It's always funny when <american government agency> announces "sanctions" on north korean, chinese, russian state sponsored hacking groups. What are you going to do, block them from using AWS?
There is often a sizeable non public component to some of these things that is firmly more in the gray zone.
For example knowing that there are few legal options to deal with Russian groups who were doing ransomware attacks on hospitals there was recently a public name and shame campaign that lots of people had this exact kind of response to but the actual way they were looking to impose costs on these groups was by making sure that other crime groups in the country were very aware of who these people were, that they didn’t have any meaningful protection but they did have a lot of crypto money that would be very easy to rob from them. The idea was to put them in harms way since as the theory goes it would cause others to think twice.
Tactics differ obviously depending on the target and what options make sense but this was for a non state backed group who didn’t have anything other than a cyber component to them.
Uh, arrest them when they show up in a country with an extradition treaty?
Do you think relatively highly paid individuals don't take foreign vacations?
> [1] That was true for the men released Thursday. Both were arrested on vacation in countries that cooperate with the U.S. Klyushin was arrested in Sion, Switzerland — four people alleged to be co-conspirators remain at large — and Seleznev in Maldives.
Russians get got, but Israelis? I don't see the US government pulling many strings to get them.
Malware companies have openly operated in Israel for decades: https://en.wikipedia.org/wiki/Download_Valley How many extraditions of those guys to America from anywhere have there ever been?
I mean really the arrest warrants or sanctions are just feel good PR for the agencies issuing them to let the public they are "doing something". It's the only thing they can do. For example, they aint ever going to pop a North Korean threat actor bc they simply cant travel at will.
They do pop Russians traveling outside of the CIS country region on vacation[1].
>According to Europol, a suspected LockBit ransomware developer was arrested in August 2024 at the request of French authorities while on holiday outside of Russia.
One of my favorite quotes about these hackers in CIS is, "Who cares if you have hundreds of millions of dollars, you are still stuck in Russia or the CIS region for the rest of your life".
> they aint ever going to pop a North Korean threat actor bc they simply cant travel at will.
True, but the USG has a long memory and holds grudges. Even if they never travel, they have to be confident every future government of the country will have their back. What's the odds the North Korean or Russian regime substantially changes in their lifetimes? Probably higher than the chance a future US administration will stop caring about an outstanding warrant.
Did you miss the legislatiin requiring KYC programs for IaaS providers? Basically adds AWS and all othe American clouds to the bucket of companies having to surveil for people on OFAC.
Exactly, it just results in misguided measures like IP-range bans. Yeah, sure, that's going to stop a group dedicated to finding zero days and other technical flaws.
For example knowing that there are few legal options to deal with Russian groups who were doing ransomware attacks on hospitals there was recently a public name and shame campaign that lots of people had this exact kind of response to but the actual way they were looking to impose costs on these groups was by making sure that other crime groups in the country were very aware of who these people were, that they didn’t have any meaningful protection but they did have a lot of crypto money that would be very easy to rob from them. The idea was to put them in harms way since as the theory goes it would cause others to think twice.
Tactics differ obviously depending on the target and what options make sense but this was for a non state backed group who didn’t have anything other than a cyber component to them.