Showing posts with label infosec. Show all posts
Showing posts with label infosec. Show all posts

Wednesday, July 3, 2024

Are You Trollin Me?

 Did Black Suit Ransomware just try to troll me?


Black Spade.

by Dominic Alvieri
July 3rd, 2024


The story goes a little something like this...


/Conti_Royal_BlackSuit/
                       |_BlackSpade/


That random mixed letter and numbered social media account chimes in. To make a long story short several people both known and unknown to me recently mentioned the same thing, "...a guy from Black Suit started his own group and is responsible for a major incident. The group is called Black Spade."

Who is Black Spade?




The Royal (Ransomware) Flush


Black Spade would be the continuation of the group formed by a Conti member who created Royal Ransomware then rebranded to Black Suit then either is planning on spinning off or rebranding to this new alleged Black Spade group.

Black Suit was attributed to the recent damaging CDK cyber incident. A  CDK spokesperson originally said "it will take months to fully restore our network" and now they will be up and running by July 4th. Now that the incident appears over I think it is important to bring this to light. Bad actors with or without ransomware in general will lie, cheat and steal to get the money they feel entitled to. They will even try to bribe or fool a researcher, reporter or analyst into making false statements during a ransom negotiation to influence the outcome. Millions of dollars are at stake. 

Is there a Black Spade? The Major Plot Twist


I really had the feeling I was being trolled. A pro level troll. Royal payback if you will. Contacted during a major incident with a major plot twist in the middle of alleged negotiations. I have never heard of such a thing. It is also rare for a group to willingly give their new spinoff and or rebrand name out beforehand. It defeats the purpose.

So is there a Black Spade? Not yet. The new Black Spade claims came somewhere a day or two before CDK's sudden positive change towards the cybersecurity incident. Once again CDK was never posted by Black Suit and they should be fully operational by Independence Day, July 4th which is tomorrow.

Once again two individuals mentioned the same name on the same day with bold new claims. The new group called "Black Spade" was a former/current Black Suit with a major victim. I asked for something concrete, an IoC, a new strain or anything that could back the claim. You just have to produce a ransom note, a data sample, post it or some evidence with a claim like that.




I had a feeling I was communicating with Royal who is still probably a little sore at me from the old Twitter days when Royal was online known as @LockerRoyal before being suspended.

I need some proof of compromise, a ransom note or something 


For those of you that do not follow threat actors as closely as I do here is a little back drop. Black Suit recently posted a record (for them) in posting 9 new victims in a day and another leaked school district that was originally posted before as their 10th post for the day. Black Suit hasn't ever posted 10 victims in a week or that frequently on a monthly basis. It did look like Black Suit was cleaning house and possibly preparing to rebrand and or exit. 

Skeptical I mentioned to both security researcher and I presume now to be the threat actor that I would put a feeler post out in a few hours mentioning the new threat group but I needed something solid to go forward with anything more. It's not a new ransomware group without a new strain so it isn't Black Spade Ransomware and it sounded somewhat feasible and a possible threat. 



My post above


Careful not to create a major stir I toned down the threat eliminating the possibility that this new group was a LockBit or AlphV BlackCat rebrand just in case it was used for leverage with potential victims during a ransom negotiation. The timestamp is underlined.

Their post roughly an hour later...


Roughly an hour after my post Black Suit posted Kadokawa. Kadokawa was the 11th post and 10th new victim for Black Suit within 2 days which is a first. The Black Suit post rate is well below that number.



The Ransomware News bot from VX Underground post with timestamp underlined.

The Black Suit Kadokawa post



It may have just been a wild coincidence with the poker reference but it didn't feel like it.

The Ace of Spades


...we prefer not to show all the aces we have prepared within the sleeve." 


No points for the poor Russian to English translation above but I did catch the reference. It may have been nothing, probably just another cybersecurity coincidence. 





"...we are only interested in money.' - Black Suit Ransomware


The Ugly Side of Cyber - Negotiations


CDK has never been posted by Black Suit or any other group to date. The original ransom request was believed to be $10 million with online rumors ballooning it to as high as $80 million. The truth is probably somewhere in between and closer to the lower figure. Ransomware groups and threat actors routinely ask for way more than they are willing to settle for. They over inflate their claims and use whatever other means are needed.

Just like that one of the two deleted their account and the next day fortunes turned for the encrypted.

CDK should be back fully operational by the time you read this. Once again CDK was never posted by Black Suit but confirmed the cyber incident and actor as being Black Suit. Kadokawa was leaked by Black Suit.

Is Black Spade for real? Is Black Spade coming? I'm not sure but if that name does come up make sure to do your due diligence.

Stay safe online and off.



Dominic Alvieri
@AlvieriD

Wednesday, June 12, 2024

How I Hacked Your Mother

Did you know I can hack you from several yard sale items?


by Dominic Alvieri
June 12th, 2024


How I Hacked Your Mother, by Dominic Alvieri



Can You Help Me With My Smart Dryer?

Kids did I ever tell you how I prevented your mom from getting hacked?

Cybersecurity articles are either way too technical or way too simply not containing any concrete or actionable information the average person can utilize.

In the simplest terms any device that has been connected to the internet will leave a digital trail and be left stored in that devices memory. They don't just magically disappear...you have to remove them.


It can without wiping your old IoT device memory.

A Simple Question Asked and Not Answered

Whenever you dispose of any IoT device what must you do with the devices memory? 

36 out of 36 random people that I asked this question to failed to answer it correctly. You must successfully wipe clean your old device memory before selling or disposing of the device. Not one of the 36.


The Cyber Show

***Important Disclaimer***

A proper forensic investigation should be done on a copy and not the original to avoid chance of corruption or tampering and it is usually copied as an image and then added as a data source to investigate further depending on the tool you are using. Please do your own research on how to properly conduct a forensic investigation but that is a key principle to strictly adhere to.

Secondly just to be safe I am leaving out the brand names of the devices researched. Remember that any device that connects to the internet will leave a digital trail. The credentials don't just disappear. 


Smartphone, Tablet, Camera, Printer...

I was driving around the other day and saw a yard sale sign and looking for a few things.


The Yard Sale Hack

How is Your Smart Washer Connecting to the Internet?


The Yard Sale Hack

It didn't take long to see an old Android smartphone and a printer for sale. I asked the owner if she new that I could find all types of credentials and data left if she didn't clean the memory from her devices. She didn't know how to respond. I explained the research I was doing. She said she deleted all the photos on the phone so she was ok. ( yikes! ) I explained how to properly dispose of any IoT device. She agreed to the sales and research. I returned the devices in a few days and revealed my findings.


Digital Forensics


I've been hacking and breaking things for a long time but I also track and trace cyber criminals & cryptocurrencies and forensically go over all types of devices. Autopsy is one of my favorite tools but I use several depending on what type of device ( desk top hard drive, smartphone, printer, etc.) I am going to go over and what I am looking for. I used several tools and addons for this project so I won't bore you.

Different devices have different types of memory. The hard drive in your computer is obviously different from the memory and storage in your smartphone. That is a blog for another day. 

It's All in the Credentials


In short the printer had her Wi-Fi credentials in plain text and the smartphone had a treasure trove of information that could be used against her. I agreed not to expose any personal details except for the minimal details that we agreed upon so sorry no redacted screen shots.



                                                                       Sample of Autopsy

How I Prevented Your Mother From Getting Hacked


What is the Best Thing to do When Disposing of an IoT device?


The best single piece of advice when getting rid of old IoT devices is to wipe clean your old IoT device memory. Every single IoT device. It is just that simple. Your can remove and destroy the storage media which also works but isn't very practical with smartphones.

How?


Again in simple term depending on the type of storage media there is professional software like Eraser or other commercial tools available. For all other devices such as printers, assistants and other non-smartphone type devices they will have instructions usually in their settings and should be a factory reset as a worst case minimum.

 Check your devices manual and carefully go over their instructions. 

Stay safe online and off. 

Wednesday, April 10, 2024

Typosquatting with Mikhail

The Infrastructure Boss


by Dominic Alvieri
April 10th, 2024




What does a former Boris Yeltsin era Defense Minister for the Russian Federation have to do with cybercrime and ransomware today?

Since early 2023 I have been tracking a cybercrime infrastructure that now accounts for over 800 phishing websites pretending to be banks, software companies and cryptocurrencies deploying malware and dropping crypto stealers.

All of the 800+ phishing sites have two things in common. They are all registered with NiceNIC.NET and the WHOIS registrant organization is "Mihail Kolesnikov." 

Several countries of origin are used including Belize and Belgrade. A few websites were also registered under the correct spelling of Mikhail with the vast majority registered as "Mihail."

Hunters International is the latest ransomware and data extortion group to join.


Hunters International


Several of the websites were deploying bumblebee malware along with various stealers. Redline stealer and new versions of Rilide and Fletchen stealers. 

A quick look - Fletchen stealer features some of the same wide array of malicious activities as other stealers including credential theft, Wi-Fi login details, browser history and cookie retrieval along with several crypto clipper options. 

Fletchen stealer is written in Rust with simple panel access and is easy to navigate but script kiddies beware, you need technical abilities to encrypt the stealer.exe file.








Hunters International registered their clearnet leak site with the registrant organization of Mihail Kolesnikov in January of this year.



WHOIS data from Hunters International


All of the malicious websites have been registered since 2022 and continue under the typosquatted registrant organization of Mihail Kolesnikov. 



Typosquatting Mikhail.




Clippers replace the destination address and replace them by generating a corresponding address with Fletchen stealer (pictured below) currently stealing Bitcoin, Ethereum, Litecoin USDC, USDT even Dogecoin and other cryptocurrencies.

"history",
"webRequests",
"tabs",
"clipboardWrite",
"clipboardRead",
"management",
"<all_urls>"
],

Fletchen Stealer

Former Rilide C2 domain /silent-scale.com

A full report will be out in the month or so detailing the Chinese registrations and Russian C2's associated with all of these "Mihail Kolesnikov" websites and malware.


The Cyber Show, by Dominic Alvieri



Dominic Alvieri
X @AlvieriD



Wednesday, May 31, 2023

Cracking the Connected Floor

Analytics and Cybersecurity 


By Dominic Alvieri
May 23rd, 2023



This KPI Isn't Pointing in the Right Direction

Fortune 500 companies are expanding their attack surfaces in a new data analytics push.

Cybersecurity takes a back seat for data analytics in a manufacturing executives dream which is turning out to be a security nightmare. It's called the connected shop floor and in this current version isn't going to end well. Corporate executives are unintentionally and unnecessarily exposing themselves to unnecessary risks. 

"This is largely driven by connecting machines using IoT and enabling Ai to digitize the results"

Apple iPads and Microsoft Bi along with several outsourced apps and technologies are involved.




100's of new endpoints and unrestricted devices 


All employees who have access to these new IoT devices running the backbone of this technological shop floor had open browser access and email capabilities. Personal emails as well as corporate and a host of new apps and software.

Oops, an employee just clicked on one of their personal emails and got phished.

Before drilling deeper into the technologies and possible exploits available for a starter there are hundreds of new IoT devices with an unrestricted browser able to view porn, YouTube or TikTok videos. A small time phisherman with a low grade infostealer may unknowingly get access to a Fortune 500 company employee and not even know it. 





The good news

Executives are starting to learn about cybersecurity. The bad news? They are slow and stubborn.

Here is a no brainer-restricting employee browser access.



App Avalanche


Once again executives are slow in embracing cybersecurity. They need the numbers to crunch to squeeze every last ounce of shareholder value that you can. Security often takes a back seat.

"Cybersecurity does not add revenue" one executive told me on the condition of anonymity. 






Exploitable


Querying one of the apps being used in one version of the connected floor returned an interesting response resulting in an error in my SQL syntax. Input sanitation issues are red flags indicating injection flaw exploits. 

Obviously I am unable to mention the firm or app until the issue is resolved. 

There are other exploitable alleys in this project.


The Deeper I Drill...

I have not received  any responses to my questions regarding the above mentioned security issues along with an uncovered topic. 


I am offensive in nature even in a defensive posture.
...

There are more holes in the floor.




Sunday, April 23, 2023

Top 10 All Time Active Ransomware Groups

 The Current Top 10 Active Ransomware Group Post Count


By Dominic Alvieri

April 23rd, 2023

@AlvieriD


Top 10 All Time Active Ransomware Groups


Quantifying ransomware group activity over the past few years there is no doubt that LockBit is the numerical leader all credibility issues aside. LockBit averages posting over one company per day since their initial formation as ABCD. No one else comes close. 


Conti members are still around but this list comprises of active groups with quantifiable active leak sites.


The top 10 active ransomware groups.

@AlvieriD


Posts that are somewhat quantifiable...


What is included in the numbers? Posts like the recent LockBit Dark Trace-Dark Tracer fiasco or their goofball post that was removed are not included. Neither are posts like the BlackCat NCR flash cyber incident that is still ongoing. 






Up and Coming Groups


The top groups to watch gaining traction are Royal and Play Ransomware. Play will be in the top 10 within the next month if current trends continue. Royal should be in the top 5 by summer.




New groups in 2023


Several new groups have arrived and in the case of Trigona, re-arrived. Money Message sans logo or not should be near the top of the new groups to watch list. Here are a few other new groups to watch:

Money Message
Trigona Ransomware
Cipher Locker
Akira Ransomware
Cross Lock Ransomware
Dunghill Leak...


Trigona Ransomware.


Cipher Locker ransomware.

Akira Ransomware.

Cross Lock Ransomware.


Dunghill.

Dunghill Leak is literally named after a pile of shit. What will they think of next.

Most Dangerous Groups


In my view Alphv BlackCat Ransomware and LockBit are fairly close in the top of this category. BlackCat has the ability to pivot quickly once in a network and LockBit is always trying to improve to stay on top but they have been getting sloppy while Alphv looks like it added another producing affiliate.

Black Basta, BlackByte, Royal and Play Ransomware deserve mention here as do a few others but my time is limited.


Stay safe.

The Cyber Show, by @AlvieriD


Monday, February 27, 2023

Who Hacked Atlassian?

The Wolf in Sheep's Clothing


Ghosts of SeigedSec


By Dominic Alvieri
February 22nd, 2023




One of the largest companies breached to date this year was carried out by a relatively unknown group, SiegedSec. "Little is known about the Hacking Crew" an analyst said as Envoy and Atlassian blamed each other initially last week. I had questions so I decided to reach out.

The SiegedSec Hacking crew? 


TechCrunch update on Atlassian.
Story by Carley Page and Zack Whittaker



Where did SiegedSec come from?


The leader of the new group called SiegedSec likes to be called Wolf and he came from and still is a member of GhostSec. The leader of GhostSec goes by Seb. Why the separate group? That was one of my first questions besides "the Furry Hackers" comments.

The Wolf in Furry Hacker Clothing insists on maintaining the controversial furry angle through the conversations and updates. Personally I think it is an act to draw attention to important matters like freedoms which have been curtailed all across the globe in the past few years.

It is tough to take this seriously and I have no idea how long it will last but neither group is leaving the scene anytime soon. Hacking Atlassian no matter how will still draw attention to whatever your cause is. This feels like an attempt to capitalize on a situation which other groups have tried to make a huge splash and then pivoting from that initial buzz into the actual or real group.


The wolf in furry clothing.
The Wolf in Furry Hacker Clothing


The Wolf in Furry Clothing


The leader of the new pack


Making a splash after a controversial United States Supreme Court decision last year, little known SiegedSec is back with a breach of giant Atlassian. I caught up with GhostSec to ask why the post was released through their channel and continued to drill down,

Here are some of the specific questions asked and answered over this past week. 


Q-Who is SiegedSec?
A-Seb (GhostSec) SiegedSec was one of my members who decided to do his own thing. He still is a member of GhostSec as well.

Q-Still a member?
A-Yes.

The questions I wanted to know that I can share...


Q-Wolf-The state hacks last year...and why active again now?
A-...not as easy as it seems to quit hacking. That's the way I would put it, hat's why SiegedSec came back

Q-How did you breach Atlassian?
A-Honestly answered and redacted for security and breach confirmed by Atlassian.


Q-Was Atlassian a target?
A-No...

Q-Did you ask Atlassian for a ransom or was it just for shits and giggles?
A-Just for shits and giggles


Q-Any other victims or lateral movement?
A-No answer or evidence was provided.


SiegedSec will be posting on their own Telegram channel



To both Seb and Wolf

Q-Did either of you breach anyone this week?

A-Both "No comment." 



I got the feeling that they both may have.



Q-Wolf or Seb, Is the UWU what I think it is along with the "Furry Hackers"




A-Yes


UWU is slang and loosely described a furry loving or friendly. Lets leave that be for now.


Throughout Wolf insisted upon being and going with the Furry Hacker theme. 

Anything SiegedSec wants to say? Shortened answer

"Just represent yourself and be yourself, be a furry hacker who cares."



GhostSec



GhostSec


Leaving out the basic get-to-know-you hacker exploit talk and the like, I asked questions to both like is either group thinking of setting up a leak site. 

Both have thought about it but not now in the works, at least not officially. 

Speaking with Seb from GhostSec he struck me as being honest in answering  my questions of which I already knew some of the answers. I obviously cannot release some questions asked and answered here but might be conversed...

 qqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqq

...at a bar and not online.

GhostSec Seb


Q-Why Maine?
A-We have nothing against the State of Maine of their people we just happened to breach them.

Q-Any specific targets or breaches you can share?
A-Not at the moment.

Q-What are the odds that LockBit or Black Cat will post while we are chatting?
A-Highly likely lol

LockBit did post a company during the interview.

Q-I wish I could post more of this conversation, Do you have a statement?
A-Shortened Answer-Hack the Planet, if there is no path, create it. Fight against injustice.


Stay safe



Dominic Alvieri on Twitter @AlvieriD



 Dominic Alvieri
Twitter @AlvieriD

Monday, January 30, 2023

Undisputed LockBit

LockBit is clearly the leading group left standing...for now.


By Dominic Alvieri

January 30th, 2023

@AlvieriD 


LockBit is the undisputed number one group.


In the early morning hours of Thursday, January 26th a multi-governmental offensive seized the Hive Ransomware leak site. No arrests have been made in the never ending ransomware whack-a-mole game. LockBit is now the undisputed leading ransomware operation.



Hive Ransomware leak site was seized on Thursday.


That evening LockBit was ready with a new game, comments and plenty of leaks ready to go. The Hive Ransomware leak site was seized early Thursday morning and the first comment or post from LockBit was a freaking game below.


LockBit playing games.

The post above was removed by LockBit. Researchers at VX Underground were able to get a comment from Mr. LockBit about the post and the news that followed. LockBit is one group I do not have communications with and do not care to. 

By Sunday evening it was business as usual as LockBit posted affiliate offerings of 14 new victims not willing to pay them from around the world. 


14 new companies ransomed by LockBit.

Spain

France

Mexico

Austria

Albania

Portugal

Australia

United States

United Kingdom


LockBit KVIE post.

Air Albania ransomed by LockBit.


Low lights from the new posts include PBS member television station KVIE in Sacramento, California, Air Albania, CPL Industries...



PBS station KVIE ransomed by LockBit.

 

LockBit is clearly the top operation remaining and is arrogantly making it known. Alphv Black Cat Ransomware is behind LockBit and there is a clear distinction from the remaining groups including new up and coming Play Ransomware, Black Basta, Vice Society...


Several other groups and former members are not included in this article including Black Matter, DarkSide and the other variations, spinoffs and new groups pending like Endurance Ransomware.


No Hive arrests to date.


Affiliates have to go somewhere...





The never ending ransomware whack-a-mole game continues in 2023.

The Cyber Show

The Kremlin, Politics and Ransomware

Qilin Ransomware caught with politically motivated fake document (and old data) in post. by Dominic Alvieri March 8th, 2025 @AlvieriD Was it...