Showing posts with label Reuters. Show all posts
Showing posts with label Reuters. Show all posts

Monday, February 27, 2023

Who Hacked Atlassian?

The Wolf in Sheep's Clothing


Ghosts of SeigedSec


By Dominic Alvieri
February 22nd, 2023




One of the largest companies breached to date this year was carried out by a relatively unknown group, SiegedSec. "Little is known about the Hacking Crew" an analyst said as Envoy and Atlassian blamed each other initially last week. I had questions so I decided to reach out.

The SiegedSec Hacking crew? 


TechCrunch update on Atlassian.
Story by Carley Page and Zack Whittaker



Where did SiegedSec come from?


The leader of the new group called SiegedSec likes to be called Wolf and he came from and still is a member of GhostSec. The leader of GhostSec goes by Seb. Why the separate group? That was one of my first questions besides "the Furry Hackers" comments.

The Wolf in Furry Hacker Clothing insists on maintaining the controversial furry angle through the conversations and updates. Personally I think it is an act to draw attention to important matters like freedoms which have been curtailed all across the globe in the past few years.

It is tough to take this seriously and I have no idea how long it will last but neither group is leaving the scene anytime soon. Hacking Atlassian no matter how will still draw attention to whatever your cause is. This feels like an attempt to capitalize on a situation which other groups have tried to make a huge splash and then pivoting from that initial buzz into the actual or real group.


The wolf in furry clothing.
The Wolf in Furry Hacker Clothing


The Wolf in Furry Clothing


The leader of the new pack


Making a splash after a controversial United States Supreme Court decision last year, little known SiegedSec is back with a breach of giant Atlassian. I caught up with GhostSec to ask why the post was released through their channel and continued to drill down,

Here are some of the specific questions asked and answered over this past week. 


Q-Who is SiegedSec?
A-Seb (GhostSec) SiegedSec was one of my members who decided to do his own thing. He still is a member of GhostSec as well.

Q-Still a member?
A-Yes.

The questions I wanted to know that I can share...


Q-Wolf-The state hacks last year...and why active again now?
A-...not as easy as it seems to quit hacking. That's the way I would put it, hat's why SiegedSec came back

Q-How did you breach Atlassian?
A-Honestly answered and redacted for security and breach confirmed by Atlassian.


Q-Was Atlassian a target?
A-No...

Q-Did you ask Atlassian for a ransom or was it just for shits and giggles?
A-Just for shits and giggles


Q-Any other victims or lateral movement?
A-No answer or evidence was provided.


SiegedSec will be posting on their own Telegram channel



To both Seb and Wolf

Q-Did either of you breach anyone this week?

A-Both "No comment." 



I got the feeling that they both may have.



Q-Wolf or Seb, Is the UWU what I think it is along with the "Furry Hackers"




A-Yes


UWU is slang and loosely described a furry loving or friendly. Lets leave that be for now.


Throughout Wolf insisted upon being and going with the Furry Hacker theme. 

Anything SiegedSec wants to say? Shortened answer

"Just represent yourself and be yourself, be a furry hacker who cares."



GhostSec



GhostSec


Leaving out the basic get-to-know-you hacker exploit talk and the like, I asked questions to both like is either group thinking of setting up a leak site. 

Both have thought about it but not now in the works, at least not officially. 

Speaking with Seb from GhostSec he struck me as being honest in answering  my questions of which I already knew some of the answers. I obviously cannot release some questions asked and answered here but might be conversed...

 qqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqq

...at a bar and not online.

GhostSec Seb


Q-Why Maine?
A-We have nothing against the State of Maine of their people we just happened to breach them.

Q-Any specific targets or breaches you can share?
A-Not at the moment.

Q-What are the odds that LockBit or Black Cat will post while we are chatting?
A-Highly likely lol

LockBit did post a company during the interview.

Q-I wish I could post more of this conversation, Do you have a statement?
A-Shortened Answer-Hack the Planet, if there is no path, create it. Fight against injustice.


Stay safe



Dominic Alvieri on Twitter @AlvieriD



 Dominic Alvieri
Twitter @AlvieriD

Thursday, October 13, 2022

New Chinese Misinformation Campaign

Fake Campaign Attempts to Attribute Chinese Advanced Persistent Threat Group APT 41 to the NSA


By Dominic Alvieri 

@AlvieriD

October 12th, 2022


New Chinese misinformation campaign


A new Chinese misinformation campaign has been spreading this past week attempting to attribute the Chinese APT 41 to the National Security Agency. Many are using the Intrusion Truth name. 


Global Times Chinese domain article tweet.





Several new accounts tweeted in Chinese Mandarin for the local media in Asia while others have been created in English for a wider audience. All accounts use the APT 41 hashtag. 


Kimberly Allen Fake FireEye Attribution in Mandarin





The above tweet translates to FireEye attributing Chinese APT 41 to the NSA.


The tweet above has been removed but the account remains.





The FBI reports concludes what we all know while some are trying to create confusion in typical APT 41 style.



Dominic Alvieri, @AlvieriD Twitter

This is a new and current campaign with all accounts still currently open. No new activity has been spotted since the initial report this week with fake attribution tweets.


Blog will be updated as needed. Stay safe.





Tuesday, April 12, 2022

A Week with Lapsus$

Conversations with Americas Most Wanted


By Dominic Alvieri


April 11th, 2022



The Cyber Show Catch Me if You Can.


What it's like

 
So what is it like to speak with someone so wanted and hated by so many? The answer may surprise you. Brash, confident and way more intelligent than people are willing to give to the remainder of the Lapsus$ group credit for. 

What is his name? I didn't ask and frankly don't care. Chances are it would be another farce. 

Where is he? I didn't ask again and don't care.

Where are the remaining members now? I again didn't ask and again don't care. That is not my job to breach Telegram and other companies and to find answers. 

This is an account from the past week with Lapsus. I am not part of Lapsus$.

Recent photo profile updates





Tagged on Twitter










That warm and cozy feeling. 


What did you talk about? None of your business. Just kidding. We did share a few laughs. Speaking of how influential a photo is in reference to text we laughed as he changed profile photos live. We are all visual creatures. We also all fall into patterns. Pattern analysis transfers well.

We spoke about women ( don't judge ) surprisingly not guns, a little tech and the minefield that has been unearthed around him. Eager to save what was a short lived legend in Lapsus$ it would come as no surprise to anyone that this is the current attempt at just that, reviving Lapsus$.






It was very interesting. There have been may articles and blogs written about the group and I am not going to be redundant but giving a brief synopsis of the past week chatting with the famed "Mox" of the prematurely pronounced dead Lapsus$ hacking and extortion group. 

In and out. Constant change, searching, contacts. Fast.

Lapsus$ is still alive albeit a like a racing team without a car or driver but it has a good pit crew. They are looking to change that. 

As several researchers have pointed out and has been confirmed there are several members of the group still active as is evident here. Actively searching to retain former glory. 

Right now it is no secret that the group is under diminished capacity. That can change at any moment.







Girls, guns, cars, companies... we didn't actually speak about guns but I'm sure that would have been interesting as well. 

Good bye Mox

To be continued fortunately by someone else. I'm exhausted.






Dominic Alvieri

Twitter @AlvieriD

Wednesday, July 7, 2021

Do Smart Contracts Make You Feel Dumb?

 

Stablecoins May Not Be Very Stable.

What is a Coin? What is a Token?

By Dominic Alvieri, @AlvieriD
July 7th, 2021 


The Crypto Craze
The Crypto Craze.



The proposed STABLE Act will require stablecoin issuers to have a banking charter and report holdings.


The STABLE Act may be coming soon. Additional reporting and disclosure of assets securitizing stablecoins is a move in the right direction for security sake.

You probably have heard Bitcoin is an investment or a store of value .
You may have also heard most ransomware is paid in Bitcoins.

Do you know the difference between a coin and a token?
Do you know about different blockchains?
Do you know what fungible means?


What or who is backing your stablecoins?



Bitcoin, Ethereum, Ripple and stablecoins are not all created equal. Bitcoin is a digital currency to invest, hold or purchase in exchange for goods or services much the way a dollar in the local store would. Your one dollar or Bitcoin is fungible or able to replace or is interchangeable or equal to the next one. What or who is behind and backing your stablecoin?



Do you know the difference between Bitcoin and Ethereum.
Do you know the difference between BTC and ETH?


What is a coin and what is a token?

Do you know the difference between a coin and a token? A coin is referred to as a cryptocurrency and can be held as an investment or used  like Bitcoin in exchange for an item, good or service.

A token is issued as a smart contract on the Ethereum blockchain and there are three main types of tokens. A token may currently be a utility, commodity or security based token. In brief a utility token generally is used between a site for a use. A commodity based token is backed by a certain asset or commodity such as gold. A security token implies ownership in that company or decentralized unit. 

Cryptocurrency and tokens have different values. Ethereum has gas to defend infinite loops.
Keccak that. Is that still used? What is that?

Obtain full details before investing in any cryptocurrency, token or other investment in general.

Smart contracts make you feel dumb?


ERC-20 and ERC-721 basics.

In short smart contracts use blockchain technologies and software to execute the exchange of an asset or property between a buyer and a seller written directly into the code of the contract on the Ethereum framework are called ERC 20s. Rather than running a separate blockchain, ERC 20 is the main technological standard and set of rules that apply to issuing smart contracts via the Ethereum blockchain. There are six basic rules and are in place for uniformity among contracts. Several digital currencies including Augur and Maker use the ERC 20 standard.

An ERC 721 is a non-fungible token. There is more to.


The wild world of cryptocurrencies.
There are many different stablecoin issuers.


A word of caution.


A word of caution going forward. Government central banks will be issuing Central Bank Digital Currencies, or CBDCs. A stablecoin is not a CBDC.

 A CBDC is not backed by any Bitcoin, Ethereum or any other digital cryptocurrency. 
It will be issued by a government.

Tether backed stablecoin assets have been questioned before.


 A stablecoin is not backed by either a CBDC, BTC, ETH, etc. Check with your actual investment prospecuts or white paper.  With Tether and other stablecoins you are trusting in a company to maintain its peg rate and assets securitizing the underlying stablecoin. 

The STABLE Act will require stablecoin issuers to acquire a banking charter or license and file reports showing detailed investment holdings backing stablecoin investments.  



Buyer beware security is on you too.
Buyer beware, the security is on you as well.


The crypto craze continues.


Be careful with valuations and security. Do use cold storage and secure 2FA for your accounts. 
The main difference between 2FA and MFA is more factors. 2FA implying two factors and MFA more than two. The more the merrier with security.

Separating MFA between devices will give you an added layer of security. If one of your security factors gets bypassed, your phone ported for example, you will still be able to maintain that second layer of defense to restrict access to that account. 

Having your tokenized security app, email second factor or even SMS alert on another private secure line is a great added layer of security. Secure your accounts with tokenized 2FA at a minimum. 



Fungible or non fungible cyber show?
Blockchain, cryptocurrency, stablecoin or token, Each are different



There are different types of blockchains, public, private and permissioned. 
There are different types of cryptocurrencies.
There are different types of stablecoins.
There are different types of tokens.

Know the difference between Bitcoin, Ethereum and Libra before you invest. Be careful with misinformation when it comes to crypto and investing in general.

 Get verified information.


The Cybersecurity Show By Dominic Alvieri
The Cyber Show by Dominic Alvieri, @AlvieriD

The Cybersecurity Show by Dominic Alvieri
The Cyber Show on Google Blogger and YouTube
    @AlvieriD

Thursday, April 8, 2021

The Masters of Spoof

 Can anyone compete with Chinese spoofs?




The Cyber Show on Blogger

What makes a good spoof?


The Cyber Show on Blogger


Chinese imported counterfeit goods have been around as long as time itself. Reproducing an item as close to the original as possible. Logo color and style. 

For the cyber criminal the goal is the same, just replicate and add urgency.


Amazon spoofs



Amazon is a global target.
The links are difficult to replicate but they they try.



The Chinese gangs use the same MO: NameCheap registers, Alibaba hosts and anything that can be will be spoofed. Amazon, Apple, Hulu, Netflix, USPS. The online version of the knock off brand.

NameCheap often surfaces with these new short link scam domains. The Chinese aren't the only ones playing this game but with years of experience they are ahead of the pack.

Often targeting the largest companies Amazon, Apple and Netflix to name a few.


Often rerunning the same campaigns with great success.


The Netflix scam
2020 Netflix scam resurfaces again.

The devil is in the details. Examine all links with great care. Or you can just not answer any email, text or call. Warranty anyone? 

Some are easier to spot. Best Buy and spot gold.






You can always go back to a landline, otherwise examine all links and go directly to the company.
The above spoofs are all pedestrian, at best. The better spoofs have been withheld to avoid duplication.

The email spoof is still the number one entry for a cyber criminal to gain access to your system.
Stay safe online and off.



The Cyber Show
by Dominic Alvieri
Twitter, @AlvieriD



Tuesday, March 16, 2021

What the Spoof

All Spoofs All the Time. 

By Dominic Alvieri, @AlvieriD
March 10th 2021



The Cyber Show by Dominic Alvieri



Everyone wants something for free.



Free Netflix and Hulu for a year?


Free Netflix and Hulu for a year to help us stay home? 

Forget about that the BMW lottery came in, and some alert in France? 







All of the following offers are coming from China. 



Spoofed SMS texts


Fake USPS delivery notices continue.




Fake USPS delivery notice.

Fake USPS SMS spoofs coming from China.


------.py


Free Netflix for a year to help you stay home.



This is a Netflix spoof.


Free Hulu for a year to help you stay home?

Is it Netflix or Hulu?





The new short domain attack continues.



                                  DO NOT

                               [click here] 









Spoofed emails have been around since the beginning of the internet. Spoofed SMS texts have been proliferating in the past few years. Knowing the domain endings is critical. Newly created short domains have been popping up with the same group. 

Technological reverse psychology if you will by tracking the bad guys back. The building below is from a Google Earth trace address of the malicious links geolocation. 



Geolocation of malicious SMS texts.
Geolocation of malicious SMS text links.


Time to harden your network security. Use VPNs and encrypted communication like Signal to minimize your surface. Use MFA and tokenized apps like Google or Microsoft Authenticator over SMS. Incognito mode is not optimal security for your browser. Tor is acceptable but slow. Nothing is full proof. Check your home network and make sure to disable port forwarding and also disable the plug n play otherwise you are leaving a back door open.

IoT devices should be secured. Check for open standards, basic passwords and check for any and all updates and patches. Patch often and early. Do not hesitate. Within 12 hours of the server exchange hack Russian bad actors were scanning for the vulnerability according to Bad Packets, a malicious scanning alert firm. 

Security minimums are no longer effective. Update to longer more difficult passwords and do not click on any suspicious link. Or avoid all links. Not realistic but you get the point. 

This IP with "no site" is the USPS spoofed SMS malicious text link above in this report.



IP address of SMS text malicious links.
Courtesy of DomainTools.



The enemies are at the gates, computers, networks, phones...








The Cyber Show on Google Blogger
by Dominic Alvieri


Twitter @AlvieriD

The Kremlin, Politics and Ransomware

Qilin Ransomware caught with politically motivated fake document (and old data) in post. by Dominic Alvieri March 8th, 2025 @AlvieriD Was it...