TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Ransomware gangs are complaining that other crooks are stealing their ransoms

297 pointsby PretzelFischover 3 years ago

21 comments

kappuchinoover 3 years ago
Re: Thieves stealing from thieves ...<p>I worked(*) with a credit-card scammer who brought in a software for creating &quot;yes-cards&quot;: Cloned Creditcards that had corrupted chip and pin settings(See <a href="https:&#x2F;&#x2F;www.zeit.de&#x2F;2016&#x2F;05&#x2F;kreditkarten-banken-betrug-sicherheit-kriminalitaet" rel="nofollow">https:&#x2F;&#x2F;www.zeit.de&#x2F;2016&#x2F;05&#x2F;kreditkarten-banken-betrug-siche...</a>, sorry its only in german).<p>It was unheard of at the time that you could do this. So we set up a test to clone a credit card of ours. The kicker was, the software didn&#x27;t work when you disconnected the computer it ran on from the internet. Security mechanism from the creator? Nope, it turns out after tracing&#x2F;dissassembly it sent the data from the cards to a third party to sell it.<p>Our informant was first confused, then outraged. No honor amongs thieves!<p>(*) journalistically!
评论 #28737472 未加载
评论 #28737969 未加载
rocquaover 3 years ago
I thiink I can see why Revil added the backdoor. It&#x27;s not to steal ransoms. It&#x27;s to prevent too juicy a target.<p>There have been reports of crews stating &quot;we won&#x27;t hit hospitals in covid&quot;. With this backdoor, if your customers hit a hospital, you can hold your promise.<p>Even worse than hospitals (from their perspective) is agitating the American intelligence services. Hit too many pipelines, or similar high-news high-impact targets and &#x27;national security threat&#x27; is your new name.<p>Worse than that still, imagine one of your affiliates is stupid enough to target inside Russia. You need to keep the Russians happy or all of a sudden trial or extradition become likely outcomes.<p>At the same time, once you have the opportunity, why not use back door for some more money.<p>Glad to see that they still aren&#x27;t fully cooperating like legal businesses yet.
评论 #28735617 未加载
评论 #28735495 未加载
评论 #28736863 未加载
评论 #28744995 未加载
评论 #28736446 未加载
matheusmoreiraover 3 years ago
&gt; Cyber criminals using a ransomware-as-a-service scheme have been spotted complaining that the group they rent the malware from could be using a hidden backdoor to grab ransom payments for themselves.<p>That&#x27;s hilarious. You&#x27;d think they&#x27;d know better than to trust code they did not write...
评论 #28735121 未加载
评论 #28737055 未加载
评论 #28738391 未加载
评论 #28735498 未加载
nostrademonsover 3 years ago
Note that REvil is the group behind the Colonial Pipeline hack that took down gas supplies down the eastern seaboard earlier this year. They were taken offline by (presumably) the U.S. intelligence services shortly after that hack.<p>It&#x27;s interesting that a.) they&#x27;re back and b.) a secret backdoor that allows REvil to override their affiliates and restore access themselves is found shortly afterwards. Particularly since REvil, in the immediate aftermath of Colonial Pipeline, before they were shut down, sent out a message to their affiliates forbidding any attacks on governments or critical infrastructure. An alternative explanation is that they cut a deal with the CIA where they are allowed to continue to operate in exchange for instituting a backdoor and handing over the keys to major Western governments, such that if they hit any &quot;politically embarrassing&quot; targets, the government can override the affiliate and restore operations.<p>Keep your friends close and your enemies closer. It&#x27;s often smarter to co-opt an adversary than it is to shut them down entirely.
评论 #28745050 未加载
评论 #28741538 未加载
staticassertionover 3 years ago
This happens with scammers a lot from what I&#x27;ve seen. I watch Jim Browning and it&#x27;s interesting to see how often a scammer will say &quot;No, that other person was trying to scam you, do not talk to them, only talk to us&quot; when they see evidence of a previous scam.
otikikover 3 years ago
Tiny violin louthiers are rejoicing thanks to this new market opportunity.
mdeck_over 3 years ago
No honor among thieves? Color me shocked.
junonover 3 years ago
So they&#x27;re basically publicly admitting they&#x27;re script kiddies.<p>Hilarious.
评论 #28735332 未加载
anonymousDanover 3 years ago
So where is the back door I wonder. In the actual payload that gets deployed to the victim&#x27;s device? Or in some backend part of the ransomware software?
评论 #28738188 未加载
trulymeover 3 years ago
What is the best defence against this? Is there some software on hdd&#x2F;sdd level that can detect file being encrypted?
评论 #28737517 未加载
评论 #28739710 未加载
评论 #28737280 未加载
评论 #28738080 未加载
ur-whaleover 3 years ago
&gt; other crooks are stealing their ransoms<p>The hallmark of an ecosystem.
Waterluvianover 3 years ago
There’s no evidence to suggest it’s happening here, but I wonder how effective it is to disrupt ransomware activity by making the community distrust each other.
评论 #28737459 未加载
drummerover 3 years ago
I can&#x27;t get the humancetipede image out of my head with these gangs chainfucking eachother with revil being the last link in the chain
elzbardicoover 3 years ago
Well. They should go to the police!
quickthrower2over 3 years ago
Who do they complain to? Is there an ombudsman?
评论 #28735416 未加载
评论 #28735668 未加载
gigatexalover 3 years ago
Fuck all of them. Criminals stealing from criminals, cry me a river.
评论 #28736630 未加载
kosasbestover 3 years ago
Good. Share the (stolen) wealth.
评论 #28738036 未加载
billpgover 3 years ago
Oh-Dear-How-Sad-Never-Mind.gif
beermonsterover 3 years ago
Would be a shame if someone else used that same back door to assist in capturing the perps.
peter_retiefover 3 years ago
I just upvoted for the headline, clickbaited by the article complaining about crooks complaining about other crooks. I wonder if there is a name for this?
BTCOGover 3 years ago
See right through your C2, seize it, so you see how we move.<p>also<p>I don&#x27;t watch TV - I sit back - and watch cowrie hijack a box - patch the hole - like howdy - its me - ya new best friend show me the way that you planned to get these ends<p>Snakes in the grass stay on my toes credentials contained within all these SQL rows no time for these hoes So what you gotta say to me? I need new information, f** all your old queries I&#x27;m planted like raspberries, Pycharm&#x27;s filled with adversaries, static build, f** your external libraries.