US, UK Sanction More Members of Trickbot Russian Cybercrime Group 

The United States and the United Kingdom on Thursday announced sanctions against more alleged members of the Russian cybercrime group named Trickbot. 

Earlier this year, the two countries sanctioned seven Russians for their alleged role in the Trickbot operation, and they have now announced sanctions against 11 additional individuals.

The latest sanctions target Andrey Zhuykov, described as a central actor and senior administrator; Maksim Galochkin, who led Trickbot testers; Maksim Rudenskiy, team lead for coders; Mikhail Tsarev, HR and finance manager; Dmitry Putilin, responsible for acquiring Trickbot infrastructure; Maksim Khaliullin, HR manager; Mikhail Chernov, in charge of internal utilities; Alexander Mozhaev, responsible for general administrative tasks; and coders Sergey Loguntsov, Vadym Valiakhmetov and Artem Kurov.

As a result of sanctions, these individuals can have their assets frozen, and entities in the US and UK are banned from doing business with them, which can also have an impact on ransomware payments.

In tandem with the sanctions, the US government announced charges against nine individuals over the development of the Trickbot malware, including seven of the newly sanctioned people and two of those targeted in the previous round of sanctions.

In addition, four of the individuals were indicted for their role in Conti ransomware attacks, each of them facing up to 25 years in prison. 

While it may be difficult for the US to apprehend these individuals given its current relations with Russia, there have been cases where Russian cybercriminals ended up being prosecuted in the United States after they traveled outside their country. This includes Trickbot developers. 

Advertisement. Scroll to continue reading.

The United States has been offering up to $10 million in rewards for information on Russian cybercriminals and individuals involved in state-sponsored operations. 

The cybercrime enterprise behind the Trickbot malware has been around for roughly a decade, targeting millions of computers worldwide as part of financially motivated operations aimed at businesses and individuals, including ransomware attacks and direct targeting of bank accounts. 

The US government says the Trickbot group has ties to Russian intelligence services. 

Microsoft announced the takedown of Trickbot infrastructure in October 2020, but CISA and the FBI warned a few months later that the malware had still been distributed in attacks. 

Earlier this year, the US announced sanctions against 22 individuals and 83 entities that allegedly helped Russia’s war against Ukraine, including its cyber operations.  

Related: Russian National Arrested, Charged in US Over Role in LockBit Ransomware Attacks

Related: US Reiterates $10 Million Reward Offer After Disruption of Hive Ransomware

Related: US Sanctions North Korean University for Training Hackers

https://www.securityweek.com/us-uk-sanction-more-members-of-trickbot-russian-cybercrime-group/




Wealthy Russian With Kremlin Ties Gets 9 Years in Prison for Hacking and Insider Trading Scheme

A wealthy Russian businessman with ties to the Kremlin was sentenced Thursday to nine years in prison for his role in a nearly $100 million stock market cheating scheme that relied on secret earnings information stolen through the hacking of U.S. computer networks.

Vladislav Klyushin, who ran a Moscow-based information technology company that did work for the highest levels of the Russian government, was convicted in February of charges including wire fraud and securities fraud after a two-week trial in federal court in Boston.

Authorities say he personally pocketed more than $33 million in the scheme, which involved breaking into computer systems to steal earnings-related filings for hundreds of companies — including Microsoft and Tesla — and then using that insider information to make lucrative trades.

Klyushin, 42, has been jailed in the U.S. since his extradition in 2021, and the more than two years he’s been detained will be credited to his prison term. He was arrested in Switzerland after arriving on a private jet and just before he and his party were about to board a helicopter to whisk them to a nearby ski resort. After he completes his sentence, he’s expected to be deported to Russia.

Klyushin, who walked into the courtroom in handcuffs, sat at a table with his attorneys and listened to an interpreter through headphones as lawyers argued over the sentence. At the advice of his attorney, he declined to address the judge before she sentenced him.

Four alleged co-conspirators — including a Russian military intelligence officer who’s also been charged with meddling in the 2016 presidential election — remain at large, and even though prosecutors allege in a court filing that they’re still “likely sitting at their keyboards,” they acknowledge that they four will likely never be extradited to the U.S. to face charges.

Prosecutors had sought 14 years in prison, saying a stiff punishment was crucial to send a message to overseas cybercriminals. Assistant U.S. Attorney Seth Kosto told the judge that Klyushin has accepted no responsibility for his crimes and that once he serves his sentence, he’ll return to Russia, where he is a “powerful person” with “powerful friends in the highest echelons of Russian society.”

Advertisement. Scroll to continue reading.

“Hackers will be watching this sentence to decide whether it’s wroth engaging in this kind of conduct,” Kosto said.

Prosecutors say the hackers stole employees’ usernames and passwords for two U.S.-based vendors that publicly traded companies use to make filings through the Securities and Exchange Commission. They then broke into the vendors’ computer systems to get filings before they became public, prosecutors said.

Armed with insider information, they were able to cheat the stock market, buying shares of a company that was about to release positive financial results, and selling shares of a company that was about to post poor financial results, according to prosecutors. Many of the earnings reports were downloaded via a computer server in Boston, prosecutors said.

Klyushin has denied involvement in the scheme. His attorney told jurors that he was financially successful long before he began trading stocks and that he continued trading in many of the same companies even after access to the alleged insider information was shut off because the hacks were discovered.

Defense attorney Maksim Nemtsev called prosecutors’ prison request “draconian,” adding that there is “no reason to think that he would would risk the well-being of his family again by committing crimes.”

His lawyers asked the court for leniency, saying Klyushin had no prior criminal history and has already been seriously punished. He spent months in solitary confinement in Switzerland while awaiting extradition to the U.S. and his company has lost multimillion dollar contracts, his attorneys wrote.

Klyushin owned a Moscow-based information technology company that purported to provide services to detect vulnerabilities in computer systems. It counted among its clients the administration of Russian President Vladimir Putin and the Ministry of Defense, according to prosecutors.

Klyushin’s close friend and an alleged co-conspirator in the case is military officer Ivan Ermakov, who was among 12 Russians charged in 2018 with hacking into key Democratic Party email accounts, including those belonging to Hilary Clinton’s presidential campaign chairman, John Podesta, the Democratic National Committee and the Democratic Congressional Campaign Committee. Ermakov, who worked for Klyushin’s company, remains at large.

Prosecutors have not alleged that Klyushin was involved in the election interference.

https://www.securityweek.com/wealthy-russian-with-kremlin-ties-gets-9-years-in-prison-for-hacking-and-insider-trading-scheme/




See Tickets Alerts 300,000 Customers After Another Web Skimmer Attack

Ticketing services agency See Tickets has notified more than 300,000 individuals that their payment card data was stolen in a new web skimmer attack.

Owned by Vivendi SA, See Tickets provides ticketing services for a broad range of event types, including comedy, festival, lifestyle, and sport, and operates both regional and international websites in North America and Europe.

In a data breach notification letter sent to the affected individuals, a copy of which was submitted to the Maine Attorney General’s Office, See Tickets says the new attack was identified in May 2023 and completely shut down in July.

“In May 2023, See Tickets became aware of unusual activity on certain of its e-commerce websites,” the agency notes in the notification letter.

A forensics firm retained to investigate the hacker attack discovered that, in May and June 2023, an unauthorized third-party “inserted multiple instances of malicious code into a number of [See Tickets’] e-commerce checkout pages”, See Tickets explains.

Between February 28 and July 2, the malicious code – which is typically referred to as a web skimmer – collected and exfiltrated the information that users provided on those checkout pages, including their names, addresses, and payment card information.

The ticketing services agency also notes that it has no evidence to suggest that the stolen personal information was fraudulently used. However, such data is typically shared between cybercriminals and used to perform various types of fraud.

Advertisement. Scroll to continue reading.

See Tickets claims to have implemented additional safeguards to protect payment card information on its web pages, but this is the second time in the past year that it warns users of a web skimmer on its websites.

Disclosed in October 2022 and impacting names, addresses, and payment card data, the first skimmer attack was identified in April 2021 but only shut down in January 2022.

Related: See Tickets Customer Payment Card Data Stolen by Web Skimmer

Related: Website of Canadian Liquor Distributor LCBO Infected With Web Skimmer

Related: Hundreds of eCommerce Domains Infected With Google Tag Manager-Based Skimmers

https://www.securityweek.com/see-tickets-alerts-300000-customers-after-another-web-skimmer-attack/




Hacker Conversations: Alex Ionescu

In this edition of Hacker Conversations, SecurityWeek talks to Alex Ionescu, a world-renowned cybersecurity expert who has combined a career as a business executive with that of a security researcher. 

The goal of Hacker Conversations is to talk to cybersecurity researchers to better understand how they fit into and operate within the cybersecurity ecosphere. 

Ionescu is currently technical director, platform operations and research at Canada’s Communications Security Establishment (which has responsibility for foreign signals intelligence and communications security, protecting government networks, and being the nation’s technical authority for cybersecurity and information assurance).

Before that, he was VP of endpoint engineering at CrowdStrike, and is the co-author of the last two editions of the Windows Internals series. He talked to SecurityWeek for this series on his experience as an independent security researcher.

“The cliché answer,” says Ionescu, “is ‘curiosity’. It’s more complex than this; but basically, it is an insatiable need to know how things work, and why they work.” One thing it doesn’t need is a desire for fame and fortune. A lot of fame and a degree of fortune can be obtained (and we’ll meet researchers in this series who have done just that), but it is the exception.

