← Back to context

Comment by MallocVoidstar

1 day ago

https://pbs.twimg.com/media/HItbXhvW4AAMD8W?format=jpg&name=...

All of their repos have been copied and are up for sale. Attackers are TeamPCP, the creators of the Shai-Hulud malware.

If that’s true and they do intend on shredding their copy on sale, what stops GitHub from buying it back themselves? (through a proxy, obv)

  • Nothing, this is one of the most common types of ransomware going on right now, exfiltration only extortion.

  • I probably wouldn't believe that "shredding". Also there will be legal consequences I think?

    • counter intuitively criminal ransomware gangs operate on trust. They have to ensure that we believe they really will shred it, otherwise no victim will ever pay a ransom ever again.

      Therefore one way to weaken these criminals would be to weaken this trust factor. In a way therefore comments like "can we actually believe they will really shred it" goes towards this aim.

      I have to wonder what criminal hacking gangs that do not operate on trust would do. Would it be like the replacement of organized crime (mafia) with the arguably wider damaging unorganized violent drug gangs?

      1 reply →