Interview with a ransomware group
therecord.media
therecord.media
Also, notice they did not mention any concern the FSB would invite them for tea, pay respects to their families, or any other ... imperial entanglements. This says a world about their standing in Russia, whether tolerated, encouraged or some other arrangement.
A hacker group in Russia declaring to only target companies in the USA and Great Britain is like a US group that only targets Iran and China. US agencies probably wouldn't find time in their busy schedules to go after someone targeting Iran either.
But yes, you are correct.
Interestingly, they answer very clearly:
> We have not been involved in legal pentesting and we believe that this could not bring the proper material reward.
They're in only for the money, so the answer is "yes".
Ransomware is not "grey" work though, if this is the implication; it's extortion, which is illegal.
Assuming that one has valid job alternatives (and they definitely have, since they're highly skilled professionals, with an available market), one needs to be have a certain degree of sociopathy in order to be able to do this line of work.
Since direct violence is involved, in my opinion this requires a degree of sociopathy.
I'm not sympathetic to spam groups either, but at least their profession doesn't have a direct contact with the victims.
some people are just outlaws and choose to do things because they are not allowed normally. so I'd say yes.
It’s a rational decision: Their method of making money is to quietly and without a fuss extort money and have the victim pay.
Attention just brings heat to their operation.
So I can just pad all my valuable data by 1MB?
However, my reply was to someone wanting to pad all of their valuable data with 1MB of fake data so if they were hit with a malware virus it would not actually screw up their data. Nevermind, that 1MB would screw up normal use as the apps would not know how to handle that padded data. But you know, yes, if you totally miss the point of the thread, I could see where thinking the point was the lack of failure of malware.
I wonder if they have leetcode style interviews :)
> BM: We think that this was a key factor for the closure of REvil and DarkSide, we have forbidden that type of targeting and we see no sense in attacking them.
I think it is your answer, too risky.
I'm all for reformed criminals giving interviews in the context of what they did being wrong, but this is an interview about how they're getting better at their crimes.
Regardless of how easy it might be given security practices, these are crimes, and they are crimes for a reason: they cause damage. Their impact is felt beyond the ransom money paid, it's felt by employees who may be put in terrible positions as their work is held ransom and who might pay up personally to avoid problems at work, it's felt by customers of these companies who end up with higher prices, it's felt by countries as their output is hit. The fact that this "industry" is getting more "professional" does not change the fact that it's harmful. They don't deserve the publicity and attention that this sort of platforming provides them.
The only difference is what these people do is illegal while what the companies do is not: the damage, though, is arguably on the same scale, if not lower for ransomware attacks depending on which infrastructure is attacked.
How about holding people for ransom that is equivalent for sure, how about killing people? Well oil industry eventually ends up killing some people.
Let’s put a stop to oil industry before we deal with the kidnappers and killers!!
Nobody said there has to be a priority. Why can't we stop both?
Moreover OP comments was not talking about stopping them, but about giving these people a platform.
Despite the damage done by oil companies they are still allowed to spend billions of dollars in marketing, lobbying, etc... Resulting in a much bigger, legalized, platform, while still causing way more damage than ransomware "companies".
How stupid people are on our planet, billionaire people are really very stupid people ... Put a scientific researcher and an entrepreneur to debate on any subject and that's when you realize that most "entrepreneurs" have the coefficient of a 5-year-old child.
why do we never see Elon Musk debate with researchers if he has as much intelligence as he says (the techno king)? It must be so as not to make a fool of himself on television (or youtube)
There's a huge difference depending on "details"
I'm just pointing out that oil companies have caused way more damage than this guy and they have had a massive platform for decades, why shouldn't we stop giving them a platform as well?
Because one thing is illegal and the other isn't? In a society that holds laws relatively high that should be a super good argument?
On the other hand, society has decided, via law making, that ransomware attacks are deserving of punishment.
With so many differing opinions it's hard to please everyone. I'm in favour of having a range of voices that I might not agree with represented in media, but criminals advertising their crimes and talking about how they're getting better at doing it feels like it's fairly clearly past a line.
These are organized crime activities akin to cartel kidnappings, Somalia Pirates, mob extortion, and kidnapping tourists for ransom. 21st century pirates/mobsters.
How long until ransomware becomes extortion or protection schemes? Pay us a yearly fee and we’ll not hack you and if someone does hack you we’ll hack them back.
Nobody is justifying anything, I'm just saying that if it's wrong to give these people a platform, why is it ok to give it to oil companies? The latter have caused way more damage than a random ransomware group.
It's easy to reply by labeling anything you don't agree with as whataboutism, because you don't have to go into the merit of the discussion. You don't have to articulate a reply, you don't need to reason about it.
I made a pretty simple analogy, and the only one who actually replied with something sensible was OP, which I appreciate.
Everyone else just tried to find logical fallacies (like now we need to stop nurses from giving birth) or just discredit the argument but without providing any meaningful reason.
Most of the damage oil companies are making is legal. At the moment fracking is legal but IMHO it’s very damaging. Undersea oil drilling is legal but there are many accidents. Shipping oil is legal but there are a lot of accidents that cause massive environmental problems.
Ransomeware is never legal and organized crime is not legal in the West. They should not have a voice at all and should be treated like the criminal organizations they are.
Why do you assume GP is ok with that.
Meanwhile, GP is explicitly putting words in my mouth, but I guess it's ok because my comment was just whataboutism, right?
let me rephrase this: do you think corporations are "good"?
some corporations provide value to society. some don't. the evaluation of this will depend on your personal values.
my personal values do evaluate ransomware as "wrong". and the laws of most (all?) countries evaluate ransomware as illegal and thus legally "wrong".
This outcome was inevitable, and hitting the bean counters where it hurts (financial bottom line) is the only way to effect change.
I'm being somewhat facetious, but I want to live in a society where not being hyper focused on all forms of security at all times, and just being _safe_ is an ok way to live your life.
"It's easy so we'll do it" is not a defence of this practice. The only reason the security is needed at all is because of people like this. I'm not saying security isn't important, but being bad at security is not a defence of people who take advantage of that poor security.
If your business is taming wild animals, should you have metal bars around them?
No, but employees and customers are, and they feel real, human costs as a result.
Just because a management team has underfunded security is not an excuse to cause pain on other people.
Sorry, but that's just not correct. It's always someone's job to clean up this mess, and that falls on individuals. If they have to clean up a stressful mess, they definitely do care. A lot.
I've had to clear up messes in the past, and it severely negatively impacts my mental health. Never, ever think that it's a victimless crime. They might not feel the force of the actual crime itself, but there are most definitely employees out there where the second-order effects on their wellbeing are starkly negative.
Again, for customers, you never know what those second-order effects of the delayed cost would be. I'm not going to whip up slippery slope arguments, but again, you're assuming that customer interactions with companies are all one-sided "I can do this later" kinds of interactions.
We shouldn't hand-wave away bad things because they only impact some faceless "company". Companies are made up of individuals, most of whom don't want to be there, but most definitely care when they're forced to do more work by some bad actor.
Unless your company is exploiting you, of course.
Suffice to say, this crap has impact on real people, in the real world. To imply it's just some neutral action doesn't reflect the reality we live in.
Now, sure, the IT dept in question could have handled this a little better. Maybe. But the presence of these advanced threats forced IT's hand here.
I've seen this happen more than once, where IT spells out the risks and recommends tighter security practices, more security hardware/software, more backups and redundancy, a bigger security team so they're not just running around fighting fires all the time and have some resources to improve security, etc, but these requests are denied because there's not enough budget for them or they're too inconvenient (as security is almost always a tradeoff against convenience).
Then there's a security incident and suddenly money materializes out of nowhere and they'll pay whatever it takes to get back online, making the security and IT teams work nights and weekends until the incident is resolved.
At the same time, security look like incompetent idiots for letting the incident happen in the first place, with everyone conveniently forgetting that multiple requests to tighten security were denied.. and many other people in the company don't even know about what happened, but consider the security team to have screwed up.
So security often wind up looking like idiots, though it's not their fault. Or maybe there really was a screwup by someone who's no longer with the company. Dealing with gigantic legacy systems and endless complexity that no one fully understands is common.
When the security incident blows over, those security budgets shrink again and the importance of security dwindles as other parts of the business take precedence, until the cycle repeats again and again.
Or security really is taken seriously at some companies, and then the security teams are often seen as the "no men", and widely despised because they stand in the way of getting work done.
These reasons and more is why I don't like to work in a security role. Let someone else take the blame.
The reason that it’s ok to have a shitty $80 lock on your front door or an unprotected window near ground level is that the value for a would be burglar to break in for a crime of opportunity is low. If you’re a well known jeweler or gun collector, you typically take other measures because you may be a target.
Cryptocurrency made computer crimes profitable crimes of opportunity.
The reason we have child pornography is that people don't need to have their photographs developed by a chemist in a photo lab anymore. The photo lab chemists would've turned them in to the cops.
Platforming criminals and making sure more people understand their competence and the threat model is a good thing. We should be scared.
* become better able to defend themselves
* become better motivated to defend themselves
* better understand how to deter these attackers
* become more motivated to seek action from government or vendors to deter these attackers
* have a more informed debate about the ransomware industry or organized crime as a whole
...?
Edit: for example, things that I had heard that were confirmed for me by this interview include that the Russian government is consciously tolerant of this activity (maybe someone could find ways to change that!?), that organized crime fears being caught or attacked by NSA, that ransomware attackers are very sensitive to their reputation and public image, that you can probably count on them to keep their side of their illicit bargains, and that they are especially motivated by money rather than ideology. All of those seem like pretty interesting ideas that might be hard to confirm quite as well in other ways.
This is an approach of like "okay lets just ignore your rational for not doing that and give the hackers a platform until you change"
These are multi-million (billion?) businesses. There's strategic leadership, target acquisition pipelines, R&D, talent recruitment and coordination with other businesses in the space.
There's every indication that with a little bit of protection money, you can even run your business with no interference from the law, as long as you don't mess around in your own backyard.
You can see from the blog post, that this "company" has done a product-market-fit analysis. They've taken a look at their competitors' work, considered the pros/cons, and decided that they can do better. Since they are a b2b company (hehe) you can be reasonably sure this is not some PR aimed at consumers. I think it reads as a recruitment pitch to their lead generators (read: hackers whom infect other networks for them).
You can see the pitch, it almost reads as a vacancy post:
- We make a lot of money
- We're new to the scene but already have had success
- We only work with the best hackers
- We pay you lots of money to infect a network, if you got what it takes
DS: Obviously, there are many talented professionals on your team. Why is it that this talent is aimed at destructive activities? Have you tried legal penetration testing?
BM: We do not deny that business is destructive, but if we look deeper—as a result of these problems new technologies are developed and created. If everything was good everywhere there would be no room for new development.
There is one life and we take everything from it, our business does not harm individuals and is aimed only at companies, and the company always has the ability to pay funds and restore all its data.
We have not been involved in legal pentesting and we believe that this could not bring the proper material reward.
For me the line between organized crime and robin hood is very blurry.
This is such a transparently self-serving joke of an excuse.
A serial killer could likewise say "Sure, I kill people, but as a result of my murders the police develop new forensic techniques."
Right.. as if that justifies anything. These people are just interested in money, no matter who it hurts. They are sociopaths.
I guess if you're ok with taking something that isn't yours you would see no problem with this. The rest of us see this as sociopathy.
That some countries legalize theft of property in other countries does not change the ethics of this at all.
> That some countries legalize theft of property in other countries does not change the ethics of this at all.
It literally does. Because those people are participating in a society where their actions are not strictly unethical. Their society does not necessarily view them as sociopaths.
Well I should concede it depends on whether your worldview accommodates different ethical frameworks or not. If you are absolutely ethical then all people must adhere to the same ethical standard and you can rightly justify punishment of outsiders.
We're not arguing about whether that's ethical, we're simply pointing out that people like that exist.
You and the parent commenter are no longer arguing about what is and isn't ethical (as you've stated, you both seem to agree), but instead on what to do about the practical reality that society in Russia does see this as ethical, and doesn't give a flying fuck what you or I think.
Now the question becomes, what should we do about that.
They outright admit that they see the targets primarily as money bags, and that they are making the economy better in exactly the same way that breaking windows makes the economy better, and your opinion is that it's ethically blurry?
No, they are pursued aggressively by the government because they compete with it.
Based on the recent pipeline incident, it seems that these crime groups realize there are other places you'd better not mess around.
Screw with Bank A or Company B ... fine. Screw with infrastructure of a country with a large scale military, control over large chunks of global finance, and so much more ... probably not a good idea.
When I was a mainframe programmer at IBM, one of they first things they taught us was how to stop the processor of a System/370 machine. If you can do that, ladies and gentlemen, you can bring down Bank of America, the US Army, the Social Security Administration, etc. So everyone there knew how to be a "black hat" hacker if we wanted to.
Was there money to be made in that? Surely. More money than IBM ever paid anyone! But the reason neither I nor any of my colleagues would ever dream of using our skills to hurt people is that last part of the sentence: it hurts people.
Yes, IBM did some awful stuff from helping Nazis to keeping apartheid alive in South Africa (over employee objections while I was there), but overall, the "corporation" provided valuable goods and services to real people who had to slog on in real jobs every day to get the world's real work done.
Oil companies are in the same boat. The world runs on oil and some ransomware attacks aren't going to change that. The idea that terrorism (and black hat hacking is absolutely a form of terrorism) is a useful way to change corporate behavior is so ill-informed that it's pathetic.
When asked about taking a "white hat" approach and selling legal pen testing (or even PTaaS), these developers declined saying they probably couldn't monetize their skills at the same level that way.
Well, I say, too effin' bad. If everyone optimizes solely for himself, there will be no one left. It's appalling to me that criminal organizations now recruit, have price lists, and get PR placement. These people and their products (and their communication channels) need to be turned off ASAP for everyone else's sanity and self-preservation.
They are self-admitted criminals. They admit to be in a destructive industry to line their own pockets. The only reason they are selective in their targets is because critical targets will increase the chances of them being caught.
