Showing posts with label trolls. Show all posts
Showing posts with label trolls. Show all posts

Friday, March 11, 2022

The DarkWeb is Pretty Bright on Telegram and Twitter

Dark net services displayed on social media.


By Dominic Alvieri

@AlvieriD

3-9-2022



More and more services and communications that were once reserved for the deepest depths of the DarkWeb are crawling up the stack, if you will to social media platforms. Ransomware group posts are now mainstream on Telegram and Twitter with calls for action, mis or disinformation and fake data leaks.

The hacking free for all


The Russian invasion of Ukraine on February 24th brought about armies of hacktivists, some real while the majority are unskilled and caught up in the wave. Legitimate groups like LAPSUS have taken to social media to announce high profile breaches from Samsung and Nvidia while other groups pretend to have hacked the world.

IT Army of Ukraine

The IT group turned army calls on users to for action providing details of direct targets the group requires taken down. More and more the IT Army of Ukraine posts targets in English and Ukrainian.





Network Battalion 65' posted a fake leak that was so embarrassing for the group but yet they post again. Not shown.


Network Battalion 65'



Like many groups constantly changing members. Brief synopsis is that the group revamping after a fallout and fake Kaspersky leak attempt. Keep an eye out.

Outrageous breach claims have been the norm. Unverified claims ranging from The National Bank of Russia to the FBI itself have been hacked. Hack the Planet until there is nothing left. Peak infosec I believe it was called. Thanks Carl.

Epic leak fail award goes to Network Battalion 65'


Right now this is a black eye that needs to be addressed. Kaspersky itself is facing intense pressure from security staff but this data breach was confirmed fake.


Kaspersky fake data leak.


Kaspersky has issued an official response courtesy of @ajvicens



Kaspersky official response to March 9th NB65 breach claim.

GhostSec

GhostSec like many malicious groups has several channels. IntelGS is Intel GhostSec a darker splintered part of the group that has also joined in the cyber war.


GhostSec


GhostSec channels appear to be currently fragmented and not coordinated.




Lapsus$


After two successful high profile leaks of Samsung and Nvidia last week LAPSUS is toying around with an anonymous poll when allegedly they have already breached Vodafone.

Mercado Libre just disclosed a breach on their latest 8k release this week with the Securities and Exchange commission. Mercado did not release a timeline or provide more vector details at this moment. 

Impresa the Portuguese media giant was hacked by Lapsus$ over the new years holiday and has had several website and platform issues ever since. The main Impresa website /impresa.pt has been down and is currently down as of March 11th, 2022.


Impresa of Portugal hacked by Lapsus.



Lapsus$ is seen toying with companies they have already hacked and allegedly hacked. Vodafone is unconfirmed at the moment.



LAPSUS Vodafone breach claim.


Groups regularly post claims and recruit people of all types. Anonymous groups large and small have taken over social media with misinformation and disinformation campaigns creating profiles, hashtags and using automated software and bots to promote their goals.

Videos and photoshopped imagers are the norm. 


IY Army of Ukraine post.


Against the West / Blue Hornet


The group appears to be restructuring and has been quiet this week as of last check. Like all groups use caution so that you don't get stung.


Against the West.

Trolls

Don't waste your time.

Stormus group tops that list. Others come to mind.

Verify any information or disinformation before you respond in any way, if at all.



Gazprom alleged data leak on Telegram




Lapsus$ live post as I blog taking credit for Ubisoft hack and advertising The Verge article about it on one of their channels.


Ubisoft hacked by Lapsus$


Lapsus$ appears to have several flaws, youth, inexperience in several key areas, smashing and grabbing what they can, the group is buying inside access from either an employee or vendor and then getting to work. Access is usually gained through a VPN or AnyDesk remote control application, recon, targeting and then deploying payloads. Social engineering methods and other low grade tactics.

Check your employees and vendors.

Currently advertising for services now.

Updated: 7 members of Lapsus$ have been arrested aged 16-21. Other members are still at large and doubtful ring leader or mastermind is teenager arrested in Oxford, England as media claims. I do not believe that to be true. There are more members at large. To be continued...


Lapsus$ advertising for hackers.

Conti

Still alive and kicking albeit smaller and segmented. Looking to reform in Russia.

Samsung Leak

Lapsus$ again.



LockBit has just allegedly leaked several companies from Singapore, verification pending. LockBit has been very active in the past 30 days. Lapsus has a mock vote due this weekend to leak another high profile company and I'm sure they will be plenty of fake anonymous group claims. 

There are other groups but this was intended to be a brief account.  
Stay safe.




Dominic Alvieri

Twitter @AlvieriD

Tuesday, February 22, 2022

Banking and Crypto Stealing 2FA Bots on Telegram

Telegram Channels are Behind Evil New Ways to Separate You From Your Money


By Dominic Alvieri


2-22-2022



Telegram has had a history of security breaches, bad actors and security issues for several years. More and more malicious actors are using the platform along with 300 million others. Recent examples during the Russian invasion of Ukraine are showing an accelerating trend of cyber activities on the platform including the SberBank breach disclosed below.


SberBank breach files.

Other recent troubling requests




The Telegram mobile protocol MTProto protocol is proprietary and has had security questions for years. Cryptographic issues aside the desktop version does not use the protocol and storers all data in plain text. Plain text is also an issue with the mobile virtual cloud set up. 

In simplistic terms all data is stored on Telegram servers and not end to end encrypted (e2ee) by default. There is a secret chat option that does but that is another story. No e2ee by default leaves millions at risk from an advanced attacker. 

The current state of the gram


Underground forums and marketplaces are nothing new for a bad actor looking to score some low grade malware, stolen credit cards or a phishing kit. No need to fire up the TOR browser now because these items are becoming more mainstream available on the web and malicious Telegram channels.

OTP 2FA password stealing bots are being packaged with hand selected robocall features like foreign language accents to target customers of specific countries. Two if these bot services have been verified as working account stealing bots and recent reports of usage and abuse has been reported.

New set language feature   /setlang   



Set language /setlang


Bank of America, Chase and Wells Fargo are among the banks that these bots works with stealing your one time password or 2FA login. Several cryptocurrency platforms are also being marketed with automated bots and classes.





Several channels are selling various One Time Password (OTP) and 2FA stealing bots. Having verified two of the products here is a breakdown of some of the malicious capabilities.

Packages are readily available for Apple Pay, banks, crypto....



OTP 2FA Password stealing bots


Vendor P above has been active in advancing the bots attack capabilities in the past week adding Bank of America and Chase to their hackable list. Security support teams at Bank of America, Chase and Telegram have been notified. 




Here is what the bot can do. The ability to go after anyone with just the minimum information that would be needed to carry out this attack is worrisome. Basic OSINT research. 

As simple and annoying as this scam is the technology behind the maliciousness does work.

Enter target data, select a few options and assets to acquire and the nightmare scenario begins. Like most malicious activities they do require at least one action from the target, barring a zero-day, zero click exploit.

Video snapshot of working bot in action





Robocalls blanket the target with messages of an account breach and that verification is needed. An extreme sense of urgency is created and conveyed in the robocall accent of your choice. The artificially curated voices of the bot repeatedly mention your account is at risk and require you to verify your account via an OTP or your 2FA verification.

Partially redacted for security.

Everything is the same as before...





We have come along way from just unlocking iPhones.



What else can this bot do?


New functions which have just been posted and untested include bypassing:
-Authy
-Google Authenticator
-Microsoft Authenticator

Several variations of the original bot are online and to no surprise many claims are stretched and many are just outright frauds.






Relentless requests are the first step and if entered, the near-instant theft takes place. When a verification code is entered the bot executes the code, enters the account and transfers all of the cash or cryptocurrencies out of the account within minutes. In this live research example a crypto account was used and emptied within 2 minutes of the final string of data obtained by the bot. Crypto firm name withheld. 

Several other options are available if the first level attempt via robocalls fail to capture the required codes. These are actual working multifaceted bots able to spear or whale nearly anyone.

What can you do? DO NOT INTERACT

Do not interact with any SMS, email, link or call regarding your breached accounts. Always go directly to your real account through and official site or representative.

Go directly to any account in question and the official site and or contacts and avoid any "urgent need" to give your information to anyone. Chances are you haven't been hacked but someone sure is trying.



The Cyber Show
by Dominic Alvieri

Twitter @AlvieriD

Monday, September 27, 2021

Social Media Accounts For Sale

Twitter Account with 185k Followers or an Instagram Public Figure with 90k for Sale


Social Media accounts for sale.

Social Media Accounts Caught for Sale

September 27th, 2021

By Dominic Alvieri


Several new social media accounts have been unveiled and are currently being offered for sale online. This isn't taking place on the DarkWeb but right here on the ClearNet. One Twitter account with up to 185k followers is for sale. A Facebook fans page and a YouTube channel are also available. Topping the intrigue list is the public figure Instagram account.

185k followers


185k Twitter followers for sale.

Twitter account for sale.


Newly created TwitterSale[.]com obviously not related to Twitter has offered social media accounts for sale.








Instagram public figure social media account names don't match


Twitter, Instagram accounts names are different

 Instagram account offered


Instagram public figure account offered for sale.


A Facebook fans group page and a YouTube channel by the name of Dj DangDut (unavailble) offered. This site has offered a meme or cartoonish account for sale as well.



Associated to this Twitter profile




How important are followers?

I have 90 followers on Twitter and reporting a fake account for sale with 90k followers. How important exactly are followers? This is a great time to bring up the fake infosec Twitter female account that had 50k followers. Theses accounts are around. Don't automatically dismiss a small account or validate a larger one just by the followers. Remember I have 90 followers. 

As of press time the site "Twitter Sale' is still active. 






The Cyber Show by Dominic Alvieri
Twitter @AlvieriD

Not on Facebook

Thursday, October 22, 2020

How To Spot a Troll

 Be on the lookout for Trolls.

Watch out for Trolls


With the political season in full swing and a sprint towards the end with the final debate tonight, be on the lookout for political trolls. Trolling will still be active in many different forms after the election. 

Common troll actions online or off are similar in malicious nature and one sided. Do you really think a person who will knock you over for a cab be a pleasant person online? Someone cut you off on the road and give you the finger? Very thoughtful and caring and no doubt similar in their online persona.

How about someone following you walking all the way home filming all the way to your home address and network? That actually happened to me and in the last 50 yards I turned around and let the expletives fly.  Common little items you may notice in a person can be hidden and multiplied online.

You can be trolled online and not even know it.

Many social sites let you peruse account activity without becoming a member, albeit with restricted messaging privileges. Someone can be trolling you right now as you read this.


Is this a political only account?
Is this a political action account?

Several accounts have been set up online on multiple platforms as political only accounts, meaning they only conduct self serving politics. Building followers some real and some fake along the way.
Can this action figure above be a real person or a person hiding with an ulterior motive?

Pattern analysis can define the account better than the person hiding behind the account. Patterns will reveal hashtag creations and associations that the person thinks they are masking with layers of malicious similarity. Lets get this person 10,000 followers, or attempts to attract others and link more fake accounts to show a social power and strength. 

Account layering is now becoming common practice as many bad actors attempt to gain leverage to sway and disinform. 

The new online version of the old game is now called whack a troll. They are seemingly everywhere. 

Join our cause...please.


Old account becomes active for the election
This account became active just in time for the election.


Russia and Iran have interfered to date with this current election process, as per the FBI. 
Many more attempts are likely before and during the election. This election has been the most challenging to date and no doubt foreshadows more difficulties in upcoming elections. 

Old accounts that are now becoming active are another give away. Sole purpose accounts with fake groups and followers have been proliferating online for years. Some repackaged, others retooled but all share the common traits of sole purpose posting, tweeting and blogging to attain a political goal. 

Can there be hidden financial agendas as well?

What about other hidden agendas?


New FBI warning for all.
New FBI warning.



New dangerous versions of trolls have been appearing online with different dangerous motives. One deceptive troll tactic is to fake a common friendship or association. So and so from xyz group gave me your name. Trolls come with many hidden agendas and dangerous forms. 

The FBI has recently confirmed an alarming social trend in other dangerous trolling incidents.

The time is now to be informed abut the dangers and the many different varieties of trolls online. The troll can be after your ID, finances or family. You have every right to protect yourself. You also have the right to know who and what you are protecting yourself from. The person or entity behind the actual account attempting to cause harm.

Be careful and informed of the dangers. Monitor, educate and inform. The dangers online and off never take a break and are evolving at a rapid pace. Be proactive and not reactive. 

There are new avenues of danger possible at every click, text, email or post. 

Cybersecurity Awareness Month is October. Stay safe and be cybersecurity aware everyday.


By Dominic Alvieri




@AlvieriD
Analyst, Researcher and Tracker.

The Kremlin, Politics and Ransomware

Qilin Ransomware caught with politically motivated fake document (and old data) in post. by Dominic Alvieri March 8th, 2025 @AlvieriD Was it...