Dark Web User Numbers Spiked During #COVID19 Lockdown

Dark Web User Numbers Spiked During #COVID19 Lockdown

The volume of dark web forum members is on the rise, with visitor numbers surging 44% during the first COVID-19 lockdowns last year, according to new data from Sixgill.

The cyber-intelligence firm analyzed five popular English and Russian language forums to better understand their popularity over time and who is responsible for most activity.

Collating data from the launch of each forum through to the end of 2020, Sixgill found that all five sites had grown their membership exponentially without impacting each other’s popularity.

Although some grew faster than others, and some months were more successful, the overall trend points towards a continued rise in the number of users visiting dark web sites, the firm concluded.

This matters, because as the population of the dark web increases, so does criminal activity, according to Sixgill security research lead, Dov Lerner.

More interesting still was the fact that user numbers soared into double-digits from January to spring 2020, before reverting to pre-COVID numbers.

“Prior Sixgill reports have noted a tremendous uptick in specific types of cybercrime on the underground during the COVID lockdowns. This includes gaming store accounts, compromised RDP credentials, money laundering services and narcotics. This research demonstrates that the number of participants in the cyber-underground spiked at the time as well,” explained Lerner.

“Why would coronavirus lockdowns lead to a massive increase in users of dark web forums? Some of these users were bored at home and decided to go exploring. Others may have been interested in turning to crime amid the economic shocks from the pandemic and the widely covered proliferation of cybercrime targeting remote workers, such as ransomware and phishing.”

The research also revealed that while user numbers are growing, only a small number seem to be responsible for the vast majority of posts. In fact, the top 20% of frequent posters generated 73% of posts.

This may be due to large numbers of inexperienced threat actors coming merely to observe but not participate in activity, or that experienced users are creating “burner” accounts to post from a new username each time, Lerner argued.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Most Public Sector Victims Refuse to Pay Ransomware Gangs

Most Public Sector Victims Refuse to Pay Ransomware Gangs

The public sector is leading the way on ransomware resilience and refusing to pay its attackers, according to new research from Veritas.

The data management firm polled 2690 IT execs at companies of over 1000 employees to compile its 2020 Ransomware Resiliency Report.

It found that 86% of public sector respondents targeted with ransomware refused to pay, compared to an average of 43% across all verticals.

This is linked to the fact that these organizations were more likely to be able to bounce back quickly from an incident, recovering over 90% of their data versus an average of 69% across all sectors, the study revealed.

Veritas claimed that this enhanced resilience to ransomware can be partly explained by the relative simplicity of public sector cloud environments.

Organizations in this vertical use just 6.43 cloud services on average, the lowest of any vertical and almost half the global average of 11.73, the vendor argued. Only 5% of government organizations run more than 20 cloud services, versus a sector-wide average of 16%.

The backup specialist noted that 46% of public sector organizations have been hit by ransomware infection at least once in the past, with 9% facing three to five attacks. This chimes with findings from Coveware, which put the sector second overall in Q3 2020, accounting for 11.6% of total attacks and behind only professional services (25.2%).

However, the digital transformation push sparked by the COVID-19 crisis may yet increase the organizational attack surface and complexity for public sector bodies, as they ramp up cloud adoption.

“Importantly, this process hasn’t finished yet and the public sector remains one of the most attractive ransomware targets around. It’s almost inevitable that with time, the complexity of cloud within public sector organizations will grow,” argued Veritas UK&I director for public sector, Andy Warren.

“Now is the time for these IT departments to make sure they’ve got the full visibility and control over that data so they can remain as prepared in the future as they are now.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

US: Fewer Than 10 Govt Agencies Hit by SolarWinds Attack

US: Fewer Than 10 Govt Agencies Hit by SolarWinds Attack

The US government has, for the first time, attributed the SolarWinds cyber-espionage attacks to Russia, and clarified that fewer agencies have been affected than some first thought.

A lengthy joint statement from the FBI, NSA, the Office of the Director of National Intelligence (ODNI) and the Cybersecurity and Infrastructure Security Agency (CISA) claimed the attack was primarily an intelligence-gathering operation, “likely Russian in origin.”

While those in the cybersecurity community have always been fairly certain that the attack was indeed one focused on data theft, this confirmation could be viewed as an attempt to silence conspiracy theorists who have tried to tie it to debunked accusations of election fraud in November.

It’s unclear why it has taken the US authorities this long to name Russia: a New York Times report published as the news first broke had insiders naming APT29, or Cozy Bear, as the culprit.

The APT group has been linked to the Russian Foreign Intelligence Service (SVR) and KGB successor the Federal Security Service (FSB), and has been blamed for previous attacks on the Democratic National Committee (DNC) in 2016 and COVID-19 vaccine stakeholders last year.

Interestingly, the Cyber Unified Coordination Group (UCG) — a task force set up by the NSA, FBI, CISA and ODNI to mange the fall-out of the attacks — claimed that fewer than 10 US government agencies were caught in the campaign, a lower number than that previously reported by some media.

“This is a serious compromise that will require a sustained and dedicated effort to remediate. Since its initial discovery, the UCG, including hardworking professionals across the United States government, as well as our private sector partners, have been working non-stop,” the statement noted.

“These efforts did not let up through the holidays. The UCG will continue taking every necessary action to investigate, remediate and share information with our partners and the American people.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Backdoor in Zyxel Firewalls and Gateways

This is bad:

More than 100,000 Zyxel firewalls, VPN gateways, and access point controllers contain a hardcoded admin-level backdoor account that can grant attackers root access to devices via either the SSH interface or the web administration panel.

[…]

Installing patches removes the backdoor account, which, according to Eye Control researchers, uses the “zyfwp” username and the “PrOw!aN_fXp” password.

“The plaintext password was visible in one of the binaries on the system,” the Dutch researchers said in a report published before the Christmas 2020 holiday.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk