Three Top Russian Cybercrime Forums Hacked

Over the past few weeks, three of the longest running and most venerated Russian-language online forums serving thousands of experienced cybercriminals have been hacked. In two of the intrusions, the attackers made off with the forums’ user databases, including email and Internet addresses and hashed passwords. Members of all three forums are worried the incidents could serve as a virtual Rosetta Stone for connecting the real-life identities of the same users across multiple crime forums.

References to the leaked Mazafaka crime forum database were posted online in the past 48 hours.

On Tuesday, someone dumped thousands of usernames, email addresses and obfuscated passwords on the dark web apparently pilfered from Mazafaka (a.k.a. “Maza,” “MFclub“), an exclusive crime forum that has for more than a decade played host to some of the most experienced and infamous Russian cyberthieves.

At the top of a 35-page PDF leaked online is a private encryption key allegedly used by Maza administrators. The database also includes ICQ numbers for many users. ICQ, also known as “I seek you,” was an instant message platform trusted by countless early denizens of these older crime forums before its use fell out of fashion in favor of more private networks, such as Jabber and Telegram.

This is notable because ICQ numbers tied to specific accounts often are a reliable data point that security researchers can use to connect multiple accounts to the same user across many forums and different nicknames over time.

Cyber intelligence firm Intel 471 assesses that the leaked Maza database is legitimate.

“The file comprised more than 3,000 rows, containing usernames, partially obfuscated password hashes, email addresses and other contact details,” Intel 471 found, noting that Maza forum visitors are now redirected to a breach announcement page. “Initial analysis of the leaked data pointed to its probable authenticity, as at least a portion of the leaked user records correlated with our own data holdings.”

The attack on Maza comes just weeks after another major Russian crime forum got plundered. On Jan. 20, a longtime administrator of the Russian language forum Verified disclosed that the community’s domain registrar had been hacked, and that the site’s domain was redirected to an Internet server the attackers controlled.

A note posted by a Verified forum administrator concerning the hack of its registrar in January.

“Our [bitcoin] wallet has been cracked. Luckily, we did not keep large amounts in it, but this is an unpleasant incident anyway. Once the circumstances became clear, the admin assumed that THEORETICALLY, all the forum’s accounts could have been compromised (the probability is low, but it is there). In our business, it’s better to play safe. So, we’ve decided to reset everyone’s codes. This is not a big deal. Simply write them down and use them from now on.”

A short time later, the administrator updated his post, saying:

“We are getting messages that the forum’s databases were filched after all when the forum was hacked. Everyone’s account passwords were forcibly reset. Pass this information to people you know. The forum was hacked through the domain registrar. The registrar was hacked first, then domain name servers were changed, and traffic was sniffed.”

On Feb. 15, the administrator posted a message purportedly sent on behalf of the intruders, who claimed they hacked Verified’s domain registrar between Jan. 16 and 20.

“It should be clear by now that the forum administration did not do an acceptable job with the security of this whole thing,” the attacker explained. “Most likely just out of laziness or incompetence, they gave up the whole thing. But the main surprise for us was that they saved all the user data, including cookies, referrers, ip addresses of the first registrations, login analytics, and everything else.”

Other sources indicate tens of thousands of private messages between Verified users were stolen, including information about bitcoin deposits and withdrawals and private Jabber contacts.

The compromise of Maza and Verified — and possibly a third major forum — has many community members concerned that their real-life identities could be exposed. Exploit — perhaps the next-largest and most popular Russian forum after Verified, also experienced an apparent compromise this week.

According to Intel 471, on March 1, 2021, the administrator of the Exploit cybercrime forum claimed that a proxy server the forum used for protection from distributed denial-of-service (DDoS) attacks might have been compromised by an unknown party. The administrator stated that on Feb. 27, 2021, a monitoring system detected unauthorized secure shell access to the server and an attempt to dump network traffic.

Some forum lurkers have speculated that these recent compromises feel like the work of some government spy agency.

“Only intelligence services or people who know where the servers are located can pull off things like that,” mused one mainstay of Exploit. “Three forums in one month is just weird. I don’t think those were regular hackers. Someone is purposefully ruining forums.”

Others are wondering aloud which forum will fall next, and bemoaning the loss of trust among users that could be bad for business.

“Perhaps they work according to the following logic,” wrote one Exploit user. “There will be no forums, there will be no trust between everyone, less cooperation, more difficult to find partners – fewer attacks.”

Update, March 4, 6:58 p.m. ET: Intel 471 says there was a fourth crime forum that got hit recently. From the blog post they just published on these events: “In February, the administrator of another popular cybercrime forum, Crdclub, announced the forum sustained an attack that resulted in the compromise of the administrator’s account. By doing so, the actor behind the attack was able to lure forum customers to use a money transfer service that was allegedly vouched for by the forum’s admins. That was a lie, and resulted in an unknown amount of money being diverted from the forum. The forum’s admins promised to reimburse those who were defrauded. No other information looked to be compromised in the attack.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Missing Teens Used School Laptops to Chat with Alleged Abductors

Missing Teens Used School Laptops to Chat with Alleged Abductors

Two teenage girls who went missing from the same North Carolina county used school-issued laptops to communicate with their alleged abductors. 

Savannah Grace Childress vanished on February 11 from her home on Canaan Church Road in Denton. The 14-year-old was found alive ten days later in Arkansas. 

Law enforcement officers investigating Childress’ disappearance discovered that the teen had been using a computer given to her by Davidson County Schools to chat with multiple people on various online platforms. 

The Alamance County Sheriff’s Office determined that one of the people Childress was in contact with—38-year-old William Ice, of Mercer County, Pennsylvania—had also been in communication with other girls in Alamance County. 

Believing that Ice took Childress from her home, the Davidson County Sheriff’s Office obtained warrants for his arrest on charges of first-degree kidnapping and soliciting a child by computer.

A multi-agency law enforcement operation tracked Ice to a McDonalds in Lonoke County, Arkansas, where officers found him seated with Childress in a red Durango. When ordered to exit the vehicle, Ice shot at officers before getting back into the car and fleeing.

State troopers gave chase, and the vehicle eventually hit a snowbank. While Childress exited the vehicle, Ice remained inside and turned his gun on himself. He died  at Little Rock Hospital on February 21. 

On February 16, 15-year-old Kayla Carlson vanished from the American Children’s Home in Lexington. Detectives with the Criminal Investigations Division discovered that Carlson had been picked up by 36-year-old Christopher Steele Boles, of Moore County.

Carlson met Boles in an online chatroom that she had accessed using her school-issued laptop. Six days after being reported missing, the teen was found in a motel in Aberdeen, Moore County.

Boles was arrested and charged with one count of abduction of children and one count of first-degree kidnapping and scheduled to appear in Lexington District Court on March 29. 

He was further charged with one count of possession of heroin, one count of possession of marijuana, and one count of possession of drug paraphernalia, for which he is scheduled to appear in Moore County District Court on April 5.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Canadian Cyber-Agency Workers Threaten Strike

Canadian Cyber-Agency Workers Threaten Strike

A dispute over wages could see workers at Canada’s equivalent of the United States’ National Security Agency stage a strike. 

The Public Service Alliance of Canada (PSAC), which represents 2,400 employees working in cryptography, applied mathematics, advanced language analysis, and cybersecurity at the Communications Security Establishment (CSE), voted last week to authorize a strike following a disagreement about changes to a wage supplement. 

The supplement—known as the market allowance—was put in place to make employees’ earnings high enough to compete with the kind of wages offered in the private sector. Union organizers have warned that making changes to the allowance could result in a dearth of talent that could potentially create a national security risk.

“CSE management is refusing to apply a wage increase to the portion of workers’ salaries that is made up of market allowances,” said Alex Silas, PSAC’s regional executive vice president for the National Capital Region.

“To give you an idea, for some of these workers [that] represents as much as 10 per cent of their annual income.”

Talks stalled on the collective agreement nearly two years ago. The Wall Street Journal reports that organizers are currently considering various tactics to persuade managers to accept the supplement, with a strike being the last resort. 

Eugene Stone, who has been employed by CSE for over two decades, said the agency may struggle to fill vacancies in the future because talented cybersecurity professionals are being snapped up by private companies. 

Stone, who heads a nine-person team tasked with vetting hardware and software purchased by the Canadian government, said: “There is a possibility [CSE] might not be able to fulfill our mandate because we don’t have the people to do it.”

About 2,900 people are employed by the CSE, which is responsible for foreign intelligence and cybersecurity.

“They perform vital work protecting Canada from foreign cyber-attacks, foreign hacking attempts,” Silas told CBC News.

“This past July, there was an attempt to hack Canadian COVID-19 research. These are the workers that stopped that.”

Christopher Williams, director general of CSE public affairs and communications services, said that “essential service agreements are in place to ensure that all areas of CSE have the people at work necessary to continue to provide for the safety and security of the public in the event of a strike.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

US Cybersecurity Firm Opens New Belfast Office

US Cybersecurity Firm Opens New Belfast Office

American cybersecurity firm Rapid7 has opened a new office in the heart of Northern Ireland’s capital city.

The company, which is headquartered in Boston, Massachusetts, serves over 9,100 customers through 14 different offices around the world.  

Rapid7’s newest digs, located in Belfast’s Chichester House, can accommodate up to 400 employees. The company said the major expansion will create up to 150 new jobs and internships in customer support, engineering, and development.

New employees will have access to much more than a desk as the site includes a ground-floor cafe, a library, a games room and a trendy bar featuring exposed brickwork and criss-crossing strings of lights. Additionally, staff can make use of a maker space kitted out with Lego, 3D printers, and Raspberry Pis.

Rapid7 currently has around 250 employees in Belfast but plans to grow this figure to 400. To fill the internship positions and recruit the next generation of automation experts and security analysts, the cybersecurity firm is collaborating with local universities. 

The expansion, which was first announced in March 2020, was supported by economic development agency Invest NI. To support the creation of 30 new jobs, Invest NI made available to Rapid7 £165,000.

Due to the outbreak of COVID-19, Rapid7’s employees are currently working from home. However, the new offices have been designed to meet government-issued guidelines regarding Covid-secure workplaces.

“We are committed to expanding our base within the Belfast cybersecurity hub, solidifying our position to help our European clients and to attract the best cybersecurity talent,” said Michael Keimig, global real estate senior manager at Rapid7.

“Our focus on providing a safe, comfortable and engaging workspace for our employees is a long-term goal of ours. We want this office to not only house our current employees, but also those we’ll be bringing on as part of future expansion in the region.

“As such, we intentionally designed the layout of the office to include enough space for 400 employees.”

Keimig added that the style of the new site had been chosen to blend in with Belfast’s existing vibe. 

“The mainstay in Rapid7’s office design is to create spaces that feel like an organic part of the city,” he said.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Microsoft: SolarWinds Attack Highlights Growing Sophistication of Nation State Actors

Microsoft: SolarWinds Attack Highlights Growing Sophistication of Nation State Actors

Microsoft has highlighted the increasingly sophisticated cyber-threat landscape, particularly as a result of the rise in nation state attacks.

During a session at the Microsoft Ignite event, the company outlined some of the trends it is seeing and actions it is taking to help mitigate them.

There has been marked rise in cyber-attacks detected by Microsoft over recent years, both from cyber-criminals and nation state actors, with the latter becoming a particular cause for concern. Tom Burt, CVP, customer security and trust, Microsoft, said that “we have seen an increase in the volume of attacks and in the sophistication of those attacks, and they’re led primarily by attacks emanating from Russia but also Iran, North Korea and China.”

The wide-ranging SolarWinds attack at the end of last year, allegedly perpetrated by Russia, has emphasized the increasingly dangerous digital environment that governments, businesses and individuals are operating in. Vasu Jakkal, corporate vice-president, Microsoft Security, Compliance and Identity at Microsoft, noted that this breach was “one of the most widespread and complex events in cybersecurity history,” and “it was a clear reminder of what we are all up against.”

Explaining how the incident occurred, Burt said that as Microsoft helped FireEye investigate the incident from early on, it discovered that the threat actor had compromised the build process for the SolarWinds Orion application, making the malware very hard to detect. This led to 18,000 Solarwinds customers around the world.

Burt added: “Then this actor picked a much smaller number of those infected companies to drop a second stage of malware and go in and conduct their espionage war.”

The enormous damage caused by this attack is something of a game-changer, with more offensive action required to disrupt nation state attacks. This is an area Microsoft is becoming involved in via its digital crimes unit, which is targeting nation state actors as well as cyber-criminals. Burt revealed this includes “taking away the infrastructure and resources they use to conduct their attacks.”

In this environment, cyber-incidents need to be treated more like conventional warfare, with rules of engagement established to ensure private individuals and organizations are not impacted in the way they were during SolarWinds. Burt explained: “We have a policy team that works with our government in the US and governments around the world to try and encourage governments to adopt enforceable rules of conduct that will describe and confine the activity of nation states in cyberspace so that citizens and enterprises are protected against these nation state attacks.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Telemarketing Biz Exposes 114,000 in Cloud Config Error

Telemarketing Biz Exposes 114,000 in Cloud Config Error

A US telemarketing company has leaked the personal details of potentially tens of thousands of consumers after misconfiguring a cloud storage bucket, Infosecurity can reveal.

A team at vpnMentor led by Noam Rotem found the unsecured AWS S3 bucket on December 24 last year. It was traced to Californian business CallX, whose analytics services are apparently used by clients to improve their media buying and inbound marketing.

According to its website, the firm counts lending marketplace Lendingtree, Liberty Mutual Insurance and smart security vendor Vivint among its customers.

Rotem found 114,000 files left publicly accessibly in the leaky bucket. Most of these were audio recordings of phone conversations between CallX clients and their customers, which were being tracked by the firm’s marketing software. An additional 2000 transcripts of text chats were also viewable.

Personally identifiable information (PII) contained in these files included full names, home addresses, phone numbers and more.

With the leaked data, attackers could launch convincing phishing, fraud and vishing attacks, warned vpnMentor.

“If cyber-criminals needed additional information, they could hijack calls logged by CallX and do fake ‘follow-up’ phone calls or emails posing as a representative of the relevant CallX client company,” it claimed.

“Using the transcripts, it would be easy to establish trust and legitimacy with targets in such schemes. As the people exposed have no apparent relationship to one another, by the time the fraud was discovered, it may be too late.”

CallX may also be at risk of regulatory scrutiny as it’s under the jurisdiction of new Californian privacy law CCPA.

Unfortunately, the bucket remains open at the time of writing. Both Infosecurity and vpnMentor have tried to contact CallX with no response. The research team first reached out to the firm on January 3 2021 and then to AWS on January 6. The cloud provider is also believed to have contacted CallX about the leak, and the US-CERT has been informed.

Misconfiguration of cloud storage isn’t just a security issue, it can quickly become a major business risk.

“Due to the bad publicity a data breach like this can create, CallX’s clients may distance themselves from the company and switch to rival software providers,” warned vpnMentor. “Those same rivals could exploit the breach to lure CallX clients away through negative marketing campaigns.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Password Reuse at 60% as 1.5 Billion Combos Discovered Online

Password Reuse at 60% as 1.5 Billion Combos Discovered Online

A security vendor discovered nearly 1.5 billion breached log-in combos circulating online last year and billions more pieces of personal information (PII), with password reuse and weak hashing algorithms commonplace.

SpyCloud’s 2021 Credential Exposure Report was compiled from the vendor’s human intelligence efforts to recover stolen data from criminal networks early in the breach lifecycle.

Some 854 breach incidents, up a third from 2019, leaked on average 5.4 million records each.

Poor password security is still rife: for users with more than one password stolen last year, SpyCloud found that 60% of credentials were reused across multiple accounts, exposing them to credential stuffing and other brute force tactics.

For the 270,000 .gov emails recovered, password reuse was even higher, at 87%.

Nearly two million passwords contained “2020” while almost 200,000 featured COVID-related keywords like “corona” and “pandemic.”

As usual, the most common password was “123456,” followed by “123456789” and “12345678.” “Password” and “111111” also appeared more than 1.2 million times each.

However, in some cases, the blame lay with the organizations tasked with protecting their customers’ personal data and logins. SpyCloud found that a third (32%) of breached passwords used the weak MD5 algorithm and 22% used SHA1. In addition, only 17% of passwords were salted.

The security firm also recovered over 4.6 billion pieces of PII including names, addresses, birthdates, job titles and social media URLs. This trove featured 1.3 billion phone numbers, the most common piece of PII found.

The findings represent a major security risk for both individual consumers and businesses, given that many credentials and email addresses are being used across corporate and personal spheres.

“These staggering numbers indicate a continued threat for account takeovers, identity theft and fraud at a time when people have been spending more time online during the COVID-19 pandemic,” said David Endler, co-founder of SpyCloud.

“Criminals didn’t stop for the coronavirus. In fact, attackers have been able to use the disruption of the pandemic to their advantage.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Microsoft Patches Four Zero-Day Exchange Server Bugs

Microsoft Patches Four Zero-Day Exchange Server Bugs

Microsoft has been forced to release out-of-band patches to fix multiple zero-day vulnerabilities being exploited by Chinese state-backed threat actors.

The unusual step was taken to protect customers running on-premises versions of Microsoft Exchange Server.

“In the attacks observed, the threat actor used these vulnerabilities to access on-premises Exchange servers which enabled access to email accounts, and allowed installation of additional malware to facilitate long-term access to victim environments,” Microsoft said.

“Microsoft Threat Intelligence Center (MSTIC) attributes this campaign with high confidence to Hafnium, a group assessed to be state-sponsored and operating out of China, based on observed victimology, tactics and procedures.”

The four zero-days are: server-side request forgery bug CVE-2021-26855, post-authentication arbitrary file write flaws CVE-2021-27065 and CVE-2021-26858, and CVE-2021-26857, which is an insecure deserialization vulnerability in the Unified Messaging service.

Combined, the vulnerabilities could allow attackers to authenticate as the Exchange server, run code as System and write a file to any path on the server. After exploiting the four bugs, the attackers are said to deploy web shells which allow them to steal data and perform additional malicious actions to further compromise their targets.

Hafnium actors usually work from leased virtual private servers in the US, primarily targeting sectors in the country such as infectious disease research, legal, higher education, defense, policy think tanks and NGOs, according to Microsoft.

“Hafnium has previously compromised victims by exploiting vulnerabilities in internet-facing servers, and has used legitimate open source frameworks, like Covenant, for command and control. Once they’ve gained access to a victim network, Hafnium typically exfiltrates data to file sharing sites like Mega,” it said.

“In campaigns unrelated to these vulnerabilities, Microsoft has observed Hafnium interacting with victim Office 365 tenants. While they are often unsuccessful in compromising customer accounts, this reconnaissance activity helps the adversary identify more details about their targets’ environments.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

BlueVoyant Appoints James M. Aquilina as Advisor

BlueVoyant Appoints James M. Aquilina as Advisor

Cybersecurity company BlueVoyant has appointed James M. Aquilina as a member of its advisory board and advisor to the CEO.

Aquilina comes with over 20 years of experience in the cybersecurity industry, including in the areas of incident response, risk management and digital forensics. He was most recently an advisor to the board of directors at The Crysis Group in the run up to its acquisition by Palo Alto Networks, and prior to this, he was president of Aon Global Cyber Solutions at Stroz Friedberg.

He has also previously served as an assistant US attorney in the Criminal Division of the US Attorney’s Office for the Central District of California. In this role, he conducted investigations into various types of cybercrime, including denial of service (DOS) attacks and internet fraud.

Additionally, Aquilina is a regular commentator on cybersecurity topics, having been quoted in numerous mainstream news outlets and has spoken at prestigious organizations including the International Law Enforcement Academy and Interpol.

Commenting on his appointment, Aquilina said: “There is enormous need for what BlueVoyant brings to the table. The company’s innovative cybersecurity solutions go beyond identifying cyber-risks, allowing clients to mitigate threats across their environment and in the supply chain, to create a solid security posture, and to promote a pervasive cyber-resilient culture. I’m thrilled to be working with BlueVoyant.”

Aquilina is the latest high profile cybersecurity appointment by BlueVoyant as the firm looks to continue its recent growth. In September 2020, it revealed Deborah Plunkett and Ariel Litvin had joined its board of directors while Ronald Moultrie became vice-president of its advisory board.

Jim Rosenthal, co-founder and CEO at BlueVoyant, added: “As we continue to scale our operations and fuel growth, our initiatives require a strategic, long-term revenue-focused executive to help us stand out in the crowded cybersecurity market. James brings a superior blend of executive leadership and cybersecurity credentials that will help us expand our business as we continue to bring our unique cybersecurity services to organizations looking to drive maximum value and create a cyber-resilient culture.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk