Isn't ransomware profit-motivated? I thought with terrorism the goal was fear rather than profit.
Isn't ransomware profit-motivated? I thought with terrorism the goal was fear rather than profit.
On a more theoretical level, it's certainly possible to do both at the same time, two birds with one stone. But it seems a lot of the big gangs are suspected state-sponsored, which is less terrorism and more cyber warfare
Hard to see how they are terrorists? What are they pushing to accomplish with their terror campaign.
Anyways, my health care system constantly assures me security is its "top" priority and "state of the art".
> On a more theoretical level, it's certainly possible to do both at the same time, two birds with one stone.
I'm not sure how well that would work. Ransomware generally has responsive and helpful support people, because without that it will be hard to convince victims to pay. If they spend their time instilling fear instead of confidence in the payment process, then no one will pay.
From what I have recently learned, this may no longer be accurate. The latest Risky Business happens to touch upon the subject.
Criminal groups in Russia have financial arrangements with the central government, and may occasionally do some freelancing for them. Now China is getting on the same boat, but apparently with less entrepreneurial approach to target selection.
If they are the only ones, I would be very much surprised. The net result is that ideological and for-profit motives will be harder to distinguish, as the same crew may well be doing different campaigns for different reasons at any given time.
Sure, some of the campaigns might be ransomware, some might be terrorism. I don't see how this disagrees with what I said.
I know anti-Russia propaganda is at its height now and I even admit it's weird watching how worked up Americans get about stuff they're been doing all around the world since WWII, but as bad as Russia might be, I don't really buy they're behind it.
I wouldn't characterize it as an attack, its closer to "preparing an attack". And why not - the former President of the United States outright said on TV that the US had placed dormant implants deep inside key Russian infrastructure without pulling the trigger as a preparations/part of countermeasures for electoral meddling in 2016. The decision to pull the trigger was left as an option for his successor. I do not doubt the Russians may be getting similar "insurance" against a possible unfriendly posture from Washington starting January 2021.
As others have noted: while this instance is unlikely to be terrorism, this is a tool that is useful in terrorism and has been used as such in the past.
> The use of violence or of the threat of violence in the pursuit of political, religious, ideological or social objectives
One could argue these are all political. In the end, you can deduce anything to being political.
Or this definition by Alex P. Schmid from 1988:
> "Terrorism is an anxiety-inspiring method of repeated violent action, employed by (semi-)clandestine individual, group, or state actors, for idiosyncratic, criminal, or political reasons, whereby—in contrast to assassination—the direct targets of violence are not the main targets. The immediate human victims of violence are generally chosen randomly (targets of opportunity) or selectively (representative or symbolic targets) from a target population, and serve as message generators. Threat- and violence-based communication processes between terrorist (organization), (imperiled) victims, and main targets are used to manipulate the main target (audience(s), turning it into a target of terror, a target of demands, or a target of attention, depending on whether intimidation, coercion, or propaganda is primarily sought".
Source and more scholar definitions see [2].
For in-depth criteria I can recommend Alex P. Schmid's "Revised Academic Consensus Definition of Terrorism" from 2011 [3] as it is what scholars at Leiden University use.
Regarding the criterium is it always political, see #9:
> 9. While showing similarities with methods employed by organized crime as well as those found in war crimes, terrorist violence is predominantly political – usually in its motivation but nearly always in its societal repercussions;
(Its too large to quote all 12 criteria; again, please see [3] (no HTTPS))
Sometimes, the goal of ransomware is political, but its disguised as if goal is financial. This provides cover for e.g. a state actor.
[1] https://en.wikipedia.org/wiki/Definition_of_terrorism
[2] https://en.wikipedia.org/wiki/Definition_of_terrorism#Schola...
[3] http://www.terrorismanalysts.com/pt/index.php/pot/article/vi...
From Oxford dictionary. Terrorism absolute includes the political struggle. The point is that terrorism uses violence and intimidation to further its goals and that it has no legal base for it.
(sarcasm / irony / etc)
On the other hand, I believe that the word terrorism and the characterization of acts as terrorists should not be taken too lightly as it can lead to misuse of power rather quickly.
Fear of losing money if you don't pay the ransom: yes. But this could sort of apply to many salespeople, marketers, negotiators. They want to make it sound very good to take the deal and very bad (yes, maybe scary) to not take the deal.
The way the fear is targeted between ransomware and terrorism is also quite different. Terrorism wants the general public to be scared. Ransomware doesn't want the general public to be scared, because that would lead to people patching their systems, reducing future profit opportunities.
Perhaps an even closer corollary would be our embargo of Cuba, which effectively cut them off from having viable trading routes. We did it to destabilize their economy, so they would get rid of Communism because we don't like Communists. How many people have died of starvation because we're artificially dampening their economy?
We can further reconcile them by saying that the entire mechanism for extracting money from the ransom victim is by making them afraid. In this case, afraid of losing their computer systems.
>We can further reconcile them by saying that the entire mechanism for extracting money from the ransom victim is by making them afraid. In this case, afraid of losing their computer systems.
You might be partially right. But I see it more of them trying to convince you to take a deal. They're trying to sell you something: your data. They want you to have as little fear as possible that you can get your data back. They want you to be 100% confident in the payment process. Yes there's fear of what would happen if you don't pay. But that's a path they want you to avoid. You could almost categorize any negotiation this way. The person you're negotiating with will try to convince you how good it is to take the deal and how bad it is to not take the deal.
The other difference between this and regular terrorism is that regular terrorism wants the general population to be scared. In ransomware, they have no goal at all of making the general population scared. In fact making the general population scared would be counterproductive, because it could lead to people patching their computers making future profits harder.