Dark Web Digest – March 2024 Edition

Dark Web Digest - March 2024

This month also brought up a lot of happenings in the dark web, the hidden part of the internet that is often used for illegal and malicious activities. From ransomware attacks and cybercrime crackdowns to AI phishing and zero-day exploits, the dark web in 2024 has seen the emergence of new types of cyber threats and criminal activities. 

Let’s discuss some of the most notable and alarming events that took place in the dark web in February 2024, and what they mean for the security and privacy of users and organizations.

34 million Roblox credentials have been leaked on the dark web

There have been a lot more cybercriminals working between 2021 and 2023, as 34 million Roblox accounts were found on the dark web. There were 4.7 million hacked accounts in 2021, but there were 15.5 million in 2023, which is a 231% increase. 

The number of hacked accounts on 11 game platforms, such as Twitch, Electronic Arts, Sony PlayStation, and Steam, has increased by 112% since 2021, according to the Kaspersky Digital Footprint Intelligence report. Cybercriminals often use sneaky tricks, like putting info stealers in cheat code files or posting harmful download links on popular sites like YouTube to take advantage of students’ trusting nature.

Criminals are often more interested in Steam accounts because they can be used to steal real money. Roblox accounts are still being used to get in-game gold and other valuable items, though. Platform owners can make their sites safer by using special services to find and quickly block accounts that have been hacked. 

Using different passwords for each service, using two-factor authentication whenever possible, and using reliable security solutions are just a few of the security steps that people and businesses can take to lower the risks of password leaks.

The FBI and its partners take down the dark website of the world’s most active ransomware gang

The FBI and its partners around the world have taken down a dark web site that LockBit, the most prolific ransomware gang in the world, used to demand money from its victims. LockBit has been a threat to businesses all over the world, including US healthcare companies. 

The NCA and FBI have made software that hackers may be able to use to unlock the computers of “hundreds” of people around the world. The 

NCA statement suggested that LockBit had been hacked for a long time, which let police get the hackers’ “source code.” 

Taking over a ransomware group’s dark website pushes cybercriminals to build new computer systems to use to demand money from victims, and it can also mean that police have more access to the hackers’ networks. 

LockBit is thought to have members or illegal partners in China, Russia, and Eastern Europe. Hackers have put information about LockBit victims online, which shows that it makes up a quarter of the ransomware market. Private and public agents all over the world will be watching what LockBit does next. Ransomware gangs, which are often based in Eastern Europe and Russia, have been fighting the FBI and its partners around the world for a long time. This operation is the latest step in that fight.

A dark web drug dealer is sentenced to 10 years

Gabriel Alva, a 32-year-old cybercriminal from Los Angeles, was given a $1.3 million cryptocurrency term after being found guilty of planning to use the dark web to sell heroin, cocaine, and methamphetamine. 

Under the fake names Diablow, RaiseAppeals, and RaisedByDiablow, Alva and his partners sold drugs illegally on the Silk Road, Dream, and Nightmare boards. 

They took cryptocurrency as payment and sold drugs like crystal meth, heroin, cocaine, and more. In 2019, federal officials raided Alva’s home and found 24 kg of methamphetamine, 2 kg of heroin, and 2 kg of cocaine. This was the end of Alva’s drug life. The feds also took six guns, including a Remington shotgun, a Smith & Wesson assault rifle, and an AR-15 assault rifle that had not been made into a special weapon.

Thousands of stolen anydesk login credentials for sale on the dark web

Cybersecurity experts have found several threat actors selling hacked AnyDesk accounts on a site in the Russian language on the dark web. The recent security breach and the sale of AnyDesk login credentials are not related. 

The recent security breach was caused by infostealing malware infecting PCs to steal private information. A threat actor going by the name “Jobaaaaa” has been seen selling Bitcoin or Monero (XMR) worth $15,000 from 18,317 hacked AnyDesk accounts

The trades were made possible by escrow services. However, Alon Gal of Hudson Rock has disagreed with Resecurity’s results and said that the threat actor is selling more than 30,000 AnyDesk accounts. The hacked AnyDesk accounts are being sold on Exploitin, a Russian-language website for cybercrime and hackers. 

If your account works, terrible things could happen, like losing money, having your data or identity stolen, having your image hurt, having your business interrupted, or even being hit by ransomware.

FBI effort to target illegal dark web crimes, a man was arrested in Malta

A 27-year-old Maltese man was arrested on suspicion of working with others to sell malware on the dark web and giving advice on the Hack Forum. A type of malware called a remote access Trojan (RAT) lets hackers get into victims’ computers or servers without permission. 

This lets them manage them from afar and maybe even take advantage of them. The Maltese Police’s Cybercrime Unit was in charge of local investigations after the US asked for help. The suspect was caught at work in Gudja, and searches in several places turned up important evidence that is being used in the case. 

He agreed to be sent back to the US, where he will be charged in a federal court. Until further court hearings, he is being held in custody at the Corradino Correctional Facility. 

Law enforcement agencies from several countries, including Nigeria, worked together with Europol to go after the sale of illegal software on the dark web at the same time. A Nigerian partner who lived in Nigeria was also caught as part of the probe.

An Indian guy was arrested for selling 4500 GB of private data on the dark web

The hacker Amit Chand, who is 21 years old and from Rajasthan, was caught illegally viewing and selling private data on the dark web that belonged to the governments, military, and people of India, the US, China, and Ukraine. 

Chand also kept over 5 lakh people’s Aadhaar cards, PAN cards, and other payment information. Also found were files that belonged to the Islamic States and the Taliban. 

The house of Chand in Srikaranpur’s 49F village was searched by the Intelligence Bureau (IB) and district cops. They found 4,500 GB of data on several devices. 

Chand has been working on the dark web since 2018, but people have started to doubt him after he became more aggressive in the last two to three months. During the raid, authorities found more than 90 million US records as well as a lot of records from the Islamic State and the Taliban. The cops and IB are questioning Chand.

Sussex man sentenced to jail for running child abuse site worldwide

Martin Yates, a guy from Eastbourne, went to jail for his part in running The Annex, a global blog about child abuse on the dark web. About 90,000 people around the world were members of the site, which shared sexual abuse videos of babies and children. 

Between January and September 2020, Yates was the site’s assistant editor. He made sure rules were followed, gave advice on how to keep the site safe, and trained other people. He admitted that he planned or helped with the sexual abuse of children, made and distributed four obscene pictures of children, and had one otherwise illegal picture of a child. 

The National Crime Agency (NCA) and the Federal Bureau of Investigation (FBI) went after the admins of the site. 

Also sent to prison for 16 and 6 years were Nathan Bake, 28, and Kabir Garg, 34. William Spearman, who is 58 years old, was given a life sentence in jail in the US in January. In the US, 14 more men have been charged for their part in trying to run the site.

Man jailed for 16 years for tempering child abuse site

A car mechanic named Nathan Bake, who is 28 years old, was given a 16-year prison sentence at Chester Crown Court after admitting to 12 crimes linked to creating and moderating dark websites where child abuse content was shared. 

A man from Alabama ran the site The Annex, which had almost 90,000 users from all over the world. Bake was in charge of moderating it. Adult content like “hurtcore” and violent content involving babies and children were shared on the site. 

Branch commander of the National Crime Agency (NCA) Adam Priestley said that the spot was safe for everything. Prosecutor Anna Pope said that users would start by going to a “gateway” on the site using the Tor browser. 

They would then have to “gain the trust” of the people running the site before they could be sent to other places. 

Bake worked his way up in the online group for child molesters and was made second-in-command when the head moderator was arrested in May 2022. After Bake was arrested in November 2022, more than 3.6 million sexy pictures were found in his home.

Norton introduces tool for real-time tracking

There is good news above all trends, even though there are dangers. Dark Web Monitoring is a new tool that Norton has launched for Indian users. With this add-on to its security solution, users can see in real-time if online stores have their personally identifiable information (PII). 

This gives people the chance to fix the problem, like calling the bank or changing their passwords, to avoid scams. Norton says that, unlike digital companies like Google, its tool does everything. 

The Aadhaar numbers, ID numbers, and phone numbers of 815 million Indians were found on the dark web in 2023. As well as gamer tags, the tool can keep an eye on up to five insurance account numbers, email addresses, phone numbers, and up to ten credit card numbers. 

Norton tells people to be careful about giving out personal information online and to log out of temporary email accounts when they’re done using them.

Dark Web Digest – October 2023 Edition

dark web digest - October 2023

Welcome to the October edition of Dark Web Digest, your go-to source for the latest news and updates from the dark web. The dark web is a breeding ground for cybercriminals, with several associated threats. In addition, it is constantly evolving, and new developments are always emerging.

This edition contains the most recent developments in cybersecurity, hacking, and the dark web. Let’s look at the latest news and incidents that occurred last month!

Cyberattack exposes donor data from Australia-based telemarketing firm

The Pareto Phone ransomware group, LockBit, has been reported as taking donor data and publishing it on the dark web (including here and here). Among the charities involved, the Australian Conservation Foundation said 13,500 supporters. According to a statement, the data accessed by ChildFund NZ included titles, names, and postal and phone numbers.

There was also the revelation that Pareto Phone hid data from charities for many years without their knowledge. This was with the Baker Heart and Diabetes Institute not working with Pareto Phone for more than eight years and the Stroke Foundation not since 2017. Children’s Fund NZ has collaborated with Pareto Phone since 2014. MSF Australia said it had not used the company for almost five years and was unaware it had retained historical records.

According to a report last October, one in eight charities in the UK suffered cybercrime within the past year due to cyberattacks. An advanced cyber security attack in 2022 on the International Committee of the Red Cross (ICRC) compromised the sensitive personal information of more than 515,000 highly vulnerable people from more than 60 Red Cross and Red Crescent National Societies worldwide.

Loyalty’s third-party research partner, Kokoro, was recently targeted in the UK. According to Kokoro’s forensic investigation, the group responsible may have accessed some client data. In this case, no postal addresses, financial details, or identity documentation were available on Kokoro’s systems. The charity clients affected were informed, with Shelter and Friends of the Earth acting to reassure and inform.

Finland, Europol take down PIILOPUOTI dark web marketplace

The Finnish law enforcement forces worked with Europol and a cybersecurity firm to shut down PIILOPUOTI. Finnish Customs said that the platform had operated on the Tor Network since May 2022 for smuggling drugs and paraphernalia into Finland.

Due to an ongoing criminal investigation, Finn Customs and its international cooperation partners won’t provide any further information. The Finnish authorities refused to comment on arrests or other illegal activities conducted on the platform. It said the investigation was born with the assistance of German and Lithuanian authorities, Europol, Eurojust, other countries’ authorities, and various Finnish police units.

PIILOPUOTI - Marketplace

Bitdefender helped law enforcement agencies investigate the platform in its investigation and participated in the takedown. Alexandru Catalin Cosoi, Bitdefender’s senior director of investigation and forensics, did not elaborate on the company’s involvement but said it “provided technical consulting to the entire investigation group.” Earlier this month, US and Polish law enforcement agencies partnered to dismantle the bulletproof hosting platform Lolek.

In April, more than a dozen international partners were involved in an FBI-led operation that seized Genesis Market, a one-stop shop for criminals selling stolen credentials and the tools to weaponize them.

Dark Web hacker threatens to sell US and European military intelligence

US Department of Defense hacker “USDoD” has warned that he intends to sell military intelligence to the dark web. The hacker entered the Airbus website by exploiting Turkish Airlines employee access.

According to USDoD, its targets are American defense contractors, NATO, Europol, and Interpol. In a lengthy interview with databreaches.net, USDoD disclosed that its next targets are American defense contractors, NATO, and Europol.

While he threatened to set up a private company to trade classified military information between the US and Europe, the Department of Defense claimed that he was not pro-Russian despite cyberattacking Russia’s adversaries. He also worked for some Russians, but he has no racial biases or political motives.

As part of the hacker’s denials, he denied receiving financial compensation for his attacks on United States and European entities. He avoids attacking China, Russia, North Korea, South Korea, Israel, and Iran exemplifies one of his strategies.

The Pentagon continues to work on cybersecurity as the Pentagon threatens to sell US military intel. The United States Air Force recently awarded Raft LLC a contract to develop a software factory for cyber operations. Cyber deterrence is also strengthened through training and drills, such as the recent “defensive hunt operation” in Lithuania.

The dark web leaks the Personal information of Dymock customers

Earlier this week, Dymocks announced that some of its customers’ information may have been compromised and leaked onto the dark web. A small group of unauthorized individuals may have accessed Dymocks’ customer records on 6 September. Customers’ information, including addresses, e-mails, phone numbers, and membership information, may have been compromised. Dymocks said an investigation is underway to determine how this happened.

Dymock

The issue was notified to customers via an e-mail sent on Friday afternoon, asking them to be “vigilant” and change their passwords. Dymocks’ customers’ postal addresses, birthdates, e-mail addresses, mobile phone numbers, gender, and membership details may have been compromised.

According to a company statement, an unauthorized party may have accessed certain customer records at Dymocks as of 6 September 2023. Neither Dymocks nor its customers know who or how many customers have been affected by the breach.

Since passwords might be available on the dark web, Dymocks suggests its customers change their online passwords, including their Dymocks accounts and social media accounts. Furthermore, the company cautioned customers against telephone, postal, and e-mail phishing scams.

Cornwall dealers used Bitcoin to buy cocaine and cannabis on the dark web

A pair of drug traffickers accused of buying cocaine and cannabis on the dark web to sell on the streets of West Cornwall have been jailed. Jason Pierce, 56, and Callum Payne, 28, both from Porthleven, were sentenced to ten years in prison.

They denied conspiracy to supply cocaine and cannabis, but a jury at Truro Crown Court found them guilty of conspiracy to supply cocaine and cannabis after a trial in June. 

The sentence for Pierce was six years and eight months, and that for Payne was three and four months in prison at Plymouth Crown Court on Friday, 15 September.

A court heard about the drugs’ purchase from the Netherlands on the dark web through Bitcoin and their distribution to locations throughout West Cornwall.

Officers uncovered the drug trafficking operation in January 2018 when they found £5,000 worth of cannabis in the car being driven by Payne.

The defendants’ computers had sophisticated privacy software that needed to be cracked to unlock evidence of their criminal activities.

As Detector Inspector Steven Moorcroft of Devon and Cornwall Police’s Serious and Organised Crime Branch explained: “This investigation began in 2018 after a chase in Porthleven led to Callum Payne fleeing a vehicle containing cannabis imported from the Netherlands through the dark web.

Dozens of Mullvad VPN accounts discovered on the dark web

According to security researcher Damien Bancal, one of the major Swedish VPN providers, Mullvad VPN, has recently been accused of leaking user data.

A ZATAZ Monitoring client discovered an astonishing data leak targeting Mullvad during an investigation. Several websites leading to Mullvad API provided access to user connection data, such as IP addresses [IPv4 and IPv6 addresses], connection dates, and other information that was not personally identifiable, the post says.

A hacker discussion led Bancal to learn about Mullvad VPN’s plans to sell data on the dark market. Among the data shared were Mullvad clients’ 16-digit IDs and expiration dates.

Researchers shared several links to a cache of Mullvad VPN forums where threat actors were trading them off. Despite an ID number, not much information can be retrieved about those accounts since no names, e-mail addresses, or other personal information are available.

The researcher said that a malicious actor can do much damage even with very little information.

According to Jan Jonsson, CEO of Mullvad VPN, the publicly revealed accounts are unsurprising. He has seen over 100 Mullvad VPN accounts personally.

Many Mullvad forums and websites list “leaked” Mullvad accounts. Mullvad donates millions of Mullvad accounts to charities each year for various reasons. Cybernews contacted him via e-mail to learn about several sources for “leaked accounts.”

There was no leak. “Firstly, we have an API with minimal functions. Secondly, we do not use passwords. We only use 16-digit account numbers.” He believes people are brute-forcing account numbers to get free accounts. 

Customer data was seized from the Swedish-owned company’s Gothenburg office in April during a police raid. Since the company had a ‘no logs’ policy, such customer data was not even available to them. If they had taken something, they couldn’t access any customer data.”

The industry has been under scrutiny because VPNs essentially allow users to remain anonymous on the internet.

VPN IDs may contain private user information, such as billing, and may collect personal information so that exposure could have serious consequences. If a VPN ID is exposed, users should change their password, enable multi-factor authentication, and notify their VPN provider.

Senate is concerned about Pakistani public data sales on the dark web.

Pakistan faces a growing challenge concerning protecting its public data, with the Senate Standing Committee on Information Technology and Telecommunication recently convening to address these concerns. The Senate greenlights Army Act amendments: 5-year jail term for revealing sensitive information. The gathering boasted a diverse composition, underlining the gravity of the situation.

A Cyber Response Team was established to combat cyber threats effectively. It was also decided to enhance public awareness regarding cybersecurity in Pakistan. The committee received an update on the National Cyber Security Policy, which outlines the government’s strategic approach to safeguarding the nation’s cyberspace. The committee heard from the CEO of Ignite, an organization that has established eight National Incubation Centers across Pakistan and generated Rs15 billion in revenue.

Senator Kauda Babar urged the establishment of more NICs in various cities, with a particular focus on Balochistan. The committee also delved into the National Telecommunication Corporation (NTC) operations, Pakistan’s official telecom and ICT service provider, and called for improvements.

The Senate Standing Committee on Information Technology and Telecommunication highlighted the need to strengthen Pakistan’s data protection measures and bolster cybersecurity efforts to promote innovation and economic growth.

Conclusion

The dark web is a dangerous place that poses several threats to individuals and businesses. However, staying informed and taking the necessary precautions can help you stay safe online. In this edition of Dark Web Digest, we have provided the latest news and updates from the dark web, as well as tips and advice on staying safe online. 

Thank you for reading Dark Web Digest, and we hope to see you again in the next edition.