This sounds liked a failed ransomware attack. They encrypted the systems - Boeing says "no thank you, we have backups". There were no valuable zero-days to sell to GRU, so give a last ditch offer to try to salvage something.
This sounds liked a failed ransomware attack. They encrypted the systems - Boeing says "no thank you, we have backups". There were no valuable zero-days to sell to GRU, so give a last ditch offer to try to salvage something.
Yes. If any of this information does end up getting leaked, it kills the credibility of the ransomware group and they'll never get paid again. Sort of mutually assured destruction.
Now of course, most people don't really trust criminals anyway so the business has a pretty strong bargaining position and I believe many of the ransoms are negotiated way down.
(or do we need eBay-like "seller ratings" and customer reviews for ransomware groups?)
Didn't Silk Road have eBay-style ratings/reviews?
My understand is that since it's a much more limited market, access is very difficult even under normal circumstances (not because of security but just because dark web markets usually have awful performance for various reasons), so it's a far different review landscape than say shopping on Amazon, at least the ones I have used. The markets themselves were fantastic about refunds/conflict resolution, better than most normal online shops. Reputation is key for basically everything dark web, and the main actors in this space are notoriously petty and bold towards anyone that makes it harder to conduct business.
I imagine it's very similar with Ransomware as there has to be some reason for the targets of the attack to believe paying the ransom is worth it, and anyone who upsets that balance for the ransomware gangs unexpectedly becomes rapidly unpopular, and usually a target for the other gangs. It very much so is heavily relying on the honor system, but it seems the groups are committed to such a system.
Silk Road was 10 years ago that would have been like the smallest one ever since then, just curious why it is referenced at all, and in such an odd way
“I heard eBay has bulletin board like reviews” you know you can just go look, in a web browser “woah thats crazy talk, I prefer 10 year old hearsay”
anyway, they often have a separate forum where one could ask more about a group
Department of Justice and Europol have lots of press releases about other markets and busts and ways they failed to bust them, and how their size eclipsed Silk Road
I guess as long as the media doesnt parade it around or makes movies about it nobody knows
Superhost for my datas
All companies and governments should take the stance that any randomwared or compromised data is now public. And if they don't have the backups, then they should consider it permanently lost.
Write it off as a business loss and hire better ops people.
The attackers attack for money, not to kill their prey, that's not profitable.
That's a somewhat reasonable stance. You definitely have no guaranteed assurance that it won't be leaked. However... depending on what you do have set up, you may have some reasons to believe that 45GB of encrypted data has not left your internal network (i.e. was only encrypted-in-place)
> And if they don't have the backups, then they should consider it permanently lost.
That's easy to say but way harder in practice. If the data in question is the design artifacts from a billion dollar project... it'd be a pretty hard sell to convince everyone "woops, we fucked up, billion dollars gone, time to close the doors and go home, we definitely shouldn't consider paying $500k or $1M or whatever they want to get all this data back".
You can rebrand as CaTBUTT, or Indrik Spider 2.0, or whatever, but if you're using some custom version of Mirai they'll eventually tag your M.O. and the threat intelligence briefings will reflect that.
And then no ransom.
It (and other malware) tend to behave in specific ways and follow specific patterns, and those patterns can be analyzed. Ditto for the servers they use, targets they hit, etc.
These approaches are known as TTPs, and documenting them is how you attribute an attack to a specific group or actor. Even if you change your org and start using servers in a different country eventually your MO will give you away.
These approaches are cataloged by IT security types, and many cybersecurity orgs release publications about Group X using approach Y.
So when you get hacked by Group Z, but they sound like X and Y, you guess it was them. And if Group X has a history of burning ransom payers then you don't pay -- they'd fuck you anyway, so save the money and start rebuilding.
Understand: For the ransomer's point of view this is another monday, albeit one where a big fish walked away.
Which just reinforces the "honor = iterative prisoner's dilemma" argument.
He’s a criminal who launders money through small businesses he owns and the accounting firm he runs. He names it ZZZ Accounting so it doesn’t get a lot of calls through people looking up accountants in phone book.
