This is what makes Ransomware as a Service so dangerous. It's basically franchising. The actual REvil gang gets to outsource the arrest risk to a third party and still gets paid billions.
This is what makes Ransomware as a Service so dangerous. It's basically franchising. The actual REvil gang gets to outsource the arrest risk to a third party and still gets paid billions.
Also: a McDonalds job is better than being a street corner dealer
> What I'm going to tell you today is that, in fact, based on 10 years of research, a unique opportunity to go inside a gang -- to see the actual books, the financial records of the gang -- that the answer turns out not to be that being in the gang was a glamorous life. But I think, more realistically, that being in a gang -- selling drugs for a gang -- is perhaps the worst job in all of America. And that's what I'd like to convince you of today.
https://www.ted.com/talks/steven_levitt_the_freakonomics_of_...
Also, wiretapping a phone only captures future calls. A warrant against a website, or the website's hosting provider can provide message history, assuming it's not E2E encrypted. And it could even get the message history of every single user in one go if the site is e.g. hacked, or if there's a broad warrant against a crime website's hosting provider.
We can see from this article that tons of these criminal websites get hacked, and then people like Brian Krebs can investigate the leaked databases to see info about the criminals' accounts.
Is this a euphemism for victim engagement, or is there some other party playing the customer role that I'm not thinking of?
I.e. it's truly an affiliate / revenue sharing system, not a sale of tools.
Also, I'm not sure about crime forums, but other forums sometimes allow image embedding, either by a profile picture hotlink, or bbcode, or html, which can get the IP of everyone who views the page.
Also, just by sending someone a link you can get that person's IP. Maybe DNS prefetching can get some info about the person even if the person doesn't click the link.
Also whatever hosting provider they use to distribute the malware to the affiliates could end up leaking their IP.
Everyone is scrambling to build a cyber army. Looks like Putin is letting the invisible hand build it for him.
The general security situation is fraught because multiple nation states are at least sheltering and sometimes sponsoring attackers who damage the economy of the opponent.
Funded startups have a lot of money. Milking money out of startups is a highly profitable market segment. Why would ransom gangs not want to get in on that? They don’t tend to ask for the ransom to be paid in ISOs…
A bit off your "real" point: No company should ever spend more mitigating a risk than the potential cost they could incur from the risk. That is just good business, but the reality is that companies generally won't spend more on cybersecurity than their peers (either as a percentage of revenue or percentage of IT spend). Whether that is the proper balance for a risk/spend calculation is the real topic.
The problem is that we can't accurately calculate the probability of a cyber event and the cost impact of that event. So the company is stuck waiting for an attack on themselves or one of their cohorts so they can adjust.
Funny, after the fact they are usually out a lot of money and they decide that they now do want to mitigate that risk.
basically you summed up the opening scene from the FightClub. The human life cost H millions, so until it is going to kill N such that N * H >= cost of the fix ...
I've heard hospital administrators make this argument after I've warned them about their security infrastructure being vulnerable to ransomware. I'm not convinced.
Given the time cost of retrofitting effective security, waiting until you become a worthwhile target doesn't work. But hiring secops and spending time on security engineering instead of your product is also deadly to startups. It is another knife-edge for startups to walk.
Edit: found this comment in this same thread https://news.ycombinator.com/item?id=29158450
RICO is quite dicey--the main charges in these indictments are 18 USC §1030 charges, which do not qualify as predicate acts for RICO charges. But the 18 USC §1956 charge (i.e., money laundering) does qualify, although the fact that there's only one count in these indictments means it's going to be harder to describe the necessary pattern for RICO. If it does, then I believe the other elements of 18 USC §1962(c) could be straightforwardly shown. (In particular, the defendant and the enterprise are clearly different).
But IANAL, and the details here can be incredibly convoluted, so make of that what you will.