection? And how, regardless of internal political turmoil?)
P.S. Not to mention, the competent (as opposed to the other) and very resource rich aspects of their intelligence services. Which can add up to a lot of haystack sifting.
Consider that every transaction is public information - so any bitcoin spent from that wallet has to go somewhere.
A friend threw out a stat for me while we were discussing this the other day that something like 80% of existing wallets are owned within places like coinbase where they are associated with named individuals. (I don't know if that is true, but for the purposes of this strategy it's the assumption I'll stick with)
Anyways - assuming 80% of wallets can be traced by law enforcement to named individuals. Imagine that you set an alert to watch all outbound transactions from any of those three wallets.
After each transaction, do a lookup on the owner of the receiving wallet. If it is a named individual, interview them to find out how they got this money. Who just sent them a bitcoin?
If the wallet is not owned by a named individual, add it to the watch-list. Repeat for all outbound transactions from that wallet until you can trace it back.
I'm interested to know how many steps it would take to arrive at the actual criminal.
The best that I got is that those criminals rely on living in countries with weak rule of law, and Bitcoin makes for just enough obfuscation that those countries won't investigate them, while countries wiling to investigate don't want to disclaim they have the ability.
Besides, anonymity is not the only feature of Bitcoin useful for criminals. There's also the fact that transactions can not be stopped or undone. Those may be even more important.
It would be interesting, if some white-hat security researcher, pays the $300 money and gets the solution (reverse engineering) . Make its available for free to everyone :)
Paying a ransom is the opposite of this. The action only helps yourself, but harms everyone else, but providing funds to the ransomer.
Reminds me of my relationship with the people who call themselves the taxing authorities.