Who’s Behind the GandCrab Ransomware?
krebsonsecurity.com
krebsonsecurity.com
I think it's definitely worth considering that this may be a frame job for some poor unwitting person.
However, I agree completely that OPSEC is probably not at the top of most larval stage hackers mind's working out of countries they don't fear extradition in.
I know that criminals tend to not be very bright, but this particular field would require at least some basic competence, I would assume.
Humans are odd creatures, it's entirely believable to think this person didn't wish them happy birthday x years ago or cut them in line at Starbucks and the person made it their mission to 'exact revenge'.
A former co-worker of mine was angry over another co-worker over something trivial. She had a known peanut allergy and at some point someone coated her keyboard and desk with peanut butter powder (which was blatantly obvious that something was all over her desk). We all knew he did it but no one saw it happen so nothing could be done about it. He would also go on and on about "you don't want to be on my list! I'm going to put you on my list!" but he'd never say it around management so again, they wouldn't do anything about him.
https://www.itwire.com/security/86867-infosec-researchers-sl...
Does this take into account the Julian/Gregorian diff?
https://en.wikipedia.org/wiki/True_Orthodoxy
(I don't think this would affect anyone's civil birthdate.)
Of course, I may be a little too sensitive about this kind of stuff. I am in the middle of reading Neal Stephenson's REAMDE right now.
[0] https://hacked.wtf/2019/04/26/dear-brian-krebs-no-more-doxxi...
I’m not a fan but I don’t see how you could call him a charlatan, he’s never claimed to be anything but a journalist.
It also occurs to me that (unfortunately) the ransomware setting may be one where comparatively few kinds of attacks are feasible. The ransomware will encrypt one short fixed-length random value (chosen by itself, not the user) once and then stop. The public key is presumably fixed and was most likely generated offline using a separate tool like OpenSSL.
The decryption presumably happens only on the ransomware author's infrastructure and is gated by a payment, so it's potentially hard to perform oracle attacks (and perhaps different kinds of decryption failures don't produce meaningfully different observable behavior, especially if a human being is in the loop returning the decryption tokens to the ransomware victims who've paid the random).