Online Street Crime
TL;DRDixon County Sheriff's Department paid a ransom after CryptoLocker-style ransomware encrypted their files in 2014, part of a wave hitting U.S. police departments that extorted nearly $3M before an international task force dismantled it.
Jordan Bloemen and Scott Francis Winder explore the commercialization of cybercrime. Jordan tells stories and interprets the nerdiness of Scott.
Transcript
Machine-generated transcript; may contain errors.
Speaker 1: Welcome back. Two years ago, an officer at the Dixon County Sheriff's Department opened his laptop. There's no fan turning lazily in the lobby of Dixon County Sheriff's Department. There's no bell that dings when you walk through the front door. From the outside, it looks more like a shopping mall than what you probably picture when I say Dixon County Sheriff's Department. The county is a pretty quiet place. It's a place with history. It's a place kind of wrapped around an interstate. It's a place with an old mill. The sheriff's department, alternatively, is tall and modern and wrapped in glass. If you look at the budget for Dixon, Tennessee, for the whole county, one thing jumps out at you. This place spends a lot on their sheriff's department and it shows. It feels like it belongs to the future of Dixon rather than its present. But in the fall of twenty fourteen, somewhere in this building kind of plucked out of time, someone fell victim to a trap from the future. This tool, still in its infancy and crawling from depths of the internet, that paints a picture of where hacking is headed. Somewhere in the Dixon County Sheriff's Department, someone turned on their laptop. And on their screen, a countdown timer had begun. Seventy two hours marching down the moment they opened the display. A timer and a message. Your files have been encrypted. There is no way you will ever see them again without the key. If you want the key, you have to pay. This is ransomware, a malicious new breed of malware that takes your digital information hostage. The ransomware that breached Dixon County and half a dozen other police departments across The United States, it took in almost $3,000,000 before it was conquered by an international joint task force that dismantled it piece by piece. But with hackers creating new breeds of ransomware every day, it represents a future in which cybercrime is more like a business, and almost anyone with the right skills is an entrepreneur. Oh, and Dixon County? They paid the ransom.
Speaker 2: My name is Jordan Blumen. And I'm Scott Winder.
Speaker 1: And this is ransomware, on this episode of Hack.
Speaker 2: Nothing better exemplifies the change that's happening in the cybersecurity world in ransomware. And to me, that's why I find it fascinating. You know, we've had malware for decades, but it was always nuisance malware. And it was, you know, people trying to hack in, and people wanted access to things they weren't supposed to have access to. And now we do it for money. Ransomware is a commercial transaction, and we have moved from hackers in the underworld causing nuisances and looking for stuff and trying to get attain access to things that they weren't supposed to, to hackers generating millions and millions of dollars.
Speaker 1: I feel like and this is probably just from the outside looking in, but I have a sense that hacking there's always been an element of, like, for profit in hacking. It's just been more at the upper levels of it where it feels like ransomware is the first time someone just getting into this world for the first time can do something that makes them money almost immediately.
Speaker 2: Yeah. I think that's probably because you saw hacking through the lens of pop culture. And it's like I saw hacking through the lens of hackers, and a lot of hackers didn't do things to generate money. They didn't make money from hacking. It's you know, it wasn't something that they could easily do. Like, you know, a hacker who wanted to make money from hacking would have to use, you know, the toolset that is being able to hack as part of a chain that generated money. You know, there wasn't just some commercial thing. You didn't hack a bank and just move money. You know, that's the kind of quintessential pop culture reference, but, you know, that didn't happen all the time. Yeah.
Speaker 1: It's almost the difference between, like, a long con or a con artist versus someone who's just willing to mug you in the street. Yeah. Coming from your background, how would you have made money hacking?
Speaker 2: You know, I think I think it would have been part of the challenge. It would have been part of the excitement. It would have been, what can I do? Okay. I have the ability to attain access to people's communications. Okay. What communications are confidential but relevant to future money? Maybe it's mergers and acquisitions information from Wall Street firms. If I had access to that stuff, then I could trade the market before the news broke. You know, it's part of the clever problem solving that went into hacking. And now we just literally have people, as you said, mugging people in the streets, and that's what ransomware is. The creativity and the cleverness of it is gone. It is just a brute force transaction.
Speaker 1: And it's also about the idea of casting a really, really, really wide net and seeing who bites. I mean, that's that's fishing. It's about putting this thing out there in the world as many times as you possibly can and seeing who falls victim to it, whereas what you're talking about is the idea of staring down a target and going after them and using all of that creativity and those skills that a hacker has to facilitate that.
Speaker 2: Yeah. Quality over quantity versus, you know Yeah. Quantity over quality. If you send out a phishing scam and demand a Bitcoin ransom from 70,000,000 people and 7,000,000 people pay it, hey, you're a wealthy, wealthy person. You know, if I know what the interest rate decisions are gonna be for the United States Federal Reserve hours before they become public, I'm also gonna be a very rich person, but I didn't injure people to get it. I think that's the difference.
Speaker 1: Okay. So what is ransomware?
Speaker 2: Well, ransomware is, you know, literally malware that holds your computer or your information ransom. And the the you in that is very flexible. Could be, you know, your mother, or it could be a hospital, or it could be the FBI. And pretty much all of those people have paid it at some point.
Speaker 1: Right. So when you say it holds your data hostage, how does it hold data hostage? We can think of holding a person hostage in a very literal way, but how do you hold data hostage?
Speaker 2: Well, the the thing that they've discovered is they can encrypt it and generate a key to decrypt it that's unique to just your data, and then they essentially hold that decryption key hostage. So your data is still in your possession. It's just being encrypted. But if you wanna unencrypt it, you need the decryption key from them. So it's using a form of key based encryption, which we've kind of touched on in other episodes.
Speaker 1: So this piece of malware infects your computer. It takes all of your data. It encrypts it, and the only way that you can unencrypt it is if you pay them for that key.
Speaker 2: Correct. And usually, it's on some demand time like a traditional ransom demand. You've got ninety six hours to produce $1,500, or else it's all gone.
Speaker 1: How do you get without getting too specific, how do you get a piece of software like this onto a victim's computer?
Speaker 2: The most interesting thing that we might be able to look at in ransomware is the, propagation of it. You know, how is it getting spread? And it's getting spread in all kinds of ways, from phishing scams over email to probably the most interesting cases are when people figure out ways to inject it into, advertising, which is called malvertising.
Speaker 1: How do you do that?
Speaker 2: I think it's ad network dependent, but some ad networks have had Flash vulnerabilities or have had HTML five vulnerabilities that will actually set off an attack vector that ends up with malware being put on your computer. So it's yeah. It's pretty substantial.
Speaker 1: I don't even we'll have to cut this. I don't even wanna go down this road, but that's that might be the most ethical argument for ad blockers I've heard yet is that they're unsecure platforms and people can use them to inject stuff on your computer. Yeah.
Speaker 2: You could you could probably spend a few months researching and put together a pretty strong argument for that. That's bananas.
Speaker 1: Yeah. Starting something new isn't just hard. It can be downright terrifying. You put a lot of work into a thing. You're not entirely sure it's going to work out. You're taking a huge leap of faith. I've started a few things. Now I know I was right for believing in, you know, the idea, the product, despite all of those fears and hesitations. But boy, does it sure help when you have a partner like Shopify on your side. Shopify is the commerce platform behind millions of businesses around the world and 10% of all e commerce in The US. From household names like, well, hacked podcasts merch, to brands just getting started, you can get started with your own design studio with hundreds of ready to use templates. Shopify helps you build a beautiful online store that matches your brand style. Did I mention that that iconic purple shop pay button is used by millions of businesses around the world? I don't know why I wouldn't. I should. It's why Shopify has the best converting checkout on the planet. It also helps boost conversions, meaning less carts, sort of getting abandoned in the parking lot, and more sales for you. It's time to turn those what ifs into sign up for your $1 per month trial at shopify.com/hacked. Go to shopify.com/hacked. One more time, that's shopify.com/hacked. Okay. So someone decides that they wanna they wanna try and do this. They wanna put ransomware in the world. Again, without being too specific, where do people find these things? Like, this is not a piece of software that I can download off the App Store.
Speaker 2: Most of them are kind of custom written, but, like, a lot of the organized crime that's using it now, they might have somebody might have written it a long time ago. Like, CryptoLocker is a big one. There's a new one that's flying around right now. It's not new, but it's it's kind of having a resurgence right now called Locky. And, yeah, these were written by people, like, I Crypto Lockers and it's I don't remember fifth, sixth version maybe. Like, it's been around for a while. So yeah. So they're generally custom written, shared amongst specific groups. So
Speaker 1: Right. And if they're not custom written?
Speaker 2: Yes. Yeah. So or or they're copycats. So so they're clones of this original good idea if you wanna say it's a good idea, but appears to make, you know, organized crime millions and millions of dollars. So I guess it's good to some people.
Speaker 1: Okay. So do you pay these people?
Speaker 2: Well, I think the general consensus is yes. Like, I think the FBI pays them. I know a sheriff's department in The States paid them, which we talked about in the opening. Hospitals have paid them. It's it's really do or die. So I think you have to make a personal decision of whether what they have of yours is worth what they want you to pay for it. So if it's the operating spreadsheets for your business, and it would cost you hundreds of thousands of dollars to pay to get them back, or you could just give them $1,500, I think the economic utility of that statement speaks for itself.
Speaker 1: It is this thing from a, like, a classic hostage situation in that they don't have a person that they're responsible for at the end of this. The data's on your computer. It's just encrypted. So it doesn't really matter to them one way or another whether or not you pay it. If you decide not to pay, you're just out of your data and they're still out there in the world. Nothing bad has happened to them.
Speaker 2: Yeah. And I think it there's some organizational structure behind that too where it's like there's call centers for a lot of the big organizations that do this. So you're completely removed. The person who is in charge of writing the code isn't probably the person who's in charge of having it deployed, who isn't the person who's in charge of communicating with the hostages. You know, it's it's you're so far removed from it. You're just a call center worker at some point, and, you know, it's not on you. You know, you're not the one deciding someone's life like you would be if you were truly holding someone hostage. So it's it's got levels of insanity and that are also levels of brilliance depending on what lens you're looking through.
Speaker 1: It's taking it's taking the skills of hacking and instead of being one phase and Alon Khan to use that term we used earlier, it's using them as a resource in starting up a business. And I feel like that's what's different about it. At least that's what feels different about it.
Speaker 2: Yeah. It's it is, you know, petty level crime activity for profit. It is organized crime in the twenty first century.
Speaker 1: I think it's worth asking. You're not willing to pay. Is there anything you can do to get this information back, or is it just lost to the world?
Speaker 2: Depends. So some of them aren't using strong enough encryption that people can actually reverse engineer the encryption. So some of them and I don't know the exact ones or I would use them by name, but but some of these different, ransomware versions, if you have some of your original files and can feed in the encrypted version and the exact same version as an original, so maybe from an email or from a backup, it can actually figure out the decryption key, and then you can decrypt your stuff. But most of the modern versions, no. It's heavy encryption, and it's gone.
Speaker 1: I think it's tough because in that moment, I would be so angry and I would be so upset even if it is just x amount of dollars for my data back. I'm so angry with these people. I don't want to give them money.
Speaker 2: Yeah. But they get you in the hook because they target specific file types, notably images, spreadsheets, word documents. So imagine if you, you know, were writing a book, keeping photo diaries of all your family, you know, and as all photos have pretty much gone digital at this point, all of your memories, you know, what are these things worth
Speaker 3: to you?
Speaker 2: Are they backed up to the cloud? Better question, was your cloud hit with ransomware? Because that's another major problem.
Speaker 1: What exactly happens when your backup gets infected?
Speaker 2: Yeah. So think about something like Google Drive or, Apple iCloud Drive, Dropbox. These are services that keep files local on your computer, but then they replicate and sync to a to essentially a a virtual hard drive in the sky. So if your files become encrypted on the local version, and they sync to the virtual hard drive in the sky, assuming there isn't version control. All of the files in the in the cloud are now the encrypted versions, not the original versions. So, you know, a lot of these little services like Dropbox have the ability to kind of look through some versions, hopefully. But for major corporations, this becomes a huge issue because you get something called hot site backups. So, like, a lot of big companies will have their entire technical infrastructure replicated at a separate server farm. So if something happens, you know, the infrastructure immediately swaps over. So imagine your building with your server farm burns down. It's kind of okay because the server farm exists in another place and the data is kept in sync in real time, which is why it's called a hot site. It's not a cold site where they have to show up and turn the servers on and rebuild the data. It's live. So major major companies will have this, but the issue is is that if one site gets hit with a ransomware, it'll real time sync to the hot site swap. So it's it's, you know, you're getting this, like, enterprise level headache. You spent millions of dollars to have this second, you know, technological infrastructure set up for you, but it can be ruined in a heartbeat.
Speaker 1: At that point, you're just paying someone to back up a virus that has compromised your system.
Speaker 2: Right. Well, if you think about it, something like a fire, like a traditional hazard. You know, a building burns down, and it's a huge incident, but can be less destructive to a company than ransomware can be.
Speaker 4: No one goes to Hank's for spreadsheets. They go for a darn good pizza. Lately, though, the shop's been quiet, so Hank decides to bring back the $1 slice. He asks Copilot in Microsoft Excel to look at his sales and costs and help him see if he can afford it. Copilot shows Hank where the money's going and which little extras make the dollar slice work. Now Hanks has a line out the door. Hank makes the pizza. Copilot handles the spreadsheets. Learn more at m365copilot.com/work.
Speaker 2: So that's when the ransoms start to get out of control. If they get into an infrastructure and encrypt an entire enterprise, databases, accounting software, every operational document, versions, logos, you name it. Imagine it all gone. Everything in public drives, and that you drive that you have at work, everything is gone.
Speaker 1: These people that are sending the software out, they send it out en masse. They try and get as many people infected as they can. Do they know when they've gotten that massive corporation whose information is worth millions versus your aunt with a couple of photos that's only willing to pay maybe a 100 couple a couple $100 for it? It?
Speaker 2: Yeah. I think the there I'm I don't know the ins and outs of the technology enough to know exactly how it does, but I assume it's based on volume. Because the first thing it does, like, if if it hits your work computer, the first thing it does is it looks not only at what's on your computer, but what's on the network that it can reach. So it starts to spread through the network. So imagine a big company where you've got thousands of computers maybe accessible over the network or sharing files back and forth, and they're literally just sharing the ransomware, you know, back and forth.
Speaker 1: Okay. So how do you defend against this either as an individual or as an organization that has this massive network of com connected computers?
Speaker 2: It's tough. The the way like, there's no man, I don't even know what to say to that. There's no level of organization that's really figured out how to avoid it. Like, it hits everybody. I know one of the things that's becoming more common is, like, a sandboxing system so that the second you download any file or any file downloads on your computer, it kinda lives inside of a little small, virtual machine on your computer so that you kind of get to run it in there and ensure that it's it works. So it won't have access to the any files any other files on the hard drive. It won't have access access to that stuff until it's been proven clean, at which at that point it can come out. But, you know, those are expensive enterprise level systems. I'm sure there are other things that I'm not super familiar with them. If anybody knows any, feel free to tweet them at us.
Speaker 1: And what about for an individual?
Speaker 2: Be smart. Same old, same old comes down to being smart. But then again, to go back to propagation, I can't remember exactly who it was, but I think it was an FTP
Speaker 1: client for OSX. Somebody had hacked
Speaker 2: their server so that if you downloaded the installer, server so that if you downloaded the installer over the course of, like, one week, inside of that installer, it also installed ransomware. Like, it's you know, as the more walls you put up, the more clever people become, and it seems people keep becoming more and more clever. So I don't know if the best way to protecting is it is just to it's to just keep your wits about you when you're doing stuff.
Speaker 1: Which is kind of the exact opposite way of people of how people actually interact with computers now. We're becoming way more trusting even as things get theoretically a lot more dangerous.
Speaker 2: I think that's the I think that's the game now. The more trusting that the end user becomes, the more field they've created for the hackers to play.
Speaker 1: So last episode, we mentioned having some potentially what's a good way to get into this?
Speaker 2: Last episode, we mentioned, some of the delays and some other things that were going on that we were trying to get going to kind of allow us to do more of this.
Speaker 1: And we were very, very hush-hush about it, but, the press release has kinda gone out, so it seems like we can probably talk about it.
Speaker 2: Yeah. So, we Why don't
Speaker 1: you just read the read the press release?
Speaker 2: Sure. Let's just read the press release. Network Media Group Incorporated is pleased to announce it has acquired the exclusive rights to adapt the iTunes podcast Hacked as a television series. Created by tech entrepreneurs and storytellers, Scott Francis Winder and Jordan Blumen. The hacked podcast explores the curious, enlightening, and occasionally criminal underbelly of the Internet. With the podcast currently attracting tens of thousands of followers for each new installment, network and the hacked creators will expand the scope and scale of the storytelling to bring its legions of podcast followers, that's you guys, an even bigger payoff with a deeper dive into the myriad of mysteries and other compelling stories lurking in the online world.
Speaker 1: We're the worst. We just read our entire press release.
Speaker 2: That is not the entire press release.
Speaker 1: No. That's the first paragraph.
Speaker 2: But anyway, so we might make a TV show.
Speaker 1: That's what we're working on. Doesn't mean that we're gonna get to make it, but it means that some very, very nice people wanna try and make it. So hopefully, that was worth the the big old delay, between the last batch of episodes.
Speaker 2: We're super ecstatic about it, truthfully. Jordan and I would love to make a TV show, and this seems like a great TV show to make.
Speaker 1: But in the meantime, we're gonna keep trying to make podcast episodes.
Speaker 2: Yeah. And if you happen to be a person that works at a major television network that wants to buy a TV show, then you should buy ours.
Speaker 4: And on that note, my name is Jordan Blumen.
Speaker 2: And I'm Scott Winder.
Speaker 1: Thanks for listening to this episode of Hacked.
Speaker 5: Have no fear. Chosen Foods is here to defend your favorite foods from the forces of seedy oils and sketchy ingredients. With cooking oils, salad dressings, and mayo, all powered by the good fats from 100% pure avocado oil and simple delicious ingredients, chosen foods.
Speaker 6: Alright. Listen up. The only gift that any dad wants on Father's Day is Goldbelly. Goldbelly ships the most iconic foods from the best restaurants across the country straight to his door for free. Let him kick back and chow down on award winning barbecue from Texas, epic deep dish pizza from Chicago, or colossal pastrami sandwiches from New York. Make dad feel like an absolute legend this Father's Day, and go to goldbelly.com to get 20% off your first order with promo code dad. That's 20% off @goldbelly.com. Code dad.
Speaker 3: Hey, sweetie. Your mother, showed me this Carvana thing, for selling the car. I'm gonna give it a try. Wish me luck. Me again. I put in the license plate. It gave me an offer. Unbelievable. Okay. I accepted the offer. They're picking it up Tuesday from the driveway. I haven't even left my chair. It's done. The car is gone. I'm holding a check. Anyway, Carvana, give it a whirl. Love you.
Speaker 4: So good, you'll wanna leave a voice mail about it. Sell your car today on Carvana. Pickup fees may apply.