6 ms·
I think this is a good thing. It might show potential victims that their opponents are not a bunch of smelly teenagers hopping online after midnight. These are
by SCHiM 5y ago
I think this is a good thing. It might show potential victims that their opponents are not a bunch of smelly teenagers hopping online after midnight.
These are multi-million (billion?) businesses. There's strategic leadership, target acquisition pipelines, R&D, talent recruitment and coordination with other businesses in the space.
There's every indication that with a little bit of protection money, you can even run your business with no interference from the law, as long as you don't mess around in your own backyard.
You can see from the blog post, that this "company" has done a product-market-fit analysis. They've taken a look at their competitors' work, considered the pros/cons, and decided that they can do better. Since they are a b2b company (hehe) you can be reasonably sure this is not some PR aimed at consumers. I think it reads as a recruitment pitch to their lead generators (read: hackers whom infect other networks for them).
You can see the pitch, it almost reads as a vacancy post:
- We make a lot of money
- We're new to the scene but already have had success
- We only work with the best hackers
- We pay you lots of money to infect a network, if you got what it takes
- rmah 5y agoWhen groups do this in furtherance of illegal activities, it's called "organized crime". And such groups need to be pursued aggressively because they are corrosive and poisonous to society at large. If they are not actively and aggressively fought, their negative effects seep into broader society and can become entrenched for generations.
- dcow 5y agoWhat about when your “organized crime” group has a moral compass and isn’t breaking local laws?: DS: Obviously, there are many talented professionals on your team. Why is it that this talent is aimed at destructive activities? Have you tried legal penetration testing? BM: We do not deny that business is destructive, but if we look deeper—as a result of these problems new technologies are developed and created. If everything was good everywhere there would be no room for new development. There is one life and we take everything from it, our business does not harm individuals and is aimed only at companies, and the company always has the ability to pay funds and restore all its data. We have not been involved in legal pentesting and we believe that this could not bring the proper material reward. For me the line between organized crime and robin hood is very blurry.
- mcguire 5y agoIt's not blurry at all. That's straight up organized crime trying to justify its existence.
- wrs 5y ago“Robin Hood”?? I must have missed the part of the interview where they talk about their charitable redistribution activities…
- pmoriarty 5y ago"We do not deny that business is destructive, but if we look deeper—as a result of these problems new technologies are developed and created." This is such a transparently self-serving joke of an excuse. A serial killer could likewise say "Sure, I kill people, but as a result of my murders the police develop new forensic techniques." Right.. as if that justifies anything. These people are just interested in money, no matter who it hurts. They are sociopaths.
- dcow 5y agoBut they're not killing people. They're extorting foreign business which is not explicitly illegal, and in fact encouraged, in certain countries. They even go above and beyond that with self-imposed restrictions against healthcare and infrastructure to try and minimize harm. I'm not saying I like what they're doing, but it seems hard to outright stop when their own country doesn't care. Same with Chinese businesses engaging in fraud with foreign investment firms. It's effectively accepted practice encouraged by their country. The market is the only real punisher. So if these types of activities are effectively allowed because people can play by the rules and engage in them, then as a society or as a company you have to respond rationally. "Well it's illegal where I live" is not really an answer. Thus my question is, "should companies pay security professionals more to combat the economics of these organizations?". People seem to think companies should pay out bug bounties on a scale much closer to what e.g. ZERODIUM would pay for 0 days to fix the economics. I guess I'm just asking if there's an economic "solution" to these ransomware groups in absence of a legal one?
- 5y ago
- nradov 5y agoHow do you propose to pursue organized crime groups in Russia who are protected by the local authorities? Financial sanctions haven't been effective.
- isaacg 5y agoOne option would be to try to doxx them, either as part of a criminal investigation or via private investigators. I bet these groups would be much less effective if their identities were publicly known. There's a reason they're not public.
- KirillPanov 5y ago> such groups need to be pursued aggressively because they are corrosive and poisonous to society at large No, they are pursued aggressively by the government because they compete with it.
- PaulDavisThe1st 5y ago> as long as you don't mess around in your own backyard. Based on the recent pipeline incident, it seems that these crime groups realize there are other places you'd better not mess around. Screw with Bank A or Company B ... fine. Screw with infrastructure of a country with a large scale military, control over large chunks of global finance, and so much more ... probably not a good idea.
- Bellamy 5y agoNext step is to search for investors.