Dark Web Digest – November 2024 Edition

Dark Web Digest - November 2024

Setting foot in November 2024, the journey along the dark web is still ongoing, full of dangerous activities, and unknown threats. In this month, we see the climbing of some cybercriminal activities, which are now based on technical strategies and the distribution of dark web marketplaces. With an estimated 2.7 million attendees, the dark web continues to be the spot for illegal goods and services ranging from drugs and stolen data forums despite both being prosecuted. Recent reports show that Germany has overtaken the United States in the number of Tor users, clearly indicating the shift of users’ characteristics and behaviors on the dark web. 

In this article, we will be taking a deeper look at the dark web by exploring the latest statistics, trends, and notable events both from national and international levels in November 2024. We’ll consider the most renowned marketplaces, analyze recent cyber incidents and talk about how the movement affects cybersecurity worldwide. Come along with us as we escape this shadowy world where anonymity dominates, and illegal transactions experience a high rate of growth.

Bohemia and Cannabia Dark Web Markets Taken Down After Joint Police Operation

The Dutch police have announced the takedown of Bohemia and Cannabia, the world’s largest and longest-running dark web market for illegal goods, drugs, and cybercrime services. The move is part of a collaborative investigation with Ireland, the United Kingdom, and the United States that began towards the end of 2022. Bohemia served 82,000 ads worldwide daily, with about 67,000 transactions taking place each month. In September 2023, the estimated turnover was €12 million.

The Politie reported that at least 14,000 transactions took place from the Netherlands with a value of at least 1.7 million euros. The police were able to identify several administrators and arrest two suspects, one in the Netherlands and the other in Ireland. Additionally, two vehicles and cryptocurrency worth €8 million were seized.

Dutch Police

The dark web is not as anonymous as users may think, and due to international cooperation, the credibility and reliability of these markets have been severely damaged. Ukrainian authorities have arrested a 28-year-old man for allegedly operating a virtual private network (VPN) that allowed people within the country to access the Russian internet (Runet) in violation of sanctions. The service had more than 48 million IP addresses and was launched by an unnamed self-taught hacker from Khmelnytskyi in the aftermath of the Russo-Ukrainian war.

The recent developments follow the sentencing of two individuals affiliated with a Russian threat group called Armageddon to 15 years in prison in absentia for carrying out cyber attacks against government entities in the country.

Some 10 Million stolen user accounts from Mideast on the dark web

Kaspersky’s Digital Footprint Intelligence (DFI) team discovered and analyzed almost 10 million records of stolen user accounts in the first half of 2024, most prevalent in Egypt, Saudi Arabia, and the UAE. The report revealed a complex web of cyber threats targeting organizations in the Middle East, with the main dangers being organized ransomware groups, ideologically motivated hacktivist activities, entry points into corporate networks, and info stealers.

Ransomware groups have become more structured, targeting the UAE and Saudi Arabia. The public sector, construction, and business services industries were among the top targeted industries. Hacktivists are becoming more destructive, shifting attacks to more critical outcomes such as data leaks and organizational compromise. Kaspersky DFI researchers observed over 11 hacktivist movements and various regional actors.

Middle East - Data leak

A key target for cybercriminals is entry points into corporate networks, exploiting initial access to more significant criminals who can further develop the attack. They discovered over 40 dark web adverts offering corporate access to government, education, manufacturing, transportation, financial, healthcare, IT, and other regional corporate organizations.

Stolen data and documents are being shared or traded on multiple publications, which can be used to commit fraud, from spam to blackmail, and targeted attacks using victim profiling. In H1 2024, cybercriminals leaked 125 corporate-related databases in different industries, with Saudi Arabia, Iraq, and Egypt experiencing the highest number of data breaches.

Vera Kholopova, Senior Analyst at Kaspersky Digital Footprint Intelligence, stated that cybercriminals are perfecting existing methods and developing innovative tactics and tools to infiltrate their victims. Vigilance is essential to safeguarding organizations’ network infrastructures from various threats lurking in the dark web.

Hoax threats to airlines: Police suspect use of VPN or dark web

Investigators are investigating bomb threats on various airlines, suspecting that a VPN or dark web browser was used to set up accounts on X. Police are trying to retrieve their IP addresses by contacting social media platforms. The initial probe points to the role of a teenager in creating one of the accounts that posted the threats. Police have also approached social media platforms to suspend the handles that posted threatening messages and asked them to remove the posts. FIRs have been registered regarding the bomb threats. 

Airport police have addressed eight bomb threat incidents this month, confirming all as hoaxes after rigorous verification and inspection. On Wednesday alone, three Delhi-based flights received bomb threats, causing panic among authorities and passengers. A bomb threat was received concerning a Bengaluru-bound Akasa Air flight carrying 184 passengers, which forced it to return to Delhi. A bomb threat assessment committee was convened, and a bomb threat assessment committee was convened. Police are holding perpetrators accountable, safeguarding passenger well-being, and maintaining seamless airport operations.

Fortra Report Reveals Surge in Domain Impersonation, Social Media Attacks, and Dark Web Activity

Fortra’s Q2 2024 report reveals a rise in digital threats, including domain impersonation attacks, phishing sites hosted on Legacy Generic Top-Level Domains (gTLDs), and the rise of new gTLDs like.dev.vip, and Russia’s.ru. The report also highlights a 60% increase in brand attacks per month, with an average of 138 attacks per month in Q2. The rise in social media platforms, particularly among younger demographics, has amplified the threat surface, making detection and monitoring critical for organizations.

Counterfeit websites targeting enterprises surged by over 50% from the previous quarter, with brands experiencing an average of 11 attacks in May alone, an 18% increase compared to April. These counterfeit sites often mimic reputable brands to deceive customers and expose them to security risks like malware or phishing attempts.

On the dark web, 93.8% of threats revolved around credit card data and fraud tools, with fraud tools emerging as the fastest-growing dark web threat. Most stolen data is sold through carding marketplaces and chat-based services, making the dark web a critical avenue for threat actors looking to monetize stolen information.

In conclusion, the report highlights the growing threat landscape and the need for security leaders to implement proactive measures to mitigate risk.

A teacher lost life savings after a hacker bought his identity on the dark web for $10

A 27-year-old science teacher, Matthew Shaw, lost £3,500 in savings after selling his identity on the dark web for $10. Shaw, who was on holiday with his wife Davina, received a notification stating he had just paid £3,500 for a hotel room. He immediately called First Direct, who informed him that someone from Romania had opened an account in his name with a digital financial services company called Monese. The scammer linked Matthew’s details to his First Direct account to pay for a hotel.

Matthew Shaw

The £3,500 transaction left Matthew with only £20 in his bank account, and the couple had to end their holiday a week early. Matthew praised First Direct as “brilliant” and fortunately, the money was refunded a week later. Despite tightening his personal security details, Matthew still receives at least six or seven email notifications daily asking him to approve unauthorised sign-in attempts.

Matthew described himself as tech-savvy and had different passwords for all his accounts. He regularly changed his email address and did not think he was vulnerable to identity theft. After a week, the £3,500 payment was refunded to his First Direct account, and he was impressed with how the bank handled the case. He was placed on a 12-month fraud prevention program, which required him to go through rigorous processes when making large transactions, obtaining loans, or setting up new accounts or credit cards.

College student who took job on dark web arrested for attempted robbery

A 23-year-old college student, Masaki Saen, was arrested in Mitaka, western Tokyo, on suspicion of trespassing and attempted robbery. Saen admitted to the allegations, claiming financial difficulties led him to his situation. 

He was instructed via encrypted messaging app Signal to travel to Tokyo and meet with other men, who were instructed to break into a home to steal valuables. Saen and several other men broke a window to enter a home in Mitaka, attempting to overpower a 70-year-old male resident. The resident, his wife, and their daughter escaped injuries. 

The suspects escaped on foot in different directions. Saen turned himself in at a police box near the east exit of Tokyo’s Ikebukuro Station and is currently searching for the other suspects. Since the end of August, over 20 reported incidents of robbery and home invasion linked to dark part-time jobs have been reported in Tokyo and neighboring prefectures. A joint task force from Tokyo’s Metropolitan Police Department and prefectural police from Chiba, Kanagawa, and Saitama is investigating the involvement of anonymous and mobile crime groups known as tokuryu to determine their command structure.

Colorado patient, employee information posted on dark web in health systems hack

Axis Health System, a healthcare provider in Western and Southwestern Colorado, has reported that its patients’ sensitive information may have been compromised following a security system breach. The company claims that a cybercriminal gained access to their systems, including files for patients and employees. The cybercriminal posted files from the network on the dark web, and they are currently investigating the full nature and scope of the information posted. Axis Health System has 13 facilities in 11 Colorado towns. According to cybersecurity groups, the hacking firm Rhysida was breached by Axis Health, who demanded a ransom of 25 Bitcoin for the data, which amounts to about $1.7 million in actual money. The Cybersecurity and Infrastructure Security Agency (CISA) states that Rhysida typically targets education, health care, manufacturing, IT, and government sectors. 

Kurtis Minder, a cybersecurity expert at GroupSense, said that advancements in artificial intelligence have made hacking easier, and many of the best defenses for companies being targeted are procedural. He suggested that concerned Coloradans should consider things like a credit freeze, as well as evaluating their own cyber hygiene by using a password manager, employing two-factor authentication wherever possible, and using identity protection services. The nonprofit health care provider said the “irregular” activity was first identified in August, and further investigation showed that the hackers gained access to the system between July 9 and September 4.

Constella Intelligence Launches HunterTM Copilot AI Assistant for Dark Web Investigations

Constella Intelligence has launched Hunter Copilot, an AI assistant feature within its deep OSINT investigations platform, Hunter. This tool automates the discovery of link relationships through intuitive entity-relationship diagrams, enabling analysts and investigators to quickly visualize complex data and uncover critical insights up to 30x faster than traditional methods. 

Hunter Copilot streamlines the investigation process, automatically analyzes thousands of relationships, and frees teams to reallocate resources to higher-priority tasks and enhance overall productivity. Its user-friendly interface and automated features make advanced investigations accessible even to smaller or less experienced teams, enabling users to harness powerful tools with just a few clicks.

Powered by Constella’s proprietary ID Fusion, Hunter Copilot connects different criminal personas of an investigated target to an actual public persona, simplifying the identification of relationships between data attributes. 

It provides clear entity-relationship diagrams, fostering collaboration and understanding. Hunter Copilot supports a combination of attributes, generating ranked lists of related identity attributes and personal and professional relationships. It also allows easy exporting of findings in CSV, JSON, or graphical formats, streamlining reporting and sharing processes.

Constella Intelligence CEO Kevin Senator is excited to introduce Hunter Copilot, a tool that elevates the capabilities of investigative teams. It transforms lengthy investigations into quick, actionable insights. With its ease of use, even smaller or less experienced teams can conduct advanced investigations in minutes, enabling them to respond effectively to digital threats.

Canberra woman recruited hit man on dark web to kill parents due to child sexual abuse, court hears

A 30-year-old woman in Canberra, Australia, has been convicted of inciting another to murder due to her sexual abuse as a young child. The woman, who pleaded guilty to the crime earlier this year, had offered $20,000 for her parents’ murder and paid $6,000 towards it through a bitcoin account. However, when interviewed by police, the woman denied having anything to do with bitcoin and said she did not know about the dark web, despite clear proof that was a lie.

Psychologist Tabatha Frew told the court that the woman was autistic and that the overlap of PTSD from the alleged sexual abuse and her autism likely drove the offending. She believed that if she was not sexually abused by a family member, she would not have committed the offenses. The alleged abuse occurred around the age of eight, a critical time for a child’s understanding of good and bad in the world.

The court heard that the woman paid $6,000 towards recruiting the hit man through a bitcoin account. Prosecutor Marcus Dyason challenged Frew’s account, asking if her assessment would change if some of the things she had claimed were shown to be untrue. Ms Frew said she would still be of the same opinion.

When asked whether she had stopped with the plan because she lost interest or didn’t have the money, Ms Frew said it wasn’t simple. Dyason maintained that financial gain was a motive for the offense. The woman has already spent two years in jail waiting for her trial, although she eventually got bail. Her lawyer, Jon White, has urged the court not to impose more prison time given her strong efforts at rehabilitation.

The woman will be sentenced next month.

Dark Web Digest – October 2024 Edition

Dark Web Digest - October 2024 Edition

Every month, new developments and events impact the dark web and its users. The dark web is a hidden part of the internet frequently used for cybercrime, drug trafficking, and hacking.

This article compiles a selection of the most noteworthy and intriguing dark web stories from September 2024, including hacks into global health systems, millions of dollars being sold, emails being stolen, and a host of other stories.

It shows how the dark web threatens privacy, security, well-being, and society. It also discusses how to protect yourself from its dangers and raises awareness.

We will provide additional details, insights, and sources for each news article. This will enable you to take appropriate safety measures and remain engaged in the future.

Diddy allegedly sold a $500 million “Freak Off” dark web video featuring Justin Bieber, Drake, and other celebrities.

Jaguar Wright has accused Sean ‘Diddy’ Combs of selling a controversial “freak off” party video for $500 million on the dark web. Wright claims that the footage includes several high-profile celebrities and that Diddy sold the video out of desperation for cash. She points to an event in Calabasas where the footage allegedly captured questionable activities. Still, no evidence suggests that the celebrities mentioned were involved in illegal activities. Currently, Diddy is being held in a Brooklyn jail, facing charges of sex trafficking, racketeering, and multiple sexual assault allegations. His infamous ‘Freak Off’ parties, which allegedly involved coercion and violence, have been a key focus during his trial. Wright also discussed the role of the “dark coin” in keeping the videos from leaking off the dark web.

Despite her allegations, many fans and commentators have questioned the legitimacy of Wright’s claims. Social media users have mocked her statements, with some questioning her credibility. Wright’s claims have drawn attention, but her credibility remains a topic of debate.

FBI Takes Action Against Dark Web Marketplace Run by Kazakh and Russian Nationals

Two men, Alex Khodyrev and Pavel Kublitskii, have been indicted in the U.S. for allegedly managing a dark web marketplace called WWH Club, which specialises in selling sensitive personal and financial information. Khodyrev and Kublitskii, who acted as the central administrators of WWH Club and its sister sites, have been charged with conspiracy to commit access device fraud and conspiracy to commit wire fraud. The FBI launched an investigation in July 2020 after determining that WWH Club’s primary domain was resolved to an IP address belonging to DigitalOcean. The marketplaces were used to buy and sell stolen personal identifying information (PII), credit card and bank account information, and computer passwords. The darknet marketplace also offered online courses for aspiring and active cyber criminals on how to conduct fraud, with the cost ranging from 10,000 rubles to 60,000 rubles. Undercover FBI agents paid approximately $1,000 in Bitcoin to attend a training course on selling sensitive information, DDoS and hacking services, credit card skimmers, and brute-force programs. If convicted, they could face up to 20 years in federal prison and the forfeiture of Khodyrev’s 2023 Mercedes-Benz G63 AMG sport utility vehicle and Kublitskii’s 2020 Cadillac CT5 Sport sedan.

Users of the Tor Dark Web Browser Allegedly Unmasked by Police

A German news outlet, NDR, has reported that police have been able to de-anonymize several Tor users’ traffic using a “timing analyses” method. Police have been surveilling Tor servers in data centres and using the “Ricochet” chat service to identify Tor users and determine their entry points to the network. A German hacking group member, Chaos Computer Club, verified the method, adding that law enforcement authorities have repeatedly and successfully carried out timing analysis attacks against selected Tor users for several years to de-anonymize them.

In response to the German investigation, Tor said in a blog post that it is “still the best solution” for internet privacy but admits that its team is left with “more questions than answers” about what is happening. Tor hasn’t been able to verify NDR’s claims because the news outlet has yet to share or publicize its evidence.

The Tor browser allows users to access the “dark web” or websites not indexed by Google or other common search engines. It can also communicate anonymous tips and circumvent authoritarian government censorship. Nearly 43% of average daily Tor users are believed to be based in Russia, with nearly 16% in Iran and about 9% in the US. German users make up about 3% of Tor users, with France and China making up another 2% of the total user base.

Some Tor users are aware of the risk of de-anonymization and have previously discussed the possibility of their traffic being traced and tied to them as individuals. However, investigators would have to spend money to participate in the network and stay undetected for an extensive period of time to potentially unmask any traffic. The more nodes that exist, the more decentralized the network is; therefore, it is harder to monitor the entire network and piece together user identities.

Thousands of US political staffers’ personal information was exposed on the dark web

Swiss software developer Proton has released a security update revealing that nearly 20% of US political staffers have had their personal data leaked on the dark web following various hacks. The study, partnered with Constella Intelligence, analyzed 16,543 email addresses belonging to US political staffers, finding 3,191 at risk. Staffers are an entry point for would-be attackers as they can access sensitive information, including those that needs security clearance.

The research shows that nearly 300 staffers had details exposed in more than 10 leaks, with one person having 31 plain-text passwords exposed on the dark web. In total, Proton found 1,848 plain-text passwords associated with political staffers. The leaks also included information from social media, including 1,487 LinkedIn profiles, 416 Facebook profiles, and 347 X profiles.

Proton advises US political staffers to avoid their work addresses to sign up for third-party services unless absolutely necessary. Password managers like Proton’s Proton Pass can improve the security of login data and save unique passwords for various online services. Proton Pass can also hide real email addresses with aliases, preventing them from ending up in data spills on the dark web.

Proton offers services like Proton Pass Monitor and the Dark Web Monitoring service to help determine whether your data has been exposed. This advice is valid for any internet user juggling hundreds of different credentials. Proton has also done similar research on the EU and UK, finding politicians in those regions might be even worse than Americans when it comes to protecting their official work addresses.

Data on the Dark Web Allows Cyberattacks, and the Healthcare Vertical is a Top Ransomware Target

ChannelE2E reports on cybersecurity trends for managed service providers (MSSPs) and managed service providers (MSSPs). SonicWall reports that healthcare organizations remain prime targets for ransomware attacks, with a minimum of 14 million US patients affected by malware breaches. The increasing digitalization of health records and telehealth services significantly expands the attack surface. To defend against cyber threats, healthcare organizations must implement a multi-layered cybersecurity strategy, focusing on regular updates, strong access controls, and 24x7x365 monitoring.

SonicWall urges MSSPs and MSPs to implement robust security measures, monitor systems in real-time, and ensure compliance with regulatory standards. Many healthcare organizations operate with limited cybersecurity resources and often rely on outdated technology, making them even more susceptible to ransomware attacks. A study by Searchlight Cyber found that 60% of vulnerabilities were used against Microsoft Exchange.

The dark web is a critical area of security for MSSPs, as they monitor it for signs of potential attacks on their clients. Many organizations rely on MSSPs to safeguard sensitive data. Still, if this data is leaked or sold on the dark web, it can lead to data breaches, financial losses, and reputational damage. Cybercriminals often sell or share stolen credentials, malware, or exploits on the dark web before an attack is executed.

AI-enhanced malware attacks are a primary concern of U.S. IT professionals for 2025, with 60% of global IT professionals surveyed for GetApp’s 6th Annual Data Security Report stating that AI-enhanced threats signal the need for businesses to prioritize new defensive strategies. High Wire Networks has been doubling down on its cybersecurity services business, with CEO Mark Porter assembling his dream team of C-suite executives to take this strategy forward in the market.

Global Healthcare Cyberattacks Have Increased by 32% Due to Dark Web Sales

A report by Check Point Research has revealed a 32% surge in cyberattacks on healthcare organizations worldwide, leaving patients and their families vulnerable to financial gain. The global weekly average number of attacks per organization within the healthcare industry has increased by 32% over the same period last year, reaching 2,018 per week. The targeted institutions, including vulnerable hospitals, are constantly under the triple threat of cybercrime such as ransomware attacks, data theft, and even selling access to these critical healthcare networks on the dark web. The top regions of attack are the Asia-Pacific (APAC) region, Latin America, Europe, and North America. The World Health Organization (WHO) has declared 17 September World Patient Safety Day to highlight the risks associated with cyberattacks in the healthcare industry. Cybercriminals also use ransomware-as-a-service (RaaS) to target healthcare organizations, partnering with others to carry out attacks and siphoning off sensitive data. To mitigate these risks, healthcare organizations must adopt comprehensive cybersecurity measures, including technological solutions, employee training, and improved security policies.

Emails from 20% of US lawmakers and staff were compromised on the dark web.

A joint investigation by digital risk firm Constella Intelligence and privacy provider Proton has revealed that nearly 3,200 US politicians and staff have had their data leaked to the dark web, affecting nearly 20% of all people working in the US Congress. The leaks occurred primarily because staffers used their official email to sign up for various online services, including high-risk dating and adult websites. The research highlights existing vulnerabilities to national security, especially worrisome with the US presidential election looming in the background.

Proton, in collaboration with Constella Intelligence, has contacted all affected political staffers to inform them their personal details have been found on the dark web and offer guidance on how to mitigate potential risks. Experts call on anyone to employ more robust cybersecurity practices, whether they are high-profile targets or not.

To mitigate potential risks, it is essential to avoid using sensitive work email addresses for third-party services unless absolutely necessary. Using hide-my-email aliases instead can help mask your real email address. Enabling two-factor authentication protections, using a reliable password manager, and signing up for data alert services that notify you when your personal details have been exposed on the dark web are all crucial steps.

Dark Web Digest – September 2024 Edition

Dark Web Digest - September 2024

This month’s report has some shocking and exciting news. Last month, a number of significant incidents occurred on the dark web. The Columbus data breach and the AMD data breach both made people very aware of how important it is to strictly follow safety measures. There are ways to stay safe from malware and dark web threats, which we already know. But this is getting more and more scary!

Below is a list of the startling revelations from the dark web iThese news stories about attacks and vulnerabilities help us remain vigilant against dark web threats. dark web threats.

Undercover police found some names during the Columbus data breach

The city of Columbus has uncovered sensitive data from its databases, including the names and personal information of undercover police and child rape victims. Cybersecurity expert Connor Goodwolf claims that the city attorney’s office’s “matrix crime database” includes every incident report and arrest record written by officers since the mid-2010s. This includes names of officers and victims, personal information like addresses and social security numbers, names of undercover police officers, summaries of incidents, and evidence such as witness and victim statements.

Columbus Ohio

Goodwolf alleges that all of this sensitive data wasn’t properly protected with encryption or basic cybersecurity techniques. He claims that so far, the only data he has found online with such protections are city payroll data and health records. In the latest batch of records, Mayor Andrew J. Ginther expressed his opinion that the dark web may have posted more personally identifiable information.

Cybercrime group Rhysida, who attempted to deploy ransomware after the city claimed an employee had downloaded an infected file, is responsible for the online data leak. The group leaked an unknown amount of city data to the dark web, despite the city’s claim that it prevented the ransomware from encrypting its files. State, city, and federal law enforcement authorities are still investigating the matter.

The city already faces class action lawsuits from multiple plaintiffs, alleging that the city did not do enough to protect their personal information online. Fraternal Order of Police Capital City Lodge No. 9 President Brian Steel expressed concern about the safety of undercover officers in particular, and the fact that the personal information of child rape victims is being released on the dark web is even more concerning for him.

Goodwolf believes that trust in the city after this hack has “completely eroded.”

AMD internal data was allegedly offered for sale.

Digital data thieves have breached AMD’s internal communications and are offering the stolen goods for sale. Criminal groups IntelBroker and EnergyWeaponUser Credited the break-in, which they claimed took place the same day and is separate from IntelBroker’s earlier theft and sale of AMD source code and other internal data from June. The BreachForums post promised buyers compromised communications from “a mix of sources,” including “idmprod.xilinx.com” and “amdsso.okta.com,” which reportedly contained user credentials, case numbers and descriptions, and internal resolutions. The attackers also provided a sample of the stolen data, which purports to be sensitive information, including user names and assignment groups. AMD did not immediately respond to The Register’s inquiries about the alleged intrusion. If this turns out to be true, it will be the second breach of AMD’s sensitive internal documents in three months. According to reports, IntelBroker is behind both, with an apparent assist this time around from a newbie. IntelBroker is also a site admin for the resurrected BreachForums. Over the past months, the group has claimed several high-profile intrusions and data sales, including Europol, the Pentagon, Korea’s Ministry of Defense, the US Army, and Home Depot, all of which have put a large target on the cybercriminals’ backs, with international cops all gunning for the gang.

Stolen credentials on the Dark Web got a Russian hacker 3+ years in prison

Georgy Kavzharadze, a 27-year-old Russian national, received a sentence of over three years in prison in the U.S. for selling financial information, login credentials, and other personal identifying information on the now-defunct dark web marketplace Slilpp. Kavjaradze, known by online monikers TeRorPP, Torque, and PlutuS, listed over 626,100 stolen login credentials for sale on Slilpp and sold over 297,300 of them between July 2016 and May 2021. We linked the stolen credentials to $1.2 million in fraudulent transactions. Estimates suggest that Kavzharadze illegally profited at least $200,000 from the sale of stolen credentials. Until June 2021, an international law enforcement operation dismantled Slilpp’s infrastructure, making it one of the largest marketplaces for selling login credentials.

Interviewing the ghost, who took down 20% of the dark web

Seven years ago, a large-scale cyber attack took over 10,000 dark web sites hosted by Freedom Hosting II (FHII) offline, resulting in the unceremoniously unplugged hosting service. The first hacker, Vanerak, discovered that over half of the websites hosted by FHII contained CSAM and scam sites, despite the company’s claim of having a zero-tolerance policy. Vanerak discovered that FHII was a clone of the original Freedom Hosting, which faced downtime in 2011 due to an exposure by LulzSec for hosting child pornography during “Operation Darknet.”

Freedom Hosting Admin Arrest

Eric Eoin Marques, the admin of Freedom Hosting, faced arrest two years later for hosting one of the largest facilitators of child sexual abuse material (CSAM). Four years later, a young female hacker weaponized the media to hold the hosting provider accountable for the same relevant conduct as its predecessor. Vanerak contacted VICE News nearly a year ago, finding her story intriguing but highly unlikely. She eventually convinced the journalist, using insider knowledge, that she was the original hacker who unceremoniously took down 20% of the dark web.

Anonymous hackers have reworked a defacement page, causing outrage among hacker Laura Vanerak. She claims that many sites may have redirected to off-site mirrors, turning her defacement and media coverage into advertisements for online predators. Vanerak did not leak emails or databases, but instead sent them to authorities. She advises hacktivists pursuing fame and recognition to question the worth of risking a heavy prison sentence and the potential unjustifiable long sentence for criminals they worked hard to take down. She warns OpChildSafety hunters about the trauma they face, as well as the importance of showing purpose and action in preventing online predators.

Hackers releasing stolen data from Columbus on the dark web

Rhysida, a hacker group, has begun releasing stolen data from the city of Columbus, claiming it was responsible for the July 18 attack. The group has listed the stolen data on the dark web and asked bidders to offer 30 bitcoins, or close to $2 million, for the data. Daniel Maldet, owner of the Columbus office of CMIT Solutions, said he is seeing 3.1 terabytes of the 6.5 terabytes the group said it stole from the city, or about 45% of the data. Secure Cyber Defense CEO Shawn Waldman, located near Dayton, is uncertain about the sale of any data. Columbus Mayor Andrew J. Ginther said that speculation by individuals external to the investigation may not benefit the objective of educating the public on the incident. Maldet said the information released appears to have come from a backup server and could be potentially damaging. If members of the Columbus police union suspect the hacking of their bank accounts or other private information, the union is directing them to a lawyer.

US company says dark web leaked 3B records

National Public Data (NPD), a company that specializes in the resale of personal information for background checks, has confirmed a significant data breach. involving the exposure of nearly 2.9 billion individuals’ names, social security numbers, and physical addresses. A third-party malicious actor orchestrated the breach, attempting to infiltrate the data in late December 2023. We identified potential leaks in April and summer of 2024. The compromised information included names, email addresses, phone numbers, social security numbers, and mailing addresses. NPD has collaborated with law enforcement and government investigators to conduct a review of potentially affected records. However, NPD has faced criticism for its handling of the situation, failing to disclose the number of affected individuals or offer compensation. Instead, NPD advises individuals to monitor their credit reports for any suspicious activity.

National Public Data

Ukrainian police arrest a darknet Russian intelligence agent

Ukrainian law enforcement has detained the leader of an organized group that set fire to Ukrainian enlistment officers‘ cars at the request of Russian intelligence and advertised other services to Russia on the darknet. The suspect posted his CV on the darknet, offering “services” for burning the cars of representatives of the Ukrainian military registration and enlistment office. Russian intelligence saw his post and tasked him with destroying military vehicles in his hometown, Khmelnytskyi. The suspect destroyed several cars with Molotov cocktails and filmed them catching fire, sending a “report” to Russian customers. During the searches, the police seized the suspect’s mobile phones and SIM cards, which he used to communicate with Russians. This is not the first time Ukrainian collaborators have used the darknet to locate or offer services to Russian intelligence.

A woman was jailed for a Bitcoin-funded Dark Web murder plot

Krista Renae Stone, a 23-year-old from Utah, received a 78-month sentence in federal prison for orchestrating a murder-for-hire through the dark web. She planned to pay $5,000 in bitcoin to a Hitman service website between March and September 2023. However, law enforcement uncovered the plot prior to its execution. The court also sentenced Stone to three years of supervised release.

AI model reaches 98% accuracy in collecting threats from dark web forums

Despite DarkWeb threats, there is good news. Researchers from the Université de Montréal and Flare Systems have found that large language models (LLMs) can extract critical cyber threat intelligence (CTI) from cybercrime forums with an impressive 98% accuracy. Vanessa Clairoux-Trépanier and Isa-May Beauchamp led the study, which developed an LLM system using OpenAI’s GPT-3.5-turbo model to analyze conversations from three prominent cybercrime forums: XSS, Exploit.in, and RAMP. We instructed the LLM system to summarize conversations and code 10 critical CTI variables, including identifying targeted organizations, critical infrastructure, and exploitable vulnerabilities. The system achieved an average accuracy score of 98%, ranging from 95% to 100% across the ten variables. This level of performance exceeded the researchers’ expectations and underscores the immense potential of LLMs in the field of cyber threat intelligence. The study also identified areas for further improvement, such as refining the FILM’s ability to distinguish between historical narratives and current events, as well as optimizing prompts and data chunking techniques. The researchers plan to continue refining the LLM system and exploring its applications in various cybersecurity domains, calling for further research into using state-of-the-art models to push the boundaries of AI-driven cyber threat intelligence.

 

Dark Web Digest – August 2024 Edition

Dark Web Digest - August 2024

This month’s August dark web digest will bring some exciting news. Google launched its first monitoring tool for the very first time in history. Other side research finds stolen data and also suggests how to stay strong against the dark web world and its attack. As we know, the dark web is a dangerous place; it is just like the internet we use on a daily basis but a place of illegal activities. From hacking to selling, there is everything that can be done on the dark web. Let’s explore this month’s digest and see what happened last and what might be happening in the future.

Google Rolls Out Free Dark Web Monitoring Tool for All Users

Google has announced that its Dark Web monitoring feature will be available to all Google account users for free, a significant change in a previously exclusive service for Google One’s premium users. The tool searches the dark web for users’ personal information, such as names, social security numbers, email addresses, and phone numbers, and advises them on how to protect their data. This move could help democratize cybersecurity and mitigate emerging threats of identity theft and personal data breaches.

Google Dark Web Monitoring - July August 2024

The Dark Web monitoring tool scans various sites and forums on the dark web where stolen information is frequently traded. If a user’s data is found, Google will send an alert providing details about the data and recommendations for securing it. This seamless integration means users do not need to download additional software or manage multiple accounts to keep their information secure.

This initiative enhances individual user security and sets a new standard for tech companies in cybersecurity. By making advanced security tools accessible to a wider audience, Google is pushing the envelope in the fight against cybercrime. The move is likely to have ripple effects across the tech industry, encouraging other companies to enhance their security offerings.

Google’s expansion of free Dark Web monitoring to all Google users is a significant step forward in online security, as it is crucial in safeguarding user data against cybercrime.

Security Researchers Find Stolen SingPass Accounts on Dark Web

According to Singaporean security researchers, there has been a 23% increase in dark web activity related to stolen identity information from citizens. Cybercriminals are selling stolen documents, which are used for fraudulent activities, identity theft, impersonation scams, and bypassing Know Your Customer (KYC) protocols. The surge is largely due to data breaches affecting online platforms that store consumer information. In April 2024, there was a noticeable increase in data dumps on the dark web, with thousands of records becoming available for sale. These records often contain biometric data, which is used for illegal activities like creating fakes. Nation-state actors and foreign operatives are highly interested in this data for intelligence purposes. A significant portion of the stolen data was discovered on XSS, a prominent underground forum. SingPass accounts, which allow access to government and private sector services in Singapore, have also been found for sale on the dark web.

Singpass - August 2024

Ticketmaster discredits dark web claims of stolen barcodes for Taylor Swift concerts

Ticketmaster has denied claims that hackers have access to working ticket barcodes for upcoming Taylor Swift concerts and other events. A hacker allegedly offered 170,000 barcodes for sale, with 20,000 available at each show. The hacker threatened Ticketmaster with more leaks if they weren’t paid $2 million, claiming to have 30 million more barcodes for NFL games and Sting concerts. Ticketmaster’s spokesperson denied the claims and stated that their SafeTix technology protects tickets by automatically refreshing a new barcode every few seconds. Ticketmaster’s parent company, Live Nation, confirmed last month that its account on data storage platform Snowflake had been breached. Hackers claimed to have a 1.3 terabyte database of information on about 560 million Ticketmaster users, including names, addresses, emails, phone numbers, event details, and specific orders.

Ticketmaster Hack - August 2024

Researchers predict seller success on dark web markets

Researchers from Leiden University have developed a method to predict successful sellers in illegal online marketplaces, which could help law enforcement track down big players on the dark web. These marketplaces, also known as cryptomarkets, are found on the dark web and cannot be accessed with regular internet browsers or search engines. Users are anonymous, and transactions are made with cryptocurrencies like bitcoin. The researchers, including Ph.D. candidate Hanjo Boekhout, Professor Frank Takes, and Professor Arjan Blokland, used data from Evolution, a popular data web market in 2014, to analyze communication patterns in the forum section. Topic engagement and betweenness centrality were identified as good predictors of seller success. Topic engagement was found to be a strong predictor, with users with many responses often becoming successful sellers. Betweenness centrality helped identify important players who were less active on the forum. The method could help law enforcement agencies prioritize investigations and identify emerging sellers before they become big.