Alex Ionescu
Alex Ionescu

It’s the process that must appeal. “You could spend years researching something and, in the end, it amounts to nothing more than knowledge gained. It’ll have no value beyond that,” he continued. “So, you must have that curiosity that makes you say at the end of the day ‘Oh, I’m glad I learned something that I can share.’ If you’re in it just for fame or just for money, it’s going to be disappointing quite quickly, because you generally don’t get there; or get there very rarely.”

This introduces two further personality traits that will benefit the researcher: patience and the lack of ego. Patience goes together with curiosity – neither work very well on their own. Research can be long and slow, so patience is necessary to keep going.

Ego is bound up with another characteristic – a desire to share what is discovered. There are caveats to sharing, which we’ll come to later, but in general researchers like to share their results because it can expand and improve the research.

Advertisement. Scroll to continue reading.

‘‘I’m proud of the research that I do, and I know what I’m good at and what I’m not,” he said. “Usually, sharing my research will lead to feedback with criticism and praise.” But the researcher needs to be able to accept the times when there is more criticism than praise, and the ability to accept disappointment is also important. Ego gets in the way of this. 

Finally, he added one more characteristic – this time not a requirement for research but a result of it: mistrust, and especially mistrust of the media. “I think there’s a large mistrust of media in general,” he commented, “because the media tends to cover up or ignore things sometimes. If it gets a ‘cease and desist’ from a Microsoft or a Sony… they’re typically not going to side with a loner in the basement when they’ve got a multi-billion-dollar company and their lawyers coming to their headquarters.”

In recent years there has been a suggested connection between Asperger’s syndrome and both white hat and black hat hackers. Asperger’s is a complex condition that is not well understood. It’s more accurate terminology today is ‘autism spectrum disorder/ASD’. It can – but not necessarily – combine social difficulties with high intellectual performance in a specific area. For the sake of argument over accuracy, we will describe such people as ‘high performing loners’.

Ionescu neither accepts nor rejects a connection – you don’t need to be a loner to be a researcher, but the occupation of research could be attractive to loners. “It is a world where you don’t need to be physically present. You can just send emails and write blogs and can hide behind a persona. Research certainly welcomes that personality trait more than other fields might.” But he adds, “Personally, I’m very extroverted, so it certainly isn’t a necessity.”

Far more important than any neurodiverse label, he says, is a willingness to learn and the ability to be patient – and the stomach for disappointment when things don’t turn out as expected. But he added, “it sounds cliché, but research is one of those areas where if you’re curious and patient and willing to learn, and if you work hard, you will get success. Sadly, the state of the security of most things in the world is that if you shake the tree hard enough, you’ll find things. So, you just have to have that patience and that work ethic.”

All of this begs an important question: how do you get started in this profession? “For me,” said Ionescu, “it was a self-taught natural progression from a hobby. Growing up in Romania, I was lucky to have access to a computer at home from the age of four.

“I was just always fascinated with how things work and what makes them tick – and the thing that I had in front of me was a computer. So, I started messing around with it in various ways, for myself really. And then the Internet came along, and I started meeting people that had similar interests. 

“I think I was very lucky from a time perspective with the internet. With it came an evolving hacker culture and then all the forums. I found that while I was doing my thing, others were doing the same. Those two worlds intersected and through various contacts, people, websites, it developed into a full-time hobby, and eventually a job.”

The basic scenario he described is one in which the profession draws in the natural hacker into becoming a researcher – it could be black hat or white hat, although in Ionescu’s case it was white hat.

It should be asked where an independent researcher gets his income, and whether there is any temptation to go to the dark side. This is particularly relevant given the recent growth in the wealth of some criminal gangs. (Nation states also purchase exploits from the ‘open market’, but the delineation between whether that remains white hat or becomes black hat probably rests with which side of the geopolitical divide you call home.)

“There are numerous ways to earn money as a white hat researcher,” said Ionescu. “You can contract with a company to sell your research back to the company; or you can use one of the various bug-hunting programs. Many of the larger companies have their own vulnerability reward scheme.”

The two ‘wrong’ routes are to sell your research to criminal gangs or to weaponize and use it yourself. “Do that,” said Ionescu, “and you’re a criminal not a researcher.” Despite this, he recognizes the pressures, which have their own geopolitical divide. “In the States and Canada and Europe,” he explained, “you can earn a lot of money – hundreds of thousands of dollars – doing research for companies like Facebook. In Russia and Iran and China you probably can’t do this – but collaborating with or working for a criminal gang could earn the same amount – a lot of money.”

Socioeconomics also plays its part. “Take the family where the eldest child has six siblings, no father and a sick mother. There’s no income, but the opportunity to make some money by encrypting a few hard drives.” 

Dissociation comes into play. Insurance will pay the ransom, so there’s no real harm done to anyone. “In exchange, the mother gets her cancer treatment or whatever is required. We could make a whole movie about this – we can justify why someone might want to go down that route in places where there’s not a lot of other opportunities.”

Responsible or full disclosure has been a perennial (‘heated’, says Ionescu) debate for more than two decades: should a researcher fully and immediately publicize discoveries to ‘force’ a vendor to fix the problems, or should the researcher disclose only to the vendor and work with the vendor to fix the problems before going public?

The intent is the same: to minimize the possibility of criminals exploiting the vulnerability. Full disclosure works to the principle that criminals may already know about the fault and are quietly exploiting it, while responsible disclosure says criminals will know about it the moment it is publicly disclosed.

“My personal stance,” says Ionescu, “is that full disclosure doesn’t help in most cases. There are corner cases, where the researcher may claim, ‘This company would not have done anything if we hadn’t put their face in the mud.’ But I think it is bad to make general policies based on exceptions.”

Against full disclosure are cases where criminals have used exploits published in Metasploit before the vendors had patched them. Supporting full disclosure is a current video gaming case.

On January 23, 2022, @DarkSoulsGame tweeted “PvP servers for Dark Souls 3, Dark Souls 2, and Dark Souls: Remastered have been temporarily deactivated to allow the team to investigate recent reports of an issue with online services.” The issue appears to be related to an exploit that had its effect published on Twitch.

Malwarebytes reported, “[A] Text to Speech voice kicks in and begins a long ramble aimed at the streamer. You’ll also hear the incredibly confused streamer in the background, talking about seeing ‘powershell.exe’ on their screen. Someone had gained control of his PC, mid-stream, to crash his game and autoplay the synthesized speech.”

The recording was apparently made and published out of frustration. An RCE vulnerability had been found in the game and reported to the publisher, but nothing had been done about it. The Twitch recording prompted further claims, with one user saying he had found and reported another (possibly different, possibly the same) RCE in 2020. 

“My main reason for not being surprised is that I also reported an RCE to Bandai Namco in early 2020 and was met with the exact same radio silence,” Reddit user LukeYui told Video Games Chronicle.

At the time of writing, the Dark Souls PvP servers were still off-line with no further public comment from Bandai Namco. The implication is that in some circumstances, researchers may conclude they need to go public with their findings to ‘force’ a vendor into action. That’s the ‘full disclosure’ argument.

But Ionescu adds a further pressure against full disclosure – the legal issue. “Different countries have different laws,” he said. “In some cases, there are issues around the legality of reverse engineering, and in other cases the research may be something that cannot be allowed to reach certain foreign countries because it’s almost considered weapons research. Then there’s the possibility of copyright infringement and DMCA in the U.S. There are lots of laws around the world to navigate; so, there’s certainly a legal aspect to traverse if you want to be very loud and noisy and vocal about your research.”

SecurityWeek asked Ionescu what research had given him the greatest personal satisfaction. He replied that it wasn’t a specific result, but a type of research that pleases him most.

“A lot of security research is done by looking at X, and finding things wrong with X. I do a lot of that,” he said. “But what really makes me feel accomplished, and what I think everyone stands from better appreciating from an engineering perspective, is when I take X (which appears to be, for the sake of argument, ‘perfect’, as used and designed in, say, 1995), and then take Y (which appears to be, for the sake of argument, ‘perfect, as used and designed in say, 2005). Then take Z,” he continued, “which someone took, in 2015, by combining X and Y together.”

The engineers assumed ‘two perfects make an extra perfect’. “But the reality is,” he continued, “It’s garbage. I call it ‘emergent design’. It’s where two technologies that independently were designed for one purpose, and they’re perfect at it, were later combined into something that made the sum of the parts worse than the individual pieces. And of course, it’s even more fun when X and Y become A, B, C, D, E, F, G…”

Curiosity creates hackers (in the original sense of the word). Natural hackers get drawn into the world of research and become either white hat or black hat researchers. The black hat researchers become a threat to cybersecurity – the white hats are a boon. 

“Many industries build lots of technologies where they simply don’t have the knowledge, the resources – I guess I could even say the will – to look at the security aspect,” says Ionescu. “So, I think we’re lucky as a society that we have these people that, thanks to their own curiosity and passion, are basically doing in many cases volunteer work; calling out how things could be better. Overall, we’re in a better place because people look at these issues – it’s good that we have these unbiased people doing research essentially for free. So, I’m happy they’re out there.”

Related: Hacker Conversations: Cris Thomas (AKA Space Rogue) From Lopht Heavy Industries

Related: Hacker Conversations: Inside the Mind of Daniel Kelley, ex-Blackhat

Related: Hacker Conversations: Youssef Sammouda, Bug Bounty Hunter

https://www.securityweek.com/hacker-conversations-alex-ionescu/




In Other News: Hacking Encrypted Linux Computers, Android Fuzzing, Skype Leaking IPs

SecurityWeek is publishing a weekly cybersecurity roundup that provides a concise compilation of noteworthy stories that might have slipped under the radar.

We provide a valuable summary of stories that may not warrant an entire article, but are nonetheless important for a comprehensive understanding of the cybersecurity landscape.

Each week, we will curate and present a collection of noteworthy developments, ranging from the latest vulnerability discoveries and emerging attack techniques to significant policy changes and industry reports.

Here are this week’s stories: 

Quickly hitting Enter key to hack an encrypted Linux computer 

Researchers at Pulse Security discovered that an attacker who has physical access to an encrypted Linux system can gain local root access to the computer — bypassing full-disk encryption — by quickly hitting Enter on the keyboard or using a special device to simulate the process. These types of attacks are not new. 

High-severity vulnerability patched in Chrome 

Advertisement. Scroll to continue reading.

A new Chrome 116 update patches a high-severity use-after-free vulnerability. These types of flaws can typically be combined with other bugs for sandbox escapes and remote code execution. The bug bounty for the vulnerability has yet to be determined by Google. 

Google details Android fuzzing efforts

Google has published a blog post detailing its Android fuzzing efforts, including how it finds vulnerabilities, why it continues to invest in fuzzing, challenges, and how others can contribute. 

Top-level domains and DNS issues

Cisco Talos has conducted research into top-level domain (TLDs) and DNS issues, highlighting potential risks related to the .kids TLD, ‘zombified’ DNS name issues related to various country TLDs, as well as problems with second-level TLDs. 

Skype mobile app is leaking IP addresses

The Skype mobile application is leaking IP addresses, according to a report from 404 Media. A hacker can obtain a targeted user’s IP by sending them a link over Skype — the victim does not have to interact with the link. Microsoft has been notified, but the company is not rushing to patch it. 

Rackspace says cost of ransomware attack remediation tops $10 million (so far)

After being hit by a ransomware attack in December 2022, cloud computing company Rackspace said in a recent earnings presentation that it has spent $10.8 million so far responding to the incident that impacted its hosted Exchange infrastructure, forcing it to sunset the offering. The company said it expects to continue to incur legal and other professional services costs in future periods.

University of Michigan cyberattack

The University of Michigan has been targeted in a cyberattack that resulted in significant disruptions to its systems, as well as internet outages. The university has not shared any information on the attack itself, citing an ongoing investigation. 

CISA and FBI release QakBot infrastructure indicators of compromise (IOCs)

CISA and the FBI have released IoCs associated with the recently disrupted QakBot botnet infrastructure. The botnet was targeted as part of an international law enforcement operation that involved the distribution of a utility designed to automatically remove the malware from infected systems.  

Classiscam cybercrime groups made millions by scamming users worldwide

Group-IB has a report on Classiscam, a scam operation that has allowed hundreds of cybercrime groups to make nearly $65 million by targeting individuals across 79 countries, tricking them into sending money for inexistent goods sold online. An automated scam-as-a-service program has made it easier for scammers to conduct their activities. 

Malwarebytes laying off 100 employees 

Cybersecurity firm Malwarebytes has laid off 100 employees as it prepares to separate its consumer- and enterprise-focused business units. Last year, the company terminated 14% of its staff (roughly 125 people). 

Related: In Other News: Africa Cybercrime Crackdown, Unpatched macOS Flaw, Investor Disclosures

Related: In Other News: US Hacking China, Unfixed PowerShell Gallery Flaws, Free Train Tickets

https://www.securityweek.com/in-other-news-hacking-encrypted-linux-computers-android-fuzzing-skype-leaking-ips/




L’FBI smantella la botnet Qakbot. Sequestrati 8,6 milioni di dollari in criptovaluta

Addio ad una della più grandi botnet malware attive nel panorama internazionale, responsabile di danni per “centinaia di milioni” di dollari a livello globale.

Ieri, l’FBI ha annunciato di aver “interrotto e smantellato” con successo il malware Qakbot, identificando oltre 700.000 computer infetti in tutto il mondo, di cui più di 200.000 negli Stati Uniti. Il Dipartimento di Giustizia ha inoltre annunciato il sequestro di oltre 8,6 milioni di dollari in criptovaluta dall’organizzazione cybercriminale di Qakbot, somma che sarà ora resa disponibile alle vittime.

“L’FBI ha neutralizzato questa catena di approvvigionamento criminale di vasta portata, tagliandola alle radici”, ha dichiarato il Direttore dell’FBI Christopher Wray in un videomessaggio. “Le vittime andavano dalle istituzioni finanziarie sulla costa orientale a un contraente governativo per infrastrutture critiche nel Midwest, fino a un produttore di dispositivi medici sulla costa occidentale.”

[embedded content]

L’operazione, condotta in collaborazione con le forze dell’ordine di Francia, Germania, Paesi Bassi, Romania, Lettonia e Regno Unito, rappresenta la più grande interruzione finanziaria e tecnica di un’infrastruttura botnet guidata dagli Stati Uniti, utilizzata dai cybercriminali per commettere ransomware, frodi finanziarie e altre attività criminali online.

Come funzionava il malware Qakbot

Il malware Qakbot è stato utilizzato per infettare i computer delle vittime tramite messaggi e-mail di spam contenenti allegati dannosi, ha affermato il Dipartimento di Giustizia. Una volta cliccato e attivato, l’agente malevolo agiva installando un ransomware, spegnendo i computer delle vittime e portando i criminali a richiedere il pagamento di un riscatto per sbloccare i dispositivi, ha affermato il dipartimento.

Una volta che le autorità hanno ottenuto l’accesso all’infrastruttura Qakbot è stato possibile identificare più di 700.000 computer in tutto il mondo, di cui 200.000 nei soli Stati Uniti, infettati dal malware. Sin dalla sua creazione nel 2008, il malware Qakbot è stato utilizzato in attacchi di ransomware e in altri reati informatici che hanno causato danni per centinaia di milioni di dollari a individui e aziende negli Stati Uniti e all’estero.

“Questa botnet ha fornito a criminali informatici come questi un’infrastruttura di comando e controllo composta da centinaia di migliaia di computer utilizzati per attacchi contro individui e aziende in tutto il mondo”, ha dichiarato Wray.

“Tutto questo è stato reso possibile dal lavoro dedicato dell’FBI di Los Angeles, dalla nostra Divisione Cyber presso la sede dell’FBI e dai nostri partner, sia qui che all’estero”, ha affermato Wray. “La minaccia informatica che affronta la nostra nazione sta diventando ogni giorno più pericolosa e complessa. Ma il nostro successo dimostra che la nostra stessa rete e le nostre stesse capacità sono più potenti.”

https://www.key4biz.it/lfbi-smantella-la-botnet-qakbot-sequestrati-86-milioni-di-dollari-in-criptovaluta/457551/




Truffe ed estorsioni con l’IA, le nuove frontiere del cybercrime passano per i deepfake vocali

Il nuovo crimine informatico emergente? L’uso dell’intelligenza artificiale e del machine learning per compiere truffe, estorsioni e “rapimenti virtuali”.

Negli Stati Uniti, l’FBI ha già messo in guardia il pubblico su come i criminali informatici utilizzino la tecnologia deepfake per manipolare foto e video innocui e convertirli in schemi redditizi di sextortion. La Federal Trade Commission ha stimato che nel 2022 le perdite derivanti da queste attività illecite hanno raggiunto i  2,6 miliardi di dollari.

Deepfake vocali generati grazie l’IA

Secondo recenti ricerche una truffa comune prevede l’utilizzo di file vocali falsi generati dall’intelligenza artificiale, noti anche come audio deepfake, che possono essere creati utilizzando quantità anche ridotte di informazioni biometriche raccolte da contenuti personali pubblicati in fonti pubbliche come TikTok, Facebook, Instagram e altre piattaforme social, inclusi i portali governativi. 

Strumenti di intelligenza artificiale come VoiceLab possono elaborare la biometria vocale, dando vita a un vocale deepfake che riproduce esattamente la voce di una persona specifica. Questo processo è anche definito clonazione vocale e si verifica quando la biometria vocale è utilizzata per compiere estorsioni o frodi.

Un caso reale di rapimento virtuale

Nell’aprile 2023, in Arizona, una donna di nome Jennifer De Stefano ha ricevuto una chiamata nella quale un anonimo affermava di aver rapito la figlia di 15 anni e chiedeva un riscatto di 1 milione di dollari, minacciando di compiere violenza sulla vittima, in caso di mancato pagamento. La donna ha affermato di aver sentito chiaramente il pianto, le urla e la voce supplichevole della figlia in sottofondo, anche se il criminale si è rifiutato di lasciarla parlare con la figlia al telefono. Dopo alcuni minuti di negoziazione, l’importo del riscatto è sceso a 50.000 dollari. Per fortuna, prima del pagamento, la vittima ha potuto verificare che sua figlia fosse al sicuro e che non fosse stata rapita. La questione è stata immediatamente denunciata alla polizia, che ha poi identificato la telefonata come una comune truffa.

Gli elementi di un sequestro virtuale

I giovani e i personaggi pubblici sono i primi a utilizzare le tecnologie emergenti o le piattaforme social in rapida crescita, per questo generano più dati biometrici che possono essere utilizzati per attacchi di rapimento virtuale. I cybercriminali utilizzano i social network come TikTok, Facebook e Instagram per cercare le vittime e creare un contesto che renda la truffa il più credibile possibile. Le vittime non solo perdono denaro a causa di questo schema cybercriminale, ma soffrono anche di un grande disagio emotivo. 

Gli elementi tipici di un attacco di rapimento virtuale sono i seguenti:

  1. Identificazione di una potenziale vittima (parente di un rapito). La vittima è una persona in grado di pagare un riscatto
  2. Identificazione di una potenziale vittima virtuale di rapimento (il rapito). Solitamente un minore
  3. Creazione di una storia. Più la storia è emotivamente manipolativa, più il giudizio e il pensiero critico di una vittima sono compromessi. È molto probabile che una persona spaventata si comporti con meno previdenza
  4. Raccolta della biometria vocale della vittima del rapimento virtuale, dai post sui social media. I cybercriminali possono anche prendere la voce di un attore da una scena di rapimento in un film e utilizzare la tecnologia deepfake per creare un audio.
  5. Identificare tempistiche ed elementi logistici. Sulla base degli aggiornamenti dei social media della vittima del rapimento virtuale, i cybercriminali daranno il via alla truffa quando il soggetto è fisicamente lontano dalla vittima del riscatto, per un periodo sufficientemente lungo. Questo impedisce alla vittima del riscatto di verificare rapidamente se il bambino/minore/rapito è al sicuro, consentendo all’attacco di andare a buon fine
  6. Effettuare la chiamata. Gli aggressori possono utilizzare software di modulazione vocale gratuiti per rendere la voce più spaventosa o minacciosa. Durante la chiamata, gli aggressori eseguiranno contemporaneamente l’audio deepfake del presunto rapito
  7. Attività post-chiamata. In caso di successo, queste attività possono includere il riciclaggio di denaro del riscatto, l’eliminazione di tutti i file pertinenti e la distruzione del telefono utilizzato 

Gran parte del lavoro in questo schema di attacco può essere ulteriormente automatizzato con strumenti di intelligenza artificiale, come ChatGPT. Utilizzando ChatGPT, ad esempio, un cybercriminale può fondere grandi set di dati di potenziali vittime non solo con informazioni vocali e video, ma anche con altri dati come la geolocalizzazione. Questo può anche servire per avere a disposizione un sistema di punteggio basato sul rischio per la selezione delle vittime, rendendo questo tipo di attacco ancora più redditizio e scalabile.

Lo studio dell’University College di Londra sui deepfake vocali

Uno studio dell’University College di Londra ha rilevato che le persone possono riconoscere il parlato generato artificialmente solo il 73% delle volte. Inoltre, i risultati erano gli stessi per lingue diverse: sia inglese che cinese.

Lo studio ha utilizzato un algoritmo di sintesi vocale addestrato su due set di dati pubblici in inglese e cinese. In anticipo, il programma ha generato 50 voci in ciascuna lingua. Questi campioni differivano da quelli su cui era stato addestrato l’algoritmo stesso.

I partecipanti (529 persone) hanno riconosciuto discorsi falsi solo il 73% delle volte. Un breve addestramento sulle caratteristiche dei deepfake ha portato solo un leggero miglioramento.

Sebbene l’IA generativa abbia vantaggi per le persone con disabilità, gli scienziati temono che governi e criminali informatici inizieranno ad abusare di queste nuove funzionalità. Così nel 2019 i truffatori hanno convinto l’amministratore delegato di una società energetica britannica a trasferire loro centinaia di migliaia di sterline imitando la voce del suo capo.

Il primo autore dello studio, Kimberly Mai, ha dichiarato: “Abbiamo utilizzato campioni generati da algoritmi relativamente vecchi. La domanda sorge spontanea: le persone saranno in grado di notare almeno qualcosa di sospetto nei record generati con la tecnologia più recente, ora e in futuro?”

https://www.key4biz.it/truffe-ed-estorsioni-con-lia-le-nuove-frontiere-del-cybercrime-passano-per-i-deepfake-vocali/457497/




UN Warns Hundreds of Thousands in Southeast Asia Roped Into Online Scams

The U.N. human rights office says criminal gangs have forced hundreds of thousands of people in Southeast Asia into participating in unlawful online scam operations, including false romantic ploys, bogus investment pitches, and illegal gambling schemes.

The Office of the U.N. High Commissioner for Human Rights, in a new report, cites “credible sources” that at least 120,000 people in strife-torn Myanmar and roughly 100,000 in Cambodia “may be held in situations where they are forced to carry out online scams.”

The report sheds new light on cybercrime scams that have become a major issue in Asia, with many of the workers trapped in virtual slavery and forced to participate in scams targeting people over the internet.

Laos, the Philippines and Thailand were also cited among the main countries of destination or transit for tens of thousands of people. Criminal gangs have increasingly targeted migrants, and lure some victims by false recruitment — suggesting they are destined for real jobs.

The rights office, citing the “enormity” of the scam operations, said the exact impact in terms of people and revenues generated is hard to estimate because of their secrecy and gaps in governmental response, but it’s believed to be in the billions of U.S. dollars every year.

Some victims have been subjected to torture, cruel punishments, sexual violence and arbitrary detention, among other crimes, it said.

In June, Philippine police backed by commandos led a raid to rescue more than 2,700 workers from China, the Philippines, Vietnam, Indonesia and more than a dozen other countries who were allegedly swindled into working for fraudulent online gaming sites and other cybercrime groups.

Advertisement. Scroll to continue reading.

In May, leaders from the Association of Southeast Asian Nations agreed in a summit in Indonesia to tighten border controls and law enforcement and broaden public education to fight criminal syndicates that traffic workers to other nations, where they are made to participate in online fraud.

https://www.securityweek.com/un-warns-hundreds-of-thousands-in-southeast-asia-roped-into-online-scams/




Meta Fights Sprawling Chinese ‘Spamouflage’ Operation

Meta on Tuesday said it purged thousands of Facebook accounts that were part of a widespread online Chinese spam operation trying to covertly boost China and criticize the West.

The campaign, which became known as “Spamouflage“, was active across more than 50 platforms and forums including Facebook, Instagram, TikTok, YouTube and X, formerly known as Twitter, according to a Meta threat report.

“We assess that it’s the largest, though unsuccessful, and most prolific covert influence operation that we know of in the world today,” said Meta Global Threat Intelligence Lead Ben Nimmo.

“And we’ve been able to link Spamouflage to individuals associated with Chinese law enforcement.”

More that 7,700 Facebook accounts along with 15 Instagram accounts were jettisoned in what Meta described as the biggest ever single takedown action at the tech giant’s platforms.

“For the first time we’ve been able to tie these many clusters together to confirm that they all go to one operation,” Nimmo said.

The network typically posted praise for China and its Xinjiang province and criticisms of the United States, Western foreign policies, and critics of the Chinese government including journalists and researchers, the Meta report says.

Advertisement. Scroll to continue reading.

The operation originated in China and its targets included Taiwan, the United States, Australia, Britain, Japan, and global Chinese-speaking audiences.

Facebook or Instagram accounts or pages identified as part of the “large and prolific covert influence operation” were taken down for violating Meta rules against coordinated deceptive behavior on its platforms.

Meta’s team said the network seemed to garner scant engagement, with viewer comments tending to point out bogus claims.

Clusters of fake accounts were run from various parts of China, with the cadence of activity strongly suggesting groups working from an office with daily job schedules, according to Meta.

Doppelganger

Some tactics used in China were similar to those of a Russian online deception network exposed in 2019, which suggested the operations might be learning from one another, according to Nimmo.

Meta’s threat report also provided analysis of the Russian influence campaign called Doppelganger, which was first disrupted by the security team a year ago.

The core of the operation was to mimic websites of mainstream news outlets in Europe and post bogus stories about Russia’s war on Ukraine, then try to spread them online, said Meta head of security policy Nathaniel Gleicher.

Companies involved in the campaign were recently sanctioned by the European Union.

Meta said Germany, France and Ukraine remained the most targeted countries overall, but that the operation had added the United States and Israel to its list of targets.

This was done by spoofing the domains of major news outlets, including the Washington Post and Fox News.

Gleicher described Doppelganger, which is intended to weaken support of Ukraine, as the largest and most aggressively persistent influence operation from Russia that Meta has seen since 2017.

Related: Meta Develops New Kill Chain Thesis

Related: Facebook Battles Cyber Campaigns Targeting Ukraine

Related: Facebook Parent Meta Links Influence Campaign to US Military

https://www.securityweek.com/meta-fights-sprawling-chinese-spamouflage-operation/




Leaseweb Reports Cloud Disruptions Due to Cyberattack 

Dutch infrastructure-as-a-service and cloud solutions provider Leaseweb shut down some critical systems last week due to a cyberattack.

The company said it detected unusual activity in certain areas of its cloud environments on the night of August 22. 

“The issue had an impact on a specific portion of our cloud-based infrastructure leading to downtime for a small number of cloud customers,” Leaseweb told customers in an email notification. 

“In response to this event, we’ve taken quick and determined steps to reduce potential risks,” the company added. “This includes temporarily disabling certain critical systems impacting the Customer Portal.”

Impacted systems should now be restored. The company’s status page does not mention any issues at the time of writing. 

SecurityWeek has reached out to Leaseweb for more information about the incident, including whether it involved ransomware and whether any customer data has been compromised. This article will be updated if the company responds.

According to its website, Leaseweb provides cloud, CDN, managed hosting, colocation, bare metal server, and other services to more than 17,000 customers, including SMBs and enterprises. 

Advertisement. Scroll to continue reading.

Related: These Are the Top Five Cloud Security Risks, Qualys Says

Related: GAO Tells Federal Agencies to Fully Implement Key Cloud Security Practices

Related: Iran-Run ISP ‘Cloudzy’ Caught Supporting Nation-State APTs, Cybercrime Hacking Groups

https://www.securityweek.com/leaseweb-reports-cloud-disruptions-due-to-cyberattack/