
Shortly before the day of thanks in late November 2020, Cyber Speech Specialist Kertis Minder received a message from the owner of a small construction company in the state of New York. Hackers hacked the network of his organization and demanded a ransom - Curtis Groupsense receives such excited messages regularly. Often the victims are small and medium-sized businesses: brewer, printing house or web design studio, whose employees come to work one morning and find that their computers are blocked, and a requirement of redemption in cryptocurrency hangs on the screen. A reference to the site in the darknet is usually attached to it, and when the victim passes along it, the return counter is turned on on the site, like a timer on a bomb in militants.
The problem of cyber -carlation in the United States became so serious that in December 2020, the head of the Federal Cybersecurity and Infrastructure Agency called it an impending national disaster. The news describes only the most loud and scandalous incidents, such as breaking the Colonial Pipeline pipeline, for which the company paid hackers from the Darkside group about five million dollars. But for each such case, there are many others that their victims try not to spread, quietly settling the issue of ransom with extortionists.
Actually, the FBI recommends victims of cyber car not to enter into negotiations with criminals. But what else can they do? In 2018, the Atlanta City Hall tried to follow this advice and refused to pay a ransom of 50 thousand dollars. As a result, they had to spend more than two million on the restoration of their networks, legal advice and so on. And if, as a result of a hacker attack, a user data leak occurred, then the victim will also have to pay a fine for this. Therefore, the Minder, a representative of one of the latest professions, the phone calls constantly. There are less than a dozen specialists in negotiations with cyber breeders in the United States, but the demand for their services is constantly growing - despite the fact that they are accused of indulgence to criminals.
The first registered case of cyber exposure occurred in 1989, when 20 thousand researchers in the field of healthcare received a diskette by mail, allegedly containing important AIDS information. There was a malicious program on this disc, and after the victim rebooted its computer for the 90th time, a warning appeared on the screen that its computer was blocked, and the printer printed a sheet with instructions on transferring the redemption of $ 180 to an anonymous account in the Panama bank. This program was developed by Joseph Popp, an evolutionary biologist from Harvard, who, after the arrest, was recognized as insane, thus avoiding the court.
The method to which the Popp is a mailing of a malicious program, which encrypted files on the victim’s computer before the payment of the ransom, is popular among modern cyber -carriers. But in the 2000s, his colleagues often used another tactic: on the victim’s computer, numerous warnings about infection with a virus popped up, which could only be bought by the purchase of an “antivirus program” for several hundred dollars from extortionists. The victims paid a ransom through prepaid cards, who helped the criminals cash out the intermediaries who took away most of the funds.
Everything has changed with the advent of Bitcoin in 2009. When it became possible to send money and accept money anonymously, cyber expression has become less risky and much more profitable. When Curtis Minder founded his cybersecurity company in 2014, the main threat was the theft of data - user, banking and so on. He hired people with knowledge of Russian, Ukrainian and Urdu, who combed the hacker forums in the darknet in search of ads for the sale of stolen data. But the level of protection of corporate networks has grown significantly since then, so network criminals switched to extortion. According to the FBI, in 2015 in the United States there were at least a thousand cyber attacks with an extortion element, and the next year, four times more.
Cyber -carriers combine teenage bravado (in the names of their groups, words like Evil - evil - and references to video games) with sharp business instincts are often found. Their business is constantly developing and diversifying: large groups contain entire call centers, whose employees help victims to understand the difficult process of buying cryptocurrency for ransom. Others sell something like a franchise-tools for hacking in exchange for part of the ransom, and also provide services on outsourcing, such as negotiating with victims.
Many of the cybercrime syndicates work from the territory of Russia or the former republics of the USSR - and their programs in search of victims avoid computers in which the working language of the operating system is installed Russian or Ukrainian. Some members of such syndicates have army experience, but the money seems to be more interested in them than geopolitical considerations.
Some cybercrime groups choose entire sectors of the economy as a goal in several parameters. First of all, this is a weak protection, a low threshold for interruptions in work and the most intense period of work - therefore, schools often become the victims in August shortly before the students returning to the lessons after the holidays or accounting firms in the tax payment season. Others “work” exclusively for large goals, developing malicious programs specifically for hacking their networks.
The negotiator with such extortions of the miner became almost accidental. A company that suspected a victim of hacking turned to him for help. But it was too late, and the hackers had already managed to send a message with a demand for a ransom, threatening to put internal documents in open access in case of disobedience. The company's management turned to Curtis with a request to help them in the negotiations, and he advised them to begin to inform the hackers for a start that their requirements were received in order to get a little time, and he began to study the tactics of conducting business converters and the advice of specialists in the release of hostages. So, he learned that it was better to offer the counter proposal to the amount not by a round figure, but not to make concessions without a good reason. In the course of communication with Hacker, Minder found out that he did not belong to any of the large syndicates, praised his technical federation and finally agreed on the amount of the redemption that arranged the company's management.
Customers of Curtis Mender often complicated his work themselves: starting negotiations without him, they reported to the extortionists, provoking them to increase the requirements. The miner acted softerly, winning time and trying to go to a more high -ranking member of the syndicate. He began to use the tactics of “mirror empathy”, repeating their own words behind hackers. In this he was helped by a girlfriend who is fluent in Russian, Ukrainian, Romanian and a little Lithuanian: on her advice, Curtis called some of his interlocutors Kuznechik.
At first, the miner conducted all the negotiations personally - the employees of his company, programmers, simply did not have the necessary communication skills. But soon, when it became clear that the demand for negotiations with cyber carriers is growing, he hired two more specialists, one of whom, Mike Fowler, a former police officer, had experience in introducing criminal groups. Fowler drew attention to a number of firms that offered for decoding data blocked by hackers. They assured that they could unlock information without paying the ransom required by criminals, even if the fee for such services exceeded the amount of ransom itself.
From the point of view of PR, large customers are more arranged for more than the prospect of negotiations with criminal organizations: they will pay better to the company in Florida than the international criminal syndicate. But such companies, it seems, just agree with hackers to pay the redemption and unlock information, taking the rest of the fee for themselves. They refuse to speak with journalists and disclose their methods to customers, saying: “It’s not your business, how we achieve our goal, the main thing is that you restore access to your information.” And cyber -carriers understand that such companies are their reliable partner; Some even offer discounts on ransom for firms involved in the "restoration of lost information."
In October 2020, the Cybersecurity and Infrastructure Agency issued a warning for negotiators, insurers from cyberosis and companies involved in the restoration of information that they may be fined in case of suspicion of cooperation with cybercriminals. And in the last quarter of the year, the number of basses paid went to decline.
In search of a comprehensive decision of the US authorities - the FBI, the Ministry of Justice and other law enforcement agencies - together with the leaders of the cybersecurity industry, they began to develop recommendations for reducing risks from cyber absorption. Among these recommendations, for example, there were an obligation to inform the authorities on the payment of the ransom, as well as the creation of a support fund for companies that refuse to comply with the requirements of criminals. In turn, the hackers began to think about their public image: for example, the Colonial Pipeline have hacked the Darkside group announced the abandonment of attacks on schools and hospitals, apologized for the failure of the socially important infrastructure and donated ten thousand dollars in the cryptocurrency to two charitable organizations. The Revil group also said that it would no longer extort money from state, educational and medical institutions.
Perhaps they are simply trying to reduce the intensity of attention to themselves security forces - but in any case, such statements can be a sign that the market is self -regulates. It is unlikely that cyber car will disappear - but at least it can decrease to a level that suits everyone.
Retold Alexei Kovalev