4 ms·
Google winlockers, they were plentiful before “ransomware” term became popular. Ransomware was already booming when cryptocurrency first hit the cybercrime scen
by ryanlol 5y ago
Google winlockers, they were plentiful before “ransomware” term became popular. Ransomware was already booming when cryptocurrency first hit the cybercrime scene after the Liberty Reserve seizure.
Gift cards were a common method of cashing out, you can anonymously cash out millions of those at around 80% of face value. IRS scammers still use gift cards for this reason.
> However, there was no practical way for criminals to get multi-million dollar payouts previously.
This is just bullshit. Read up on Zeus, SpyEye and various contemporary BEC gangs.
Read up on the craigslist scammers stealing billions selling non existent cars.
- ARandumGuy 5y agoI'm not disputing that before cryptocurrency people made a lot of money stealing, scamming, and hacking people. And people will continue to do so as long as we have money and computers. What's new is demanding millions of dollars in ransom against large companies and organizations. This is a fundamentally different scale then locking grandma's computer and demanding some iTunes gift cards. Without cryptocurrency, most "ransomware" relied on getting a small amount of money from a lot of victims. These high profile attacks rely on getting a lot of money from a single victim. That's what changed with cryptocurrency. > Read up on Zeus, SpyEye and various contemporary BEC gangs. I spent a bit of time reading up on those, and none of those seem like ransomware to me. Ransomware involves locking down a computer (or group of computers), then demanding a ransom to unlock it. That's a different attack then stealing bank account information or social engineering scams.
- ryanlol 5y ago> That's what changed with cryptocurrency. Do you have any evidence to suggest that cryptocurrency was the driving force here, rather than just natural evolution of ransomware operations? I don’t believe so. Winlockers blew up right before cryptocurrency showed up, the early ones were very unsophisticated but hugely profitable. I believe they would have naturally evolved towards bigger payments even without cryptocurrency, it’s easier to process the occasional wire for $10M than to process tens of thousands of payments for $100. I’ve never seen anyone actually familiar with the cybercrime market try to argue that cryptocurrency is a driving factor behind ransomware. You hear it from apparently highly qualified ”infosec professionals”, but most of those people have never interacted with this scene. > I spent a bit of time reading up on those, and none of those seem like ransomware to me. Ransomware involves locking down a computer (or group of computers), then demanding a ransom to unlock it. That's a different attack then stealing bank account information or social engineering scams. Of course, the point was about their ability to receive huge payouts pre-cryptocurrency. Ransomware groups wouldn’t have any trouble accepting tens of millions of usd by wire transfer, especially since they can penalize the company if the money doesn’t land. Oh yeah, check this out https://twitter.com/malwaretechblog/status/1401003303085875201?s=21 https://twitter.com/malwaretechblog/status/14010033030858752...