Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I think you are assigning too much “us vs them” to the ransomware marketplace.

With ransomware criminals, “us” is the attacker, and “them” is everyone with a computer who might pay. Political boundaries don’t factor in to it at all. It is by nature an anonymous attack, hence the term “ransom”.

It is strange to me that almost all high-profile ransomware attacks that have been publicized in the US are claimed by the FBI to be Russian or Chinese. There are plenty of other countries with greedy criminals that know software, too.



> I think you are assigning too much “us vs them” to the ransomware marketplace.

Attacking things in a foreign jurisdiction is massively appealing from a "what will get me thrown in jail by my own government if things go wrong" perspective. You don't need any political loyalty for that calculation.


The problem is that state-level actors are considerably more sophisticated in their activities than what was seen here. There was a story on HN a while back that can best be summed up as "Defending against this is impossible: Mossad is gonna Mossad and there is nothing you can do about it: https://news.ycombinator.com/item?id=26591669


There's a difference between a criminal who is state sanctioned and a state-level actor.


When your government greenlights criminal activities against their enemies it helps a lot. Many* cyber criminals act as mercs for hire, and are in fact hired for official government operations against the US.

It's simply not true that political boundaries don't factor in. They're a massive part - most obviously, consider extradition or whether the attacker's government will cooperate with the US.

* I say many, but it's more like "it happens", but it feels important to point out.


I always thought it would be fun, if one had enough pull, to get a Letter of Marque and Reprisal issued to oneself snuck onto one of the giant omnibus bills that nobody in the Congress reads in its entirety before voting on it. It could easily be interpreted to cover cyberprivateering.


It is absolutely trivial for an attacker in the US or anywhere to make their ransomware attack appear to come from Russia (to someone who doesn’t know that).


I don't see how that's relevant to the incentives of foreign enemies attacking us. As I said, there are many. It basically stops being criminal activity.

Do you really think that's not the case, or that that isn't going to considerably skew where these attacks come from?


I think he's making the point that the attributions of "This came from <insert geopolitical enemy here>" are without any evidence. How exactly do you determine that a hack originated in Russia when Russian ips will not hand over their traffic to US authorities? Just because a lot of illicit web traffic originates from Israeli servers, for example, does not mean that it originated in Israel. In reality, our cyber security agencies have no idea where these guys are coming from: it COULD very well be from Russia, sure, but it could also be from your neighbor next door who vpn'd in through a chain of servers starting in france and ending in mali.


> I think he's making the point that the attributions of "This came from <insert geopolitical enemy here>" are without any evidence.

Badly, I guess, because no one has mentioned evidence or a lack of evidence anywhere in the thread.

> How exactly do you determine that a hack originated in Russia when Russian ips will not hand over their traffic to US authorities?

There are a lot of different ways. GEOIP is just one method. Examining the artifacts for code-reuse from other malware is another big one. Looking at the types of attacks is another ie: "this malware uses these techniques, and these are favored by groups 1,2,3".

There's a lot more to it than that, and not all of it is public. I've seen attribution done through backdoor channels that were not strictly legal.

> In reality, our cyber security agencies have no idea where these guys are coming from

No, more often than not we definitely do.


That might be easier to believe if these ransomware strains didn't do things like automatically disable themselves on computers with Russian language support installed.


Yes, nobody in the west using a compromised russian box for c&c would ever put such code in their ransomware payload. That would obfuscate its origin, and we all know criminals aren't clever enough for that sort of thing.

There can only be one explanation: russian hackers operating with Putin's tacit approval. Us in the west should add this to the mounting pile of "evidence" supporting going into another cold war, because that will surely improve the entire situation. Attributing the unattributable to our preconceived enemies to escalate a conflict always ends well.

Snark aside, on a technical, factual level, this simply isn't evidence of origin, not even a little bit. "russian hackers" is such a tired punchline now that if I, being in the west, were to suddenly jump the fence after 3 decades and choose A Life Of Crime, using russian configuration file names, UTC+3 daytime operating hours, russian-hosted c&c IPs (or, better yet, russia-controlled but plausibly deniable ones like belarus or kazakhstan), and silly stuff like skipping infection of ru-locale machines would be obvious things I would be doing to fuel this existing narrative sailwind. It's utterly silly to think that this in any way suggests origin.


Exactly, people do not understand how trivially easy it is to completely halt US investigations into internet traffic origins just by pivoting off of a box in a country which doesn't hand over its ip logs to the United States. I would imagine that, should you choose to hack a russian target, you would pivot off of an american box (or would the US hand those logs over? I actually think they might even if Russia wouldn't reciprocate).


Russian and a bunch of other CIS countries. It could very well originate from Moldova or Kazakhstan.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: