In a logical extreme you could start adding features like "Give us the info of people you know and for every one we successfully extract a ransom from we'll give you 10% off your ransom."
It's interesting to think about at least.
In a logical extreme you could start adding features like "Give us the info of people you know and for every one we successfully extract a ransom from we'll give you 10% off your ransom."
It's interesting to think about at least.
Storfer learned quickly never to use the term “hacking.” Instead, he would assume his correspondent “thinks they’re a businessman,” Storfer said. “I’d say: ‘Look, we can’t afford this [ransom] at this time. Do you mind providing your product [recovery key] at a lower rate?’ And it worked,” he said. “They’re doing a job where everyone hates them, so feeling like they were respected made them work with us. I like to think empathy goes a long way.”
The rapport sometimes reaped discounts. “We were able to get a $5,000 ransom lessened to $3,000 because they knew we could deliver it exactly when we said we were going to get it to them,” Storfer said.
[1]: https://features.propublica.org/ransomware/ransomware-attack...There was a story a while back, perhaps on HN, discussing the results of an academic survey of prisoners (in the UK, I think). They consistently evaluated themselves as more honorable than the average person on almost every dimension.
But the issue is there are many different ransomware gangs and malware families. We'd probably start seeing a twisted form of corporate PR from most of them. "We're not like the rest. We abide by a strict code of ethics and believe fair and honest dealing is paramount to our reputation and customers' trust in us. We will never add hidden charges or 'alter the deal'. Rest assured that your keys are stored securely and will always be delivered to you within 4 hours of payment. That's the CryptoLockDeluxe guarantee."
It reminds me a lot of piracy in EVE Online, where pirates' reputation for allowing ships to carry on after paying the random was considered a big deal.
1. They infect a major institution with ransomware.
2. They demand, and successfully receive, a major ransom.
3. They DON'T immediately release the key, despite the ransom being paid. Instead, they issue an open demand for ransoms to be paid to a random Bitcoin address from other major ransomware groups.
4. The meta-ransomers only release the key to the original victim if they receive sufficient ransoms from other ransomers.
The meta-criminals would essentially be ransoming the credibility of ransomers. If the ransomers don't pay up, then the meta-ransomers will chip away at their credibility.
First thought is that the 'meta-ransomers' would probably only get one or two shots at such an action working before the major groups make some sort of statement (and even perhaps provide some sort of way to 'authenticate' that it an attack is from one of of the more 'trustworthy' ransomware groups.)
Second thought is that it would have to be a gutsy group of rogue actors or group of rogue actors. A lot of these underground folks still know each other one way or another and this would probably be considered a big 'f--- you' to the rest of the community. Bridges would be burned, unspoken agreements in the sphere may be violated. You could even see the ransomers quickly turn their efforts to exposing the meta-ransomers.
On the other hand, it could become an 'arms race' as the meta and non-meta ransomers start trying to shut each other's ransomware down
I think you could do it by issueing the shares as a zkAsset using AZTEC, and any ransom paid in btc could be transposed to renBTC on Ethereum, deposited into zkSYNC and distributed to all shareholders proportionately in the zkSYNC, that distribution transaction wouldn't be recorded onchain (although maybe zkSYNC has some ability to monitor transactions) and shareholders can withdraw their dividend at their own will.
But otherwise they can just convert the BTC to XMR first, and reintegrate that however they want.
I would think the biggest impediment to insiders doing this would be how to successfully hide and use the money, if it was a lot.