Dark Web Digest – January 2024 Edition

dark web digest - January 2024

As we all know, the dark web is a mysterious part of the internet world, often attracting controversy, illegal activities and curiosities. It can be accessed by a TOR browser that runs against legal terms and goes against law enforcement and government oversight. In simple terms, it is home to several illegal and illicit activities, including drug trafficking, hacking and cybercrime, yet also to some legitimate and useful purposes such as activism, privacy protection and journalism. 

In the previous editing, we discussed some shocking news and this month, nothing different. In this dark web digest edition of January 2024, we will see some latest trends, news and developments related to the dark web. 

Let’s get started.

Cyber Attack Exposes Yakult Australia Employee Files on Dark Web

Yakult Australia, a popular probiotic company, has been targeted by a ransomware attack that has exposed its company records and sensitive employee documents, including passports, on the dark web. The company, based in Melbourne, is working with cyber incident experts to investigate the extent of the incident. All offices in Australia and New Zealand remain open and continue to operate. The group responsible for the breach is DragonForce, which has listed nearly two dozen targets that have refused to cooperate since the beginning of December. The targets range from a Texas-based family charity to commercial entities like Coca-Cola in Singapore and a South Australian-based bathroom manufacturer.

A sample of the 95 gigabytes of data leaked by ABC Investigations found company records dating back to 2001, including scans of passports and driver’s licenses, pre-employment medical assessments and certificates, salaries, and performance reviews. At least one of the passport scans belongs to a warehouse employee. In the leaked cache, the ABC has also seen Japanese passports, where Yakult’s parent company is based. A separate database also contains the names and addresses of nearly 9,000 people. It is unclear if these are customer records, but ABC has verified the accuracy of some of the names and addresses.

Yakult Australia became aware of the cyber attack on December 15, and DragonForce listed the probiotic company as one of its victims before publishing the stolen cache on Christmas Day morning. ABC Investigations has not independently verified each of DragonForce’s published leaks.

Dark Web Ads Target Booking.com Partners, Affecting Customer Security

Booking.com has been targeted by scammers for years, with hackers now posting ads on dark web forums to obtain the passwords of hotel partners. The scammers gain access to a hotel’s extranet, install malware, access passwords, and mimic IP addresses to bypass two-factor authorisation. They use the hotel partners’ login credentials to enter their Booking.com accounts and send urgent messages to customers urging them to send money to the scammers or risk losing their reservations. Booking.com acknowledges that the hackers are not gaining access to Booking.com’s backend systems but acknowledges that the scammers have broken into hotel partners’ accounts. 

The hackers then communicate with Booking.com customers/hotel guests, urging them to send money to the fraudsters. The hackers then message customers from the official app and can trick people into paying money to them instead of the hotel. Booking.com has been unable to make the problem disappear, and the company has been working diligently to support its partners in securing their systems and helping potential customers recover lost funds. The company has been publishing best practices for avoiding these scams and is working to help customers recoup lost funds.

German Authorities Dismantle Global Dark Web Hub ‘Kingdom Market’

German law enforcement has disrupted the dark web platform called Kingdom Market, which specializes in selling narcotics and malware to thousands of users. The operation, which involved collaboration from the U.S., Switzerland, Moldova, and Ukraine authorities, began on December 16, 2023. Kingdom Market has been accessible over the TOR and Invisible Internet Project (I2P) anonymisation networks since March 2021, trafficking illegal narcotics, advertising malware, criminal services, and forged documents. As many as 42,000 products were sold via several hundred seller accounts on the platform before its takedown, with 3,600 originating from Germany. Transactions were facilitated through cryptocurrency payments, with the website operators receiving a 3% commission for processing the sales of illicit goods. The operators of ‘Kingdom Market’ are suspected of commercially operating a criminal trading platform and of illicit trafficking in narcotics. In addition, one person connected to the running of Kingdom Market has been charged in the U.S. with identity theft and money laundering.

GTA 5 Source Code Leaked Online One Year After Rockstar Hack

The source code for Grand Theft Auto 5 was leaked on Christmas Eve, a year after the Lapsus$ hacking group hacked Rockstar Games and stole corporate data. The hackers claimed to have stolen the GTA 5 and GTA 6 source code and assets, including a GTA 6 testing build. They also shared GTA 5 source code samples as proof of their theft.

Security research group vx-underground spoke to the leaker on Discord, who said the source code was leaked sooner than expected. They claimed to have received the source code in August 2023, motivated by combating scamming in the GTA V modding scene. BleepingComputer reviewed the leak, which appears to be legitimate GTA 5 source code, but could not independently verify its authenticity.

The Lapsus$ hackers are known for their skills in performing social engineering and SIM-swapping attacks to breach corporate networks. They have hacked companies such as Uber, Microsoft, Rockstar Games, Okta, Nvidia, Mercado Libre, T-Mobile, Ubisoft, Vodafone, and Samsung. Their success led the Department of Homeland Security (DHS) Cyber Safety Review Board to analyze their tactics and share recommendations for preventing similar attacks in the future.

While the Lapsus$ group has not been very active since members were arrested, some members are now believed to be active in the loose-knit hacking collective known as Scattered Spider. Scattered Spider shares similar tactics to Lapsus$, utilizing social engineering, phishing, MFA fatigue, and SIM-swapping attacks to gain initial network access to large organizations.

Health Data Breach Sparks Extortion Threats

A cyberattack on Integris Health, Oklahoma’s largest not-for-profit health network, compromised the personal information of two million patients. The breach was confirmed on November 28, 2023, and extortion emails were sent to patients threatening to sell their stolen data to other threat actors. The emails contained links to a dark web page where stolen data, including names, Social Security numbers, dates of birth, and hospital visits, was listed for about 4,674,000 people. The hackers who claimed responsibility for the cyberattack began sending the extortion emails on December 24. The emails claim to include dates of birth, Social Security numbers, addresses, phone numbers, insurance information, and employment details. The hackers threaten to sell the stolen data of those who do not pay the $50 deletion fee by January 5, 2024.

The cyberattack on Integris Health is similar to those used in the attack on Fred Hutchinson Cancer Center, where patients were subjected to similar extortion emails. Integris Health advised patients not to reply to the hackers or follow any instructions found in the extortion emails. A PDF containing frequently asked questions about the incident can be found at the bottom of the page. Affected patients are advised to stay alert and take necessary safety measures to reduce risks related to the compromised data.

Enhancing Cyber Security in Greece Amidst Frequent Attacks

The recent cyber-attacks targeting public bodies in Greece have highlighted a weakness in security, which the government of Prime Minister Kyriakos Mitsotakis plans to address with new legislation to create a National Cybersecurity Authority. The bill is about to be submitted for public consultation. Criminal groups prefer certain infrastructures in public sector services in Greece, possibly due to unpreparedness or laxity in taking protection measures.

According to CheckPoint Research, the number of cyber-attacks globally jumped 38% between 2021 and 2022. In the last six months, the top six targets in Greece were healthcare, retail/wholesale, finance/banking, manufacturing, and transportation. HPPC suffered a DDoS attack on November 8 but said it had not detected any data breaches; hacker group Ragnar Locker took responsibility for the attack on DESFA in August last year and posted 361 gigabytes of DESFA data on the dark web; the Greek postal service announced it had been hit in December 2022, nine months after the actual attack.

An organized security system is crucial, as achieving security is a long-term effort and not only a technical problem. A major problem is that when an organization is attacked, it does not provide all the necessary information in time. The Hellenic Data Protection Authority (DPA) has not issued any fines for personal data breaches following cyber-attacks.

Greece’s left-wing opposition party SYRIZA has accused the government of “inaction on the critical issue of cyber-security,” but Mavridis said cybercriminals are always ahead of everyone else. The point is not to be too far behind, as criminals constantly develop new ideas and attacks.

Currently, the fight against cyber-attacks in Greece is the responsibility of several different organizations. The military’s Cyber Defence Directorate protects the internet infrastructure of the Greek armed forces, the Cyber Security Operations Centre of the intelligence services protects the state’s digital infrastructure, and the police’s Cyber Crime Division handles online crime.

The legal framework, though complex, looks sufficient to prevent and fight cyber-attacks. However, the reality lags, with low awareness and education levels and no serious investment by companies in protecting their systems and compliance with the requirements of the existing legal framework. Greek experts suggest that the best way to deal with cyber-attacks is through prevention, detection, reaction, and sharing of information, as well as specialized cyber security personnel and heightened security awareness.

Vitoratos called for a strong National Cybersecurity Authority that can monitor the implementation of Greece’s National Cybersecurity Strategy and the compliance of actors while also being transparent and open with the public and civil society.

Rising Dark Web Sales of Stolen Data Prompt Cybersecurity Warning

CyberSecurity Malaysia has warned of a significant rise in data breach incidents from January to November this year, with stolen data being sold on the dark web. The increase includes Personally Identifiable Information (PII), including full names, permanent addresses, household income, identification numbers, email addresses, or phone numbers of victims. 

CyberSecurity Malaysia emphasizes the importance of protecting personal and sensitive data, as it safeguards privacy, individuals, and business reputation. The company also urges organizations to be responsible for preventing such incidents and handling data exposure incidents appropriately.

