Cyber attacks on critical infrastructure can be indirect (as in this case, the offices of Colonial Pipeline) or direct (Stuxnet). Colonial shut down their system as a mitigation and response protocol, not the hackers. The dual sword that are cyber attacks can be criminally motivated with terrorism impact. Ransomware is usually installed on a network through an end user's idiocy of opening up a phishing email and/or entering user credentials to a spoofed website. Can't wait to find out the specifics of that.
Darkside is a for profit operation that actually has a code of ethics on who not to attack, in other words, they attack for profit entities to make a profit themselves. They have their roots in Eastern Europe, and I am not sure they really are tied to Russia, in that their signatures are a bit different than the usual state sponsored or affiliated groups. In fact, I wouldn't be surprised if there were a few good old American mercenaries mixed in with the group. There are some strange bedfellows in the cyber crime realm.
Darkside is a for profit operation that actually has a code of ethics on who not to attack, in other words, they attack for profit entities to make a profit themselves. They have their roots in Eastern Europe, and I am not sure they really are tied to Russia, in that their signatures are a bit different than the usual state sponsored or affiliated groups. In fact, I wouldn't be surprised if there were a few good old American mercenaries mixed in with the group. There are some strange bedfellows in the cyber crime realm.
Comment