Showing posts with label LockBit. Show all posts
Showing posts with label LockBit. Show all posts

Wednesday, July 3, 2024

Are You Trollin Me?

 Did Black Suit Ransomware just try to troll me?


Black Spade.

by Dominic Alvieri
July 3rd, 2024


The story goes a little something like this...


/Conti_Royal_BlackSuit/
                       |_BlackSpade/


That random mixed letter and numbered social media account chimes in. To make a long story short several people both known and unknown to me recently mentioned the same thing, "...a guy from Black Suit started his own group and is responsible for a major incident. The group is called Black Spade."

Who is Black Spade?




The Royal (Ransomware) Flush


Black Spade would be the continuation of the group formed by a Conti member who created Royal Ransomware then rebranded to Black Suit then either is planning on spinning off or rebranding to this new alleged Black Spade group.

Black Suit was attributed to the recent damaging CDK cyber incident. A  CDK spokesperson originally said "it will take months to fully restore our network" and now they will be up and running by July 4th. Now that the incident appears over I think it is important to bring this to light. Bad actors with or without ransomware in general will lie, cheat and steal to get the money they feel entitled to. They will even try to bribe or fool a researcher, reporter or analyst into making false statements during a ransom negotiation to influence the outcome. Millions of dollars are at stake. 

Is there a Black Spade? The Major Plot Twist


I really had the feeling I was being trolled. A pro level troll. Royal payback if you will. Contacted during a major incident with a major plot twist in the middle of alleged negotiations. I have never heard of such a thing. It is also rare for a group to willingly give their new spinoff and or rebrand name out beforehand. It defeats the purpose.

So is there a Black Spade? Not yet. The new Black Spade claims came somewhere a day or two before CDK's sudden positive change towards the cybersecurity incident. Once again CDK was never posted by Black Suit and they should be fully operational by Independence Day, July 4th which is tomorrow.

Once again two individuals mentioned the same name on the same day with bold new claims. The new group called "Black Spade" was a former/current Black Suit with a major victim. I asked for something concrete, an IoC, a new strain or anything that could back the claim. You just have to produce a ransom note, a data sample, post it or some evidence with a claim like that.




I had a feeling I was communicating with Royal who is still probably a little sore at me from the old Twitter days when Royal was online known as @LockerRoyal before being suspended.

I need some proof of compromise, a ransom note or something 


For those of you that do not follow threat actors as closely as I do here is a little back drop. Black Suit recently posted a record (for them) in posting 9 new victims in a day and another leaked school district that was originally posted before as their 10th post for the day. Black Suit hasn't ever posted 10 victims in a week or that frequently on a monthly basis. It did look like Black Suit was cleaning house and possibly preparing to rebrand and or exit. 

Skeptical I mentioned to both security researcher and I presume now to be the threat actor that I would put a feeler post out in a few hours mentioning the new threat group but I needed something solid to go forward with anything more. It's not a new ransomware group without a new strain so it isn't Black Spade Ransomware and it sounded somewhat feasible and a possible threat. 



My post above


Careful not to create a major stir I toned down the threat eliminating the possibility that this new group was a LockBit or AlphV BlackCat rebrand just in case it was used for leverage with potential victims during a ransom negotiation. The timestamp is underlined.

Their post roughly an hour later...


Roughly an hour after my post Black Suit posted Kadokawa. Kadokawa was the 11th post and 10th new victim for Black Suit within 2 days which is a first. The Black Suit post rate is well below that number.



The Ransomware News bot from VX Underground post with timestamp underlined.

The Black Suit Kadokawa post



It may have just been a wild coincidence with the poker reference but it didn't feel like it.

The Ace of Spades


...we prefer not to show all the aces we have prepared within the sleeve." 


No points for the poor Russian to English translation above but I did catch the reference. It may have been nothing, probably just another cybersecurity coincidence. 





"...we are only interested in money.' - Black Suit Ransomware


The Ugly Side of Cyber - Negotiations


CDK has never been posted by Black Suit or any other group to date. The original ransom request was believed to be $10 million with online rumors ballooning it to as high as $80 million. The truth is probably somewhere in between and closer to the lower figure. Ransomware groups and threat actors routinely ask for way more than they are willing to settle for. They over inflate their claims and use whatever other means are needed.

Just like that one of the two deleted their account and the next day fortunes turned for the encrypted.

CDK should be back fully operational by the time you read this. Once again CDK was never posted by Black Suit but confirmed the cyber incident and actor as being Black Suit. Kadokawa was leaked by Black Suit.

Is Black Spade for real? Is Black Spade coming? I'm not sure but if that name does come up make sure to do your due diligence.

Stay safe online and off.



Dominic Alvieri
@AlvieriD

Monday, February 19, 2024

The Part Timers

The Part Time Ransomware Groups.


by Dominic Alvieri
February 18th, 2024



It seems like everyone is attacking critical infrastructure these days. There are several nation states and 12 current active ransomware groups that have attacked critical infrastructure around the world. Here are 7 of the 12 active ransomware groups:

ALPHV BlackCat
Black Basta
Hunters International
LockBit
Play Ransomware
RansomHouse
Rhysida Ransomware

Can you name any of the other 5?

Remember the dentist/part time ransomware operator?


There may be another dentist deploying ransomware. Or maybe even a slick lawyer. The rash of bad actors attacking critical infrastructure has to be dealt with immediately. 

Who are these part time ransomware operators and why we should make examples out of them? Tracking several of these groups and I can safely say it wouldn't take long to take down at least 2 of the 5 groups I mention below. I predict that at least one of the groups listed below should be comfortably viewing life behind some cold steel bars sometime this year. 

Attacking critical infrastructure should be heavily penalized and actors jailed for so long that it should never cross the pea brain of any ransomware idiot. 

What is a part time operator?


A part time ransomware operator attacks and posts fewer than about 8 victims per month by my definition and for the purposes of this analysis and article. The part time operator more than likely has another job and or profession in addition to breaching companies. 

Cuba Ransomware would be a perfect example but exempt from this discussion due to their backing which is fairly safe to say it stems from the Russian Government and has nothing at all to do with Cuba.




Who are the part time ransomware operators?


Qilin Ransomware

Infrastructure breached - Electric utility


Qilin started quietly on the ransomware seen in 2023 but has ramped up and is set to graduate to a full time operator. Business is good for Qilin who breached and evidentially negotiated with Electric Power of Serbia posting and removing the utility serval times before finally leaking them.

Qilin appears to have quit his day job and about to deploy ransomware full time. 17 posts year to date thru 6 weeks of 2024. 


Qilin Ransomware.





Lorenz

Infrastructure breached - Hospital




Strictly business includes critical infrastructure.

Lorenz is a classic part time operator. A dentist? Probably not. Lorenz has more technical skills than some of the other part timers. I could write a whole other article about Lorenz but let me just say for the purposes of this topic that Lorenz has also breached critical infrastructure in Cogdell Memorial Hospital.

Daixin Team


Infrastructure breached - Hospitals, health networks & water districts


Daixin is the worst of the part timers. Daixin is not a dentist, not by far. I would define the group as the state sponsored nasty version of Cuba. I say this with a moderate degree of certainty from some of their TTPs. Daixin has the most experience and is probably the most likely to continue to cause havoc of any group on this list. 

A majority of the Daixin Team attacks have been against critical infrastructure.

Here is a visual snapshot of Daixin critical infrastructure attacks:




Fitgibbon Hospital cyber attack.


OakBend Medical Center cyber attack.


Meow Leaks (seriously)

Infrastructure breached - Hospital


Meow Leaks breached Vanderbilt University Medical Center and Hospital early in 2023 before they created their leak site later in the year. It is difficult to take a group calling themselves Meow seriously but they have attacked critical infrastructure and eventually I will take a deeper look at the group.


Vanderbilt Health cyber attack.


Money Message

Infrastructure breached - Hospital


Anna Jaques Hospital cyber attack.

The Money Message group came on the scene in 2023 and joins the not so famous list by breaching Anna Jaques Hospital. MM also breached a major dental company in 2023 so this may not be the first or last venture towards critical level companies. 

Money Message is trying to stay quiet behind the scene but they are now on radar.

Something has to be done.

Examples have to be made of these bad actors otherwise every pimple faced ransomware wannabe may start attempting to attack critical infrastructure. That will not end well.



The Cyber Show 

Dominic Alvieri

X - @AlvieriD 

Wednesday, January 17, 2024

Where Are They Now?

 The Conti Boys


By Dominic Alvieri
1/14/2024


Where Are They Now?


Ransomware groups have come and gone but few have continued to resonate across the criminal ransomware spectrum as the former members of Conti Ransomware. We all know the pipeline hacking name so let's cut to the chase.

Where are members of Conti? Start with the list below.

The list below does not include leaked source code offshoots like Monti or any others. All of the following groups can be attributed to former Conti. 

In alphabetical order:

Akira Ransomware, Black Basta, Black Byte, Black Suit (Royal Ransomware),  Karakurt Team, Three AM



Royal on the run.

Royal on The Run


Royal Ransomware was arguably on the run after their attack on the City of Dallas, Texas and has rebranded as Black Suit. Royal Black Suit of you like. Black Suit is active again.



Karakurt on an extended vacation.


100 Days Without Fam


By all accounts Karakurt has been inactive for over 100 days now. No posts. No attacks. No nothing.

So what happened? No speculations please.



Karakurt Team in high level discussions.






Black Byte Bitten


The Black Byte leak site was only active for a few hours over the past 2 months only producing a black and white logo change. That's it. I don't expect Black Byte to rebrand. Time will tell as it always does.




Akira Ransomware


Akira Akira. Not my favorite. Why don't we call him angry Conti. Angry Conti has set up his own thing including a cool retro site. Just a reminder that this cool retro site is trying to peg your system and steal your credentials as you browse their leak site. Phish your visitors. Great evil business model.




Black Basta


If there was ever a racist Conti this is it. More hateful. Targeted. The question is whether for Black Basta to retool or rebrand after the "Basta Busta" released. LockBit proved that you can continue without rebranding. Black Cat ransomware is also challenging what you would think to be the norm.





Black Basta was named by one of the most racist white guys ever. 





There are arguments to be made to include a few other names and strains. I fell like I missed a name or two. 

Don't mount a locker or hack illegally.



The Cyber Show.


Dominic Alvieri X- @AlvieriD
The Cyber Show

Sunday, August 13, 2023

Ransomware Groups May Soon Get Their Hands on Your Fingerprints.

You have to give us your fingerprint


By Dominic Alvieri
Aug. 13th, 2023



Give me your fingerprint or you are fired.


"You have no choice, the company is switching over."


Imagine being forced to give your biometric fingerprint away to third party. Now imagine your employer mandating this and you having no choice in the matter? Well imagine no more.

Meet the Kronos Biometric fingerprint time clock. Can you guarantee that my biometrics are safe. Where is the security answer please? 

I am so opposed to this and I can't do a thing about it. Being forced does not constitute consent.

For the record I object again. 




Which finger?


 Point in fact Kronos settled a lawsuit in 2022 stemming from their data breach in 2021.

Millions of workers are being forced to hand over their fingerprints. There is no consent. You are required to abide by company rules and companies are switching over to fingerprint readers because Kronos is switching over to biometric time clocks. 

Period. You have no choice. Once again I am so against this.






Fairly soon ransomware groups may be able to get their hands on your fingerprints.

I cannot state this point any clearer, you have NO choice except to clock in with your finger. 

I am strongly opposed to the forceful relinquishment of and collection of biometric data

Stay safe.





Dominic Alvieri

@AlvieriD

The Cyber Show 

Sunday, April 23, 2023

Top 10 All Time Active Ransomware Groups

 The Current Top 10 Active Ransomware Group Post Count


By Dominic Alvieri

April 23rd, 2023

@AlvieriD


Top 10 All Time Active Ransomware Groups


Quantifying ransomware group activity over the past few years there is no doubt that LockBit is the numerical leader all credibility issues aside. LockBit averages posting over one company per day since their initial formation as ABCD. No one else comes close. 


Conti members are still around but this list comprises of active groups with quantifiable active leak sites.


The top 10 active ransomware groups.

@AlvieriD


Posts that are somewhat quantifiable...


What is included in the numbers? Posts like the recent LockBit Dark Trace-Dark Tracer fiasco or their goofball post that was removed are not included. Neither are posts like the BlackCat NCR flash cyber incident that is still ongoing. 






Up and Coming Groups


The top groups to watch gaining traction are Royal and Play Ransomware. Play will be in the top 10 within the next month if current trends continue. Royal should be in the top 5 by summer.




New groups in 2023


Several new groups have arrived and in the case of Trigona, re-arrived. Money Message sans logo or not should be near the top of the new groups to watch list. Here are a few other new groups to watch:

Money Message
Trigona Ransomware
Cipher Locker
Akira Ransomware
Cross Lock Ransomware
Dunghill Leak...


Trigona Ransomware.


Cipher Locker ransomware.

Akira Ransomware.

Cross Lock Ransomware.


Dunghill.

Dunghill Leak is literally named after a pile of shit. What will they think of next.

Most Dangerous Groups


In my view Alphv BlackCat Ransomware and LockBit are fairly close in the top of this category. BlackCat has the ability to pivot quickly once in a network and LockBit is always trying to improve to stay on top but they have been getting sloppy while Alphv looks like it added another producing affiliate.

Black Basta, BlackByte, Royal and Play Ransomware deserve mention here as do a few others but my time is limited.


Stay safe.

The Cyber Show, by @AlvieriD


Friday, March 17, 2023

SpaceX Contractor Allegedly Breached

 LockBit leaves a message for Elon Musk


By Dominic Alvieri
March 17, 2023
Twitter @AlvieriD



SpaceX contractor allegedly breached.


To breach a contractor. That is in one sense a back door into a companies product or service without hacking into the company itself. This perfect example is the alleged breach of Maximum Industries from Texas. Maximum is a precision manufacturer and AS-9100 certified meaning their parts can be and are supplied to the aerospace industry. AS-9100 is a management standard for manufacturers in the aerospace industry supply chain.

LockBit posted Maximum Industries earlier in the week with an explicit message to Elon Musk. Last night LockBit posted alleged evidence composing of a mutual non-disclosure agreement and "certified" SpaceX drawings. 

LockBit message to Elon in the post below.




LockBit post.



Elon Musk is possibly the number one target in the world. So are his companies and their suppliers.

LockBit claims upwards of 3,000 SpaceX drawings. Catching up with several in the know each one product may have 100 or more drawings with variations and modifications fit to scale so the actual number of products compiled in any LockBit claim would have to be reduced significantly.

What is it worth?


Hard to say without additional evidence, and I'm not in the rocket parts market but there has to be some value to any and all competitors. The part in question does not seem high tech per se but neither is a pencil until you need to write something down. Remember writing?

Is that a 2019 model rocket in your garage?



Mutual non-disclosure agreement


This is tricky. Under normal business disclosure by either side would void the agreement. What are the legal ramifications? I am not a lawyer but did speak with one under the condition of anonymity and was advised not to comment on this. So much for hindsight.

Anyone could have made that copy of the alleged NDA btw. The alleged document is cutoff, unsigned and unverified at the moment. If it was authentic copies would be available to forensically match what was shown including handwriting analysis if needed. 

What happens when a ransomware group discloses an NDA?


This is the current situation. Once again I am not a lawyer and you a reading a free cybersecurity blog so no legal advice. This one is playing out live now.

"...SpaceX contractors were more talkative"

Analyzing this statement would lead one to believe that LockBit might have contractor emails. Take that with a bit of salt. A bit of salt. Cyber dork.





Neither company has made any comment as of this writing and I don't expect Elon Musk to respond to my tweet. Oh well, cyber goes on.

The deadline is Monday pending further drama this weekend.







The Cyber Show

Happy Saint Patrick's Day

@AlvieriD

The Kremlin, Politics and Ransomware

Qilin Ransomware caught with politically motivated fake document (and old data) in post. by Dominic Alvieri March 8th, 2025 @AlvieriD Was it...