Normal view
-
Bitcoin News - Darknet Archives
- US Authorities Bust Billion-Dollar Crypto Laundering Network, Charge 2 Russians
-
Bitcoin News - Darknet Archives
- German Authorities Shut Down 47 Crypto Exchange Services in Cybercrime Crackdown
German Authorities Shut Down 47 Crypto Exchange Services in Cybercrime Crackdown
Darknet Market Solaris Hacked by Competitor, Elliptic Reveals
A leading marketplace on the dark web, Solaris, has been hit by a rival, according to crypto analytics company Elliptic. The Russia-linked platform, which tried to occupy space vacated by the busted Hydra, is believed to have conquered up to a fifth of the illicit market before the hack.
Solaris Allegedly Taken Over by Darknet Marketplace Called Kraken
Solaris, a major marketplace for drugs and other illicit products, has been targeted in a hacking attack carried out by a similar enterprise, Kraken, not to be confused with the well-known cryptocurrency exchange with the same name.
After in April last year law enforcement authorities shut down Hydra, the former leader in this business, seizing its servers in Germany and arresting an alleged operator in Russia, Solaris managed to gain between 20% and 25% market share, according to estimates quoted by Elliptic.
This week, the blockchain forensics company reported that since Friday, Jan. 13, those who visited the onionsite were being transferred to Kraken. The latter claimed to have taken control over the infrastructure, Gitlab repository and source code of Solaris and blocked its bitcoin wallets.
Kraken is another player in the dark web space and, like Solaris and Hydra, is targeting the Russian-language segment of the underground market. The illegal trading platforms are suspected of having other ties to Russia as well.
For example, Solaris is believed of have used the services of one of the Russian “patriotic” hacker groups. The pro-Kremlin Killnet is known for launching distributed denial-of-service (DDoS ) attacks on Ukraine after Russia invaded the country in late February, 2022.
This isn’t the first attempt to breach Solaris. Ukrainian-born cyber intelligence expert Alex Holden claimed to have hacked into the marketplace, according to a report in December, and getting hold of some of the bitcoin sent to dealers using the site and to its owners.
Helped by his cybersecurity company, Holden said he specifically targeted a wallet used for crypto exchange transactions and was able to divert 1.6 BTC. The cryptocurrency was later donated to a Kyiv-based charity.
What do you make of the darknet market Kraken’s hacking attack on rival Solaris? Share your thoughts on the subject in the comments section below.
-
Bitcoin News - Darknet Archives
- Darknet Forum Dread to Relaunch After Month-Long Downtime Due to DDOS Attack
Darknet Forum Dread to Relaunch After Month-Long Downtime Due to DDOS Attack
According to web portal darkdot.com and anonymous journalist Darkdotfail, the popular darknet forum Dread has been down for a month. The well-known forum, which was a place for darknet market (DNM) patrons to discuss operations security, rate specific vendors, and talk about stealth delivery ideas, has been absent for 30 days. However, the forum’s founder, “Hugbunter,” has stated that it will relaunch in the near future.
Dread Forum Founder Announces Plans to Relaunch
In the underground world of darknet markets (DNMs), the forum Dread was known for being a go-to source of information. According to a Jan. 1, 2023 update hosted on darkdot.com, the forum has been down for a month. “Dread is a critical source of truth in an anonymous community proliferated with scams,” the update notes. “The popular Tor freedom of speech forum went offline on Nov. 30, 2022, and has yet to return.” The update adds that while the Dread admin team typically posts status updates on Reddit at /r/dreadalert, communication has been sparse.
The anonymous journalist known as Darkdotfail has written about the issue on Twitter and their website, dark.fail, also indicates that Dread is currently offline. According to a Jan. 5, 2023 update on the website, Dread is offline due to a DDOS attack and readers should follow /r/dreadalert for updates. On Jan. 2, 2023, the DNM and Tor researcher wrote that Dread’s founder, Hugbunter, had privately confirmed that the forum will return. “Dread’s now been offline for a month, Hugbunter privately confirmed to us that it will return,” Darkdotfail wrote. Two days later, Darkdotfail shared an update from the Reddit forum /r/dreadalert.
The privacy advocate and anonymous journalist said:
Hugbunter posted an update regarding Dread’s downtime to /r/dreadalert. Meanwhile, the team behind Incognito Market opportunistically coded and launched a competing forum, Libre, during Dread’s downtime. Never boring around here.
The message from Hugbunter, which includes the founder’s PGP signature, explains that the team has been “working extremely hard to restore service.” In the message, the Dread founder estimates that the team is about a week away from a solid estimated time of arrival (ETA).
“As of right now, we’re about a week out from being able to give a solid ETA on a return of Dread, but I will say we’re hopeful of it being next week,” Hugbunter detailed. “This depends on there being no further issues as we finalize everything on the server side and also if I manage to work through some rewrites of the codebase in a timely manner, however, it is not an easy or small task — So no further pressure please.”
This is not the first time Dread has experienced a significantly long downtime. On Sept. 30, 2019, Bitcoin.com News reported on the forum’s first major outage. At that time, Hugbunter’s dead man’s switch was triggered, resulting in a temporary loss of control over the forum. However, Hugbunter returned shortly after and validated the forum owner’s identity through the PGP keys associated with the Dread founder. The forum remained active, with some exceptions due to DDOS attacks, until Nov. 2022. In addition to Dread’s outage from DDOS attacks, the Tor Project reported that the Tor network itself has slowed by close to 50%.
