❌

Reading view

There are new articles available, click to refresh the page.

DOJ Captures Alleged β€˜Architect’ of Darknet Marketplace Incognito

DOJ Captures Alleged β€˜Architect’ of Darknet Marketplace IncognitoAccording to the U.S. Department of Justice (DOJ), the operator of the darknet marketplace Incognito was apprehended at John F. Kennedy Airport on May 18. Law enforcement officials claim Rui-Siang Lin allegedly constructed the DNM and facilitated the sale of over $100 million worth of illegal drugs through the platform. Federal Authorities Nab Alleged Darknet […]

Hive Ransomware Network Dismantled by American, European Law Enforcement

Hive Ransomware Network Dismantled by American, European Law Enforcement

Law enforcement authorities from over a dozen countries in Europe and North America have taken part in disrupting the activities of the Hive ransomware group, the U.S. Justice Department and Europol announced. Hive is believed to have targeted various organizations worldwide in the past couple of years, often extorting payments in cryptocurrency.

Captured Decryption Keys Helped Hive Victims Avoid Paying $130 Million in Ransom

Ransomware network Hive, which has had around 1,500 victims in more than 80 countries, has been hit in a months-long disruption campaign, the U.S. Department of Justice (DOJ) and the European Union Agency for Law Enforcement Cooperation (Europol) revealed. A total of 13 nations participated in the operation, including EU member states, the U.K. and Canada.

Hive has been identified as a major cybersecurity threat as the ransomware has been used by affiliated actors to compromise and encrypt data and computer systems of government facilities, oil multinationals, IT and telecom companies in the EU and U.S., Europol said. Hospitals, schools, financial firms, and critical infrastructure have been targeted, the DOJ noted.

It has been one of the most prolific ransomware strains, Chainalysis pointed out, which has collected at least $100 million from victims since its launch in 2021. A recent report by the blockchain forensics company unveiled that revenue from such attacks has decreased last year, with a growing number of affected organizations refusing to pay the demanded ransoms.

According to the announcements by the law enforcement authorities, the U.S. Federal Bureau of Investigation (FBI) penetrated Hive’s computers in July 2022 and captured its decryption keys, providing them to victims around the world which prevented them from paying another $130 million.

Working with the German Federal Police and the Dutch High Tech Crime Unit, the Bureau has now seized control over the servers and websites that Hive used to communicate with its members and the victims, including the darknet domain where the stolen data was sometimes posted. FBI Director Christopher Wray was quoted as stating:

The coordinated disruption of Hive’s computer networks … shows what we can accomplish by combining a relentless search for useful technical information to share with victims.

The Hive ransomware was created, maintained and updated by developers while being employed by affiliates in a β€˜ransomware-as-a-service’ (RaaS) double extortion model, Europol explained. The affiliates would initially copy the data and then encrypt the files before asking for a ransom to decrypt the information and not publish it on the leak site.

The attackers exploited various vulnerabilities and used a number of methods, including single factor logins via Remote Desktop Protocol (RDP), virtual private networks (VPNs), and other remote network connection protocols as well as phishing emails with malicious attachments, the law enforcement agencies detailed.

Do you expect police authorities around the world to dismantle more ransomware networks in the near future? Tell us in the comments section below.

Darknet Forum Dread to Relaunch After Month-Long Downtime Due to DDOS Attack

According to web portal darkdot.com and anonymous journalist Darkdotfail, the popular darknet forum Dread has been down for a month. The well-known forum, which was a place for darknet market (DNM) patrons to discuss operations security, rate specific vendors, and talk about stealth delivery ideas, has been absent for 30 days. However, the forum’s founder, β€œHugbunter,” has stated that it will relaunch in the near future.

Dread Forum Founder Announces Plans to Relaunch

In the underground world of darknet markets (DNMs), the forum Dread was known for being a go-to source of information. According to a Jan. 1, 2023 update hosted on darkdot.com, the forum has been down for a month. β€œDread is a critical source of truth in an anonymous community proliferated with scams,” the update notes. β€œThe popular Tor freedom of speech forum went offline on Nov. 30, 2022, and has yet to return.” The update adds that while the Dread admin team typically posts status updates on Reddit at /r/dreadalert, communication has been sparse.

The anonymous journalist known as Darkdotfail has written about the issue on Twitter and their website, dark.fail, also indicates that Dread is currently offline. According to a Jan. 5, 2023 update on the website, Dread is offline due to a DDOS attack and readers should follow /r/dreadalert for updates. On Jan. 2, 2023, the DNM and Tor researcher wrote that Dread’s founder, Hugbunter, had privately confirmed that the forum will return. β€œDread’s now been offline for a month, Hugbunter privately confirmed to us that it will return,” Darkdotfail wrote. Two days later, Darkdotfail shared an update from the Reddit forum /r/dreadalert.

The privacy advocate and anonymous journalist said:

Hugbunter posted an update regarding Dread’s downtime to /r/dreadalert. Meanwhile, the team behind Incognito Market opportunistically coded and launched a competing forum, Libre, during Dread’s downtime. Never boring around here.

The message from Hugbunter, which includes the founder’s PGP signature, explains that the team has been β€œworking extremely hard to restore service.” In the message, the Dread founder estimates that the team is about a week away from a solid estimated time of arrival (ETA).

β€œAs of right now, we’re about a week out from being able to give a solid ETA on a return of Dread, but I will say we’re hopeful of it being next week,” Hugbunter detailed. β€œThis depends on there being no further issues as we finalize everything on the server side and also if I manage to work through some rewrites of the codebase in a timely manner, however, it is not an easy or small task β€” So no further pressure please.”

This is not the first time Dread has experienced a significantly long downtime. On Sept. 30, 2019, Bitcoin.com News reported on the forum’s first major outage. At that time, Hugbunter’s dead man’s switch was triggered, resulting in a temporary loss of control over the forum. However, Hugbunter returned shortly after and validated the forum owner’s identity through the PGP keys associated with the Dread founder. The forum remained active, with some exceptions due to DDOS attacks, until Nov. 2022. In addition to Dread’s outage from DDOS attacks, the Tor Project reported that the Tor network itself has slowed by close to 50%.

In the Jan. 3 message, Hugbunter, the founder of Dread, detailed that the forum’s DDOS issues would be solved by the time it returns and β€œany other service who needs assistance.” Hugbunter promised that Dread will relaunch with a revamped user experience and proper DDOS protection, saying β€œthe plans I have with the relaunch and also for the near future are going to allow all of us to move forward significantly and we will continue to innovate this space. We are not going anywhere and I still have much to provide and share.”

What do you think about Dread’s current downtime and Hugbunter explaining that the forum will return soon? Let us know what you think about this subject in the comments section below.

Germany Shuts Down Hydra Market, Seizes Servers and Bitcoin

Germany Shuts Down Hydra Market, Seizes Servers and Bitcoin

Law enforcement agencies in Germany have targeted Hydra, a leading darknet market (DNM). As part of an operation conducted with U.S. support, the German police were able to establish control over the servers of the Russian-language platform in the country and take down its website.

Investigators Hit Hydra in Germany, Confiscate Millions in Crypto

Hydra Market, one of the largest marketplaces on the darknet, has been shut down by German authorities which seized its server infrastructure. According to an announcement by the Federal Criminal Police Office (BKA), law enforcement agents also confiscated bitcoin worth around €23 million ($25 million). The following message appeared on Hydra’s website on Tuesday:

BKA carried out the raid together with the Central Office for Combating Cybercrime (ZIT) at the Public Prosecutor’s Office in Frankfurt which is leading the investigation against Hydra’s operators and administrators. They are wanted for running illegal online platforms facilitating the trade of drugs and money laundering.

The German police noted that Hydra had been active since at least 2015 before the seizures which came after extensive investigations by the BKA and ZIT. They started in August last year and were conducted with the participation of several U.S. agencies.

The darknet marketplace, which was accessible via the Tor network, was targeting Russian speakers. It had around 17 million customers and over 19,000 registered sellers, the press release detailed. Besides banned substances, these also offered stolen data, forged documents and digital services.

Hydra became a major darknet market after overtaking another Russian platform, DNM Ramp. According to the data compiled by the blockchain forensics company Chainalysis, the region of Eastern Europe sends more digital currency to darknet marketplaces than any other region.

Washington has been alleging Moscow’s involvement with malicious cyber actors like DNMs, ransomware groups and other crypto-related crime. In September, the U.S. Department of the Treasury’s Office of Foreign Assets Control (OFAC) sanctioned the Russia-based crypto broker Suex which is believed to have received more than $20 million from darknet markets like Hydra.

The Treasury Department has imposed sanctions against Hydra and a crypto exchange called Garantex. The trading platform, which has been operating mostly out of Russia, is suspected of processing over $100 million in transactions linked to illicit actors and darknet markets, including $2.6 million from Hydra.

Meanwhile, the U.S. Department of Justice announced criminal charges against a Russian resident, Dmitry Pavlov, for conspiracy to distribute narcotics and conspiracy to commit money laundering. The 30-year-old Pavlov is allegedly the administrator of Hydra Market’s servers.

German law enforcement officials think that Hydra was likely the darknet market with the highest turnover globally. BKA and ZIT have estimated that its sales reached at least €1.23 billion in 2020 alone. They also noted that the investigations were hampered by the platform’s own β€˜Bitcoin Bank Mixer’ service.

Do you think other darknet markets will be targeted after Hydra? Let us know in the comments section below.

❌