Botnets are being sold on the dark web for as little as $99

Cyber criminals are offering ready-made botnets on the dark web for as little as $99, making cyber attacks cheaper and easier than ever. Botnets like Mirai target online consumer devices such as IP cameras and home routers, with individually tailored infection processes, malware types, infrastructure, and evasion techniques. Recent research from Cloudflare found that 4% of HTTP DDoS attacks and 2% of L3/4 DDoS attacks were launched by a Mirai-variant botnet during the first quarter of this year.

Botnet Attack

Since the beginning of 2024, Kaspersky researchers found more than 20 offers for botnets for hire or sale on dark web forums and Telegram channels. The lowest offers started at $99 and the highest reached $10,000. Botnets can be hired or acquired as leaked source code for between $30 and $4,800 per month, with custom botnet development also available in some cases. Access to leaked source code can be obtained for free or a fee of $10 to $50.

Botnet activity is on the rise, with researchers at NetScout discovering a sharp rise in global botnet activity, spiking at more than a million devices. A Trustwave report last year found that botnets were responsible for more than 95% of all malicious traffic on the internet, with Mirai, Mozi, and Kinsing botnets accounting for almost all exploit attempts that were run over HTTP or HTTPS protocols.

CSAM Pedophiles Identified via Dark Web Malware

Information-stealing malware logs on the dark web have identified numerous individuals who download and share child sexual abuse material (CSAM), highlighting a new law enforcement technique. Recorded Future’s Insikt Group used stolen data to trace these identities across platforms, obtaining usernames, IP addresses, and system characteristics. Law enforcement uses this information to identify perpetrators and make arrests. Infostealer logs like Redline, Raccoon, and Vidar include critical data, including passwords, browsing history, cryptocurrency information, and more.

Researchers may use info stealer data to link CSAM account users to email, banking, and social networking accounts. This development demonstrates its potential to improve child sexual exploitation tracking and convictions. As child predators increasingly use artificial intelligence (AI) to create sexually graphic photographs of children, hampering law enforcement attempts to prevent internet sexual exploitation. Stanford University’s Internet Observatory found that AI-powered technologies have allowed criminals to create fake images and videos based on actual children’s photos, increasing child sexual abuse content.

As of 2023, the National Center for Missing and Exploited Children’s CyberTipline recorded over 36 million suspected child sexual abuse incidents. The proposed Kids Online Safety Act in the United States and the Online Harms Act in Canada attempt to hold social media companies accountable for harmful AI-generated material. However, social media companies using AI for content moderation are making child sexual abuse detection and reporting harder, possibly allowing offenders to escape prison.

Man convicted for encouraging child sexual abuse on the dark web

A man from Peterborough, Colin Thackeray, has been convicted of promoting child sexual abuse on a dark web site. Thackeray, a 62-year-old moderator, shared advice on grooming children with the intention of sexually abusing them. The sites involved the sexual abuse of boys and linked to indecent imagery. Thackeray had over 2,000 indecent images of children on his devices, with 350 in Category A, 655 in Category B, and 1,459 in Category C. When arrested in September 2019, NCA officers found a laptop and chat logs where Thackeray was exchanging indecent images, discussing how to groom and abuse children, and role-playing sexual activity with children.

Colin ThackerayHe was charged with making indecent images of children, possessing prohibited images, intentionally encouraging or assisting an offence, and attempting to cause or incite a boy under 13 to engage in sexual activity. Thackeray pleaded guilty to three counts of making indecent images and one count of possessing indecent images in July 2022 and was further convicted of two counts of intentionally encouraging the sexual assault of a child under 13 and one count of attempting to incite a child under 13 to engage in sexual activity.

Bitzlato founder won’t get more jail over $700M dark web clearing house

Bitzlato Founder ScamAnatoly Legkodymoc, founder of the defunct crypto exchange Bitzlato, has been sentenced to time served after pleading guilty to one charge of operating an unlicensed money-transmitting business. Legkodymov served 18 months at Brooklyn’s Metropolitan Detention Centre (MDC) and agreed to forgo any claim to the $23 million in crypto assets seized by French law enforcement during the global sting operation that shut down the exchange on Jan. 23, 2023. The prosecution alleged that Legkodymov aided in the exchange of over $700 million in cryptocurrency through the Russian dark web black market Hydra Market and failed to implement adequate measures to monitor who was using the exchange.

Bitzlato users regularly visited the exchange’s customer service portal to ask for help with transactions on Hydra Market and frequently admitted they were trading under false identities. Legkodymov was arrested in Miami on Jan. 17, 2023, following a coordinated international effort to shut down the exchange. Europol reported that roughly 46% of assets processed by Bitzlato were linked to illicit activities, with others linked to cyber scams, money laundering, ransomware, and child abuse material.

Stolen credentials could unmask thousands of darknet child abuse website users

Researchers at Recorded Future have discovered that thousands of people with accounts on darknet websites for sharing child sexual abuse material (CSAM) could be unmasked using information stolen by cybercriminals. The researchers identified these individuals from credentials harvested by infostealer malware, which typically steals log-in credentials for banking services, which are then exploited by financial fraudsters. The logs link these anonymous CSAM website users to accounts on clear web platforms, such as Facebook, where they have used their real names and sometimes even include autofill data stored in a web browser, such as a home address.

Infostealers steal data from infected devices, including login credentials, operating system information, cryptocurrency addresses, and other data that these actors then post or share or sell on dark web sources. Retailers involved in the ecosystem for trading these stolen credentials include Russia Market and 2Easy Shop, as well as the now-defunct Genesis Market, which was seized by law enforcement last year, leading to more than 120 arrests.

Recorded Future analyzes these records for domains used by corporate customers to protect compromised employee accounts or identify when customers are impacted to tackle consumer fraud. By querying this data alongside partners like the World Childhood Foundation and the Anti-Human Trafficking Intelligence Initiative, the researchers were able to identify approximately 3,300 unique users with accounts on at least one darknet site for the sharing of CSAM.

The researchers aim to share the methodology as a proof-of-concept of what can be done using the type of data that they have, and pass it on to those who can take more action.

Dark Web Digest – July 2024 Edition

Dark Web Digest - July 2024

This month’s digest brings some exciting and shocking news. There are very serious incidents happened in dark web last month. From MPS leaked data to Department of justice leak data warned everyone that they should take safety measure at all cost. As we already know some way how to stay safe against malware and dark web attacks. However, this becomes more and more dangerous! 

Below are some shocking news we have seen last month in world of dark web. These insights and vulnerability in these incident are really supportive to stay alert from dark web attacks. 

Majority of UK MPs have had their data leaked to the dark web

British politicians have had their data leaked to the dark web, with over two-thirds of them exposed. Out of 650 MPs, 443 have had personal data exposed on the dark web, mostly from third-party services they have signed up to via their parliamentary email addresses. 

This is compared to just 44% of EU MEPs. French deputies and senators had the best security, with only 18% of searched emails appearing in hacker exchanges. 

UK Parliament Cover

The data shows that politicians used their official email addresses to set up accounts on third-party websites, putting themselves and their information at risk. 216 plain text passwords associated with MPs’ accounts were exposed on the dark web, with parliamentary emails being the biggest piece of data involved. Cybercriminals often use the tactic of ‘credential stuffing’ to enter stolen passwords and emails into different platforms to gain access to different accounts. Some social media profiles were also affected, with 16 breaches of Instagram, 117 of LinkedIn, 21 of X, and 21 of Facebook.

Los Angeles schools investigating claims of data for sale on dark web

LAUSD is investigating a claim that certain district records are for sale online, stemming from a threat actor’s post on BreachForums offering to sell about 24 million records belonging to LAUSD for $1,000. 

The LAUSD spokesperson stated that they prioritize the privacy of students, families, and employees. The latest claims on compromised district data have yet to be verified by LAUSD. Kaustubh Medhe, vice president of research and threat intelligence at threat-intel firm, Cyble, said that the records appear to have personal identifiable information, including student IDs, names, dates of birth, English proficiency status, special education status, home addresses, phone numbers, and parents’ names. 

The information can lead to privacy concerns, but the fact that it’s only being sold for $1,000 indicates it lacks sensitive account-level information, making it less valuable for fraud but still significant for secondary attacks like phishing. A new ransomware group called Rhysida has emerged and strongly resembles Vice Society, suggesting that Satanic may be trying to monetize old data posted by the Vice Society group in 2022.

Google is making its dark web monitoring tool 

Google is integrating its dark web report feature into the ‘results about you’ section of the Google app this summer. 

Previously only available to Google One subscribers, the feature will now be available to all Google account holders. The dark web monitoring tool, which was previously exclusive to paying Google One customers, will provide detailed analysis of leaked personal data. 

Google Dark Web Monitoring Tool

The new integration aims to enhance security by making dark web monitoring available to a broader audience. The dark web monitoring will become part of a combined solution with ‘Results about you,’ a feature that helps users find and request the removal of personal contact information from search results. 

This expansion comes after Google ended support for its Google One-destined VPN tool due to lack of use by customers. Google aims to focus on more frequently used tools.

Police to probe reported fingerprint data sales on dark web

The Indonesian National Police are investigating reports that data from its Automatic Fingerprint Identification System (Inafis) was being sold on the dark web after a massive national database breach that temporarily crippled public services. 

The National Cyber and Crypto Agency (BSSN) revealed that a new variant of ransomware was used in the cyberattack on two temporary National Data Center (PDN) facilities, which affected databases managed by over 200 central and regional institutions. 

The cyberattack occurred around the same time that the BSSN discovered that data allegedly stolen from the police’s Inafis was being offered for sale on the dark web. The government is still trying to restore public services affected by the ransomware attack, although some services have been restored and are running normally, such as the Immigration Office under the Law and Human Rights Ministry.

Dark Web Sees 230% Rise in Singapore Identity Theft

Singaporean security researchers have found a 230% increase in dark web activity involving stolen identity information from citizens. Cybercriminals are selling these stolen documents, which can be used for fraud, identity theft, impersonation scams, and bypass Know Your Customer (KYC) protocols. In April 2024, there was a significant increase in data dumps on the dark web, with thousands of records available for sale. 

Singapore Identity Theft

These records often include biometric data, which are reused for illegal activities, including deepfakes. Nation-state actors and foreign operatives are also interested in this data for intelligence gathering. 

A significant portion of the stolen data was found on XSS, a prominent underground forum. Cybercriminals are also selling templates for forged documents with advanced security features. Singpass accounts, which provide access to government and private sector services in Singapore, have also been found for sale on the dark web.

Preteen Girl’s 92% Instagram Followers Grown Up Men, Pics Found On Dark Web: Report

Instagram, a platform owned by Meta, has been a topic of discussion about online safety due to incidents of girls being targeted by predatory adults. 

A recent report in the Wall Street Journal (WSJ) revealed that 92% of a preteen girl’s US followers are grown men. The girl started her Instagram channel after being encouraged by her mother to become an influencer. The algorithm steered men with deviant sexual attraction to her page, resulting in unwanted comments and sponsored offers. 

The girl’s page’s follower count grew to over 100,000 within a year, and she started receiving sponsorship offers. However, the comments from grown-up male followers became worse when she launched a paid subscription for “super-fans.” Meta has maintained that it does not allow anyone under 13 to open accounts on their own, but it has not done enough to stop incidents like these. 

The site’s algorithms take users to their favorite content without any filter about its appropriateness. The girl’s mother moderates comments and does not allow certain types of photos, like swimsuit pictures. 

Last year, WSJ linked Instagram’s recommendation algorithms to a “vast network of paedophiles” seeking illegal underage sexual content and activity.

BlackBerry Cylance Data Offered for Sale on Dark Web

BlackBerry is investigating a potential data breach involving Cylance data being sold on the dark web. The cybercriminals are claiming to have 34 million million customer and employee emails, personal information, sales prospects, and user and partner lists. 

The data was accessed from a third-party platform and appears to be from 2015-2018, predating BlackBerry’s acquisition of the Cylance product portfolio. BlackBerry is aware of the potential data breach and is currently conducting an investigation.

Blackberry
BlackBerry Limited – software company specializing in cybersecurity

Emsisoft threat analyst Brett Callow noted that the Cylance data may have been obtained as a result of a recent campaign targeting customers of cloud data platform Snowflake. The campaign has impacted many organizations, including high-profile companies like Ticketmaster, Anheuser-Busch, Allstate, Advance Auto Parts, Mitsubishi, Neiman Marcus, Progressive, Santander Bank, and State Farm. 

There is no evidence that the attacks involved a vulnerability in Snowflake systems or products, or that the vendor’s production or corporate systems have been compromised. BlackBerry does not confirm or deny that the data comes from Snowflake, but it is currently not a Snowflake customer.

Department of Justice on dark web marketplace arrest

The last news we got is marketplace arrest. Rui-Siang Lin, the creator of Incognito, has been arrested in the US for allegedly operating a $100 million dark web scheme to traffic deadly drugs. The FBI and Homeland Security Investigations New York have accused Lin of operating Incognito Market, one of the largest online platforms for narcotics sales, and of conducting $100 million in illicit transactions.

The site allowed anonymous transactions through a unique banking system that authorized cryptocurrency deposits and transfers, ensuring the anonymity of buyers and sellers. 

The FBI has also emphasized the ongoing work to disrupt illegal drug sales online, which often have tragic consequences. The Food and Drug Administration’s Office of Criminal Investigations has also weighed in, stressing their ongoing work to disrupt illegal drug sales online. 

If convicted, Lin faces several charges, including a mandatory life sentence for engaging in a continuing criminal enterprise, narcotics conspiracy, money laundering, and conspiracy to sell adulterated and misbranded medication. The US Attorney General, Merrick B. Garland, has criticized drug traffickers who believe they can operate outside the law on the dark web.

 

Dark Web Digest – June 2024 Edition

Dark Web Digest - June 2024

No one knows about the dark web, but hackers, drug dealers, and other types of cybercrime use it often. Every month, new things are happening the dark web. This June month’s digest will cover some of the most important and interesting news highlighted on the news and social media in May 2024.

Indian Election Hit by Cyberattacks, Dark Web Data Leaks

Security researchers have reported a surge in cyber activity targeting the upcoming Indian general election, driven by hacktivist groups. The election, which will determine all 543 members of the Lok Sabha, is set to occur in seven phases from April 19 to June 1, 2024. The cyber-attacks intensified since the launch of the #OpIndia campaign last year, with a 300% spike following the #OpIsrael campaign. 

India Election 2024

The surge is linked to heightened online protests amid the Israel-Gaza crisis. India, with its population of over 1.4 billion and GDP of $3.41T, has become a prime target for foreign threat actors and nation-state groups. Security has alerted Indian authorities about leaked voter ID cards and other sensitive data, aiming to undermine trust in India’s election systems. The firm urged Indian citizens to remain cautious of unreliable sources and emphasized the necessity of robust digital identity protection measures.

Dell customer order database of ’49M records’ stolen, sold on black web

Dell has confirmed that 49 million customer information records and orders have been stolen from a Dell portal. The stolen data includes names, addresses, and details about Dell equipment but does not include sensitive information like payment details. Dell’s portal was compromised, and the stolen data included columns such as service tag, items, date, country, warranty, organization name, address, city, province, postal code, customer code, and order number.

Dell has taken steps to contain the damage, notified law enforcement, and hired a third-party forensic firm. A spokesperson for Dell said the company is taking proactive steps to protect customers’ information and monitoring the situation. 

Dell also downplayed the significance of the data exposure, stating that they take privacy and confidentiality seriously and are currently investigating an incident involving a Dell portal. The company also warned people to be alert for scammers using the stolen data to impersonate Dell staff and defraud victims.

A data breach at Ticketmaster may have affected 560 million customers.

Ticketmaster has been targeted in a cyber-attack by ShinyHunters, demanding £400,000 in ransom to prevent the sale of customer data. The group claims to have access to 560 million customers’ names, addresses, phone numbers, and partial payment details.

Live Nation, the parent company of Ticketmaster, has launched an investigation into the incident and is cooperating with law enforcement. 

Ticketmaster Hack

Authorities in Australia and the US are working with Ticketmaster to understand and respond to the incident. 

Bank Santander confirmed that it had been hacked about two weeks ago. ShinyHunters is also reported to be behind the cyber-attack, posting an advert on a hacker forum for the data, which it claims to have 30 million customers, 6 million account numbers and balances, and 28 million credit card numbers.

The alleged $100 million dark-web drug kingpin, 23, arrested

A 23-year-old Taiwanese man, Rui-Siang Lin, has been arrested in New York for allegedly running the $100 million global dark web narcotics e-commerce operation Incognito Market. 

Lin Rui Siang

The dark website was formed in October 2020 and ran until March of this year, serving as a forum to buy and sell commodities, including heroin, cocaine, LSD, MDMA, oxycodone, methamphetamines, ketamine, and alprazolam. Lin is accused of running the entire business, supervising all operations, employees, vendors, and customers, and holding “ultimate decision-making authority over every aspect of the multimillion-dollar operation.”

Incognito Market provided a user experience that matched those offered by modern e-commerce sites, with vetting and registration of sellers, advertising, customer service facilities, and a slick UX. It distinguished itself from other e-commerce sites by requiring access through the Tor web browser and accepting only cryptocurrency. The DoJ noted that Lin had great IT skills, evidenced by his GitHub account, which described him as a “Backend and Blockchain Engineer, Monero Enthusiast,” he held approximately 35 publicly available software coding projects.

Lin also collected enemies, such as the spread of fentanyl due to the platform’s non-pure or authentic listings. 

The platform’s final days were allegedly spent extorting users between $100 and $20,000, under threat of revealing they had participated in the purchase and sale of illegal drugs. If convicted, Lin faces a mandatory minimum penalty of life in prison for engaging in a continuing criminal enterprise, a maximum penalty of life in prison for narcotics conspiracy, a maximum penalty of 20 years for money laundering, and a maximum of five years for conspiracy to sell adulterated and misbranded medication.

A man was jailed for selling 76 kg of drugs on the dark web.

A man, Donatas Kasputis, has been jailed for nine years for selling 76kg of drugs on the dark web. He used the username “Goodgear” to sell cocaine, ecstasy, and mephedrone to 550 buyers across the UK and abroad. Kasputis was arrested in July carrying 16 packages of drugs and pleaded guilty to eight offenses at Norwich Crown Court. 

Donatas Kasputis

The East Midlands Special Operations Unit (EMSOU) cyber investigations team discovered Kasputis’s drug operation after examining his username, “Beatyhouse2015”. 

The suspect was eventually identified through DNA profiling, and his home was searched, revealing 130g of cocaine, 1,300 ecstasy tablets, 6.4kg of mephedrone, and more than 1.4kg of cannabis. The information on the 550 people who were identified as buying drugs from “Goodyear” has been shared with the relevant police forces.

Fake Pegasus spyware source code floods the dark web

Cybersecurity firm CloudSEK has discovered that cybercriminals are exploiting the Pegasus spyware name to deceive victims on the dark web. Based on months of research on dark web sources, the report exposes a systematic effort to leverage the Pegasus name for financial gain. Threat actors bomb platforms like Telegram with posts claiming to sell genuine Pegasus source code. CloudSEK researchers analyzed approximately 25,000 posts on Telegram, many of which claimed to sell authentic Pegasus code. These posts often followed a common template offering illicit services, frequently mentioning Pegasus and NSO tools.

The report also identified six instances of fake Pegasus HVNC (Hidden Virtual Network Computing) samples distributed on the dark web between May 2022 and January 2024. 

The same misuse was also observed on surface web code-sharing platforms, where scammers were disseminating their randomly generated source codes, falsely associating them with the Pegasus Spyware. After analyzing 15 samples and over 30 indicators from human intelligence (HUMINT), deep, and dark web sources, CloudSEK discovered that nearly all samples were fraudulent and ineffective. Threat actors created their own tools and scripts, distributing them under Pegasus’ name to capitalize on its notoriety for financial gain.

To combat the Pegasus scam, CloudSEK recommends employee awareness, regular updates, and alerts about scam tactics and trends involving Pegasus and similar high-profile names. 

Network monitoring should be implemented to identify unusual activity that might indicate employees accessing the dark web or IRC platforms, and strict access controls should be implemented to limit and monitor employees’ ability to visit potentially dangerous sites or download unauthorized software.

Man arrested in Karachi Pakistan for creating vulgar wife videos for dark web

Women Police in Karachi’s Central District detained the man for reportedly abusing his wife and children and filming the incident on orders from an unknown source. A guy was arrested in Karachi, Pakistan, on Friday for reportedly producing filthy movies of his wife and sharing them on dark websites.

Karachi Man Arrested

Cyber security organizations collect data from all web platforms, including Dark Web forums, to avoid real-time attacks on exposed data, provide actionable intelligence on illegal drug and pharmaceutical exchanges, and monitor insider threats.Cyber security organizations collect information from many web platforms, including Dark Web forums, to avoid real-time attacks on exposed data, provide actionable intelligence on illegal drug and pharmaceutical exchanges, and monitor insider threats.(Shutterstock)

During questioning, Tahir confirmed that website owners had approached him over WhatsApp, according to Pakistan’s Ary News. He continued, “I am unsure of how the website proprietor obtained my WhatsApp number.”

Women Police in Karachi’s Central District detained the man for reportedly abusing his wife and children and filming the incident on orders from an unknown source. According to SHO Women Iram Amjad, the man was apprehended during a raid while his wife and four children were saved.

According to Aaj TV, the individual claimed to have received instructions via email from an unknown source abroad. Amjad further stated that the suspect was instructed to film recordings of each task and send them back via email.

He had hurt and abused his wife and was going to tape his daughter for the next duty. He also stated that the man was involved in violence, sexual harassment, and other criminal actions.

The arrest was made in the case after the victim’s sister Huma Rizvi, who lives in the United States, filed a report.

According to authorities, Elia, the suspect’s wife, accused him of pushing her to have sexual intercourse with his buddies. She also said he attempted to create inappropriate videos with their daughter. According to Aaj TV, Elia said that Tahir took nude images of their 16-year-old daughter and was blackmailing her into sleeping with his pals.

Elia also said in her police statement that Tahir was suspicious and beat her and the children physically and emotionally. She claimed that throughout the last 12 years, she had fled the house multiple times, but her parents had always interfered and rectified the situation.

According to Khyber News, Tahir admitted to setting a camera in the bathroom to watch his wife but then removed it and did not upload any footage. He also admitted to physically assaulting his wife and apparently intending to record his daughter before being caught.

The cops confiscated his phone and laptop, which are currently being investigated.

