BBC Visits 'Hated and Hunted' Ransomware Expert (bbc.co.uk)
In "Hated and hunted," a BBC reporter describes visiting a ransomware expert "who has devoted himself, at huge personal cost, to helping victims of ransomware around the world."
They hate him so much that they leave him angry threats buried deep inside the code of their own viruses... "I was shocked but I also felt a real sense of pride," says Fabian. "Almost like, a little bit cocky. I'm not going to lie, yeah, it was nice...." He works remotely for a cyber security company, often sitting for hours at a time working with colleagues in different countries. When he's "in the zone", the outside world becomes even less important and his entire existence focuses on the code on his screen. He once woke up with keyboard imprints all over his face after falling asleep during a 35-hour session.
All of this to create anti-ransomware programs that he and his company usually give away free. Victims simply download the tools he makes for each virus, follow the instructions and get their files back... According to research from Emsisoft, the cyber security company Fabian works for, a computer is attacked every two seconds. Their network has managed to prevent 2,584,105 infections in the past 60 days -- and that's just one anti-virus firm of dozens around the world.... "It's pretty much an arms race," says Fabian. "They release a new ransomware virus, I find a flaw in its code and build the decryption tool to reverse it so people can get their files back. Then the criminals release a new version which they hope I can't break... It escalates with them getting more and more angry with me...."
Fabian accepts that moving around and restricting his life and circle of friends is just a part of the sacrifice for his hobby-turned-profession... He earns a very good salary but looking around his home and at his life it's hard to see how he spends it.
He estimates that he's "upset or angered" 100 different ransomware gangs (based on his analysis of the Bitcoin wallets where they collect their ransoms.) One group had collected about $250,000 (£191,000) in three months -- until Fabian created a countering anti-ransomware program -- which is one reason he carefully hids his identity.
"I know how much money they make and it would be literally nothing for them to drop 10 or 20,000 for like some Russian dude to turn up to my house and beat the living hell out of me."
All of this to create anti-ransomware programs that he and his company usually give away free. Victims simply download the tools he makes for each virus, follow the instructions and get their files back... According to research from Emsisoft, the cyber security company Fabian works for, a computer is attacked every two seconds. Their network has managed to prevent 2,584,105 infections in the past 60 days -- and that's just one anti-virus firm of dozens around the world.... "It's pretty much an arms race," says Fabian. "They release a new ransomware virus, I find a flaw in its code and build the decryption tool to reverse it so people can get their files back. Then the criminals release a new version which they hope I can't break... It escalates with them getting more and more angry with me...."
Fabian accepts that moving around and restricting his life and circle of friends is just a part of the sacrifice for his hobby-turned-profession... He earns a very good salary but looking around his home and at his life it's hard to see how he spends it.
He estimates that he's "upset or angered" 100 different ransomware gangs (based on his analysis of the Bitcoin wallets where they collect their ransoms.) One group had collected about $250,000 (£191,000) in three months -- until Fabian created a countering anti-ransomware program -- which is one reason he carefully hids his identity.
"I know how much money they make and it would be literally nothing for them to drop 10 or 20,000 for like some Russian dude to turn up to my house and beat the living hell out of me."
I like to see the national breakdown. I know a few e Europe groups that are permanently butt hurt.
it will probably just cost a ruble or two
Ironically silk road had a solution for this problem. Just create an etherium payable contract that pays when the ransom where evil doer is killed, as measure by whatever method the contract specified as satisfactory proof the right person received the right result.
Of course this is also a terrible idea. Paying mercs to kill people is going to result in incompetent mercs and dead innocents. Not to mention the whole idea of murder.
Still given human nature if this option were offerend anonymously but widely available I'm also sure the go fund me kitty would swell.
THe only thing one can say is that in the end you'd be both remorseful and gratified and possibly incarcerated
Some drink at the fountain of knowledge. Others just gargle.
When they go low, we aim high
Some drink at the fountain of knowledge. Others just gargle.
alternate headline: "Assassins pay BBC to find address of ransomware expert."
"First they came for the slanderers and i said nothing."
They hate him so much that they leave him angry threats buried deep inside the code of their own viruses...
So in other words evil people do bad things to good people. Since Cain and Abel, some things never change.
Sure bad guys could try to thwart payments buy buying shares and voting no or not voting, but that's transient. They would be effectively having to match 25% of the growing kitty and thus funding their own wanted-poster-reward.
I note that one doesn't have to make this a wanted-dead reward. I just phrased it that way for the drama. A bounty for bringing them to justice would be much better and more wholesome.
“It’s pretty much an arms race,” says Fabian. "They release a new ransomware virus, I find a flaw in its code and build the decryption tool to reverse it so people can get their files back.”
How does this work? There's probably some government agencies with the ability to crack various encryption schemes, but a dev at some anti-virus company?
I'm sure he's pretty good at what he does, and there's probably a handful of instances where the ransomware folk did something dumb. But file encryption is pretty standard stuff, and I can't imagine it's too hard to generate a unique decrpytion key for each victim and to stop that key from persisting on the victims machine.
So is the story mostly hype and the guy just cracked a couple crappy tools? Are the ransomware folk really that incompetent? Or am I missing something?
I stole this Sig
Who reads this drivel lol?
Years ago, Fabian was a teen heartthrob back during my mother’s youth... and now, here in his twilight years, he’s helping ransomware victims recover their data? That’s seriously impressive.
#DeleteChrome
Thank you sir, for doing what you do!
Best Regards,
Everyone except the crooks.
Backup people!
So.... labelling that "some Russian" = murderer is ok; but if we written that about any location in Africa this would become racial slur?
Your US/UK politicall correctness is so silly.
Ah, the "subtlety" of Western propaganda. The dude who turns up and beats the living hell out of the good guy can't be just Dude. Quite often it has to be Russian Dude. Malice or stupidity? Or just plain old xenophobia?
Either these malware authors are absolutely useless or this guy is the author of the malware he's saving people from, or he's just a total bullshit artist looking for some free publicity. Did anyone verify his claims?
You can't backup people... yet!
Lest we forget the difference between reality and xenophobia.
Slapping the label of racism on something doesn't change the reality of it. The labeling is just propaganda to forward an agenda.
I've been hacking things all my life and I became a professional software developer in 1983. Virus writers are not going to leave peoples names in code. Your purpose of writing a virus is to keep the code as simple and as small as possible. Well that is unless you are developing it in JavaScript than anyone can reverse engineer it. But anyone stupid enough to send out source code with the virus is asking for it anyway. Reverse engineering the binary does not produce pretty source code in a language that you choose and more than likely does not ever contain messages to the person trying to undo what the virus does.
And again, no. a virus writer does not know who is infected and not infected and how if he does get an infection to occur how it became un-infected. For all the virus writer know is that maybe the computer is unplugged or an operating system reinstall occurred.
Nathan
I worked with Fabian and an agent of the FBI at one of my client locations. I had the ransomer "John Smith" sympathetic and talking back and forth through email, convinced that the situation was about to cost a computer tech ("Tim") who had not set backups up correctly his job - and that the ransom money paid was his personal money, not that of the intended victim company. And I managed to convince him that the decryption code we paid for didn't work properly on all of the files. (I opened several in Notepad, deleted a portion from the bottom of each, and then saved the versions I sent him to look at - which he actually asked to do to try to help: better customer support than a lot of legal outfits, to be honest. ;) ) He actually sent money *back* to the fictional tech's Paypal account (and offered to get him a job doing what he was doing!) - which resulted in both Paypal accounts getting locked and the ransomer losing access to a much larger sum that he had in that account. (Part of the reason I'm posting this anonymously is that I had a feeling he was just the equivalent of a CSR, and I *might* have pissed of some Russian mob that day.) During the conversations, he gave away information that led us to believe that he was in Belarus, based on time zones.
Fabian's methods, at least when I worked with him that time and on one other occasion after that, did not attempt to hack the encryption or anything so impossible as that. They relied on finding traces left behind on the system - files including deleted files, things in memory if the system hadn't been rebooted, etc - from the original encryption process that could be used to recover the key to decrypt with. I almost feel reluctant to share that, but at the same time, anyone who reads the message board he works with victims on would know that, because he doesn't exactly keep it a secret, and surely the ransomers would read it.
See subject: When you get threats or attacked? YOU ARE EFFECTIVE vs. those doing wrong - period.
* Care to debate that?
APK
P.S.=> I know that's "how it is", I go thru it since a very SIMPLE WARE I've created IS EFFECTIVE vs. threats galore (& who does the attacking?? Those adversely affected by my efforts - they make me laugh)... apk
You are a LEGENDary SPAMMER.
See my subject: I stop advertisers (biggest spammers) who infect, track & slow us (w/ botherders & malwaremakers) - do you? No.
* I've never seen YOU (or "your kind" that STALKS me by UNIDENTIFIABLE anonymous posts like the LAZY unskilled WEEZIL wastes you are) ever be useful OR produce anything YOURSELF (especially of code of your own, not stolen "OpenSORES") that's any good either, lol - I do (see below next)!
Via the best hosts file multiplatform:
APK Hosts File Engine 2.0++ 64-bit for Linux h t t p : / / a p k . i t - m a t e . c o . u k / A P K H o s t s F i l e E n g i n e F o r L i n u x . z i p
APK Hosts File Engine 10++ SR-1 32/64-bit for Windows https://hosts-file.net/?s=Down...
Make a Wheel https://isc.sans.edu/forums/di... as I did giving users more speed/security/reliability & anonymity NATIVELY doing more for less vs. ANY single 'solution'!
APK
P.S.=> You are a LEGENDary FAILURE do-NOTHING "ne'er-do-well" JEALOUS "Lil' Jowie", lol... apk
Hosts efficacy recently vs. threats & results in https://tech.slashdot.org/comm... https://yro.slashdot.org/comme... https://it.slashdot.org/commen... https://linux.slashdot.org/com... https://news.slashdot.org/comm... https://apple.slashdot.org/com... https://it.slashdot.org/commen... https://it.slashdot.org/commen... https://it.slashdot.org/commen... https://it.slashdot.org/commen... https://it.slashdot.org/commen... https://it.slashdot.org/commen... https://search.slashdot.org/co... https://it.slashdot.org/commen... https://it.slashdot.org/commen... https://tech.slashdot.org/comm... https://tech.slashdot.org/comm... https://apple.slashdot.org/com... https://tech.slashdot.org/comm... https://it.slashdot.org/commen... https://tech.slashdot.org/comm... https://tech.slashdot.org/comm... https://science.slashdot.org/c... https://tech.slashdot.org/comm... https://tech.slashdot.org/comm... https://tech.slashdot.org/comm... https://it.slashdot.org/commen... https://it.slashdot.org/commen... https://yro.slashdot.org/comme...
* That's only recently while I've been on Linux (July 2018) & 100's of times vs. MANY other botnets/malwares etc. in the past circa 2006-early 2018 while I was on Windows: CONCRETE VERIFIABLE UNDENIABLE REALITY (see those links 4 proof). ... & that's ONLY what /. reported on (there were FAR more /. OMITTED reporting on).
APK
P.S.=> "It's working: Neville... it's working!" - "I AM LEGEND" + HOSTNAME USE IS DOWN IN MALWARE https://unit42.paloaltonetwork... (my ACT OF