Individual Selling Fentanyl Online Receives Life Sentence for 29 Overdose Deaths, Including 2 in Oregon

A Pennsylvania man, Henry Konah Koffie, was sentenced to life in federal prison for selling fentanyl online, which prosecutors say caused the overdose deaths of at least 29 people. Koffie, 38, sold a synthetic drug called furanyl fentanyl, a synthetic drug with no medical use. Between September 2015 and his arrest outside Philadelphia in July 2017, Koffie made 7,849 separate transactions, selling the drug in all 50 states. In Oregon, law enforcement linked Koffie to three overdoses, two of which ended in death. In March, a jury in Portland convicted Koffie on several felonies, including two counts of distribution of a controlled substance resulting in the death of an adult.

Koffie received fentanyl in the mail from suppliers in China, then advertised on AlphaBay, a former dark web site, and shipped the drugs through the mail to customers across the country. Investigators linked Koffie’s sales with overdose deaths in at least 15 states, including Idaho, Texas, Florida, Hawaii, California, New York, Minnesota, and Ohio. Scott Kerin, an assistant U.S. Attorney who prosecuted the case, called the drug Koffie was selling poison.

Koffie’s defense attorney asked Mosman not to sentence him to life in prison, stating that life is redeemable. Mosman acknowledged that it is a rare case that warrants a life sentence, as the callousness and cruelty with which a defendant commits a crime that kills others merits the highest sentence.

Dark Web Digest – December 2023 Edition

Deep Web Digest - December 2023

Welcome to the Dark Web Digest for December 2023. This month, we are going to sее a concisе overview of the latest dеvеlopmеnts on thе dark side of thе internet. We bring some terrifying stories highlighting thе untiring threats posed by thе dark web from stolen university data appearing on illicit markets to thе exposure of a ransomware mastermind who shared too much.

In cybersecurity, partnerships bеtwееn Blackbird.AI and Dark Owl aim to combat narrative attacks, while thе NHRC chief calls for thе dеvеlopmеnt of digital forensic infrastructure to tackle dark web activities.

Legal actions include a life sеntеncе for an individual running dark web child exploitation sites and thе suspension of MyGov accounts linkеd to dark web fraud kits. A ‘wеll-dеsignеd scam’ targеting Booking.com customers underscores thе-evolving nature of dark web schemes, emphasizing thе ongoing nееd for vigilance.

There are not just these; this digest got more from above this. Stay tuned for some latest trends and news from the darkwеb novеrmеbr 2023 digest. Let us get started!

British Library hack: Customer data offered for sale on dark web

The first news is from the British Library. The British Library has confirmed that user data was hacked in a cyber-attack and offered for sale on the dark web. The attack on October 31 continues to affect the library’s website, online systems, and some onsite services. The ransomware group Rhys Ida, claims to be behind the attack and plans to auction off the stolen data. 

The price for data, including passport scans, was set at 20 Bitcoin (£596,459). The library has warned users who use the same password elsewhere to change it as a precaution. The library will continue working with cybersecurity specialists to examine the material and advice users on practical steps. 

The library has also confirmed that some employee data was leaked in the attack, but there was no evidence of compromised user data. The ransomware group shared an image on the dark web showing various documents, some of which appear to be HMRC employment contracts and passports. The cybercriminals announced an auction for “exclusive, unique and impressive data” that would end before 08:00 GMT on November 27.

Sensitive data stolen from Aegean University leaked to dark web

The University of the Aegean has published hundreds of files containing sensitive data stolen by the cybercriminal group Lockbit. The university’s electronic systems were targeted with Lockbit’s ransomware on March 2, and the attackers demanded payment or the release of the seized files. The University of the Aegean has informed the Data Protection Authority and is investigating the leaked files. 

The files contain the personal data of university employees, process forms for tenders, building plans, internal university documents, and certificates of completion of studies. Lockbit infects an organization’s system with ransomware and coerces targets into paying, with a countdown displayed when the data will be released.

Blackbird.AI and DarkOwl Partner To Enable Organizations To Identify Plot Attacks Across The Dark Web

Blackbird.AI, a leader in AI-driven Narrative and Risk Intelligence, has partnered with DarkOwl, a leading provider of Darknet Data, to help organizations identify narrative attacks across the dark web. Darknet and messaging apps are complex, noisy, and opaque social platforms often used by bad actors to develop and deploy harmful narratives and cyber attacks. 

Through this partnership, organizations gain valuable insights that have historically been difficult for cyber and communications professionals to see and protect themselves against. The Constellation Narrative Intelligence Platform is designed to detect narrative attacks and manipulation, including misinformation and disinformation. 

DarkOwl offers the world’s largest commercially available database of information continuously collected from the darknet. It enables Blackbird.AI and its customers to turn this data into a powerful tool to identify narrative risks at scale and drive better decision-making. The darknet datasets are updated from thousands of sites across multiple darknets daily. They will be made available through Blackbird.AI’s Constellation Platform, allowing users to parse and analyze the data for specific narrative attack use cases.

Develop digital forensic infrastructure to deal with Dark Web: NHRC chief.

Justice Arun Kumar Mishra, chairperson of the National Human Rights Commission (NHRC), has expressed concern about the Dark Web and its potential threats to society. He emphasized the need for a digital forensic infrastructure to combat the Dark Web, which is 96% of cyberspace and is used for criminal purposes such as child exploitation, privacy destruction, modern slavery, trafficking, and ransom demands. 

Mishra also emphasized the need to invest in a broad-based digital forensic infrastructure to combat cyberspace misuse and criminal commerce while ensuring the digital divide is nonexistent. He also insisted on the importance of violence-free elections and gender equality, stating that violence has no place in the democratic process. 

Ransomware Mastermind Uncovered After Oversharing on Dark Web

Researchers were tasked with a ransomware-as-a-service (RaaS) operation by farnetwork, a cybercriminal known by various aliases. The Nokoyawa affiliate business’s affiliate was involved in the process, which involved at least five different ransomware strains. Farnetwork demonstrated its ability to execute privilege escalation, use ransomware to encrypt files and demand cash for an encryption key. 

The Group-IB researcher learned that Farnetwork already had a foothold in various enterprise networks and needed someone to deploy the ransomware and collect money. The deal involved the Nokoyawa affiliate receiving 65% of the extortion money, the botnet owner receiving 20%, and the ransomware owner receiving 15%. 

Farnetwork’s ransomware activities can be traced back to 2019, with details about past operations with Nefilim and Karma ransomware and payments as high as $1 million. The crook also mentioned past work with Hive and Nemty.

‘Scam-in-a-box’: MyGov suspends thousands of accounts linked to dark web fraud kits

Thousands of MyGov accounts are being suspended each month due to concerns that they have been breached via “scam-in-a-box” kits sold by criminals on the dark web. These products created fake websites and provided the specialist knowledge required to launch phishing attacks on Centrelink, the Australian Tax Office, and Medicare accounts. So far this year, more than 4,500 MyGov scams have been confirmed, with thousands of accounts suspended each month due to suspected fraud.

The government services minister, Bill Shorten, said Australians had already lost $3.1bn to scams this year, and authorities were taking the issue seriously. The problem with these hacks and the proliferation of phishing scams we now see is that increasing amounts of stolen identifying details end up on the dark web.

Scammers and hackers are targeting MyGov until the government overhauls its I.D. verification, which it is in the final stages of doing. The Albanese government is determined to disrupt malicious actors by bolstering online defences. It is working closely with Senator Katy Gallagher to establish a digital I.D. that will be a crucial line of defence against cybercrime when found. Last year, after the Optus breach, the government confirmed it was considering using myGov or its myGovID system to centralize digital identity authentication.

In August, the Australian Tax Office warned people against clicking on emails and text message scams directing people to fake MyGov websites. In 2019, Guardian Australia reported on dark vendors offering Medicare details for US$21 ($33) and other vendors charging up to US$340 for fake Medicare cards alongside other fake forms of identification, such as a New South Wales driver’s license.

Man Sentenced to Life in Prison for Running Four Dark Web Child Exploitation Websites

A Missouri man, Clint Robert Schram, has been sentenced to life in prison for running four websites dedicated to sharing images and videos of child sexual abuse. Schram, 55, of Kansas City, hosted, managed, and maintained these websites from his home, each operating over the dark web. Each website was devoted to advertising, distributing, and exchanging images and videos depicting the sexual abuse of children. Schram recruited, managed, and directed different tiers of staff members who helped run the websites.

On May 10, a federal jury convicted Schram of one count of engaging in a child exploitation enterprise and four counts each of advertisement of child pornography and conspiracy to advertise child pornography. The U.S. District Court for the Western District of Missouri has charged several defendants with Schram’s websites.

The FBI’s Child Exploitation Operational Unit and Kansas City Field Office investigated the case, with assistance provided by FBI field offices and resident agencies in Portland, Oregon; Chattanooga, Tennessee; Tulsa, Oklahoma; and Poulsbo, Washington; Homeland Security Investigations’ offices in Burlington, Vermont, and Boston; and the Criminal Division’s Child Exploitation and Obscenity Section’s (CEOS) High Technology Investigative Unit.

CEOS Trial Attorney Kyle P. Reynolds and Assistant U.S. Attorneys Alison D. Dunning and David Luna for the Western District of Missouri are prosecuting the cases, with valuable assistance from the U.S. Attorney’s Offices for the District of Oregon, District of Vermont, Northern District of Oklahoma, Western District of Washington, and Eastern District of Tennessee. 

Project Safe Childhood, a nationwide initiative launched in May 2006 by the Justice Department, marshals federal, state, and local resources to better locate, apprehend, and prosecute individuals who exploit children via the internet, as well as to identify and rescue victims.

Booking.com customers warned of ‘well-designed scam’ putting details for sale on the dark web

Booking.com customers have been warned of a “well-designed scam” that has seen account details sold on the dark web. Cybersecurity firm Secureworks has found that criminals target the website’s partner hotels to steal user details and then send phishing emails to the customers, claiming their reservation will be cancelled if they do not provide payment information urgently. The tactic is seeing a “high success rate,” and Booking.com is aware of some of its partners having been affected in recent months.

The scam unfolds in two phases, starting with hotels targeted by scam emails. They often claim to be from a guest who has left valuable documents during their stay, who then sends a follow-up email directing the hotel to a Google Drive link purporting to show an image of the lost item. The link contains malware called Vidar Infostealer, allowing criminals to access the Booking.com account portal people use to make their reservations. From there, they can target the customers.

In one case involving a hotel in Scotland, a receptionist was duped by a scam caller who claimed to want to book a room for herself and her child with severe allergies. The attachment contained the malware. It gathered details of all the hotel’s Booking.com customers and sent them fraudulent emails saying they had 24 hours to pay.

Secureworks has found Booking.com credentials sold on dark web forums for up to $2,000 (£1,576). The company has recommended that hotels make staff aware and teach them how to identify such attacks, while customers should use multifactor authentication to protect their accounts. They should also question any emails or app messages requesting payment details and contact Booking.com or the hotel directly if they have concerns.

Booking.com has made significant investments to limit the impact of online fraud and has shared additional tips and updates with partners about protecting themselves and their businesses.

The doctor planned to have his girlfriend killed by hiring a hitman over the dark web, U.S. feds say

A Georgia doctor, Dr. James Wan, hired a hitman over the dark web and sent thousands of dollars in Bitcoin to have his girlfriend shot to death. In April 2022, Wan placed a murder-for-hire order through a “dark web marketplace” with instructions to kill his girlfriend. He instructed the hitman to “shoot and go” and sent a 50% down payment of about $8,000 (RM37,300) in Bitcoin to ensure the murder would be carried through.

Wan messaged the marketplace’s administrator two days after hiring a hitman to confirm his Bitcoin payment was received. After learning the amount wasn’t received, Wan sent another Bitcoin payment of about $8,000 (RM37,300) to ensure the hitman received the money. The marketplace administrator confirmed the second payment went through to Wan’s escrow account and asked if he wanted his girlfriend to die in an “accident or normal shooting”.

The FBI learned of Wan’s “cold-hearted” plot and extended protection to his girlfriend, whom agents informed of the hit Wan had put on her. On October 17, Wan pleaded guilty to one count of using a facility of interstate commerce in the commission of murder-for-hire.

Wan’s motives for wanting his girlfriend dead are unclear, as prosecutors did not specify possible reasons. He is scheduled to be sentenced in the case on January 18.

That is from last month’s dark web digest of December.  Every month, we uncover something novel and intriguing on the dark web. We do our best to keep you updated on the latest events and trends in this mysterious space. Stay tuned for our next digest in January, where we will bring you even more dark web insights and stories!

 

Dark Web Digest – November 2023 Edition

Deep Web Digest - November 2023

Darkweb is part of the internet that is not indexed by search engines. It is accessible only through specialized software, such as Tor. It is used for illegal activities such as drug trafficking, money laundering, and child pornography. There is no doubt that the dark web is becoming more and more dangerous, and many people are becoming its victims every month. The dark web is filled with many incidents and trends every month, some horrifying. This month, let’s look back at what happened.

This month, the dark Web has seen a rise in attacks, data breaches, cryptocurrency, sexual harassment, and child abuse scams. Additionally, the dark web is used for illegal goods and services, including drugs and weapons.

McLaren’s ransomware attack may have leaked patient data to the dark web.

McLaren Health Care has acknowledged that a ransomware attack on its 14 Michigan hospitals in late August and early September may have leaked patient data onto the dark web. BlackCat/AlphV, a ransomware gang with ties to Russia, claimed responsibility for the cyberattack, stealing six terabytes of McLaren’s data, including the personal information of 2.5 million patients. 

McLaren's ransomware attack may have leaked patient data to the dark web

The cybercriminals threatened to extort patients by leaking mammograms for people potentially having breast cancer. They began targeting patients directly, saying they had the mammograms and would leak them if the clinic didn’t pay the ransom.

Healthcare providers are required to report any breach of protected health information to the U.S. Department of Health and Human Services and the Federal Trade Commission. The federal HIPAA Breach Notification Rule offers some protection by requiring healthcare providers to disclose details about the type of information compromised; steps people should take to protect themselves, what is being done to investigate the breach, and contact information within 60 days of discovering the breach. If the cyberattack involves 500 people or more, a prominent media outlet must also be notified within 60 days.

Trustwave, a Chicago-based cybersecurity company, released a report in July that found nationally, 24% of all cyberattacks in the U.S. in 2022 targeted the healthcare industry. The average cost of a healthcare data breach in 2023 is about $11 million.

US Charge Man with Running Stolen Credentials Marketplace

Sandu Diaconu, a 31-year-old Moldovan man, has been extradited from the UK to the US for allegedly operating a website that sold access to compromised computer credentials. 

The US charges Diaconu with conspiracy to commit access device and computer fraud, wire fraud conspiracy, money laundering conspiracy, access device fraud, and computer fraud. 

US Charge Man with Running Stolen Credentials Marketplace

If found guilty, he faces up to 20 years in federal prison. The charges relate to his alleged administration of the E-Root marketplace, which sold access to compromised computer credentials for years. Authorities believe over 350,000 credentials were listed for sale on E-Root.

The E-Root marketplace used various methods to hide the identities of its administrators, buyers, and sellers, including using Perfect Money to conceal payments and offering its illicit cryptocurrency exchange service for converting Bitcoin to Perfect Money. 

Buyers could search for compromised computer credentials through various criteria, including price, geographic location, internet service provider, and operating system. Many victims, including at least one government agency in Tampa, Florida, were subjected to ransomware attacks, and some stolen credentials were linked to stolen identity tax schemes.

The E-Root marketplace was taken down in 2020, and Diaconu was arrested in the UK in May 2021. In September 2023, Westminster Magistrates’ Court ordered his extradition to the US.

 The takedown of the E-Root marketplace is part of a growing crackdown on cybercrime websites, similar to the recent German police shutdown of Russian darknet marketplace Hydra and the Europol arrest of nearly 300 individuals on the underground marketplace Monopoly Market.

FBI exposes million-dollar crypto scam orchestrated by six Indians in New York

The US FBI has charged six Indians in a $30 million cryptocurrency scam. The six Indians, Shaileshkumar Goyani, Brijeshkumar Patel, Hirenkumar Patel, Naineshkumar Patel, Nileshkumar Patel, and Raju Patel, allegedly operated an illegal $30 million money-transmitting business using cryptocurrencies between July 2021 and September 2023. 

FBI exposes million-dollar crypto scam orchestrated by six Indians in New York

The FBI began an investigation in April 2021 when they identified a vendor on multiple dark web marketplaces who offered a service to ship cash via the US Postal Service in exchange for Bitcoin or other cryptocurrency. 

An individual was arrested for mailing packages of cash from a post office in Westchester County, New York, where the informant obtained money by meeting people three times a week and receiving amounts ranging between $100,000 and $300,000 each time. 

The FBI investigation revealed that one of the men made frequent trips outside of New York, including to New Jersey, Massachusetts, Georgia, and Pennsylvania. One of the arrested men claimed that his wealthiest clients were hackers and some made money selling drugs.

Dark web usage, paranoia detail by London, Ont. family accused of killing

Nathaniel Veltman, a man accused of killing four members of a London, Ontario, Muslim family in a terrorist attack, took three grams of psychedelic mushrooms to escape his delusional paranoia.

Dark web usage, paranoia detail by London, Ont. family accused of killing

Veltman testified in his defense in a Windsor, Ontario, courtroom, stating that he needed to escape the hell he was living in in his mind. 

On June 6, 2021, the Afzaal family was out for a walk when they were struck by a black pickup truck driven by Veltman. The family was killed, and a nine-year-old boy survived.

Veltman was arrested in the hours following the attack and has pleaded not guilty to four counts of first-degree murder and one count of attempted murder, as well as associated terrorism charges. 

Defence and prosecution lawyers agree that he drove the truck at full speed four seconds before impact and never touched the brake pedal.

Veltman’s obsessions shifted from religion and sometimes pornography to conspiracy websites and satirical shock-humor sites. He watched far-right sites “constantly” from September to December 2020, watching them during 10-minute breaks at work, lunch, as soon as he got up, and before going to bed. 

From January to March 2021, Veltman didn’t work, thinking he could focus on school. Instead, he said his internet use spiraled even further out of control. At one point, he ripped his television off the wall to try to avoid streaming videos on it.

After two suicide attempts in March, Veltman decided he had “nothing left to lose” and started purposely seeking out extreme content that he’d in the past avoided because he thought they would trigger too much rage. 

He felt this unspeakable rage rising inside himself and felt like he had nothing to lose. He watched a mass shooting video and was repulsed by it “like any normal person” but then got desensitized to it after watching it over and over.

Veltman testified that he had dabbled with magic mushrooms in high school but took a large dose with a friend in April 2020. He described collapsing, writhing on the floor, yelling, and being in agony. He triggered a psychotic event, which he couldn’t fight or control, eventually forgetting everything.

After the April incident, Veltman didn’t use psychedelics again until June 5, 2021, when he got three grams from a friend and drank them in a tea, distraught over the death of his grandmother on June 4, 2021.

Ransomware Gang Moves to Release Sabre Leak Data

The Dunghill Leak group, responsible for a cyberattack on travel booking giant Sabre Corporation, has announced plans to release 1.3 terabytes of stolen data in eight batches. The data includes sensitive databases on ticket sales and client data. 

The breach occurred after Sabre acknowledged the breach on September 6, 2023, after a series of files purportedly stolen from them surfaced on the group’s dark website. The Australian travel industry is on high alert, as Sabre’s software and data underpin many airline and hotel bookings, check-ins, and apps. 

The expansive data cache now looms with the potential to release databases on ticket sales, client data, personal information of Sabre employees, detailed financial information, and files associated with the airline-client application. The breach is believed to have occurred around mid-2023. Dunghill Leak, believed to have evolved from the Dark Angels and Babuk ransomware groups, has previously targeted other high-profile companies. 

Australia and most developed nations have advised against paying ransoms to hacker gangs. Sabre faced a security incident in 2017, which cost them $2.4 million in settlements after a breach in their hotel reservation system.

Child sex abuse images generated by AI risk flooding the internet 

The Internet Watch Foundation (IWF) has warned governments and technology providers to prevent the proliferation of child sexual abuse images on the internet. The IWF warns that a flood of AI-generated images could overwhelm law enforcement investigators and expand the pool of potential victims. 

Child sex abuse images generated by AI risk flooding the internet 

The report exposes a dark side of the race to build generative AI systems that enable users to describe in words what they want to produce, from emails to novel artwork or videos, and have the system spit it out. 

If not stopped, the flood of deepfake child sexual abuse images could bog investigators down trying to rescue children who turn out to be virtual characters. Perpetrators could also use the images to groom and coerce new victims.

The IWF analysts discovered faces of famous children online and a “massive demand for the creation of more images of children who’ve already been abused, possibly years ago.” They are taking existing real content and using that to create new content for these victims. 

The IWF’s report is meant to flag a growing problem more than offer prescriptions, but it urges governments to strengthen laws to make it easier to combat AI-generated abuse. It mainly targets the European Union, where there’s a debate over surveillance measures that could automatically scan messaging apps for suspected images of child sexual abuse even if the image is not previously known to law enforcement.

SONY CONFIRMS DATA BREACH IN MAY – OVER 6000 PEOPLE AFFECTED

Sony Interactive Entertainment (Sony) confirmed a data breach on May 28, 2023, affecting thousands of current and former staff and their families in the United States. The breach was discovered on June 2, 2023, and the platform was immediately offline. 

SONY CONFIRMS DATA BREACH IN MAY – OVER 6000 PEOPLE AFFECTED

Sony launched an investigation with the help of external cybersecurity experts and notified law enforcement. The incident was limited to the MOVEit vendor software and did not impact Sony’s other systems.

The breach was caused by a flaw in the MOVEit vendor software, discovered by Sony in early June 2023. The vulnerability tracking number is CVE-2023-34362, a high-risk SQL injection vulnerability that can remotely execute arbitrary code. 

The malicious hackers had illegal access to data from the platform. After discovering the breach, Sony took immediate action, and the compromised data included personal information such as names, addresses, Social Security numbers, and dates of birth.

Sony launched a probe with the help of external cybersecurity experts and notified law enforcement. The incident did not impact any other of Sony’s systems apart from the MOVEit vendor software. However, all current and former staff have emails from Sony informing them of the breach.

Sony has suffered several data breaches in the past, including a major breach in 2011 that exposed the personal information of millions of users. In August 2017, a hacker group accessed Sony’s social media accounts and deleted data from Sony systems using a variant of the Shamoon virus. In July this year, the Clop ransomware group used the MOVEit vulnerability to launch large-scale attacks. Sony discovered the attack three days later and found unauthorized downloads.

The breach has potentially exposed the personal information of over 6,000 people, precisely 6,791 Americans. Hackers can use this data to steal the identity of the owners and for other malicious purposes.

Conclusion

These are some of the most significant trends and news on the dark web in October 2023. They illustrate the diverse and dynamic nature of the dark web, as well as its challenges and opportunities for law enforcement, security, and society. The dark web is not only a source of crime and danger but also a platform for innovation and resistance. As such, it deserves our attention and understanding. We will keep you updated with upcoming trends and incidents happening in the dark web world. So stay in touch with us

Dangers Lurking on the Dark Web or the Hidden Wiki

Dark Web - Hidden Wiki Things

The anonymity of the dark web’s hidden wiki allows illegal and unethical activities to flourish unseen. Understanding these dangers provides perspective on the darker corners of the Internet.

Some of the more sinister elements hosted on hidden wiki dark web markets and forums include:

  • Sale of illegal drugs, firearms, and pharmaceuticals
  • Distribution of child exploitation and pornography
  • Trafficking of stolen data, hacked information, and malware
  • Scams and phishing schemes designed to steal money and identities
  • Predators targeting victims with minimal risk of detection
  • Human trafficking operations that deal with modern slavery

The hidden wiki also enables whistleblowers and political dissidents to share classified data and criticize oppressive regimes. However, the many illicit temptations and threats outnumber this valid political speech.

Criminals, hackers, and bad actors operate on the hidden wiki’s dark web with impunity. The anonymity empowers all objectionable and dangerous behaviors hidden from authorities and public scrutiny.

Real dangers lurk in the unruly hubs of the encrypted Internet. But, insights into this hidden wiki can improve public discourse on online privacy, oversight, and security issues.

The deep web has a lot of regular private stuff, and the hidden wiki on the dark web is a hidden place where crime happens. We need to stop believing exaggerated stories about the hidden wiki or the dark web but still care about the private stuff on the deep web. Knowing the truth helps us protect privacy better and find ways to stop dangerous secrets. 

What Lies Ahead – Anticipating Hidden Wiki’s Future in 2024

Hidden Wiki - 2024

What is the Hidden Wiki?

The hidden wiki is a dark web website that contains links to various websites and resources not indexed by standard search engines.

The hidden wiki has legitimate uses but is well known for indexing illegal and illicit content on the dark web. 

Who uses the Hidden Wiki? 

Journalists, whistleblowers, and news media utilize hidden wikis to safeguard their anonymity when reporting on or exposing government actions. These platforms serve as a shield to protect their identities while they criticize and investigate government activities.

Hackers use hidden wikis to upload illegal and legal documents of a company they hacked and sell the data for ransomware. This is to hide the anonymity. Hackers often do this for ransomware. 

Users of the hidden wiki mostly visit the illegal websites on the dark web to buy and sell illicit products. 

The common trade on the dark web sites will be stolen credit cards and their credentials, drugs, weapons, pirated movies, software, etc., 

How to surf the Hidden Wiki safely? 

Some of the websites on the dark web are safe to visit as TOR encrypts the data that is sent and received. However, the encryption can be intervened by the websites you visit. 

So, to protect your computer system and anonymity, one should use a VPN to surf the dark web. 

When you connect to a VPN server, your internet traffic is sent through an encrypted tunnel, ensuring your data’s privacy and security.

Your IP address will be replaced with the IP address of the VPN server. This masks your actual location and identity.

Data transmitted between your device and the VPN server is encrypted, making it challenging for anyone to intercept or monitor your online activities.

NordVPN Promotion Image

Always use a premium VPN. We recommend you use NordVPN, the pioneer in the VPN industry, before accessing any onion links. 

What to expect in the Hidden Wiki in 2024? 

One can find the following things on the hidden wiki in 2024. 

Marketplaces: Marketplaces are where one can buy illicit goods. Most trade of the dark web happens in common marketplaces. The past marketplaces the federal agents seized are The alphabay Market, Silk Road, etc. New marketplaces will rise in 2024. 

Directories: The hidden wiki that existed before served as a directory of links to the dark web. Like this, more illegal hidden wiki directory websites will emerge in 2024. 

Forums and Communities: There are forums and communities on the dark web for various interests and discussions, including hacking, privacy, political activism, and more. 

Whistleblower Platforms: Some sections of the Hidden Wiki may contain links to platforms that cater to whistleblowers and those looking to share sensitive information anonymously.

Illegal Content: Unfortunately, some parts of the Hidden Wiki may host links to illicit activities, such as sites offering drugs, hacking services, stolen data, and other illegal goods and services.

Illegal Content on 2024 - Hidden Wiki

Controversial and Extreme Content: The dark web is known for hosting controversial and extreme content, including political extremism, conspiracy theories, and other illegal materials.

Apart from this standard look of the hidden wiki, more changes will keep the hidden wiki fresh. The following are expected to be the change: 

The new blogger’s community will rise. New websites that focus on news, blogs, technical solutions, reviews on gadgets, etc., will come in the upcoming years. 

The illegal activities on the dark web will be reduced, and users will focus on the good things needed for their daily lives. 

When more people use the TOR platform, industry giants also move slowly. 

Concerns about using a Hidden Wiki: 

Illegal Activities: The dark web is known for hosting illegal marketplaces where users can buy and sell drugs, weapons, stolen data, counterfeit currency, and more. 

Scams and Fraud: Scammers operate on the dark web, offering various fraudulent services, such as selling fake passports, stolen credit card information, or scamming users through fake marketplaces and services.

Malware and Cyberattacks: Dark web websites can be riddled with malware, making users vulnerable to cyberattacks and potential security breaches if they are not careful about the links they click or the files they download.

Risk to Personal Privacy: While the dark web can offer increased privacy and anonymity, there are still risks associated with using it. Users may inadvertently reveal their identity or location, especially if they make mistakes in maintaining their anonymity.

To avoid this type of data risk, always use a premium VPN. We recommend you to use the NordVPN. 

NordVPN Promotion Image

Law Enforcement and Surveillance: Government agencies may monitor dark web activities, and users engaging in illegal actions can face legal consequences if identified. 

Infection from Malicious Software: Dark web marketplaces may host software that contains malware or viruses, putting your device and data at risk.

Ethical and Moral Dilemmas: Even if your intent is not to engage in illegal activities, accessing the dark web can raise ethical and moral questions, as it indirectly supports a platform known for illegal practices.

Advantages of using a TOR:

No search engines on the TOR store or use the user’s data. Providing complete anonymity to its users. 

TOR encrypts the data sent and received. This means no third party can view or access the data. 

Tor routes the internet traffic through a network of volunteer-run servers, making it difficult for government agencies and advertisers to trace online activities back to you.

Tor prevents websites and online services from tracking your IP address and collecting data about your online behavior, enhancing your privacy.

It can protect your data from certain types of surveillance and hacking, making it a valuable tool for whistleblowers, journalists, and activists concerned about digital security.

Internet users are becoming aware of the anonymity they need in their life. So, search engines like duckduckgo will be the future, which don’t store user data nor sell them. 

Frequently Asked Questions(FAQ):

Is it illegal to use the Hidden Wiki?

It is entirely legal to access the hidden wiki. It is illegal only when you do illegal activities on the dark web. 

Is it safe to access the Hidden Wiki? 

Some of the websites on the hidden wiki are safe to visit/access. If you are unsure about a link, don’t click on the link. 

Can I use a free VPN to access the Hidden Wiki? 

A free VPN can be used to access the hidden wiki. But free VPNs earn by selling the user data. So, you are risking your data and privacy. We advise you never to use a free VPN to access the hidden wiki. 

Dark Web Digest – October 2023 Edition

dark web digest - October 2023

Welcome to the October edition of Dark Web Digest, your go-to source for the latest news and updates from the dark web. The dark web is a breeding ground for cybercriminals, with several associated threats. In addition, it is constantly evolving, and new developments are always emerging.

This edition contains the most recent developments in cybersecurity, hacking, and the dark web. Let’s look at the latest news and incidents that occurred last month!

Cyberattack exposes donor data from Australia-based telemarketing firm

The Pareto Phone ransomware group, LockBit, has been reported as taking donor data and publishing it on the dark web (including here and here). Among the charities involved, the Australian Conservation Foundation said 13,500 supporters. According to a statement, the data accessed by ChildFund NZ included titles, names, and postal and phone numbers.

There was also the revelation that Pareto Phone hid data from charities for many years without their knowledge. This was with the Baker Heart and Diabetes Institute not working with Pareto Phone for more than eight years and the Stroke Foundation not since 2017. Children’s Fund NZ has collaborated with Pareto Phone since 2014. MSF Australia said it had not used the company for almost five years and was unaware it had retained historical records.

According to a report last October, one in eight charities in the UK suffered cybercrime within the past year due to cyberattacks. An advanced cyber security attack in 2022 on the International Committee of the Red Cross (ICRC) compromised the sensitive personal information of more than 515,000 highly vulnerable people from more than 60 Red Cross and Red Crescent National Societies worldwide.

Loyalty’s third-party research partner, Kokoro, was recently targeted in the UK. According to Kokoro’s forensic investigation, the group responsible may have accessed some client data. In this case, no postal addresses, financial details, or identity documentation were available on Kokoro’s systems. The charity clients affected were informed, with Shelter and Friends of the Earth acting to reassure and inform.

Finland, Europol take down PIILOPUOTI dark web marketplace

The Finnish law enforcement forces worked with Europol and a cybersecurity firm to shut down PIILOPUOTI. Finnish Customs said that the platform had operated on the Tor Network since May 2022 for smuggling drugs and paraphernalia into Finland.

Due to an ongoing criminal investigation, Finn Customs and its international cooperation partners won’t provide any further information. The Finnish authorities refused to comment on arrests or other illegal activities conducted on the platform. It said the investigation was born with the assistance of German and Lithuanian authorities, Europol, Eurojust, other countries’ authorities, and various Finnish police units.

PIILOPUOTI - Marketplace

Bitdefender helped law enforcement agencies investigate the platform in its investigation and participated in the takedown. Alexandru Catalin Cosoi, Bitdefender’s senior director of investigation and forensics, did not elaborate on the company’s involvement but said it “provided technical consulting to the entire investigation group.” Earlier this month, US and Polish law enforcement agencies partnered to dismantle the bulletproof hosting platform Lolek.

In April, more than a dozen international partners were involved in an FBI-led operation that seized Genesis Market, a one-stop shop for criminals selling stolen credentials and the tools to weaponize them.

Dark Web hacker threatens to sell US and European military intelligence

US Department of Defense hacker “USDoD” has warned that he intends to sell military intelligence to the dark web. The hacker entered the Airbus website by exploiting Turkish Airlines employee access.

According to USDoD, its targets are American defense contractors, NATO, Europol, and Interpol. In a lengthy interview with databreaches.net, USDoD disclosed that its next targets are American defense contractors, NATO, and Europol.

While he threatened to set up a private company to trade classified military information between the US and Europe, the Department of Defense claimed that he was not pro-Russian despite cyberattacking Russia’s adversaries. He also worked for some Russians, but he has no racial biases or political motives.

As part of the hacker’s denials, he denied receiving financial compensation for his attacks on United States and European entities. He avoids attacking China, Russia, North Korea, South Korea, Israel, and Iran exemplifies one of his strategies.

The Pentagon continues to work on cybersecurity as the Pentagon threatens to sell US military intel. The United States Air Force recently awarded Raft LLC a contract to develop a software factory for cyber operations. Cyber deterrence is also strengthened through training and drills, such as the recent “defensive hunt operation” in Lithuania.

The dark web leaks the Personal information of Dymock customers

Earlier this week, Dymocks announced that some of its customers’ information may have been compromised and leaked onto the dark web. A small group of unauthorized individuals may have accessed Dymocks’ customer records on 6 September. Customers’ information, including addresses, e-mails, phone numbers, and membership information, may have been compromised. Dymocks said an investigation is underway to determine how this happened.

Dymock

The issue was notified to customers via an e-mail sent on Friday afternoon, asking them to be “vigilant” and change their passwords. Dymocks’ customers’ postal addresses, birthdates, e-mail addresses, mobile phone numbers, gender, and membership details may have been compromised.

According to a company statement, an unauthorized party may have accessed certain customer records at Dymocks as of 6 September 2023. Neither Dymocks nor its customers know who or how many customers have been affected by the breach.

Since passwords might be available on the dark web, Dymocks suggests its customers change their online passwords, including their Dymocks accounts and social media accounts. Furthermore, the company cautioned customers against telephone, postal, and e-mail phishing scams.

Cornwall dealers used Bitcoin to buy cocaine and cannabis on the dark web

A pair of drug traffickers accused of buying cocaine and cannabis on the dark web to sell on the streets of West Cornwall have been jailed. Jason Pierce, 56, and Callum Payne, 28, both from Porthleven, were sentenced to ten years in prison.

They denied conspiracy to supply cocaine and cannabis, but a jury at Truro Crown Court found them guilty of conspiracy to supply cocaine and cannabis after a trial in June. 

The sentence for Pierce was six years and eight months, and that for Payne was three and four months in prison at Plymouth Crown Court on Friday, 15 September.

A court heard about the drugs’ purchase from the Netherlands on the dark web through Bitcoin and their distribution to locations throughout West Cornwall.

Officers uncovered the drug trafficking operation in January 2018 when they found £5,000 worth of cannabis in the car being driven by Payne.

The defendants’ computers had sophisticated privacy software that needed to be cracked to unlock evidence of their criminal activities.

As Detector Inspector Steven Moorcroft of Devon and Cornwall Police’s Serious and Organised Crime Branch explained: “This investigation began in 2018 after a chase in Porthleven led to Callum Payne fleeing a vehicle containing cannabis imported from the Netherlands through the dark web.

Dozens of Mullvad VPN accounts discovered on the dark web

According to security researcher Damien Bancal, one of the major Swedish VPN providers, Mullvad VPN, has recently been accused of leaking user data.

A ZATAZ Monitoring client discovered an astonishing data leak targeting Mullvad during an investigation. Several websites leading to Mullvad API provided access to user connection data, such as IP addresses [IPv4 and IPv6 addresses], connection dates, and other information that was not personally identifiable, the post says.

A hacker discussion led Bancal to learn about Mullvad VPN’s plans to sell data on the dark market. Among the data shared were Mullvad clients’ 16-digit IDs and expiration dates.

Researchers shared several links to a cache of Mullvad VPN forums where threat actors were trading them off. Despite an ID number, not much information can be retrieved about those accounts since no names, e-mail addresses, or other personal information are available.

The researcher said that a malicious actor can do much damage even with very little information.

According to Jan Jonsson, CEO of Mullvad VPN, the publicly revealed accounts are unsurprising. He has seen over 100 Mullvad VPN accounts personally.

Many Mullvad forums and websites list “leaked” Mullvad accounts. Mullvad donates millions of Mullvad accounts to charities each year for various reasons. Cybernews contacted him via e-mail to learn about several sources for “leaked accounts.”

There was no leak. “Firstly, we have an API with minimal functions. Secondly, we do not use passwords. We only use 16-digit account numbers.” He believes people are brute-forcing account numbers to get free accounts. 

Customer data was seized from the Swedish-owned company’s Gothenburg office in April during a police raid. Since the company had a ‘no logs’ policy, such customer data was not even available to them. If they had taken something, they couldn’t access any customer data.”

The industry has been under scrutiny because VPNs essentially allow users to remain anonymous on the internet.

VPN IDs may contain private user information, such as billing, and may collect personal information so that exposure could have serious consequences. If a VPN ID is exposed, users should change their password, enable multi-factor authentication, and notify their VPN provider.

Senate is concerned about Pakistani public data sales on the dark web.

Pakistan faces a growing challenge concerning protecting its public data, with the Senate Standing Committee on Information Technology and Telecommunication recently convening to address these concerns. The Senate greenlights Army Act amendments: 5-year jail term for revealing sensitive information. The gathering boasted a diverse composition, underlining the gravity of the situation.

A Cyber Response Team was established to combat cyber threats effectively. It was also decided to enhance public awareness regarding cybersecurity in Pakistan. The committee received an update on the National Cyber Security Policy, which outlines the government’s strategic approach to safeguarding the nation’s cyberspace. The committee heard from the CEO of Ignite, an organization that has established eight National Incubation Centers across Pakistan and generated Rs15 billion in revenue.

Senator Kauda Babar urged the establishment of more NICs in various cities, with a particular focus on Balochistan. The committee also delved into the National Telecommunication Corporation (NTC) operations, Pakistan’s official telecom and ICT service provider, and called for improvements.

The Senate Standing Committee on Information Technology and Telecommunication highlighted the need to strengthen Pakistan’s data protection measures and bolster cybersecurity efforts to promote innovation and economic growth.

Conclusion

The dark web is a dangerous place that poses several threats to individuals and businesses. However, staying informed and taking the necessary precautions can help you stay safe online. In this edition of Dark Web Digest, we have provided the latest news and updates from the dark web, as well as tips and advice on staying safe online. 

Thank you for reading Dark Web Digest, and we hope to see you again in the next edition.

Exercise Caution with Downloads and Ads to Avoid Malware on the Dark Web

Exercise Caution with Downloads and Ads to Avoid Malware on the Dark Web

When browsing the hidden wiki on the dark web, users must be extremely cautious regarding downloads and advertisements that carry a high risk of delivering malware or viruses. A few simple precautions can help mitigate this threat.

Like the open Internet, the hidden wiki on the dark web harbors many malicious actors attempting to infect devices with malware disguised as legitimate downloads. Everything from media files to documents and programs can contain harmful scripts or executables. Clicking on advertisements also frequently triggers malware installs or redirects.

Avoid Suspicious Downloads

Refrain from downloading files from the dark web or hidden wiki sites unless necessary. If you must download something, inspect it thoroughly with antivirus scanners to check for embedded malware. Also, avoid opening unexpected email attachments which may have malware.

Use Antivirus and Ad Blockers

Install reputable internet security software with real-time protection to block and quarantine malware. Utilize ad blockers to avoid risky click-throughs from ads. Both precautions decrease malware exposure substantially.

Hidden Wiki - Dark Web Checklist

Analyze Files in Isolated Environments

If you need to closely analyze a suspicious download, do so in an isolated virtual machine or air-gapped computer. This contains the file away from your main device preventing malware installation. Only transfer files to your real device once fully scanned and deemed safe.

Keep Software Patched and Updated

Apply the latest security patches to operating systems, browsers and applications. Cybercriminals exploit known unpatched software vulnerabilities to deliver malware. Auto update features help maintain protection.

Monitor for Suspicious Activity

Watch for signs of a breach like abnormal network traffic, crashes, popups or browser redirects. These may indicate successful malware installation requiring immediate remediation. Perform regular virus scans to detect dormant threats.

With vigilance around downloads and ads, dark web users can avoid enticing traps set by cybercriminals to compromise devices. Refusing risky actions will keep your anonymity tools malware-free and identity secure.

Strong Passwords and Authentication Lock Down Accounts

Robust passwords and authentication methods are essential for securing accounts created on the dark web. Weak credentials place anonymity and sensitive data at risk.

Any sites or services used require unique, complex passwords that are only used on that specific site. Cybercriminals steal huge password lists and attempt reused logins across sites. Unique passwords prevent this lateral movement.

Generate Complex Passwords

Passwords should be 12+ characters using unpredictable combinations of upper and lower case letters, numbers, and symbols. Avoid common words or personally identifiable info.

Enable Two-Factor Authentication

When available, enable two-factor authentication (2FA) for an added layer of login security. 2FA requires providing a secondary one-time code from your phone when logging in.

Use a Password Manager

A encrypted password manager helps generate and store strong unique passwords securely. It also fills logins automatically preventing typing errors that could lock you out.

Change Passwords Regularly

Frequently change passwords, especially for highly sensitive accounts like those holding cryptocurrency wallets or financial information. This limits window of exposure if a password is somehow compromised.

Strong authentication practices prevent unauthorized access to accounts and sensitive data. Treat anonymous hidden wiki credentials with the same care as any highly sensitive password.

Vet Sites Thoroughly Before Making Dark Web or Hidden Wiki Purchases

When purchasing goods on the dark web or on the Hidden Wiki, only shop on well-established marketplaces and merchant sites with extensive positive feedback. Avoid shady vendors and diligently research listings to avoid scams.

While dark web hidden wiki commerce carries inherent risks, the consequences of dealing with disreputable sellers and markets include rip-offs, dangerous or tainted products, and law enforcement stings. Homework must be done before buying anything.

Read Independent Dark Web / Hidden Wiki Market Reviews

Consult dark web market and vendor review sites like DarkNet101 and DarkWebNews for reputation insight. Experienced users highlight trusted sellers versus scammers.

Check Seller Histories and Ratings on Hidden Wiki

On marketplaces, inspect seller profiles closely including customer ratings, reviews, and trade volumes indicating legitimacy. Favor long-standing vendors with mostly positive feedback.

Use Escrow When Possible

Opt to use escrow payment options on markets whenever available. Escrow holds funds securely until the product is delivered, minimizing fraud and losses.

Verify Products Upon Receipt

When orders do arrive, thoroughly verify product quality, safety, and legality before use. Having anonymous seller info makes redress difficult.

Conducting due diligence on sellers protects customers from avoidable losses when navigating hidden wiki commerce filled with scammers.

Protect Anonymity By Avoiding Personal Info Leak on The Hidden Wiki

To maintain anonymity on the dark web and the hidden wiki, users must be highly cautious about accidentally revealing any personal identifying information in online interactions.

When creating accounts, never divulge full name, address, phone, email, social media profiles, or other identifying details. Avoid uploading profile photos of yourself.

When sites request access to contacts, location, camera, microphone, or other sensitive permissions – deny access. Enabling these creates the risk of compromising anonymity.

Stay Anonymous on the Dark Web

In chat rooms and forums, share zero personal information and never open attachments from strangers that could contain malware compromising your system.

If creating anonymous social media accounts, again, avoid sharing anything identifiable and do not link accounts to your real profiles.

Staying anonymous requires vigilance to never associate online hidden wiki activities with a real-world identity in any way. A single slip-up could undo other precautions.

Dark Web Digest – September 2023 Edition

Deep Web Digest - September 2023

The term ‘dark web’ is often associated with all things illegal. In reality, this may only be half-true. While there is a lot of illicit activity on the dark web, it is also a place where people can communicate anonymously and securely, free from government surveillance. 

The dark web is also used for activities such as activism or whistleblowing. There are tons of news coming out from the dark web each month. The number of illegal activities is not only for the government but also affecting society. August is not so far behind if we compare it with past months on the dark web. 

Therefore, this month’s edition covers the latest dark web news from August, and headlines are leaks, dark web access sales, and vast databases of user information.

Dark Web - Hidden Wiki - Digest September 2023

NSW Man Charged Over Failed Dark Web Drug Imports

The Downing Centre Local Court will hear an alleged attempt to import synthetic opioids, among other illicit drugs, by a Western Sydney man today (August 29 2023).

Several items allegedly contained drugs, including cookware, toy cars, and a blackjack set.

ABF officers intercepted three British air cargo shipments in May 2023. There were 133 MDMA tablets, 100 oxycodone tablets, and 97 analogues of Nitazene, a potent opioid more potent than fentanyl. The third and fourth consignments contained 60g MDMA, 25g ketamine, 15g meth and 14g heroin.

The ABF alerted the AFP, who executed a warrant on May 19 2023, at the Greenfield Park address. The AFP seized fake ID cards, kitchen scales, spoons with white residue, and zip-lock bags.

The intended recipient is a 23-year-old Greenfield Park resident.

According to AFP, his regular encrypted communications with two other people in the UK helped import and traffic border-controlled

On May 20 2023, the man was charged with one count of attempted importation of border-controlled drugs in contravention of section 307.6 of the Criminal Code (Cth).

According to AFP Detective Superintendent Craig Bellis, while each package contained relatively small amounts of illicit drugs, they constituted dozens of individual street deals that harmed society.

Malicious AI Arrives on the Dark Web

Recently, artificial intelligence has advanced at an unprecedented pace, and nefarious non-state actors have been using it to expand their harmful activities. Dark web forums have been buzzing about using OpenAI’s ChatGPT. A tool called WormGPT, based on the open-source GPT-J large-language model developed in 2021, appeared on the dark web on July 13. It generates sophisticated phishing and business email attacks and writes malicious code.

FraudGPT, based on GPT-3 technology, appeared for sale on the dark web on July 22. It is marketed as an advanced bot for offensive purposes, costing US$200 a month to US$1,700 for an annual license. It’s too soon to know how effective WormGPT and FraudGPT are; the specific datasets and algorithms they are trained on are unknown. Furthermore, the malicious AI bots for sale could be scams in themselves.

AI offers enormous opportunities for nefarious actors to enhance their malicious activity and expand their operations. It can create convincing phishing emails and scrape the internet for personal details about a target. AI technology is getting smarter – fast. FraudGPT’s creator is developing DarkBART and DarkBERT, two new malicious AI tools with internet access and integrated with Google Lens.

AI-powered cybercrime will demand an even more proactive approach to cybersecurity, but good cyber hygiene and awareness training remain relevant as the first line of defence against cybercriminals.

Mother of Girl Nearly Sold on the Dark Web Gives Warning to Parents

A Jasper County man is accused of trying to sell a 16-year-old girl’s personal information on the dark web. The girl’s mother spoke exclusively to Atlanta News First. The FBI knocked on her door on June 29 of this year to deliver news they never expected. They told her a tipster, who lived in England, called the anonymous FBI tip line to say this woman’s daughter was in danger.

The mother said Ivey stole photos from their family’s Facebook page and sent them to a private account. Kelly Ivey tried to sell information about a 16-year-old female on the dark web, but her mother believed a higher power protected her daughter from being identified. She said people should not let their guard down, even in safe places.

ChatGPT’s Badboy Brothers for Sale on Dark Web

KrakenLabs, Outpost24’s threat intelligence team, has spotted several illicit adaptations of the AI large language learning model ChatGPT on the dark web. The foremost perversion appears to have been the lugubriously named WormGPT, a no-holds-barred deviation from the original that will obligingly perform tasks that its ‘ proper’ sibling would normally refuse to function.

CanadianKingpin12 advertised a chatbot last month that wrote malicious code, created hacking tools, and found system leaks and vulnerabilities. Prices for WormGPT, FraudGPT, DarkBERT, and DarkGPT vary widely. Last charges $100 for a month’s subscription, CanadianKingpin12 charges $90 for a month’s subscription, and DarkBERT offers $1,000 for a lifetime membership.

 

Artificial intelligence (AI) is one of the new ways threat actors achieve their goals, and it could drastically change the underground ecosystem. 

Last announced the end of WormGPT on August 9, citing too much publicity as a reason for hanging up the black hat. KrakenLabs put a slightly different slant on it, noting that the Telegram channels controlled by Last and DarkStux closed down the day the announcement was made.

A tool quickly gaining popularity is not always helpful, as it increases the chance of something going wrong. KrakenLabs noted a scam involving bogus adverts offering AI-enabled illegal digital tools, taking payment, and never delivering the promised articles. Even Last admitted that “anyone could reproduce what WormGPT did” by using jailbroken ChatGPT versions.

Thousands of Charity Donors Have Data Leaked on Dark Web After Telemarketer Hack

A cyberattack on telemarketer Pareto Phone has resulted in thousands of charity donors’ data being leaked onto the dark web. Three charities have said their donors’ data has been published on the dark web.

The attack was claimed by cyber criminal group LockBit, which said it had stolen 150 gigabytes of personal data.

The Fred Hollows Foundation is “deeply disappointed” that its data was still held by Pareto Phone, considering it hadn’t used its services for almost a decade. The charity has requested Pareto Phone delete any remaining donor data.

Another charity, Médecins Sans Frontières, has raised concerns about Pareto Phone and data retention. They have not worked with Pareto Phone for almost five years.

Professor Nigel Phair said, “organizations need to be careful when using third-party providers and should ensure that data is not kept beyond what is needed.”

He also said the “Privacy Commissioner now has increased penalties at their disposal.”

Cyble’s Dark Web Monitoring Helps Companies Comply with SEBI’s Cybersecurity Mandates

SEBI has rolled out comprehensive cybersecurity guidelines for Market Infrastructure Institutions in the wake of escalating cyber threats. These guidelines are a wake-up call for MIIs to beef up their cyber defences.

SEBI’s latest guidelines require MIIs to proactively monitor the dark web for stolen data, hacking tools, and other malicious artefacts. This allows them to gather crucial intelligence on emerging threats and vulnerabilities, better positioning themselves to mount a robust and timely defence.

Mandar Patil, SVP – Global Sales and Customer Success at Cyble, points out that cybersecurity can’t be a mere afterthought or a box to tick off a checklist. Cyble offers comprehensive dark web monitoring capabilities that meet SEBI’s requirements.

Brand abuse is a challenge for MIIs today. Dark web monitoring can help organizations safeguard their reputation and brand integrity.

The updated SEBI directives coincide with the Digital Personal Data Protection Bill 2023, which imposes substantial penalties for data breaches. Together, these initiatives signal an emerging consensus about the importance of a robust cybersecurity infrastructure for financial entities.

The Digital Personal Data Protection Bill 2023, which seeks to safeguard Indian citizens’ privacy, recently received approval in the Rajya Sabha.

Georgia Man Tried to Sell Teen Girl’s Location on Dark Web, Cops Say. Now He’s in Jail

Kelly Garret Ivey, 41, is accused of selling the location of a teenage girl on a dark website. The website showed pictures of the girl next to the advertisement.

Captain Billy Bryant, the lead investigator of the Jasper County Sheriff’s Office case, said information about the ad came through the FBI’s anonymous tip line. Investigators visited the family’s house and eventually linked the ad to Ivey via his accounts.

Bryant says. “The dark web is just like the regular internet. Anytime you do something, there are ways to backtrack that,” he said. The dark web is a network of online pages requiring certain software or authorization. The pages have less security than regular websites and have become hubs for illegal activity since the dark web’s conception in the early Internet era.

Ivey was arrested at his Forsyth home on June 30. He is in jail in Jasper County and was formally charged with cruelty to children in the first and second degree. He was also charged with human trafficking and attempting to commit a felony. The Telegraph will update this story if more information becomes available.

Police Send Warning Letters to ‘Dark Web’ Drug Buyers

A police officer has sent hundreds of warning letters to addresses that have received online requests for recreational and counterfeit drugs.

ERSOU is a joint effort between seven east-of-England police forces, including Norfolk and Suffolk, to combat organized crime. Investigations have revealed the sale of prescription, recreational, and stupefying drugs – known as ‘date rape’ drugs.

The dark web is a hidden part of the internet, often used as a criminal marketplace. The Eastern Region Special Operations Unit has seized more than £500,000 worth of illicit substances from dark web vendors over the last 18 months.

Detective Inspector Graham Paul said that many items for sale on the dark web are illegal and dangerous and that those who use it for illicit activity could be part of one of our investigations.

Charity Donor Details Leaked to Dark Web After Pareto Phone Breach

Some of Australia’s most high-profile charities have become inadvertently involved in a massive data breach with cybercriminals hacking thousands of donor details through a third party. The charity stressed that its systems had not been impacted.

The Fred Hollows Foundation said they had not worked with Pareto Phone since 2014 and had not known the data was still held by the company. The data does not contain financial, credit card or bank account information.

Professor Tanya Buchanan, CEO of Cancer Council Australia, told news.com.au it was still waiting for Pareto Phone to clarify how many donors’ data had been breached.

Pareto Phone did not respond to requests for comment but said it worked with forensic specialists to analyze affected files.

The hacking company, Pareto Phone, collected donations from charity supporters. The data breach occurred in April this year, affecting a “subset” of Canteen supporters.

Google One To Roll Out Dark Web Report For Subscribers

Google is reportedly in talks to roll out a new feature called Dark Web Report in India. This will alert users if their personal information is detected on the dark web, allowing them to safeguard themselves against fraudulent activities.

Users can activate the dark web report option to check if their details are on the dark web. They can also start real-time dark web monitoring to receive ongoing updates on new findings, recommended actions, and assistance.

Dark Web Digest – August 2023: Unveiling the Cyber Shadows

Deep Web Digest - August 2023

The dark web is a part of the internet no one knows about. It’s often used for hacking, drug trafficking, and cybercrime. Each month, innovations and events affect the dark web and its users.

This article summarizes some of the most relevant and interesting dark web stories from July 2023. We’ve seen password logs sold for millions of dollars, DarkBERT GPT-Based Malware, hackers publishing Swiss hooligan data, you name it.

This news should be on your radar if you haven’t heard it yet. It shows how the dark web threatens privacy, security, and well-being, as well as society at large. As well, they talk about how to protect yourself from the dark web’s dangers and raise awareness.

We will provide you with additional details, insights, and sources for each news article. This will enable you to take appropriate safety measures and remain engaged in the future.

  • Over 19 Million Password Logs Sold on the Dark Web and Telegram

A recent discovery has shocked the cybersecurity community as over 19 million password logs were found up for sale on the dark web. This alarming development has raised serious concerns among hackers, security experts, and students alike.

According to MyPowerCloud, the massive password log sale was exposed on both the dark web. This highlights the growing sophistication of cybercriminals in their illicit activities. The dark web continues to be a hotbed for illegal trade. This incident serves as a stark reminder of the ever-present threats lurking in the digital underworld.

dark web and telegram

Compromised passwords come from various sources, including well-known data breaches and hacking incidents, putting countless users at risk. For hackers, this new trove of passwords presents a golden opportunity to exploit unsuspecting victims and wreak havoc on their personal and professional lives.

  • Over 400,000 Businesses Credentials Stolen by Info-Stealing Malware

Over 400,000 credentials were stolen, yes you heard right! It is terrifying to see what is happening on the dark web. Well, the dark web experienced a massive data breach as information-stealing malware infiltrated business environments, targeting valuable data in web browsers, email clients, and more. Some experts pointed out that prominent malware families, such as Redline, Raccoon, Titan, Aurora, and Vidar, are available to cybercriminals via a subscription-based model.

These malware campaigns not only affect careless internet users but also pose a significant risk to corporate environments. Approximately 375,000 logs containing access to critical business applications like Salesforce, Hubspot, Quickbooks, AWS, GCP, Okta, and DocuSign were discovered.

Moreover, over 48,000 logs provided access to “okta.com,” an identity management service widely used by organizations. 

The analysis found more than 200,000 stealer logs containing OpenAI credentials, putting proprietary information and source code at risk.

  • 8 Year Old Boy Orders an AK-47 from the Dark Web

In a shocking turn of events, Dutch expert Barbara Gemen discovered that her 8-year-old son had unknowingly entered the dark web’s perilous world and bought an AK-47. Initially innocent, the young boy’s fascination with computers led to dangerous hacking escapades. 

He started with harmless online orders but soon engaged in illegal money transactions with criminals using code phrases to conceal his activities. 

The situation escalated when he purchased and received a deadly AK-47 gun from Poland to Bulgaria, without raising suspicions. Despite alerting law enforcement, no action was taken, leaving Barbara to take matters into her own hands. She became a Cyber Special for the Dutch police, advocating for online safety for her son and others.

This incident underscores the need for parental awareness and education to safeguard children from the dangerous allure of the dark web. This is especially true as easy access to technology exposes them to cybercrime temptations.

  • DarkBERT GPT-Based Malware Trains Up on the Entire Dark Web

You’ve got a safety tool that turns into a threat! You’re right, it is. 

DarkBART is a dark version of Google’s BART AI. DarkBERT, created by South Korean firm S2W, aims to combat cybercrime but has unfortunately fallen into the wrong hands. It’s rumored that CanadianKingpin12 trained DarkBERT using an extensive corpus of text from the Dark Web. This empowered it to conduct more sophisticated cyberattacks.

darkbert

It is even more alarming that DarkBERT will have access to the entire Dark Web as its knowledge base. This will allow threat actors to tap into the collective intelligence of hackers underground. With Google Lens integration, these chatbots can now handle text accompanied by images, making their capabilities even more formidable.

  • Brazil Tops South America in Dark Web Card Theft

Brazil has become a hotspot for dark web card theft, ranking fifth globally and first in South America. Nord VPN cybersecurity study revealed that over 144,000 Brazilian payment cards have been stolen and traded online. In addition, approximately 92,000 cards are currently available for illegal purchase. These stolen cards are sold for $8.84 each, generating an estimated $18.5 million for cybercriminals.

Even more troubling, two out of three stolen credit cards on the dark web contain additional private information, such as phone numbers, addresses, and Social Security numbers, greatly increasing the risk of identity theft for victims.

The study also showed that the United States has the highest number of credit card fraud cases globally. This accounts for more than half of the 6 million stolen card records analyzed. American credit cards sell for a lower price on the dark web, around $6 per unit. Danish cards are the most valuable, averaging R$12.

In the South American landscape, Brazil reported the highest number of stolen payment cards, followed by Chile with 30,000 stolen cards. The highest risk of credit card theft occurs in countries such as Malta, Australia, and New Zealand, while Brazil ranks 38th. Conversely, Russia is the least risky, and China ranks third from the bottom. This study sheds light on the alarming scale of cybercrime and the need for heightened cybersecurity measures worldwide.

  • OpenAI Credentials Available on the Dark Web

The most concerning news is, security researchers have recently discovered a security weakness on the dark web. The OpenAI credentials of over 200,000 compromised users were found available for purchase on the dark web. This incident has raised alarms in the tech community and among cybersecurity experts.

chatgpt data leak

The compromised data includes sensitive information such as login credentials, access keys, and even source code and business plans. Hackers and cybercriminals are now equipped with powerful tools to exploit vulnerabilities and gain unauthorized access to OpenAI systems.

For hackers and security experts, this development serves as a stark reminder of the ever-present risks in the digital landscape. It underscores the importance of staying vigilant and continuously improving security measures.

  • Swiss Hooligans Data Leaked on the Dark Web by Hackers

In the aftermath of a ransomware attack on IT provider Xplain, sensitive data has surfaced on the dark web. This includes an extract from the HOOGAN information system dating back to 2015. The leaked data contains details of 766 individuals listed in the HOOGAN database, a register of known hooligans. However, crucial information about their offenses and actions is missing.

Fedpol, the Federal Office of Police, acted swiftly to inform the affected individuals and is actively investigating the transmission and storage methods used during the attack. The breach also exposed sensitive government data belonging to the federal police, army, and the Federal Office for Customs and Border Security. Consequently, the Office of the Attorney General and the Federal Data Protection Commissioner have initiated separate investigations.

Fedpol aims to reassure the public that HOOGAN’s database remains secure and operational despite the breach. As per the latest data, the HOOGAN database listed 1,017 hooligans as of June 2023. Of these, 332 individuals face ongoing measures such as exclusion orders, stadium bans, and reporting obligations. The data relating to police measures will be retained for three years following their conclusion.

  • A dark web AI tool called “FraudGPT” facilitates cybercrime

A new AI tool following in the footsteps of ChaosGPT and WormGPT. This tool is now making its presence felt on the dark web and Telegram, catering to cybercriminal activities and raising serious concerns.

FraudGPT is being sold on Dark Web Forums and Telegram for prices ranging from $200 to $1700 per year.

The Chat GPT Fraud Bot offers unrestricted exclusive tools and features for users. FraudGPT has limitless potential, and the promoter claims that users can use it to perform any desired tasks. So far, FraudGPT has been confirmed to have sold over 3000 copies.

FraudGPT is a colossal risk because it can make believable fake websites and write harmful code. Taking advantage of this all-in-one solution, scammers can appear more believable, so they can cause greater damage on a larger scale. 

In addition to WormGPT, another AI cybercrime tool has been discovered on Dark Web forums. As a blackhat alternative to GPT models that is specifically tailored for malicious activities such as phishing and business email compromise, WormGPT is marketed as a tool for phishing and business email compromise.

  • Dark web investigation leads to charges against Perth man

A 49-year-old man from Marangaroo, Western Australia, is facing serious charges related to online child abuse. The WA JACET charged him on July 3, 2023, for his dark web activities, which were reported by the ACCCE.

The police found 17 videos of child abuse on his computer in June. The man allegedly visited multiple dark websites to access such content and used various tactics to avoid detection.

Detective Hinscliff condemned viewing child abuse material and warned online offenders that law enforcement would pursue them relentlessly, even if they use the dark web or anonymizing technologies.

The charges brought against the man include possessing and accessing child abuse material, both of which are violations of the Criminal Code 1995 (Cth). If convicted, he could face up to 15 years in prison.

The partners of the Australian Federal Police and the police themselves are determined to fight against child abuse and exploitation. The ACCCE’s role is to make the digital world safer by tackling online child sexual exploitation.

  • Man Jailed for Importing Explosives After Dark Web Plot

Finally, in dark web august digest, we got a shocking case that has come to light involving a 36-year-old Żebbug resident, Jomic Calleja Maatouk, who was sentenced to five years in prison for his involvement in a dark web plot to illegally import explosives from the United States. 

The court deemed Calleja a “lethal weapon,” capable of inflicting “chaos and destruction.”

Jomic Calleja Maatouk’s dark web plot involved seeking lethal poisons, but when unsuccessful, he turned to explosives. Foreign security services alerted investigators about his attempts to get deadly chemicals. The poisons seemed to target a specific person, and he aimed to buy “five doses” but was advised to start with one. Investigators also found an order for C-4 explosives. Maltese investigators executed a controlled delivery operation to stop the threat. Facing many charges, Calleja pleaded not guilty, but the court considered his criminal record. Magistrate Donatella Frendo Dimech emphasized the need to protect society, resulting in a five-year prison sentence for rehabilitation and public safety.

The court ordered the forfeiture of €51,000 in bail bonds, revoked Calleja’s bail, and issued an immediate re-arrest. Additionally, he was required to cover €2,827.08 in court expert expenses.

This case serves as a stark reminder of the potential threats lurking on the dark web and the importance of vigilant law enforcement efforts to protect the public from harm.