Conclusion

In conclusion, the constantly shifting dark web in May 2024 will likely be a platform for criminal activity, with cybercrime illegal product trading. It attempts to elude law enforcement remaining common. Understanding this underground marketplace for educational purposes emphasizes the constant conflict between criminal elements and police in the digital age. 

 

Dark Web Digest – May 2024 Edition

Dark Web Digest - May 2024

Welcome back to the shady side of the internet! This month’s Dark Web Digest comes with exciting news from worldwide. In this digest, we will disclose the growing market for fakes on the dark web. Imitations of everything from expensive clothes to dangerous drugs are a significant threat to our safety and our wallets. 

That said, it’s not just about getting a bad deal; counterfeit products, attacks, stealing information, and much more can hurt legitimate companies and put the economy at risk. Let’s get ahead of it!

Leaked Pak Suzuki Data Allegedly Up For Sale On Dark Web

The first trending news was from Pakistan, where the Hackers are said to have put Pak Suzuki Motor Company Limited (PSX: PSMC) company data up for auction on the dark web.

The total amount of data is 447.5 GB (without compression), including papers about finance, accounting, HR/employees, IT, compliance, and administration. “We learned on April 9, 2024, that our company’s data had been stolen in a cyberattack.” “First investigations show that HR, financial, and other data from the server has been sent to a public IP address,” PSMC told the Pakistan Stock Exchange earlier today.

Suzuki Sign

The threat actor’s message says that the stolen data includes source codes for IT programs, executives’ PST email accounts, passports, salary and tax documents, SAP and ERP databases, internal databases, VoIP records (March 2024) and contracts with other companies, as well as information from the computers of influential company executives, CFOs, IT managers, directors, more. It was also said to have about 37 GB of info from Suzuki’s main office in Japan.

This came after the company recently said it was removing itself from PSX.

PSMC began the share purchase offer (SPA) in February 2024 to sell 22.14 million shares at Rs. 609 each and remove the company from the stock market.

As a result of Suzuki Motor Corporation, Japan’s recent decision to buy all the shares of Pak Suzuki Motor Company Limited (the Company) that the Sponsor or Majority Shareholder does not own, this decision was made.

Researchers have found that “rude” ransomware tools are easy to find and cheap on the dark web

Cybersecurity firm Sophos discovered 19 ransomware types sold for one-time use on dark web forums from June 2023 to February 2024. Researchers compared the cybercrime tools to “junk guns,” cheap, imported handguns that flooded the U.S. in the 1960s and 1970s. These tools offer low barriers to entry and little traceability, making them attractive to would-be cybercriminals. When posted, the varieties ranged from $20 to 0.5 bitcoin, or approximately $13,000.

The one-off cybercrime tools differ from ransomware-as-a-service models because no affiliates who expect a cut of the profits are involved. They allow criminals to get in on the action cheaply, quickly, and independently, targeting small companies and individuals unlikely to have the resources to defend themselves or respond effectively to incidents. However, there are risks, such as the tools being defective or backdoored as part of a scam.

The efficacy of these tools in the wild is unclear, as there is little infrastructure for investigators to monitor, and targets are likely small businesses or individuals, resulting in little publicity. Additionally, attackers do not have leaked sites for stolen data. At least one of the tools for sale, EvilExtractor, was observed being used last year in attacks in the U.S. and Europe, and there were claims on forums of three other variants having been successfully used.

Christopher Budd, director of Sophos X-Ops, emphasized the challenges these tools pose for defenders, as most attacks will likely go undetected and unreported. Users on dark web forums show the amateurish nature of operations, with no dumb questions for individuals who aspire to develop their abilities.

AT&T Responds to New Data Set Made Public on the Dark Web

AT&T has found that fields unique to AT&T data were in a data set posted on the dark web about two weeks ago. Although AT&T has decided on this, it is unclear if the data in those fields came from AT&T or one of its sellers. The data source for the rest of the data set, which has personal information like social security numbers, is still being looked into.

AT&T has started a thorough review with the help of both internal and external cybersecurity experts. According to our first look at the data, it seems to be from 2019 or earlier. It affects about 7.6 million current AT&T account holders and about 65.4 million past account holders.

ATT

At this point, AT&T does not have proof that someone broke into its servers without permission and stole the data set. The company is getting in touch with those who will be affected and will offer credit tracking at our cost if it applies.

Seattle man was given a sentence for buying 630,000 fake pills on the Dark Web

IN ST. LOUIS – A man who bought 630,000 fake Xanax and other pills on the dark web was given a five-year prison term and told to pay a $10,000 fine by U.S. District Court Judge Stephen R. Clark on Thursday.

Maximillian Gregory Verbowski will also be overseen by the police for three years after he gets out of jail.

Verbowski bought large amounts of fake generic alprazolam (an anti-anxiety drug) and other prescription pills on the dark web from October 2019 to August 30, 2021, and then sold them. He did this using both cryptocurrency and cash. Verbowski’s source got drug ingredients from China and used a pill press and stamps to make the pill lines look like they were made by an honest company. The pills were then sent by the source to post office boxes that Verbowski opened using fake names.

Verbowski, who is now 29 years old and lives in Seattle, pleaded guilty in June to one count of plot to sell fake drugs, one count of selling counterfeit drugs, and one count of using a phoney name on mail to commit a crime.

There were investigations into the case by the FBI, the Drug Enforcement Administration, the U.S. Postal Inspection Service, and Homeland Security Investigations.

Indian drug dealer imprisoned in US for dark web sales

Banmeet Singh, an Indian citizen 40 years old from Haldwani, has been sentenced to five years in jail in the US for trafficking drugs on the dark web and has been told to pay back about $150 million.

PTI said that Singh was caught in London in April 2019 because the US asked him to be. 

Banmeet SinghIn March 2023, he was sent back to the US. He admitted in January that he was involved in a plot to sell illegal drugs to launder money. Still, he pleaded guilty to conspiracy to commit money laundering and possession of controlled substances.

According to court records and statements, Banmeet set up vendor marketing tools on black market sites like Silk Road, Alpha Bay, Hansa, and others. He sold illegal drugs like fentanyl, LSD, ecstasy, Xanax, ketamine, and tramadol through these methods.

People who bought drugs from Singh through the vendor sites he ran did so using Bitcoin.

Singh, in the meantime, either personally shipped the drugs from Europe to the US or arranged for their shipment through US mail or another shipping service.

Singh was in charge of at least eight delivery cells in the US from 2012 to July 2017. These cells were in Ohio, Florida, North Carolina, Maryland, New York, North Dakota, Washington, and other places.

The Department of Justice said on Friday, “People in these distribution cells received drug shipments and then re-packed and re-shipped the drugs to places in all 50 states, Canada, England, Ireland, Jamaica, Scotland, and the US Virgin Islands.”

“Throughout the conspiracy, the Singh drug organization moved hundreds of kilograms of controlled substances throughout the United States and set up a multimillion-dollar drug business that laundered millions of dollars’ worth of drug proceeds in cryptocurrency currency account statements, which ultimately came to be worth about USD150 million,” an official release stated.

San Jose police arrest 2 and seize heroin, meth, cocaine in dark web bust

Police in San Jose said Thursday that they caught two people who they think were selling drugs on the “dark web.”

Around 7:45 p.m. on November 25, police in San Jose stopped a car near Alum Rock Avenue and South White Road. Officers reportedly found different amounts of illegal drugs in the vehicle during a search. This led police to get a search warrant for the driver’s home in San Jose.

Police said that they found several guns, cocaine, methamphetamine, heroin, opioids, and other drugs for sale in the house. Police are also said to have found proof in the house that drugs were being sent through the U.S. Postal Service.

Joshua Jordan, 36, of San Jose, the main suspect by police, was found with the stolen goods.

Two Suspects

After a four-month investigation that ended on November 27, San Jose police say they found that Jordan was selling illegal drugs on the dark web and only taking cryptocurrency as payment.

A second suspect, 36-year-old Jonathan Correll Jr. of San Jose, was also named. He was said to be working with Jordan to sell drugs on the dark web. The cops caught Jordan in Santa Clara on March 22 and Correll Jr. in San Jose. Several hundred grams of heroin, methamphetamine, cocaine, Xanax, Cialis, morphine, Psilocybin, and MDMA (also known as ecstasy) were reportedly found by detectives when they carried out search warrants at properties linked to the suspects. It was also taken two semiautomatic pistols, ammunition, a semiautomatic handgun with an extended magazine, and about $6,000 in cash.

Jordan and Correll Jr. were taken to the Santa Clara County Main Jail on suspicion of selling drugs and having guns without a license.

ED and FBI Busted Rs 3000 Crore Dark Web Drug Empire

India’s Enforcement Directorate (ED) and the US Federal Bureau of Investigation (FBI) have successfully busted a Rs 3,000 crore scam involving digital currencies in Uttarakhand, leading to the arrest of two individuals suspected of operating an international drug trafficking network. The operation began in August 2023 and involved an investigation by the ED. The ED identified two Indian nationals, Parvinder Singh and Banmeet Singh, who were apprehended from Haldwani, Uttarakhand, on April 27.

The suspects used dark web vendor marketplaces to facilitate drug sales, using anonymity provided by the internet’s hidden sectors. They used cryptocurrency transactions to exchange drugs for digital currencies, which were then laundered through various cryptocurrency wallets, complicating the traceability of the illicit money flow. The US FBI successfully seized digital currency assets worth approximately Rs 1,500 crore linked to the criminal network. The ED also recovered critical documents relevant to the case, which were shared with the FBI for further analysis and evidence gathering.

The operation highlights the growing nexus between digital currencies and criminal enterprises and underscores the need for international collaboration in tackling sophisticated schemes. Further investigations are underway to dismantle the network and mitigate the risk posed by similar operations in the future. The crackdown serves as a warning to those using advanced technologies for criminal activities, showcasing global law enforcement entities’ extensive reach and resolve.

Dark Web Digest – April 2024 Edition

Dark Web Digest April 2024

The dark web is an online space that several individuals know about. It is frequently used for hacking, drug trafficking, and cybercrime. Events and new technologies affect the dark web and its users every month.

Some of the most important and interesting dark web news from March 2024 are summed up in this digest. If you haven’t heard these before, this digest should be on your next reading list. It includes the dark web’s negative things that affect everyone’s safety, privacy, health, and society. Additionally, these news stories will enable us to stay safe on the dark web and make us more aware of how dangerous it could be for us.

We will give you more information, ideas, and sources for each news story. You can then take the right safety steps and stay engaged with the future.

AT&T alleges that data of 73 million customers were leaked on the ‘dark web’

AT&T, the largest telecommunication network in the United States, has reported a breach involving personal information belonging to millions of past and present customers, including Social Security numbers (SSNs), passcodes, and contact details. The breach, discovered on the “dark web,” affected approximately 73 million accounts. 

The hacked data appears to be from 2019 or earlier and does not include personal financial information or phone records. AT&T planned to notify all 7.6 million existing account users whose sensitive personal information had been compromised about the breach. The company has already reset the passcodes and is investigating the situation. 

AT&T

The vulnerability was originally disclosed on a hacker site over two weeks ago, and it is unknown whether the leak is related to a similar breach in 2021 that was widely reported, but AT&T did not admit it. A hacker is alleged to have gained access to the data of 70 million AT&T consumers, including their names, addresses, phone numbers, social security numbers, and dates of birth. If the company fails to notify impacted customers, it will likely face class action lawsuits. AT&T faced challenges earlier in February after an outage temporarily knocked out mobile phone service for thousands of users.

StealthMole gets $7 million for its A.I. dark web spying business.

Singapore-based Singapore-based company StealthMole has secured funding from Korea Investment Partners (KIP), a joint venture between RHL Ventures, Penjana Kapital, KB Investment, Hibiscus Fund, and Smilegate Investment. The funding will be used to support StealthMole’s expansion into new markets and the application of its technology to more commercial uses. 

The company uses 255 billion analyzed data points from the dark web, deep web, and hidden sources to trace criminals, aiding governments and law enforcement in early risk mitigation and criminal tracking. StealthMole’s founder, Louis Hur, cited a critical market gap in cybersecurity and white-hat hacking and a lack of data points and information networks, specifically within Asia. 

The company’s managing director, Kim Min-Q, emphasized the company’s agility in addressing the increasing rampantness and advancedness of cybercrimes as organizations worldwide digitize. StealthMole, co-led by Simon Choi and Hur, is a threat investigator and specialist in enterprise I.T. security. The cybersecurity sector faces a challenging market environment, with decreased valuations and increasing pressure to sell while competing for vital funding and collaborations.

Change Healthcare might have stopped a $22 million dark web ransom

A hacker has reportedly accessed the data of numerous healthcare firms partnered with Change Healthcare, posing a risk that the affiliate hacker still possesses sensitive medical information. The $22 million ransom would be a profitable score for AlphV, as it is the largest payment in the history of ransomware. 

Change Healthcare

The attack shows AlphV’s comeback after being the target of an FBI operation in December. 

The group vanished and renamed multiple times, with earlier incarnations under the names Darkside, BlackMatter, and BlackCat. The hackers working under that Darkside handle were responsible for the 2021 Colonial Pipeline ransomware attack, which triggered the shutdown of gas transportation across the Eastern Seaboard of the U.S. and resulted in a brief fuel shortage in some East Coast cities.

More than 225,000 chatGPT logins are being sold on dark web markets.

Between January and October 2023, over 225,000 logs containing compromised OpenAI ChatGPT credentials were made available for sale on underground markets, according to Group-IB. These login details were found in information stealer logs related to LummaC2, Raccoon, and RedLine stealer malware. The number of infected devices decreased slightly in mid-and late summer but grew significantly between August and September. 

Between June and October 2023, over 130,000 unique hosts with access to OpenAI ChatGPT were infiltrated, a 36% increase over the first five months of 2023. The sharp increase in ChatGPT credentials for sale is due to the overall rise in the number of hosts infected with information stealers, data from which is then put up for sale on markets or in UCLs. 

Threat actors from Russia, North Korea, Iran, and China are experimenting with artificial intelligence (AI) and large language models (LLMs) to complement their ongoing cyber attack operations. The abuse of valid account credentials by threat actors has emerged as a top access technique, primarily fueled by the easy availability of such information via stealer malware.

Dutch citizens’ sensitive documents are taken and shared on the dark web

Thousands of stolen passports and other sensitive documents have been discovered on the dark web, a hidden part of the internet, where criminals use them for identity fraud and fraud. Over 5,100 digital copies of I.D.s have been published on the dark web, and RTL Nieuws has monitored all ransomware attacks and the data stolen for a year. Other sensitive documents, such as account statements, pay slips, and divorce papers, can also be found on the dark web. 

Malicious parties can use these documents to commit identity fraud and transfer bank accounts, loans, or telephone subscriptions to the victim’s name. The majority of victims are unaware of their sensitive data and documents being on the dark web, fearing that criminals will misuse their identity. 

The Dutch Data Protection Authority is concerned about the severity of the consequences for victims, as many are unaware of the theft. Victims like Teun are shocked by the situation and wish they could have taken action.

Swedish hospital’s stolen information being sold on the dark web

A hacker group, Medusa, has listed data stolen from a Swedish hospital, Sophiahemmet, for sale on its dark web website. The group is demanding a million U.S. dollars to delete the data and has published proof of compromise. The dark web is a hidden part of the internet that requires special software, configurations, or authorizations to access. 

Sophiahemmet Hospital

The attack knocked out telephones at the hospital overnight, causing it to shut down all computers as a security measure. Region Stockholm activated stabsläge, which has the lowest level of heightened preparedness used in healthcare services. 

Many files from the attack are up for sale, although the hospital has not confirmed the amount of data affected. The attack is the latest in a series of cyber attacks targeting Swedish businesses and public authorities, although it is not known whether this attack is connected to previous incidents. Akira, a Russian hacker group, has threatened to leak data from Bjuv, a small municipality in southern Sweden, in the form of confidential documents, contracts, agreements, and personal files.

Alleged Data Breach: 15,500 Mexican Debit/Credit Cards Sold on Dark Web

A dark web actor, known as “powerup,” has sold over 15,500 debit and credit cards linked to Mexican citizens. The sale was advertised on an underground forum, with an initial bid of $47,000. The seller, known as “powerup,” assured potential buyers of a “fresh database” originating from Mexico. This is part of a global credit and debit card skimming campaign. 

Dark web marketplaces for credit and debit cards serve as conduits for the illicit trade of stolen payment information, catering to various cybercriminals. Traditionally, criminals would capture or purchase card data for personal use. 

However, the methodology has evolved, with modern methods transcending traditional physical card skimmers, including sophisticated digital attacks and large-scale cyber breaches. Mastercard’s recent report revealed a case involving the illicit card testing service Try2Check, described as the “gold standard” of unauthorized credit card verification platforms. The underground economy surrounding debit and credit card fraud still exists despite law enforcement efforts.

Massive Increase in Russian Dark Web Posts About U.S. Election Interference in 2024

The last news concerns the Surge in Russian Dark Web Posts About the U.S. Election. In the first two months of 2021, there has been a significant increase in dark web discussions about election interference, with most of these discussions referring to the U.S. presidential election and written in Russian. Analysts at NordVPN found that in 2022, there were 26 such discussions on hidden forums, but it increased to 101 last year, a nearly 400 percent increase. 

The company cautioned that the chatter did not indicate a cyberattack or foreign influence operation but suggested that artificial intelligence (A.I.) improvements could make disinformation easier to produce and more convincing.

Russian election interference has been a concern since 2016, with the Kremlin meddling in the U.S. presidential election in a systematic fashion. In 2021, a report by U.S. intelligence agencies found that Putin authorized a range of government organizations to conduct interference operations aimed at undermining Joe Biden, while Iran carried out a “multi-pronged covert influence campaign” intended to undercut Trump. Experts are most concerned about using A.I. to create fake leaks that could damage candidates.

In the past year, there has been an explosion in the sophistication and adoption of A.I. software, with models able to generate text and images, edit videos, and find patterns in large datasets. However, with every positive use of the emerging technology comes the potential for negative ones, such as deepfakes, which are used to create involuntary pornography and false political narratives.

Dark Web Digest – March 2024 Edition

Dark Web Digest - March 2024

This month also brought up a lot of happenings in the dark web, the hidden part of the internet that is often used for illegal and malicious activities. From ransomware attacks and cybercrime crackdowns to AI phishing and zero-day exploits, the dark web in 2024 has seen the emergence of new types of cyber threats and criminal activities. 

Let’s discuss some of the most notable and alarming events that took place in the dark web in February 2024, and what they mean for the security and privacy of users and organizations.

34 million Roblox credentials have been leaked on the dark web

There have been a lot more cybercriminals working between 2021 and 2023, as 34 million Roblox accounts were found on the dark web. There were 4.7 million hacked accounts in 2021, but there were 15.5 million in 2023, which is a 231% increase. 

The number of hacked accounts on 11 game platforms, such as Twitch, Electronic Arts, Sony PlayStation, and Steam, has increased by 112% since 2021, according to the Kaspersky Digital Footprint Intelligence report. Cybercriminals often use sneaky tricks, like putting info stealers in cheat code files or posting harmful download links on popular sites like YouTube to take advantage of students’ trusting nature.

Criminals are often more interested in Steam accounts because they can be used to steal real money. Roblox accounts are still being used to get in-game gold and other valuable items, though. Platform owners can make their sites safer by using special services to find and quickly block accounts that have been hacked. 

Using different passwords for each service, using two-factor authentication whenever possible, and using reliable security solutions are just a few of the security steps that people and businesses can take to lower the risks of password leaks.

The FBI and its partners take down the dark website of the world’s most active ransomware gang

The FBI and its partners around the world have taken down a dark web site that LockBit, the most prolific ransomware gang in the world, used to demand money from its victims. LockBit has been a threat to businesses all over the world, including US healthcare companies. 

The NCA and FBI have made software that hackers may be able to use to unlock the computers of “hundreds” of people around the world. The 

NCA statement suggested that LockBit had been hacked for a long time, which let police get the hackers’ “source code.” 

Taking over a ransomware group’s dark website pushes cybercriminals to build new computer systems to use to demand money from victims, and it can also mean that police have more access to the hackers’ networks. 

LockBit is thought to have members or illegal partners in China, Russia, and Eastern Europe. Hackers have put information about LockBit victims online, which shows that it makes up a quarter of the ransomware market. Private and public agents all over the world will be watching what LockBit does next. Ransomware gangs, which are often based in Eastern Europe and Russia, have been fighting the FBI and its partners around the world for a long time. This operation is the latest step in that fight.

A dark web drug dealer is sentenced to 10 years

Gabriel Alva, a 32-year-old cybercriminal from Los Angeles, was given a $1.3 million cryptocurrency term after being found guilty of planning to use the dark web to sell heroin, cocaine, and methamphetamine. 

Under the fake names Diablow, RaiseAppeals, and RaisedByDiablow, Alva and his partners sold drugs illegally on the Silk Road, Dream, and Nightmare boards. 

They took cryptocurrency as payment and sold drugs like crystal meth, heroin, cocaine, and more. In 2019, federal officials raided Alva’s home and found 24 kg of methamphetamine, 2 kg of heroin, and 2 kg of cocaine. This was the end of Alva’s drug life. The feds also took six guns, including a Remington shotgun, a Smith & Wesson assault rifle, and an AR-15 assault rifle that had not been made into a special weapon.

Thousands of stolen anydesk login credentials for sale on the dark web

Cybersecurity experts have found several threat actors selling hacked AnyDesk accounts on a site in the Russian language on the dark web. The recent security breach and the sale of AnyDesk login credentials are not related. 

The recent security breach was caused by infostealing malware infecting PCs to steal private information. A threat actor going by the name “Jobaaaaa” has been seen selling Bitcoin or Monero (XMR) worth $15,000 from 18,317 hacked AnyDesk accounts

The trades were made possible by escrow services. However, Alon Gal of Hudson Rock has disagreed with Resecurity’s results and said that the threat actor is selling more than 30,000 AnyDesk accounts. The hacked AnyDesk accounts are being sold on Exploitin, a Russian-language website for cybercrime and hackers. 

If your account works, terrible things could happen, like losing money, having your data or identity stolen, having your image hurt, having your business interrupted, or even being hit by ransomware.

FBI effort to target illegal dark web crimes, a man was arrested in Malta

A 27-year-old Maltese man was arrested on suspicion of working with others to sell malware on the dark web and giving advice on the Hack Forum. A type of malware called a remote access Trojan (RAT) lets hackers get into victims’ computers or servers without permission. 

This lets them manage them from afar and maybe even take advantage of them. The Maltese Police’s Cybercrime Unit was in charge of local investigations after the US asked for help. The suspect was caught at work in Gudja, and searches in several places turned up important evidence that is being used in the case. 

He agreed to be sent back to the US, where he will be charged in a federal court. Until further court hearings, he is being held in custody at the Corradino Correctional Facility. 

Law enforcement agencies from several countries, including Nigeria, worked together with Europol to go after the sale of illegal software on the dark web at the same time. A Nigerian partner who lived in Nigeria was also caught as part of the probe.

An Indian guy was arrested for selling 4500 GB of private data on the dark web

The hacker Amit Chand, who is 21 years old and from Rajasthan, was caught illegally viewing and selling private data on the dark web that belonged to the governments, military, and people of India, the US, China, and Ukraine. 

Chand also kept over 5 lakh people’s Aadhaar cards, PAN cards, and other payment information. Also found were files that belonged to the Islamic States and the Taliban. 

The house of Chand in Srikaranpur’s 49F village was searched by the Intelligence Bureau (IB) and district cops. They found 4,500 GB of data on several devices. 

Chand has been working on the dark web since 2018, but people have started to doubt him after he became more aggressive in the last two to three months. During the raid, authorities found more than 90 million US records as well as a lot of records from the Islamic State and the Taliban. The cops and IB are questioning Chand.

Sussex man sentenced to jail for running child abuse site worldwide

Martin Yates, a guy from Eastbourne, went to jail for his part in running The Annex, a global blog about child abuse on the dark web. About 90,000 people around the world were members of the site, which shared sexual abuse videos of babies and children. 

Between January and September 2020, Yates was the site’s assistant editor. He made sure rules were followed, gave advice on how to keep the site safe, and trained other people. He admitted that he planned or helped with the sexual abuse of children, made and distributed four obscene pictures of children, and had one otherwise illegal picture of a child. 

The National Crime Agency (NCA) and the Federal Bureau of Investigation (FBI) went after the admins of the site. 

Also sent to prison for 16 and 6 years were Nathan Bake, 28, and Kabir Garg, 34. William Spearman, who is 58 years old, was given a life sentence in jail in the US in January. In the US, 14 more men have been charged for their part in trying to run the site.

Man jailed for 16 years for tempering child abuse site

A car mechanic named Nathan Bake, who is 28 years old, was given a 16-year prison sentence at Chester Crown Court after admitting to 12 crimes linked to creating and moderating dark websites where child abuse content was shared. 

A man from Alabama ran the site The Annex, which had almost 90,000 users from all over the world. Bake was in charge of moderating it. Adult content like “hurtcore” and violent content involving babies and children were shared on the site. 

Branch commander of the National Crime Agency (NCA) Adam Priestley said that the spot was safe for everything. Prosecutor Anna Pope said that users would start by going to a “gateway” on the site using the Tor browser. 

They would then have to “gain the trust” of the people running the site before they could be sent to other places. 

Bake worked his way up in the online group for child molesters and was made second-in-command when the head moderator was arrested in May 2022. After Bake was arrested in November 2022, more than 3.6 million sexy pictures were found in his home.

Norton introduces tool for real-time tracking

There is good news above all trends, even though there are dangers. Dark Web Monitoring is a new tool that Norton has launched for Indian users. With this add-on to its security solution, users can see in real-time if online stores have their personally identifiable information (PII). 

This gives people the chance to fix the problem, like calling the bank or changing their passwords, to avoid scams. Norton says that, unlike digital companies like Google, its tool does everything. 

The Aadhaar numbers, ID numbers, and phone numbers of 815 million Indians were found on the dark web in 2023. As well as gamer tags, the tool can keep an eye on up to five insurance account numbers, email addresses, phone numbers, and up to ten credit card numbers. 

Norton tells people to be careful about giving out personal information online and to log out of temporary email accounts when they’re done using them.

Dark Web Digest – February 2024 Edition

Dark Web Digest - February 2024

Welcome to the Dark Web Digest, a monthly blog that brings you the latest news and trends from the dark web. The dark web is a hidden part of the internet that most people never see. It is where you can find illegal, dangerous, or controversial things. Some people use the dark web for good reasons, such as protecting their privacy or escaping restrictions. Others use it for bad reasons, such as buying drugs, weapons, or stolen data. But that is now just used to define the dark web, and there is much more to know!

In this February edition will explore some of the most exciting and essential stories from the dark web in January 2024. Remember, the dark web is not a place for the timid, so browse carefully and stay safe.

Fake X Gold Accounts For Sale On The Dark Web

The very first piece of news is the theft of X Gold accounts. A surge of fake or stolen X (Twitter) Gold accounts has been flooding marketplaces and forums on both the surface web and the dark web over the past year, according to a report by CloudSEK. Threat actors have used multiple techniques to forge or steal X Gold accounts since Elon Musk’s firm introduced its new verified accounts program in December 2022. The report identified the first advertisement for a Gold account on dark web marketplaces in March 2023. Cybercriminals selling these accounts use several methods to acquire them, including manually creating fake accounts, brute-forcing existing accounts, and using malware to harvest credentials and steal accounts. Prices for counterfeit or stolen accounts range from around $0.30 for a new X account without a checkmark to about $500 for a Gold account. CloudSEK recommends organizations close dormant accounts and has an alerting system to warn of stolen corporate social media account credentials and password protection practices. Employees should be trained on workplace cybersecurity practices, updated password policies, and educated against using cracked software and its dangers.

3,000 Dark Web Posts Found Misuse of ChatGPT and LLMs

Kaspersky’s Digital Footprint Intelligence service discovered nearly 3,000 dark web posts 2023 discussing illegal activities involving ChatGPT and other large language models (LLMs). These discussions included creating malicious alternatives, jailbreaking techniques, lists of malicious prompts, and discussions on stolen accounts with access to the paid version of ChatGPT. Threat actors on the dark web actively share knowledge on exploiting ChatGPT, discussing topics like creating malware, using artificial intelligence for processing user data dumps, and sharing jailbreaks to bypass content moderation policies. The research also found a high volume of conversations around tools like WormGPT, XXXGPT, and FraudGPT, which were marketed as alternatives to ChatGPT with fewer restrictions. The research comes just after OpenAI suspended a developer for creating a chatbot that mimicked U.S. Congressman Dean Philips. This act, the organization says, violated its rules on political campaigning or impersonating individuals without consent. The research highlights that ChatGPT can be used for misuse and that cyber criminals actively share knowledge on exploiting it.

Indian Pleads is guilty of running a Dark Web Enterprise and Losing $150 Million

Indian national Banmeet Singh has pleaded guilty to operating a global dark web enterprise to sell dangerous drugs to communities across America. He created vendor marketing sites on dark web marketplaces to sell controlled substances, including fentanyl, LSD, ecstasy, Xanax, Ketamine, and Tramadol. Singh personally shipped or arranged the shipment of drugs from Europe to America through U.S. mail or other shipping services. From mid-2012 through July 2017, Singh controlled at least eight distribution cells within the U.S., moving hundreds of kilograms of controlled substances throughout the U.S. The multimillion-dollar drug enterprise laundered millions of dollars of drug proceeds into cryptocurrency accounts, which ultimately became worth approximately USD 150 million. Singh faces an agreed-upon sentence of eight years in prison.

750 Million Indian Info For Sale On The Dark Web

Indian infosec firm CloudSEK has discovered records of 750 million Indian mobile network subscribers on the dark web, with two crime gangs offering the data for just $3,000. The 1.8TB trove contains mobile subscribers’ names, phone numbers, addresses, and Aadhaar details. CloudSEK claims threat actors obtained the data through undisclosed asset work within law enforcement channels rather than a leak from Indian telcos. The leak poses a considerable risk to individuals and organizations, potentially leading to financial losses, identity theft, reputational damage, and increased susceptibility to cyber-attacks.

Singapore-based crypto outfit Terraform Labs (TFL) filed for Chapter 11 bankruptcy in the United States, calling the move “a strategic, protective step” to continue executing its business plan while resolving outstanding legal proceedings. The company has assets and liabilities from $100 to $500 million.

India’s I.T. minister, Rajeev Chandrasekhar, has proposed a $1.2 million supercomputing and quantum computing hub, offering high-performance computing access to startups and micro, small, and medium enterprises. The public-private scheme will include graphic processing units in PPP mode with data centers in private space and public data centers under C-DAC (Centre for Development of Advanced Computing). Telstra International and Trans-Pacific Networks (TPN) have announced a partnership on the Echo undersea cable, connecting the U.S. directly to Singapore, Indonesia, and Guam.

African Bank Data Breach Claims of Customer Data on Sale

A dark web user, cnHunter, has claimed to have sold 1843 customer records of the African Bank, which are now up for $250. The data breach includes sensitive details such as customer names, account numbers, phone numbers, serial numbers, and bank account types. The threat actor claims to have complete access to the bank’s database, allowing potential buyers to view, add, edit, and delete information related to guarantor lists, customer lists, and new and old forms. The Cyber Express has sought more information from the affected organization, but no official statement or response has been received, leaving the claims unverified. 

The African Bank website appears to be operational, adding to the uncertainty surrounding the authenticity of the reported breach. The European Central Bank (ECB) is set to conduct a cyber resilience stress test on 109 directly supervised banks in 2024, focusing on recovery measures rather than just preventive capabilities. The test will involve 28 banks undergoing an enhanced assessment, providing additional information on how they dealt with the simulated cyberattack.

Child Sex Offender Admits Being A Moderator Of Dark Web Abuse Site

A man from Swindon, Brent Saunders, has pleaded guilty to being a ‘Global Moderator’ on a dark website dedicated to sharing child sexual abuse content. The National Crime Agency (NCA) discovered that the site had over 2,000 members and was only accessible using Tor. The moderator, Wetty’, was heavily involved in running the site, providing advice on personal security, and evading law enforcement detection. Saunders was identified as the man behind the account and had previous convictions relating to the sexual exploitation of children.

In August 2022, NCA officers arrested Saunders at his home in Freshbrook. He confirmed that he held the rank of Global Moderator and had uploaded indecent images of children to the site. He also admitted his sexual interest in children, particularly girls aged 8-12. Investigators recovered data relating to his account, including over 3,000 posts and private messages he sent to other users.

Wiltshire Police charged Saunders with breaching the sexual harm prevention order and sentenced them to two years and eight months in prison for the breach. Last year, he was charged with a further nine counts, including arranging/facilitating the sexual exploitation of a child under 13, participating in the criminal activities of an organized crime group, distributing and making indecent images of children in categories A-C, and possessing a prohibited image of a child.

Wirex And Zerofox New Strategies Against Dark Web Activities

UK-based digital payment platform Wirex has integrated ZeroFox’s Dark Web Monitoring tool into its system to combat Dark Web activities and money mule threats. The integration allows for real-time dark web scanning for potential dangers like leaked data and compromised credentials. Wirex aims to benefit from ZeroFox’s advanced monitoring capabilities, which issue detailed alerts about potential threats, ensuring a quick response to incidents. The integrated system identifies and responds to suspicious account activities, reducing the risk of financial fraud and reinforcing user transactions. Wirex is also committed to compliance with Know-Your-Customer (KYC) regulations and has partnered with banks and financial institutions to provide online security tools and expand its suite of services. The company also offers educational content and partnerships to empower users about security and responsible financial practices.

Father and Son Duo Sentenced in Dark Web Bitcoin Case

The last news we got in this digest is about father Joseph Farace and his son, Ryan Farace, who have been sentenced to federal prison for operating an illegal dark web drug business and a Bitcoin laundering scheme. Ryan earned over 9,138 Bitcoins through drug sales from 2013 to 2017. In 2020, he arranged to transfer 2,874 BTC to an overseas account, leading to the seizure of 2,957.9 BTC. The cases highlight concerns over cryptocurrency use in money laundering.

Conclusion

That concludes our January edition of the dark web digest. We hope you found it informative and insightful. The dark web is constantly evolving and dynamic, with new daily developments and challenges. We will return next month with more stories and tips from the dark web. Until then, stay safe and keep in touch.