(or do we need eBay-like "seller ratings" and customer reviews for ransomware groups?)
(or do we need eBay-like "seller ratings" and customer reviews for ransomware groups?)
Understand: For the ransomer's point of view this is another monday, albeit one where a big fish walked away.
Which just reinforces the "honor = iterative prisoner's dilemma" argument.
You can rebrand as CaTBUTT, or Indrik Spider 2.0, or whatever, but if you're using some custom version of Mirai they'll eventually tag your M.O. and the threat intelligence briefings will reflect that.
And then no ransom.
It (and other malware) tend to behave in specific ways and follow specific patterns, and those patterns can be analyzed. Ditto for the servers they use, targets they hit, etc.
These approaches are known as TTPs, and documenting them is how you attribute an attack to a specific group or actor. Even if you change your org and start using servers in a different country eventually your MO will give you away.
These approaches are cataloged by IT security types, and many cybersecurity orgs release publications about Group X using approach Y.
So when you get hacked by Group Z, but they sound like X and Y, you guess it was them. And if Group X has a history of burning ransom payers then you don't pay -- they'd fuck you anyway, so save the money and start rebuilding.
Didn't Silk Road have eBay-style ratings/reviews?
My understand is that since it's a much more limited market, access is very difficult even under normal circumstances (not because of security but just because dark web markets usually have awful performance for various reasons), so it's a far different review landscape than say shopping on Amazon, at least the ones I have used. The markets themselves were fantastic about refunds/conflict resolution, better than most normal online shops. Reputation is key for basically everything dark web, and the main actors in this space are notoriously petty and bold towards anyone that makes it harder to conduct business.
I imagine it's very similar with Ransomware as there has to be some reason for the targets of the attack to believe paying the ransom is worth it, and anyone who upsets that balance for the ransomware gangs unexpectedly becomes rapidly unpopular, and usually a target for the other gangs. It very much so is heavily relying on the honor system, but it seems the groups are committed to such a system.
Silk Road was 10 years ago that would have been like the smallest one ever since then, just curious why it is referenced at all, and in such an odd way
“I heard eBay has bulletin board like reviews” you know you can just go look, in a web browser “woah thats crazy talk, I prefer 10 year old hearsay”
anyway, they often have a separate forum where one could ask more about a group
Department of Justice and Europol have lots of press releases about other markets and busts and ways they failed to bust them, and how their size eclipsed Silk Road
I guess as long as the media doesnt parade it around or makes movies about it nobody knows
He’s a criminal who launders money through small businesses he owns and the accounting firm he runs. He names it ZZZ Accounting so it doesn’t get a lot of calls through people looking up accountants in phone book.
Look to Amazon for new ideas on DGA-derived names for your fly-by-night business.
Some homeowners thought it was going to be him cutting their lawns and would get upset because the contract said he’d do it. So he’d just rip up the contract in front of them and refuse to cut their lawn ever again.
In Florida there were so many houses with lawns in so many subdivisions he was always busy anyway. Plus he liked getting into fights with adults. Win win, I guess.
Superhost for my datas
All companies and governments should take the stance that any randomwared or compromised data is now public. And if they don't have the backups, then they should consider it permanently lost.
Write it off as a business loss and hire better ops people.
The attackers attack for money, not to kill their prey, that's not profitable.
That's a somewhat reasonable stance. You definitely have no guaranteed assurance that it won't be leaked. However... depending on what you do have set up, you may have some reasons to believe that 45GB of encrypted data has not left your internal network (i.e. was only encrypted-in-place)
> And if they don't have the backups, then they should consider it permanently lost.
That's easy to say but way harder in practice. If the data in question is the design artifacts from a billion dollar project... it'd be a pretty hard sell to convince everyone "woops, we fucked up, billion dollars gone, time to close the doors and go home, we definitely shouldn't consider paying $500k or $1M or whatever they want to get all this data back".
On the other hand, holding their side of the promise allows them to build a reputation, which makes it easier to get future victims to pay. Why would they leak the data if someone paid?