Dark Web Digest – July 2024 Edition

Dark Web Digest - July 2024

This month’s digest brings some exciting and shocking news. There are very serious incidents happened in dark web last month. From MPS leaked data to Department of justice leak data warned everyone that they should take safety measure at all cost. As we already know some way how to stay safe against malware and dark web attacks. However, this becomes more and more dangerous! 

Below are some shocking news we have seen last month in world of dark web. These insights and vulnerability in these incident are really supportive to stay alert from dark web attacks. 

Majority of UK MPs have had their data leaked to the dark web

British politicians have had their data leaked to the dark web, with over two-thirds of them exposed. Out of 650 MPs, 443 have had personal data exposed on the dark web, mostly from third-party services they have signed up to via their parliamentary email addresses. 

This is compared to just 44% of EU MEPs. French deputies and senators had the best security, with only 18% of searched emails appearing in hacker exchanges. 

UK Parliament Cover

The data shows that politicians used their official email addresses to set up accounts on third-party websites, putting themselves and their information at risk. 216 plain text passwords associated with MPs’ accounts were exposed on the dark web, with parliamentary emails being the biggest piece of data involved. Cybercriminals often use the tactic of ‘credential stuffing’ to enter stolen passwords and emails into different platforms to gain access to different accounts. Some social media profiles were also affected, with 16 breaches of Instagram, 117 of LinkedIn, 21 of X, and 21 of Facebook.

Los Angeles schools investigating claims of data for sale on dark web

LAUSD is investigating a claim that certain district records are for sale online, stemming from a threat actor’s post on BreachForums offering to sell about 24 million records belonging to LAUSD for $1,000. 

The LAUSD spokesperson stated that they prioritize the privacy of students, families, and employees. The latest claims on compromised district data have yet to be verified by LAUSD. Kaustubh Medhe, vice president of research and threat intelligence at threat-intel firm, Cyble, said that the records appear to have personal identifiable information, including student IDs, names, dates of birth, English proficiency status, special education status, home addresses, phone numbers, and parents’ names. 

The information can lead to privacy concerns, but the fact that it’s only being sold for $1,000 indicates it lacks sensitive account-level information, making it less valuable for fraud but still significant for secondary attacks like phishing. A new ransomware group called Rhysida has emerged and strongly resembles Vice Society, suggesting that Satanic may be trying to monetize old data posted by the Vice Society group in 2022.

Google is making its dark web monitoring tool 

Google is integrating its dark web report feature into the ‘results about you’ section of the Google app this summer. 

Previously only available to Google One subscribers, the feature will now be available to all Google account holders. The dark web monitoring tool, which was previously exclusive to paying Google One customers, will provide detailed analysis of leaked personal data. 

Google Dark Web Monitoring Tool

The new integration aims to enhance security by making dark web monitoring available to a broader audience. The dark web monitoring will become part of a combined solution with ‘Results about you,’ a feature that helps users find and request the removal of personal contact information from search results. 

This expansion comes after Google ended support for its Google One-destined VPN tool due to lack of use by customers. Google aims to focus on more frequently used tools.

Police to probe reported fingerprint data sales on dark web

The Indonesian National Police are investigating reports that data from its Automatic Fingerprint Identification System (Inafis) was being sold on the dark web after a massive national database breach that temporarily crippled public services. 

The National Cyber and Crypto Agency (BSSN) revealed that a new variant of ransomware was used in the cyberattack on two temporary National Data Center (PDN) facilities, which affected databases managed by over 200 central and regional institutions. 

The cyberattack occurred around the same time that the BSSN discovered that data allegedly stolen from the police’s Inafis was being offered for sale on the dark web. The government is still trying to restore public services affected by the ransomware attack, although some services have been restored and are running normally, such as the Immigration Office under the Law and Human Rights Ministry.

Dark Web Sees 230% Rise in Singapore Identity Theft

Singaporean security researchers have found a 230% increase in dark web activity involving stolen identity information from citizens. Cybercriminals are selling these stolen documents, which can be used for fraud, identity theft, impersonation scams, and bypass Know Your Customer (KYC) protocols. In April 2024, there was a significant increase in data dumps on the dark web, with thousands of records available for sale. 

Singapore Identity Theft

These records often include biometric data, which are reused for illegal activities, including deepfakes. Nation-state actors and foreign operatives are also interested in this data for intelligence gathering. 

A significant portion of the stolen data was found on XSS, a prominent underground forum. Cybercriminals are also selling templates for forged documents with advanced security features. Singpass accounts, which provide access to government and private sector services in Singapore, have also been found for sale on the dark web.

Preteen Girl’s 92% Instagram Followers Grown Up Men, Pics Found On Dark Web: Report

Instagram, a platform owned by Meta, has been a topic of discussion about online safety due to incidents of girls being targeted by predatory adults. 

A recent report in the Wall Street Journal (WSJ) revealed that 92% of a preteen girl’s US followers are grown men. The girl started her Instagram channel after being encouraged by her mother to become an influencer. The algorithm steered men with deviant sexual attraction to her page, resulting in unwanted comments and sponsored offers. 

The girl’s page’s follower count grew to over 100,000 within a year, and she started receiving sponsorship offers. However, the comments from grown-up male followers became worse when she launched a paid subscription for “super-fans.” Meta has maintained that it does not allow anyone under 13 to open accounts on their own, but it has not done enough to stop incidents like these. 

The site’s algorithms take users to their favorite content without any filter about its appropriateness. The girl’s mother moderates comments and does not allow certain types of photos, like swimsuit pictures. 

Last year, WSJ linked Instagram’s recommendation algorithms to a “vast network of paedophiles” seeking illegal underage sexual content and activity.

BlackBerry Cylance Data Offered for Sale on Dark Web

BlackBerry is investigating a potential data breach involving Cylance data being sold on the dark web. The cybercriminals are claiming to have 34 million million customer and employee emails, personal information, sales prospects, and user and partner lists. 

The data was accessed from a third-party platform and appears to be from 2015-2018, predating BlackBerry’s acquisition of the Cylance product portfolio. BlackBerry is aware of the potential data breach and is currently conducting an investigation.

Blackberry
BlackBerry Limited – software company specializing in cybersecurity

Emsisoft threat analyst Brett Callow noted that the Cylance data may have been obtained as a result of a recent campaign targeting customers of cloud data platform Snowflake. The campaign has impacted many organizations, including high-profile companies like Ticketmaster, Anheuser-Busch, Allstate, Advance Auto Parts, Mitsubishi, Neiman Marcus, Progressive, Santander Bank, and State Farm. 

There is no evidence that the attacks involved a vulnerability in Snowflake systems or products, or that the vendor’s production or corporate systems have been compromised. BlackBerry does not confirm or deny that the data comes from Snowflake, but it is currently not a Snowflake customer.

Department of Justice on dark web marketplace arrest

The last news we got is marketplace arrest. Rui-Siang Lin, the creator of Incognito, has been arrested in the US for allegedly operating a $100 million dark web scheme to traffic deadly drugs. The FBI and Homeland Security Investigations New York have accused Lin of operating Incognito Market, one of the largest online platforms for narcotics sales, and of conducting $100 million in illicit transactions.

The site allowed anonymous transactions through a unique banking system that authorized cryptocurrency deposits and transfers, ensuring the anonymity of buyers and sellers. 

The FBI has also emphasized the ongoing work to disrupt illegal drug sales online, which often have tragic consequences. The Food and Drug Administration’s Office of Criminal Investigations has also weighed in, stressing their ongoing work to disrupt illegal drug sales online. 

If convicted, Lin faces several charges, including a mandatory life sentence for engaging in a continuing criminal enterprise, narcotics conspiracy, money laundering, and conspiracy to sell adulterated and misbranded medication. The US Attorney General, Merrick B. Garland, has criticized drug traffickers who believe they can operate outside the law on the dark web.

 

Dark Web Digest – June 2024 Edition

Dark Web Digest - June 2024

No one knows about the dark web, but hackers, drug dealers, and other types of cybercrime use it often. Every month, new things are happening the dark web. This June month’s digest will cover some of the most important and interesting news highlighted on the news and social media in May 2024.

Indian Election Hit by Cyberattacks, Dark Web Data Leaks

Security researchers have reported a surge in cyber activity targeting the upcoming Indian general election, driven by hacktivist groups. The election, which will determine all 543 members of the Lok Sabha, is set to occur in seven phases from April 19 to June 1, 2024. The cyber-attacks intensified since the launch of the #OpIndia campaign last year, with a 300% spike following the #OpIsrael campaign. 

India Election 2024

The surge is linked to heightened online protests amid the Israel-Gaza crisis. India, with its population of over 1.4 billion and GDP of $3.41T, has become a prime target for foreign threat actors and nation-state groups. Security has alerted Indian authorities about leaked voter ID cards and other sensitive data, aiming to undermine trust in India’s election systems. The firm urged Indian citizens to remain cautious of unreliable sources and emphasized the necessity of robust digital identity protection measures.

Dell customer order database of ’49M records’ stolen, sold on black web

Dell has confirmed that 49 million customer information records and orders have been stolen from a Dell portal. The stolen data includes names, addresses, and details about Dell equipment but does not include sensitive information like payment details. Dell’s portal was compromised, and the stolen data included columns such as service tag, items, date, country, warranty, organization name, address, city, province, postal code, customer code, and order number.

Dell has taken steps to contain the damage, notified law enforcement, and hired a third-party forensic firm. A spokesperson for Dell said the company is taking proactive steps to protect customers’ information and monitoring the situation. 

Dell also downplayed the significance of the data exposure, stating that they take privacy and confidentiality seriously and are currently investigating an incident involving a Dell portal. The company also warned people to be alert for scammers using the stolen data to impersonate Dell staff and defraud victims.

A data breach at Ticketmaster may have affected 560 million customers.

Ticketmaster has been targeted in a cyber-attack by ShinyHunters, demanding £400,000 in ransom to prevent the sale of customer data. The group claims to have access to 560 million customers’ names, addresses, phone numbers, and partial payment details.

Live Nation, the parent company of Ticketmaster, has launched an investigation into the incident and is cooperating with law enforcement. 

Ticketmaster Hack

Authorities in Australia and the US are working with Ticketmaster to understand and respond to the incident. 

Bank Santander confirmed that it had been hacked about two weeks ago. ShinyHunters is also reported to be behind the cyber-attack, posting an advert on a hacker forum for the data, which it claims to have 30 million customers, 6 million account numbers and balances, and 28 million credit card numbers.

The alleged $100 million dark-web drug kingpin, 23, arrested

A 23-year-old Taiwanese man, Rui-Siang Lin, has been arrested in New York for allegedly running the $100 million global dark web narcotics e-commerce operation Incognito Market. 

Lin Rui Siang

The dark website was formed in October 2020 and ran until March of this year, serving as a forum to buy and sell commodities, including heroin, cocaine, LSD, MDMA, oxycodone, methamphetamines, ketamine, and alprazolam. Lin is accused of running the entire business, supervising all operations, employees, vendors, and customers, and holding “ultimate decision-making authority over every aspect of the multimillion-dollar operation.”

Incognito Market provided a user experience that matched those offered by modern e-commerce sites, with vetting and registration of sellers, advertising, customer service facilities, and a slick UX. It distinguished itself from other e-commerce sites by requiring access through the Tor web browser and accepting only cryptocurrency. The DoJ noted that Lin had great IT skills, evidenced by his GitHub account, which described him as a “Backend and Blockchain Engineer, Monero Enthusiast,” he held approximately 35 publicly available software coding projects.

Lin also collected enemies, such as the spread of fentanyl due to the platform’s non-pure or authentic listings. 

The platform’s final days were allegedly spent extorting users between $100 and $20,000, under threat of revealing they had participated in the purchase and sale of illegal drugs. If convicted, Lin faces a mandatory minimum penalty of life in prison for engaging in a continuing criminal enterprise, a maximum penalty of life in prison for narcotics conspiracy, a maximum penalty of 20 years for money laundering, and a maximum of five years for conspiracy to sell adulterated and misbranded medication.

A man was jailed for selling 76 kg of drugs on the dark web.

A man, Donatas Kasputis, has been jailed for nine years for selling 76kg of drugs on the dark web. He used the username “Goodgear” to sell cocaine, ecstasy, and mephedrone to 550 buyers across the UK and abroad. Kasputis was arrested in July carrying 16 packages of drugs and pleaded guilty to eight offenses at Norwich Crown Court. 

Donatas Kasputis

The East Midlands Special Operations Unit (EMSOU) cyber investigations team discovered Kasputis’s drug operation after examining his username, “Beatyhouse2015”. 

The suspect was eventually identified through DNA profiling, and his home was searched, revealing 130g of cocaine, 1,300 ecstasy tablets, 6.4kg of mephedrone, and more than 1.4kg of cannabis. The information on the 550 people who were identified as buying drugs from “Goodyear” has been shared with the relevant police forces.

Fake Pegasus spyware source code floods the dark web

Cybersecurity firm CloudSEK has discovered that cybercriminals are exploiting the Pegasus spyware name to deceive victims on the dark web. Based on months of research on dark web sources, the report exposes a systematic effort to leverage the Pegasus name for financial gain. Threat actors bomb platforms like Telegram with posts claiming to sell genuine Pegasus source code. CloudSEK researchers analyzed approximately 25,000 posts on Telegram, many of which claimed to sell authentic Pegasus code. These posts often followed a common template offering illicit services, frequently mentioning Pegasus and NSO tools.

The report also identified six instances of fake Pegasus HVNC (Hidden Virtual Network Computing) samples distributed on the dark web between May 2022 and January 2024. 

The same misuse was also observed on surface web code-sharing platforms, where scammers were disseminating their randomly generated source codes, falsely associating them with the Pegasus Spyware. After analyzing 15 samples and over 30 indicators from human intelligence (HUMINT), deep, and dark web sources, CloudSEK discovered that nearly all samples were fraudulent and ineffective. Threat actors created their own tools and scripts, distributing them under Pegasus’ name to capitalize on its notoriety for financial gain.

To combat the Pegasus scam, CloudSEK recommends employee awareness, regular updates, and alerts about scam tactics and trends involving Pegasus and similar high-profile names. 

Network monitoring should be implemented to identify unusual activity that might indicate employees accessing the dark web or IRC platforms, and strict access controls should be implemented to limit and monitor employees’ ability to visit potentially dangerous sites or download unauthorized software.

Man arrested in Karachi Pakistan for creating vulgar wife videos for dark web

Women Police in Karachi’s Central District detained the man for reportedly abusing his wife and children and filming the incident on orders from an unknown source. A guy was arrested in Karachi, Pakistan, on Friday for reportedly producing filthy movies of his wife and sharing them on dark websites.

Karachi Man Arrested

Cyber security organizations collect data from all web platforms, including Dark Web forums, to avoid real-time attacks on exposed data, provide actionable intelligence on illegal drug and pharmaceutical exchanges, and monitor insider threats.Cyber security organizations collect information from many web platforms, including Dark Web forums, to avoid real-time attacks on exposed data, provide actionable intelligence on illegal drug and pharmaceutical exchanges, and monitor insider threats.(Shutterstock)

During questioning, Tahir confirmed that website owners had approached him over WhatsApp, according to Pakistan’s Ary News. He continued, “I am unsure of how the website proprietor obtained my WhatsApp number.”

Women Police in Karachi’s Central District detained the man for reportedly abusing his wife and children and filming the incident on orders from an unknown source. According to SHO Women Iram Amjad, the man was apprehended during a raid while his wife and four children were saved.

According to Aaj TV, the individual claimed to have received instructions via email from an unknown source abroad. Amjad further stated that the suspect was instructed to film recordings of each task and send them back via email.

He had hurt and abused his wife and was going to tape his daughter for the next duty. He also stated that the man was involved in violence, sexual harassment, and other criminal actions.

The arrest was made in the case after the victim’s sister Huma Rizvi, who lives in the United States, filed a report.

According to authorities, Elia, the suspect’s wife, accused him of pushing her to have sexual intercourse with his buddies. She also said he attempted to create inappropriate videos with their daughter. According to Aaj TV, Elia said that Tahir took nude images of their 16-year-old daughter and was blackmailing her into sleeping with his pals.

Elia also said in her police statement that Tahir was suspicious and beat her and the children physically and emotionally. She claimed that throughout the last 12 years, she had fled the house multiple times, but her parents had always interfered and rectified the situation.

According to Khyber News, Tahir admitted to setting a camera in the bathroom to watch his wife but then removed it and did not upload any footage. He also admitted to physically assaulting his wife and apparently intending to record his daughter before being caught.

The cops confiscated his phone and laptop, which are currently being investigated.

Conclusion

In conclusion, the constantly shifting dark web in May 2024 will likely be a platform for criminal activity, with cybercrime illegal product trading. It attempts to elude law enforcement remaining common. Understanding this underground marketplace for educational purposes emphasizes the constant conflict between criminal elements and police in the digital age.