Someone is hacking the hackers
gizmodo.com
gizmodo.com
After years of researching computer security and cybercrime I think this is most likely the case with this one.
"KrebsOnSecurity reports that the intruder subsequently dumped the stolen data on the dark web."
If Law Enforcement people are after them they wouldn't do this they would simply seize the website and put notification on website's front page so it seems like rival group hacked them or simply whitehat hackers.
Some of this cybercrime forums are running for more than a decade so no wonder they have attention and problems with Law and cyber criminals alike.
In general, most of those organizations want convictions, and will do what you said in regard to seizures and warrants.
Some organizations, or people, might be playing a different game, and might see it advantageous to themselves or their governments if certain criminal entities are disrupted, but not convicted.
And then you have other organizations that have carte blanche to do whatever they want, from smuggling drugs[1] to funding paramilitary groups and terrorism abroad, who might be interfering with criminals simply because they got in their way.
[1] https://en.wikipedia.org/wiki/CIA_involvement_in_Contra_coca...
Or, that some russian intelligence service is linked to the forum (it would be unlikely for them to not at least use some of the potential) and it was part of a bigger play, to disrupt their activity.
Law Enforcement Agencies work in cooperation with DOJ and they obtain evidence with the use of warrant[1] which is issued by court.
Speaking of obtaining illegal evidence you can search for numerous court cases where judges turned blind eye on questionable methods of obtaining evidence using hacking techniques. Some of those cases were seizure of Dark Web websites and their servers. Courts will always protect government agencies because they want to be cohesive and in synergy.
But the point being that it’s not universal that judges will facilitate such methods.
[0] https://en.wikipedia.org/wiki/Fruit_of_the_poisonous_tree
"reports on the web say" can often be used to get court ordered investigations - no matter the validity of the anonymous info.
So "illegally obtained info" can spawn "legal" routes to investigate the same...
False. These forums are hosted in places that US law enforcement have no power to seize.
Btw the most wanted hacker in the world was identified when his Jabber server was hosted in USA not in Russia. US used this opsec mistake and seized the server.
Russian cyber criminals often travel to Europe to countries like Czech Republic and Spain or to neighboring East Europe that's where they get arrested.
Russia uses black hats for many of its cyber attacks. They turn a blind eye to their blackhat activities in return.
Why would a three letter agency want to attack Russian hacker forums? To strike them where it hurts, where they earn their money.
The likely culprits would be FIVEEYES law enforcement and/or intelligence. But the main people of interest on these forums likely all reside in Russia and perhaps some neighboring countries. An indictment against any of them is purely symbolic; these people know never to travel to a Western country and risk arrest.
So, if you're FBI/CIA/NSA or similar, and you want to mitigate and disrupt all this fraud and theft and malware and PII harvesting from semi-organized Eastern European cybercrime, you're going to have to use some unconventional tactics. If I were a US "cyber commander" I think I'd consider trying to breach and expose their infrastructure and account info, and perhaps also plant some false flags so they think a rival was responsible.
All of that helps encourage confusion, infighting, and decreased trade and communication. Keep doing it over and over and soon enough certain types of activities might become less lucrative, since more things have to be pushed even deeper underground and are less able to depend on semi-public advertisements for vending illicit goods and services.
I could also imagine the US government considering it "fair game" from a geopolitical perspective. The current administration probably would be more likely to feel that way compared to the previous one, at least. Especially since there's evidence the Russia security services do sometimes team up with cybercriminals for certain things and turn a blind eye to them as long as they aren't targeting other Russian citizens.
Yep, everyone always says they were the victim of a sophisticated hack by advanced state-sponsored level hackers, whereas maybe their password was <company name>123.
I imagine there is very little to gain from the leaked credentials. I mean we are talking about cyber-criminals, who always like to mess with their real IP with Tor or VPNs. And who would be stupid enough to use their legal name on a darkweb carding forum?
The US GOV need to focus more on Tether not us because Tether steals billions of dollars directly from economy. Everybody know who is Merlin!
Hey, here’s the new bank account info to send stolen money to:
Hey bro, can you borrow me 100k for a few days?
Maybe this was an elaborate honeytrap set by the hackers for the hacker hackers.
Possibly an AI independently hacked the hackers.
A hacker may have convinced an AI to hack the hackers while posing as the hacker hackers. The AI then hacked the hackers’ honeytrap which exposed one single piece of data included by mistake. Only the AI knows why, since the hacker was brainwashed by a secret society of vegans.
News at 11.
Only intelligence services or people who know where the servers are located can pull off things like that,” mused one mainstay of Exploit. “Three forums in one month is just weird. I don’t think those were regular hackers. Someone is purposefully ruining forums.
The thing with the state actor stuff is; once a actor state creates some tooling and methodologies, what could possibly prevent this from getting into private hands? (I mean, serious question) States have huge computing power for cracking passwords or whatever, state have "patience" but still, computing power can be stolen (via botnets or however), any process can be automated, etc.
Zero-days and backdoor access points are like turn-key WMDs and the rest are analogous to small pistols and oddly shaped special-purpose wrenches. As long as the zero-days and backdoors stay private, I think there isn't that much concern.
If they don't stay private, then, yeah, it's a severe risk to the world. But those aren't exactly tools; more like privileged knowledge.
You're unlikely to find some super secret intelligence agency hash cracker or DDoS tool that's 100x better than all existing free and paid tools, or something like that. And I think you're probably not going to find a leak that gives you access to a gargantuan government botnet, as you suggest. Even if they're incompetent enough to somehow have that become exposed and accessible by some random internet person, they'd almost certainly shut it down within minutes. Also, odds are such a person could rent a larger botnet through a number of much simple means, anyway.
https://en.wikipedia.org/wiki/EternalBlue "On May 12, 2017, the worldwide WannaCry ransomware used this exploit to attack unpatched computers.[6][8][9][10][11][12]:1 On June 27, 2017, the exploit was again used to help carry out the 2017 NotPetya cyberattack on more unpatched computers."
I don't at all mean to downplay the severity of the risk of leaked zero-days in the slightest. It's massive. ETERNALBLUE leaking was an unprecedented fuckup, not unlike a government bioweapons facility accidentally leaking a supervirus that causes a pandemic. (Not trying to say anything about COVID, here; just an apt analogy, I think.)
However, I'd also say that zero-days aren't tools or part of tooling. They're discovered vulnerabilities - privileged knowledge, basically. Intelligence agencies possess a lot of privileged information which could be very damaging if leaked.
If a software tool contains an exploit for a zero-day, thus leaking the zero-day, then, yes, the tools themselves are a huge threat.
But I'm thinking more about the typical hacking and engineering tools you'd see, which generally aren't very weaponizable by the general public and not that interesting besides the purpose of potentially detecting their past usage and discovering things an intelligence agency might have done. That's why I said "as long as the zero-days and backdoors stay private, I think there isn't that much concern".
I interpreted the poster as being concerned about the more ordinary things (they mentioned password cracking and botnets, for example), though I think I misunderstood them.
So I can imagine, that a very well designed, modular hacker weapon by the NSA is something they value and want to keep for themself.
0-days come and go. This is a seperate issue.
But having the whole world know how your tools run? Sounds like a nightmare. Because that allows for detection.
PLus the fact, script kiddies eventually will get their hands on it.
>weren't really a big deal for anyone besides NSA and CIA.
It's an absolute nightmare if you're NSA or CIA. You're going to have to remake everything from scratch, pretty much. It'll be very tedious and will probably result in a lot of downtime and delays of other projects.
It's like when that stealth Black Hawk crash-landed on Osama bin Laden's compound. (Though that was probably a lot more annoying and difficult to re-engineer than software.)
I was just thinking about it in terms of a common media scaremonger narrative of them possessing tools that if leaked can in some way bestow magic powers or other unnatural abilities onto ordinary people. And that kind of is the case for major zero-days like ETERNALBLUE, but for general software tools, it's a total red herring.
However, yes, a very dedicated, very smart group of blackhat hackers could probably achieve somewhat similar things as an intelligence agency's hacking division. You don't necessarily have to be a government to be an APT.
There are still other advantages, though. For one, at NSA, you can do anything you want with legal impunity, while a blackhat might be imprisoned for doing the exact same thing. Also, you have access to a huge organization and various things they've already embedded themselves into, like backdoors and internet traffic taps.
So, they do have an inherent advantage, even if the people involved aren't necessarily inherently better hackers. (Though they may be, if they're better at hiring than you are at recruiting for your private organization.) Given enough time and effort, a private group could maybe also embed themselves in a lot of places, but they're all at the mercy of their governments and allied governments, and may constantly risk arrest.
In terms of this particular incident, I believe it absolutely could be either a government or a private whitehat/greyhat/blackhat individual or group.
> Only intelligence services or people who know where the servers are located can pull off things like that.
I don't really know how the quotee would arrive at that conclusion, but I do agree the seemingly systemic nature of these hacks, e.g. "Let's hit the popular dark web forums." isn't usually how criminals operate, based on my limited understanding.
That said, groups of people do seemingly weird things all the time, so I dunno if it's anything other than a gentle nudge in a direction. Hardly a smoking gun.
Additionally, I've always heard the sophistication levels of hacking groups go (from least to most): activists -> criminals -> state groups. I don't know if that's changed in some recent years, but that's how I learned it.
Indeed. Most cybercrime, like most crime in general, is primarily interested in just making money as effectively, efficiently, and safely as possible. No point stirring up a bunch of big hornet's nests when you don't need to.
Whatever it is, it's definitely not ordinary activity. Non-exhaustive list of some possibilities I'd imagine:
- Blackhats who are part of that sphere with a chip on their shoulder
- Blackhats trying to start, promote, or perhaps (false-flag style) direct suspicion towards a competing forum or other platform
- Whitehats / greyhats who just don't like fraudsters and thieves and want to fuck with them and give them a taste of their own medicine
- Intelligence agencies / law enforcement
My own assumption so far is that credentials that were previously being passed along through (essentially) in-person key-exchange parties, have now been forced to be passed along over channels like email/Slack/etc., making the ability to spin “mail/chat server admin creds” into “general system-level elevated creds” a lot more frequent.
Of course the whole situation was less than ideal to begin with, but now it's even worse.
In my experience, most... don't.
Enterprise IT at non-tech companies is an absolute #&@_ show. The only rationale I've been able to come with is: if some portion of your company isn't developing / keeping up with tech trends, your IT shop isn't going to be pressured to either.
True story: A friend was pentesting a large company network in Germany, wrote his report and got paid. Years later, when being hired as head of IT security, he pulled out his old report and simply tried the default/easily crackable passwords he had discovered in the core infrastructure: They all still worked.
If his section about "use jump hosts" was ever useful for the company, it was because someone had that page open by accident, needed a place to put down his mug of coffee - et voila: His report even made a difference!
This year is going to be huge for Google cloud and m365.
I had one of those jobs for a while. It was awful. The worst part was the ridiculous demands (example: all bugs should be fixable in 30 minutes or less) on top of the embarrassingly low pay.
Half of this is actually the right way to do it. On one hand undervaluing IT in almost any company these days is a major problem waiting to blow up. IT isn't just an end, it's the means to do everything else. Using computers but ignoring any good IT practice under the excuse that it's not an IT company is like working from an office with asbestos, lead paint, and black mold because you're not a construction company.
But on the other hand non-technical companies, meaning ones without a strong IT culture and focus, should undervalue programming expertise. One of the worst things a non-tech company should do is deploy all kinds of custom IT solutions developed internally by their "programmers with expertise". Invariably (and I mean this in the most literal sense possible) they will end up with a patchwork of systems that nobody understands or maintains properly but which underpins all the core services the company needs or delivers.
So...no, undervaluing programming expertise is never a good thing, whether your particular needs are for a lot of programming or only a little. Either you need exactly zero programming—in which case undervaluing it is impossible—or you need some—in which case you need to value it the right amount.
In general precision is important but in this case it doesn't make that much of a difference besides a linguistic discussion. Let's try to look beyond it and more at the point I was trying to make: In the companies referenced above, as I understand them, valuing "programming expertise" at all is setting yourself up for disaster. You'll be tempted to use it but pretty much by definition in those companies you have no ability to support the outcome long term. Even tech focused companies have a hard time keeping up with the custom solutions they develop and are struggling with technical debt.
If you worked in these companies you know how this goes and have seen the story countless times. IT manager of small IT dept has a "great idea", hires some people to implement it, and they get it sort of done with the limited resources. Pretty soon both the techies and the manager move on to greener pastures, leaving the solutions in the hands of someone with little to no interest in it but who has another "great idea". The best solutions are manageable ones and custom stuff is hard to manage in the best of cases. Programming expertise is like a live grenade, only useful in capable hands (which "non-tech" companies are almost without exception not).
Perhaps your second is IT being overvalued? You've described a situation where technologies are being deployed inappropriately by an organization ill-equipped to handle the ongoing effort required. This is the sort of silver bullet thinking I would expect from leadership that does not understand IT beyond that it is powerful.
I took the archetypal "non-technical companies" you gave as an example earlier. If I understood your meaning correctly in the vast majority of those cases undervaluing "programming expertise" is probably the best thing to do. And by "undervaluing" I mean they such companies should not consider this as a skill they should rely on to build their IT around.
It's not that the skill is not useful in itself, just that it doesn't serve that type of company well, and valuing it suggests the companies are considering heading in waters that they're unlikely to successfully navigate.
Most of those companies will do things inappropriately because they are ill-equipped to handle this. For all intents and purposes "programming expertise" in such a company is like driving drunk. Sure you can get home safe anyway but that's not a reason to be proud of. Or you can crash but the real issue isn't that you couldn't cut it while driving drunk. You shouldn't be doing it to begin with.
The first: I am a competent employee, who can do what needs to be done (in whatever technology).
The second: I am a forward-thinking planner, who surveys and keeps abreast of options and can identify, test, and deploy appropriate ones.
In my experience, it's the second that's lacking. Aka the "we can only deploy if Microsoft holds our hands through it" shops. Usually 1/2 because of lacking talent and 1/2 because of lacking / incorrect policies.
I've seen, but haven't seen too many, instances of "insert crazy state-of-the-art technology." Usually it's just institutional paralysis that prevents anything from getting done.
They might also be unable to know if a job applicant is good at IT or not? And listen mostly to how he/she describes him/herself, and how confident he/she sounds?
Meaning, the company in effect hires IT people a bit randomly, and then mostly finds people who aren't that good at their job.
And if the company started paying more, then, more competent people, but also lots of more so-so competent people, would apply for the job? And I wonder if the company then still ends up with a random mediocre IT people who are unable to really secure the network? Just that the salaries are higher?
I wonder if the underlying problem is that 99% of the population is unable to know if someone is good at software or not
It's a sh*tshow everywhere.
Which means they rely on those companies to do the right thing, while not really prioritizing the work (i.e. not giving it much budget), or being able to critically evaluate the quality of the work being done.
So none of this is surprising.
There may be some room to question the general technical expertise and competence of a shop that runs a bunch of Windows 7 systems, though. IT running beyond the limit of their competency may not be capable of doing what you so wisely and rightly point to.
Or they may simply not have a choice.
My company has a particular automated machine that I have to work with once or twice a month. It is controlled by a computer that runs Windows XP. It can only run Windows XP because the company that made the software went out of business years ago.
Because of that, the control computer is not permitted on the public internet. When I interface with it, it's using a dedicated laptop through a VPN to a remote session which then accesses the control machine on a dialup connection. It's slow as heck, but since I only have to do it once or twice a month, I deal.
Just before the pandemic, we looked into replacing the circa 1995 automated machine with a new one. Because of the nature of the machine, and the local government regulations about replacing it, the cost would have been little over one million dollars. Not going to happen.
Everyone hates it. But that's why my company's IT department, which tries hard to keep up with the times, has a single Windows XP computer in its stable.
Changing out the part for an unapproved one, obviously, voids the certification.
Not all machines are computers.
He isn't entirely oblivious about security, has his hard drive encrypted and encrypts some of his calls, but the non-updated system is a disaster waiting to happen.
A humble brag!
There are some very elderly machines out there.
For example, Sam needs to use a corporate network, doesn't really understand "apps" or what a "TOTP" is, so they optimize (weaken security) to allow them in.
I'm sure today's 60-year-olds are still perfectly good at the kind of things they've been doing since they were 20.
Haven’t had much use of that lately.
I think a better descriptor would be "app-native" -- i.e. "I don't understand or care how anything computing works under the hood, and it'd better be tied off with a pretty bow and UI."
So yes, I have no idea how things I don't use work. This isn't that I'm unwilling to think, things are more open ended.
The more likely reason you're noticing is that thanks to covid, and the accelerated death of real news services, combined with the echo chamber effect where we're all reminding each other of how bad things are, means you're getting more exposure to sensationalism, because that echos the best. And hacks certainly qualify as sensational, especially on slow news days, where news services desperately need clicks, and "X got hacked" gets those (even if it's a report on a hack that isn't actually one, like when someone walked into a data container with tens of servers, one of which happened to be rented by a password manager).
The real wtf is what happened in 2017, though.
[1]: https://nvd.nist.gov/vuln/search/statistics?form_type=Basic&...
What do you consider a big news item that isn't "sensationalism"? (Your link timed-out)
This global situation is specific because a lot of people are working remotely so they easier to target and compromise then before.
In the last decade or so a lot of businesses moved their presence and other ops online and lots of them practice poor cyber security that's why you see a lot of hacks happening.
Speaking of big companies they are always targets of state sponsored attacks and industrial espionage.
I feel like with a lot of security or cyber-crime stuff there's a "physician who smokes" dynamic to it where the people who you expect to have great security actually often don't take a lot of precautions. How many hackers end up being exposed because of fairly trivial or random accidents is actually surprising.
Veterans of many years are the ones who get too comfortable, and too complacent. I guess the confidence of many years leads them to work a little too closely to the blade.
This might be a universal human trait, across any industry.
Getting the SSH pubkeys of other developers is easy. Grab them from github or from a shared server or ask them once. Then use age/rage to asymmetrically encrypt the secret you want to share. No password has to travel in cleartext anywhere.
And one in which many countries i.e. Russia, Israel, China, Saudi Arabia, North Korea did not want Biden to win and who have a record of state-sponsored hacking.
Solarwinds and the Microsoft compromises for example are clearly at a scale beyond your regular criminal hacker.
VF was hacked with a MITM attack that intercepted admin credentials, you can check CT logs to verify this.
If there is a open and clear way to it, it is no longer underground/dark web.
I bet they are a very paranoid circle, though.
State-sponsored entities and research groups don't take down forums, for the same reason you don't arrest all the low-level perps on the street. You need to watch them to trail them to the bigger crimes. And blackhats don't take out forums of other blackhats.
How much? :)
Shutdown and a threatening message? Maybe. Dumping the data on darknet? I'm not even sure if they can legally do that. Besides, which agency wouldn't use that to gain even more possibly useful information?
At this point, I presume governments are breaking every law on the books. Who is going to stop them?
They don't have security.txt or bug bounty. First time I've had to go thru data I've obtained and email multiple times to get thing patched. They were ass about it.
p.s. The company is affiliated with three letter agencies and basically offer them device decryption.
A LOT of anti social people seem to act badly thinking no one is going to even look at what logs exist due to existing policy, let alone illegal sources of info that are used in parallel construction.
https://www.npr.org/2021/03/04/973696073/a-former-police-chi...
I don't understand so I have to ask:
What allows these sites to be designated as Russian? Is it simply the location of the server(s)? Is it a geographic designation, or more of a political one? Or both?
Since their inception in the mid-aughts, both of these forums (Mazafaka and DirectConnection) have been among the most difficult to join — admitting only native Russian speakers and requiring each applicant to furnish a non-refundable cash deposit and “vouches” or guarantees from at least three existing members.
In addition, their administration is exclusively Russian nationals, and all forum posts and communications are done in Russian.
Oh no. Not my username, email address and hashed password. I'm shaking right now. But then again there's always some idiot who doesn't try to anonymize.