Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I never quite understood why these ransom-ware attackers restrict themselves to a small subset of the MSP's clients. E.g.: The SolarWinds attack affected only something like 1% of their customers, when it could easily have been 50% or more!

If you're evil and out for money, wouldn't you want to cast the widest net possible? Similarly, by encrypting a huge number of corporations concurrently, you'd "exhaust" the ability of a country to respond. There's only so many recovery specialists and IT contractors available to respond in an emergency. Encrypt only a few hundred targets and they can all recover. But if you encrypt a few hundred thousand, then there wouldn't be enough warm bodies available!

Thinking about it, I wonder if these attackers have set up permanent operations, with staff, payroll, and everything. Maybe they just to fly under the radar and collect a nice steady income instead of a risky but potentially huge one-time payoff...



Give it time, these are start-ups bootstrapping themselves. They don't have the support infrastructure in place yet to scale to beyond a few hundred companies. As it is, there are going to be a lot of over-worked people at REvil doing crunch time, missing family dinners and their kids' recitals and soccer games managing the logistics of this hack.

No worries though, the ransom from this round should serve nicely as a Series B round of financing & enable rapid scaling of the post-hack ransom extraction process.


I wonder how much of a human element is involved in each individual hack. I would have thought the sticky note, encryption, payment & decryption was all automated.


As I understand it there is often a lot of discourse that takes place between the hacker and the hacked - agreeing prices, haggling, proof of files etc.

Yes much can be automated but there is usually a human element to these deals and that costs the hackers money.

They also want to be careful to limit their hacks to companies their handlers are happy for them to hack. Go too wide and you risk hitting a company directly or indirectly linked to your state/handler/patron.


You are correct. I have had the "pleasure" of going through the negotiation process before. There are even companies that specialise in it, and have DBs on who is a "trusted" threat actor (the industry term) who will actually honor the terms of the transaction or not.

There are thousands, if not tens of thousands, of such deals done every year.


You'd think a GPT3 / GAN could be created to handle much of that. It's a percentages game anyway.


Why would you want GPT to handle multi million dollar negotiations?

Sorta playing into stereotypes about engineers here.


Scale.

Perhaps not the largest groups, but the smaller ones, posssibly.


That stuff is automated.

What's not is managing big sums of money, turning crypto in to a more traditional currency/assets. That side of the operation probably has more people doing leg work than you'd think.


We really need someone from REvil to do an AMA on HN for this sort of detail. How did they get their first paying "customer"? What's their churn rate? Do they appreciate strong security measures, rendering each lost "sale" somewhat bittersweet? How are they handling the transition from developer-driven startup to a more mature organization?


More importantly, how long are they on Dogecoin? (Funny post, btw. The whole thing is totally absurd.)


I know, and yet I'm only half joking because they probably face some of the same issues as any legitimate tech business. There's plenty of extra issues on top that go with any organized crime-- money laundering, worrying about law enforcement, loyalty of their members and brutal enforcement of it. I really am fascinated by what the structure of this would look like from the inside. Of course much of it depends on the degree to which it may actually be state-sponsored, or just lightly assisted or politely ignored. Now with the added prospect of a powerful country with a vendetta against them.

It's even conceivable that if they go too far and political pressure in the US builds high enough, and Russia &/or their countries of residence are also put under pressure, that they could find themselves on the wrong end of a drone strike or no-knock flash-bank assisted rapid entry to homes and business locations. All they have to do is pick the wrong target that directly leads to deaths-- hospitals the most obvious, but industrial accidents or "rapid unplanned disassembly" of something like a chemical plant...

I was shocked at the pipeline attack, followed by one on the US's food supply. These rise to the level of terrorism, and when fear & anger become dominant motivating factors the event horizon for any ability to predict what happens will become significantly shorter and less certain.

And in the middle of all of that will be a team of techies and support staff struggling to cope with day to day realities of running a thriving organization. There's an IT Crowd satire show somewhere in there that Netflix should consider.


Unsure why everyone is acting like this is a new phenomena. These organizations have been getting multi-million payments for the better part of a decade, it is just only being covered by the media now.

Why couldn't they have bootstrapped years ago? I suspect the real reason is they actually want to avoid extensive media coverage.


The new differences are:

1) Scale of the attacks. Taking large portions of a country's petro-chemical/energy pipeline is far above the threat level presented by most prior hacks. The same goes for shutting down ~20% of the nation's pork & beef food supply. And now hundreds of companies impacted as a result of a single breach. Ransomware isn't new, but it is in hockey-stick growth mode.

2) Increased market for crypto currencies. Criminal activity may not, by far, be the dominant activity, but the more legitimate transactions there are, the easier it is to hide criminal transaction.

3) Bootstrapping this type of thing takes time because it's not just about capital in this case. It's also about accumulating vulnerabilities and compromising systems long enough that backups-- for example a week or month old-- are still useless (also encrypted). And going back to earlier backups will lose the company too much essential data.

4) And as you said, avoiding media coverage that will bring too much attention, and with it the potential for a crackdown. The slow burn on increasing ransomware over the years has acclimate people to it in a way that makes even the most recent massive attacks a little more normalized, especially when they pay the ransom & get back up & running in a few days. That limits the amount of public pressure to fight this head on with mandated increased security and massive resources thrown at pro-actively going after these hackers.

5) In 2016 ransomware wasn't quite as mature. 2020 is different, and the political landscape is different: I'm not making a partisan comment here. I'm not saying the previous US administration prevented these things better or the current administration dropped the ball. What I'm saying is that when there's any new administration, there are threat actors that will test the waters, see how far they can go. I definitely thing that's a factor here, especially so close after the Biden administration delivered its list of 16 untouchable sectors to Russia & Putin. There's going to be a lot of adversarial interest in just how firm those limits are, and what the response will be.

Otherwise, from a national awareness standpoint, you do approach an important point: It may not be a new phenomena, but for the vast majority of Americans that don't follow tech news, this is new and, given the scale of recent attacks, somewhat scary.


It's not enough to just gain access - once you're in you need to compromise other defenses, you need to communicate your demand to the victim, you need to know how much to extort, you need to actually process the payment. Either you do this on a case by case basis or you take advantage of additional exploits that will only be viable for a subset of your potential targets, and this is all a race against time before someone notices your initial exploit. Either way, it's likely impractical for any non-nation state actor to simultaneously attack more than a few thousand targets in one go.

This is combined with a business model resembling patent trolls: you want to extort just a little less than is worth fighting for. If a company gets hit on its own, it's probably not in a position to really do anything about it, but if there is some major hack affecting tons of companies, the odds of an actor with significantly more tech capability like the US government getting involved go way up, and suddenly fighting seems like a good option.


Maybe you’re a state actor and a ransom demand, at least an overt one, is not your objective.


My mind went there as well. Say I'm an affluent oligarch shorting major companies. I'd paying the ransom group to massively attack the company or various companies. Then cash out during the chaos.


Yes, except for the fact that we don't hear about most of these attacks because both the attacker and attacked keep them quiet.

That doesn't jive with your market manipulation hypothesis.


SolarWinds affected 100% of installations that updated their deployments during that 8 month window. Your 1% comes from the ratio of networks that were specifically targeted and received 2nd stage with all the goodies.

The reason why 2nd stage was only given to (relatively) small number of organizations - because the attack wasn’t ransomware, attackers didn’t have economical motives (in fact they were spooks on a government payroll).

EDIT: I can’t spell


Tinfoil hat, but that Solarwinds access was way more valuable than a ransomware payoff. Made sense to keep quiet with it.


Yeah, I'm guessing they're going for steady income over risking a serious retaliation. If the hack is serious enough, there will be consequences.


FWIW though (and I don't have easily available "sources") there was this immediate retaliation where Biden was like "we will completely prosecute these offenders" and within days DarkSide PR department said "Hey sorry we didn't mean to disrupt core services, we just want money" (sic)

So it's a spectrum


That's not even close to what happened.

The administration left it alone for days saying they'll let private business sort it out. (Default investigation notwithstanding.)

When a bunch of news media started reporting the group was Russian and then insinuate it was a state sponsored attack, DarkSide said something along the lines of, "We didn't realize this would start geopolitical conflict. We will be careful to vet clients more carefully in the future."


They also accepted a ransom substantially below their typical going rate. The Darkside people were probably shitting their pants, this is not what they intended at all.


Did they leave it alone for days? The FBI seized the ransom (claiming it was left in a Coinbase account) so clearly someone was doing something.


"Left alone" as in publicly and geopolitically.

The FBI investigated the crime as they always do. It was treated as a standard international monetary theft.


I mean it's reasonably close - but FWIW thanks for the correction, it's been a wild year


Sounds so spooky, do say more! Do you mean Jason Bourne / John Wick shows up at the hackers’ nest?


Well, if the attacker manages to kill a few thousand people, there's precedent for the USA going to war over it. It would depend on the host nation of course, if it was e.g. China, Russia or some state in their sphere of influence, it'd be different than if the hackers were holed out in, say, Afghanistan.


Or Raytheon, yeah, I imagine so.


Because there are plenty of zero-days the NSA can deploy if you step out of your lane.

It’s as much a political game at this point as anything.

If anyone thinks they can hide behind cryptocurrency and hold truly strategic companies hostage they are deluding themselves.

They’ll either end up hacked beyond their wildest imagination or facing literal hellfires.

It’s brinkmanship. When the devs literally die, they think twice.


At some point, some nation-state will get annoyed enough to do something drastic. That's what ended state-sponsored terrorism.

Or even a company. Uber's security chief once became annoyed with an attack from Nigeria. They traced the attack to an Internet cafe and sent some "lawyers" to talk to the attacker.

