Showing posts with label Hacking. Show all posts
Showing posts with label Hacking. Show all posts

Friday, February 7, 2025

I Lost My Device

 Hacking an Account with MFA? Brute Forcing, using MFA Fatigue, Phishing...


The Cyber Show by Dominic Alvieri

by Dominic Alvieri
February 7th, 2025

SS7 probably has something to do with it 

There must be a lot of great hackers nowadays with all the high profile social media account takeovers to start 2025. The NASDAQ stock market, TIME Magazine and Jupiter have all had their X accounts hacked to push crappy fake meme coins. 

Sadly it isn't as difficult as it sounds. 




What is your favorite method?

SMS or Short Message Service based text messages MFA is one of the top MFA methods used. SMS and voice calling have very poor authentication standards due to a technicality called SS7. Signaling System Number 7 or SS7 is a protocol used which in my hackers opinion allows phone numbers to be spoofed and messages to be hijacked.

You can use brute force, use man-in-the-middle or mobile (MiTMO) attacks, phishing, MFA fatigue or just SIM jack user's mobile but one of the easiest is the social engineering method.

The Master Social Engineer

Social engineering doesn't need a degree but it sure helps. One of the most effective and popular methods is to send an MFA code to the suspect and social engineer from there. Among the other easiest ways to bypass an accounts MFA is to socially engineer the security team claiming that you have lost your device...the device that has the MFA method tied to it. Obviously I have to leave a few details out depending on the tied method of authentication.



For the Security Teams Beware of - "I Lost my Device"

Security teams take note because the kids sure are taking advantage of this one. 

Stay safe, online and off.

Saturday, February 1, 2025

Deep Seek and Destroy

 Seek deep and ye shall find


Deep Seek and Destroy

by Dominic Alvieri
February 1st, 2025

Malware, credential phishing, fake meme coins, exposed data...



Build a better mousetrap and the world will beat a path to your door. Deep Seek created a major storm when they came to market mainstream and have drawn unwanted attention ranging from questions about outright intellectual property theft to security vulnerabilities including exposed databases and a rash of bad actors jumping on the DeepSeek bandwagon. 

First a note about authenticity because the documents and all the api call logs (Microsoft) speak for themselves. Some docs 








Deep Seek credential phishing


/deepseeklogin[.]com (left)

This credential phishing site is actually not bad and will get some people to commit. You can easily spot the incorrect url and missing official links.




Show us the malware already


Here is one example from Who said what?  /deepsekk[.]sbs

I do apologize there is a new MD5 I forgot to copy and am unable to find it now or access my own account but is on Virus Total and if memory servers the file is deepseek_v5.35.dmg 





There is no $DEEP or $SEEK meme coins

Crypto scammers jumped on quickly. Toe scam examples are $DEEP and $SEEK.

Enough said

Hacked social media


This DeepSeek R1 account below is a hacked account with 35K followers on X. This isn.t the only hacked or fake account on social media. 




Hundreds of new domains every day


Small sample courtesy of DNPedia. 
The current total of questionable domains registered is now over 2,000 




Other 


Always check the other category. The only official site is /deepseek[.]com

Here are a few other active examples -

/deepseek-ai[.]com
/deepseek[.]ai
/deepseek[.]org
/deepseek[.]cyou
/deepseeklogin[.]com

Please avoid any of these sites. Personally I am not a fan of DeepSeek. Logging keystrokes.

Enough said again. Stay safe online and off. 

Wednesday, December 25, 2024

How to Hack a Drone

Annoying drones invading your private property?


How to Hack a Drone


By Dominic Alvieri
December 25th, 2024

Hacking is Illegal and for Nerds

Stopping a common drone is easier than you think.

Hacking drones is not new. We're not firing up Kali and taking over a drone for an offensive campaign but merely expressing the defensive capabilities available to take down an illegal drone illegally invading your private property. You will be surprised by how easy it actually is.

I have always believed that anything that communicates from a point to another point can be intercepted or hacked. Drones are no different. It's been a few years since I have compromised a drone so this refresher was inspired from the recent panic of drone sightings in New Jersey.

In simplest terms most drones need to use Wi-Fi to communicate with and receive commands from the operator via the controller...so don't forget to log the MAC addresses.


nist.gov


Defensive Techniques 


The basic ways to defend against a drone offensive is to take control of the drone, shoot down, destroy or otherwise capture and stop the drone physically, disable drone communications and force a "Go Home" landing or otherwise disable the drone itself to force a landing.

Check the laws in your state or country


Drones over about a half of a pound must be registered in the United States and generally must be flown lower than 400 feet and controlled within your eye sight.


FAA

Dependency Confusion, if you will


Since most people don't have access to a high powered device to emit an electromagnetic pulse and wouldn't want to risk shooting a drone down most lean towards another path. 

I like to call it creating a dependency confusion. Dependency confusion can have multiple definitions and also be known as a substitution attack which is an attack path that creates and registers malicious packages publicly to mimic and fool users of privately coded packages. This is also called namespacing.

Roughly speaking most spoofings are also a form of dependency confusion. You would fool a device or service to connect to and receive commands form an apparent authorized device which you control.






GPS Frequencies


Detecting a drone using radio frequency sensors is quite easy if you were so inclined. By detecting the exact frequency you can obtain the serial number and MAC address of the drone and target it directly but you shouldn't have to get that granular. You would start with a radio frequency jammer.  

Generally speaking certain frequency bands will have more common household devices using it so this method will create unintended interference so check your local laws.

Drone frequency bands vary and include 433 and 915 MHz, 1.2 & 1.3GHz, 2.4 GHz and 5.8GHz.




Radio Frequency Analysers, Spoofers and Jammers


The goal is this simple hack to mask the signal between the drone and the controller and either force it into "Go Home" mode and either go to the pre programmed home location and fly away or land or crash where it currently is. 

Once again drones that use Wi-Fi communicate between the onboard unit and the controller and can have advanced RF Analysers detect their communication and even their MAC addresses but they are not commercially available. RF Spoofers and difficult to find and legally in the gray area. 

The simplest way is to jam the signal and confuse the drone. If that fails we can always open up Kali and get more granular in detail for another attack. Certain details have been left out for safety.

Stay safe, online and off.






Wednesday, July 3, 2024

Are You Trollin Me?

 Did Black Suit Ransomware just try to troll me?


Black Spade.

by Dominic Alvieri
July 3rd, 2024


The story goes a little something like this...


/Conti_Royal_BlackSuit/
                       |_BlackSpade/


That random mixed letter and numbered social media account chimes in. To make a long story short several people both known and unknown to me recently mentioned the same thing, "...a guy from Black Suit started his own group and is responsible for a major incident. The group is called Black Spade."

Who is Black Spade?




The Royal (Ransomware) Flush


Black Spade would be the continuation of the group formed by a Conti member who created Royal Ransomware then rebranded to Black Suit then either is planning on spinning off or rebranding to this new alleged Black Spade group.

Black Suit was attributed to the recent damaging CDK cyber incident. A  CDK spokesperson originally said "it will take months to fully restore our network" and now they will be up and running by July 4th. Now that the incident appears over I think it is important to bring this to light. Bad actors with or without ransomware in general will lie, cheat and steal to get the money they feel entitled to. They will even try to bribe or fool a researcher, reporter or analyst into making false statements during a ransom negotiation to influence the outcome. Millions of dollars are at stake. 

Is there a Black Spade? The Major Plot Twist


I really had the feeling I was being trolled. A pro level troll. Royal payback if you will. Contacted during a major incident with a major plot twist in the middle of alleged negotiations. I have never heard of such a thing. It is also rare for a group to willingly give their new spinoff and or rebrand name out beforehand. It defeats the purpose.

So is there a Black Spade? Not yet. The new Black Spade claims came somewhere a day or two before CDK's sudden positive change towards the cybersecurity incident. Once again CDK was never posted by Black Suit and they should be fully operational by Independence Day, July 4th which is tomorrow.

Once again two individuals mentioned the same name on the same day with bold new claims. The new group called "Black Spade" was a former/current Black Suit with a major victim. I asked for something concrete, an IoC, a new strain or anything that could back the claim. You just have to produce a ransom note, a data sample, post it or some evidence with a claim like that.




I had a feeling I was communicating with Royal who is still probably a little sore at me from the old Twitter days when Royal was online known as @LockerRoyal before being suspended.

I need some proof of compromise, a ransom note or something 


For those of you that do not follow threat actors as closely as I do here is a little back drop. Black Suit recently posted a record (for them) in posting 9 new victims in a day and another leaked school district that was originally posted before as their 10th post for the day. Black Suit hasn't ever posted 10 victims in a week or that frequently on a monthly basis. It did look like Black Suit was cleaning house and possibly preparing to rebrand and or exit. 

Skeptical I mentioned to both security researcher and I presume now to be the threat actor that I would put a feeler post out in a few hours mentioning the new threat group but I needed something solid to go forward with anything more. It's not a new ransomware group without a new strain so it isn't Black Spade Ransomware and it sounded somewhat feasible and a possible threat. 



My post above


Careful not to create a major stir I toned down the threat eliminating the possibility that this new group was a LockBit or AlphV BlackCat rebrand just in case it was used for leverage with potential victims during a ransom negotiation. The timestamp is underlined.

Their post roughly an hour later...


Roughly an hour after my post Black Suit posted Kadokawa. Kadokawa was the 11th post and 10th new victim for Black Suit within 2 days which is a first. The Black Suit post rate is well below that number.



The Ransomware News bot from VX Underground post with timestamp underlined.

The Black Suit Kadokawa post



It may have just been a wild coincidence with the poker reference but it didn't feel like it.

The Ace of Spades


...we prefer not to show all the aces we have prepared within the sleeve." 


No points for the poor Russian to English translation above but I did catch the reference. It may have been nothing, probably just another cybersecurity coincidence. 





"...we are only interested in money.' - Black Suit Ransomware


The Ugly Side of Cyber - Negotiations


CDK has never been posted by Black Suit or any other group to date. The original ransom request was believed to be $10 million with online rumors ballooning it to as high as $80 million. The truth is probably somewhere in between and closer to the lower figure. Ransomware groups and threat actors routinely ask for way more than they are willing to settle for. They over inflate their claims and use whatever other means are needed.

Just like that one of the two deleted their account and the next day fortunes turned for the encrypted.

CDK should be back fully operational by the time you read this. Once again CDK was never posted by Black Suit but confirmed the cyber incident and actor as being Black Suit. Kadokawa was leaked by Black Suit.

Is Black Spade for real? Is Black Spade coming? I'm not sure but if that name does come up make sure to do your due diligence.

Stay safe online and off.



Dominic Alvieri
@AlvieriD

Wednesday, January 17, 2024

Where Are They Now?

 The Conti Boys


By Dominic Alvieri
1/14/2024


Where Are They Now?


Ransomware groups have come and gone but few have continued to resonate across the criminal ransomware spectrum as the former members of Conti Ransomware. We all know the pipeline hacking name so let's cut to the chase.

Where are members of Conti? Start with the list below.

The list below does not include leaked source code offshoots like Monti or any others. All of the following groups can be attributed to former Conti. 

In alphabetical order:

Akira Ransomware, Black Basta, Black Byte, Black Suit (Royal Ransomware),  Karakurt Team, Three AM



Royal on the run.

Royal on The Run


Royal Ransomware was arguably on the run after their attack on the City of Dallas, Texas and has rebranded as Black Suit. Royal Black Suit of you like. Black Suit is active again.



Karakurt on an extended vacation.


100 Days Without Fam


By all accounts Karakurt has been inactive for over 100 days now. No posts. No attacks. No nothing.

So what happened? No speculations please.



Karakurt Team in high level discussions.






Black Byte Bitten


The Black Byte leak site was only active for a few hours over the past 2 months only producing a black and white logo change. That's it. I don't expect Black Byte to rebrand. Time will tell as it always does.




Akira Ransomware


Akira Akira. Not my favorite. Why don't we call him angry Conti. Angry Conti has set up his own thing including a cool retro site. Just a reminder that this cool retro site is trying to peg your system and steal your credentials as you browse their leak site. Phish your visitors. Great evil business model.




Black Basta


If there was ever a racist Conti this is it. More hateful. Targeted. The question is whether for Black Basta to retool or rebrand after the "Basta Busta" released. LockBit proved that you can continue without rebranding. Black Cat ransomware is also challenging what you would think to be the norm.





Black Basta was named by one of the most racist white guys ever. 





There are arguments to be made to include a few other names and strains. I fell like I missed a name or two. 

Don't mount a locker or hack illegally.



The Cyber Show.


Dominic Alvieri X- @AlvieriD
The Cyber Show

Sunday, August 13, 2023

Ransomware Groups May Soon Get Their Hands on Your Fingerprints.

You have to give us your fingerprint


By Dominic Alvieri
Aug. 13th, 2023



Give me your fingerprint or you are fired.


"You have no choice, the company is switching over."


Imagine being forced to give your biometric fingerprint away to third party. Now imagine your employer mandating this and you having no choice in the matter? Well imagine no more.

Meet the Kronos Biometric fingerprint time clock. Can you guarantee that my biometrics are safe. Where is the security answer please? 

I am so opposed to this and I can't do a thing about it. Being forced does not constitute consent.

For the record I object again. 




Which finger?


 Point in fact Kronos settled a lawsuit in 2022 stemming from their data breach in 2021.

Millions of workers are being forced to hand over their fingerprints. There is no consent. You are required to abide by company rules and companies are switching over to fingerprint readers because Kronos is switching over to biometric time clocks. 

Period. You have no choice. Once again I am so against this.






Fairly soon ransomware groups may be able to get their hands on your fingerprints.

I cannot state this point any clearer, you have NO choice except to clock in with your finger. 

I am strongly opposed to the forceful relinquishment of and collection of biometric data

Stay safe.





Dominic Alvieri

@AlvieriD

The Cyber Show 

Wednesday, May 31, 2023

Cracking the Connected Floor

Analytics and Cybersecurity 


By Dominic Alvieri
May 23rd, 2023



This KPI Isn't Pointing in the Right Direction

Fortune 500 companies are expanding their attack surfaces in a new data analytics push.

Cybersecurity takes a back seat for data analytics in a manufacturing executives dream which is turning out to be a security nightmare. It's called the connected shop floor and in this current version isn't going to end well. Corporate executives are unintentionally and unnecessarily exposing themselves to unnecessary risks. 

"This is largely driven by connecting machines using IoT and enabling Ai to digitize the results"

Apple iPads and Microsoft Bi along with several outsourced apps and technologies are involved.




100's of new endpoints and unrestricted devices 


All employees who have access to these new IoT devices running the backbone of this technological shop floor had open browser access and email capabilities. Personal emails as well as corporate and a host of new apps and software.

Oops, an employee just clicked on one of their personal emails and got phished.

Before drilling deeper into the technologies and possible exploits available for a starter there are hundreds of new IoT devices with an unrestricted browser able to view porn, YouTube or TikTok videos. A small time phisherman with a low grade infostealer may unknowingly get access to a Fortune 500 company employee and not even know it. 





The good news

Executives are starting to learn about cybersecurity. The bad news? They are slow and stubborn.

Here is a no brainer-restricting employee browser access.



App Avalanche


Once again executives are slow in embracing cybersecurity. They need the numbers to crunch to squeeze every last ounce of shareholder value that you can. Security often takes a back seat.

"Cybersecurity does not add revenue" one executive told me on the condition of anonymity. 






Exploitable


Querying one of the apps being used in one version of the connected floor returned an interesting response resulting in an error in my SQL syntax. Input sanitation issues are red flags indicating injection flaw exploits. 

Obviously I am unable to mention the firm or app until the issue is resolved. 

There are other exploitable alleys in this project.


The Deeper I Drill...

I have not received  any responses to my questions regarding the above mentioned security issues along with an uncovered topic. 


I am offensive in nature even in a defensive posture.
...

There are more holes in the floor.




Sunday, April 23, 2023

Top 10 All Time Active Ransomware Groups

 The Current Top 10 Active Ransomware Group Post Count


By Dominic Alvieri

April 23rd, 2023

@AlvieriD


Top 10 All Time Active Ransomware Groups


Quantifying ransomware group activity over the past few years there is no doubt that LockBit is the numerical leader all credibility issues aside. LockBit averages posting over one company per day since their initial formation as ABCD. No one else comes close. 


Conti members are still around but this list comprises of active groups with quantifiable active leak sites.


The top 10 active ransomware groups.

@AlvieriD


Posts that are somewhat quantifiable...


What is included in the numbers? Posts like the recent LockBit Dark Trace-Dark Tracer fiasco or their goofball post that was removed are not included. Neither are posts like the BlackCat NCR flash cyber incident that is still ongoing. 






Up and Coming Groups


The top groups to watch gaining traction are Royal and Play Ransomware. Play will be in the top 10 within the next month if current trends continue. Royal should be in the top 5 by summer.




New groups in 2023


Several new groups have arrived and in the case of Trigona, re-arrived. Money Message sans logo or not should be near the top of the new groups to watch list. Here are a few other new groups to watch:

Money Message
Trigona Ransomware
Cipher Locker
Akira Ransomware
Cross Lock Ransomware
Dunghill Leak...


Trigona Ransomware.


Cipher Locker ransomware.

Akira Ransomware.

Cross Lock Ransomware.


Dunghill.

Dunghill Leak is literally named after a pile of shit. What will they think of next.

Most Dangerous Groups


In my view Alphv BlackCat Ransomware and LockBit are fairly close in the top of this category. BlackCat has the ability to pivot quickly once in a network and LockBit is always trying to improve to stay on top but they have been getting sloppy while Alphv looks like it added another producing affiliate.

Black Basta, BlackByte, Royal and Play Ransomware deserve mention here as do a few others but my time is limited.


Stay safe.

The Cyber Show, by @AlvieriD


The Kremlin, Politics and Ransomware

Qilin Ransomware caught with politically motivated fake document (and old data) in post. by Dominic Alvieri March 8th, 2025 @AlvieriD Was it...