In the Jan. 3 message, Hugbunter, the founder of Dread, detailed that the forum’s DDOS issues would be solved by the time it returns and “any other service who needs assistance.” Hugbunter promised that Dread will relaunch with a revamped user experience and proper DDOS protection, saying “the plans I have with the relaunch and also for the near future are going to allow all of us to move forward significantly and we will continue to innovate this space. We are not going anywhere and I still have much to provide and share.”
What do you think about Dread’s current downtime and Hugbunter explaining that the forum will return soon? Let us know what you think about this subject in the comments section below.
-
Bitcoin News - Darknet Archives
- Ukrainian Steals Bitcoin From Russian Darknet Market, Donates to Charity
Ukrainian Steals Bitcoin From Russian Darknet Market, Donates to Charity
A Ukrainian living in the U.S. has reportedly hacked a major drug market on the Russian dark web, diverting some of its crypto proceeds. The man says he donated the digital cash stolen from the illicit website to an organization delivering humanitarian aid across his war-torn homeland.
Wisconsin Resident With Ukrainian Roots Hacks Russian Dark Web Market Solaris
Ukrainian-born cyber intelligence expert Alex Holden, who left Kyiv as a teenager in the 1980s and now lives in Mequon, Wisconsin, claims he has hacked into Solaris, one of Russia’s largest online drug markets, Forbes informs in a report.
Supported by his team at Hold Security, he was able to get hold of some of the bitcoin sent to dealers and the darknet site’s owners. The cryptocurrency, worth over $25,000, was later transferred to Enjoying Life, a charitable foundation based in the Ukrainian capital.
Without revealing exactly how he did it, Holden explained he took control of much of the internet infrastructure behind Solaris, including some administrator accounts, obtained the website’s source code and a database of its users and drop off locations for drug deliveries.
For a while, the Ukrainian and his colleagues also gained access to the “master wallet” of the marketplace. It was used by buyers and dealers to deposit and withdraw funds and operated as the platform’s crypto exchange, the article details.
Given the rapid turnover, the wallet rarely had more than 3 BTC at a time. Holden managed to appropriate 1.6 BTC and send it to Enjoying Life. Hold Security donated another $8,000 to the charity, which provides assistance to people affected by the war in Ukraine.
Solaris Linked to ‘Patriotic’ Russian Hacking Collective Killnet
The darknet market Solaris is suspected of having connections to the hacking crew Killnet, which after Moscow launched its invasion in late February became one of Russia’s “patriotic” hacker groups vowing to target Ukrainians and their supporters.
Killnet has also conducted a number of attacks in the U.S., including on airport and state government websites as well as the National Geospatial-Intelligence Agency. It reportedly hit the Eurovision song contest, the Estonian government and Italy’s National Health Institute.
The group was also blamed for attacking Rutor, the main rival of Solaris, which became Russia’s leading underground drugs market after Hydra was shut down this past spring. According to U.S. cybersecurity firm Zerofox, Solaris was paying Killnet for DDoS services.
Besides the battlefield, Russia and Ukraine have also clashed in the online space, with the government in Kyiv recruiting experts for its own cyberforce. The special unit was tasked to identify and prevent Russian attacks but also hack back.
Hits such as those on Russia’s largest bank, Sber, and the Moscow Stock Exchange have been attributed to the Ukrainian IT army. Social media accounts associated with the hacktivist collective Anonymous took responsibility for many other attacks.
What do you think about Alex Holden’s attack on the Russian darknet market Solaris? Let us know in the comments section below.
-
Bitcoin News - Darknet Archives
- Alleged Hydra Administrator Dmitry Pavlov Reportedly Arrested in Russia
Alleged Hydra Administrator Dmitry Pavlov Reportedly Arrested in Russia
A district court in Moscow has arrested a man whom local media reports identify as Dmitry Pavlov, alleged administrator of the recently shut down darknet market Hydra. Russian authorities believe he has been involved in drug-related crime punishable by up to 20 years in prison.
Moscow Court Arrests Russian Believed to Be Hydra Administrator
Meshchansky District Court of Moscow has taken into custody a certain Dmitry Olegovich Pavlov accused of production, sale, and distribution of drugs under Russia’s Criminal Code, the “Moscow” City News Agency reported this week, quoting the court’s press service.
Pavlov, who was arrested on Monday, April 11, has the same names as a 30-year-old Russian citizen and resident charged for similar offenses in relation to his alleged role as an administrator of the recently busted Hydra Market, one of the largest marketplaces on the darknet.
Earlier this month, German law enforcement seized Hydra’s server infrastructure in the country and took down the Russian-language platform’s website. The operation was carried with support from several U.S. agencies.
On April 5, the U.S. Department of Justice announced criminal charges against Dmitry Pavlov for conspiracy to distribute narcotics and conspiracy to commit money laundering. According to an indictment filed with the U.S. District Court for the Northern District of California, the Russian is also accused of administering and providing hosting services to Hydra.
The Russian business daily Kommersant quoted Pavlov telling the BBC on April 6 he had not been contacted by U.S. authorities and that he learned about the charges from the media. He also insisted his company had all the necessary licenses from Roskomnadzor, Russia’s communications watchdog, and was not administering any websites but only leasing servers as an intermediary.
The United States has been alleging the Russian Federation’s involvement with crypto-related criminal organizations, including darknet markets (DNMs) and ransomware actors. In September, the U.S. Department of the Treasury’s Office of Foreign Assets Control (OFAC) sanctioned the Russia-based crypto broker Suex, believed to have received more than $20 million from DNMs like Hydra.
The department also imposed sanctions on Hydra itself — which had been active since at least 2015 and had around 17 million customers before it was shut down — and on a cryptocurrency exchange called Garantex, suspected of processing over $2.6 million in transactions from the darknet market platform.
Do you expect other arrests in Russia in connection with the Hydra case? Tell us in the comments section below.