8 ms·
What's it like to negotiate with ransomware gangs?
- TheJoeMan 6y agoYou don’t get to negotiate with terrorists, and you shouldn’t get to pay ransoms for your subpar security.
- gostsamo 6y agoIn theory there is no difference between theory and practice. In practice... Paying ransom is bad, but it is bad for the commons and relieves one from a short-term pain point. Just like pollution, the cost will be paid from someone else later.
- C1sc0cat 6y agoDoes get you put on the sucker list
- benburleson 6y agoWell, if you pay the ransom and fail to plug your security holes, you are a sucker.
- ben509 6y agoAs stated, this is a non sequitur; you need to explain your reasoning behind why one thing implies the other.
- vincnetas 6y agoYou can see this as payment for pen testing. Expensive pen testing, that you could have bought earlier for cheaper and with better status report.
- steve76 6y agoStart going bankrupt. Losses roll down hill and eventually the skid will be thrown into an Albanian meat grinder.
- bradleyjg 6y agoThe thing I don’t get about these ransomware attacks is that bitcoin isn’t actually anonymous. On the contrary, it’s highly traceable. So we know what entities (exchanges) are conspiring with these criminals. Why isn’t the FBI going full untouchables on them? Granted if they are in China/Russia there are limits, but even there, we have tools.
- drchopchop 6y agoThey can wash the coins via converting to alts and back, especially at shady foreign exchanges that don't care about KYC/AML. I don't see how the FBI has any jurisdiction, or even whether this is big enough potatoes for them to devote significant time and resources to.
- bradleyjg 6y agoThe US has a lot of tools at its disposal to make life difficult for foreign financial institutions. There’s no legal bar to using them here. I agree that no individual ransomware attack has yet been impactful enough to justify a national response, but cumulatively we are probably there.
- gowld 6y agoForeign attacks on the US are the jurisdiction of the trillion dollar military.
- anaganisk 6y agoSimple there are not meddling with DEA or Hollywood. They're good.
- billpg 6y agoWhat I don't get is the idea of trusting a criminal to live up to their promises if the victim pays up. "They would lose a lot of reputation if they broke their side of the deal." What reputation? Is there some sort of website where I can go read reviews of a ransomware gang? Even if there were, what's stopping the "bad" gangs from pretending to be the "good" ones? Trademarks?
- zorked 6y agoI negotiated for a friend in a small ransomware case. They paid $2k. Yes, reputation is important, I did some research to check whether others had successfully negotiated. If you get a reputation for not delivering nobody will negotiate with you. Likewise if you have a good reputation the amount of money people are willing to risk on getting their data back goes up, and that's good for business. It's also a reason why the ransomware was very clearly branded. It's criminal but the principles of business still apply.
- billpg 6y agoI may been a bit glib in my original post, but is there actually a website where ransomware gangs reputation are tracked?
- wruza 6y agoIn our case I googled the email address that was left in every folder and read forums on how their users dealt with it. We negotiated $2k to $400. My company bought a small business and it happened next day. A hole in RDP that was simply open to the internets. No backups, no failover, just a regular business, you know. Partially my fault, as this thing should have been evaluated/fixed before the deal. Convincing the owners that it wasn't me (I just got an administrative password) was a separate fun.
- gowld 6y agoSeems like it was an inside job if it happened the same day.
- autosharp 6y agoAren't these criminals providing a useful service to society? Corporations (and the governments that are supposed to set and enforce standards) are clearly failing to protect the data that is collected about people. These criminals are increasing the incentive for corporate data security. The Equifax case is a good example of the problem. They leaked data on lots of Americans, who never agreed to their data being collected, they externalized an enormous amount of damage they created, and they are still in business. Government is clearly failing here. I feel safer knowing that there are people out there, hunting down these unsecured caches of data.
- intrasight 6y agoAn analogy. Perhaps 20% of modern integrated circuits are dedicated to testing. Perhaps the same percent of GDP is spent combating crime. In a ideal world, we'd not need to waste all that silicon real estate on testing. And in an ideal world, we wouldn't be wasting resource on combating crime. But the world is not ideal.
- hammock 6y ago>Aren't these criminals providing a useful service to society? Maybe if the ransom paid was required to be spent on data security improvements...
- emidln 6y ago> I feel safer knowing that there are people out there, hunting down these unsecured caches of data. There's very little difference between maliciously encrypting someone's data once you have managed to establish code execution vs exfiltrating all of the data and then using any PII to open lines of credit. For you as a consumer, the former doesn't harm you. The later has the ability to harm you quite a bit in ways that take months/years to sort out. Do you really feel safer because the criminals that cracked these systems flipped a coin that landed on the "extort our victim" side rather than the "free leads to customers of our victims" side?
- c22 6y agoYes, that's the point. These organizations holding my PII haven't historically given half a damn if all my data gets exfiltrated or not. By electing to pursue the other side of the coin these attackers provide incentive for those companies to batten down the hatches, causing my PII to become more protected as a side-effect, thus leading to a greater feeling of safety.
- smrtinsert 6y agoIsn't production data being replicated to backups at a minimum daily? How is ransomware still a thing at big corps in 2020.
- unixhero 6y agoThe cancer of our time: Active directory and domain controllers. Ransomware is just the attack vector. At the end of the cyber kill cHain lies AD.
- mikorym 6y agoCould you elaborate?
- unixhero 6y agoAttackers fool humans into clicking on URL's leading to malware downloads, or with embedded or attached malware in emails. Then when the payload has been installed on the victim's computer. The next step is to spread and also to get control of as many machines as possible in on the same and neighbouring networks. With the eventual goal of command and control. When unimpeeded, these attacks now take 5-10 minutes. From here they lay low, for months.. Then the shit really hit the fan when they take the domain controller infrastructure through a GOLDEN TICKET using KERBEROASTING attacks. Then Kansas is going bye bye. You better pray your competent IT leadership has taken steps to make IDENTIFY, DETECT, PROTECT, RESPOND, RECOVER dimensions (NIST framework) a reality across the technologies your company relies on. MITRE defines a generic framework for hacking attacks: - INITIAL ACCESS - EXECUTION - PERSISTENCE - PRIVILEGE ESCALATION - DEFENSE EVATION - CREDENTIAL ACCESS - DISCOVERY - LATERAL MOVEMENT - COLLECTION - COMMAND AND CONTROL - EXFILTRATION - IMPACT From here I recommend you read the MITRE ATTACK framework, great reading! https://attack.mitre.org/ https://attack.mitre.org/ https://www.youtube.com/watch?v=bkfwMADar0M https://www.youtube.com/watch?v=bkfwMADar0M https://www.youtube.com/watch?v=b6GUXerE9Ac https://www.youtube.com/watch?v=b6GUXerE9Ac https://www.youtube.com/watch?v=_SsUeWYoO1Y https://www.youtube.com/watch?v=_SsUeWYoO1Y Real talk!
- lhoff 6y ago> roughly half of U.S. corporations report being attacked by ransomware last year. Holy f.. I knew that is was bad. But that is way worse then i expected.
- josefresco 6y ago... based on a survey of "5,000 IT managers" Source: https://www.sophos.com/en-us/medialibrary/Gated-Assets/white-papers/sophos-the-state-of-ransomware-2020-wp.pdf https://www.sophos.com/en-us/medialibrary/Gated-Assets/white...
- croissants 6y agoThe exact question is "in the last year, has your organization been hit by ransomware?". It reads a little vague to me -- is a visible unsuccessful attack the same as getting "hit by ransomware"?
- mikorym 6y agoInteresting article, but I would say this is squarely from the perspective of the less technical people involved: lawyers, prosecutors, management types, apart a little bit from Art who knows about the steps in unencryption and so forth—interesting, none the less. My opinion about it is that many companies don't understand their systems (and yes, I do blame Microsoft, Apple and for that matter Salesforce or Oracle). However, many people don't understand their microwave ovens, myself included, so perhaps it's unrealistic to start that conversation and perhaps focus on the pragmatists, like Art.
- kencausey 6y agoIs anyone aware of the implementation of a system where documents are checked out for access, possibly with limitted read only access and only optionally write access? My thought is that documents would then be slotted into categories like unimportant, contains sensitive information, must not be lost and possibly have greater barriers to access based on these criteria.