Look to Amazon for new ideas on DGA-derived names for your fly-by-night business.
Some homeowners thought it was going to be him cutting their lawns and would get upset because the contract said he’d do it. So he’d just rip up the contract in front of them and refuse to cut their lawn ever again.
In Florida there were so many houses with lawns in so many subdivisions he was always busy anyway. Plus he liked getting into fights with adults. Win win, I guess.
On the other hand, holding their side of the promise allows them to build a reputation, which makes it easier to get future victims to pay. Why would they leak the data if someone paid?
Obviously this behavior doesn't apply to all of them, but it's a clear effort by some of them to immediately appear more palatable to random IT worker, the execs, and the lawyers who are watching the who process play out.
And it also lines up with the fact that ransomware groups have freaking HR departments to handle their employees.
regarding drug dealers, I wouldn't consider it a good comparison. the actions of one dealer typically doesn't affect others, they're just not that connected beyond professional recognition/courtesy. If dealer A is shorting their customers, dealer B absolutely wouldn't care as why would they? they have no relationship, and it'd probably mean the customers go to dealer B instead. business will continue as usual even if one bad actor is doing shitty stuff to their customers.
with ransomware that is not the case -- if public opinion overwhelmingly tells there's no sense in paying because the ransomware gangs never follow their word, that affects all the gangs, not just the bad actor. the gangs already have a hard enough argument to make as to why the targets should pay so anything that frustrates that further is frowned upon.
The reason ransomware worked was you didn't have to trust the group long-term - just enough to give you a copy of your data back.
It's the difference between you making a copy of my car keys and stealing them. Yes, I will pay for "a" key back - I only have to trust you enough to hand it over.
Hilarious.
So is murder for hire. However, both being firmly within the "crime" category of business, all allusions to legitimate business concepts such as "reputation", "contract" and "predictability" are illusory, rhetorical and rarely survive first contact with some felonious scumbag who wants to screw you over. Particularly when one side of the interaction is not an experienced and dangerous criminal.
There are people who consider these groups credible?? The world really has gone insane.
There are review sites for ransomware groups?
"honored promise not to disclose, didn't gloat or taunt, would pay again, 10/10"
At least for 'most'.
So a part of one gang made some claims and some other not-gang claims they have ties with FSB or SVR => all gangs are operating under personal Putin blessing. Even North Korean and Ukrainian, right?
I don't buy it. There's nothing to stop the group from rebranding themselves. The company has no proof nobody else got a copy of the data. And the group could simply hang onto the data, extort a bunch of money from other companies, then start back at the beginning and demand even more (knowing that the data is worth _at least_ what was already paid for it).
Apart from the fact that nobody would pay them if they have no reputation.
If LockBit does something to taint their image in the media and among security organizations, then rebrands to avoid their negative history, forensics will still eventually tie their new name back to their old org, and victim's will have to decide whether they should trust that their data will be handled correctly after payment.
As for re-victimizing old organizations, there's almost zero chance of that working. Most data is only sensitive for a certain time frame, long enough that they can make the proper notifications, change credentials, etc.
Lastly, there still needs to be someone to download and abuse the data they leak. I've monitored ransomware torrents a few times and not observed any downloads completed over the course of a couple weeks following a data leak.
LockBit just did a sort of collective bargaining with affiliate groups that resulted in guidance for setting initial ransom amounts and rules restricting discounts about 50%.
Hard to say...
You're effectively trusting the liar they wont lie again
Its possible they leak it to high profile customers without publicly announcing it
Business should make decision assuming the data will be leaked eventually regardless of random paid or not
Perhaps only thing business can assume is the data wont be publicly released in short amount of time
Usually we blame the Chinese, but in this case I think its a toss between CIA and NSA.
(I think I'm on some kind of list now)
Edit: I am an idiot. I was thinking of Airbus, see @perihelions comment below
https://www.economist.com/special-report/2003/06/12/airbuss-...
