Showing posts with label ransomware. Show all posts
Showing posts with label ransomware. Show all posts

Saturday, March 8, 2025

The Kremlin, Politics and Ransomware

Qilin Ransomware caught with politically motivated fake document (and old data) in post.


Qilin Ransomware

by Dominic Alvieri

March 8th, 2025

@AlvieriD

Was it a breach or not?

The Ministry of Foreign Affairs of Ukraine was breached...in 2022 which is not what one devious up and coming ransomware group would like you to think. The post below is from Qilin Ransomware. 


Ministry of Foreign Affairs of Ukraine.
Original Qilin Ransomware MFA of Ukraine post.

Did the Kremlin Call?

Qilin shuffled document samples for the first 10 minutes after their MFA of Ukraine post which peaked my interest. Originally listing 82 samples (the first 12 I retrieved and verified) then 31 and finally 104 if that hasn't changed.  I regularly go back and check for updates and double check my research but it is usually the deletions that catch your eye. Most of the data samples are from 2022 or earlier. Qilin did release samples dated in 2025. All but one was removed which is one of the dozen I already had.


The only sample dated after 2025 is fake.


The document references a January 31st, 2025 missile strike by Russian troops at the Bristol Hotel in Odessa, Ukraine. Have I mentioned that I hate politics? The fake document is signed by an official who has never been an ambassador of Ukraine to Moldova.

All of the remaining documents are dated between 2019 & 2022 which were previously leaked in 2022 on Telegram after a  breach of the MFA of Ukraine in that year.

Most of the majors players have made some political reconfirmations recently


I've actually always hated politics and this has the big stink of a political pressure move.

RansomHub also recently released a tox profile message stating never to target CIS states. LockBit loves Trump and has said so and posted several times. Once again hate is a strong word but...



Can you do me a favor...




Stay safe online and off.

Wednesday, June 12, 2024

How I Hacked Your Mother

Did you know I can hack you from several yard sale items?


by Dominic Alvieri
June 12th, 2024


How I Hacked Your Mother, by Dominic Alvieri



Can You Help Me With My Smart Dryer?

Kids did I ever tell you how I prevented your mom from getting hacked?

Cybersecurity articles are either way too technical or way too simply not containing any concrete or actionable information the average person can utilize.

In the simplest terms any device that has been connected to the internet will leave a digital trail and be left stored in that devices memory. They don't just magically disappear...you have to remove them.


It can without wiping your old IoT device memory.

A Simple Question Asked and Not Answered

Whenever you dispose of any IoT device what must you do with the devices memory? 

36 out of 36 random people that I asked this question to failed to answer it correctly. You must successfully wipe clean your old device memory before selling or disposing of the device. Not one of the 36.


The Cyber Show

***Important Disclaimer***

A proper forensic investigation should be done on a copy and not the original to avoid chance of corruption or tampering and it is usually copied as an image and then added as a data source to investigate further depending on the tool you are using. Please do your own research on how to properly conduct a forensic investigation but that is a key principle to strictly adhere to.

Secondly just to be safe I am leaving out the brand names of the devices researched. Remember that any device that connects to the internet will leave a digital trail. The credentials don't just disappear. 


Smartphone, Tablet, Camera, Printer...

I was driving around the other day and saw a yard sale sign and looking for a few things.


The Yard Sale Hack

How is Your Smart Washer Connecting to the Internet?


The Yard Sale Hack

It didn't take long to see an old Android smartphone and a printer for sale. I asked the owner if she new that I could find all types of credentials and data left if she didn't clean the memory from her devices. She didn't know how to respond. I explained the research I was doing. She said she deleted all the photos on the phone so she was ok. ( yikes! ) I explained how to properly dispose of any IoT device. She agreed to the sales and research. I returned the devices in a few days and revealed my findings.


Digital Forensics


I've been hacking and breaking things for a long time but I also track and trace cyber criminals & cryptocurrencies and forensically go over all types of devices. Autopsy is one of my favorite tools but I use several depending on what type of device ( desk top hard drive, smartphone, printer, etc.) I am going to go over and what I am looking for. I used several tools and addons for this project so I won't bore you.

Different devices have different types of memory. The hard drive in your computer is obviously different from the memory and storage in your smartphone. That is a blog for another day. 

It's All in the Credentials


In short the printer had her Wi-Fi credentials in plain text and the smartphone had a treasure trove of information that could be used against her. I agreed not to expose any personal details except for the minimal details that we agreed upon so sorry no redacted screen shots.



                                                                       Sample of Autopsy

How I Prevented Your Mother From Getting Hacked


What is the Best Thing to do When Disposing of an IoT device?


The best single piece of advice when getting rid of old IoT devices is to wipe clean your old IoT device memory. Every single IoT device. It is just that simple. Your can remove and destroy the storage media which also works but isn't very practical with smartphones.

How?


Again in simple term depending on the type of storage media there is professional software like Eraser or other commercial tools available. For all other devices such as printers, assistants and other non-smartphone type devices they will have instructions usually in their settings and should be a factory reset as a worst case minimum.

 Check your devices manual and carefully go over their instructions. 

Stay safe online and off. 

Wednesday, April 10, 2024

Typosquatting with Mikhail

The Infrastructure Boss


by Dominic Alvieri
April 10th, 2024




What does a former Boris Yeltsin era Defense Minister for the Russian Federation have to do with cybercrime and ransomware today?

Since early 2023 I have been tracking a cybercrime infrastructure that now accounts for over 800 phishing websites pretending to be banks, software companies and cryptocurrencies deploying malware and dropping crypto stealers.

All of the 800+ phishing sites have two things in common. They are all registered with NiceNIC.NET and the WHOIS registrant organization is "Mihail Kolesnikov." 

Several countries of origin are used including Belize and Belgrade. A few websites were also registered under the correct spelling of Mikhail with the vast majority registered as "Mihail."

Hunters International is the latest ransomware and data extortion group to join.


Hunters International


Several of the websites were deploying bumblebee malware along with various stealers. Redline stealer and new versions of Rilide and Fletchen stealers. 

A quick look - Fletchen stealer features some of the same wide array of malicious activities as other stealers including credential theft, Wi-Fi login details, browser history and cookie retrieval along with several crypto clipper options. 

Fletchen stealer is written in Rust with simple panel access and is easy to navigate but script kiddies beware, you need technical abilities to encrypt the stealer.exe file.








Hunters International registered their clearnet leak site with the registrant organization of Mihail Kolesnikov in January of this year.



WHOIS data from Hunters International


All of the malicious websites have been registered since 2022 and continue under the typosquatted registrant organization of Mihail Kolesnikov. 



Typosquatting Mikhail.




Clippers replace the destination address and replace them by generating a corresponding address with Fletchen stealer (pictured below) currently stealing Bitcoin, Ethereum, Litecoin USDC, USDT even Dogecoin and other cryptocurrencies.

"history",
"webRequests",
"tabs",
"clipboardWrite",
"clipboardRead",
"management",
"<all_urls>"
],

Fletchen Stealer

Former Rilide C2 domain /silent-scale.com

A full report will be out in the month or so detailing the Chinese registrations and Russian C2's associated with all of these "Mihail Kolesnikov" websites and malware.


The Cyber Show, by Dominic Alvieri



Dominic Alvieri
X @AlvieriD



Monday, February 19, 2024

The Part Timers

The Part Time Ransomware Groups.


by Dominic Alvieri
February 18th, 2024



It seems like everyone is attacking critical infrastructure these days. There are several nation states and 12 current active ransomware groups that have attacked critical infrastructure around the world. Here are 7 of the 12 active ransomware groups:

ALPHV BlackCat
Black Basta
Hunters International
LockBit
Play Ransomware
RansomHouse
Rhysida Ransomware

Can you name any of the other 5?

Remember the dentist/part time ransomware operator?


There may be another dentist deploying ransomware. Or maybe even a slick lawyer. The rash of bad actors attacking critical infrastructure has to be dealt with immediately. 

Who are these part time ransomware operators and why we should make examples out of them? Tracking several of these groups and I can safely say it wouldn't take long to take down at least 2 of the 5 groups I mention below. I predict that at least one of the groups listed below should be comfortably viewing life behind some cold steel bars sometime this year. 

Attacking critical infrastructure should be heavily penalized and actors jailed for so long that it should never cross the pea brain of any ransomware idiot. 

What is a part time operator?


A part time ransomware operator attacks and posts fewer than about 8 victims per month by my definition and for the purposes of this analysis and article. The part time operator more than likely has another job and or profession in addition to breaching companies. 

Cuba Ransomware would be a perfect example but exempt from this discussion due to their backing which is fairly safe to say it stems from the Russian Government and has nothing at all to do with Cuba.




Who are the part time ransomware operators?


Qilin Ransomware

Infrastructure breached - Electric utility


Qilin started quietly on the ransomware seen in 2023 but has ramped up and is set to graduate to a full time operator. Business is good for Qilin who breached and evidentially negotiated with Electric Power of Serbia posting and removing the utility serval times before finally leaking them.

Qilin appears to have quit his day job and about to deploy ransomware full time. 17 posts year to date thru 6 weeks of 2024. 


Qilin Ransomware.





Lorenz

Infrastructure breached - Hospital




Strictly business includes critical infrastructure.

Lorenz is a classic part time operator. A dentist? Probably not. Lorenz has more technical skills than some of the other part timers. I could write a whole other article about Lorenz but let me just say for the purposes of this topic that Lorenz has also breached critical infrastructure in Cogdell Memorial Hospital.

Daixin Team


Infrastructure breached - Hospitals, health networks & water districts


Daixin is the worst of the part timers. Daixin is not a dentist, not by far. I would define the group as the state sponsored nasty version of Cuba. I say this with a moderate degree of certainty from some of their TTPs. Daixin has the most experience and is probably the most likely to continue to cause havoc of any group on this list. 

A majority of the Daixin Team attacks have been against critical infrastructure.

Here is a visual snapshot of Daixin critical infrastructure attacks:




Fitgibbon Hospital cyber attack.


OakBend Medical Center cyber attack.


Meow Leaks (seriously)

Infrastructure breached - Hospital


Meow Leaks breached Vanderbilt University Medical Center and Hospital early in 2023 before they created their leak site later in the year. It is difficult to take a group calling themselves Meow seriously but they have attacked critical infrastructure and eventually I will take a deeper look at the group.


Vanderbilt Health cyber attack.


Money Message

Infrastructure breached - Hospital


Anna Jaques Hospital cyber attack.

The Money Message group came on the scene in 2023 and joins the not so famous list by breaching Anna Jaques Hospital. MM also breached a major dental company in 2023 so this may not be the first or last venture towards critical level companies. 

Money Message is trying to stay quiet behind the scene but they are now on radar.

Something has to be done.

Examples have to be made of these bad actors otherwise every pimple faced ransomware wannabe may start attempting to attack critical infrastructure. That will not end well.



The Cyber Show 

Dominic Alvieri

X - @AlvieriD 

Sunday, August 13, 2023

Ransomware Groups May Soon Get Their Hands on Your Fingerprints.

You have to give us your fingerprint


By Dominic Alvieri
Aug. 13th, 2023



Give me your fingerprint or you are fired.


"You have no choice, the company is switching over."


Imagine being forced to give your biometric fingerprint away to third party. Now imagine your employer mandating this and you having no choice in the matter? Well imagine no more.

Meet the Kronos Biometric fingerprint time clock. Can you guarantee that my biometrics are safe. Where is the security answer please? 

I am so opposed to this and I can't do a thing about it. Being forced does not constitute consent.

For the record I object again. 




Which finger?


 Point in fact Kronos settled a lawsuit in 2022 stemming from their data breach in 2021.

Millions of workers are being forced to hand over their fingerprints. There is no consent. You are required to abide by company rules and companies are switching over to fingerprint readers because Kronos is switching over to biometric time clocks. 

Period. You have no choice. Once again I am so against this.






Fairly soon ransomware groups may be able to get their hands on your fingerprints.

I cannot state this point any clearer, you have NO choice except to clock in with your finger. 

I am strongly opposed to the forceful relinquishment of and collection of biometric data

Stay safe.





Dominic Alvieri

@AlvieriD

The Cyber Show 

Tuesday, June 13, 2023

The Mushroom Policy

Is Obstructing Security Obstructing Justice?


by Dominic Alvieri
June 13th, 2023

Mushroom Policy. 


What does a mushroom have to do with cybersecurity?

Let's put a name to what has been going on in the corporate world regarding ransomware attack communications. Yes, I said ransomware. The Schneier Blog just put out an excellent short blog on some of the legal tactics behind some of the recent delays for incident responders and security efforts.

How does one grow mushrooms? 

If you know how to nurture mushrooms you're wanted in corporate public relation departments around the globe. In most cases to grow mushrooms you to keep them in the dark and feed them a lot of crap. Literally that's all you have to do. Very much like the lawyer-fed communication orders given to PR rooms to disseminate lately.

"to grow mushrooms you keep them in the dark and feed them a lot of crap."


In many cases I don't believe that every company would come forward if samples, flashes or exfiltrated data itself didn't leak out. Many companies wouldn't say a word about it. After being confronted several companies have come forward with vague crafted statements months after the fact. Truth be told sometimes it does take some time to do a complete forensic investigation. 

Don't mention or use the word ransomware, say cyber incident. It sounds better. They didn't name names.

The Ostrich Policy

You could just bury your head in the sand and hope it goes away.


Employees of Highland Homes in Texas have reached out in April saying that their bosses kept denying the Alphv BlackCat posts claiming that they breached the company. BlackCat finally dumped alleged company data a few weeks ago in late May.



Accountability

If you are going to make money off of my data you have to protect it better. Stand up a be the good corporate citizen we always hear about.


Stay safe. 

Dominic Alvieri 
@AlvieriD

Wednesday, May 31, 2023

Cracking the Connected Floor

Analytics and Cybersecurity 


By Dominic Alvieri
May 23rd, 2023



This KPI Isn't Pointing in the Right Direction

Fortune 500 companies are expanding their attack surfaces in a new data analytics push.

Cybersecurity takes a back seat for data analytics in a manufacturing executives dream which is turning out to be a security nightmare. It's called the connected shop floor and in this current version isn't going to end well. Corporate executives are unintentionally and unnecessarily exposing themselves to unnecessary risks. 

"This is largely driven by connecting machines using IoT and enabling Ai to digitize the results"

Apple iPads and Microsoft Bi along with several outsourced apps and technologies are involved.




100's of new endpoints and unrestricted devices 


All employees who have access to these new IoT devices running the backbone of this technological shop floor had open browser access and email capabilities. Personal emails as well as corporate and a host of new apps and software.

Oops, an employee just clicked on one of their personal emails and got phished.

Before drilling deeper into the technologies and possible exploits available for a starter there are hundreds of new IoT devices with an unrestricted browser able to view porn, YouTube or TikTok videos. A small time phisherman with a low grade infostealer may unknowingly get access to a Fortune 500 company employee and not even know it. 





The good news

Executives are starting to learn about cybersecurity. The bad news? They are slow and stubborn.

Here is a no brainer-restricting employee browser access.



App Avalanche


Once again executives are slow in embracing cybersecurity. They need the numbers to crunch to squeeze every last ounce of shareholder value that you can. Security often takes a back seat.

"Cybersecurity does not add revenue" one executive told me on the condition of anonymity. 






Exploitable


Querying one of the apps being used in one version of the connected floor returned an interesting response resulting in an error in my SQL syntax. Input sanitation issues are red flags indicating injection flaw exploits. 

Obviously I am unable to mention the firm or app until the issue is resolved. 

There are other exploitable alleys in this project.


The Deeper I Drill...

I have not received  any responses to my questions regarding the above mentioned security issues along with an uncovered topic. 


I am offensive in nature even in a defensive posture.
...

There are more holes in the floor.




Sunday, April 23, 2023

Top 10 All Time Active Ransomware Groups

 The Current Top 10 Active Ransomware Group Post Count


By Dominic Alvieri

April 23rd, 2023

@AlvieriD


Top 10 All Time Active Ransomware Groups


Quantifying ransomware group activity over the past few years there is no doubt that LockBit is the numerical leader all credibility issues aside. LockBit averages posting over one company per day since their initial formation as ABCD. No one else comes close. 


Conti members are still around but this list comprises of active groups with quantifiable active leak sites.


The top 10 active ransomware groups.

@AlvieriD


Posts that are somewhat quantifiable...


What is included in the numbers? Posts like the recent LockBit Dark Trace-Dark Tracer fiasco or their goofball post that was removed are not included. Neither are posts like the BlackCat NCR flash cyber incident that is still ongoing. 






Up and Coming Groups


The top groups to watch gaining traction are Royal and Play Ransomware. Play will be in the top 10 within the next month if current trends continue. Royal should be in the top 5 by summer.




New groups in 2023


Several new groups have arrived and in the case of Trigona, re-arrived. Money Message sans logo or not should be near the top of the new groups to watch list. Here are a few other new groups to watch:

Money Message
Trigona Ransomware
Cipher Locker
Akira Ransomware
Cross Lock Ransomware
Dunghill Leak...


Trigona Ransomware.


Cipher Locker ransomware.

Akira Ransomware.

Cross Lock Ransomware.


Dunghill.

Dunghill Leak is literally named after a pile of shit. What will they think of next.

Most Dangerous Groups


In my view Alphv BlackCat Ransomware and LockBit are fairly close in the top of this category. BlackCat has the ability to pivot quickly once in a network and LockBit is always trying to improve to stay on top but they have been getting sloppy while Alphv looks like it added another producing affiliate.

Black Basta, BlackByte, Royal and Play Ransomware deserve mention here as do a few others but my time is limited.


Stay safe.

The Cyber Show, by @AlvieriD


The Kremlin, Politics and Ransomware

Qilin Ransomware caught with politically motivated fake document (and old data) in post. by Dominic Alvieri March 8th, 2025 @AlvieriD Was it...