FBI seizes bot shop ‘Genesis Market’ amid arrests targeting operators, suppliers
krebsonsecurity.com
krebsonsecurity.com
The FBI agent in a hoodie, eating a cookie while hacking into the Matrix is just too good.
I’d bet money that’s what it is now.
Hint: It is above the image data.
"...Hacker culture was born in the US as a counterculture, but that origin only remains in its aesthetics — the rest has been assimilated. At least they can wear a t-shirt, dye their hair blue, use their hacker names, and feel like rebels while they work for the Man."
It's a pretty common trope that a revolutionary (a cultural mindset I think hackers adopt) will sometimes / inevitably need to adopt the tactics of their enemy, but even if that's a truism, you certainly don't need to work for them. You can find your own way, especially in hacking.
Because when you go to the NSA to hack Russia, you have no guarantee you'll actually be assigned that task. They might ask you to first hack the leader of a "potential terrorist organization," then you do so and it turns out it was an activist leader in the Black Lives Matter movement. What are you gonna do, complain to your boss? And, now you're a Fed. Now you can't even turn around and be a whistleblower or whatever because the State knows EVERYTHING about you, background checked you, and can smack you with a legal baseball bat if you act against their interests, slapping you with charges like "sharing state secrets" or whatever else they can dream up about confidential State information and technology.
No thanks. Like others are say, you can't be punk and a fed.
Anyway we're drawing fake lines in the sand here. Even if the PRC and the USA are at war, they're probably doing so at the whims of the real "Man," that being capital interests, corporations and billionaires. By plugging into the USA "side" you're just working for corporate interests in the end.
(These qualities are not entirely unlike the qualities that define e.g. an elite fighter jet pilot. But you can't realistically be an elite fighter jet pilot and an underground punk.)
I think it would be fair to distinguish between the activity of hacking and the spirit of hacking. The author of the quote is pointing out the cognitive dissonance in regards to the spirit.
He claims legacy car companies are bad at security and pay a lot.
But 99% of tennis courts aren't being used for by or for serious tennis-pros.
The joke about it was that closing security holes is never “lame”, and that the American hacking scene consists to a large extent of FBI, NSA or CIA, which explains the award.
To quote Felix von Leitner [1]: “They can say “Ex-“ a hundred times, but you won't get rid of the stench by declaring the termination of your employment.”
it is significantly more subversive to slowly, dilligently and without much attention change existing institutions rather than 'sticking it to the man'. That's the difference between teenager hacktivism and effectively pursuing change. The boring, blue haired kids at gov. institutions are going to run them in 20-30 years.
Obnoxious, loud, visible activism or counter-culture usually just exists to draw attention to itself while generally getting nothing done, and even taking pride in that fact.
And from a loud activist point of view, the slow and steady/sneaky workers are the ones who can do things like bail people out of jail, funnel money and information, etc.
Regardless of how good it feels to express discontent towards the status quo there is a cost to giving society the middle finger.
Phineas Fisher can look down their nose at me, but I got clean money and avoided the drugs and gang culture that took out so many of the associates I had growing up. If working for the man is losing, give me another L.
Job Posting: Seize Art Designer UI/UX
"Let's roll with it!" the boss exclaims.
Complete with a non-proportional/stretched/distorted Canadian flag randomly thrown into the logo soup.[1]
What is that next to the cookie? To the right? Is that a cookie monster with eyes?
edit: lol one of their images is a mecahnical octopus climbing the Great Wall of China
[1] https://www.popularmechanics.com/space/satellites/g2728/best...
This has big "congratulations, local felon, you've won a ticket to the Super Bowl" energy [0]. But if it was enough to fool criminals in 1985, it's probably enough to fool criminals in 2023.
[0] https://www.sportskeeda.com/nfl/what-operation-flagship-how-...
It’s actually entirely reasonable for regular people to contact botnet administrators without any intention of purchasing criminal services. Security researchers sometimes do this when investigating the source of botnet attacks or when tracing machines they deliberately allowed to be infected (honeypots). The FBI may be very interested in getting testimony from these security researchers, even outside the scope of expert witnesses they may select out of the researchers they’re regularly in contact with.
Hah, cops, good faith, pick one.
> There’s nothing illegal about contacting criminals if you have no intention of committing a crime.
The resoundingly consistent legal advice from any lawyer you can find regarding communicating with cops will ALWAYS be: "don't."
I can't fathom why anyone would go out of their way to have a chat with the FBI.
If the FBI needs to talk to you for whatever they're up to, they can find and contact you, and then have a pleasant conversation with your lawyer. If they absolutely need to talk to you, they should only do it after forcing the matter with the subpoena, and your lawyer should be there.
These processes and protections exist for a very good reason.
https://www.lacriminaldefenseattorney.com/never-talk-to-the-...
Plenty of these are spawn out of Discord/Telegram networks to coordinate infrastructure. Via the grey/blackhat versions of Twilio.
It's far too common for the operators to give a shit.
They need to sell to people so the Discord/Telegram and website need to be easy to access.
And Discord/Telegram and websites want it to be easy to make stuff with/on them. The alternative is some vetting process where you submit a form for what the site is for and then someone from an authority logs in and checks manually.
This is not conspiracy, the FBI seriously does shit like this.
Does anyone know how they get this data?
So an extension will seem benign when it initially gets checked by Google as part of becoming part of its submission to the Chrome Store. Then, later, the external “3rd party” script that is hosted remotely will get replaced with a different, malicious script. The malicious extension carries on stealing cookies, credentials, and fingerprints until someone reverse engineers it and reports it to Google.
Google will not always recognize the issue immediately because the 3rd-party malicious code is not strictly “part of” the extension so there’s a bit of a song and dance while the person who reversed it convinces Googles reviewers that “yes, this really is actually malicious, you need to analyze the third party code that loads later” and then Google eventually takes it down after a semi-involved back-and-forth where extensive documentation and video walk-throughs are provided by the exasperated white-hat Good Samaritan.
Do you have any specifics to share ?
I’m guessing the malware is something else besides a browser extension.
let harmless = { func : function() { }, harmlessExternallyLoadedString : '' };
let toAccess = 'func';
//do stuff that seems legit
if(true) {
let toAccess = 'harmlessExternallyLoadedString';
}
harmless[toAccess] = 'alert(1);'; //imagine this being a fetch request
//later on
setTimeout(harmless.func, 1);
now imagine the logic for what othervar is set to is obfuscated a bit by a more complex logic tree, and the example was a bit less contrived.Once they get to like 100k DAU popularity level you’ll start getting emails from people who claim to want to purchase the extension from you for a few thousand or “sponsor” the development by supporting you with ads.
You either sell it, or include some JavaScript that later (few weeks) turns malicious and starts harvesting.
That’s probably how. Like I say, I have no idea if that’s how these people work, but it seems a likely attack vector.
a second way is through chrome extensions that log cookies and form data. the old cookies can be replaced with the new, stolen session via cookie editor
This is why 'strong passwords' will never be good enough when hackers simply control the actual session
Is it ironic that you can pay bitcoins to steal bitcoins?
Talk about whack the mole debugging of the virtual by the real space. It could even come to a "arrangement" with the agents, increasing the number of markets to "bash" over time, so a metric for success exists and grows.
Are these bots using the cookies stored locally by the browsers that the compromised systems user is using?
this kind of access to hacking should be reserved only for the legitimate institutions of civilized society.