- "According to a European Parliament report, published in 2001, America's National Security Agency (NSA) intercepted faxes and phone calls between Airbus, Saudi Arabian Airlines and the Saudi government in early 1994. The NSA found that Airbus agents were offering bribes to a Saudi official to secure a lion's share for Airbus in modernising Saudi Arabian Airlines' fleet. The planes were in a $6 billion deal that Edouard Balladur, France's then prime minister, had hoped to clinch on a visit to see King Fahd in January 1994. He went home empty-handed."
- "James Woolsey, then director of the Central Intelligence Agency, recounted in a newspaper article in 2000 how the American government typically reacted to intelligence of this sort. “When we have caught you [Europeans]...we go to the government you're bribing and tell its officials that we don't take kindly to such corruption,” he wrote. Apparently this (and a direct sales pitch from Bill Clinton to King Fahd) swung the aircraft part of the deal Boeing's and McDonnell Douglas's way."
Let's say some three digit agencies create sort of malware distribution forums in the darknet. They make sure to only broadcast to people who wants to play with malwares so the net catches the "bad guys" mostly, except for a few curious researchers or journalists maybe. Then they start to share recent generarion malwares they created. They don't need to distribute them by themselves because they already have the CCC servers. Some malware gangs would eventually be the frontend and start the distribution.
In this way you not only distribute the malwares without getting impacted, you also get to know the gangs so whenever you want to catch a few fishes you just pull the net.
Once the darknet forum dies out or they need to wipe the records, they would just leave and create a new one.
Just my wild thought.
If I was based in a country I would not want to target those that can more easily get me into jail and/or kill me.
I have no idea if FSB work for them, this is more speculation than open secret, but they certainly do tolerate them and see them in a good eye as long as they target western companies and agencies. The enemy of my enemies is my friend.
https://www.wsj.com/articles/how-north-koreas-hacker-army-st...
This isn't really true in general: intelligence agencies often want access to funds with less/no oversight from (or to skirt controls enacted by) other parts of the government. As an example, that was the dynamic at the basis of the Iran-Contra affair in the US.
Actually I'm often surprised that many ransomers/hostage-takers go through with their threats when they don't get their demands. The only reason I can see them doing it is if reputation matters to them for future negotiations. more than the risks from the greater liabilities they incur by going through with the threats.
It doesn't have to be the whole group; perhaps one guy decides to branch out on his own, and grabs the data on his way out the door.
However if you have adequate backup and recovery mechanisms in place then you're not the best to prey on.
It's a business model that works until the majority of targets have appropriate backup and recovery processes.
Trust isn't all-or-nothing. When I ride a bus I'm trusting the driver with my life, but I wouldn't trust them to babysit my kids.
Mutability is deniability. I don't trust hardware companies with that. And I don't have to, either.
Stop hawking this SGX snakeoil. Except maybe to ransomware authors, who deserve what they'll get.
Attestations are quite certainly traceable to the EPID, which is a fuse array -- it's on the die, not the motherboard. In order to attest, the key that encrypts the victim's data would have to be SGX-generated. What kind of RNG do you think it uses? Maybe Dual_EC_DRDBG?
I suppose it helps them in the former case, if they also had no backups. But the hackers are already in a very bad place if the CPUs get captured, so I don't think they care about SGX at that point. The hackers don't need to trust SGX. They only need the victims to trust it.
You mean:
1. generate a public/private key in enclave
2. generate attestation from SGX enclave with public key hash.
3. seal the public/private key somewhere so it can be reused later, otherwise pc restart or app failures / no data.
4. publish source code that generates mrenclave somewhere that can be audited.
5. encrypt in place and assume remote trusts you when you say data was only exfiltrated encrypted or not at all.
Now, 5 is the problem i mentioned. Why would anyone trust that data was not exfiltrated unencrypted and copied a few times.
> and the unencrypted plaintext never leaves the victim organization.
You also mentioned this to be fair. Why would this be trusted?
6. Release data if no payment on bitcoin.
SGX enclaves do not have magic trusted access to network to get bitcoin payments data.
It can be man in the middled or fooled by omission by who controls machibe.
So key can be releases by feeding it bad data (payment was not done and time expired - release to the world).
There's also the problem that attestation might lead to the originating group if cpu is identifiable.