Dark Web Digest – January 2024 Edition

dark web digest - January 2024

As we all know, the dark web is a mysterious part of the internet world, often attracting controversy, illegal activities and curiosities. It can be accessed by a TOR browser that runs against legal terms and goes against law enforcement and government oversight. In simple terms, it is home to several illegal and illicit activities, including drug trafficking, hacking and cybercrime, yet also to some legitimate and useful purposes such as activism, privacy protection and journalism. 

In the previous editing, we discussed some shocking news and this month, nothing different. In this dark web digest edition of January 2024, we will see some latest trends, news and developments related to the dark web. 

Let’s get started.

Cyber Attack Exposes Yakult Australia Employee Files on Dark Web

Yakult Australia, a popular probiotic company, has been targeted by a ransomware attack that has exposed its company records and sensitive employee documents, including passports, on the dark web. The company, based in Melbourne, is working with cyber incident experts to investigate the extent of the incident. All offices in Australia and New Zealand remain open and continue to operate. The group responsible for the breach is DragonForce, which has listed nearly two dozen targets that have refused to cooperate since the beginning of December. The targets range from a Texas-based family charity to commercial entities like Coca-Cola in Singapore and a South Australian-based bathroom manufacturer.

A sample of the 95 gigabytes of data leaked by ABC Investigations found company records dating back to 2001, including scans of passports and driver’s licenses, pre-employment medical assessments and certificates, salaries, and performance reviews. At least one of the passport scans belongs to a warehouse employee. In the leaked cache, the ABC has also seen Japanese passports, where Yakult’s parent company is based. A separate database also contains the names and addresses of nearly 9,000 people. It is unclear if these are customer records, but ABC has verified the accuracy of some of the names and addresses.

Yakult Australia became aware of the cyber attack on December 15, and DragonForce listed the probiotic company as one of its victims before publishing the stolen cache on Christmas Day morning. ABC Investigations has not independently verified each of DragonForce’s published leaks.

Dark Web Ads Target Booking.com Partners, Affecting Customer Security

Booking.com has been targeted by scammers for years, with hackers now posting ads on dark web forums to obtain the passwords of hotel partners. The scammers gain access to a hotel’s extranet, install malware, access passwords, and mimic IP addresses to bypass two-factor authorisation. They use the hotel partners’ login credentials to enter their Booking.com accounts and send urgent messages to customers urging them to send money to the scammers or risk losing their reservations. Booking.com acknowledges that the hackers are not gaining access to Booking.com’s backend systems but acknowledges that the scammers have broken into hotel partners’ accounts. 

The hackers then communicate with Booking.com customers/hotel guests, urging them to send money to the fraudsters. The hackers then message customers from the official app and can trick people into paying money to them instead of the hotel. Booking.com has been unable to make the problem disappear, and the company has been working diligently to support its partners in securing their systems and helping potential customers recover lost funds. The company has been publishing best practices for avoiding these scams and is working to help customers recoup lost funds.

German Authorities Dismantle Global Dark Web Hub ‘Kingdom Market’

German law enforcement has disrupted the dark web platform called Kingdom Market, which specializes in selling narcotics and malware to thousands of users. The operation, which involved collaboration from the U.S., Switzerland, Moldova, and Ukraine authorities, began on December 16, 2023. Kingdom Market has been accessible over the TOR and Invisible Internet Project (I2P) anonymisation networks since March 2021, trafficking illegal narcotics, advertising malware, criminal services, and forged documents. As many as 42,000 products were sold via several hundred seller accounts on the platform before its takedown, with 3,600 originating from Germany. Transactions were facilitated through cryptocurrency payments, with the website operators receiving a 3% commission for processing the sales of illicit goods. The operators of ‘Kingdom Market’ are suspected of commercially operating a criminal trading platform and of illicit trafficking in narcotics. In addition, one person connected to the running of Kingdom Market has been charged in the U.S. with identity theft and money laundering.

GTA 5 Source Code Leaked Online One Year After Rockstar Hack

The source code for Grand Theft Auto 5 was leaked on Christmas Eve, a year after the Lapsus$ hacking group hacked Rockstar Games and stole corporate data. The hackers claimed to have stolen the GTA 5 and GTA 6 source code and assets, including a GTA 6 testing build. They also shared GTA 5 source code samples as proof of their theft.

Security research group vx-underground spoke to the leaker on Discord, who said the source code was leaked sooner than expected. They claimed to have received the source code in August 2023, motivated by combating scamming in the GTA V modding scene. BleepingComputer reviewed the leak, which appears to be legitimate GTA 5 source code, but could not independently verify its authenticity.

The Lapsus$ hackers are known for their skills in performing social engineering and SIM-swapping attacks to breach corporate networks. They have hacked companies such as Uber, Microsoft, Rockstar Games, Okta, Nvidia, Mercado Libre, T-Mobile, Ubisoft, Vodafone, and Samsung. Their success led the Department of Homeland Security (DHS) Cyber Safety Review Board to analyze their tactics and share recommendations for preventing similar attacks in the future.

While the Lapsus$ group has not been very active since members were arrested, some members are now believed to be active in the loose-knit hacking collective known as Scattered Spider. Scattered Spider shares similar tactics to Lapsus$, utilizing social engineering, phishing, MFA fatigue, and SIM-swapping attacks to gain initial network access to large organizations.

Health Data Breach Sparks Extortion Threats

A cyberattack on Integris Health, Oklahoma’s largest not-for-profit health network, compromised the personal information of two million patients. The breach was confirmed on November 28, 2023, and extortion emails were sent to patients threatening to sell their stolen data to other threat actors. The emails contained links to a dark web page where stolen data, including names, Social Security numbers, dates of birth, and hospital visits, was listed for about 4,674,000 people. The hackers who claimed responsibility for the cyberattack began sending the extortion emails on December 24. The emails claim to include dates of birth, Social Security numbers, addresses, phone numbers, insurance information, and employment details. The hackers threaten to sell the stolen data of those who do not pay the $50 deletion fee by January 5, 2024.

The cyberattack on Integris Health is similar to those used in the attack on Fred Hutchinson Cancer Center, where patients were subjected to similar extortion emails. Integris Health advised patients not to reply to the hackers or follow any instructions found in the extortion emails. A PDF containing frequently asked questions about the incident can be found at the bottom of the page. Affected patients are advised to stay alert and take necessary safety measures to reduce risks related to the compromised data.

Enhancing Cyber Security in Greece Amidst Frequent Attacks

The recent cyber-attacks targeting public bodies in Greece have highlighted a weakness in security, which the government of Prime Minister Kyriakos Mitsotakis plans to address with new legislation to create a National Cybersecurity Authority. The bill is about to be submitted for public consultation. Criminal groups prefer certain infrastructures in public sector services in Greece, possibly due to unpreparedness or laxity in taking protection measures.

According to CheckPoint Research, the number of cyber-attacks globally jumped 38% between 2021 and 2022. In the last six months, the top six targets in Greece were healthcare, retail/wholesale, finance/banking, manufacturing, and transportation. HPPC suffered a DDoS attack on November 8 but said it had not detected any data breaches; hacker group Ragnar Locker took responsibility for the attack on DESFA in August last year and posted 361 gigabytes of DESFA data on the dark web; the Greek postal service announced it had been hit in December 2022, nine months after the actual attack.

An organized security system is crucial, as achieving security is a long-term effort and not only a technical problem. A major problem is that when an organization is attacked, it does not provide all the necessary information in time. The Hellenic Data Protection Authority (DPA) has not issued any fines for personal data breaches following cyber-attacks.

Greece’s left-wing opposition party SYRIZA has accused the government of “inaction on the critical issue of cyber-security,” but Mavridis said cybercriminals are always ahead of everyone else. The point is not to be too far behind, as criminals constantly develop new ideas and attacks.

Currently, the fight against cyber-attacks in Greece is the responsibility of several different organizations. The military’s Cyber Defence Directorate protects the internet infrastructure of the Greek armed forces, the Cyber Security Operations Centre of the intelligence services protects the state’s digital infrastructure, and the police’s Cyber Crime Division handles online crime.

The legal framework, though complex, looks sufficient to prevent and fight cyber-attacks. However, the reality lags, with low awareness and education levels and no serious investment by companies in protecting their systems and compliance with the requirements of the existing legal framework. Greek experts suggest that the best way to deal with cyber-attacks is through prevention, detection, reaction, and sharing of information, as well as specialized cyber security personnel and heightened security awareness.

Vitoratos called for a strong National Cybersecurity Authority that can monitor the implementation of Greece’s National Cybersecurity Strategy and the compliance of actors while also being transparent and open with the public and civil society.

Rising Dark Web Sales of Stolen Data Prompt Cybersecurity Warning

CyberSecurity Malaysia has warned of a significant rise in data breach incidents from January to November this year, with stolen data being sold on the dark web. The increase includes Personally Identifiable Information (PII), including full names, permanent addresses, household income, identification numbers, email addresses, or phone numbers of victims. 

CyberSecurity Malaysia emphasizes the importance of protecting personal and sensitive data, as it safeguards privacy, individuals, and business reputation. The company also urges organizations to be responsible for preventing such incidents and handling data exposure incidents appropriately.

Individual Selling Fentanyl Online Receives Life Sentence for 29 Overdose Deaths, Including 2 in Oregon

A Pennsylvania man, Henry Konah Koffie, was sentenced to life in federal prison for selling fentanyl online, which prosecutors say caused the overdose deaths of at least 29 people. Koffie, 38, sold a synthetic drug called furanyl fentanyl, a synthetic drug with no medical use. Between September 2015 and his arrest outside Philadelphia in July 2017, Koffie made 7,849 separate transactions, selling the drug in all 50 states. In Oregon, law enforcement linked Koffie to three overdoses, two of which ended in death. In March, a jury in Portland convicted Koffie on several felonies, including two counts of distribution of a controlled substance resulting in the death of an adult.

Koffie received fentanyl in the mail from suppliers in China, then advertised on AlphaBay, a former dark web site, and shipped the drugs through the mail to customers across the country. Investigators linked Koffie’s sales with overdose deaths in at least 15 states, including Idaho, Texas, Florida, Hawaii, California, New York, Minnesota, and Ohio. Scott Kerin, an assistant U.S. Attorney who prosecuted the case, called the drug Koffie was selling poison.

Koffie’s defense attorney asked Mosman not to sentence him to life in prison, stating that life is redeemable. Mosman acknowledged that it is a rare case that warrants a life sentence, as the callousness and cruelty with which a defendant commits a crime that kills others merits the highest sentence.

Dark Web Digest – December 2023 Edition

Deep Web Digest - December 2023

Welcome to the Dark Web Digest for December 2023. This month, we are going to sее a concisе overview of the latest dеvеlopmеnts on thе dark side of thе internet. We bring some terrifying stories highlighting thе untiring threats posed by thе dark web from stolen university data appearing on illicit markets to thе exposure of a ransomware mastermind who shared too much.

In cybersecurity, partnerships bеtwееn Blackbird.AI and Dark Owl aim to combat narrative attacks, while thе NHRC chief calls for thе dеvеlopmеnt of digital forensic infrastructure to tackle dark web activities.

Legal actions include a life sеntеncе for an individual running dark web child exploitation sites and thе suspension of MyGov accounts linkеd to dark web fraud kits. A ‘wеll-dеsignеd scam’ targеting Booking.com customers underscores thе-evolving nature of dark web schemes, emphasizing thе ongoing nееd for vigilance.

There are not just these; this digest got more from above this. Stay tuned for some latest trends and news from the darkwеb novеrmеbr 2023 digest. Let us get started!

British Library hack: Customer data offered for sale on dark web

The first news is from the British Library. The British Library has confirmed that user data was hacked in a cyber-attack and offered for sale on the dark web. The attack on October 31 continues to affect the library’s website, online systems, and some onsite services. The ransomware group Rhys Ida, claims to be behind the attack and plans to auction off the stolen data. 

The price for data, including passport scans, was set at 20 Bitcoin (£596,459). The library has warned users who use the same password elsewhere to change it as a precaution. The library will continue working with cybersecurity specialists to examine the material and advice users on practical steps. 

The library has also confirmed that some employee data was leaked in the attack, but there was no evidence of compromised user data. The ransomware group shared an image on the dark web showing various documents, some of which appear to be HMRC employment contracts and passports. The cybercriminals announced an auction for “exclusive, unique and impressive data” that would end before 08:00 GMT on November 27.

Sensitive data stolen from Aegean University leaked to dark web

The University of the Aegean has published hundreds of files containing sensitive data stolen by the cybercriminal group Lockbit. The university’s electronic systems were targeted with Lockbit’s ransomware on March 2, and the attackers demanded payment or the release of the seized files. The University of the Aegean has informed the Data Protection Authority and is investigating the leaked files. 

The files contain the personal data of university employees, process forms for tenders, building plans, internal university documents, and certificates of completion of studies. Lockbit infects an organization’s system with ransomware and coerces targets into paying, with a countdown displayed when the data will be released.

Blackbird.AI and DarkOwl Partner To Enable Organizations To Identify Plot Attacks Across The Dark Web

Blackbird.AI, a leader in AI-driven Narrative and Risk Intelligence, has partnered with DarkOwl, a leading provider of Darknet Data, to help organizations identify narrative attacks across the dark web. Darknet and messaging apps are complex, noisy, and opaque social platforms often used by bad actors to develop and deploy harmful narratives and cyber attacks. 

Through this partnership, organizations gain valuable insights that have historically been difficult for cyber and communications professionals to see and protect themselves against. The Constellation Narrative Intelligence Platform is designed to detect narrative attacks and manipulation, including misinformation and disinformation. 

DarkOwl offers the world’s largest commercially available database of information continuously collected from the darknet. It enables Blackbird.AI and its customers to turn this data into a powerful tool to identify narrative risks at scale and drive better decision-making. The darknet datasets are updated from thousands of sites across multiple darknets daily. They will be made available through Blackbird.AI’s Constellation Platform, allowing users to parse and analyze the data for specific narrative attack use cases.

Develop digital forensic infrastructure to deal with Dark Web: NHRC chief.

Justice Arun Kumar Mishra, chairperson of the National Human Rights Commission (NHRC), has expressed concern about the Dark Web and its potential threats to society. He emphasized the need for a digital forensic infrastructure to combat the Dark Web, which is 96% of cyberspace and is used for criminal purposes such as child exploitation, privacy destruction, modern slavery, trafficking, and ransom demands. 

Mishra also emphasized the need to invest in a broad-based digital forensic infrastructure to combat cyberspace misuse and criminal commerce while ensuring the digital divide is nonexistent. He also insisted on the importance of violence-free elections and gender equality, stating that violence has no place in the democratic process. 

Ransomware Mastermind Uncovered After Oversharing on Dark Web

Researchers were tasked with a ransomware-as-a-service (RaaS) operation by farnetwork, a cybercriminal known by various aliases. The Nokoyawa affiliate business’s affiliate was involved in the process, which involved at least five different ransomware strains. Farnetwork demonstrated its ability to execute privilege escalation, use ransomware to encrypt files and demand cash for an encryption key. 

The Group-IB researcher learned that Farnetwork already had a foothold in various enterprise networks and needed someone to deploy the ransomware and collect money. The deal involved the Nokoyawa affiliate receiving 65% of the extortion money, the botnet owner receiving 20%, and the ransomware owner receiving 15%. 

Farnetwork’s ransomware activities can be traced back to 2019, with details about past operations with Nefilim and Karma ransomware and payments as high as $1 million. The crook also mentioned past work with Hive and Nemty.

‘Scam-in-a-box’: MyGov suspends thousands of accounts linked to dark web fraud kits

Thousands of MyGov accounts are being suspended each month due to concerns that they have been breached via “scam-in-a-box” kits sold by criminals on the dark web. These products created fake websites and provided the specialist knowledge required to launch phishing attacks on Centrelink, the Australian Tax Office, and Medicare accounts. So far this year, more than 4,500 MyGov scams have been confirmed, with thousands of accounts suspended each month due to suspected fraud.

The government services minister, Bill Shorten, said Australians had already lost $3.1bn to scams this year, and authorities were taking the issue seriously. The problem with these hacks and the proliferation of phishing scams we now see is that increasing amounts of stolen identifying details end up on the dark web.

Scammers and hackers are targeting MyGov until the government overhauls its I.D. verification, which it is in the final stages of doing. The Albanese government is determined to disrupt malicious actors by bolstering online defences. It is working closely with Senator Katy Gallagher to establish a digital I.D. that will be a crucial line of defence against cybercrime when found. Last year, after the Optus breach, the government confirmed it was considering using myGov or its myGovID system to centralize digital identity authentication.

In August, the Australian Tax Office warned people against clicking on emails and text message scams directing people to fake MyGov websites. In 2019, Guardian Australia reported on dark vendors offering Medicare details for US$21 ($33) and other vendors charging up to US$340 for fake Medicare cards alongside other fake forms of identification, such as a New South Wales driver’s license.

Man Sentenced to Life in Prison for Running Four Dark Web Child Exploitation Websites

A Missouri man, Clint Robert Schram, has been sentenced to life in prison for running four websites dedicated to sharing images and videos of child sexual abuse. Schram, 55, of Kansas City, hosted, managed, and maintained these websites from his home, each operating over the dark web. Each website was devoted to advertising, distributing, and exchanging images and videos depicting the sexual abuse of children. Schram recruited, managed, and directed different tiers of staff members who helped run the websites.

On May 10, a federal jury convicted Schram of one count of engaging in a child exploitation enterprise and four counts each of advertisement of child pornography and conspiracy to advertise child pornography. The U.S. District Court for the Western District of Missouri has charged several defendants with Schram’s websites.

The FBI’s Child Exploitation Operational Unit and Kansas City Field Office investigated the case, with assistance provided by FBI field offices and resident agencies in Portland, Oregon; Chattanooga, Tennessee; Tulsa, Oklahoma; and Poulsbo, Washington; Homeland Security Investigations’ offices in Burlington, Vermont, and Boston; and the Criminal Division’s Child Exploitation and Obscenity Section’s (CEOS) High Technology Investigative Unit.

CEOS Trial Attorney Kyle P. Reynolds and Assistant U.S. Attorneys Alison D. Dunning and David Luna for the Western District of Missouri are prosecuting the cases, with valuable assistance from the U.S. Attorney’s Offices for the District of Oregon, District of Vermont, Northern District of Oklahoma, Western District of Washington, and Eastern District of Tennessee. 

Project Safe Childhood, a nationwide initiative launched in May 2006 by the Justice Department, marshals federal, state, and local resources to better locate, apprehend, and prosecute individuals who exploit children via the internet, as well as to identify and rescue victims.

Booking.com customers warned of ‘well-designed scam’ putting details for sale on the dark web

Booking.com customers have been warned of a “well-designed scam” that has seen account details sold on the dark web. Cybersecurity firm Secureworks has found that criminals target the website’s partner hotels to steal user details and then send phishing emails to the customers, claiming their reservation will be cancelled if they do not provide payment information urgently. The tactic is seeing a “high success rate,” and Booking.com is aware of some of its partners having been affected in recent months.

The scam unfolds in two phases, starting with hotels targeted by scam emails. They often claim to be from a guest who has left valuable documents during their stay, who then sends a follow-up email directing the hotel to a Google Drive link purporting to show an image of the lost item. The link contains malware called Vidar Infostealer, allowing criminals to access the Booking.com account portal people use to make their reservations. From there, they can target the customers.

In one case involving a hotel in Scotland, a receptionist was duped by a scam caller who claimed to want to book a room for herself and her child with severe allergies. The attachment contained the malware. It gathered details of all the hotel’s Booking.com customers and sent them fraudulent emails saying they had 24 hours to pay.

Secureworks has found Booking.com credentials sold on dark web forums for up to $2,000 (£1,576). The company has recommended that hotels make staff aware and teach them how to identify such attacks, while customers should use multifactor authentication to protect their accounts. They should also question any emails or app messages requesting payment details and contact Booking.com or the hotel directly if they have concerns.

Booking.com has made significant investments to limit the impact of online fraud and has shared additional tips and updates with partners about protecting themselves and their businesses.

The doctor planned to have his girlfriend killed by hiring a hitman over the dark web, U.S. feds say

A Georgia doctor, Dr. James Wan, hired a hitman over the dark web and sent thousands of dollars in Bitcoin to have his girlfriend shot to death. In April 2022, Wan placed a murder-for-hire order through a “dark web marketplace” with instructions to kill his girlfriend. He instructed the hitman to “shoot and go” and sent a 50% down payment of about $8,000 (RM37,300) in Bitcoin to ensure the murder would be carried through.

Wan messaged the marketplace’s administrator two days after hiring a hitman to confirm his Bitcoin payment was received. After learning the amount wasn’t received, Wan sent another Bitcoin payment of about $8,000 (RM37,300) to ensure the hitman received the money. The marketplace administrator confirmed the second payment went through to Wan’s escrow account and asked if he wanted his girlfriend to die in an “accident or normal shooting”.

The FBI learned of Wan’s “cold-hearted” plot and extended protection to his girlfriend, whom agents informed of the hit Wan had put on her. On October 17, Wan pleaded guilty to one count of using a facility of interstate commerce in the commission of murder-for-hire.

Wan’s motives for wanting his girlfriend dead are unclear, as prosecutors did not specify possible reasons. He is scheduled to be sentenced in the case on January 18.

That is from last month’s dark web digest of December.  Every month, we uncover something novel and intriguing on the dark web. We do our best to keep you updated on the latest events and trends in this mysterious space. Stay tuned for our next digest in January, where we will bring you even more dark web insights and stories!

 

Dark Web Digest – November 2023 Edition

Deep Web Digest - November 2023

Darkweb is part of the internet that is not indexed by search engines. It is accessible only through specialized software, such as Tor. It is used for illegal activities such as drug trafficking, money laundering, and child pornography. There is no doubt that the dark web is becoming more and more dangerous, and many people are becoming its victims every month. The dark web is filled with many incidents and trends every month, some horrifying. This month, let’s look back at what happened.

This month, the dark Web has seen a rise in attacks, data breaches, cryptocurrency, sexual harassment, and child abuse scams. Additionally, the dark web is used for illegal goods and services, including drugs and weapons.

McLaren’s ransomware attack may have leaked patient data to the dark web.

McLaren Health Care has acknowledged that a ransomware attack on its 14 Michigan hospitals in late August and early September may have leaked patient data onto the dark web. BlackCat/AlphV, a ransomware gang with ties to Russia, claimed responsibility for the cyberattack, stealing six terabytes of McLaren’s data, including the personal information of 2.5 million patients. 

McLaren's ransomware attack may have leaked patient data to the dark web

The cybercriminals threatened to extort patients by leaking mammograms for people potentially having breast cancer. They began targeting patients directly, saying they had the mammograms and would leak them if the clinic didn’t pay the ransom.

Healthcare providers are required to report any breach of protected health information to the U.S. Department of Health and Human Services and the Federal Trade Commission. The federal HIPAA Breach Notification Rule offers some protection by requiring healthcare providers to disclose details about the type of information compromised; steps people should take to protect themselves, what is being done to investigate the breach, and contact information within 60 days of discovering the breach. If the cyberattack involves 500 people or more, a prominent media outlet must also be notified within 60 days.

Trustwave, a Chicago-based cybersecurity company, released a report in July that found nationally, 24% of all cyberattacks in the U.S. in 2022 targeted the healthcare industry. The average cost of a healthcare data breach in 2023 is about $11 million.

US Charge Man with Running Stolen Credentials Marketplace

Sandu Diaconu, a 31-year-old Moldovan man, has been extradited from the UK to the US for allegedly operating a website that sold access to compromised computer credentials. 

The US charges Diaconu with conspiracy to commit access device and computer fraud, wire fraud conspiracy, money laundering conspiracy, access device fraud, and computer fraud. 

US Charge Man with Running Stolen Credentials Marketplace

If found guilty, he faces up to 20 years in federal prison. The charges relate to his alleged administration of the E-Root marketplace, which sold access to compromised computer credentials for years. Authorities believe over 350,000 credentials were listed for sale on E-Root.

The E-Root marketplace used various methods to hide the identities of its administrators, buyers, and sellers, including using Perfect Money to conceal payments and offering its illicit cryptocurrency exchange service for converting Bitcoin to Perfect Money. 

Buyers could search for compromised computer credentials through various criteria, including price, geographic location, internet service provider, and operating system. Many victims, including at least one government agency in Tampa, Florida, were subjected to ransomware attacks, and some stolen credentials were linked to stolen identity tax schemes.

The E-Root marketplace was taken down in 2020, and Diaconu was arrested in the UK in May 2021. In September 2023, Westminster Magistrates’ Court ordered his extradition to the US.

 The takedown of the E-Root marketplace is part of a growing crackdown on cybercrime websites, similar to the recent German police shutdown of Russian darknet marketplace Hydra and the Europol arrest of nearly 300 individuals on the underground marketplace Monopoly Market.

FBI exposes million-dollar crypto scam orchestrated by six Indians in New York

The US FBI has charged six Indians in a $30 million cryptocurrency scam. The six Indians, Shaileshkumar Goyani, Brijeshkumar Patel, Hirenkumar Patel, Naineshkumar Patel, Nileshkumar Patel, and Raju Patel, allegedly operated an illegal $30 million money-transmitting business using cryptocurrencies between July 2021 and September 2023. 

FBI exposes million-dollar crypto scam orchestrated by six Indians in New York

The FBI began an investigation in April 2021 when they identified a vendor on multiple dark web marketplaces who offered a service to ship cash via the US Postal Service in exchange for Bitcoin or other cryptocurrency. 

An individual was arrested for mailing packages of cash from a post office in Westchester County, New York, where the informant obtained money by meeting people three times a week and receiving amounts ranging between $100,000 and $300,000 each time. 

The FBI investigation revealed that one of the men made frequent trips outside of New York, including to New Jersey, Massachusetts, Georgia, and Pennsylvania. One of the arrested men claimed that his wealthiest clients were hackers and some made money selling drugs.

Dark web usage, paranoia detail by London, Ont. family accused of killing

Nathaniel Veltman, a man accused of killing four members of a London, Ontario, Muslim family in a terrorist attack, took three grams of psychedelic mushrooms to escape his delusional paranoia.

Dark web usage, paranoia detail by London, Ont. family accused of killing

Veltman testified in his defense in a Windsor, Ontario, courtroom, stating that he needed to escape the hell he was living in in his mind. 

On June 6, 2021, the Afzaal family was out for a walk when they were struck by a black pickup truck driven by Veltman. The family was killed, and a nine-year-old boy survived.

Veltman was arrested in the hours following the attack and has pleaded not guilty to four counts of first-degree murder and one count of attempted murder, as well as associated terrorism charges. 

Defence and prosecution lawyers agree that he drove the truck at full speed four seconds before impact and never touched the brake pedal.

Veltman’s obsessions shifted from religion and sometimes pornography to conspiracy websites and satirical shock-humor sites. He watched far-right sites “constantly” from September to December 2020, watching them during 10-minute breaks at work, lunch, as soon as he got up, and before going to bed. 

From January to March 2021, Veltman didn’t work, thinking he could focus on school. Instead, he said his internet use spiraled even further out of control. At one point, he ripped his television off the wall to try to avoid streaming videos on it.

After two suicide attempts in March, Veltman decided he had “nothing left to lose” and started purposely seeking out extreme content that he’d in the past avoided because he thought they would trigger too much rage. 

He felt this unspeakable rage rising inside himself and felt like he had nothing to lose. He watched a mass shooting video and was repulsed by it “like any normal person” but then got desensitized to it after watching it over and over.

Veltman testified that he had dabbled with magic mushrooms in high school but took a large dose with a friend in April 2020. He described collapsing, writhing on the floor, yelling, and being in agony. He triggered a psychotic event, which he couldn’t fight or control, eventually forgetting everything.

After the April incident, Veltman didn’t use psychedelics again until June 5, 2021, when he got three grams from a friend and drank them in a tea, distraught over the death of his grandmother on June 4, 2021.

Ransomware Gang Moves to Release Sabre Leak Data

The Dunghill Leak group, responsible for a cyberattack on travel booking giant Sabre Corporation, has announced plans to release 1.3 terabytes of stolen data in eight batches. The data includes sensitive databases on ticket sales and client data. 

The breach occurred after Sabre acknowledged the breach on September 6, 2023, after a series of files purportedly stolen from them surfaced on the group’s dark website. The Australian travel industry is on high alert, as Sabre’s software and data underpin many airline and hotel bookings, check-ins, and apps. 

The expansive data cache now looms with the potential to release databases on ticket sales, client data, personal information of Sabre employees, detailed financial information, and files associated with the airline-client application. The breach is believed to have occurred around mid-2023. Dunghill Leak, believed to have evolved from the Dark Angels and Babuk ransomware groups, has previously targeted other high-profile companies. 

Australia and most developed nations have advised against paying ransoms to hacker gangs. Sabre faced a security incident in 2017, which cost them $2.4 million in settlements after a breach in their hotel reservation system.

Child sex abuse images generated by AI risk flooding the internet 

The Internet Watch Foundation (IWF) has warned governments and technology providers to prevent the proliferation of child sexual abuse images on the internet. The IWF warns that a flood of AI-generated images could overwhelm law enforcement investigators and expand the pool of potential victims. 

Child sex abuse images generated by AI risk flooding the internet 

The report exposes a dark side of the race to build generative AI systems that enable users to describe in words what they want to produce, from emails to novel artwork or videos, and have the system spit it out. 

If not stopped, the flood of deepfake child sexual abuse images could bog investigators down trying to rescue children who turn out to be virtual characters. Perpetrators could also use the images to groom and coerce new victims.

The IWF analysts discovered faces of famous children online and a “massive demand for the creation of more images of children who’ve already been abused, possibly years ago.” They are taking existing real content and using that to create new content for these victims. 

The IWF’s report is meant to flag a growing problem more than offer prescriptions, but it urges governments to strengthen laws to make it easier to combat AI-generated abuse. It mainly targets the European Union, where there’s a debate over surveillance measures that could automatically scan messaging apps for suspected images of child sexual abuse even if the image is not previously known to law enforcement.

SONY CONFIRMS DATA BREACH IN MAY – OVER 6000 PEOPLE AFFECTED

Sony Interactive Entertainment (Sony) confirmed a data breach on May 28, 2023, affecting thousands of current and former staff and their families in the United States. The breach was discovered on June 2, 2023, and the platform was immediately offline. 

SONY CONFIRMS DATA BREACH IN MAY – OVER 6000 PEOPLE AFFECTED

Sony launched an investigation with the help of external cybersecurity experts and notified law enforcement. The incident was limited to the MOVEit vendor software and did not impact Sony’s other systems.

The breach was caused by a flaw in the MOVEit vendor software, discovered by Sony in early June 2023. The vulnerability tracking number is CVE-2023-34362, a high-risk SQL injection vulnerability that can remotely execute arbitrary code. 

The malicious hackers had illegal access to data from the platform. After discovering the breach, Sony took immediate action, and the compromised data included personal information such as names, addresses, Social Security numbers, and dates of birth.

Sony launched a probe with the help of external cybersecurity experts and notified law enforcement. The incident did not impact any other of Sony’s systems apart from the MOVEit vendor software. However, all current and former staff have emails from Sony informing them of the breach.

Sony has suffered several data breaches in the past, including a major breach in 2011 that exposed the personal information of millions of users. In August 2017, a hacker group accessed Sony’s social media accounts and deleted data from Sony systems using a variant of the Shamoon virus. In July this year, the Clop ransomware group used the MOVEit vulnerability to launch large-scale attacks. Sony discovered the attack three days later and found unauthorized downloads.

The breach has potentially exposed the personal information of over 6,000 people, precisely 6,791 Americans. Hackers can use this data to steal the identity of the owners and for other malicious purposes.

Conclusion

These are some of the most significant trends and news on the dark web in October 2023. They illustrate the diverse and dynamic nature of the dark web, as well as its challenges and opportunities for law enforcement, security, and society. The dark web is not only a source of crime and danger but also a platform for innovation and resistance. As such, it deserves our attention and understanding. We will keep you updated with upcoming trends and incidents happening in the dark web world. So stay in touch with us

Dark Web Digest – October 2023 Edition

dark web digest - October 2023

Welcome to the October edition of Dark Web Digest, your go-to source for the latest news and updates from the dark web. The dark web is a breeding ground for cybercriminals, with several associated threats. In addition, it is constantly evolving, and new developments are always emerging.

This edition contains the most recent developments in cybersecurity, hacking, and the dark web. Let’s look at the latest news and incidents that occurred last month!

Cyberattack exposes donor data from Australia-based telemarketing firm

The Pareto Phone ransomware group, LockBit, has been reported as taking donor data and publishing it on the dark web (including here and here). Among the charities involved, the Australian Conservation Foundation said 13,500 supporters. According to a statement, the data accessed by ChildFund NZ included titles, names, and postal and phone numbers.

There was also the revelation that Pareto Phone hid data from charities for many years without their knowledge. This was with the Baker Heart and Diabetes Institute not working with Pareto Phone for more than eight years and the Stroke Foundation not since 2017. Children’s Fund NZ has collaborated with Pareto Phone since 2014. MSF Australia said it had not used the company for almost five years and was unaware it had retained historical records.

According to a report last October, one in eight charities in the UK suffered cybercrime within the past year due to cyberattacks. An advanced cyber security attack in 2022 on the International Committee of the Red Cross (ICRC) compromised the sensitive personal information of more than 515,000 highly vulnerable people from more than 60 Red Cross and Red Crescent National Societies worldwide.

Loyalty’s third-party research partner, Kokoro, was recently targeted in the UK. According to Kokoro’s forensic investigation, the group responsible may have accessed some client data. In this case, no postal addresses, financial details, or identity documentation were available on Kokoro’s systems. The charity clients affected were informed, with Shelter and Friends of the Earth acting to reassure and inform.

Finland, Europol take down PIILOPUOTI dark web marketplace

The Finnish law enforcement forces worked with Europol and a cybersecurity firm to shut down PIILOPUOTI. Finnish Customs said that the platform had operated on the Tor Network since May 2022 for smuggling drugs and paraphernalia into Finland.

Due to an ongoing criminal investigation, Finn Customs and its international cooperation partners won’t provide any further information. The Finnish authorities refused to comment on arrests or other illegal activities conducted on the platform. It said the investigation was born with the assistance of German and Lithuanian authorities, Europol, Eurojust, other countries’ authorities, and various Finnish police units.

PIILOPUOTI - Marketplace

Bitdefender helped law enforcement agencies investigate the platform in its investigation and participated in the takedown. Alexandru Catalin Cosoi, Bitdefender’s senior director of investigation and forensics, did not elaborate on the company’s involvement but said it “provided technical consulting to the entire investigation group.” Earlier this month, US and Polish law enforcement agencies partnered to dismantle the bulletproof hosting platform Lolek.

In April, more than a dozen international partners were involved in an FBI-led operation that seized Genesis Market, a one-stop shop for criminals selling stolen credentials and the tools to weaponize them.

Dark Web hacker threatens to sell US and European military intelligence

US Department of Defense hacker “USDoD” has warned that he intends to sell military intelligence to the dark web. The hacker entered the Airbus website by exploiting Turkish Airlines employee access.

According to USDoD, its targets are American defense contractors, NATO, Europol, and Interpol. In a lengthy interview with databreaches.net, USDoD disclosed that its next targets are American defense contractors, NATO, and Europol.

While he threatened to set up a private company to trade classified military information between the US and Europe, the Department of Defense claimed that he was not pro-Russian despite cyberattacking Russia’s adversaries. He also worked for some Russians, but he has no racial biases or political motives.

As part of the hacker’s denials, he denied receiving financial compensation for his attacks on United States and European entities. He avoids attacking China, Russia, North Korea, South Korea, Israel, and Iran exemplifies one of his strategies.

The Pentagon continues to work on cybersecurity as the Pentagon threatens to sell US military intel. The United States Air Force recently awarded Raft LLC a contract to develop a software factory for cyber operations. Cyber deterrence is also strengthened through training and drills, such as the recent “defensive hunt operation” in Lithuania.

The dark web leaks the Personal information of Dymock customers

Earlier this week, Dymocks announced that some of its customers’ information may have been compromised and leaked onto the dark web. A small group of unauthorized individuals may have accessed Dymocks’ customer records on 6 September. Customers’ information, including addresses, e-mails, phone numbers, and membership information, may have been compromised. Dymocks said an investigation is underway to determine how this happened.

Dymock

The issue was notified to customers via an e-mail sent on Friday afternoon, asking them to be “vigilant” and change their passwords. Dymocks’ customers’ postal addresses, birthdates, e-mail addresses, mobile phone numbers, gender, and membership details may have been compromised.

According to a company statement, an unauthorized party may have accessed certain customer records at Dymocks as of 6 September 2023. Neither Dymocks nor its customers know who or how many customers have been affected by the breach.

Since passwords might be available on the dark web, Dymocks suggests its customers change their online passwords, including their Dymocks accounts and social media accounts. Furthermore, the company cautioned customers against telephone, postal, and e-mail phishing scams.

Cornwall dealers used Bitcoin to buy cocaine and cannabis on the dark web

A pair of drug traffickers accused of buying cocaine and cannabis on the dark web to sell on the streets of West Cornwall have been jailed. Jason Pierce, 56, and Callum Payne, 28, both from Porthleven, were sentenced to ten years in prison.

They denied conspiracy to supply cocaine and cannabis, but a jury at Truro Crown Court found them guilty of conspiracy to supply cocaine and cannabis after a trial in June. 

The sentence for Pierce was six years and eight months, and that for Payne was three and four months in prison at Plymouth Crown Court on Friday, 15 September.

A court heard about the drugs’ purchase from the Netherlands on the dark web through Bitcoin and their distribution to locations throughout West Cornwall.

Officers uncovered the drug trafficking operation in January 2018 when they found £5,000 worth of cannabis in the car being driven by Payne.

The defendants’ computers had sophisticated privacy software that needed to be cracked to unlock evidence of their criminal activities.

As Detector Inspector Steven Moorcroft of Devon and Cornwall Police’s Serious and Organised Crime Branch explained: “This investigation began in 2018 after a chase in Porthleven led to Callum Payne fleeing a vehicle containing cannabis imported from the Netherlands through the dark web.

Dozens of Mullvad VPN accounts discovered on the dark web

According to security researcher Damien Bancal, one of the major Swedish VPN providers, Mullvad VPN, has recently been accused of leaking user data.

A ZATAZ Monitoring client discovered an astonishing data leak targeting Mullvad during an investigation. Several websites leading to Mullvad API provided access to user connection data, such as IP addresses [IPv4 and IPv6 addresses], connection dates, and other information that was not personally identifiable, the post says.

A hacker discussion led Bancal to learn about Mullvad VPN’s plans to sell data on the dark market. Among the data shared were Mullvad clients’ 16-digit IDs and expiration dates.

Researchers shared several links to a cache of Mullvad VPN forums where threat actors were trading them off. Despite an ID number, not much information can be retrieved about those accounts since no names, e-mail addresses, or other personal information are available.

The researcher said that a malicious actor can do much damage even with very little information.

According to Jan Jonsson, CEO of Mullvad VPN, the publicly revealed accounts are unsurprising. He has seen over 100 Mullvad VPN accounts personally.

Many Mullvad forums and websites list “leaked” Mullvad accounts. Mullvad donates millions of Mullvad accounts to charities each year for various reasons. Cybernews contacted him via e-mail to learn about several sources for “leaked accounts.”

There was no leak. “Firstly, we have an API with minimal functions. Secondly, we do not use passwords. We only use 16-digit account numbers.” He believes people are brute-forcing account numbers to get free accounts. 

Customer data was seized from the Swedish-owned company’s Gothenburg office in April during a police raid. Since the company had a ‘no logs’ policy, such customer data was not even available to them. If they had taken something, they couldn’t access any customer data.”

The industry has been under scrutiny because VPNs essentially allow users to remain anonymous on the internet.

VPN IDs may contain private user information, such as billing, and may collect personal information so that exposure could have serious consequences. If a VPN ID is exposed, users should change their password, enable multi-factor authentication, and notify their VPN provider.

Senate is concerned about Pakistani public data sales on the dark web.

Pakistan faces a growing challenge concerning protecting its public data, with the Senate Standing Committee on Information Technology and Telecommunication recently convening to address these concerns. The Senate greenlights Army Act amendments: 5-year jail term for revealing sensitive information. The gathering boasted a diverse composition, underlining the gravity of the situation.

A Cyber Response Team was established to combat cyber threats effectively. It was also decided to enhance public awareness regarding cybersecurity in Pakistan. The committee received an update on the National Cyber Security Policy, which outlines the government’s strategic approach to safeguarding the nation’s cyberspace. The committee heard from the CEO of Ignite, an organization that has established eight National Incubation Centers across Pakistan and generated Rs15 billion in revenue.

Senator Kauda Babar urged the establishment of more NICs in various cities, with a particular focus on Balochistan. The committee also delved into the National Telecommunication Corporation (NTC) operations, Pakistan’s official telecom and ICT service provider, and called for improvements.

The Senate Standing Committee on Information Technology and Telecommunication highlighted the need to strengthen Pakistan’s data protection measures and bolster cybersecurity efforts to promote innovation and economic growth.

Conclusion

The dark web is a dangerous place that poses several threats to individuals and businesses. However, staying informed and taking the necessary precautions can help you stay safe online. In this edition of Dark Web Digest, we have provided the latest news and updates from the dark web, as well as tips and advice on staying safe online. 

Thank you for reading Dark Web Digest, and we hope to see you again in the next edition.

Dark Web Digest – September 2023 Edition

Deep Web Digest - September 2023

The term ‘dark web’ is often associated with all things illegal. In reality, this may only be half-true. While there is a lot of illicit activity on the dark web, it is also a place where people can communicate anonymously and securely, free from government surveillance. 

The dark web is also used for activities such as activism or whistleblowing. There are tons of news coming out from the dark web each month. The number of illegal activities is not only for the government but also affecting society. August is not so far behind if we compare it with past months on the dark web. 

Therefore, this month’s edition covers the latest dark web news from August, and headlines are leaks, dark web access sales, and vast databases of user information.

Dark Web - Hidden Wiki - Digest September 2023

NSW Man Charged Over Failed Dark Web Drug Imports

The Downing Centre Local Court will hear an alleged attempt to import synthetic opioids, among other illicit drugs, by a Western Sydney man today (August 29 2023).

Several items allegedly contained drugs, including cookware, toy cars, and a blackjack set.

ABF officers intercepted three British air cargo shipments in May 2023. There were 133 MDMA tablets, 100 oxycodone tablets, and 97 analogues of Nitazene, a potent opioid more potent than fentanyl. The third and fourth consignments contained 60g MDMA, 25g ketamine, 15g meth and 14g heroin.

The ABF alerted the AFP, who executed a warrant on May 19 2023, at the Greenfield Park address. The AFP seized fake ID cards, kitchen scales, spoons with white residue, and zip-lock bags.

The intended recipient is a 23-year-old Greenfield Park resident.

According to AFP, his regular encrypted communications with two other people in the UK helped import and traffic border-controlled

On May 20 2023, the man was charged with one count of attempted importation of border-controlled drugs in contravention of section 307.6 of the Criminal Code (Cth).

According to AFP Detective Superintendent Craig Bellis, while each package contained relatively small amounts of illicit drugs, they constituted dozens of individual street deals that harmed society.

Malicious AI Arrives on the Dark Web

Recently, artificial intelligence has advanced at an unprecedented pace, and nefarious non-state actors have been using it to expand their harmful activities. Dark web forums have been buzzing about using OpenAI’s ChatGPT. A tool called WormGPT, based on the open-source GPT-J large-language model developed in 2021, appeared on the dark web on July 13. It generates sophisticated phishing and business email attacks and writes malicious code.

FraudGPT, based on GPT-3 technology, appeared for sale on the dark web on July 22. It is marketed as an advanced bot for offensive purposes, costing US$200 a month to US$1,700 for an annual license. It’s too soon to know how effective WormGPT and FraudGPT are; the specific datasets and algorithms they are trained on are unknown. Furthermore, the malicious AI bots for sale could be scams in themselves.

AI offers enormous opportunities for nefarious actors to enhance their malicious activity and expand their operations. It can create convincing phishing emails and scrape the internet for personal details about a target. AI technology is getting smarter – fast. FraudGPT’s creator is developing DarkBART and DarkBERT, two new malicious AI tools with internet access and integrated with Google Lens.

AI-powered cybercrime will demand an even more proactive approach to cybersecurity, but good cyber hygiene and awareness training remain relevant as the first line of defence against cybercriminals.

Mother of Girl Nearly Sold on the Dark Web Gives Warning to Parents

A Jasper County man is accused of trying to sell a 16-year-old girl’s personal information on the dark web. The girl’s mother spoke exclusively to Atlanta News First. The FBI knocked on her door on June 29 of this year to deliver news they never expected. They told her a tipster, who lived in England, called the anonymous FBI tip line to say this woman’s daughter was in danger.

The mother said Ivey stole photos from their family’s Facebook page and sent them to a private account. Kelly Ivey tried to sell information about a 16-year-old female on the dark web, but her mother believed a higher power protected her daughter from being identified. She said people should not let their guard down, even in safe places.

ChatGPT’s Badboy Brothers for Sale on Dark Web

KrakenLabs, Outpost24’s threat intelligence team, has spotted several illicit adaptations of the AI large language learning model ChatGPT on the dark web. The foremost perversion appears to have been the lugubriously named WormGPT, a no-holds-barred deviation from the original that will obligingly perform tasks that its ‘ proper’ sibling would normally refuse to function.

CanadianKingpin12 advertised a chatbot last month that wrote malicious code, created hacking tools, and found system leaks and vulnerabilities. Prices for WormGPT, FraudGPT, DarkBERT, and DarkGPT vary widely. Last charges $100 for a month’s subscription, CanadianKingpin12 charges $90 for a month’s subscription, and DarkBERT offers $1,000 for a lifetime membership.

 

Artificial intelligence (AI) is one of the new ways threat actors achieve their goals, and it could drastically change the underground ecosystem. 

Last announced the end of WormGPT on August 9, citing too much publicity as a reason for hanging up the black hat. KrakenLabs put a slightly different slant on it, noting that the Telegram channels controlled by Last and DarkStux closed down the day the announcement was made.

A tool quickly gaining popularity is not always helpful, as it increases the chance of something going wrong. KrakenLabs noted a scam involving bogus adverts offering AI-enabled illegal digital tools, taking payment, and never delivering the promised articles. Even Last admitted that “anyone could reproduce what WormGPT did” by using jailbroken ChatGPT versions.

Thousands of Charity Donors Have Data Leaked on Dark Web After Telemarketer Hack

A cyberattack on telemarketer Pareto Phone has resulted in thousands of charity donors’ data being leaked onto the dark web. Three charities have said their donors’ data has been published on the dark web.

The attack was claimed by cyber criminal group LockBit, which said it had stolen 150 gigabytes of personal data.

The Fred Hollows Foundation is “deeply disappointed” that its data was still held by Pareto Phone, considering it hadn’t used its services for almost a decade. The charity has requested Pareto Phone delete any remaining donor data.

Another charity, Médecins Sans Frontières, has raised concerns about Pareto Phone and data retention. They have not worked with Pareto Phone for almost five years.

Professor Nigel Phair said, “organizations need to be careful when using third-party providers and should ensure that data is not kept beyond what is needed.”

He also said the “Privacy Commissioner now has increased penalties at their disposal.”

Cyble’s Dark Web Monitoring Helps Companies Comply with SEBI’s Cybersecurity Mandates

SEBI has rolled out comprehensive cybersecurity guidelines for Market Infrastructure Institutions in the wake of escalating cyber threats. These guidelines are a wake-up call for MIIs to beef up their cyber defences.

SEBI’s latest guidelines require MIIs to proactively monitor the dark web for stolen data, hacking tools, and other malicious artefacts. This allows them to gather crucial intelligence on emerging threats and vulnerabilities, better positioning themselves to mount a robust and timely defence.

Mandar Patil, SVP – Global Sales and Customer Success at Cyble, points out that cybersecurity can’t be a mere afterthought or a box to tick off a checklist. Cyble offers comprehensive dark web monitoring capabilities that meet SEBI’s requirements.

Brand abuse is a challenge for MIIs today. Dark web monitoring can help organizations safeguard their reputation and brand integrity.

The updated SEBI directives coincide with the Digital Personal Data Protection Bill 2023, which imposes substantial penalties for data breaches. Together, these initiatives signal an emerging consensus about the importance of a robust cybersecurity infrastructure for financial entities.

The Digital Personal Data Protection Bill 2023, which seeks to safeguard Indian citizens’ privacy, recently received approval in the Rajya Sabha.

Georgia Man Tried to Sell Teen Girl’s Location on Dark Web, Cops Say. Now He’s in Jail

Kelly Garret Ivey, 41, is accused of selling the location of a teenage girl on a dark website. The website showed pictures of the girl next to the advertisement.

Captain Billy Bryant, the lead investigator of the Jasper County Sheriff’s Office case, said information about the ad came through the FBI’s anonymous tip line. Investigators visited the family’s house and eventually linked the ad to Ivey via his accounts.

Bryant says. “The dark web is just like the regular internet. Anytime you do something, there are ways to backtrack that,” he said. The dark web is a network of online pages requiring certain software or authorization. The pages have less security than regular websites and have become hubs for illegal activity since the dark web’s conception in the early Internet era.

Ivey was arrested at his Forsyth home on June 30. He is in jail in Jasper County and was formally charged with cruelty to children in the first and second degree. He was also charged with human trafficking and attempting to commit a felony. The Telegraph will update this story if more information becomes available.

Police Send Warning Letters to ‘Dark Web’ Drug Buyers

A police officer has sent hundreds of warning letters to addresses that have received online requests for recreational and counterfeit drugs.

ERSOU is a joint effort between seven east-of-England police forces, including Norfolk and Suffolk, to combat organized crime. Investigations have revealed the sale of prescription, recreational, and stupefying drugs – known as ‘date rape’ drugs.

The dark web is a hidden part of the internet, often used as a criminal marketplace. The Eastern Region Special Operations Unit has seized more than £500,000 worth of illicit substances from dark web vendors over the last 18 months.

Detective Inspector Graham Paul said that many items for sale on the dark web are illegal and dangerous and that those who use it for illicit activity could be part of one of our investigations.

Charity Donor Details Leaked to Dark Web After Pareto Phone Breach

Some of Australia’s most high-profile charities have become inadvertently involved in a massive data breach with cybercriminals hacking thousands of donor details through a third party. The charity stressed that its systems had not been impacted.

The Fred Hollows Foundation said they had not worked with Pareto Phone since 2014 and had not known the data was still held by the company. The data does not contain financial, credit card or bank account information.

Professor Tanya Buchanan, CEO of Cancer Council Australia, told news.com.au it was still waiting for Pareto Phone to clarify how many donors’ data had been breached.

Pareto Phone did not respond to requests for comment but said it worked with forensic specialists to analyze affected files.

The hacking company, Pareto Phone, collected donations from charity supporters. The data breach occurred in April this year, affecting a “subset” of Canteen supporters.

Google One To Roll Out Dark Web Report For Subscribers

Google is reportedly in talks to roll out a new feature called Dark Web Report in India. This will alert users if their personal information is detected on the dark web, allowing them to safeguard themselves against fraudulent activities.

Users can activate the dark web report option to check if their details are on the dark web. They can also start real-time dark web monitoring to receive ongoing updates on new findings, recommended actions, and assistance.

Dark Web Digest – August 2023: Unveiling the Cyber Shadows

Deep Web Digest - August 2023

The dark web is a part of the internet no one knows about. It’s often used for hacking, drug trafficking, and cybercrime. Each month, innovations and events affect the dark web and its users.

This article summarizes some of the most relevant and interesting dark web stories from July 2023. We’ve seen password logs sold for millions of dollars, DarkBERT GPT-Based Malware, hackers publishing Swiss hooligan data, you name it.

This news should be on your radar if you haven’t heard it yet. It shows how the dark web threatens privacy, security, and well-being, as well as society at large. As well, they talk about how to protect yourself from the dark web’s dangers and raise awareness.

We will provide you with additional details, insights, and sources for each news article. This will enable you to take appropriate safety measures and remain engaged in the future.

  • Over 19 Million Password Logs Sold on the Dark Web and Telegram

A recent discovery has shocked the cybersecurity community as over 19 million password logs were found up for sale on the dark web. This alarming development has raised serious concerns among hackers, security experts, and students alike.

According to MyPowerCloud, the massive password log sale was exposed on both the dark web. This highlights the growing sophistication of cybercriminals in their illicit activities. The dark web continues to be a hotbed for illegal trade. This incident serves as a stark reminder of the ever-present threats lurking in the digital underworld.

dark web and telegram

Compromised passwords come from various sources, including well-known data breaches and hacking incidents, putting countless users at risk. For hackers, this new trove of passwords presents a golden opportunity to exploit unsuspecting victims and wreak havoc on their personal and professional lives.

  • Over 400,000 Businesses Credentials Stolen by Info-Stealing Malware

Over 400,000 credentials were stolen, yes you heard right! It is terrifying to see what is happening on the dark web. Well, the dark web experienced a massive data breach as information-stealing malware infiltrated business environments, targeting valuable data in web browsers, email clients, and more. Some experts pointed out that prominent malware families, such as Redline, Raccoon, Titan, Aurora, and Vidar, are available to cybercriminals via a subscription-based model.

These malware campaigns not only affect careless internet users but also pose a significant risk to corporate environments. Approximately 375,000 logs containing access to critical business applications like Salesforce, Hubspot, Quickbooks, AWS, GCP, Okta, and DocuSign were discovered.

Moreover, over 48,000 logs provided access to “okta.com,” an identity management service widely used by organizations. 

The analysis found more than 200,000 stealer logs containing OpenAI credentials, putting proprietary information and source code at risk.

  • 8 Year Old Boy Orders an AK-47 from the Dark Web

In a shocking turn of events, Dutch expert Barbara Gemen discovered that her 8-year-old son had unknowingly entered the dark web’s perilous world and bought an AK-47. Initially innocent, the young boy’s fascination with computers led to dangerous hacking escapades. 

He started with harmless online orders but soon engaged in illegal money transactions with criminals using code phrases to conceal his activities. 

The situation escalated when he purchased and received a deadly AK-47 gun from Poland to Bulgaria, without raising suspicions. Despite alerting law enforcement, no action was taken, leaving Barbara to take matters into her own hands. She became a Cyber Special for the Dutch police, advocating for online safety for her son and others.

This incident underscores the need for parental awareness and education to safeguard children from the dangerous allure of the dark web. This is especially true as easy access to technology exposes them to cybercrime temptations.

  • DarkBERT GPT-Based Malware Trains Up on the Entire Dark Web

You’ve got a safety tool that turns into a threat! You’re right, it is. 

DarkBART is a dark version of Google’s BART AI. DarkBERT, created by South Korean firm S2W, aims to combat cybercrime but has unfortunately fallen into the wrong hands. It’s rumored that CanadianKingpin12 trained DarkBERT using an extensive corpus of text from the Dark Web. This empowered it to conduct more sophisticated cyberattacks.

darkbert

It is even more alarming that DarkBERT will have access to the entire Dark Web as its knowledge base. This will allow threat actors to tap into the collective intelligence of hackers underground. With Google Lens integration, these chatbots can now handle text accompanied by images, making their capabilities even more formidable.

  • Brazil Tops South America in Dark Web Card Theft

Brazil has become a hotspot for dark web card theft, ranking fifth globally and first in South America. Nord VPN cybersecurity study revealed that over 144,000 Brazilian payment cards have been stolen and traded online. In addition, approximately 92,000 cards are currently available for illegal purchase. These stolen cards are sold for $8.84 each, generating an estimated $18.5 million for cybercriminals.

Even more troubling, two out of three stolen credit cards on the dark web contain additional private information, such as phone numbers, addresses, and Social Security numbers, greatly increasing the risk of identity theft for victims.

The study also showed that the United States has the highest number of credit card fraud cases globally. This accounts for more than half of the 6 million stolen card records analyzed. American credit cards sell for a lower price on the dark web, around $6 per unit. Danish cards are the most valuable, averaging R$12.

In the South American landscape, Brazil reported the highest number of stolen payment cards, followed by Chile with 30,000 stolen cards. The highest risk of credit card theft occurs in countries such as Malta, Australia, and New Zealand, while Brazil ranks 38th. Conversely, Russia is the least risky, and China ranks third from the bottom. This study sheds light on the alarming scale of cybercrime and the need for heightened cybersecurity measures worldwide.

  • OpenAI Credentials Available on the Dark Web

The most concerning news is, security researchers have recently discovered a security weakness on the dark web. The OpenAI credentials of over 200,000 compromised users were found available for purchase on the dark web. This incident has raised alarms in the tech community and among cybersecurity experts.

chatgpt data leak

The compromised data includes sensitive information such as login credentials, access keys, and even source code and business plans. Hackers and cybercriminals are now equipped with powerful tools to exploit vulnerabilities and gain unauthorized access to OpenAI systems.

For hackers and security experts, this development serves as a stark reminder of the ever-present risks in the digital landscape. It underscores the importance of staying vigilant and continuously improving security measures.

  • Swiss Hooligans Data Leaked on the Dark Web by Hackers

In the aftermath of a ransomware attack on IT provider Xplain, sensitive data has surfaced on the dark web. This includes an extract from the HOOGAN information system dating back to 2015. The leaked data contains details of 766 individuals listed in the HOOGAN database, a register of known hooligans. However, crucial information about their offenses and actions is missing.

Fedpol, the Federal Office of Police, acted swiftly to inform the affected individuals and is actively investigating the transmission and storage methods used during the attack. The breach also exposed sensitive government data belonging to the federal police, army, and the Federal Office for Customs and Border Security. Consequently, the Office of the Attorney General and the Federal Data Protection Commissioner have initiated separate investigations.

Fedpol aims to reassure the public that HOOGAN’s database remains secure and operational despite the breach. As per the latest data, the HOOGAN database listed 1,017 hooligans as of June 2023. Of these, 332 individuals face ongoing measures such as exclusion orders, stadium bans, and reporting obligations. The data relating to police measures will be retained for three years following their conclusion.

  • A dark web AI tool called “FraudGPT” facilitates cybercrime

A new AI tool following in the footsteps of ChaosGPT and WormGPT. This tool is now making its presence felt on the dark web and Telegram, catering to cybercriminal activities and raising serious concerns.

FraudGPT is being sold on Dark Web Forums and Telegram for prices ranging from $200 to $1700 per year.

The Chat GPT Fraud Bot offers unrestricted exclusive tools and features for users. FraudGPT has limitless potential, and the promoter claims that users can use it to perform any desired tasks. So far, FraudGPT has been confirmed to have sold over 3000 copies.

FraudGPT is a colossal risk because it can make believable fake websites and write harmful code. Taking advantage of this all-in-one solution, scammers can appear more believable, so they can cause greater damage on a larger scale. 

In addition to WormGPT, another AI cybercrime tool has been discovered on Dark Web forums. As a blackhat alternative to GPT models that is specifically tailored for malicious activities such as phishing and business email compromise, WormGPT is marketed as a tool for phishing and business email compromise.

  • Dark web investigation leads to charges against Perth man

A 49-year-old man from Marangaroo, Western Australia, is facing serious charges related to online child abuse. The WA JACET charged him on July 3, 2023, for his dark web activities, which were reported by the ACCCE.

The police found 17 videos of child abuse on his computer in June. The man allegedly visited multiple dark websites to access such content and used various tactics to avoid detection.

Detective Hinscliff condemned viewing child abuse material and warned online offenders that law enforcement would pursue them relentlessly, even if they use the dark web or anonymizing technologies.

The charges brought against the man include possessing and accessing child abuse material, both of which are violations of the Criminal Code 1995 (Cth). If convicted, he could face up to 15 years in prison.

The partners of the Australian Federal Police and the police themselves are determined to fight against child abuse and exploitation. The ACCCE’s role is to make the digital world safer by tackling online child sexual exploitation.

  • Man Jailed for Importing Explosives After Dark Web Plot

Finally, in dark web august digest, we got a shocking case that has come to light involving a 36-year-old Żebbug resident, Jomic Calleja Maatouk, who was sentenced to five years in prison for his involvement in a dark web plot to illegally import explosives from the United States. 

The court deemed Calleja a “lethal weapon,” capable of inflicting “chaos and destruction.”

Jomic Calleja Maatouk’s dark web plot involved seeking lethal poisons, but when unsuccessful, he turned to explosives. Foreign security services alerted investigators about his attempts to get deadly chemicals. The poisons seemed to target a specific person, and he aimed to buy “five doses” but was advised to start with one. Investigators also found an order for C-4 explosives. Maltese investigators executed a controlled delivery operation to stop the threat. Facing many charges, Calleja pleaded not guilty, but the court considered his criminal record. Magistrate Donatella Frendo Dimech emphasized the need to protect society, resulting in a five-year prison sentence for rehabilitation and public safety.

The court ordered the forfeiture of €51,000 in bail bonds, revoked Calleja’s bail, and issued an immediate re-arrest. Additionally, he was required to cover €2,827.08 in court expert expenses.

This case serves as a stark reminder of the potential threats lurking on the dark web and the importance of vigilant law enforcement efforts to protect the public from harm.

Dark Web Digest July 2023 Edition – Unveiling the Latest Insights and Events

Deep Web Digest - July 2023

The dark web remains a mysterious realm shrouded in secrecy and intrigue. It is an enigmatic corner of the internet where anonymity reigns supreme, allowing users to navigate hidden networks and engage in activities beyond the reach of conventional search engines. 

In this edition of Dark Web Digest, we embark on a journey to uncover the latest insights and events unfolding during July 2023. We peel back the layers of this clandestine world to shed light on emerging trends, noteworthy incidents, and the pulse of the dark web community. 

Dark Web Digest July 2023

The Dark Web Digest July 2023 Edition is a comprehensive and expertly curated guide that provides valuable insights and information about the dark web. 

This edition serves as an essential resource for individuals seeking to understand the workings of the dark web, its hidden markets, and the potential security risks associated with this clandestine realm.

dark web 2023

The Dark Web Digest July 2023 Edition goes beyond the surface-level information commonly found elsewhere. We aim to deliver personalized content that humanizes the dark web experience, enabling readers to grasp the significance and implications of the latest developments. Our conversational tone, devoid of slang or fluffy language, ensures clarity and makes the content easily accessible to readers of all backgrounds.

Let’s talk about some happening from the dark web in 2023!

Millions of U.K. University Credentials Found on Dark Web

The dark web has once again raised concerns in the realm of cybersecurity as security researchers recently uncovered a staggering 2.2 million compromised credentials linked to the top 100 universities in the U.K. This alarming discovery poses a significant risk to the faculty, students and their valuable data.

Trillion, Crossword Cybersecurity’s risk monitoring service, was responsible for unearthing these compromised credentials. Interestingly, more than half of these compromised accounts (54%) were associated with prestigious Russell Group institutions known for their excellence in education and research.

It is worth noting that the U.K. boasted nearly 2.2 million students enrolled in higher education institutions during the 2021/22 academic year, including approximately 680,000 international students. Additionally, there were an estimated 234,000 staff members. While the scale of this breach is substantial, it remains unclear how many affected individuals are still affiliated with the universities.

The implications of this breach extend beyond the compromised accounts themselves. Crossword Cybersecurity has emphasized the potential risk to sensitive research projects. If threat actors gain access to user accounts with compromised credentials, they could jeopardize ongoing research initiatives. This is particularly concerning for universities involved in government-funded programs in critical areas such as nuclear energy and defence.

Stuart Jubb, the Managing Director of Crossword Cybersecurity, underscored the importance of safeguarding universities and their valuable reputation. He stressed that effective cybersecurity practices are essential for protecting the students and staff and the information shared with them for research purposes by both the public and private sectors. Given universities’ unique challenges, where secrecy and openness intersect, a multi-faceted approach to cybersecurity is crucial. Jubb emphasized the need for proactive monitoring of stolen credentials and implementing multi-factor authentication across all organizations, not just within the education sector.

While the primary motive behind targeting university credentials may be to gain unauthorized access to unpublished research, the potential consequences are more far-reaching. Threat actors may also aim to acquire sensitive personally identifiable information (PII) from students and staff. Furthermore, phishing attempts and identity fraud could be on the horizon.

The research report highlighted an interesting trend: the top 30 universities in the country are up to 50% more likely to have compromised credentials than other institutions within the top 100. Additionally, it revealed that universities in London had experienced more breached logins (506,330) than those in Scotland, Wales, and Northern Ireland combined (465,767).

Man Jailed For Importing Explosives after Dark Web Plot to Obtain Deadly Poisons


Jomic Calleja Maatouk, a 36-year-old resident of Żebbug, has been sentenced to five years in prison and ordered to forfeit €51,000 in bail bonds. The court described Calleja as a “lethal weapon” capable of causing “chaos and destruction.” 

The judgement was delivered after Calleja faced criminal charges for conspiring to import explosives illegally from the United States. Disturbing messages retrieved by investigators revealed Calleja’s plan to purchase lethal substances from the dark web, including polonium 210, ricin, and fentanyl. When his attempt to acquire these poisons failed, he turned to explosives. 

Foreign security services alerted investigators, leading them to Calleja. Chat conversations between Calleja and the seller indicated his interest in acquiring poisons for a specific target. Ultimately, Calleja was found guilty of multiple charges and pleaded not guilty. 

The court considered the seriousness of the crimes, his criminal record, and the need to protect society. The five-year prison sentence aims to rehabilitate Calleja while ensuring public safety. His previous bail bonds were forfeited, and he was re-arrested. Inspector Omar Zammit acted as the prosecutor, while Benjamin Valenzia represented the defence.

“Triangulation Trojan” Launches Sophisticated Attack on Apple Devices

Security experts recently uncovered a highly advanced and targeted cyberattack called “Triangulation” that targets Apple’s mobile devices. This attack aims to infiltrate the iPhones of employees, particularly those in middle and top management positions within certain companies.

The attack method involves sending an invisible iMessage with a malicious attachment. By exploiting multiple vulnerabilities in the iOS operating system, the attachment can execute on the device without any action required from the user. Once installed, the spyware operates covertly, secretly transmitting sensitive data back to remote servers. This includes recordings from the device’s microphone, photos from instant messaging apps, geolocation information, and other user activity data.

Detecting and removing this spyware is a complex task due to the unique characteristics of iOS. One clear indicator of the Triangulation attack is the disabling of iOS updates on the infected device. 

Creating a backup of the device and analyzing it using a specialized utility tool is recommended to confirm an infection. Kaspersky is also developing a free detection tool to aid in identifying this spyware.

Unfortunately, there is no practical method to remove Triangulation without losing user data, as the spyware blocks iOS updates. 

The only viable solution is to reset the infected iPhones to factory settings and reinstall the latest version of the operating system along with all user data. This step is crucial to prevent re-infection through outdated iOS versions.

The sophisticated nature of this attack allowed it to remain undetected until anomalies within the network originating from Apple devices were identified by Kaspersky’s Unified Monitoring and Analysis Platform (KUMA), a specialized Security Information and Event Management (SIEM) solution. Further investigations revealed that the spyware had compromised several iPhones belonging to senior employees.

Kaspersky continues investigating this incident and plans to provide additional information in a dedicated post on Securelist. They expect to uncover more details about the widespread impact of this spyware in the coming days. 

It is important to note that while Kaspersky was targeted in this attack, they were not the primary objective. They assure users that this incident leaves their business processes and data unaffected.

‘Sensitive’ Australian Government Documents Leaked on the Dark Web

A highly advanced cyberattack named “Triangulation” has been uncovered by security experts. This targeted attack specifically aims at infiltrating Apple mobile devices, particularly those used by employees in middle and top management positions within specific companies. The attack involves sending an invisible iMessage with a malicious attachment, exploiting multiple vulnerabilities in the iOS operating system. 

Once installed, the spyware operates covertly, collecting and transmitting sensitive data back to remote servers without user consent. Detecting and removing this spyware is challenging, as it turns off iOS updates on infected devices. Experts recommend creating a backup and using specialized utility tools to confirm an infection. 

Kaspersky is developing a free detection tool for this purpose. Unfortunately, there is currently no effective method to remove Triangulation without losing user data. Resetting infected iPhones to factory settings and reinstalling the latest iOS version is the only solution. 

The attack was discovered through anomalies identified by Kaspersky’s Unified Monitoring and Analysis Platform. Investigations revealed compromised iPhones belonging to senior employees. Kaspersky is actively investigating the incident and plans to share more details soon. While Kaspersky was targeted, its business processes and data remain unaffected. 

In another incident, a cybersecurity hack on law firm HWL Ebsworth has impacted at least 60 government agencies, including the Defence Department and Home Affairs. The agency responsible for the national disability insurance scheme also assesses the potential exposure of sensitive client information. 

The affected entities are notifying individuals and fulfilling their obligations under the Privacy Act 1988. The cybercriminal group Blackcat, one of Australia’s top three ransomware groups, has consistently targeted large organizations.

Clop Hackers Begin Posting Company Names on Dark Web

Clop, a cybercrime gang believed to be based in Russia, has recently escalated its activities on the dark web. They have posted company profiles of multiple businesses from which they claim to have stolen data. 

This move comes after Clop issued a warning, threatening to release staff members’ sensitive information and personal details if negotiations were not initiated. British Airways, Boots, and the BBC were among the companies affected, as their payroll provider, Zellis, experienced a breach. 

The situation has intensified further, with over 26 organizations, including universities and banks, having their company profiles published on Clop’s leak site. This tactic aims to increase the pressure on companies to pay ransoms.

Clop managed to infiltrate MOVEit, a widely used business software, allowing them to target numerous companies and institutions worldwide. 

While the U.S. Cybersecurity and Infrastructure Security Agency (Cisa) confirmed that only data stored on MOVEit had been stolen, there were no ongoing incursions into other parts of the national network. However, it was reported that a contractor at a U.S. national laboratory and a radioactive waste storage site under the U.S. Department of Energy (DoE) management were among the victims.

The list of potential victims continues to grow. Shell, the government of Nova Scotia, U.K. regulator Ofcom, the Minnesota Department of Education, and Landal GreenParks, a Dutch campsite and recreation company, are now added to the roster. In the U.K., Adare SEC, a communications firm that handles digital and printed communications for various businesses, confirmed that it was impacted by the MOVEit hack and that data had been stolen. 

The situation serves as a reminder of the increasing threats posed by cybercriminals on the dark web and highlights the critical need for organizations to bolster their cybersecurity defences.

Man Charged with Running $18 Million ‘Monopoly’ Darknet Marketplace

The extradition of the suspected administrator of the Monopoly Market darknet marketplace has been completed, marking a significant development in the ongoing battle against illegal activities on the dark web. Milomir Desnica, a citizen of Serbia and Croatia, was extradited from Austria to the United States to face charges related to running the illicit marketplace. This comes after his arrest in Vienna last November and the subsequent seizure of Monopoly Market’s servers in December 2021.

dark web monopoly

The U.S. Department of Justice (DOJ) has accused Desnica of facilitating around $18 million in illegal drug transactions using cryptocurrencies through the Monopoly Market platform. The marketplace operated on the dark web, offering a platform for the trade of illicit substances. The charges against Desnica include conspiracy to possess and distribute methamphetamine and conspiracy to launder monetary instruments. The indictment seeks the confiscation of any criminal proceeds.

The extradition of Desnica follows an extensive international operation conducted by Europol in collaboration with law enforcement agencies from various countries. This operation resulted in the arrest of 288 individuals and the seizure of significant amounts of cash, crypto assets, drugs, and weapons, amounting to over $53 million.

During the investigation, authorities discovered incriminating evidence on the Monopoly servers, including records of narcotics sales, financial transactions involving cryptocurrencies, and communications with vendors. This evidence played a crucial role in identifying Desnica as the operator of the darknet marketplace.

The DOJ has revealed that Desnica allegedly utilized multiple cryptocurrency exchanges between April 2020 and July 2022 to convert the proceeds from the drug sales. By moving the digital assets between blockchains and eventually selling them to peer-to-peer traders in Serbia in exchange for fiat currency, Desnica is accused of attempting to launder the illicit funds.

If convicted, Desnica faces severe penalties. The drug distribution charge carries a maximum sentence of life imprisonment, while the conspiracy to commit a money laundering charge can result in a maximum term of 20 years behind bars. Additionally, the charges may also lead to substantial financial penalties.

The takedown of Monopoly Market and other darknet marketplaces has been a significant focus for law enforcement agencies worldwide. Just a few months before Desnica’s extradition, German authorities shut down Hydra, one of the largest darknet markets at the time, primarily catering to Russian-speaking users. These operations demonstrate the commitment of international law enforcement to combat illegal activities on the dark web and protect public safety.

The case against Milomir Desnica serves as a reminder that illegal marketplaces on the dark web are not beyond the reach of law enforcement. It also emphasizes the increasing sophistication of investigations targeting individuals involved in such criminal enterprises. As efforts to dismantle these illicit platforms continue, the fight against cybercrime and illegal activities on the dark web remains a top priority for security experts and law enforcement agencies worldwide.

Conclusion

The Dark Web Digest July 2023 Edition has provided a comprehensive overview of the latest happenings in the dark web, shedding light on the activities and risks associated with this hidden realm. As a security expert, it is evident that the dark web is a hotbed for illicit activities, from the trade of illegal substances to cybercrime and data breaches.

Throughout this edition, we have explored various incidents highlighting the dangers and consequences of engaging with the dark web.

As the dark web continues to evolve, law enforcement agencies and security experts remain vigilant in their efforts to disrupt and dismantle illegal activities. Collaboration, international cooperation, and advanced technologies are vital in addressing these challenges.

In conclusion, the Dark Web Digest July 2023 Edition has provided valuable insights into the dark web’s underbelly. Individuals, organizations, and policymakers need to stay informed about the latest developments and adopt proactive measures to protect themselves from the threats lurking within the depths of the internet. By arming ourselves with knowledge and maintaining a solid security posture, we can confidently navigate the digital landscape and contribute to a safer and more secure online environment.