3 ms·
I'm not sure that attacker reputation is particularly meaningful. The group can rebrand into a new identity at any time. They're anonymous cybercriminals after
by AlotOfReading 5mo ago
I'm not sure that attacker reputation is particularly meaningful. The group can rebrand into a new identity at any time. They're anonymous cybercriminals after all and there are lots of reasons they might need to do that beyond reputation laundering.
The calculus for the victims doesn't seem to change much whether the same people are using a "new" name or an old one to hold their systems hostage.
- onemoresoop 5mo agoYeah but fewer ransomes would be paid out regardless of who is attacking. They could be spoiling their own market and am sure they would
- AlotOfReading 5mo agoThat's a motivation to avoid tragedy of the commons, not because they're trying to maintain their own reputation to victims. It benefits the criminals even if they change their name.
- Freak_NL 5mo agoThe name ShinyHunters is currently quite well-known due to a number of high-profile hacks (Odido in the Netherlands this year was huge). Their brand has a significant value right now.
- jasonfarnon 5mo agoHow does everyone know its ShinyHunters and not someone pretending? I imagine they have some mechanism to authenticate, I'm curious what it is.
- HDBaseT 5mo agoBecause ShinyHunters published they hacked Canvas on their own website. They also redirected the canvas login pages to a ShinyHunters message, whilst this could be done by another group/person, its unlikely. You can also validate PGP keys and TOX accounts, etc via their website.
- jasonfarnon 5mo agoOK, I didn't realize they had a stable website all this time. I guess it's all out there in the open with these groups.
- applfanboysbgon 5mo ago> I'm not sure that attacker reputation is particularly meaningful. The group can rebrand into a new identity at any time. They're anonymous cybercriminals after all and there are lots of reasons they might need to do that beyond reputation laundering. It is very meaningful. You seem to equate that "new" = "trust by default", but a new group is distrusted by default. Let's say that for a new group which is unproven to hold up their end of the deal, only 5% of victims will pay the ransom. But if you've built up a reputation over 5 years of honoring your ransoms, then maybe 50% of your victims will pay the ransom. Reputation is literally everything here. I doubt Instructure would have paid such a high-profile ransom if they didn't have a strong reason to believe it would work.
- Ancapistani 5mo agoAgreed. This is the same problem that crypto addresses in an unregulated market - it provides attestation and continuity, but not much else. New actors are untrusted. Trust must be built through small transactions until someone trusts you enough for larger transactions. Survive long enough without major reputational harm and you can even offer to act as an escrow service for parties with less trust.
- esseph 5mo ago> I'm not sure that attacker reputation is particularly meaningful. The group can rebrand into a new identity at any time. Reputation is everything in a collective.