Dark Web Digest – February 2024 Edition

Dark Web Digest - February 2024

Welcome to the Dark Web Digest, a monthly blog that brings you the latest news and trends from the dark web. The dark web is a hidden part of the internet that most people never see. It is where you can find illegal, dangerous, or controversial things. Some people use the dark web for good reasons, such as protecting their privacy or escaping restrictions. Others use it for bad reasons, such as buying drugs, weapons, or stolen data. But that is now just used to define the dark web, and there is much more to know!

In this February edition will explore some of the most exciting and essential stories from the dark web in January 2024. Remember, the dark web is not a place for the timid, so browse carefully and stay safe.

Fake X Gold Accounts For Sale On The Dark Web

The very first piece of news is the theft of X Gold accounts. A surge of fake or stolen X (Twitter) Gold accounts has been flooding marketplaces and forums on both the surface web and the dark web over the past year, according to a report by CloudSEK. Threat actors have used multiple techniques to forge or steal X Gold accounts since Elon Musk’s firm introduced its new verified accounts program in December 2022. The report identified the first advertisement for a Gold account on dark web marketplaces in March 2023. Cybercriminals selling these accounts use several methods to acquire them, including manually creating fake accounts, brute-forcing existing accounts, and using malware to harvest credentials and steal accounts. Prices for counterfeit or stolen accounts range from around $0.30 for a new X account without a checkmark to about $500 for a Gold account. CloudSEK recommends organizations close dormant accounts and has an alerting system to warn of stolen corporate social media account credentials and password protection practices. Employees should be trained on workplace cybersecurity practices, updated password policies, and educated against using cracked software and its dangers.

3,000 Dark Web Posts Found Misuse of ChatGPT and LLMs

Kaspersky’s Digital Footprint Intelligence service discovered nearly 3,000 dark web posts 2023 discussing illegal activities involving ChatGPT and other large language models (LLMs). These discussions included creating malicious alternatives, jailbreaking techniques, lists of malicious prompts, and discussions on stolen accounts with access to the paid version of ChatGPT. Threat actors on the dark web actively share knowledge on exploiting ChatGPT, discussing topics like creating malware, using artificial intelligence for processing user data dumps, and sharing jailbreaks to bypass content moderation policies. The research also found a high volume of conversations around tools like WormGPT, XXXGPT, and FraudGPT, which were marketed as alternatives to ChatGPT with fewer restrictions. The research comes just after OpenAI suspended a developer for creating a chatbot that mimicked U.S. Congressman Dean Philips. This act, the organization says, violated its rules on political campaigning or impersonating individuals without consent. The research highlights that ChatGPT can be used for misuse and that cyber criminals actively share knowledge on exploiting it.

Indian Pleads is guilty of running a Dark Web Enterprise and Losing $150 Million

Indian national Banmeet Singh has pleaded guilty to operating a global dark web enterprise to sell dangerous drugs to communities across America. He created vendor marketing sites on dark web marketplaces to sell controlled substances, including fentanyl, LSD, ecstasy, Xanax, Ketamine, and Tramadol. Singh personally shipped or arranged the shipment of drugs from Europe to America through U.S. mail or other shipping services. From mid-2012 through July 2017, Singh controlled at least eight distribution cells within the U.S., moving hundreds of kilograms of controlled substances throughout the U.S. The multimillion-dollar drug enterprise laundered millions of dollars of drug proceeds into cryptocurrency accounts, which ultimately became worth approximately USD 150 million. Singh faces an agreed-upon sentence of eight years in prison.

750 Million Indian Info For Sale On The Dark Web

Indian infosec firm CloudSEK has discovered records of 750 million Indian mobile network subscribers on the dark web, with two crime gangs offering the data for just $3,000. The 1.8TB trove contains mobile subscribers’ names, phone numbers, addresses, and Aadhaar details. CloudSEK claims threat actors obtained the data through undisclosed asset work within law enforcement channels rather than a leak from Indian telcos. The leak poses a considerable risk to individuals and organizations, potentially leading to financial losses, identity theft, reputational damage, and increased susceptibility to cyber-attacks.

Singapore-based crypto outfit Terraform Labs (TFL) filed for Chapter 11 bankruptcy in the United States, calling the move “a strategic, protective step” to continue executing its business plan while resolving outstanding legal proceedings. The company has assets and liabilities from $100 to $500 million.

India’s I.T. minister, Rajeev Chandrasekhar, has proposed a $1.2 million supercomputing and quantum computing hub, offering high-performance computing access to startups and micro, small, and medium enterprises. The public-private scheme will include graphic processing units in PPP mode with data centers in private space and public data centers under C-DAC (Centre for Development of Advanced Computing). Telstra International and Trans-Pacific Networks (TPN) have announced a partnership on the Echo undersea cable, connecting the U.S. directly to Singapore, Indonesia, and Guam.

African Bank Data Breach Claims of Customer Data on Sale

A dark web user, cnHunter, has claimed to have sold 1843 customer records of the African Bank, which are now up for $250. The data breach includes sensitive details such as customer names, account numbers, phone numbers, serial numbers, and bank account types. The threat actor claims to have complete access to the bank’s database, allowing potential buyers to view, add, edit, and delete information related to guarantor lists, customer lists, and new and old forms. The Cyber Express has sought more information from the affected organization, but no official statement or response has been received, leaving the claims unverified. 

The African Bank website appears to be operational, adding to the uncertainty surrounding the authenticity of the reported breach. The European Central Bank (ECB) is set to conduct a cyber resilience stress test on 109 directly supervised banks in 2024, focusing on recovery measures rather than just preventive capabilities. The test will involve 28 banks undergoing an enhanced assessment, providing additional information on how they dealt with the simulated cyberattack.

Child Sex Offender Admits Being A Moderator Of Dark Web Abuse Site

A man from Swindon, Brent Saunders, has pleaded guilty to being a ‘Global Moderator’ on a dark website dedicated to sharing child sexual abuse content. The National Crime Agency (NCA) discovered that the site had over 2,000 members and was only accessible using Tor. The moderator, Wetty’, was heavily involved in running the site, providing advice on personal security, and evading law enforcement detection. Saunders was identified as the man behind the account and had previous convictions relating to the sexual exploitation of children.

In August 2022, NCA officers arrested Saunders at his home in Freshbrook. He confirmed that he held the rank of Global Moderator and had uploaded indecent images of children to the site. He also admitted his sexual interest in children, particularly girls aged 8-12. Investigators recovered data relating to his account, including over 3,000 posts and private messages he sent to other users.

Wiltshire Police charged Saunders with breaching the sexual harm prevention order and sentenced them to two years and eight months in prison for the breach. Last year, he was charged with a further nine counts, including arranging/facilitating the sexual exploitation of a child under 13, participating in the criminal activities of an organized crime group, distributing and making indecent images of children in categories A-C, and possessing a prohibited image of a child.

Wirex And Zerofox New Strategies Against Dark Web Activities

UK-based digital payment platform Wirex has integrated ZeroFox’s Dark Web Monitoring tool into its system to combat Dark Web activities and money mule threats. The integration allows for real-time dark web scanning for potential dangers like leaked data and compromised credentials. Wirex aims to benefit from ZeroFox’s advanced monitoring capabilities, which issue detailed alerts about potential threats, ensuring a quick response to incidents. The integrated system identifies and responds to suspicious account activities, reducing the risk of financial fraud and reinforcing user transactions. Wirex is also committed to compliance with Know-Your-Customer (KYC) regulations and has partnered with banks and financial institutions to provide online security tools and expand its suite of services. The company also offers educational content and partnerships to empower users about security and responsible financial practices.

Father and Son Duo Sentenced in Dark Web Bitcoin Case

The last news we got in this digest is about father Joseph Farace and his son, Ryan Farace, who have been sentenced to federal prison for operating an illegal dark web drug business and a Bitcoin laundering scheme. Ryan earned over 9,138 Bitcoins through drug sales from 2013 to 2017. In 2020, he arranged to transfer 2,874 BTC to an overseas account, leading to the seizure of 2,957.9 BTC. The cases highlight concerns over cryptocurrency use in money laundering.

Conclusion

That concludes our January edition of the dark web digest. We hope you found it informative and insightful. The dark web is constantly evolving and dynamic, with new daily developments and challenges. We will return next month with more stories and tips from the dark web. Until then, stay safe and keep in touch.

Dark Web Digest – January 2024 Edition

dark web digest - January 2024

As we all know, the dark web is a mysterious part of the internet world, often attracting controversy, illegal activities and curiosities. It can be accessed by a TOR browser that runs against legal terms and goes against law enforcement and government oversight. In simple terms, it is home to several illegal and illicit activities, including drug trafficking, hacking and cybercrime, yet also to some legitimate and useful purposes such as activism, privacy protection and journalism. 

In the previous editing, we discussed some shocking news and this month, nothing different. In this dark web digest edition of January 2024, we will see some latest trends, news and developments related to the dark web. 

Let’s get started.

Cyber Attack Exposes Yakult Australia Employee Files on Dark Web

Yakult Australia, a popular probiotic company, has been targeted by a ransomware attack that has exposed its company records and sensitive employee documents, including passports, on the dark web. The company, based in Melbourne, is working with cyber incident experts to investigate the extent of the incident. All offices in Australia and New Zealand remain open and continue to operate. The group responsible for the breach is DragonForce, which has listed nearly two dozen targets that have refused to cooperate since the beginning of December. The targets range from a Texas-based family charity to commercial entities like Coca-Cola in Singapore and a South Australian-based bathroom manufacturer.

A sample of the 95 gigabytes of data leaked by ABC Investigations found company records dating back to 2001, including scans of passports and driver’s licenses, pre-employment medical assessments and certificates, salaries, and performance reviews. At least one of the passport scans belongs to a warehouse employee. In the leaked cache, the ABC has also seen Japanese passports, where Yakult’s parent company is based. A separate database also contains the names and addresses of nearly 9,000 people. It is unclear if these are customer records, but ABC has verified the accuracy of some of the names and addresses.

Yakult Australia became aware of the cyber attack on December 15, and DragonForce listed the probiotic company as one of its victims before publishing the stolen cache on Christmas Day morning. ABC Investigations has not independently verified each of DragonForce’s published leaks.

Dark Web Ads Target Booking.com Partners, Affecting Customer Security

Booking.com has been targeted by scammers for years, with hackers now posting ads on dark web forums to obtain the passwords of hotel partners. The scammers gain access to a hotel’s extranet, install malware, access passwords, and mimic IP addresses to bypass two-factor authorisation. They use the hotel partners’ login credentials to enter their Booking.com accounts and send urgent messages to customers urging them to send money to the scammers or risk losing their reservations. Booking.com acknowledges that the hackers are not gaining access to Booking.com’s backend systems but acknowledges that the scammers have broken into hotel partners’ accounts. 

The hackers then communicate with Booking.com customers/hotel guests, urging them to send money to the fraudsters. The hackers then message customers from the official app and can trick people into paying money to them instead of the hotel. Booking.com has been unable to make the problem disappear, and the company has been working diligently to support its partners in securing their systems and helping potential customers recover lost funds. The company has been publishing best practices for avoiding these scams and is working to help customers recoup lost funds.

German Authorities Dismantle Global Dark Web Hub ‘Kingdom Market’

German law enforcement has disrupted the dark web platform called Kingdom Market, which specializes in selling narcotics and malware to thousands of users. The operation, which involved collaboration from the U.S., Switzerland, Moldova, and Ukraine authorities, began on December 16, 2023. Kingdom Market has been accessible over the TOR and Invisible Internet Project (I2P) anonymisation networks since March 2021, trafficking illegal narcotics, advertising malware, criminal services, and forged documents. As many as 42,000 products were sold via several hundred seller accounts on the platform before its takedown, with 3,600 originating from Germany. Transactions were facilitated through cryptocurrency payments, with the website operators receiving a 3% commission for processing the sales of illicit goods. The operators of ‘Kingdom Market’ are suspected of commercially operating a criminal trading platform and of illicit trafficking in narcotics. In addition, one person connected to the running of Kingdom Market has been charged in the U.S. with identity theft and money laundering.

GTA 5 Source Code Leaked Online One Year After Rockstar Hack

The source code for Grand Theft Auto 5 was leaked on Christmas Eve, a year after the Lapsus$ hacking group hacked Rockstar Games and stole corporate data. The hackers claimed to have stolen the GTA 5 and GTA 6 source code and assets, including a GTA 6 testing build. They also shared GTA 5 source code samples as proof of their theft.

Security research group vx-underground spoke to the leaker on Discord, who said the source code was leaked sooner than expected. They claimed to have received the source code in August 2023, motivated by combating scamming in the GTA V modding scene. BleepingComputer reviewed the leak, which appears to be legitimate GTA 5 source code, but could not independently verify its authenticity.

The Lapsus$ hackers are known for their skills in performing social engineering and SIM-swapping attacks to breach corporate networks. They have hacked companies such as Uber, Microsoft, Rockstar Games, Okta, Nvidia, Mercado Libre, T-Mobile, Ubisoft, Vodafone, and Samsung. Their success led the Department of Homeland Security (DHS) Cyber Safety Review Board to analyze their tactics and share recommendations for preventing similar attacks in the future.

While the Lapsus$ group has not been very active since members were arrested, some members are now believed to be active in the loose-knit hacking collective known as Scattered Spider. Scattered Spider shares similar tactics to Lapsus$, utilizing social engineering, phishing, MFA fatigue, and SIM-swapping attacks to gain initial network access to large organizations.

Health Data Breach Sparks Extortion Threats

A cyberattack on Integris Health, Oklahoma’s largest not-for-profit health network, compromised the personal information of two million patients. The breach was confirmed on November 28, 2023, and extortion emails were sent to patients threatening to sell their stolen data to other threat actors. The emails contained links to a dark web page where stolen data, including names, Social Security numbers, dates of birth, and hospital visits, was listed for about 4,674,000 people. The hackers who claimed responsibility for the cyberattack began sending the extortion emails on December 24. The emails claim to include dates of birth, Social Security numbers, addresses, phone numbers, insurance information, and employment details. The hackers threaten to sell the stolen data of those who do not pay the $50 deletion fee by January 5, 2024.

The cyberattack on Integris Health is similar to those used in the attack on Fred Hutchinson Cancer Center, where patients were subjected to similar extortion emails. Integris Health advised patients not to reply to the hackers or follow any instructions found in the extortion emails. A PDF containing frequently asked questions about the incident can be found at the bottom of the page. Affected patients are advised to stay alert and take necessary safety measures to reduce risks related to the compromised data.

Enhancing Cyber Security in Greece Amidst Frequent Attacks

The recent cyber-attacks targeting public bodies in Greece have highlighted a weakness in security, which the government of Prime Minister Kyriakos Mitsotakis plans to address with new legislation to create a National Cybersecurity Authority. The bill is about to be submitted for public consultation. Criminal groups prefer certain infrastructures in public sector services in Greece, possibly due to unpreparedness or laxity in taking protection measures.

According to CheckPoint Research, the number of cyber-attacks globally jumped 38% between 2021 and 2022. In the last six months, the top six targets in Greece were healthcare, retail/wholesale, finance/banking, manufacturing, and transportation. HPPC suffered a DDoS attack on November 8 but said it had not detected any data breaches; hacker group Ragnar Locker took responsibility for the attack on DESFA in August last year and posted 361 gigabytes of DESFA data on the dark web; the Greek postal service announced it had been hit in December 2022, nine months after the actual attack.

An organized security system is crucial, as achieving security is a long-term effort and not only a technical problem. A major problem is that when an organization is attacked, it does not provide all the necessary information in time. The Hellenic Data Protection Authority (DPA) has not issued any fines for personal data breaches following cyber-attacks.

Greece’s left-wing opposition party SYRIZA has accused the government of “inaction on the critical issue of cyber-security,” but Mavridis said cybercriminals are always ahead of everyone else. The point is not to be too far behind, as criminals constantly develop new ideas and attacks.

Currently, the fight against cyber-attacks in Greece is the responsibility of several different organizations. The military’s Cyber Defence Directorate protects the internet infrastructure of the Greek armed forces, the Cyber Security Operations Centre of the intelligence services protects the state’s digital infrastructure, and the police’s Cyber Crime Division handles online crime.

The legal framework, though complex, looks sufficient to prevent and fight cyber-attacks. However, the reality lags, with low awareness and education levels and no serious investment by companies in protecting their systems and compliance with the requirements of the existing legal framework. Greek experts suggest that the best way to deal with cyber-attacks is through prevention, detection, reaction, and sharing of information, as well as specialized cyber security personnel and heightened security awareness.

Vitoratos called for a strong National Cybersecurity Authority that can monitor the implementation of Greece’s National Cybersecurity Strategy and the compliance of actors while also being transparent and open with the public and civil society.

Rising Dark Web Sales of Stolen Data Prompt Cybersecurity Warning

CyberSecurity Malaysia has warned of a significant rise in data breach incidents from January to November this year, with stolen data being sold on the dark web. The increase includes Personally Identifiable Information (PII), including full names, permanent addresses, household income, identification numbers, email addresses, or phone numbers of victims. 

CyberSecurity Malaysia emphasizes the importance of protecting personal and sensitive data, as it safeguards privacy, individuals, and business reputation. The company also urges organizations to be responsible for preventing such incidents and handling data exposure incidents appropriately.

Individual Selling Fentanyl Online Receives Life Sentence for 29 Overdose Deaths, Including 2 in Oregon

A Pennsylvania man, Henry Konah Koffie, was sentenced to life in federal prison for selling fentanyl online, which prosecutors say caused the overdose deaths of at least 29 people. Koffie, 38, sold a synthetic drug called furanyl fentanyl, a synthetic drug with no medical use. Between September 2015 and his arrest outside Philadelphia in July 2017, Koffie made 7,849 separate transactions, selling the drug in all 50 states. In Oregon, law enforcement linked Koffie to three overdoses, two of which ended in death. In March, a jury in Portland convicted Koffie on several felonies, including two counts of distribution of a controlled substance resulting in the death of an adult.

Koffie received fentanyl in the mail from suppliers in China, then advertised on AlphaBay, a former dark web site, and shipped the drugs through the mail to customers across the country. Investigators linked Koffie’s sales with overdose deaths in at least 15 states, including Idaho, Texas, Florida, Hawaii, California, New York, Minnesota, and Ohio. Scott Kerin, an assistant U.S. Attorney who prosecuted the case, called the drug Koffie was selling poison.

Koffie’s defense attorney asked Mosman not to sentence him to life in prison, stating that life is redeemable. Mosman acknowledged that it is a rare case that warrants a life sentence, as the callousness and cruelty with which a defendant commits a crime that kills others merits the highest sentence.