But they can't be because enough people don't share your worldview. Do you believe private communication is a human right? Well then you can't stop them communicating either. How would we achieve a world where these products and services could be universally banned immediately?
You are right, the problem is ethics. The problem is that it's not universally criminal to attack other countries' wealth.
If it came out that this group ran their infrastructure on IBM cloud, and you still worked at IBM, what would you do? It seems you think that the generation of wealth for IBM's shareholders is more important stopping genocide therefore it's okay to be complicit. So you seem to have some general notion of ethical total harm.
> The idea that terrorism (and black hat hacking is absolutely a form of terrorism) is a useful way to change corporate behavior is so ill-informed that it's pathetic.
It does change behavior, though, whether you like it or not.
Private communication, even for business, is a human right. I was not suggesting that some authoritarian arm "shut them off," but rather that a profusion of businesses and individuals simply chose to ignore them. Death by recission.
It's also one's right to choose to be in an ethical business or not. I've rejected many customers and employers because I didn't want to help in their aims.
I was among the people who protested IBM's continued involvement in apartheid and it did end before I left. Companies can chose to "not be evil" or they can just say that.
And yes, sadly, everything changes human behavior. What I was going for is that ethics is a practical phenomenon as well as nice one for other people. I still believe that more can be accomplished through volunteerism (including volunteer agreements about money and work rather than coercive ones) than through violence. Perhaps that's naive or hopeful but I hope a few of us persist in keeping the idea alive.
So yeah, a Russian.
Correction: this is free advertising for criminals _actively looking to recruit associates to assist them in committing crimes_, and helps them commit crime.
Don't upvote "Weapons Smuggling, Inc. (YC21) is hiring a coordination specialist for EMEA operations"
I cannot argue against it?
To me what's more obviously wrong whether I'm rich or poor is leaking personal info on employees, HR correspondence etc. I don't know whether this group would since they say it hasn't got that far yet but other groups have.
Extortion, mugging, burglary etc are worse than the "perfect theft" where you move some numbers from one account to another.
I wonder if the people involved believe their own spin that "your boss is the one at fault, would rather you suffer than pay"
Are we really going to justify this just by "it is against the law"? So many things are against the law, so many ancient laws demonstrate the inability of humans to create the absolute corpus of ethical behaviours™.
The Kantian categorical imperative goes something like, "act as if the basis of your actions would be made universal law." What happens if everyone conducts denial of service and ransom attacks against anyone they perceive as a legitimate target?
https://www.aamc.org/news-insights/growing-threat-ransomware...
https://www.wsj.com/articles/the-ruthless-cyber-gang-behind-...
I think it's kind of neat that we're waging war via bit flipping instead of meat flipping, let's call it progress.
Take any organization you think is "worthy" of being attacked in this manner, and consider all of the implications of such an attack. Think about the people inside the organization, and those outside of the organization that benefit from that its continued operations.
I think it's fair to say the public opinion of oil companies is fairly low; however, arguably the biggest impact of the Colonial Pipeline attack was not on the executives running the company, but on the end customers of gas stations unable to fuel their vehicles due to the shortage (whether truly real or created by panic). I would argue that everyday workers unable to get to work or to the store to buy food is more important than a few executives not getting their bonuses or having their shares lose value.
This isn't to say that these corporations are above all reproach and should be allowed to continued operating in whatever way they see fit simply because they have employees and customers are relying on them. But it's also the wrong mindset to think that it's OK to attack corporations in this way just because they "deserve it" in some way.
Médecins Sans Frontières is a huge company. Their annual budget is around $1.6bn. Are you ok with them being subject to ransomware attacks?
> It would not extort healthcare, critical infrastructure, oil and gas, defense, non-profit, and government organizations
There is so much collateral damaged created by this sort of attack against any company of sufficient size. It's easy to wave your hand and say they're a rich company they can afford it, but no company exists in isolation, they're all part of economies, and ultimately it's real people somewhere who take the damage.
Leeching off of companies is kind of like stealing a grain of rice from everyone. The company's costs increase and the price eventually makes its way back to the consumer.
Another way to think about it is the total amount of labor needed for the world to operate as it does. In a world that has no ransomware, the labor needed is X. In a world with ransomware it is X + cost of building ransomware + cost of dealing with ransomware.
I'm sure the criminals console themselves by thinking about it that way, but as someone who had to use an emergency room and was denied other services during the month+ Scripps was down (during a global pandemic, no less), it was easy to see how ransomware attacks can directly hurt an enormous number of employees and customers.
My point was that ransomware is wrong even in an idealized abstract scenario where it only targets non-critical companies.
Thanks for providing your experience. It drive home that in practice it is much more like beating and robbing many people than it is like stealing just a single grain of rice from them.