US Offers $10m Reward to Unmask DarkSide Leaders

US Offers $10m Reward to Unmask DarkSide Leaders

The US State Department has offered $10m to anyone able to help reveal the identity or location of “leaders” of the DarkSide ransomware group.

In a first for the government, the department also said it would offer $5m for information “leading to the arrest and/or conviction in any country of any individual conspiring to participate in or attempting to participate in a DarkSide variant ransomware incident.”

The group most famously was responsible for the Colonial Pipeline outage earlier this year, which forced gas prices up and led to fuel shortages up and down the US East Coast.  

“In offering this reward, the United States demonstrates its commitment to protecting ransomware victims around the world from exploitation by cyber-criminals,” the statement noted.

“The United States looks to nations who harbor ransomware criminals that are willing to bring justice for those victim businesses and organizations affected by ransomware.”

The reward is being offered under the department’s Transnational Organized Crime Rewards Program (TOCRP), which has apparently paid out $135m and helped to bring over 75 criminals to justice since 1986.

Jake Williams, co-founder and CTO at BreachQuest, said the move was long overdue and would help to drive a wedge between threat actors, following news of disruption of the REvil group by law enforcement.

“As ransomware operators have adopted an affiliate model for operations, the number of people they must place trust in, even at arm’s length, has increased dramatically. With rewards this large, there’s a substantial incentive for these criminals to turn on one another,” he argued.

“Perhaps more importantly than the specific impacts to DarkSide, this action undermines trust across the ransomware as a service affiliate model.”

However, John Bambenek, principal threat hunter at Netenrich, was more pessimistic, arguing that even if a threat actor were unmasked, they would likely remain safe from US prosecutors if harbored somewhere like Russia.

“Absent a bounty hunter willing to travel to their jurisdiction, put their unconscious body in a bag and dumping it at the nearest US embassy, I doubt this will have much of an impact,” he claimed.

“To be fair, it certainly won’t hurt either. I just don’t expect to see any press conference with the secretary of state handing out a large, cardboard $10m check anytime soon.”

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Facial Recognition Firm Could Be Ordered to “Close” in UK, Warn Experts

Facial Recognition Firm Could Be Ordered to “Close” in UK, Warn Experts

Controversial facial recognition firm Clearview AI will most likely be required to dramatically scale back operations in the UK, following a joint investigation by the UK and Australian privacy regulators, experts have claimed.

After an investigation lasting over 15 months, the Office of the Australian Information Commissioner (OAIC) released its ruling on Tuesday. It said the New York-based firm had breached Australians’ privacy by scraping their images from the web without their knowledge and disclosing them through its facial recognition tool.

It ordered the firm to stop collecting these photos and delete all pictures of Australian citizens in a database said to contain as many as three billion images. That would effectively close down its operations in the country.

The UK’s Information Commissioner’s Office (ICO) released only an anodyne statement saying it is “considering its next steps and any formal regulatory action that may be appropriate under the UK data protection laws.”

However, it’s likely to take the same line as its Australian counterpart, argued Jonathan Armstrong of compliance specialist Cordery.

“The ICO/OAIC investigation found that Clearview AI had behaved unlawfully in part because its data processing was not transparent. Transparency is a key theme of GDPR – more than €1bn worth of GDPR fines relate to the breach of the transparency obligations under GDPR,” he explained.

“The ICO has not yet announced the measures it will take. We can assume that the ICO is contemplating a similar order relating to the UK as GDPR has similar powers in GDPR Art. 58(2). The ICO has used these powers previously in an enforcement notice against HMRC in 2019.”

The regulators are also continuing their probe into the use of Clearview AI by police forces to identify individuals in the two countries.

The ICO has previously expressed “serious concerns” about law enforcers’ use of facial recognition tech but has thus far done little except remind police that it should be done lawfully, whilst calling for a statutory code of practice to be introduced.

In the meantime, last year saw police use of facial recognition technology ruled unlawful for the first time globally, after a UK Court of Appeal decision.

For its part, Clearview AI reportedly intends to appeal the OAIC’s decision, claiming it operates legitimately in Australia.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Ukraine Unmasks Armageddon Group as FSB Officers

Ukraine Unmasks Armageddon Group as FSB Officers

Ukrainian special services claim to have identified the operatives behind the prolific “Armageddon” hacking group, alleging they are Russian FSB officers.

In a brief statement, the Security Service of Ukraine (SSU) revealed that the group, also known as “Garmaredon,” was responsible for over 5000 attacks on the Ukrainian government and critical infrastructure assets.

It targeted 1500 government computer systems intending to steal sensitive information relating to security and defense and blocking information systems, as well as attacking power plants and heat and water systems, the SSU said.

The five were reportedly members of the Crimean FSB before defecting to the Russian side after the invasion of the Ukrainian peninsula in 2014. As a result, they’re being accused of treason and espionage, malware development and interference with computers.

The SSU said it had managed to unmask the individuals despite their use of FSB tools to stay hidden online.

“The Armageddon hacker group is an FSB special project, which specifically targeted Ukraine,” it said. “This ‘line of work’ is coordinated by the FSB’s 18th Center (Information Security Center) based in Moscow.”

Although the individuals have not been arrested, the SSU will be hoping to send a signal to the FSB with this notice.

The security service also released a detailed technical document highlighting the group’s TTPs, including exploitation of legacy Windows vulnerabilities, malware loaded onto removable media, the EvilGnome Linux backdoor and a custom RAT dubbed “Pteranodon.”

John Hultquist, VP of intelligence analysis at Mandiant, explained that Armageddon has also been observed attacking global targets.

“Due to the ongoing conflict, Ukraine has born early witness to many of Russia’s most aggressive cyber-attack capabilities, from the ability to knock power offline to the earliest versions of the fake ransomware that eventually became NotPetya,” he added.

“If we want to see what’s coming next, we have to be mindful of the lessons already being learned in Ukraine and other countries where cyberattacks are frequent and evolving.”

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Bowser to Pay Nintendo $4.5M Restitution

Bowser to Pay Nintendo $4.5M Restitution

The alleged leader of the hacking group Team-Xecuter has reportedly admitted taking part in a piracy conspiracy against Japanese gaming giant Nintendo.

Canadian national Gary Bowser, who is also known as GaryOPA, was arrested in October last year on suspicion of creating and selling illegal circumvention devices that enabled users to hack video game consoles so they could be used to play pirated copies of authentic gaming titles. 

Consoles against which the device was effective included the Nintendo Switch, the Nintendo 3DS, the Nintendo Entertainment System Classic Edition, the Sony PlayStation Classic, and the Microsoft Xbox.

In April 2021, Nintendo of America’s president, Doug Bowser (no relation), filed a lawsuit against Gary Bowser accusing the Canadian of running a “pirate operation” that infringed upon Nintendo’s copyright by creating and selling hacks. 

Gary Bowser, aged 52, was charged with 11 felony counts, including conspiracy to commit wire fraud, wire fraud, conspiracy to circumvent technological measures and to traffic in circumvention devices, trafficking in circumvention devices, and conspiracy to commit money laundering. His alleged conspirator, Frenchman Max Louarn, faces the same charges.

Bowser was deported to the US after his arrest in the Dominican Republic in September 2020. While initially denying the allegations, Bowser has now reportedly entered into a plea agreement in which he admits his part in the conspiracy and agrees to pay Nintendo restitution of $4.5m.

The plea agreement states that Bowser “knowingly and willfully participated in a cyber-criminal enterprise that hacked leading gaming consoles and that developed, manufactured, marketed, and sold a variety of circumvention devices that allowed the enterprise’s customers to play pirated versions of copyrighted video games, commonly referred to as ‘ROMs’” between June 2013 and his arrest in 2020.

“While Bowser may not have kidnapped a princess this time, his conviction means that his acts of piracy against Nintendo’s bottom line are not going unpunished,” commented John Bambenek, principal threat hunter at Netenrich, a San Jose, California–based digital IT and security operations company, referencing the perennial Super Mario villain also named Bowser.

“While he will pay a hefty sum, it certainly beats the alternative of being dropped into lava, which is the customary fate given to the bad guys in Nintendo’s world.”

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

BrakTooth Bluetooth Bugs Bite: Exploit Code, PoC Released

CISA is urging vendors to patch, given the release of public exploit code & a proof of concept tool for bugs that open billions of devices – phones, PCs, toys, etc. – to DoS & code execution.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains