Week 15 - The Social Contract Theory with Russian hackers

     We have all heard about the infamous Russian ransomware groups and FBI wanted list-level hackers. They wreck havoc all over the world, collect enormous ransom payments and are highly professional.

    But what if I said that... these communities and people have their own ethics?

    As crazy as this can sound, the Russian-speaking darker side of the Internet has their own set of unwritten rules and are very ethical about them. In my opinion, it's the perfect example of Hobbes' Social Contract Theory, where a set of people or communities agree to rules solely to avoid problems and keep their population safer.

    Here are some of the "ethical" methods the Russian-based criminals/hackers are known to use.

 

Disabling malware launches on friendly devices

    One would think that malware operators from Russia would like to maximize profits by infecting as many devices as possible, no matter the origin and location. 

    While there are obviously some groups that do attack devices in every country (incl. Russia), most of them actually program their stealers/droppers/trojans and so on to self-destruct when an ex-Soviet country language is detected on a system (1).

    Let's have a look at the group ransomware group DarkSide's exclusion list:


(source: https://krebsonsecurity.com/2021/05/try-this-one-weird-trick-russian-hackers-hate/)

    As we can see, the group has completely disabled malware execution on any language friendly, allied or important to the Kremlin.


COVID-19 financial relief for cybercriminals

    Another (comical) thing about their community-orientated actions was the situation during the COVID-19 crisis. As we all know, stores selling credit cards, dumps, personal data etc. are solely orientated on gaining financial profit. But a funny thing happened when the pandemic hit Russia - online shops started giving out discounts and financial help to their clients!

    Let's have a look at an update from Brian's Club (a large underground store, using the name of a cybersecurity researcher Brian Krebs):

(source: https://krebsonsecurity.com/2020/04/how-cybercriminals-are-weathering-covid-19/)

    Yes, you read that right! Loyal clients of the Russian-based store started getting pandemic support from the owner! Rhetorically speaking - did we see our local supermarkets do something like that?


Ethical ransomware targeting

    As I described above, many bad programs were coded to not run on friendly territories. But what about the Western countries? Did all of the groups only focus on profit or were there some that thought of average citizens in these countries?

    Well, yes they did. Some ransomware groups started applying rules during the pandemic that were very ethical (from these criminals). They publicly stated that they would not attack educational institutions, first responders and public hospitals (3).

    In my opinion, this was just pure humanity from them. Why would they risk the lives of other people they have never seen, who do not have any financial possibilities for them to exploit? 

    It was really great to hear that some groups actually acted like decent human beings, only going after the "rich", like banks, software companies and so on.


Sources:

  1.  https://krebsonsecurity.com/2021/05/try-this-one-weird-trick-russian-hackers-hate/
  2.  https://krebsonsecurity.com/2020/04/how-cybercriminals-are-weathering-covid-19/
  3.  https://www.forbes.com/sites/daveywinder/2020/03/19/coronavirus-pandemic-self-preservation-not-altruism-behind-no-more-healthcare-cyber-attacks-during-covid-19-crisis-promise/?sh=5ca1ffeb252b

Comments