Showing posts with label CNBC. Show all posts
Showing posts with label CNBC. Show all posts

Sunday, April 23, 2023

Top 10 All Time Active Ransomware Groups

 The Current Top 10 Active Ransomware Group Post Count


By Dominic Alvieri

April 23rd, 2023

@AlvieriD


Top 10 All Time Active Ransomware Groups


Quantifying ransomware group activity over the past few years there is no doubt that LockBit is the numerical leader all credibility issues aside. LockBit averages posting over one company per day since their initial formation as ABCD. No one else comes close. 


Conti members are still around but this list comprises of active groups with quantifiable active leak sites.


The top 10 active ransomware groups.

@AlvieriD


Posts that are somewhat quantifiable...


What is included in the numbers? Posts like the recent LockBit Dark Trace-Dark Tracer fiasco or their goofball post that was removed are not included. Neither are posts like the BlackCat NCR flash cyber incident that is still ongoing. 






Up and Coming Groups


The top groups to watch gaining traction are Royal and Play Ransomware. Play will be in the top 10 within the next month if current trends continue. Royal should be in the top 5 by summer.




New groups in 2023


Several new groups have arrived and in the case of Trigona, re-arrived. Money Message sans logo or not should be near the top of the new groups to watch list. Here are a few other new groups to watch:

Money Message
Trigona Ransomware
Cipher Locker
Akira Ransomware
Cross Lock Ransomware
Dunghill Leak...


Trigona Ransomware.


Cipher Locker ransomware.

Akira Ransomware.

Cross Lock Ransomware.


Dunghill.

Dunghill Leak is literally named after a pile of shit. What will they think of next.

Most Dangerous Groups


In my view Alphv BlackCat Ransomware and LockBit are fairly close in the top of this category. BlackCat has the ability to pivot quickly once in a network and LockBit is always trying to improve to stay on top but they have been getting sloppy while Alphv looks like it added another producing affiliate.

Black Basta, BlackByte, Royal and Play Ransomware deserve mention here as do a few others but my time is limited.


Stay safe.

The Cyber Show, by @AlvieriD


Thursday, October 13, 2022

New Chinese Misinformation Campaign

Fake Campaign Attempts to Attribute Chinese Advanced Persistent Threat Group APT 41 to the NSA


By Dominic Alvieri 

@AlvieriD

October 12th, 2022


New Chinese misinformation campaign


A new Chinese misinformation campaign has been spreading this past week attempting to attribute the Chinese APT 41 to the National Security Agency. Many are using the Intrusion Truth name. 


Global Times Chinese domain article tweet.





Several new accounts tweeted in Chinese Mandarin for the local media in Asia while others have been created in English for a wider audience. All accounts use the APT 41 hashtag. 


Kimberly Allen Fake FireEye Attribution in Mandarin





The above tweet translates to FireEye attributing Chinese APT 41 to the NSA.


The tweet above has been removed but the account remains.





The FBI reports concludes what we all know while some are trying to create confusion in typical APT 41 style.



Dominic Alvieri, @AlvieriD Twitter

This is a new and current campaign with all accounts still currently open. No new activity has been spotted since the initial report this week with fake attribution tweets.


Blog will be updated as needed. Stay safe.





Thursday, September 1, 2022

Is This Email Phishing You Off?

How to Immediately Tell if This Email is from MetaMask or Phishing You

By Dominic Alvieri @AlvieriD

August 31st, 2022


MetaMask phishing attempt.

Is this a phishing attempt?

Yes.

Here is how to find out immediately. 

Most people don't remember but MetaMask did not collect your email when you created your account. MetaMask does not send emails. If you receive an email from "MetaMask" it is a phishing attempt.

The cover photo is from a current phishing campaign using a sense of urgency and fear of terminated access.

This phishing attempt obviously did not come from MetaMask. Official support @MetaMaskSupport Twitter

New redirected verification landing page and QR code linking to the phish.





This fake MetaMask email has a convoluted journey with websites hosted in Denmark and redirected to China with an Alibaba registered domain hosting the actual phish. I will post an update to this blog post or my Twitter when I close this file as the campaign is still active and a new dated email circulating.

Not another QR code...


MetaMask QR code phishing.



Remember MetaMask Does Not Send You Emails


What if this tip doesn't work with others?


This sounds easy enough and it is, whenever a question arises about whether an account has been hacked, suspended or restricted in any way is to go directly to the account in question, not through any courtesy link, notice or email.






Friday, July 22, 2022

Unhappy Anniversary

The United States Federal Minimum Wage is frozen in time


by
Dominic Alvieri
July 22nd, 2022

Twitter @AlvieriD


Unhappy Anniversary


Why are we leaving everyone behind?


There is absolutely no excuse for the United States federal minimum wage to be frozen in time since 2009.

Year after year there is no change just like a broken clock. Even after this last slide stocks are still up quite nicely since 2009. Athlete and executive salaries, housing prices...and now inflation are soaring.

Arizona Cardinals star quarterback Kyler Murray just signed a 5 year $230 million dollar contract and once again the federal minimum wage has not changed since 2009.



Last minimum wage change was in 2009.


The US Department of Labor documents the history of changes to the Minimum Wage Law. They have not been documenting much over the last decade plus.

What is going on?


What has the US Department of Labor been doing? In a word-NOTHING.

It is in corporate America's best interest to keep wages low. 

Workers wanted more money but yadda, yadda, yadda the lobbyists took care of it. 


Most jobs in one way or another are based off of the minimum wage. Any US State wishing to go above that rate may do so but it is against the law to go below that federal minimum level.

There are several different categories of jobs including skilled jobs, professional, hourly etc. This isn't a deep dive or a skewed data driven bs info blog. Just a blog about a physical real world problem.

Pre-pandemic the hospitality industry was one of the industries in the United States that made up a majority of the job growth over the previous 10 year period according to several archived analyst articles on CNBC. 

During this time restauranteurs, franchisers, coffee houses and the like sprung up on nearly every corner during the expansion. Think Dunkin Donuts, Starbucks, Subway etc. not to mention the casual Texas Roadhouse or TGIFs down the strip. Don't forget about Shake Shack. 




sad but true...

Firms are still lobbying hard for the government not to raise wages for those who need it most.

It is pretty sad that corporations pay lobbyists to keep wages down. 

In a nutshell corporate America pays lobbyists mostly congregated on a few block stretch of K Street in Washington DC not far from the Capitol. It is in their best interest to keep wages low. Year after year corporate and franchised locations continue to mushroom while the starting minimum wage remained the same.

Lobbying.






The major problem is corporate and entrepreneurial America got greedy and didn't raise many minimum basic rates during the expansion and then the pandemic hit. Now the inflationary decline is upon us and staffs are being cut are employers are now unable to raise rates. Although some states did raise minimum wages many did not. Wages overall did show gains but paled in comparison to the overall growth of the upper income brackets.

Without posting more mind numbing data suffice it to say the federal minimum needs to rise dramatically and rise today.

Otherwise we really are leaving everyone else behind.


Dominic Alvieri 

Monday, May 30, 2022

NRA I Don't Need an AR-15 to Hunt a Duck But I Need a Raise

What do the NRA and the NRA stand for?


By Dominic Alvieri


May 29th, 2022



The National Rifle Association


The National Rifle Association held their annual convention in Houston Texas this week days after the mass shooting in Uvalde, Texas. Texas senator Ted Cruz made a speech last night blaming everything but the truth on the increase in the amount of mass shootings in our country. Cruz blamed violent video games which have been proven not to be the root cause and thoroughly written about.

I hate politics.

The NRA board of directors just re-elected longtime head Wayne LaPierre even amid scandals which says a lot about the group at the moment.





I am a firm believer in the right to keep and bear arms but a person does not need an AR-15 to hunt a duck or a deer. 

***Nearly every single mass shooting in the United States from Columbine to Uvalde has been carried out with an AR-15***

It is time for command and control. WE have the right to keep and bear arms and to be protected. Guns don't kill without being in control of the wrong person.

Not only were the speakers unshaken but they were heartless.




What does the NRA lobby? How much do they spend? Who contributes?

Good questions. Many sites have data readily available and in this case used from /opensecrets.org



2021 data was not available




For arguments sake lets say this dataset is a correct representation. A majority of spending is in the classic general "outside spending' category. What does that entail? This outside spending funds an entity called the Victory Fund which is a special purpose vehicle tied closely to the National Rifle Association.

Who donates to the NRA? Readily available information with the usual suspects like the gun makers themselves that I will not go over here but was an informative journey and a deeper dive is required. 

What does the group lobby? This is a small sample with viewpoints and political comments aside.




In 13 years the NRA has not budged on gun control.

S-3 was recently hired by the NRA





Americans will never give up their right to bear arms but we have past the point for gun control. In most states you can buy a gun at the age of 18 but have to wait until you are 21 to drink. 

Let that thought marinate for a moment.

There are many groups that are intent on keeping loose gun regulation and control. How many more innocent people have to die before we recognize the need for some control. 

 

The National Restaurant Association


This NRA represents the second largest private sector employer in the United States. 




In 13 years the National Restaurant Association has lobbied against raising the minimum wage in every instance. Contributors include the usual large corporate chain restaurants from Darden and new economy firms like DoorDash who contribute and lobby to keep wages down.

But how low?

The servers who serve you food and beverages have not had a raise in 13 years. In the state of Pennsylvania a server makes $2.83 per hour. In 35 years the pay rate for a server in Pennsylvania has only gone from $2.01 to $2.83 an hour. That is not a typo.

How can this be?


The largest growth industry pre-pandemic was the food and beverage sector which needed and still needs low wages to not only get back to previous levels but to continue to grow. Growth at the expense of a young and uneducated revolving door work force except for those for whom it is their profession.

Server wages are based off of a percentage of the Federal minimum wage subsidized by the employer to that Federal minimum, currently $7.25 an hour if tips are not made above that minimum hourly level.











Coca-Cola, McDonald's, DoorDash all donating to lobby and lobbyists to keep the minimum wage down. It is in their best interest to keep wage costs down and margins up. Business 101.

What about the people. We the people?






I will spare you the complete list but it is fair to say there a a lot of people who have a keen interest in keeping the Federal minimum wage down.


Both the NRA and the other NRA, the National Restaurant Association receive substantial amounts of money from groups intent on keeping the status quo, but for how much longer?




In 13 years the National Rifle Association has done nothing to control AR-15s which have been used in every mass school shooting.

In 13 years the National Restaurant Association has lobbied against raising the minimum wage every time.

Who do these groups work for? That was a rhetorical question.

Stay safe.


Tuesday, April 12, 2022

A Week with Lapsus$

Conversations with Americas Most Wanted


By Dominic Alvieri


April 11th, 2022



The Cyber Show Catch Me if You Can.


What it's like

 
So what is it like to speak with someone so wanted and hated by so many? The answer may surprise you. Brash, confident and way more intelligent than people are willing to give to the remainder of the Lapsus$ group credit for. 

What is his name? I didn't ask and frankly don't care. Chances are it would be another farce. 

Where is he? I didn't ask again and don't care.

Where are the remaining members now? I again didn't ask and again don't care. That is not my job to breach Telegram and other companies and to find answers. 

This is an account from the past week with Lapsus. I am not part of Lapsus$.

Recent photo profile updates





Tagged on Twitter










That warm and cozy feeling. 


What did you talk about? None of your business. Just kidding. We did share a few laughs. Speaking of how influential a photo is in reference to text we laughed as he changed profile photos live. We are all visual creatures. We also all fall into patterns. Pattern analysis transfers well.

We spoke about women ( don't judge ) surprisingly not guns, a little tech and the minefield that has been unearthed around him. Eager to save what was a short lived legend in Lapsus$ it would come as no surprise to anyone that this is the current attempt at just that, reviving Lapsus$.






It was very interesting. There have been may articles and blogs written about the group and I am not going to be redundant but giving a brief synopsis of the past week chatting with the famed "Mox" of the prematurely pronounced dead Lapsus$ hacking and extortion group. 

In and out. Constant change, searching, contacts. Fast.

Lapsus$ is still alive albeit a like a racing team without a car or driver but it has a good pit crew. They are looking to change that. 

As several researchers have pointed out and has been confirmed there are several members of the group still active as is evident here. Actively searching to retain former glory. 

Right now it is no secret that the group is under diminished capacity. That can change at any moment.







Girls, guns, cars, companies... we didn't actually speak about guns but I'm sure that would have been interesting as well. 

Good bye Mox

To be continued fortunately by someone else. I'm exhausted.






Dominic Alvieri

Twitter @AlvieriD

Tuesday, February 22, 2022

Banking and Crypto Stealing 2FA Bots on Telegram

Telegram Channels are Behind Evil New Ways to Separate You From Your Money


By Dominic Alvieri


2-22-2022



Telegram has had a history of security breaches, bad actors and security issues for several years. More and more malicious actors are using the platform along with 300 million others. Recent examples during the Russian invasion of Ukraine are showing an accelerating trend of cyber activities on the platform including the SberBank breach disclosed below.


SberBank breach files.

Other recent troubling requests




The Telegram mobile protocol MTProto protocol is proprietary and has had security questions for years. Cryptographic issues aside the desktop version does not use the protocol and storers all data in plain text. Plain text is also an issue with the mobile virtual cloud set up. 

In simplistic terms all data is stored on Telegram servers and not end to end encrypted (e2ee) by default. There is a secret chat option that does but that is another story. No e2ee by default leaves millions at risk from an advanced attacker. 

The current state of the gram


Underground forums and marketplaces are nothing new for a bad actor looking to score some low grade malware, stolen credit cards or a phishing kit. No need to fire up the TOR browser now because these items are becoming more mainstream available on the web and malicious Telegram channels.

OTP 2FA password stealing bots are being packaged with hand selected robocall features like foreign language accents to target customers of specific countries. Two if these bot services have been verified as working account stealing bots and recent reports of usage and abuse has been reported.

New set language feature   /setlang   



Set language /setlang


Bank of America, Chase and Wells Fargo are among the banks that these bots works with stealing your one time password or 2FA login. Several cryptocurrency platforms are also being marketed with automated bots and classes.





Several channels are selling various One Time Password (OTP) and 2FA stealing bots. Having verified two of the products here is a breakdown of some of the malicious capabilities.

Packages are readily available for Apple Pay, banks, crypto....



OTP 2FA Password stealing bots


Vendor P above has been active in advancing the bots attack capabilities in the past week adding Bank of America and Chase to their hackable list. Security support teams at Bank of America, Chase and Telegram have been notified. 




Here is what the bot can do. The ability to go after anyone with just the minimum information that would be needed to carry out this attack is worrisome. Basic OSINT research. 

As simple and annoying as this scam is the technology behind the maliciousness does work.

Enter target data, select a few options and assets to acquire and the nightmare scenario begins. Like most malicious activities they do require at least one action from the target, barring a zero-day, zero click exploit.

Video snapshot of working bot in action





Robocalls blanket the target with messages of an account breach and that verification is needed. An extreme sense of urgency is created and conveyed in the robocall accent of your choice. The artificially curated voices of the bot repeatedly mention your account is at risk and require you to verify your account via an OTP or your 2FA verification.

Partially redacted for security.

Everything is the same as before...





We have come along way from just unlocking iPhones.



What else can this bot do?


New functions which have just been posted and untested include bypassing:
-Authy
-Google Authenticator
-Microsoft Authenticator

Several variations of the original bot are online and to no surprise many claims are stretched and many are just outright frauds.






Relentless requests are the first step and if entered, the near-instant theft takes place. When a verification code is entered the bot executes the code, enters the account and transfers all of the cash or cryptocurrencies out of the account within minutes. In this live research example a crypto account was used and emptied within 2 minutes of the final string of data obtained by the bot. Crypto firm name withheld. 

Several other options are available if the first level attempt via robocalls fail to capture the required codes. These are actual working multifaceted bots able to spear or whale nearly anyone.

What can you do? DO NOT INTERACT

Do not interact with any SMS, email, link or call regarding your breached accounts. Always go directly to your real account through and official site or representative.

Go directly to any account in question and the official site and or contacts and avoid any "urgent need" to give your information to anyone. Chances are you haven't been hacked but someone sure is trying.



The Cyber Show
by Dominic Alvieri

Twitter @AlvieriD

The Kremlin, Politics and Ransomware

Qilin Ransomware caught with politically motivated fake document (and old data) in post. by Dominic Alvieri March 8th, 2025 @AlvieriD Was it...