Spyware maker LetMeSpy shuts down after hacker deletes server data
Spyware maker LetMeSpy shuts down after hacker deletes server data

Spyware maker LetMeSpy shuts down after hacker deletes server data | TechCrunch

cross-posted from: https://lemmy.zip/post/1088852
Archived version: https://archive.ph/cR91h
Archived version: https://ghostarchive.org/archive/F2HRY
Nice, another bunch of assholes out of business. Just one question: why the fk did they not have backups? They weren’t just wee little hateful bastards but stoopid on top too?
As someone who deals with this sort of thing, for ransomware and other destructive intrusions, the first thing they go for is the backups themselves.
Companies that have an second backup copy that is seperate somehow so non-lateral movement isn't possible are the ones that survive this level of breach.
Or they could just be stupid (cheap) and didn't have any lol
well they dealt in malware, perhaps they wanted the evidence to be easy to delete in case law enforcement decided to visit
Often the server needs access to make backups, so when you get in and get root, you sometimes also have access to delete the backups.
It depends on how it's set up. If the server pushes the backups somewhere else and has write access, then the hacker can delete them. But if another account logs in to the server and makes a backup and downloads it, it's impossible for the hacker to access the backup.
Depends on if you planned for the scenario or not.
I go for stupid &cheap, most people think backups is when onedrive and Microsoft reinforces that insane idea with popups).