FBI has obtained 7k Lockbit ransomware decryption keys
fbi.gov
fbi.gov
"Just a week ago, our field offices in Charlotte, Indianapolis, Jacksonville, Los Angeles, and Cleveland worked with the Defense Criminal Investigative Service and U.S. Secret Service—along with international partners from Denmark, France, Germany, and the Netherlands—to conduct a technical operation against four groups who offer malware as a service, in the first such operation ever conducted.
That operation, Endgame, defeated multiple malware variants, took down more than 100 servers, and dismantled the infrastructure for four key pieces of global malware, which had been responsible for hundreds of millions of dollars in damages and had even compromised the critical-care online system a hospital needed to keep patients alive. "
I didn't expect so much honesty, I would have expected "We and only we are the greatest and best".
It is however, in the US govts interest to not present this, so as not to encourage people away from US tech.
It works like this: NSA brings the illegal evidence, and agencies like FBI and DEA launders it, building a fake case that omits the illegal evidence but includes other evidence that were obtained from it, rewriting history to make it seem like the investigation never ever used illegal means.
It's like git rebase, but for criminal investigations.
https://en.wikipedia.org/wiki/Parallel_construction#By_the_U...
It's kind of like a journalist getting information off the record from a source. They can't use that for a story, and the only way they can write about it is if they can find enough on the record or on background sourcing or data to be able to back it up.
[0] https://en.m.wikipedia.org/wiki/United_States_Secret_Service
So the last time, I ended up researching it for a Cybershow episode (sorry dang :) and got down dark rabbit holes like these ones [0,1] and realised just how hard this is. It's not just infiltration, it's very stealthy, careful, long-term work. Getting right into the heart of the beast and getting all the stuff, off an airgapped machine! Imagine discovering a severe exploit with massive lateral impact and needing to do a delicate, intricate coordinated disclosure so that nobody gets tipped-off... and then cutting it at the root and bagging all the loot, That's gotta feel good.
[0] https://www.wired.com/story/764-com-child-predator-network/
[1] https://www.wired.com/story/tracers-in-the-dark-welcome-to-v...
Future malware will protect against this by making such takedowns too painful by reconfiguring victims systems to depend on the malware c&c server.
Ie. transfer vital user data to the c&c server, such as disk encryption keys, then serve it back to the victims whenever needed.
If the FBI takes down the c&c servers, suddenly all the victims suffer outages and data loss.
Official Web site: https://operation-endgame.com
Europol press release: https://www.europol.europa.eu/media-press/newsroom/news/larg...
'Operation Endgame' Hits Malware Delivery Platforms
https://news.ycombinator.com/item?id=40524823
I think the ransomware decryption keys qualifies as significant new information vs. being a dupe.
It’s my understanding the Celtics have a “win song.” So, as a fellow sports fan, I hope they play “All I Do Is Win” by DJ Khaled in Boston at least four times between now and June 23.
I would prefer Team America's America song.I wonder if companies that don't pay the ransoms even keep the encrypted data for the future, or they cut their losses and just delete everything with the idea they're never going to get the data back.
And of course the hardest hit companies don't even have viable backups, so it's even further from their mind to actually take a backup of the encrypted data.
So that seems very very unlikely.
"...LockBit was set up by a Russian coder named Dimitri Khoroshev...He maintains the image of a shadowy hacker, using online aliases like "Putinkrab," "Nerowolfe," and "LockBitsupp." But, really, he is a criminal, more caught up in the bureaucracy of managing his company than in any covert activities.
Essentially, he licenses LockBit ransomware, allowing hundreds of affiliate criminal groups to run shakedowns.In exchange for the use of his software, he gets a 20% cut of whatever ransoms they collect from innocent people and companies around the world.
To help his affiliates succeed, he provides them assistance through hosting and storage, by estimating optimal ransom demands, and by laundering cryptocurrency.
He even offers discounts for high-volume customers."
It's a tough life for a ransomware CEO: Ladies and gentlemen, I'm thrilled to announce that this quarter, we've achieved an unprecedented 99.9% encryption rate, with ransom payments up by 20%. We're setting new industry standards, one locked file at a time. It's nothing personal, just business...
How did authorities identify the alleged LockBit boss?
Better customer service than AWS/GCP/Azure
"We're sorry...
The request has been blocked. "
With the title: "This site has determined a security issue with your request." Is the FBI afraid of me ?
Edit: ;)
The rot runs deep.
You keep using that word. I do not think it means what you think it means
The ACLU is free to challenge the law in the supreme court. If the supreme court rules in their favor, then the law is unconstitutional..
There is a large body of history about these unconstitutional laws at this point. It would be wise of anyone willing to make such claims to orient themselves with the current status quo and how we arrived here.