Showing posts with label LockBit. Show all posts
Showing posts with label LockBit. Show all posts
Wednesday, July 3, 2024
Are You Trollin Me?
by Dominic Alvieri
July 3rd, 2024
/Conti_Royal_BlackSuit/
That random mixed letter and numbered social media account chimes in. To make a long story short several people both known and unknown to me recently mentioned the same thing, "...a guy from Black Suit started his own group and is responsible for a major incident. The group is called Black Spade."
Who is Black Spade?
Black Spade would be the continuation of the group formed by a Conti member who created Royal Ransomware then rebranded to Black Suit then either is planning on spinning off or rebranding to this new alleged Black Spade group.
Black Suit was attributed to the recent damaging CDK cyber incident. A CDK spokesperson originally said "it will take months to fully restore our network" and now they will be up and running by July 4th. Now that the incident appears over I think it is important to bring this to light. Bad actors with or without ransomware in general will lie, cheat and steal to get the money they feel entitled to. They will even try to bribe or fool a researcher, reporter or analyst into making false statements during a ransom negotiation to influence the outcome. Millions of dollars are at stake.
I really had the feeling I was being trolled. A pro level troll. Royal payback if you will. Contacted during a major incident with a major plot twist in the middle of alleged negotiations. I have never heard of such a thing. It is also rare for a group to willingly give their new spinoff and or rebrand name out beforehand. It defeats the purpose.
So is there a Black Spade? Not yet. The new Black Spade claims came somewhere a day or two before CDK's sudden positive change towards the cybersecurity incident. Once again CDK was never posted by Black Suit and they should be fully operational by Independence Day, July 4th which is tomorrow.
Once again two individuals mentioned the same name on the same day with bold new claims. The new group called "Black Spade" was a former/current Black Suit with a major victim. I asked for something concrete, an IoC, a new strain or anything that could back the claim. You just have to produce a ransom note, a data sample, post it or some evidence with a claim like that.
I had a feeling I was communicating with Royal who is still probably a little sore at me from the old Twitter days when Royal was online known as @LockerRoyal before being suspended.
For those of you that do not follow threat actors as closely as I do here is a little back drop. Black Suit recently posted a record (for them) in posting 9 new victims in a day and another leaked school district that was originally posted before as their 10th post for the day. Black Suit hasn't ever posted 10 victims in a week or that frequently on a monthly basis. It did look like Black Suit was cleaning house and possibly preparing to rebrand and or exit.
Skeptical I mentioned to both security researcher and I presume now to be the threat actor that I would put a feeler post out in a few hours mentioning the new threat group but I needed something solid to go forward with anything more. It's not a new ransomware group without a new strain so it isn't Black Spade Ransomware and it sounded somewhat feasible and a possible threat.
Careful not to create a major stir I toned down the threat eliminating the possibility that this new group was a LockBit or AlphV BlackCat rebrand just in case it was used for leverage with potential victims during a ransom negotiation. The timestamp is underlined.
Roughly an hour after my post Black Suit posted Kadokawa. Kadokawa was the 11th post and 10th new victim for Black Suit within 2 days which is a first. The Black Suit post rate is well below that number.
The Ransomware News bot from VX Underground post with timestamp underlined.
No points for the poor Russian to English translation above but I did catch the reference. It may have been nothing, probably just another cybersecurity coincidence.
CDK has never been posted by Black Suit or any other group to date. The original ransom request was believed to be $10 million with online rumors ballooning it to as high as $80 million. The truth is probably somewhere in between and closer to the lower figure. Ransomware groups and threat actors routinely ask for way more than they are willing to settle for. They over inflate their claims and use whatever other means are needed.
Just like that one of the two deleted their account and the next day fortunes turned for the encrypted.
CDK should be back fully operational by the time you read this. Once again CDK was never posted by Black Suit but confirmed the cyber incident and actor as being Black Suit. Kadokawa was leaked by Black Suit.
Is Black Spade for real? Is Black Spade coming? I'm not sure but if that name does come up make sure to do your due diligence.
Stay safe online and off.
Dominic Alvieri
@AlvieriD
Monday, February 19, 2024
The Part Timers
The Part Time Ransomware Groups.
by Dominic Alvieri
February 18th, 2024
It seems like everyone is attacking critical infrastructure these days. There are several nation states and 12 current active ransomware groups that have attacked critical infrastructure around the world. Here are 7 of the 12 active ransomware groups:
ALPHV BlackCat
Black Basta
Hunters International
LockBit
Play Ransomware
RansomHouse
Rhysida Ransomware
Can you name any of the other 5?
Remember the dentist/part time ransomware operator?
There may be another dentist deploying ransomware. Or maybe even a slick lawyer. The rash of bad actors attacking critical infrastructure has to be dealt with immediately.
Who are these part time ransomware operators and why we should make examples out of them? Tracking several of these groups and I can safely say it wouldn't take long to take down at least 2 of the 5 groups I mention below. I predict that at least one of the groups listed below should be comfortably viewing life behind some cold steel bars sometime this year.
Attacking critical infrastructure should be heavily penalized and actors jailed for so long that it should never cross the pea brain of any ransomware idiot.
What is a part time operator?
A part time ransomware operator attacks and posts fewer than about 8 victims per month by my definition and for the purposes of this analysis and article. The part time operator more than likely has another job and or profession in addition to breaching companies.
Cuba Ransomware would be a perfect example but exempt from this discussion due to their backing which is fairly safe to say it stems from the Russian Government and has nothing at all to do with Cuba.
Who are the part time ransomware operators?
Qilin Ransomware
Infrastructure breached - Electric utility
Qilin started quietly on the ransomware seen in 2023 but has ramped up and is set to graduate to a full time operator. Business is good for Qilin who breached and evidentially negotiated with Electric Power of Serbia posting and removing the utility serval times before finally leaking them.
Qilin appears to have quit his day job and about to deploy ransomware full time. 17 posts year to date thru 6 weeks of 2024.
Lorenz
Infrastructure breached - Hospital
Strictly business includes critical infrastructure.
Lorenz is a classic part time operator. A dentist? Probably not. Lorenz has more technical skills than some of the other part timers. I could write a whole other article about Lorenz but let me just say for the purposes of this topic that Lorenz has also breached critical infrastructure in Cogdell Memorial Hospital.
Daixin Team
Infrastructure breached - Hospitals, health networks & water districts
Daixin is the worst of the part timers. Daixin is not a dentist, not by far. I would define the group as the state sponsored nasty version of Cuba. I say this with a moderate degree of certainty from some of their TTPs. Daixin has the most experience and is probably the most likely to continue to cause havoc of any group on this list.
A majority of the Daixin Team attacks have been against critical infrastructure.
Here is a visual snapshot of Daixin critical infrastructure attacks:
Meow Leaks (seriously)
Infrastructure breached - Hospital
Meow Leaks breached Vanderbilt University Medical Center and Hospital early in 2023 before they created their leak site later in the year. It is difficult to take a group calling themselves Meow seriously but they have attacked critical infrastructure and eventually I will take a deeper look at the group.
Money Message
Infrastructure breached - Hospital
The Money Message group came on the scene in 2023 and joins the not so famous list by breaching Anna Jaques Hospital. MM also breached a major dental company in 2023 so this may not be the first or last venture towards critical level companies.
Money Message is trying to stay quiet behind the scene but they are now on radar.
Something has to be done.
Examples have to be made of these bad actors otherwise every pimple faced ransomware wannabe may start attempting to attack critical infrastructure. That will not end well.
The Cyber Show
Dominic Alvieri
X - @AlvieriD
Wednesday, January 17, 2024
Where Are They Now?
The Conti Boys
By Dominic Alvieri
1/14/2024
Ransomware groups have come and gone but few have continued to resonate across the criminal ransomware spectrum as the former members of Conti Ransomware. We all know the pipeline hacking name so let's cut to the chase.
Where are members of Conti? Start with the list below.
The list below does not include leaked source code offshoots like Monti or any others. All of the following groups can be attributed to former Conti.
In alphabetical order:
Akira Ransomware, Black Basta, Black Byte, Black Suit (Royal Ransomware), Karakurt Team, Three AM
Royal on The Run
Royal Ransomware was arguably on the run after their attack on the City of Dallas, Texas and has rebranded as Black Suit. Royal Black Suit of you like. Black Suit is active again.
100 Days Without Fam
By all accounts Karakurt has been inactive for over 100 days now. No posts. No attacks. No nothing.
So what happened? No speculations please.
| Karakurt Team in high level discussions. |
Black Byte Bitten
The Black Byte leak site was only active for a few hours over the past 2 months only producing a black and white logo change. That's it. I don't expect Black Byte to rebrand. Time will tell as it always does.
Akira Ransomware
Akira Akira. Not my favorite. Why don't we call him angry Conti. Angry Conti has set up his own thing including a cool retro site. Just a reminder that this cool retro site is trying to peg your system and steal your credentials as you browse their leak site. Phish your visitors. Great evil business model.
Black Basta
If there was ever a racist Conti this is it. More hateful. Targeted. The question is whether for Black Basta to retool or rebrand after the "Basta Busta" released. LockBit proved that you can continue without rebranding. Black Cat ransomware is also challenging what you would think to be the norm.
Black Basta was named by one of the most racist white guys ever.
There are arguments to be made to include a few other names and strains. I fell like I missed a name or two.
Don't mount a locker or hack illegally.
Dominic Alvieri X- @AlvieriD
The Cyber Show
Sunday, August 13, 2023
Ransomware Groups May Soon Get Their Hands on Your Fingerprints.
You have to give us your fingerprint
By Dominic Alvieri
Aug. 13th, 2023
"You have no choice, the company is switching over."
Imagine being forced to give your biometric fingerprint away to third party. Now imagine your employer mandating this and you having no choice in the matter? Well imagine no more.
Meet the Kronos Biometric fingerprint time clock. Can you guarantee that my biometrics are safe. Where is the security answer please?
I am so opposed to this and I can't do a thing about it. Being forced does not constitute consent.
For the record I object again.
Which finger?
Point in fact Kronos settled a lawsuit in 2022 stemming from their data breach in 2021.
Millions of workers are being forced to hand over their fingerprints. There is no consent. You are required to abide by company rules and companies are switching over to fingerprint readers because Kronos is switching over to biometric time clocks.
Period. You have no choice. Once again I am so against this.
Fairly soon ransomware groups may be able to get their hands on your fingerprints.
I cannot state this point any clearer, you have NO choice except to clock in with your finger.
I am strongly opposed to the forceful relinquishment of and collection of biometric data
Stay safe.
Dominic Alvieri
@AlvieriD
The Cyber Show
Sunday, April 23, 2023
Top 10 All Time Active Ransomware Groups
The Current Top 10 Active Ransomware Group Post Count
By Dominic Alvieri
April 23rd, 2023
Quantifying ransomware group activity over the past few years there is no doubt that LockBit is the numerical leader all credibility issues aside. LockBit averages posting over one company per day since their initial formation as ABCD. No one else comes close.
Conti members are still around but this list comprises of active groups with quantifiable active leak sites.
Posts that are somewhat quantifiable...
What is included in the numbers? Posts like the recent LockBit Dark Trace-Dark Tracer fiasco or their goofball post that was removed are not included. Neither are posts like the BlackCat NCR flash cyber incident that is still ongoing.
Up and Coming Groups
The top groups to watch gaining traction are Royal and Play Ransomware. Play will be in the top 10 within the next month if current trends continue. Royal should be in the top 5 by summer.
New groups in 2023
Several new groups have arrived and in the case of Trigona, re-arrived. Money Message sans logo or not should be near the top of the new groups to watch list. Here are a few other new groups to watch:
Money Message
Trigona Ransomware
Cipher Locker
Akira Ransomware
Cross Lock Ransomware
Dunghill Leak...
Dunghill Leak is literally named after a pile of shit. What will they think of next.
Most Dangerous Groups
In my view Alphv BlackCat Ransomware and LockBit are fairly close in the top of this category. BlackCat has the ability to pivot quickly once in a network and LockBit is always trying to improve to stay on top but they have been getting sloppy while Alphv looks like it added another producing affiliate.
Black Basta, BlackByte, Royal and Play Ransomware deserve mention here as do a few others but my time is limited.
Stay safe.
Friday, March 17, 2023
SpaceX Contractor Allegedly Breached
LockBit leaves a message for Elon Musk
By Dominic Alvieri
March 17, 2023
Twitter @AlvieriD
To breach a contractor. That is in one sense a back door into a companies product or service without hacking into the company itself. This perfect example is the alleged breach of Maximum Industries from Texas. Maximum is a precision manufacturer and AS-9100 certified meaning their parts can be and are supplied to the aerospace industry. AS-9100 is a management standard for manufacturers in the aerospace industry supply chain.
LockBit posted Maximum Industries earlier in the week with an explicit message to Elon Musk. Last night LockBit posted alleged evidence composing of a mutual non-disclosure agreement and "certified" SpaceX drawings.
LockBit message to Elon in the post below.
Elon Musk is possibly the number one target in the world. So are his companies and their suppliers.
LockBit claims upwards of 3,000 SpaceX drawings. Catching up with several in the know each one product may have 100 or more drawings with variations and modifications fit to scale so the actual number of products compiled in any LockBit claim would have to be reduced significantly.
What is it worth?
Hard to say without additional evidence, and I'm not in the rocket parts market but there has to be some value to any and all competitors. The part in question does not seem high tech per se but neither is a pencil until you need to write something down. Remember writing?
Is that a 2019 model rocket in your garage?
Mutual non-disclosure agreement
This is tricky. Under normal business disclosure by either side would void the agreement. What are the legal ramifications? I am not a lawyer but did speak with one under the condition of anonymity and was advised not to comment on this. So much for hindsight.
Anyone could have made that copy of the alleged NDA btw. The alleged document is cutoff, unsigned and unverified at the moment. If it was authentic copies would be available to forensically match what was shown including handwriting analysis if needed.
What happens when a ransomware group discloses an NDA?
This is the current situation. Once again I am not a lawyer and you a reading a free cybersecurity blog so no legal advice. This one is playing out live now.
"...SpaceX contractors were more talkative"
Analyzing this statement would lead one to believe that LockBit might have contractor emails. Take that with a bit of salt. A bit of salt. Cyber dork.
Neither company has made any comment as of this writing and I don't expect Elon Musk to respond to my tweet. Oh well, cyber goes on.
The deadline is Monday pending further drama this weekend.
The Cyber Show
Happy Saint Patrick's Day
@AlvieriD
Subscribe to:
Posts (Atom)
The Kremlin, Politics and Ransomware
Qilin Ransomware caught with politically motivated fake document (and old data) in post. by Dominic Alvieri March 8th, 2025 @AlvieriD Was it...
-
Qilin Ransomware caught with politically motivated fake document (and old data) in post. by Dominic Alvieri March 8th, 2025 @AlvieriD Was it...
-
The Conti Boys By Dominic Alvieri 1/14/2024 @AlvieriD Ransomware groups have come and gone but few have continued to resonate across the cr...
-
Seek deep and ye shall find by Dominic Alvieri February 1st, 2025 @AlvieriD Malware, credential phishing, fake meme coins, exposed data... ...


