Dark Web Digest – August 2024 Edition

Dark Web Digest - August 2024

This month’s August dark web digest will bring some exciting news. Google launched its first monitoring tool for the very first time in history. Other side research finds stolen data and also suggests how to stay strong against the dark web world and its attack. As we know, the dark web is a dangerous place; it is just like the internet we use on a daily basis but a place of illegal activities. From hacking to selling, there is everything that can be done on the dark web. Let’s explore this month’s digest and see what happened last and what might be happening in the future.

Google Rolls Out Free Dark Web Monitoring Tool for All Users

Google has announced that its Dark Web monitoring feature will be available to all Google account users for free, a significant change in a previously exclusive service for Google One’s premium users. The tool searches the dark web for users’ personal information, such as names, social security numbers, email addresses, and phone numbers, and advises them on how to protect their data. This move could help democratize cybersecurity and mitigate emerging threats of identity theft and personal data breaches.

Google Dark Web Monitoring - July August 2024

The Dark Web monitoring tool scans various sites and forums on the dark web where stolen information is frequently traded. If a user’s data is found, Google will send an alert providing details about the data and recommendations for securing it. This seamless integration means users do not need to download additional software or manage multiple accounts to keep their information secure.

This initiative enhances individual user security and sets a new standard for tech companies in cybersecurity. By making advanced security tools accessible to a wider audience, Google is pushing the envelope in the fight against cybercrime. The move is likely to have ripple effects across the tech industry, encouraging other companies to enhance their security offerings.

Google’s expansion of free Dark Web monitoring to all Google users is a significant step forward in online security, as it is crucial in safeguarding user data against cybercrime.

Security Researchers Find Stolen SingPass Accounts on Dark Web

According to Singaporean security researchers, there has been a 23% increase in dark web activity related to stolen identity information from citizens. Cybercriminals are selling stolen documents, which are used for fraudulent activities, identity theft, impersonation scams, and bypassing Know Your Customer (KYC) protocols. The surge is largely due to data breaches affecting online platforms that store consumer information. In April 2024, there was a noticeable increase in data dumps on the dark web, with thousands of records becoming available for sale. These records often contain biometric data, which is used for illegal activities like creating fakes. Nation-state actors and foreign operatives are highly interested in this data for intelligence purposes. A significant portion of the stolen data was discovered on XSS, a prominent underground forum. SingPass accounts, which allow access to government and private sector services in Singapore, have also been found for sale on the dark web.

Singpass - August 2024

Ticketmaster discredits dark web claims of stolen barcodes for Taylor Swift concerts

Ticketmaster has denied claims that hackers have access to working ticket barcodes for upcoming Taylor Swift concerts and other events. A hacker allegedly offered 170,000 barcodes for sale, with 20,000 available at each show. The hacker threatened Ticketmaster with more leaks if they weren’t paid $2 million, claiming to have 30 million more barcodes for NFL games and Sting concerts. Ticketmaster’s spokesperson denied the claims and stated that their SafeTix technology protects tickets by automatically refreshing a new barcode every few seconds. Ticketmaster’s parent company, Live Nation, confirmed last month that its account on data storage platform Snowflake had been breached. Hackers claimed to have a 1.3 terabyte database of information on about 560 million Ticketmaster users, including names, addresses, emails, phone numbers, event details, and specific orders.

Ticketmaster Hack - August 2024

Researchers predict seller success on dark web markets

Researchers from Leiden University have developed a method to predict successful sellers in illegal online marketplaces, which could help law enforcement track down big players on the dark web. These marketplaces, also known as cryptomarkets, are found on the dark web and cannot be accessed with regular internet browsers or search engines. Users are anonymous, and transactions are made with cryptocurrencies like bitcoin. The researchers, including Ph.D. candidate Hanjo Boekhout, Professor Frank Takes, and Professor Arjan Blokland, used data from Evolution, a popular data web market in 2014, to analyze communication patterns in the forum section. Topic engagement and betweenness centrality were identified as good predictors of seller success. Topic engagement was found to be a strong predictor, with users with many responses often becoming successful sellers. Betweenness centrality helped identify important players who were less active on the forum. The method could help law enforcement agencies prioritize investigations and identify emerging sellers before they become big.

Botnets are being sold on the dark web for as little as $99

Cyber criminals are offering ready-made botnets on the dark web for as little as $99, making cyber attacks cheaper and easier than ever. Botnets like Mirai target online consumer devices such as IP cameras and home routers, with individually tailored infection processes, malware types, infrastructure, and evasion techniques. Recent research from Cloudflare found that 4% of HTTP DDoS attacks and 2% of L3/4 DDoS attacks were launched by a Mirai-variant botnet during the first quarter of this year.

Botnet Attack

Since the beginning of 2024, Kaspersky researchers found more than 20 offers for botnets for hire or sale on dark web forums and Telegram channels. The lowest offers started at $99 and the highest reached $10,000. Botnets can be hired or acquired as leaked source code for between $30 and $4,800 per month, with custom botnet development also available in some cases. Access to leaked source code can be obtained for free or a fee of $10 to $50.

Botnet activity is on the rise, with researchers at NetScout discovering a sharp rise in global botnet activity, spiking at more than a million devices. A Trustwave report last year found that botnets were responsible for more than 95% of all malicious traffic on the internet, with Mirai, Mozi, and Kinsing botnets accounting for almost all exploit attempts that were run over HTTP or HTTPS protocols.

CSAM Pedophiles Identified via Dark Web Malware

Information-stealing malware logs on the dark web have identified numerous individuals who download and share child sexual abuse material (CSAM), highlighting a new law enforcement technique. Recorded Future’s Insikt Group used stolen data to trace these identities across platforms, obtaining usernames, IP addresses, and system characteristics. Law enforcement uses this information to identify perpetrators and make arrests. Infostealer logs like Redline, Raccoon, and Vidar include critical data, including passwords, browsing history, cryptocurrency information, and more.

Researchers may use info stealer data to link CSAM account users to email, banking, and social networking accounts. This development demonstrates its potential to improve child sexual exploitation tracking and convictions. As child predators increasingly use artificial intelligence (AI) to create sexually graphic photographs of children, hampering law enforcement attempts to prevent internet sexual exploitation. Stanford University’s Internet Observatory found that AI-powered technologies have allowed criminals to create fake images and videos based on actual children’s photos, increasing child sexual abuse content.

As of 2023, the National Center for Missing and Exploited Children’s CyberTipline recorded over 36 million suspected child sexual abuse incidents. The proposed Kids Online Safety Act in the United States and the Online Harms Act in Canada attempt to hold social media companies accountable for harmful AI-generated material. However, social media companies using AI for content moderation are making child sexual abuse detection and reporting harder, possibly allowing offenders to escape prison.

Man convicted for encouraging child sexual abuse on the dark web

A man from Peterborough, Colin Thackeray, has been convicted of promoting child sexual abuse on a dark web site. Thackeray, a 62-year-old moderator, shared advice on grooming children with the intention of sexually abusing them. The sites involved the sexual abuse of boys and linked to indecent imagery. Thackeray had over 2,000 indecent images of children on his devices, with 350 in Category A, 655 in Category B, and 1,459 in Category C. When arrested in September 2019, NCA officers found a laptop and chat logs where Thackeray was exchanging indecent images, discussing how to groom and abuse children, and role-playing sexual activity with children.

Colin ThackerayHe was charged with making indecent images of children, possessing prohibited images, intentionally encouraging or assisting an offence, and attempting to cause or incite a boy under 13 to engage in sexual activity. Thackeray pleaded guilty to three counts of making indecent images and one count of possessing indecent images in July 2022 and was further convicted of two counts of intentionally encouraging the sexual assault of a child under 13 and one count of attempting to incite a child under 13 to engage in sexual activity.

Bitzlato founder won’t get more jail over $700M dark web clearing house

Bitzlato Founder ScamAnatoly Legkodymoc, founder of the defunct crypto exchange Bitzlato, has been sentenced to time served after pleading guilty to one charge of operating an unlicensed money-transmitting business. Legkodymov served 18 months at Brooklyn’s Metropolitan Detention Centre (MDC) and agreed to forgo any claim to the $23 million in crypto assets seized by French law enforcement during the global sting operation that shut down the exchange on Jan. 23, 2023. The prosecution alleged that Legkodymov aided in the exchange of over $700 million in cryptocurrency through the Russian dark web black market Hydra Market and failed to implement adequate measures to monitor who was using the exchange.

Bitzlato users regularly visited the exchange’s customer service portal to ask for help with transactions on Hydra Market and frequently admitted they were trading under false identities. Legkodymov was arrested in Miami on Jan. 17, 2023, following a coordinated international effort to shut down the exchange. Europol reported that roughly 46% of assets processed by Bitzlato were linked to illicit activities, with others linked to cyber scams, money laundering, ransomware, and child abuse material.

Stolen credentials could unmask thousands of darknet child abuse website users

Researchers at Recorded Future have discovered that thousands of people with accounts on darknet websites for sharing child sexual abuse material (CSAM) could be unmasked using information stolen by cybercriminals. The researchers identified these individuals from credentials harvested by infostealer malware, which typically steals log-in credentials for banking services, which are then exploited by financial fraudsters. The logs link these anonymous CSAM website users to accounts on clear web platforms, such as Facebook, where they have used their real names and sometimes even include autofill data stored in a web browser, such as a home address.

Infostealers steal data from infected devices, including login credentials, operating system information, cryptocurrency addresses, and other data that these actors then post or share or sell on dark web sources. Retailers involved in the ecosystem for trading these stolen credentials include Russia Market and 2Easy Shop, as well as the now-defunct Genesis Market, which was seized by law enforcement last year, leading to more than 120 arrests.

Recorded Future analyzes these records for domains used by corporate customers to protect compromised employee accounts or identify when customers are impacted to tackle consumer fraud. By querying this data alongside partners like the World Childhood Foundation and the Anti-Human Trafficking Intelligence Initiative, the researchers were able to identify approximately 3,300 unique users with accounts on at least one darknet site for the sharing of CSAM.

The researchers aim to share the methodology as a proof-of-concept of what can be done using the type of data that they have, and pass it on to those who can take more action.

Dark Web Digest – June 2024 Edition

Dark Web Digest - June 2024

No one knows about the dark web, but hackers, drug dealers, and other types of cybercrime use it often. Every month, new things are happening the dark web. This June month’s digest will cover some of the most important and interesting news highlighted on the news and social media in May 2024.

Indian Election Hit by Cyberattacks, Dark Web Data Leaks

Security researchers have reported a surge in cyber activity targeting the upcoming Indian general election, driven by hacktivist groups. The election, which will determine all 543 members of the Lok Sabha, is set to occur in seven phases from April 19 to June 1, 2024. The cyber-attacks intensified since the launch of the #OpIndia campaign last year, with a 300% spike following the #OpIsrael campaign. 

India Election 2024

The surge is linked to heightened online protests amid the Israel-Gaza crisis. India, with its population of over 1.4 billion and GDP of $3.41T, has become a prime target for foreign threat actors and nation-state groups. Security has alerted Indian authorities about leaked voter ID cards and other sensitive data, aiming to undermine trust in India’s election systems. The firm urged Indian citizens to remain cautious of unreliable sources and emphasized the necessity of robust digital identity protection measures.

Dell customer order database of ’49M records’ stolen, sold on black web

Dell has confirmed that 49 million customer information records and orders have been stolen from a Dell portal. The stolen data includes names, addresses, and details about Dell equipment but does not include sensitive information like payment details. Dell’s portal was compromised, and the stolen data included columns such as service tag, items, date, country, warranty, organization name, address, city, province, postal code, customer code, and order number.

Dell has taken steps to contain the damage, notified law enforcement, and hired a third-party forensic firm. A spokesperson for Dell said the company is taking proactive steps to protect customers’ information and monitoring the situation. 

Dell also downplayed the significance of the data exposure, stating that they take privacy and confidentiality seriously and are currently investigating an incident involving a Dell portal. The company also warned people to be alert for scammers using the stolen data to impersonate Dell staff and defraud victims.

A data breach at Ticketmaster may have affected 560 million customers.

Ticketmaster has been targeted in a cyber-attack by ShinyHunters, demanding £400,000 in ransom to prevent the sale of customer data. The group claims to have access to 560 million customers’ names, addresses, phone numbers, and partial payment details.

Live Nation, the parent company of Ticketmaster, has launched an investigation into the incident and is cooperating with law enforcement. 

Ticketmaster Hack

Authorities in Australia and the US are working with Ticketmaster to understand and respond to the incident. 

Bank Santander confirmed that it had been hacked about two weeks ago. ShinyHunters is also reported to be behind the cyber-attack, posting an advert on a hacker forum for the data, which it claims to have 30 million customers, 6 million account numbers and balances, and 28 million credit card numbers.

The alleged $100 million dark-web drug kingpin, 23, arrested

A 23-year-old Taiwanese man, Rui-Siang Lin, has been arrested in New York for allegedly running the $100 million global dark web narcotics e-commerce operation Incognito Market. 

Lin Rui Siang

The dark website was formed in October 2020 and ran until March of this year, serving as a forum to buy and sell commodities, including heroin, cocaine, LSD, MDMA, oxycodone, methamphetamines, ketamine, and alprazolam. Lin is accused of running the entire business, supervising all operations, employees, vendors, and customers, and holding “ultimate decision-making authority over every aspect of the multimillion-dollar operation.”

Incognito Market provided a user experience that matched those offered by modern e-commerce sites, with vetting and registration of sellers, advertising, customer service facilities, and a slick UX. It distinguished itself from other e-commerce sites by requiring access through the Tor web browser and accepting only cryptocurrency. The DoJ noted that Lin had great IT skills, evidenced by his GitHub account, which described him as a “Backend and Blockchain Engineer, Monero Enthusiast,” he held approximately 35 publicly available software coding projects.

Lin also collected enemies, such as the spread of fentanyl due to the platform’s non-pure or authentic listings. 

The platform’s final days were allegedly spent extorting users between $100 and $20,000, under threat of revealing they had participated in the purchase and sale of illegal drugs. If convicted, Lin faces a mandatory minimum penalty of life in prison for engaging in a continuing criminal enterprise, a maximum penalty of life in prison for narcotics conspiracy, a maximum penalty of 20 years for money laundering, and a maximum of five years for conspiracy to sell adulterated and misbranded medication.

A man was jailed for selling 76 kg of drugs on the dark web.

A man, Donatas Kasputis, has been jailed for nine years for selling 76kg of drugs on the dark web. He used the username “Goodgear” to sell cocaine, ecstasy, and mephedrone to 550 buyers across the UK and abroad. Kasputis was arrested in July carrying 16 packages of drugs and pleaded guilty to eight offenses at Norwich Crown Court. 

Donatas Kasputis

The East Midlands Special Operations Unit (EMSOU) cyber investigations team discovered Kasputis’s drug operation after examining his username, “Beatyhouse2015”. 

The suspect was eventually identified through DNA profiling, and his home was searched, revealing 130g of cocaine, 1,300 ecstasy tablets, 6.4kg of mephedrone, and more than 1.4kg of cannabis. The information on the 550 people who were identified as buying drugs from “Goodyear” has been shared with the relevant police forces.

Fake Pegasus spyware source code floods the dark web

Cybersecurity firm CloudSEK has discovered that cybercriminals are exploiting the Pegasus spyware name to deceive victims on the dark web. Based on months of research on dark web sources, the report exposes a systematic effort to leverage the Pegasus name for financial gain. Threat actors bomb platforms like Telegram with posts claiming to sell genuine Pegasus source code. CloudSEK researchers analyzed approximately 25,000 posts on Telegram, many of which claimed to sell authentic Pegasus code. These posts often followed a common template offering illicit services, frequently mentioning Pegasus and NSO tools.

The report also identified six instances of fake Pegasus HVNC (Hidden Virtual Network Computing) samples distributed on the dark web between May 2022 and January 2024. 

The same misuse was also observed on surface web code-sharing platforms, where scammers were disseminating their randomly generated source codes, falsely associating them with the Pegasus Spyware. After analyzing 15 samples and over 30 indicators from human intelligence (HUMINT), deep, and dark web sources, CloudSEK discovered that nearly all samples were fraudulent and ineffective. Threat actors created their own tools and scripts, distributing them under Pegasus’ name to capitalize on its notoriety for financial gain.

To combat the Pegasus scam, CloudSEK recommends employee awareness, regular updates, and alerts about scam tactics and trends involving Pegasus and similar high-profile names. 

Network monitoring should be implemented to identify unusual activity that might indicate employees accessing the dark web or IRC platforms, and strict access controls should be implemented to limit and monitor employees’ ability to visit potentially dangerous sites or download unauthorized software.

Man arrested in Karachi Pakistan for creating vulgar wife videos for dark web

Women Police in Karachi’s Central District detained the man for reportedly abusing his wife and children and filming the incident on orders from an unknown source. A guy was arrested in Karachi, Pakistan, on Friday for reportedly producing filthy movies of his wife and sharing them on dark websites.

Karachi Man Arrested

Cyber security organizations collect data from all web platforms, including Dark Web forums, to avoid real-time attacks on exposed data, provide actionable intelligence on illegal drug and pharmaceutical exchanges, and monitor insider threats.Cyber security organizations collect information from many web platforms, including Dark Web forums, to avoid real-time attacks on exposed data, provide actionable intelligence on illegal drug and pharmaceutical exchanges, and monitor insider threats.(Shutterstock)

During questioning, Tahir confirmed that website owners had approached him over WhatsApp, according to Pakistan’s Ary News. He continued, “I am unsure of how the website proprietor obtained my WhatsApp number.”

Women Police in Karachi’s Central District detained the man for reportedly abusing his wife and children and filming the incident on orders from an unknown source. According to SHO Women Iram Amjad, the man was apprehended during a raid while his wife and four children were saved.

According to Aaj TV, the individual claimed to have received instructions via email from an unknown source abroad. Amjad further stated that the suspect was instructed to film recordings of each task and send them back via email.

He had hurt and abused his wife and was going to tape his daughter for the next duty. He also stated that the man was involved in violence, sexual harassment, and other criminal actions.

The arrest was made in the case after the victim’s sister Huma Rizvi, who lives in the United States, filed a report.

According to authorities, Elia, the suspect’s wife, accused him of pushing her to have sexual intercourse with his buddies. She also said he attempted to create inappropriate videos with their daughter. According to Aaj TV, Elia said that Tahir took nude images of their 16-year-old daughter and was blackmailing her into sleeping with his pals.

Elia also said in her police statement that Tahir was suspicious and beat her and the children physically and emotionally. She claimed that throughout the last 12 years, she had fled the house multiple times, but her parents had always interfered and rectified the situation.

According to Khyber News, Tahir admitted to setting a camera in the bathroom to watch his wife but then removed it and did not upload any footage. He also admitted to physically assaulting his wife and apparently intending to record his daughter before being caught.

The cops confiscated his phone and laptop, which are currently being investigated.

Conclusion

In conclusion, the constantly shifting dark web in May 2024 will likely be a platform for criminal activity, with cybercrime illegal product trading. It attempts to elude law enforcement remaining common. Understanding this underground marketplace for educational purposes emphasizes the constant conflict between criminal elements and police in the digital age.