6 ms·
There have been ransomware attacks that are covers for outright attacks, iirc some where the payment and decryption mechanism didn't even function. On a more t
by mwill 6y ago
There have been ransomware attacks that are covers for outright attacks, iirc some where the payment and decryption mechanism didn't even function.
On a more theoretical level, it's certainly possible to do both at the same time, two birds with one stone. But it seems a lot of the big gangs are suspected state-sponsored, which is less terrorism and more cyber warfare
- donor20 6y agoAnd plenty just want to get paid - it's actually pretty impressive how many take down / don't share if they are paid or actually come through with the decryption keys. Hard to see how they are terrorists? What are they pushing to accomplish with their terror campaign. Anyways, my health care system constantly assures me security is its "top" priority and "state of the art".
- mwill 6y agoI'm not saying all ransom ware attacks are terrorists, just that ransomware attacks are not always profit-motivated, some are covers for larger attacks, some are just disruption operations, and either one of those can be considered terrorism, or cyber warfare. (I am not the user who originally said this was terrorism)
- toomanybeersies 6y agoNot saying that it's the case with most (or even any) ransomware, but it's very common for terrorist organisations/liberation movements/violent non-state actors fund their activities through organised crime. ETA used to rob banks, the Contras trafficked cocaine, the RIRA smuggles cigarettes and launders agricultural fuel, the remnants of the Islamic State have turned to illegal forestry, etc. etc.
- Thorrez 6y agoIf it's a fake ransomware then yeah that's probably terrorism. If it's fake it's obviously not done for profit. I'm referring to actual ransomware that works, that's done for profit. > On a more theoretical level, it's certainly possible to do both at the same time, two birds with one stone. I'm not sure how well that would work. Ransomware generally has responsive and helpful support people, because without that it will be hard to convince victims to pay. If they spend their time instilling fear instead of confidence in the payment process, then no one will pay.
- bostik 6y ago> I'm referring to actual ransomware that works, that's done for profit. From what I have recently learned, this may no longer be accurate. The latest Risky Business happens to touch upon the subject. Criminal groups in Russia have financial arrangements with the central government, and may occasionally do some freelancing for them. Now China is getting on the same boat, but apparently with less entrepreneurial approach to target selection. If they are the only ones, I would be very much surprised. The net result is that ideological and for-profit motives will be harder to distinguish, as the same crew may well be doing different campaigns for different reasons at any given time.
- Thorrez 6y ago>If they are the only ones, I would be very much surprised. The net result is that ideological and for-profit motives will be harder to distinguish, as the same crew may well be doing different campaigns for different reasons at any given time. Sure, some of the campaigns might be ransomware, some might be terrorism. I don't see how this disagrees with what I said.
- mcintyre1994 6y agoThe best example of this is probably the 2017 Russian attacks on Ukraine, which used Petya disguised as ransomware.
- ethanbond 6y agoNotPetya is a good example. Looked like a broad ransomware attack very similar to the earlier Petya attack. Turned out it was very likely a broad cover for a very narrow attack against Ukraine’s power grid during Russian invasion.
- AsyncAwait 6y agoSay what you will about Russia, but I don't believe they'd attack hospitals dealing with COVID in the middle of the pandemic as a cover for some kind of attack. I know anti-Russia propaganda is at its height now and I even admit it's weird watching how worked up Americans get about stuff they're been doing all around the world since WWII, but as bad as Russia might be, I don't really buy they're behind it.
- ethanbond 6y agoI wasn’t commenting necessarily on this attack. Just saying the claim that ransomware attacks are purely financial is demonstrably untrue in at least one case.
- sangnoir 6y ago> Say what you will about Russia, but I don't believe they'd attack hospitals dealing with COVID in the middle of the pandemic as a cover for some kind of attack. I wouldn't characterize it as an attack, its closer to "preparing an attack". And why not - the former President of the United States outright said on TV that the US had placed dormant implants deep inside key Russian infrastructure without pulling the trigger as a preparations/part of countermeasures for electoral meddling in 2016. The decision to pull the trigger was left as an option for his successor. I do not doubt the Russians may be getting similar "insurance" against a possible unfriendly posture from Washington starting January 2021.