DarkSide ransomware gang quits after servers, Bitcoin stash seized
krebsonsecurity.com
krebsonsecurity.com
As a result, the ransom had the optics of an attack on infrastructure. As evidenced by the coverage of Americans desperately filling up containers.
This created the impetus for the US to treat this as an incident far and above the ambient ransomware activities leading up to this.
It also gave the US an opportunity to show how effective it could be when it had the political cover to do so.
(It almost seems oil does not require infrastructure - you can, theoretically, prep for an oil infrastructure outage by storing it containers, same as you do with water and food. But you can't really prep for a medical infrastructure outage. Is it just that, as a result, there were no photos of people hoarding medical care and so there was less political will?)
If a hospital is shut down, then people will start dying immediately. The consequences are much more direct and severe.
If a hospital closes, patients can be moved. If there's no gas, patients can't get to any hospital.
An attack on a hospital affects someone if they work there or are using that hospital. A pipeline attack affects people who drive cars places and need gas. The latter group is much larger than the former.
Hospital affects workers who work there and people using that hospital VS Pipeline affects workers who work there and people currently refilling their cars with gas from there
Or
Hospital affects workers who work there and everyone within a radius who could need it at any moment VS Pipeline affects works who work there and people who generally rely on that gas to drive
Suddenly the groups seems much similarly sized, while one being important for staying alive VS the other being a nice-to-have, if we consider it being offline for a week or two only.
I know which one I would consider being worse if I was a country. But then we're also talking about a country who's fascination for oil is like no other, so this is hardly surprising.
The number of people reliant on this pipeline is several orders of magnitude greater than would be impacted by taking a single hospital offline. You’d need to have many hospitals impacted to create a similar level of risk. The only big difference is that taking out hospital infrastructure can kill people immediately whereas the impact of a pipeline failure won’t generally be felt for days or weeks.
Edit: Based on your other response it sounds like we are on the same page.
But if you instead compare 40% of the hospitals going offline VS 40% loosing access to gas, with similar conditions, I think the mortality will be higher by attacking hospitals. I think the government could probably somehow logistically ration oil if shit really hits the pan too, so essentials can keep running. Probably worse situation with hospitals, even though the military could probably help out there a bit.
That's why it's weird to not react when people are attacking hospitals, vs oil pipelines. But as said before in my other comment, maybe not too weird.
The average person fills their gas tank once a month, so they are much more likely to notice personally.
If the intended situation is to be able to (for instance) set up a coup attempt on the target country, have it come off well enough to produce chaos, and THEN have your tame cybercriminals knock out key infrastructure, that would be an extremely effective act of war.
Freaking people out while not destroying the target country is a bad, bad misstep. They did indeed kick the hornets' nest, but so ineffectively that the best response would be to try and cover the whole thing up and pretend it was nothing. Might work for some, but I doubt the US government is amused.
The difference is response is a matter of impact scale. Usually, the infrastructure of a small group of hospitals is at stake. This time an entire state is hoarding gasoline. Both are infrastructure but the latter is causing nationwide effects.
Which is somewhat disturbing, because first the industry is still considered more important than civil services (city councils, hospitals). And second they will still continue using Windows services in their backbones. I have nothing against using Windows as frontends, but in the backbone of a critical company it's criminal negligence. Easy to hack, no backups, untrained admins with no idea about security. Wasting billions on money on theatre, and not working servers, groupware and email.
The game was changed when Colonial closed the valves and services were impacted.
Five distinct disciplines compose the ESS, encompassing a wide range of emergency response functions and roles:
* Law Enforcement* Fire and Rescue Services
* Emergency Medical Services
* Emergency Management
* Public Works
Emergency Medical Services ≠ Hospital
Hospitals obviously do rely on infrastructure, so you'd see much more panic if someone could disrupt a national supply of blood plasma or insulin or something.
I think a more likely answer is that optics had little to do with it. Attack a hospital and you've got angry hospital administrators mad at you. Attack an oil pipeline and you've got billionaire oil executives and shareholders who have much of the US government in their pocket mad at you.
You really don't want to anger people who can buy US elections.
Oil pipelines that serve everything from energy to transportation to manufacturing are far more integral to keeping all aspects of society running for magnitudes more people.
Not sure what you mean, what did the US do exactly?
https://mobile.twitter.com/TheRecord_Media/status/1393192862...
See also: https://en.m.wikipedia.org/wiki/Argumentum_ad_populum
During the conspiracy, the FSB officers facilitated Belan’s other criminal activities, by providing him with sensitive FSB law enforcement and intelligence information that would have helped him avoid detection by U.S. and other law enforcement agencies outside Russia, including information regarding FSB investigations of computer hacking and FSB techniques for identifying criminal hackers. Additionally, while working with his FSB conspirators to compromise Yahoo’s network and its users, Belan used his access to steal financial information such as gift card and credit card numbers from webmail accounts; to gain access to more than 30 million accounts whose contacts were then stolen to facilitate a spam campaign; and to earn commissions from fraudulently redirecting a subset of Yahoo’s search engine traffic.
Here's what the Treasury had to say about it in April [2]:
To bolster its malicious cyber operations, the FSB cultivates and co-opts criminal hackers, including the previously designated Evil Corp, enabling them to engage in disruptive ransomware attacks and phishing campaigns.
More about Evil Corp etc in [3].
[1] https://www.justice.gov/opa/pr/us-charges-russian-fsb-office...
[2] https://home.treasury.gov/news/press-releases/jy0127
[3] https://apnews.com/article/business-technology-general-news-...
Go on
There is much more if you care to go down that rabbit hole.
https://blog.malwarebytes.com/threat-analysis/2017/06/eterna...
Why call it diskcoder.c anyway? It’s Petya
It's the same as domestic operations here in the USA: GRU comes up with ways to run loosely controlled groups that are accomplishing roughly the same ends. It's about making the battle space more confusing and unpredictable, and it's been going on for quite some time, very successfully. The soldiers don't report back to central control: they're NOT controlled, they're just loosely directed.
This would be the same. The hackers doing this don't have to be direct agents here, they're sheltered by the Russian state and only need to have some indication of where and what to strike. It's one-way communication, and it's possible to get the desired feedback through things like Facebook and Google Analytics (by paying for it like any ordinary customer).
What are the sides of any company other than "business"?
> After Colonial Pipeline reported that its corporate computer networks were hit by the ransomware attack, the company shut down the pipeline as a precaution due to a concern that the hackers might have obtained information allowing them to carry out further attacks on vulnerable parts of the pipeline.
Yes, it's guesswork and pretty extreme conjecture but it has just the right amount of coldheartedness to it: https://zetter.substack.com/p/biden-declares-state-of-emerge...
> New details from within Colonial Pipeline have come to light surrounding the decision to shut off supply. Those briefed on the matter have suggested that fuel flows were shut down due to the company's billing system being compromised. Company officials were reportedly concerned that they would not be able to accurately bill customers for fuel delivered, and chose to stop delivery instead.
It’s a privately financed, constructed and operated pipeline. I don’t see why they should be obligated to operate without getting paid.
Who's been messin' up everything...
Colonial obviously have done well in certain ways: their business side and operational side are decoupled. Business side got hit with a major IT problem - and the damage was contained. Pipelines kept working as intended. That's good operational planning, and they deserve credit for it. They were perfectly capable of, quite literally, keeping the lights on for 100M people.
> It’s a privately financed, constructed and operated pipeline. I don’t see why they should be obligated to operate without getting paid.
Because they are critical infrastructure. Colonial are entitled to their profits as long as they keep their side of the bargain: supply oil and fuel for those 100M people who critically depend on them.
This is where role of a regulation comes in. Make it the critical supplier's responsibility to ensure that they supply. If they lose their billing capability, that's their problem. Not their customers'.
(Oh shit, everything just went down, turn on the generator, go plug that printer and laptop in, and print off all the reports of where we were from the offsite/offline/whatever backup).
What did they do before computers?
Failing to plan is planning to fail and all.
I like the idea of monthly planned downtimes where possible so people don’t run around like a headless chicken when things go down. No different than a fire drill.
If they did, I would expect their employees to be out of practice with such methods since they weren't working that way day-to-day. Unless they're running regular "all computers are down"-drills to keep their employees sharp, downtime was probably inevitable.
I've long wondered if that really was the case, seemed absolutely sensible...
In truth both factors probably played a role in this case, perhaps also with a hefty dose of "our software literally can't run if billing is down because it was never designed to handle that".
Operations side performs whatever services the business side has committed to.
A lot of people like to think of ransomware attacks as the ultimate stress test as far as security goes, and thus a good thing - but let's not get too blinded by our professions (most probably in tech), these kinds of attacks can have serious consequences: Imagine if some foreign state agency (masquerading as hackers) launches a multiheaded attack on, say, utilities plants - in the middle of the winter. The victims/targets will pay whatever us necessary.
With that said, I understand that many people will recoil at such things - we saw what the patriot act did, and how easy it is to overstep and abuse such laws, in the name of "national security". But it is a serious problem, in the same way actual piracy thrived in the gulf of Aden, as soon as the shipping companies started paying.
A common understanding is that terrorism is intended to frighten people or make them feel unsafe, while various official definitions of terrorism include the idea that it's intended to coercively achieve some particular political goal.
If attackers just intend to get money, they're probably well-described as extortionists (or in some cases, as you said, akin to pirates). If they just intend to damage a particular society without demanding anything from it or getting it to change its behavior, they might be saboteurs.
Attacks with these motives or that pretend to have these motives could still be considered national security threats (and taken very seriously), but maybe shouldn't be described specifically as terrorism.
From the victim's perspective it matters less who is attacking you or why they are attacking you and much more what the results of the attack are, how you can mitigate and recover from the damage, and what needs to be done to prevent future attacks.
For the case of DarkSide and Colonial Pipeline, the attackers did not claim to have a political motive, but the resulting fuel shortages and panic buying might as well have been a form of terrorism.
You can make a reasonable argument that "nothing is apolitical" but but that's not the definition of political being used when people say what terrorism is.
I'm a frequent "everything is political" commenter myself, but since when is naked self interest through theft a political action?
The insanity of it all is incomprehensible.
How does taxation drive value? Which taxation? There are governments that don't charge income taxes, there are governments that don't charge property taxes, there are governments that don't charge sales taxes.
Also note that the work of legal historians such as Christine Desan who are not affiliated with MMT economists concurs with this analysis.
Also note that most mainstream economists do actually agree with the tenets of MMT when individually stated but base their disagreement on a deliberate misreading/misstatement of MMT which they then proceed to criticise.
That taxation is sufficient to drive demand for a currency is not contentious, that it is necessary is unconfirmed.
Tally sticks are an early example of monetized debt as a taxation medium.
That only true when right is up and down is left.
I have to believe that played a role in the response they received as well.
maybe in as far as their capabilities go, but the important characteristic of a state actor is that retaliating against them is construed as a retaliation against the state that backs them. Darkside is very different to a state actor, as demonstrated here - retaliation has no significant geopolitical implications, so it can be swift and harsh.
>As noted in previous stories here, during times of conflict with Russia’s neighbors, Slavik was known to retool his crime machines to search for classified information on victim systems in regions of the world that were of strategic interest to the Russian government – particularly in Turkey and Ukraine.
>“Cybercriminals are recruited to Russia’s national cause through a mix of coercion, payments and appeals to patriotic sentiment,” reads a 2017 story from The Register on security firm Cybereason’s analysis of the Russian cybercrime scene. “Russia’s use of private contractors also has other benefits in helping to decrease overall operational costs, mitigating the risk of detection and gaining technical expertise that they cannot recruit directly into the government.
https://krebsonsecurity.com/2019/12/inside-evil-corp-a-100m-...
Would that change if they, for example, demanded the release of prisoners of a specific political persuasion?
How would that not be classified as a political motive?
Yes.
"Terrorism is, in the broadest sense, the use of intentional violence to achieve political aims." https://en.wikipedia.org/wiki/Terrorism
Ransomware is non-state, not violent, and is done for economic, not political aims.
There’s a well known phenonenom of a certain large nation harbouring cybercrime gangs and keeping them on the government leash. Their economic activity benefits the governments political agenda. Ergo all conditions are true.
That doesn't mean that the large, developed nations in question are engaging in organized crime.
Taking advantage of regulatory arbitrage does not mean that their government is in collusion with them.
If it did, then we could pile a lot of crimes at the feet of Western governments. Some mining firm violently puts down a strike in Central America? Clearly, we can conclude that Canada/the US is engaging in terrorism! [1]
[1] https://digitalcommons.osgoode.yorku.ca/cgi/viewcontent.cgi?... [2]
[2] 28 Canadian companies, 44 deaths, 30 of which were targeted extra-judicial killings. Are we going to lay those at the feet of Parliament, too? [3]
[3] Or do we have one set of standards for Russia, and another for our own behaviour?
Are there no ransomware operations linked to North Korea? I was under the impression that there was some level of activity there to maintain supplies of globally-usable currency.
The Great Firewall is likewise, not remotely similar to the restrictions placed on internet access in North Korea.
If serious ransomware attacks are being conducted by state actors with the sole intent of causing damage, and we want to use powerful terminologies to describe them, "acts of war" seems a reasonable start.
Yes, this is semantics--but some of my concern here is that just freely tossing around "terrorism" gives cover for organizations not to be diligent in at least attempting to secure their networks and digital assets.
A precise definition of terrorism tends to be difficult to pin down (mostly due to the difficulty of considering what is a legitimate asymmetrical warfare tactic by a nascent liberation movement versus an illegitimate terrorist act). But a general rule of thumb is that terrorism is a) violence b) directed at civilian populations c) to effect policy.
However, there are threats to national security that are not terrorist in nature; gang warfare in Mexico and Central America would be an example of such a threat.
I don't think it's necessary to staple the term to the action in order to take it seriously. It should, however, be taken seriously as the national security threat it is. For instance, climate change is a national security issue but oil executives, while distasteful, aren't terrorists.
I agree that many folks in the tech community (and especially here, though I don't know if they're overrepresented here) treat technology as platonic. That's not going to cut it moving forward. Technology that enables bad things in the world should be curtailed even if its "neat."
I'm not sure leaving infrastructure hanging out in the breeze can be compensated for by cracking down on personal liberty, however. Unless you're proposing cutting off international computer network integration.
Well... yes? That isn't a sense of the word "terrorism".
Generally though, the Justice department defines terrorism to be "the unlawful use of force and violence against persons or property to intimidate or coerce a government, the civilian population, or any segment thereof, in furtherance of political or social objectives"
These ransomware attacks fall in the middle. They are 'deniable' by state actors as just crooks who happen to be within their borders. They certainly don't push any social objective other than to enrich the criminals. So that leaves them under the jurisdiction of law enforcement.
I have read anecdotal evidence that there are the equivalent to "Letters of Marque"[1] for Russian criminals who attack enemies of the Kremlin. They wouldn't completely qualify as the Russians aren't actually in a declared state of war (this works fine for North Korea) but conceptually if you accept that criminals are gonna crim, then pointing them at people you don't like at least keeps the damage outside of your area of concern.
In this particular case, the fairly rapid take down of these guys gives me pause. One wonders if the FBI and Interpol had Colonial pay with Bitcoin that they then traced to the destination wallets. And then working backward from there to the server infrastructure. That would be an interesting capability if it exists.
These people thought they were sticking it to the man but they were actually sticking it to people like me.
I wish Biden realized how hard homeliness can be. Cities, and towns, need to stop ticketing vechicles that are parked overnight, and used as residences. I would like to see any federal, state, or local land, set aside for the homeless.
Hang in there.
The meanings of words is important; rational discussion is impossible when people shift commonly-accepted meanings and definitions to suit their agenda. It's an extremely common strategy in politics. And the word "terrorism" already received more than its fair share of this treatment quite thoroughly in the decade following 9/11.
Sounds like the ransomeware people finally robbed the wrong people.
Not saying it's false, but the story doesn't ring true to me.
They appear to be sophisticated, yet they made the newbie error of keeping all the funds in a network accessible device, rather than a cold wallet. Really?
For say a nation engaging in cyber war, this could be flipped around: attacking basic infrastructure but disguising it as smaller groups of criminals trying to make a buck. Not sure how effective the disguise would be, but it could obviously do some serious damage.
Um. Terrorism is basically never a threat to national security.
Terrorism has a legal definition, and something affecting national security is not the determining factor in calling something terrorism.
"Terrorism includes the unlawful use of force and violence against persons or property to intimidate or coerce a government, the civilian population, or any segment thereof, in furtherance of political or social objectives." [1]
And why would you say this is desirable to the US? Just general "governments take advantage of crises to gain power" reasons?
The hacker group attacked resources considered "critical infrastructure"; this was closer to an act of war than any other cyber attack has come. The US Cyber Command responded swiftly.
> "governments take advantage of crises to gain power"
Please, elaborate? I fail to see how the US Govt is taking advantage of this crisis for more power.
OP used all kinds of language we associate with governments doing sketchy stuff: "what could be sold as reasonable doubt to shut down the pipeline"; "created the impetus" ("impetus" is often used to claim the real motivations were something else); "political cover"; etc.
I just didn't know how else to interpret all the cloak-and-dagger language about the US's behavior. Personally, it seems to me like our response was pretty reasonable. I think the "government takes advantage of crises" line of argument only goes so far, and at its extreme leads to dumb stuff like 9/11 truthers.
I'm pretty sure it's actually happening we just don't hear about it.
I suspect small or medium organizations rather then megacorps would be easier targets if they haven’t invested money in accounting controls.
Plenty, if not all, corporate level financial controls will be bypassed by the executive branch showing up in suits.
My read is that tax enforcement failure is intentional, lubricated by political donations and influence, vs incompetence.
See the high-net-worth enforcement group at the IRS that was quickly shut down for murky reasons.
There is something called the "gun test". The crypto on an encrypted hard drive is not more secure than the gold bars in a locked safe. Its security is a function of how the secret holder response to gun-on-their-head events. In this case, since the government is directly involved (and angry), a lot of criminals may pick personal safety over assets.
Frankly, I think a large portion of cryptocurrency proponents are overly confident in its "decentralization" and "safety". Cryptocurrency is only as safe as gold bars in a locked safe; and worse if you use a public exchange.
In cryptography, rubber-hose cryptanalysis is a euphemism for the extraction of cryptographic secrets (e.g. the password to an encrypted file) from a person by coercion or torture[1]—such as beating that person with a rubber hose, hence the name—in contrast to a mathematical or technical cryptanalytic attack.
If you're tortured to keep revealing keys to deeper and deeper volumes, eventually you're going to hit a point where there are no more volumes, but you can't prove it.
I think the original threat model was someone willing to torture you, but willing to accept plausible deniability once you'd revealed some moderately sensitive information.
In reality, if someone is willing to torture you a couple volumes deep, there's a good chance they're going to just keep torturing you forever. Rubberhose may still work in this model, since in theory the promise of avoiding torture loses most of its power. The downside is that once you format a partition with Rubberhose, you're resigning yourself to being tortured forever.
All the cryptographic, air gapped security hardware doesn’t matter if someone can beat the keys out of you.
That's usually the problem that people who pay a lot of taxes have with the taxes.
It's very hard to do this with gold.
B. To bury gold you must transport the valuable property in meat space to your hiding spot after acquiring it. With cryptocurrency, you hide the secrets before they have value and transfer the funds to them without new data actually traveling to the hiding spot, electronically or physically.
With state actors, you have to assume they have access/backdoors to most modern computing devices, and that device has to connect to the internet only twice - feds activate the backdoor and give it instructions, and have the device send the requested info back to the fed.
Minix being the most popular operating system, thanks to Intel-backdoor-on-a-chip, is only the tip of the iceberg.
If that's not enough and anyone of them is in the USA they do have access
Can your wallet be hard to crack? Yes but either use your zero day to get all data including a Password or book a little bit of supercomputer time for brute forcing.
They might have linguists available to help out with a dictionary attack.
As aluminum foil hat this might have sound in pre Snowden that's how it could have been played out.
What you store is your private key.
Your private key was generated together with your public key, and your public key is, well, public.
So the question is, can someone re-generate your private key?
In theory, yes, it is possible. In practice, it takes a very very long time.
But sometimes flaws are found in the generation process, like a weak pseudo-random number generated used, which significantly reduces the solution space, and then it becomes feasible.
Most people serious about cryptocurrencies do not trust computers/harddrives anymore since years. They use "hardware wallets", which are HSMs with a very small attack surface. It's not impossible that hacks happen but there's a gap so wide between "a Windows 10 computer running some Bitcoin software wallet" and "a Ledger Nano S" hardware wallet that it's basically two different worlds.
Think a Yubikey (with a tiny screen) to cryptographically sign your transaction.
$5 wrench attack still works but compromising your private key(s) by "logging every OS keystroke in the name of telemetry" or "using one of the tens JavaScript 0-day from today" doesn't.
The idea behind these cryptocurrencies hardware wallets is that ANY computer you connect them to is compromised (which is precisely why you're using an hardware wallet) and that, yet, that's not a problem.
I have to say: it's not a bad way to think about computer (in)security.
That's not what you do if you just stole everyone's money / should run...
It just demonstrates that they're incompetent.
Beyond all the technical discussion about the value of cryptocurrencies I never believed that the idea that everybody would carry their cryptocurrency wallet with them at all time was in any way realistic. People would get their wallet stolen, destroyed or lost all the time, locking them away from their savings. The vast majority of people will prefer having the peace of mind of entrusting their coins to a third party who'd handle the technical details and provide insurance against lost and theft. And just like that we've reinvented banks.
So which of the following is most likely:
- the government has a tool that can break private key encryption and used it to confiscate a hacker groups funds
OR
- whoever controls the groups wallet transferred it out and is on the run
Someone got a little sloppy on their payment processing server (also seized) or with maintaining separate wallets and control of that server allowed sending of payments to an account specified by whoever was in control - likely since the server was for paying affiliates.
"BTC is bad cause it can be used by drug dealers to launder money"
"BTC is not even secure from government access"
Surely someone will point out both can be true but the point is the anti-btc folks seem to be talking out both sides of the mouth
The most beautiful being: "The cryptocurrencies scam should all stop but, please, let us collect all the due taxes on the gains you made".
From that standpoint which one is it: are they legal or illegal? Because it's funny that they both want it to be illegal, yet they want people to pay taxes on the gains they made.
Hypocrites.
In this case even the pros messed it up, but this is a very high profile case with undoubtedly a massive amount of manpower thrown at it in various agencies. You don't mess with USA's oil.
And even then it's unclear if the money was actually confiscated.
Can you explain how you reach this conclusion? It doesn’t seem to follow.
Both of those seem pretty hard to be true at the same time
That’s what doesn’t seem to follow.
Cash, for example is hard to trace if the serial numbers haven’t already been recorded, and good for money laundering, for example, but it doesn’t secure your money from government access if the government puts resources into it.
In order to seize someone's cryptocurrency, the government has to literally seize the private keys used to sign transactions. This could be as easy as seizing computers containing the key but it could also be as hard as torturing people until they reveal their seed phrase.
They can't simply order the banks to freeze people's assets. They have to physically go there and try to seize them. This puts a limit on the scope of their operations. It's just like surveillance: encryption makes dragnet espionage harder but it's still perfectly possible for a target to be attacked directly.
https://www.treasury.gov/ofac/downloads/sdnlist.txt
> Digital Currency Address - XMR 5be5543ff73456ab9f2d207887e2af87322c651ea1a873c5b25b7ffae456c320;
Note the lack of the 0x prefix. Here's the transaction on the block explorer:
https://localmonero.co/blocks/search/5be5543ff73456ab9f2d207...
You ask that like it seems implausible. To me, given what we know, it sounds light-handed for them.
https://www.nytimes.com/2016/03/30/world/europe/russia-chech...
Credibly threatening repeated 51% attacks against Bitcoin is well within any G7 member’s budget.
Semiconductor production can't be scaled up instantly, so 51% attacks require seizure of assets.
Even if the USA purchased every single CPU, GPU, FPGA, and ASIC made in the next month, it's unlikely they will have more than 10% of the network or so.
To seize the majority of the hashpower, they'd have to seize Chinese miners, which require either US-China cooperation or a world war.
The latest and greatest Intel i7 can do maybe 30 mh/s.
You would need more than all cpus produced in history. I can believe G7 secretly having a third of total known CPU compute.
I can't believe G7 secretly having multiples of all known CPU compute.
I don't consider that the most likely scenario, but something in the willingness to declare defeat got me into "what if" mode.
>gave the US an opportunity to show how effective it could be
unless you know something we don't, that's quite a conclusion to jump to
Just like with The Silk Road. Once it became large enough and Ross started to taunt the authorities to find him, the police had no choice. It’s continuing existence chipped away the legitimacy of the authorities, they had to shut it down just to maintain appearances.
Just like this ransom ware. Keep it small, it’s not worth going after. Start screwing with the economy and the govt goes from 0 to 10 very quickly.
Statements like this seem to point to ransomware activities being far more coordinated and "business-like" than they often get credit for.
I do wonder if ransomware is (in a strange way) a(n illegal) free-market response to what is perceived to be an under-valuation of tech skills - aggrieved people who can carry out attacks and gain access to deploy ransomware are likely to be able to earn more through this route, even factoring in their "risk of being caught".
If a market correction occurs (ransomware becomes a real fear, organisations rapidly start to value security skills more and pay "megabucks" for the skills and hire them at-scale), the risk/reward of being caught starts to mean access brokers reduce in number, and the compensation reaches a free market equilibrium (accounting for the "getting caught" risk of criminal activity).
A lot of the time I still see people trying to hire entry-level people into live/ operational security roles, without the experience they'd need. I wonder if this is partly due to a desire to cut costs, rather than accept the need to pay rock-star compensation?
But a more precise calculus would take into account that (1) the proliferation in ransomware is recent and explosive, and (2) getting hit by one ransomware group doesn't mean a second group won't strike soon. (Although I'm guessing the second wouldn't be allowed to use the same ransomware-as-a-service platform, as that would harm the platform's reputation.)
The outcome here shows that executives made the right call. The $5MM fee was easily paid, less than the costs of security, and the insurance company will probably cover it anyway. And the government/people were so outraged that the attackers were met with fucking swift justice.
The company will probably get some grants or something to cover the cost of "securing their infrastructure." Never let a good crisis go to waste.
Any employee choosing to spend millions to avoid the cost of a heretofore unencountered cyberattack would be making a strategic decision, while probably not being empowered to make decisions at that level. So they do not take action.
Bureaucracies do not take visionary action. They stay the course.
Maybe now utilities going to the US for a similar reason will be in everyone's DR/IR plan (even if Colonial didn't reach out to the US admin).
Everyone want's to make the calculation and hope it's not them, but if it's everyone at once, or there is no ransom option it's a completely different ball game. This is a situation where we are asking private companies to take responsibility for something outside of a profit motive and the results are some what less than surprising.
Sadly my experience is that organisations like this will take their $5m ransom (or other remediation cost), assume it's a one-off, then divide it by their number of ransom-free years, and proclaim it was better value for money than hiring 2 or 3 senior security gurus on $300k /yr with 60 vacation days, and letting them bring in a team to deliver meaningful security.
Beyond taking security out of the hands of bean-counters though, I'm not sure how you address this. Pursuing organisations that pay ransoms and prosecuting senior CEO/CFO-type executives for conspiracy to commit money laundering (and pushing for criminal convictions) could discourage paying ransoms. If it's left to businesses as something they can write down as a "cost", I don't see it getting better - there has to be a risk to the liberty of the CEO/CFO before they'll take security seriously in my experience. 90 days in federal prison would certainly sharpen their focus in future.
> In an apparent industry first, the global insurance company AXA said Thursday it will stop writing cyber-insurance policies in France that reimburse customers for extortion payments made to ransomware criminals.
https://www.insurancejournal.com/news/international/2021/05/...
It's a gamble. It's easy to point fingers at the company that was caught out, but for the hundreds or thousands that aren't ransomed and aren't paying the extra money for security, they took that gamble and so far they've come out ahead not having spent all that money on prevention.
I'm not advocating that these companies to have less security or not do better on security, but the fact is a lot of them have made the objectively correct decision for themselves, which will continue to be correct right up until they're hit, if they ever are. The whole situation is analogous to health insurance in a way, and the same incentives are at play, along with similar consequences for individual companies and all of us as a whole, as providing easy targets for these groups allows them to thrive and grow and target others.
The criminal penalties for executives in leadership and board positions (and I'm not saying this is my preferred approach) would certainly go a long way toward changing the calculus of this exchange.
If a business externalizes the cost, does it matter to them?
Civil penalties levied by regulators will drive the change that matters.
I mean, yes? Maybe not before next quarter's revenue statement, but eventually it will have to start to matter?
If your dog goes and craps in the yard every day, you eventually have to clean it up or you will get flies in the yard, and if you have to open the door or leave the house at all then sooner or later you will have flies in the house, it matters, yes. It's really not any more complicated than that.
If you are responsible for dumping toxic waste out the back door of your factory, it's only a matter of time before it's in your drinking water at your house, a couple of miles down the road. Externalizing a problem doesn't really get rid of it, just makes it someone else's problem (for now at least.) Those other people are real people, and they will find you.
One natural solution would be to subsidize cyberdefense. The political difficulty is that a rational subsidy would be proportional to the harm of an attack, which would mean giving the most money to the biggest corporations.
The best solution would be for the firm to raise their prices the very small amount necessary to cover the expense, and for consumers to tolerate the expense because they know it's worth it. But a pipeline is a natural monopoly, presumably charging a monopoly-optimal price that (correctly) assumes a populace ignorant of such concerns until it's too late.
"OK, now that you have our attention, and the eyes of the entire international media apparatus are on us, here's how we're going to do this. We're going to send some integer number of million money dollars down this pipe, and you're going to turn that gas pipe back on like you said you would.
Then here's what happens next... we're going to give you an integer number of minutes running head start before the drone strikes start raining down on these 12 sites we've identified as likely candidates for your location, ... now how many millions was it that you were asking for from us again?"
Doesn't really matter how much it was, either, if it has really been seized already in less than 24 hours. Was it enough to convince the boss guy or gal to take the bait and risk revealing themselves? (Probably not, but IMHO that wasn't likely to happen anyway, at least not since the heat started getting turned up on them all.)
The servers that were claimed to be seized were on cloud platforms.
And even then, we don't know if this is true or if it's just an exit strategy.
I'm inclined to agree that our cyber-security apparatus is not up to the task, but it's also true that nobody has perfect OpSec, (and I'd guess there are few out there have deeper pockets to track down and make sure the perpetrators regret this, than the combination of US government + oil companies.)
Yep. Compromised people on the inside, informants, "intensive interrogation" etc. are more likely the way, as has always been the case.
Also the agencies that would know who these people are would not want to reveal what they know in order to save random XYZ Corp's bacon. With this being seen as a "critical infrastructure" attack and something closer to an act of war/terrorism, the stakes got higher.
If you want to be a criminal who gets away with it you really need exactly one big action, and at most a few tiny practice runs before the big one. Choose your target well because once the big one is done you have to be done. (and don't do anything copycat - investigations to get the first guy might find you instead)
The US government has a long reach, but even they cannot do anything to you if you are in Russia, for example.
The USA threatening to rain drones on Russia is just going to get laughed at. Nuclear war isn't breaking out over darkside.
Putin already denied responsibility and Biden apparently accepted that, so we wouldn't be attacking the Russian government. Wink
Ransomware gangs aren't the vigilante heroes/embodiment of the undervalued IT security worker. They're a group of people looking to make a quick buck and don't give a damn about the harm they cause or who they cause it to.
Most ransomware hackers are not so amoral enough to go around murdering people or calling hits. Some are, but most ain't.
This is a business that actually provides better support than a regular business.
From conversations with friends in the Infragard side of this, and the agencies that collaborate, they have 24/7 English support available before and after payment, as well as decryption remote support if you can't get your files decrypted... there are also instances of refunds if they can't decrypt your files due to technical issues.
Unlike regular businesses, support is a sales channel since it's the way to ensure you get paid so a lot of resources go to support activities in these "organizations".
Not much capital is needed though and the affiliate and licensing model is better, which also just means an address is hardcoded that splits payment, or a server controls the private key (or master private key for infinite unique address creation) to addresses and automatically splits received payments to the RaaS service
I get that was supposed to be a joke, its exactly the same or even more streamlined than the licit economy. There is no major distinction except the kinds of “risk factors” one might list.
There's definitely a hierarchy to it. Any particular group may not necessarily develop or own the software or infrastructure they're using. You can probably liken it to drug markets, where there are some top-level central players and many tiers below that make up the whole supply and distribution chain. (And potentially, the absolute top-level / "The Commission" may be certain elements of certain nations' governments, in some cases, or at least closely associated with them, which further complicates matters.)
You might find this 2020 interview with a ransomware operator interesting: https://talos-intelligence-site.s3.amazonaws.com/production/...
I would like to hear more about this, that sounds kind of hilarious. "Ah, apologies, we'll get that back to you within 3 business days. Have a nice day, I hope you had backups"
I mostly dont do ransomware housecalls anymore, but my teammates tell me the situation has mostly not improved.
The thing I find fascinating from a sociology perspective about ransomware is that they have to. To be a successful ransomware company, you have to simultaneously be:
1. Completely immoral enough to attack companies, hold their data ransom and potentially put them out of business and reveal the private details of thousands of people.
2. Create enough trust in the company you attacked that they believe you will give the data back once you pay them.
It is crazy that they are psychologically savvy enough to simultaneously attain those directly conflicting goals.
step 1: "join my disruptor gang and we'll protect your lifestyle/income/status in exchange for tribute, or at least not becoming a disruptee yourself."
step 2: end up eventually recapitulating the exact same system you disrupted, but now you get all the spoils of the incumbent power
They're available for their interests, not yours. They're actively robbing you and will be highly available to keep things moving efficiently, the same way physical bank robbers used to make sure staff were comfortable enough to open the safe and provide cover.
What level of support do you get for a 5 million dollar AWS budget?
A customer willingly pays to get value in return. Having your resources stolen (even with the option to choose between data or money) just makes you a victim.
$5M on AWS gets you $5M of services. If they didn't have to actually provide anything then they could have an entire team to talk to you 24hrs a day. But these comparisons are beyond ridiculous and you know it.
$5M on ransomware may have saved you either $10k or $10M on security before you had to pay out.
Reminds me of this negotiation: https://www.reuters.com/article/us-cyber-cwt-ransom/payment-...
Previously discussed here: https://news.ycombinator.com/item?id=24032779
Sure. In the same way the mugging people is a response to undervaluing “beating the crap out of people and taking their money” skills.
"When the system fails you, you create your own system."
Which relates to what you're saying. When clever, intelligent people are ostracized and marginalized, they then use those skills to get illegally what society has prevented them from getting legally.
At some point, the idea of getting caught doesn't even register anymore.
If we just paid engineers more would this type of crime disappear?
Or is greed, ego, arrogance also a part of their actions?
We probably will never know. A lot of hackers turn to hacking because of various reasons - some ideological, others because they felt they didn't fit in anywhere else.
>> If we just paid engineers more would this type of crime disappear?
Probably not. You cannot get rid of one type of crime by simply paying people NOT to do it. It is what is - at no time in human history has any civilization had zero crime. That's regardless of punishments and financial incentives.
>> Or is greed, ego, arrogance also a part of their actions?
I think its different things at different times. When I was hacking, it was arrogance, thinking I was smarter than others and trying to prove it. That leads to thinking you are beyond law enforcement when you get away with it (ego). If you're into it solely for financial gain, then the other two feed your greed. Get one nice payout for your ransomware and now you think its easy to do and you'll never be caught - increasing your greed to get more.
They all kind of play into each other:
arrogance: "I'll never get caught."
ego: "They'll never catch me, my ops sec is too good for law enforcement."
greed: "This was too easy, next time I'll target a bigger company for a bigger payout."
Ehh, maybe. Or maybe they’re just bored sociopaths who get thrills looking for a big score.
[1] https://krebsonsecurity.com/2021/05/a-closer-look-at-the-dar...
Yeah, just dirtbags making money.
Nobody cares if you sabotage a random small business. Lots of people care when you attack a fuel pipeline. Attention is bad for this business.
Times have changed and when govt agencies see this as an attack on critical infrastructure, you're looking at some serious jail time. I would say its only a matter of time until they're tracked down. When you're being hunted like that, the govt works 24/7 and never stops. People on the run don't have that luxury.
I had gotten into an argument with a professor on a discussion board. He used derogatory terms to refer to me, which pissed me off. I sent him a virus that was supposed to just damage files and delete some random files. It turns out it propagated onto their main network and crashed the entire universities network.
Suddenly, you feel untouchable (even though the virus had gotten out of control, which I didn't mean it to do). You feel like you can do anything and are beyond the reach of law enforcement. I'd never done anything like that and you felt really powerful, in control. You now had this idea if someone slights you, you have something to shut them down and they can't reach you.
Then the feds show up in your class, bring you to a windowless room on campus you didn't even know existed and start threatening you with jail time while they question you. This happened in the late 90's and the CFAA was still really new and DA's really didn't know how to apply it. I was pretty lucky for sure. The stuff they were threatening me with was like interference with interstate commerce, identity theft, stuff like that. They gave me the old, "You have a bright future kid, don't fuck it up." speech at the end. That was enough to scare me straight so to speak. I lost my campus network access for a year, which sucked, but the whole experience was enough for me to stop doing what I was doing.
It was just in time too, because you saw during the early aughts, the feds really started going after hackers. They started using the broad powers of the CFAA to put some really high profile people in jail with some pretty hefty prison times. To this day, I still look back and feel like I dodged a bullet there.
> the virus had gotten out of control, which I didn't mean it to do
This isn't just a whoops, how do you "accidentally" create a virus that leaves the boundaries of the computer and traverses their network?
I copied an existing virus someone had given me. The last part of the virus was to multiply and seek out any other computers attached to the network and delete and damage the files on those computers as well. I didn't know that. When it damaged the professors PC, he was using it on his home network, so he said there was only one PC it infected.
When he got back to campus, he sent the email to the network team (a group of students and professors) and they tried testing it out on a group of PC's. They thought the PC's were sandboxed. Turns out they weren't. The next 24 hours the virus rampaged and pillaged PC's attached all over the network. I'm still not sure how it eventually crashed the network. All the people involved refused to tell me exactly how it crashed their network - they said they didn't want me encouraging others to do it, so I was never told the full story.
To this day, I'm still not sure what happened, but it had to be bad enough to call in the Feds, right?
Save the malware there, then anybody on the network with access can run it.
It's just digital Privateering - Francis Drake with a laptop.
> If a market correction occurs...
The English solved it by expanding their Navy and enlisting those who would otherwise pirate. Seems like as good a solution as any here.
In anycase disparity of oppourtunity is what breaks trust and therefor collaboration. The world needs to universally operate in the ballpark of fairness or we are all at risk in the long term. (This comment is also influenced by the under valued tech resources thought).
Edit (sorry some more thought while fixing typos): When the disparity of oppourtunity is at state level there are privateers and wars, when at a personal level there are muggings and burglaries etc.
*this is all probably stupidly obvious.. but as its against uncontrolled capitalism or classist segregation we dont seem to want to say it too much maybe?
This is the "organized" in organized crime. It's not lone bored teenagers doing this stuff.
Almost all crime syndicates work this way. There is a balancing point where the crime you do does enough damage to make you money, but not so much money that the government dedicates elites to come knocking on your door. What DarkSide did was veer too far in the wrong direction.
They only don’t get credit for that in mainstream media. In the Cyber Security world, Ransomware as a Service (and various other malware-aaS) groups have been discussed as well organized, customer-focused entities for quite some time.
I swear this is the first time it seems the world is hearing about RaaS, which feels weird since it’s a pretty dominant model today.
I am... flabbergasted. What? Ransomware has always been a brand of extortion; it's right there in the name. Extortion has become dangerous and toxic? You have got to be kidding me. I wonder what's next for these folks. A life of simple, honest, pleasant and non-toxic crime?
Misplaced ransomware runs a far more substantial risk of triggering enforcement action now. Or at least that's the perception I'm deriving from the quote.
Otoh, as a kid I was into small-time mischief (pilfering candy from teacher's desk kinda stuff). I had a good sense of what would go unnoticed, but I was a bit too trusting of my friends. They'd go overboard, get caught, and I'd take the blame. So, I can sympathise with this a bit
Without external proof, I wouldn't hazard a guess as to which it is
Tragedy of the commons? Sort of? Not really?
It's maybe a tiny bit like SWATing before the police shot and killed one of the victims. Before, SWATers rationalized it as a prank, generally. (Of course, in reality it always was a potentially murderous prank, as most people recognized.) Once someone was killed and the SWATer was arrested and sentenced to life in prison, they got a wake-up call to the magnitude and potential consequences of their actions.
Unfortunately, in this case the ransomers will probably rarely ever face any repercussions (as long as they never travel internationally), since they live under a government that shields and permits their activities as long as the victims are far away.
They might risk getting hacked, like what ostensibly happened here, though this could easily also just be a cover story for them to disappear (and maybe retire for good) so the heat can die down. Could indeed potentially be a legitimate breach by a government or vigilante or rival though, though, due to how much this story blew up.
If so, this is either:
1. one heckuva Mickey Mouse operation
2. a smokescreen
The statement never mentions Bitcoin, but let's assume that this is the "cryptocurrency" being referred to.
That Bitcoin private keys were being stored on a "server" strains credulity. There's very little reason to do so, and every reason not to.
Payments can be received and orders fulfilled by a server - without private keys. Multiple addresses can be watched in read-only mode.
The only reason for a server to hold private keys is if that server is capable of making automated payments, and that capability is a crucial part of the operation.
Bitcoin's history is littered with the corpses of people who messed up the management of their own cryptographic keys. Any reasonably competent operator would know about them and would never, under any circumstances hold private keys on a server.
Which leaves Option 2. Smokescreen. Make it look like all the loot was lost, try to throw investigators off the trail.
If so, it's a lame attempt.
One other possibility comes to mind. The ransom itself was the smokescreen.
The amount of the ransom was nothing for a company the size of Colonial. And it's about 1/10 of the annual salary of some developers. Why risk the prospect of life in prison for such as small payoff?
The reason is, of course, to make this operation look like something it's not. A Mickey Mouse band of idiots who can't manage their own private keys or servers. Lots of reasons to do this, starting with the notion that the attackers are trying to conceal their identities. And maybe that this was a test operation. Throw in the trinkets of ransom to make it look believable to the public.
The DOJ could bolster credibility of itself to the ignorant by saying “thats right criminals you cant hide” even if the DOJ never got anything.
https://www.levels.fyi/?compare=Amazon,Apple,Netflix,Google,...
I do thin the parent's point still stands though, my current salary is not nearly that high but you'd have to pay me a lot more than $500k for me to risk hacking an American pipeline. That's an insane amount of risk for a few years worth of salary (that I'll probably have to be very careful laundering if I don't want to raise suspicions).
Like a senior engineer at a FANG is probably making that much or more all in.
Entry level salary for tier one firms across finance and tech is probably around 250-300k. Not hard to get to 500k with some experience.
> Like a senior engineer at a FANG
Becoming a Senior Engineer at FAANG is very unusual, across all tech workers.
It's doable with the right amount of work, dedication, and willingness to relocate to the right locations, of course. But it's nowhere near guaranteed or common.
If you get your foot in the door into FAANG and work very hard, you have a decent shot. If you don't want to relocate, that's your problem. There are trade off's in life. If you can't relocate, that's unfortunate.
It's not a problem, it's a choice.
HN some times acts like FAANG is the only acceptable goal for a software engineer, and that all other choices are somehow wrong or inferior. We really need to get past this idea that there's only, single correct decision.
This sudden quit seems similar, specially with the withdrawal of funds to an "unknown address", as if they closed shop and disappeared.
And if you notice the trick? Well, they out number you. You probably won't win in a fight either.
Maybe they were ready to go anyway, but since they work in tourist traps, they probably avoid violence to attract as little attention as possible.
First, you can live like a fucking KING for $2000/mo in southeast asia and most of central/south america. 24k/yr is 208 years. Bonus! The food is awesome, the people are great, the climate is ... nice most of the year, and the pollution is a little awful in the cities, but damn the beaches are gorgeous, and there are loads of them.
Second, ETF index funds for DJIA/NASDAQ/SP500, easily clear 5-7% per 5/yrs in BAD times; bluechip/bellweather stocks & municipal funds pay dividends that would easily clear that after taxes. Investing like a grown adult versus /r/stonks are two completely different things. I recommend you hire a CFPA (or RIA) for at least a few years as soon as you can afford it, bonus if you can do it in your 20's, it will at least set you on the right track.
Of course, once you get old and medical conditions bankrupt you that's a problem. But then you swan dive off of Machu Picchu and go out in style!!
If you do everything perfectly you have a target painted on your back for life, a group of friends that all want to be the first to save their skins by giving the rest of you up, and a huge chunk of that change given away trying to launder that money well enough that you don’t get caught. Not to mention the foolishness that comes with suddenly finding yourself with a big pile of money which is easy to pretend wouldn’t affect you when there’s no chance of it actually being a challenge you’ll ever have.
Your advice to high tech thieves is to hire an accountant?
Best to find a job tending bar in a country not too friendly for an extradition and keeping the money under your mattress to hire the best lawyer you could afford to avoid spending the rest of your life in prison hoping that the CIA doesn’t make you disappear.
This is ignoring the interest
That is why people bring up Russia and North Korea. Those are the two most likely countries that wouldn't. There are a few others, but not many.
Even China which in general I wouldn't trust would in this case. If China did an attack like this it would be much more targeted and they wouldn't be looking for ransom money - See the attacks on the Iran nuclear program for example: attack a target that actually matters. (those attacks were probably US or Israel, but it is the type of thing China might do).
I wouldn't be surprised if the US Government here reached out to foreign governments for assistance in dismantling their infrastructure (it almost certainly was not on US soil).
An individual hospital probably couldn't garner that kind of backing, but oil pipelines? The US would probably be willing to use military strikes to keep the oil flowing. A small country would be very willing to help out to maintain good will.
(This isn't some anti-Russian screed or anything; this is just one particular point where the Russian government is IMO behaving improperly. I could elaborate if needed.)
Presumably in return for some sort of gratuity. Perhaps they decided they weren’t getting a big enough cut.
There's a pretty clear message here that the US isn't fucking around.
Darkside has opened negotiations in the tens of millions in the past [0], with an average demand in the millions [1]
[0] https://krebsonsecurity.com/2021/05/a-closer-look-at-the-dar...
[1] https://www.areteir.com/darkside-ransomware-caviar-taste-on-...
I mean if you have 100M in some account, can you actually run it trough "private" currencies to remove traces? BTC, ETH etc. all seems super traceable, even more so than in regular banking.
Also how are criminals getting their money out with no one noticing, does Panama/Malta etc. have Kraken/Bittrex equivalents with no questions asked?
This is certainly not a given. The government isn’t going to be cracking signal messages within any reasonable timeframe either.
[1] https://www.forbes.com/sites/kellyphillipserb/2020/09/14/irs...
There is a literal virtual tumbler built into the transaction protocol called ring signatures.
Stealth addresses (an additional crypto key pair) obfuscate senders and receivers.
They also hide the amount transferred which blew my mind.
There is no safe, only shades of safer.
Is the mathematical underpinnings of Monero sound? That's a good starting point. There are still implementation bugs, compiler bugs, architecture bugs, supply chain vulnerabilities, and state actors with unlimited $.
Nope.
Monero, ZCash, and mimblewimble-based cryptos (grin, beam) are certainly not pseudo-anonymous, and tracking is darn near impossible if the users don't do anything stupid.
People like to seem like all these crypto's are totally anonymous, but every transaction ends up in some sort of public blockchain. So unless you have air-tight OPSEC and people that will never talk, no matter what kind of jail time they are facing, its always going to be traceable with enough interest.
Most authorities around the world will want to nail you - and or your money - in cooperation with the US authorities (or otherwise for their own benefit). Once they know the US wants you, you become a toy to be used to some end, you're toast, your life is over.
You don't need to live there for very long. Just for long enough to cash out into fiat, launder the money, etc...
Vietnam doesn't like the US for historical reasons, but overall they want to play on the world stage. Also US relations have been thawing over the years. I'm inclined to think they see it as to their advantage to help out.
Similar with China - they want the ability to get at the US, but they are more likely to reserve it for something that matters to them. Money doesn't really matter as much as they get plenty sending the US cheap plastic toys. Though if China declares war next week this could be their first attack (highly unlikely, it is possible though)
Vietnam has a complicated relationship with the US. Don't trust western media too much on it, there is quite a bit of propaganda and extrapolation from conflict with China that doesn't carry over. Relations with the US appear to thaw but this is mainly limited to trade. Strategically Vietnam is solidly allied with Russia and otherwise independent. There is no scenario in which Vietnam extradites to America or allows American intelligence to operate on their soil.
The same is with China. There is zero political cost, they will simply ignore the hackers until they leave the country. US intelligence is quite weak in terms of real assets in China, so uncertainty would be very high.
Plenty of solutions. Mules using exchanges, buying NFTs from yourself, "lucky" investment picks in low liquidity alts, etc
Each localbitcoins account can trade up to $200k a year without any kind of in-person verification.
Also a lot of exchanges let you cash out via western union so... you could theorically send yourself say 10k or 20k a a month with that, there's no need to just withdraw it all at once.
It's super trivial to withdraw, say, 1M. You can use https://tornado.cash/ to mix 100 ETH, there's currently around 10k such deposits, so you could do that 2-3 times to move 1M in ETH to an address that can't be tied to your previous addresses.
It's possible but no longer trivial to withdraw 10M. You could use the above method over a period of time, and some other methods.
It becomes much more difficult at much higher values. You could probably get 100M out disguised as trading profits or something. If I spent a few days thinking about it I could probably figure out ways to mix that much money on ETH, filter through DeFi apps, etc. Seems doable.
You could also just work with large exchanges that don't care. I don't know which ones are like that now, probably fewer than years ago.
But if you do hundreds of withdrawals from tornado, it's less anonymous, because the set of people that have deposited that range to tornado is much smaller than the set of people who did a handful of deposits. Instead of 10k, you might be one of a few dozen or less.
You could always send a million to a friend (through tornado) and have them cash out for a cut, and repeat that 100 times, if you have 100 friends. That would kill on-chain analysis.
For example, I want to buy ZCash that is untraceable to me. I need to exchange ownership of a hardware wallet (like a physical USB device) for a pre-determined amount of state fiat, lets say USD in this case. In order to facilitate this I need to find a trusted seller, arrange a meeting, verify the actual value of the physical wallet, and make the exchange. There are non-physical means of making it harder to trace state fiat back to you, but not impossible. The state has simply had too much influence over these places of transaction for too long for anybody to be truly un-findable given a long enough period of time.
Assuming I can find someone willing to on-ramp me like this I will need to take steps to ensure that our communications are encrypted and untraceable. This means not only do I need a decentralized encrypted messaging service, I also need to conduct this communication in a way that does not give away my geographical location and is not vulnerable to security logs (say by checking the cafe's video feed from the time I was messaging my seller). Then I need to go to the meet, exchange the physical wallet for cash, and verify the amount in it is accurate (and also preferably not stolen). I need to do this without revealing my identity to my seller and avoiding security logs once again. This is all now possible whereas before Satoshi it was impossible, but it is still difficult.
Alternatively, I could just sell some kind of digital asset in exchange for ZCash to begin with. Now I do not have to worry about an on-ramp. If I control my distribution server then I can erase or encrypt my sales logs in order to prevent any estimation of my total sales for the year.
Off-ramping is much harder. I either need to become a seller of a physical wallet which has all the same problems that plagued me before, or I need to live in an economy where off-ramping is not required. This would be a physical location where all transactions are conducted in secure, anonymize, cyrpto-currency transactions. Similar to my earlier problem, this is now possible but extremely difficult. An individual or a group of individuals is going to have to bootstrap an entire local economy.
Being localized is also an issue since there is nothing preventing the USG from simply rolling in the tanks to break up this localized tax haven.
You sell the token in the clean address at a massive profit and cash out under your real name and ID and even pay taxes.
Go look at any highly pumped token on Uniswap/Sushiswap/Pancakeswap and you’ll find plenty of addresses that either bought or added to the liquidity pool using funds that begin with Tornado.cash, there is no way to distinguish the nature of the transaction from simple observation. All blockchain technology is heading to parity with the privacy afforded by traditional banking, without the financial intermediary to question anything for the state.
Less liquidity there, for now. Meaning the exits would more likely be the same beneficial owner, but definitely an additional route for liquidity.
Similarly, I think there should be a version of Tornado.cash that stores notes in SGX and Secure Enclaves, as enough devices have this now. (Although that forces only one device to have the note. Instead of a transferable IOU)
How well does Keplr or Cosmos wallets work over Tor? Are their any onion nodes that can resolve broadcasted transactions?
But honestly, this only shows that IT systems are nowadays so complex that you cannot get them right and be able to truly protect you, no matter if you’re good or bad guy.
Only if that agent has the master keys. Strong security is about making sure that there is no master key.
In accounting systems, which are targets of fraud and malfeasance (e.g. Enron), there is a "4 eyes" principle. It takes at least 2 people to change something that impacts the financials. But that can't stop 2 people from colluding.
Back to the topic, if one agent or informant builds trust with one actor in the target group, and they collude or if one slip is made, it could be game over. Once the org is compromised, how do you know who to trust?
But it’s really hard to build systems and organizations like that.
I would say invest more thought, less money.
For example, use open source more. Minimize the amount of data and information you have that needs to be closed source.
Avoid Windows. Use Gmail over Outlook. Have offline backups with sneakernet disaster planning. Get a cheap safety deposit box for storing keys. Use 2FA. There are lots of free/low cost ways to have better security.
Why would you recommend this? I can understand the reasoning behind the rest of your recommendations, but not this one.
Telling people to just use Linux as a remedy doesn’t help. If you don’t invest into securing your Windows infra, your Linux infra will be also full of holes.
I do not think you can have secure Windows infrastructure today. In the future, a few years after it's fully open source, perhaps.
Of course you are free to make your own bets.
Open source doesn’t make stuff magically secure. Remember heartbleed? Or how easy it’s was proven (by sketchy research, sure, but that’s secondary point) to bring malicious code into THE open source project, Linux kernel?
Believing that by simply using open source you have secure infra, and that by using Windows is naive view by people who never seriously worked on security for big companies.
I say all of that as a heavy Linux supporter. Linux is better, yes. But it’s not a magic bullet. I’ve worked in Windows shops that had extremely good security, and Linux shops that could’ve been hacked by someone after one day classes of how to be a hacker.
Sure you didn’t.
They'd just take the money and disappear. The fact that they are continuing means that they want to continue the business.
And if they are doing that, then why would they suddenly break all existing contracts? Surely that would ruin a lot of their reputation, and hurt their ability to get clients. Can you imagine what kind of amazing free PR they would be getting if they continued the attack? Surely other criminals would be amazed at their ability to resist counter hacks. That would mean more clients and more money.
No, no. While I'm sure there is theft in the ransomware world, I don't think you make this kind of play from a position of strength.
So, I think there's a good case to be made that this is the best course of action, given they are scared but don't want to quit entirely (which seems clear). It isn't nearly as bad a hit to their reputation as just taking the money and running, so they don't have to hide their identities and rebuild new ones to start over in crime, and they don't lose nearly as much money, and they probably won't lose the clients they actually care about.
These people need to be found and imprisoned
I’m mildly surprised they survived this long
Imagine feeling hurt that your low-key mob activities are equalled to high-stakes mob activities, so much that your consider it "dangerous" and "toxic". Really love the irony here.
Well, their cyber security may not be the most advanced, but traditional security (i.e. military strength) likely dissuades criminals from choosing those targets that are likely to put them on the short list.
"Look guys, yeah, it's really easy to hack the power plants that supply electricity to the white house, but then we'll all have military ninjas showing up in our bedrooms at 3 in the morning. So if you try that little stunt again, then we're going to get our own ninjas to give you a visit. Go hack a cereal company or something."
The game changed when the valves to the pipeline were closed as a precaution. They just went from thief to threat.
>“However, a strong caveat should be applied to these developments: it’s likely that these ransomware operators are trying to retreat from the spotlight more than suddenly discovering the error of their ways”
Other than that, there are no giveaway spellings or idioms. It could just as easily be someone whose exposure to English is dominated by technical documentation, which tends to use mostly American style.
I grew up in the US but lived most of my adult life abroad, and the only thing I can tell you for sure is that you should never stereotype anyone based on the way they use their second or third language.
Might have something to do with many of these rules being derived from Latin and their native language is probably closer in structure to Latin than English is.
If I were to write a long piece, you'd almost certainly notice that I'm not a native speaker. I'm subscribed to a few Telegram channels led by Russian speaking people and I always spot minor mistakes in their messages. Even when the text is grammatically correct, the way sentences are structured is what usually reveals them. I observe similar pattern with the partners I work with. Heck, even my English teacher's English (she is my friend on FB) is different from a typical writing style of a native speaker.
It obviously doesn't mean that Russians cannot learn a more "traditional" English, but when it comes to Russian hackers...meh, the chances are low, imho.
I think a native English speaker would have written either "I observe a similar pattern" or "I observe similar patterns". Your choice of words in that sentence feels russian to me (although I may be influenced knowing what you told earlier).
Still relevant
[0] https://news.ycombinator.com/item?id=27097966
___________________
There is a theory floating about that some ransomware attacks were done purely to damage a country's infra and making money was a bonus, but not the main aim. So the perpetrators used ransomware as a front and the real goal is to destroy and disrupt a country's computer infra.
But then we could argue ransomware is just going to bolster and make our systems antifragile and resilient against such attacks in the future, so the ransomware attacks could backfire since in the future it would be much harder to attack the US for example with other types of malware.
It also means people are going to be storing mission critical and crown-jewels type data in airgapped systems and making filesystems read-only. The data would also be encrypted and compartmented into separate containers so attacks can't affect the whole filesystem if the airgap was breached.
If I were these guys (I am glad I am not), You have just brought down far more interest and heat from now just law enforcement but probably at least a couple of intelligence services.
Arranging your own death would seem like a reasonable thing to do.
All our money is gone, stolen. All our servers are gone, grabbed by law enforcement. We have nothing left. Bye.
It would be interesting to follow the Bitcoins traversal around the network.
Surely, they're not storing their bitcoin keys on some aws linux box are they?
"So for instance if you run a ransomware business and shut down, like, a marketing agency or a dating app or a cryptocurrency exchange until it pays you a ransom in Bitcoin, that’s great, that’s good money. A crime, sure, but good money. But if you shut down the biggest oil pipeline in the U.S. for days, that’s dangerous, that’s a U.S. national security issue, that gets you too much attention and runs the risk of blowing up your whole business"
https://www.bloomberg.com/opinion/articles/2021-05-11/crypto...
How do you "seize" bitcoin?
Key lesson as summed up beautifully by an old timer in our team "You don't mess with big oil."
https://www.cisa.gov/critical-infrastructure-sectors
Pretty easy to identify what is Critical Infrastructure.
The bigger reason for more coverage is optics. People take money out of their wallet on a regular basis to pay for gas. Gas gets them to their job, where they can then make more money to pay for gas, food, and so on. If Gas is affected, their job, their routine and their wallet is affected.
It is kind of ironic actually, the ransomware targeted billing systems of colonial, however they didn't really secure their own money.
Some pretty good karma/irony there. They left wallet keys laying around on a server.
Are they armchair criminal masterminds who don't really have a visceral understanding of how much damage they're doing? Or just straight up psychopaths? I can't think of any other options.
"The REvil representative said its program was introducing new restrictions on the kinds of organizations that affiliates could hold for ransom, and that henceforth it would be forbidden to attack those in the “social sector” (defined as healthcare and educational institutions) and organizations in the “gov-sector” (state) of any country. Affiliates also will be required to get approval before infecting victims."
They aren't trying to cause this kind of harm.
Additionally: "DarkSide organizers also said they were releasing decryption tools for all of the companies that have been ransomed but which haven’t yet paid."
This people have more morals then most rich businessman, IMO.
I don't know nearly enough to guess, but it doesn't seem cut-and-dried to me that this is a case of them realizing what they did was wrong.
In any case, the same question still applies for what happened before: why were they in a psychological state that made them try this in the first place?
Even if we grant that they've changed their tune for moral reasons, that would rule out straight psychopaths, but would include people who had severe antisocial traits but still started to have some feelings about it once they saw the real-life consequences. We see this with repentant murderers.
As far as rich businessmen who do evil stuff, there's a literature on that, and it seems to be a complicated mix. There's "just filling my role" (for those not at the very top of their organizations), thinking you'd be replaced by someone else doing the same thing, dissociation/denial about what you're doing, and -- yeah -- straight up antisocial/psychopath types. And more. It's a fascinating topic.
You've finally figured out that extortion is bad, well done.
"Dark Side" is a silly name & I know of many silly security folk. Seems like a cultural fit somewhere...
Looking forward to the day when someone proves there is nothing the state can do. But for now we have to watch these lackadaisical shit shows.
I sincerely hope that no companies had paid the Tsar’s ransom before Sergey headed off for his dacha in the Urals. Forking out millions and still having your network out would be a bitter pill indeed to swallow."
Guessing the US leaned on some other country hard to confiscate servers asap...
Loads of "bulletproof" hosting locations but don't think any can withstand that kind of focused above national law type pressure
They want a certain type of police/authority chasing them for financial crimes, not special forces cutting their throats in the middle of the night because they're perceived to be terrorists attacking a superpower's critical infrastructure and trying to harm large numbers of people.
It was probably planned all along.
“Tech audit of Colonial Pipeline found ‘glaring’ problems”
https://apnews.com/article/va-state-wire-technology-business...
I believe they shut down the pipeline because they were unable to bill.
The pipeline did not need to be shutdown because of a danger to infrastructure, it was a corporate management decision to protect the company’s interests.
Colonial used a ransomeware attack on their company to do their own form of retaliatory blackmail on the entire southeast US to get a state level response and avoid the payout.
The above is not a defense of ransomeware, and I understand why Colonial acted as they did/it seems to have worked. They likely would not have gotten state level help had they not shut down the pipeline. But they have a larger level of responsibility for the damage caused by the pipeline shutdown than is being portrayed.
Just goes to show how unsophisticated they are and how low ransomware game barrier of entry really is.
if it was this possible before, why wait until now?
Or, if it isn't true - perhaps they're deflecting attention.
:-)
Kudos if that was a deliberate joke.
Whoever called this an insult isn't paying attention.
How do you feel about Wikileaks and the prosecution of Julian Assange?