Someone tried a ransomware attack on the Teamsters Union in 2019.[1] The FBI advised them to pay. The Teamsters didn't pay. There were no further attacks. The Teamsters declined to comment. (For those unfamiliar with American labor history, trying to push around the Teamsters Union usually ends badly for the pushers.)

[1] https://thehill.com/policy/cybersecurity/558066-teamsters-re...


>That's what ended state-sponsored terrorism.

Wait, what? Have you notified the Department of State?

https://www.state.gov/state-sponsors-of-terrorism/

Iran is still on there. I'm pretty sure some people have been "annoyed enough to do something drastic" for quite a while.

https://en.wikipedia.org/wiki/Assassination_of_Iranian_nucle...


You make it sound like the Teamsters Union could do something bad to the attackers, so attackers gave up, but in reality Teamsters just rebuilt from archives, which was perhaps an economical decision:

“Ultimately, the union decided not to pay the ransom based on advice from its insurance company, and instead rebuilt its systems based on archived materials, NBC reported.”


I wish you would have sourced the Uber Nigeria story instead.


It's in the book "Super Pumped: The Battle for Uber".


Given that paying the ransom only outs yourself as a potential repeated target who pays, it was a wise decision

Source: https://searchsecurity.techtarget.com/news/252502519/Repeat-...


Maybe a nation state is already behind it? https://cryptome.org/2021/06/Peck-Barb-1974.pdf

Was Edward Snowdon "https://www.youtube.com/watch?v=1GtVt6quoD8&t=78s" or a psychologically manipulated patsy for the good/bad guys & girls?

https://en.wikipedia.org/wiki/Full-spectrum_dominance isnt just about hacking a few computers, its about getting inside the brain of each and every one of us/you like a https://www.youtube.com/watch?v=lG7DGMgfOb8.

Or is this line of thought just a https://www.youtube.com/watch?v=wmin5WkOuPw&t=48s ?


If i recall correctly solarwinds was more of an espionage operation by russia government actors. Their targets were mainly government agencies in US. The ransomware attack are from private profit-seeking groups, although I remember the head of REvil tweeted once he was neighbours with KGB's number two guy so you could argue the distinction is vague


Attribution is quite hard. When the 3-letter-agency tools leaked a few years ago, one of their leaked tools concerned deliberate false attribution.

The solarwinds attack seemed to be about using a supply-chain attack to gain persistent access for recon and lateral movement. Pivot to Azure via Microsoft via SolarWinds software. Whomever it was tried to stay invisible for as long as possible. Once the game was up, they were not so careful about visible actions.

RansomWare is more smash and grab though it's interesting/sad to see the current trends of Supply Chain attack prevalence and Ransomware attacks converge.


> The SolarWinds attack affected only something like 1% of their customers, when it could easily have been 50% or more!

If it was me (it was not), I’d use it to gain persistance in companies like Kaseya, extending my beachhead as first priority. After that is basically game over, cleaning it would take making new IT systems from scratch. And lets not forget firmware…


> If it was me (it was not)

Sure…


Sure. No melted craters, no fallout.


You'd need to be able to process all the orders also. Every company needs support to pay the random and unlock.

Also, at some point the military gets involved.


Yeah. If you take down 100 companies, it's crime. If you take down 100,000, it's an attack.


Correct, this won't get better until these groups are physically disbanded.


Didn't it only affect those who were unpatched hence the low percent? Current hack is 0-day.


Solarwinds was distributed by a malicious patch (through legit channels). So all orgs were unpatched and in fact all got at least first stage downloaded (if they patched during that window).


Steady income is definitely the way to play. You don’t want to make a demand so large that there’s cheaper alternatives of dealing with you.

Also you want the company to stay in business so it can continue generating revenue to extract future ransoms, and not have it lose a bunch of its customers from your repeated attacks.


I did write an answer before but now it seems like only Internet facing VSA servers are effected and some other measures may have stopped the attack. It could be all the servers they could find...


I would not be surprised if there is a market for the tools and the knowledge. That the real hackers just sells it and then other people do the attacks and thereby taking the risk. Similar setups existed with botnets.


DarkSide's business model was to professionalize ransomware attacks with a dedicated professional services IT model, finance, and helpdesk support.


Note that i n the case of SolarWinds, there was no demands for ransoms. It was good old state level spying, not a job to get few bitcoins.


> when it could easily have been 50% or more!

Was that down to slow patching cadence at 99% of companies?

In which case those customers have different vulnerabilities to tend to.


At some point you cross the threshold of "this is too much, drone them". Or send an assassin. Yes, even the United States does this occasionally.

I suspect the attackers know this. Or else they aren't in it for the money. One or the other.


Yeah unless they work from an office in e.g. Moscow. The US is powerful for sure but even they would think twice before droning a building in Moscow over some hacks, especially without concrete proof that's where they originated. At least I hope they would because if not then we may be closer to a world war than we thought...


The catchy rhyme being "warheads on foreheads".




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: