What would you do if you were a foreign intelligence service? Participate in attacks yourself?
No! You would drop hints and supply tools sideways to sloppy groups of idiots enabling them to be destructive, maybe acquiring some funds, and keeping your hands as clean as possible. Then when it comes out that "elite russian hackers" were incompetent idiots, it makes people think the claims of your connection to the crimes are even less likely.
Tricks and disinformation are the name of the game.
If you actually were elite, you would hide and practice and save your actual actions for critical moments and not show your hand for a few million dollars. Or you'd go into security consulting which is a far safer, more profitable, and overall smarter thing to do.
exactly. Look at stuxnet - nobody knew it was an attack until it was over!
There's enough self-styled cypherpunk infosec experts that might insist on being paid only in BTC and then lose their decrypted wallet...
Even if you’re completely amoral, getting a hefty paycheck, 401k, etc. is going to be appealing to most people with that skill level. It’s not a coincidence that a lot of this happens in places where people have poor career options which makes that more appealing.
If there are millions of people trying to ransomware businesses and hundreds of important businesses with really bad security, depending on how talented the best hackers are - the odds could be quite high you get hacked by a not-so-talented hacker.
this is a true criminal SaaS, partly because its low risk, high reward for the developers and partly because its a russian funded op that needs to cover its ass in the nature of its attacks on democracy and corporatism.
Why not. Remember Elite Russian GRU hackers identified because they all registered their cars with the DMV at the same address? https://www.bellingcat.com/news/uk-and-europe/2020/10/22/rus...
Smart people do dumb things.
They just happen to be in an untouchable legal jurisdiction.
Can't wait to read this report!
If you imagine the extremely unlikely scenario where the DOJ put out a statement that anyone in the US who happened to extract money out of persons or companies in Russia would not be prosecuted or hindered by US law enforcement, what sort of people would jump in to try their hand at that. It seems to me it would certainly be an attractive idea for script kiddies to jump on to if they felt it was low/no risk.
The responsible vulnerability was in Java applets, which I had disabled for security reasons. But Java secretly re-enabled itself after updating. I kept Java uninstalled for a long time after that.
What is it that's so implausible? That's just one possible interpretation. I see many possibilities here. Below are some, where "The FBI" loosely refers to the bureau, collaborating agencies and their partners and contractors:
* The FBI has (through active exploitation of hosts/services) gained access to a large number of BTC private keys, which they can utilize if and when they become a point of interest
* The FBI has some channel to index and get access to cryptocurrency wallets/private keys from hosts running on cooperating service providers such as GCP, AWS and Azure.
* The FBI continuously monitors for BTC addresses/public keys and opportunistically bruteforces them looking for weak keys, keeping a catalogue of broken ones and waiting until they become a point of interest
* These coins were sent through some anonymization network/protocol/service and the wallet in question actually has no relationship to the hack at all but just belonged to some clueless user.
I have already been assuming all of the above to be going on and this particular instance could be a result of either.
There is also the more boring explanation that these 64 something BTC was supposedly "tumbled" but not enough, transferred to a centralized exchange and subsequently frozen. It's also important to remember that it's not a single group/entity responsible for the whole chain here. Darkside provides the software and affiliate program, and maybe some servers. The attacks themselves are performed by "partners" (who just pay for access and could be anyone anywhere). Most likely the wallet here was not under control of Darkside ("The Russan elite hacker group") themselves but some affiliate who could be anything from a "lucky" clueless script kiddie and an actual professional who made one stupid mistake along the way.
True crime stories abound with comical errors (as do plenty of true not-crime stories). As it turns out, real people fuck up in comical ways all the time.
> I'm supposed to believe some elite Russian hacking group keeps their crypto wallets running on a US host where the FBI just logs right in and snatches the private key?
No, you aren't supposed to believe either (a) that DarkSide are an elite group, or (b) any particular narrative about how the FBI got the private key. AFAICT, no one is selling the first claim, and the only people selling narratives about how the FBI got the private key are doing conspiracy-theory-level creative interpretation of documents.
At the same time, the obvious tin foil hat answer of it was the feds who concocked the entire scheme also doesn't add up. If the NSA/CIA was behind it, they would be smart enough to not use a US based server / wallet. That makes the story inconsistent, and brings up the questions I am asking here. Instead, they would just use a clean wallet (preferably out of Russia). I.E. the misdirection and misinformation does not add up if it was an "inside job" by the US government.
If SHA256 and asymmetric crypto are compromised to this extent, we have a far bigger problem to worry about.
EDIT: as "koheripbal" says below, maybe their tumbler is a boob (paraphrased).
> According to FireEye, affiliates are required to pay up to 25% of ransom payments under $500,000, and 10% of any successful extortion attempts over $5 million.
So the ransomware authors might not always be the people collecting the initial payments. Although according to the press release here, it was siezed from the DarkSide group itself? So it's still a bit confusing.
They're downloadable and leased out.
This allows people to focus on choosing targets instead of the entire vertical integration and liability at each step.
From when they planned for the capacity, probably not. But how do we, at any time, know that hasn’t happened in the past?
> A government 51% attack would probably involve doing a private chip run.
Sure, and when that classified capacity is acquired via, say, the NSA’s black budget, we’ll all know before (or, heck, even after, until they decide to something disruptive with it) they decide to light up the capacity...how?
OTOH, any attack won’t just be to redirect funds, because that can’t be done without broader disruption that would make it pointless for that purpose.
51% attacks don’t allow for withdrawing funds from an account - only for rolling back recent transactions
As long as the ignorance stays high, they get government contracts
Genuinely curious why you think your response was related or even mutually exclusive
Think about it for a second.
If they wanted to discourage copycat criminals, the easiest way to do it would be to claim they seized the crypto, right?
But what proof do we have that the feds actually seized anything? Is the bitcoin transaction publicly listed anywhere where we can audit what happened? And even if you see the coins were moved, how do we know it was actually the feds that moved them and not the actual criminals?
I'm sure the feds will sell the bitcoin in the fullness of time, like this:
Not saying that’s what they will do, just that I think it would make sense to me.
If the feds falsely claimed to have done it, the criminals could embarrass them by moving the coins again.
Um, what? Did you do a survey of all people who are good at computer security?
Furthermore, maybe the attackers _are_ working a legitimate job. Do we know attacker's life details?
They host their hacking tools and other software close to the victim because if you see your network infrastructure logs linking back to an IP address in Russia or China for example it would immediately rise alarm and suspicion.
“Russian hackers” once again, eh?
With ransomware criminals, “us” is the attacker, and “them” is everyone with a computer who might pay. Political boundaries don’t factor in to it at all. It is by nature an anonymous attack, hence the term “ransom”.
It is strange to me that almost all high-profile ransomware attacks that have been publicized in the US are claimed by the FBI to be Russian or Chinese. There are plenty of other countries with greedy criminals that know software, too.
It's simply not true that political boundaries don't factor in. They're a massive part - most obviously, consider extradition or whether the attacker's government will cooperate with the US.
* I say many, but it's more like "it happens", but it feels important to point out.
Do you really think that's not the case, or that that isn't going to considerably skew where these attacks come from?
Badly, I guess, because no one has mentioned evidence or a lack of evidence anywhere in the thread.
> How exactly do you determine that a hack originated in Russia when Russian ips will not hand over their traffic to US authorities?
There are a lot of different ways. GEOIP is just one method. Examining the artifacts for code-reuse from other malware is another big one. Looking at the types of attacks is another ie: "this malware uses these techniques, and these are favored by groups 1,2,3".
There's a lot more to it than that, and not all of it is public. I've seen attribution done through backdoor channels that were not strictly legal.
> In reality, our cyber security agencies have no idea where these guys are coming from
No, more often than not we definitely do.
Attacking things in a foreign jurisdiction is massively appealing from a "what will get me thrown in jail by my own government if things go wrong" perspective. You don't need any political loyalty for that calculation.
There can only be one explanation: russian hackers operating with Putin's tacit approval. Us in the west should add this to the mounting pile of "evidence" supporting going into another cold war, because that will surely improve the entire situation. Attributing the unattributable to our preconceived enemies to escalate a conflict always ends well.
Snark aside, on a technical, factual level, this simply isn't evidence of origin, not even a little bit. "russian hackers" is such a tired punchline now that if I, being in the west, were to suddenly jump the fence after 3 decades and choose A Life Of Crime, using russian configuration file names, UTC+3 daytime operating hours, russian-hosted c&c IPs (or, better yet, russia-controlled but plausibly deniable ones like belarus or kazakhstan), and silly stuff like skipping infection of ru-locale machines would be obvious things I would be doing to fuel this existing narrative sailwind. It's utterly silly to think that this in any way suggests origin.
There are numerous incentives that, to me, make it not only reasonable but extraordinarily likely.
To me all this seems par for the course. There's nothing unusual about any of it. It's what you would expect. It's basically like distributed stochastic terrorism, indirectly/loosely driven by a more capable state actor with specific intent to establish deniability.
Not even plausible deniability. Just some convenient way to say 'Nyet! And we are VERY OFFENDED that you would even suggest such a thing!'.
Just the fortunes of war, really.
It’s not a conspiracy. You just have the cause and effect backwards.
Maybe the US struck a deal with whoever did this to safe face or something.
What does one do for Bitcoin, short of a hard fork?
This assumes perfect opsec: the guy is unphishable, has a quick-response switch to wipe their computers when their house is raided, etc. They get a lot of people through simple gaps: bust the door down when the target is in the bathroom, grab the unlocked computer in a public setting, etc.
The other big assumption is that the only copy of the key belonged to someone in the gang who is a high-value target. If it’s an exchange, they need to make an official request. Someone offering laundering services or a lower-value person in the gang, the offer is likely going to be offered a plea bargain for cooperating to get bigger fish versus a much longer sentence.
Even if it is the most culpable member of the gang, the prospect of a very long prison sentence versus something shorter is going to weigh heavily — especially if you know that they’re just going to leave you in jail until you give them the key anyway.
Anyone competent enough to extort a foreign company out of millions is not going to attempt to cash out through an exchange.