Normal view
-
TechCrunch - Dark Web
- Fraud as a service: Scammers are using encrypted messaging to undercut BNPL revenue
Fraud as a service: Scammers are using encrypted messaging to undercut BNPL revenue
-
TechCrunch - Dark Web
- Don’t buy a breach or a bad reputation: A more effective approach to M&A due diligence
Don’t buy a breach or a bad reputation: A more effective approach to M&A due diligence
-
TechCrunch - Dark Web
- NetWalker ransomware operator extradited to the US, over $28M in bitcoin seized
NetWalker ransomware operator extradited to the US, over $28M in bitcoin seized
FIN7 hackers set up a fake company to recruit for cyberattacks
Ring’s latest security updates are good, but still opt-in
-
TechCrunch - Dark Web
- This crowdsourced payments tracker wants to solve the ransomware visibility problem
This crowdsourced payments tracker wants to solve the ransomware visibility problem
Fujifilm becomes the latest victim of a network-crippling ransomware attack
-
TechCrunch - Dark Web
- DOJ says it seized over $1 billion in bitcoin from the Silk Road drugs marketplace
DOJ says it seized over $1 billion in bitcoin from the Silk Road drugs marketplace
Maze, a notorious ransomware group, says it’s shutting down
One of the most active and notorious data-stealing ransomware groups, Maze, says it is “officially closed.”
The announcement came as a waffling statement, riddled with spelling mistakes and published on its website on the dark web, which for the past year has published vast troves of stolen internal documents and files from the companies it targeted, including Cognizant, cybersecurity insurance firm Chubb, pharmaceutical giant ExecuPharm, Tesla and SpaceX parts supplier Visser and defense contractor Kimchuk.
Where typical ransomware groups would infect a victim with file-encrypting malware and hold the files for a ransom, Maze gained notoriety for first exfiltrating a victim’s data and threatening to publish the stolen files unless the ransom was paid.
It quickly became the preferred tactic of ransomware groups, which set up websites — often on the dark web — to leak the files it stole if the victim refused to pay up.
Maze initially used exploit kits and spam campaigns to infect its victims, but later began using known security vulnerabilities to specifically target big-name companies. Maze was known to use vulnerable virtual private network (VPN) and remote desktop (RDP) servers to launch targeted attacks against its victim’s network.
Some of the demanded ransoms reached into the millions of dollars. Maze reportedly demanded $6 million from one Georgia-based wire and cable manufacturer, and $15 million from one unnamed organization after the group encrypted its network. But after COVID-19 was declared a pandemic in March, Maze — as well as other ransomware groups — promised to not target hospitals and medical facilities.
But security experts aren’t celebrating just yet. After all, ransomware gangs are still criminal enterprises, many of which are driven by profit.
A statement by the Maze ransomware group, claiming it has shut down. Screenshot: TechCrunch
“Obviously, Maze’s claims should be taken with a very, very small pinch of salt,” said Brett Callow, a ransomware expert and threat analyst at security firm Emsisoft. “It’s certainly possible that the group feels they have made enough money to be able to close shop and sail off into the sunset. However, it’s also possible — and probably more likely — that they’ve decided to rebrand.”
Callow said the group’s apparent disbanding leaves open questions about the Maze group’s connections and involvement with other groups. “As Maze was an affiliate operation, their partners in crime are unlikely to retire and will instead simply align themselves with another group,” he said.
Maze denied that it was a “cartel” of ransomware groups in its statement, but experts disagree. Steve Ragan, a security researcher at Akamai, said Maze was known to post on its website data from other ransomware, like Ragnar Locker and the LockBit ransomware-for-hire.
“For them to pretend now that there was no team-up or cartel is just plain backwards. Clearly these groups were working together on many levels,” said Ragan.
“The downside to this, and the other significant element, is that nothing will change, Ransomware is still going to be out there,” said Ragan. “Criminals are still targeting open access, exposed RDP [remote desktop protocol] and VPN portals, and still sending malicious emails with malicious attachments in the hope of infecting unsuspecting victims on the internet,” he said.
Jeremy Kennelly at FireEye’s Mandiant threat intelligence unit said that while the Maze brand may be dead, its operators are likely not gone for good.
“We assess with high confidence that many of the individuals and groups that collaborated to enable the Maze ransomware service will likely continue to engage in similar operations — either working to support existing ransomware services or supporting novel operations in the future,” said Kennelly.
Maze, a notorious ransomware group, says it’s shutting down by Zack Whittaker originally published on TechCrunch
Cyber threat startup Cygilant hit by ransomware
Cygilant, a threat detection cybersecurity company, has confirmed a ransomware attack.
Christina Lattuca, Cygilant’s chief financial officer, said in a statement that the company was “aware of a ransomware attack impacting a portion of Cygilant’s technology environment.”
“Our Cyber Defense and Response Center team took immediate and decisive action to stop the progression of the attack. We are working closely with third-party forensic investigators and law enforcement to understand the full nature and impact of the attack. Cygilant is committed to the ongoing security of our network and to continuously strengthening all aspects of our security program,” the statement said.
Cygilant is believed to be the latest victim of NetWalker, a ransomware-as-a-service group, which lets threat groups rent access to its infrastructure to launch their own attacks, according to Brett Callow, a ransomware expert and threat analyst at security firm Emsisoft.
The file-encrypting malware itself not only scrambles a victim’s files but also exfiltrates the data to the hacker’s servers. The hackers typically threaten to publish the victim’s files if the ransom isn’t paid.
A site on the dark web associated with the NetWalker ransomware group posted screenshots of internal network files and directories believed to be associated with Cygilant.
Cygilant did not say if it paid the ransom. But at the time of writing, the dark web listing with Cygilant’s data had disappeared.
“Groups permanently delist companies when they’ve paid or, in some cases, temporarily delist them once they’ve agreed to come to the negotiating table,” said Callow. “NetWalker has temporarily delisted pending negotiations in at least one other case.”
Cyber threat startup Cygilant hit by ransomware by Zack Whittaker originally published on TechCrunch
Decrypted: iOS 13.5 jailbreak, FBI slams Apple, VCs talk cybersecurity
It was a busy week in security.
Newly released documents shown exclusively to TechCrunch show that U.S. immigration authorities used a controversial cell phone snooping technology known as a “stingray” hundreds of times in the past three years. Also, if you haven’t updated your Android phone in a while, now would be a good time to check. That’s because a brand-new security vulnerability was found — and patched. The bug, if exploited, could let a malicious app trick a user into thinking they’re using a legitimate app that can be used to steal passwords.
Here’s more from the week.
THE BIG PICTURE
Every iPhone now has a working jailbreak
Decrypted: iOS 13.5 jailbreak, FBI slams Apple, VCs talk cybersecurity by Zack Whittaker originally published on TechCrunch
ICE used ‘stingray’ cell phone snooping tech hundreds of times since 2017
Newly released documents show U.S. immigration authorities have used a secretive cell phone snooping technology hundreds of times across the U.S. in the past three years.
The documents, obtained through a public records lawsuit by the American Civil Liberties Union and seen by TechCrunch, show that U.S. Immigration and Customs Enforcement (ICE) deployed cell site simulators — known as stingrays — at least 466 times between 2017 and 2019, which led to dozens of arrests and apprehensions. Previously obtained figures showed ICE used stingrays more than 1,885 times over a four-year period between 2013 and 2017.
The documents say that stingrays were not deployed for civil immigration investigations, like removals or deportations.
Although the numbers offer a rare insight into how often ICE uses this secretive and controversial technology, the documents don’t say how many Americans also had their phones inadvertently ensnared by these surveillance devices.
“We are all harmed by government practices that violate the Constitution and undermine civil liberties,” said Alexia Ramirez, a fellow with the ACLU’s Speech, Privacy, and Technology Project. “ICE’s use of cell site simulators affects all people, regardless of their immigration status.”
“When cell site simulators search for an individual, they necessarily also sweep in sensitive, private information about innocent bystanders,” said Ramirez. “This is part of the reason courts have said there are serious Fourth Amendment concerns with this technology.”
A letter from Harris Corp., which builds cell site simulators — known as “stingrays,” describing the non-disclosure terms for its Crossbow cell site simulator. (Source: ACLU)
Stingrays impersonate cell towers and capture the calls, messages, location and in some cases data of every cell phone in their range. Developed by Harris Corp., stingrays are sold exclusively to law enforcement. But their purchase and use are covered under strict non-disclosure agreements that prevent police from discussing how the technology works. These agreements are notoriously prohibitive; prosecutors have dropped court cases rather than disclose details about the stingrays.
The newly released documents are heavily redacted and offer little more about what we know of how stingrays work. One document did, however, reveal for the first time the existence of Harris’ most recent stingray, Crossbow. An email from 2012 refers to Crossbow as the “latest, most technologically up-to-date version of a Stingray system.”
But the civil liberties group said its public records lawsuit is not over. Customs and Border Protection (CBP), which was also named in the suit, has not yet turned over any documents sought by the ACLU, despite spending $2.5 million on buying at least 33 stingrays, according to a 2016 congressional oversight report.
“We are deeply skeptical of CBP’s assertion that they do not possess records about cell site simulators,” said Ramirez. “Given public information, the agency’s claim just doesn’t pass the sniff test.”
CBP has until June 12 to respond to the ACLU’s latest motion.
When reached, a spokesperson for CBP was unable to comment by our deadline. ICE did not respond to a request for comment.
ICE used ‘stingray’ cell phone snooping tech hundreds of times since 2017 by Zack Whittaker originally published on TechCrunch