Russian Cybercrime Forums Open Doors to Chinese-Speakers

Russian Cybercrime Forums Open Doors to Chinese-Speakers

Security researchers have started to see a thawing of relations between Russian and Chinese and English-speaking threat actors.

The Russian-speaking cybercrime world has hitherto been fairly closed to actors from other regions. However, Flashpoint claimed to have seen a more inclusive approach adopted of late, especially on the Ramp forum.

“In October, Ramp administrators made changes to the forum’s interface that make it more accessible to Chinese-speaking and English-speaking threat actors,” the threat intelligence firm claimed.

“Forum sections are now in Russian, English, and Mandarin; the main administrator is addressing members in English more often than before; and there is noticeably more English content and comments – and even coming from some Russian-speaking actors.”

There are said to be around 30 Chinese users on the forum thus far.

However, although Russian cyber-criminals may seek international alliances, Flashpoint warned that the moves might be a smokescreen similar to those surrounding the Groove ransomware gang.

“In late October 2021, the Groove ransomware gang called on other ransomware operators to jointly attack US entities; once this generated media attention, the operator of Groove’s public blog claimed that it was a media hack,” it said.

“It is certainly possible that Ramp’s overture to Chinese-speaking threat actors is part of a similar strategy.”

That said, other Russian-speaking forums also appear to be warming to international users.

On notorious site XSS, one user apparently replied to a thread with a Chinese-language ad looking for partners in a ransomware operation. In another case, a Russian XSS member greeted two Chinese forum members with a message in machine-translated Mandarin.

Threat actors are typically more willing to share tactics, techniques and procedures (TTPs) than their counterparts in the legitimate economy. However, the pooling of capability and intelligence across traditionally distinct cybercrime spheres would be a particularly unwelcome development.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Threat Actors Discuss Leasing Zero-Day Exploits

Threat Actors Discuss Leasing Zero-Day Exploits

Ransomware gangs can now afford to pay as much as $10m for zero-day exploits, but for those without the money, developers have discussed renting out malicious code, according to Digital Shadows.

The threat intelligence firm’s new report ⁠–⁠ Vulnerability Intelligence, Do You Know Where Your Flaws Are? ⁠–⁠ is based on a detailed analysis of the cybercrime underground.

It confirmed that ransomware actors are now wealthy enough to compete with state-backed operatives in buying zero-days.

“These prices can appear enormous but there‘s a key aspect to keep in mind. Whatever legitimate bug bounty programs offer — and we’ve often seen them offering multimillion-dollar bounties before ⁠–⁠ cyber-criminals must offer more in order to compete with them, given the risks (jail time) and additional requirements needed during illicit activity (i.e. money laundering),” the report claimed.

However, while there are easy pickings from exploiting exposed RDP appliances and phishing users, these actors are unlikely to spend big at present, it added.

For those without that kind of money, there’s another option ⁠–⁠ Digital Shadows also observed cyber-criminals discussing a potential “exploit-as-a-service” model.

“This model would allow capable threat actors to ‘lease’ zero-day exploits to other cyber-criminals to conduct cyber-attacks. In fact, while a developer can generate large profits when selling a zero-day exploit, it often takes them a significant amount of time to complete such a sale,” it explained.

“However, this model enables zero-day developers to generate substantial earnings by renting the zero-day out while waiting for a definitive buyer. Additionally, with this model, renting parties could test the proposed zero-day and later decide whether to purchase the exploit on an exclusive or non-exclusive basis.”

That said, legacy vulnerabilities still offer fertile hunting ground for most threat actors, who are even sharing databases of target organizations that have not patched specific systems such as Microsoft Exchange.

According to the report, the cybercrime community is adept at information sharing in this regard, with older members imparting wisdom to help novice threat actors.

“Besides sharing tutorials, experienced, trusted users often provide reviews of their preferred (or least favorite) tool on the market, just like any other good consumer would,” the report claimed.

“Reviews cover everything from vulnerability-scanning tools to online bulletproof-hosting services, and many include detailed descriptions of how they work. These diligent reviewers are helping their peers identify relevant products for exploitation and make more informed decisions.”

However, there’s no honor among thieves, with Digital Shadows also observing threat actors attempting to troll or scam fellow forum members.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

NSA Grants Boost University’s Cyber Academy

NSA Grants Boost University’s Cyber Academy

The University of North Georgia (UNG) has grown its cybersecurity training program after receiving funding from the National Security Agency (NSA). 

UNG, which has campuses in Blue Ridge, Cumming, Dahlonega, Gainesville, and Oconee, was awarded two grants totaling $265,000 by the NSA.

The university will use the money to provide free cybersecurity instruction through two different avenues: the GenCyber Warrior Academy and the Advancing GenCyber Education for North Georgia Teachers (AGENTs) of Change camp.

Both training programs are in-person learning opportunities in the Pennington Military Leadership Center on UNG’s Dahlonega Campus.

The first initiative provides cybersecurity instruction to high school students, while the second delivers cybersecurity training to middle or high school teachers. 

Next summer, in its sixth year of operation, the annual GenCyber Warrior Academy will host 40 high school students from June 5–11. AGENTs of Change, which will run for the second time from June 27–July 1, will give 24 teachers more than 30 hours of cyber and computer science professional development.

For the first time in 2022, UNG faculty and staff will provide additional monthly pre-academy instruction sessions that will start in January and post-camp guidance that will extend into October. 

This increase in tuition and learning materials was made possible through the record-breaking grants from the NSA.

“The new year-round format gives us an opportunity to share more content and background to get everybody up to the same level,” said Dr. Bryson Payne, professor of computer science at UNG and coordinator of the university’s cyber programs.

“Before they come to camp, they’ll already have done some valuable hands-on activities. The post-camp activities will help them keep their skills sharp.”

Dr. Lindsay Linsky, associate professor of middle grades education and assistant director of UNG’s Center for Teaching, Learning and Leadership, said the AGENTs of Change gave teachers an important opportunity. 

“This may be one of their first chances to learn about how to teach cyber,” said Linsky. “There’s a need for more teachers to understand what cybersecurity is and how to teach it ethically to their students.”

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

New Partnership to Invest in Cybersecurity Startups

New Partnership to Invest in Cybersecurity Startups

A new business collaboration is bringing startup expertise and funding to cybersecurity companies.

In a press conference held Tuesday, San Antonio, Texas-based company Geekdom announced that it is partnering with gener8tor, a nationally ranked accelerator company based in Wisconsin, to launch a program to help cybersecurity companies develop products for the market. 

The 12-week program will launch in San Antonio in the summer of 2022. Within the first year of its launch, five startup companies will be selected to complete the program and receive an investment of $100,000 each.

A further ten companies are slated to receive accelerator investment funding via the program in 2023. 

“I am beyond excited about what’s happening,” said San Antonio’s mayor, Ron Nirenberg.

“Now we have gener8tor providing the fuel for the startup community to continue to catalyze cybersecurity in San Antonio. The excitement is real.”

Geekdom provides a co-working space located in downtown San Antonio along with resources and opportunities to help create and develop businesses.

“We are part of the transformation that is occurring right as we watch,” said Graham Weston, who founded Geekdom and the web-hosting and cloud-computing company Rackspace Technology.

He added: “Every single day, we need to be working on building innovation in the city, and on having ideas fertilized, encouraged, accelerated.”

Troy Vosseller, the co-founder of gener8tor, said that the accelerator aimed to disrupt the current trend in which venture capital money is concentrated in California, New York, and Massachusetts.

“Our focus is on these secondary markets outside of Silicon Valley,” said Vosseller, “The San Antonio community is doubling down on its strengths. Cybersecurity, with the assets that exist here, is exactly the smart strategy.”

The program will be open to startups located in America and abroad.

“We anticipate hundreds of applicants, from which we’ll narrow that down to the top five,” said Vosseller.

“They’ll be spending three months here, during which time we’re connecting them with mentors, customers, corporate partners, the cybersecurity assets that exist here as well as investors.”

He said the program will explore how to help the selected companies “relocate and have a significant presence here in San Antonio for the long term.”

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Spear-Phishing Campaign Exploits Glitch Platform to Steal Credentials

Threat actors are targeting Middle-East-based employees of major corporations in a scam that uses a specific ‘ephemeral’ aspect of the project-management tool to link to SharePoint phishing pages.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains