I “Vulkan Files” e la cyberwar di Putin

L’inchiesta “Vulkan Files” svela come la società russa Vulkan, che si occupa di sviluppo software e sicurezza informatica, lavori per i servizi segreti russi realizzando armi informatiche e fornendo servizi all’intelligence russa.

I documenti, che fanno riferimento al periodo che va dal 2016 al 2021, provengono da un informatore anonimo probabilmente interno alla NTC Vulkan che mosso dal disappunto per il cyber-conflitto invia al quotidiano tedesco Süddeutsche Zeitung circa 5.000 pagine dopo l’invasione Russa dell’Ucraina.

“People should know the dangers of this. Because of the events in Ukraine, I decided to make this information public. The company is doing bad things and the Russian government is cowardly and wrong. I am angry about the invasion of Ukraine and the terrible things that are happening there. I hope you can use this information to show what is happening behind closed doors.”

Virgolettato riportato dal The Guardian, che insieme ad altri media internazionali indagano sul consistente fascicolo contenente documenti interni dove si raccontano gli strumenti messi a disposizione del Servizio di sicurezza federale russo (FSB), le sue forze armate (GOU e GRU) e il Servizio di intelligence estero (SVR) da parte della società Vulkan e apparentemente utilizzati in diverse operazioni informatiche di grande rilievo, come le interferenze nelle elezioni presidenziali degli Stati Uniti del 2016 e il cyber spionaggio.

Il 30 marzo 2023 vengono diffusi i primi dettagli dell’indagine, anche se un giudizio definitivo sulla veridicità rimane difficile da sostenere, i file appaiono autentici a molteplici agenzie di intelligence; essi sono composti da progetti ben strutturati, comunicazioni email, dettagli di contratti e relativi budget.

Pur non essendo ancora confermato l’utilizzo degli strumenti realizzati da Vulkan in contesti reali, si indaga su possibili connessioni con gli attacchi informatici perpetrati da gruppi di cyber criminali risalenti alla Russia quali Sandworm, ritenuto responsabile di cyber attacchi su scala globale come il lancio del malware NotPetya, il blackout che per ben due volte ha paralizzato l’Ucraina e l’interruzione delle Olimpiadi in Corea del Sud. Le tecnologie messe a punto dalla Vulcan appaiono in grado di colpire infrastrutture critiche come le linee elettriche, trasporto ferroviario, marittimo e aereo.

Figure 1: Assessment of capabilities documented in NTC Vulkan aligned with broader strategic goals of Russian intelligence services https://www.mandiant.com/resources/blog/cyber-operations-russian-vulkan

Dai dati analizzati emerge la preferenza di target fortemente sensibili, quali le infrastrutture critiche e sistemi industriali, prediligendo l’indirizzamento di operazioni offensive verso obiettivi OT attraverso attacchi IT/OT. All’interno dei documenti si rintracciano i dettagli relativi a tre progetti in particolare: Scan – strumento che scansiona Internet alla ricerca di vulnerabilità da utilizzare in futuri attacchi informatici; Amesit – un framework per la sorveglianza e il controllo di Internet nelle regioni sotto il comando della Russia che consente anche la disinformazione tramite falsi profili di social media – e Krystal-2B – programma di formazione per operatori informatici sui metodi necessari per abbattere le infrastrutture ferroviarie, aeree e marittime.

A cura della Redazione

Condividi sui Social Network:

https://www.ictsecuritymagazine.com/notizie/i-vulkan-files-e-la-cyberwar-di-putin/




Il Social Engineering

«La guerra si fonda sull’inganno»
L’Arte della Guerra, Sun Tzu

Il social engineering – o ingegneria sociale – è una disciplina che sfrutta processi cognitivi di influenzamento, inganno e manipolazione per indurre una persona a compiere un’azione o a comunicare informazioni riservate.

La storia è Maestra di vita, e l’arte di ingannare l’avversario non si sviluppa certamente con la nascita dei computer e della sicurezza informatica: probabilmente la più antica prova di un attacco di ingegneria sociale si trova nella Bibbia, Genesi 27, dove Rebecca inganna suo marito Isacco facendogli benedire il secondogenito Giacobbe, rendendolo il suo successo re, invece di Esaù, che era il maggiore.

Ma i libri di storia sono pieni di episodi in cui si sono perpetrati inganni e tranelli, sicuramente l’esempio scolastico per eccellenza è quello del Cavallo di Troia, che i Greci usarono per espugnare la città di Troia (non per nulla con il termine “Trojan Horse” intendiamo un tipo di codice o software dannoso che sembra legittimo ma può prendere il controllo del tuo computer, progettato per danneggiare, interrompere, rubare o in generale infliggere altre azioni dannose ai tuoi dati o alla tua rete).

Le azioni criminali basate sull’ingegneria sociale, di cui abbiamo notizie fin dalla notte dei tempi, possono concretizzarsi con o senza l’ausilio di tecnologia.

Purtroppo è un dato di fatto che l’ingegneria sociale si è evoluta nel tempo da una tecnica di attacco che puntava esclusivamente sul carisma e l’abilità dell’attaccante verso una strategia ibrida, ancora più incisiva e subdola che sfrutta sia le abilità cognitive che quelle informatiche.

Questo è stato reso possibile negli ultimi anni grazie alla crescita della digitalizzazione della comunicazione con la diffusione dei social (fucina inesauribile di informazioni) e dei vari servizi di messaggistica. L’ingegnere sociale sfrutta, per l’appunto, la percezione distorta che l’utente medio ha di questi strumenti, ritenendoli puramente virtuali, privi di insidie e scollegati dal mondo reale.

I cybercriminali sanno che l’ingegneria sociale funziona meglio quando ci si concentra sulle emozioni delle persone. Approfittare delle emozioni umane è molto più facile che hackerare una rete o cercare delle vulnerabilità.

Il principio alla base dell’ingegneria sociale è quello di sfruttare il fattore umano, ovvero mettere le persone in situazioni in cui si sa già che faranno affidamento sulle forme più comuni di interazione sociale, come la tendenza a fidarsi delle persone e a rivelare informazioni private (magari pubblicando sui social network), il desiderio di un professionista nel dimostrare acume e superiorità nel suo campo, la tendenza della maggior parte delle persone ad essere più disponibili verso chi mostra interesse nei loro riguardi.

L’attacco fa, dunque, leva su tratti caratteristici dell’essere umano, come la disponibilità e la buona fede dell’attaccato, l’ignoranza e la disattenzione o, ancora, la paura, l’urgenza, la gratitudine.

“Si possono investire milioni di dollari per i propri software, per l’hardware delle proprie macchine e per dispositivi di sicurezza all’avanguardia, ma se c’ è anche solo un unico dipendente della nostra azienda che può essere manipolato con un attacco di ingegneria sociale, tutti i soldi investiti saranno stati inutili” (dal libro l’Arte dell’Inganno di Kevin Mitnick).

In un contesto caratterizzato dall’incessante ricerca di nuovi e più sofisticati sistemi tecnologici di difesa informatica, tali da rendere le reti sempre più impenetrabili ed i software sempre più sofisticati, ciò che indebolisce il processo di security dagli attacchi di cognitive hacking è proprio l’uomo.
Le tattiche utilizzate per eseguire un buon attacco di ingegneria sociale si basano principalmente sull’elicitation (e “elicitazione”) termine inglese che consiste nel porre domande preparate apposta, tramite un insieme di tecniche e metodi (utilizzati dai professionisti dell’intelligence e della cyber intelligence) per raccogliere informazioni di nascosto.

In sostanza, un professionista dell’intelligence si impegna in una conversazione con l’obiettivo di raccogliere informazioni e, utilizzando metodi di elicitazione, carpisce le informazioni di cui ha bisogno senza che l’obiettivo si renda conto di essere sfruttato per ottenere informazioni, che possono essere successivamente utilizzate in una campagna di ingegneria sociale su larga scala.

L’elicitazione è un’attività poco rischiosa e difficile da individuare. Spesso e volentieri chi cade vittima rivelando informazioni importanti, neanche si rende conto di come sia potuta uscire l’informazione e, se anche una domanda ad un secondo ripensamento dovesse risultare sospetta, le vittime tendono a considerarla una domanda a cui avrebbero potuto rispondere oppure no, in cui nessuno si ricorda del contenuto delle informazioni che sono trapelate.
Basta fare al bersaglio individuato la domanda giusta al momento giusto e tutte le porte si apriranno.

“Se il vostro avversario ha un carattere iroso, dovete tentare di irritarlo, se è arrogante, provate a incoraggiare la sua arroganza… Colui che è in grado di muovere il proprio avversario lo fa creando una situazione che indurrà il nemico a compiere una certa mossa; questi alletta il nemico con qualcosa che l’altro pensa di poter far suo. Tiene in movimento il nemico facendogli pendere davanti un’esca e poi attaccandolo con truppe scelte.”
(Sun Tzu, l’Arte della Guerra)

Ma se un qualsiasi cittadino, “custode” di informazioni riservate, rischia di mettere a repentaglio la propria sicurezza e di chi gli sta intorno, pensiamo cosa potrebbe verificarsi se la vittima è un soggetto che svolge un’attività di Pubblica Sicurezza.

In ambito di Sicurezza Nazionale, l’utilizzo di reti informatiche non classificate, come Facebook, Twitter, Instagram (solo per citarne i più conosciuti), espone le Forze Armate a rischi sempre più elevati di perdita di informazioni sensibili che, se inserite in un opportuno ciclo di intelligence, possono arrecare un notevole danno alla sicurezza del contingente militare, delle operazioni in corso e più in generale della Difesa.

Si può a questo punto provare a definire il concetto di cyber-intelligence come l’insieme degli sforzi e delle attività svolte da o per conto di un’organizzazione, progettate e messe in atto per identificare, tracciare, misurare e/o monitorare, attraverso l’utilizzo di strumenti informatici, le minacce digitali, i dati e/o le operazioni di un avversario.

Data la peculiarità e la complessità delle attività che si celano dietro questo termine, le operazioni di cyber-intelligence spesso possono non essere sufficienti da sole a fornire al decisore una visione informativa completa. In questi casi, dunque, ad esse potranno essere affiancati altri metodi d’intelligence tradizionali come, prima fra tutti, la Human intelligence (HUMINT) o la Signal intelligence (SIGINT). Infatti, a differenza delle armi nucleari e delle altre armi di distruzione di massa, le c.d. cyber-weapons non richiedono particolari infrastrutture, né tantomeno materiali speciali e, spesso, neppure conoscenze tecniche particolarmente approfondite per essere predisposte. In quest’ottica, quindi, si dovrebbe fare esclusivo affidamento sulle poche, spesso labili, tracce elettroniche lasciate dall’avversario nelle fasi preliminari all’attacco informatico, ovvero quelle di footprinting o fingerprinting.

I tradizionali metodi di cyber-intelligence per la raccolta di informazioni riservate, pertanto, potrebbero mostrare il fianco quando l’obiettivo è quello di comprendere a pieno le capacità e/o le intenzioni reali del nemico, qualora non vengano comunque affiancati anche da attività similari nel “mondo fisico”. Un ulteriore elemento che si collega a quanto appena analizzato e che pertanto, seppure brevemente, deve essere tenuto in debita considerazione, è quello relativo alle tecniche d’ingegneria sociale, di cui finora abbiamo discusso. Non si deve dimenticare, infatti, che la maggior parte dei malware o delle tecniche di phishing, ad esempio, utilizzano, seppur in maniera generalizzata e non mirata, delle tecniche di ingegneria sociale per far sì che l’utente del sistema informatico sia invogliato ad aprire l’allegato infetto, ovvero ritenga valido e credibile il contenuto della mail ricevuta.

Appare evidente allora che, per fronteggiare una simile minaccia, che basa la sua forza sull’insicurezza degli strumenti tecnologici, sulla poca accortezza degli utenti e sulle tecniche di ingegneria sociale, un primo argine alla possibile fuoriuscita di informazioni classificate e sensibili viene proprio da policies di cyber security stringenti, accorte e, soprattutto, specificatamente tarate sulle esigenze operative del contingente che in un’ottica di sicurezza nazionale, va intesa come la capacità di resistere alle minacce intenzionali e non intenzionali attuate contro i sistemi informatici a rilevanza nazionale, nonché di rispondere e rimediare a dette azioni.

In una società che ormai poggia le fondamenta sul concetto stesso di informazione e sulla rilevanza che questo concetto ha all’interno dei meccanismi di funzionamento di tutti i sistemi cibernetici, su cui si basa il dialogo e l’infosharing tra i vari Stati su cui poggia il perno delle discussioni in atto a livello internazionale al fine di armonizzare il quadro normativo e gli standard di sicurezza, risulta particolarmente intuitivo comprendere come impossessarsi, proteggere e usare la maggior quantità possibile di esse sia lo sforzo più rilevante a supporto di un’efficace strategia di vittoria per molti dei conflitti che saranno combattuti in futuro. Se è vero, infatti, che: “In linea di massima, a proposito della battaglia, l‘attacco diretto mira al coinvolgimento; quello di sorpresa, alla vittoria” (Sun Tzu, l’Arte della Guerra), allo stato attuale, proprio gli attacchi informatici possono essere ancora in grado di conseguire con facilità questo espediente.

“Se l’intelligence è indispensabile per comprendere la realtà, la cyber Intelligence lo è ancora di più per orientarsi nella realtà e nel suo doppio: le galassie in espansione del web” (Cyber intelligence, Mario Caligiuri).

Articolo a cura di Giuseppe Maio

Profilo Autore

Giuseppe Maio è Security Advisor in ambito Governance, Risk and Compliance (GRC) per un importante società di Consulenza strategica. Dopo aver conseguito una laurea in Giurisprudenza presso l’Università Mediterranea di Reggio Calabria, ha frequentato un master di II Livello presso
l’Università LUISS Guido Carli in “Cybersecurity: Politiche Pubbliche, Normative e Gestione”. Attualmente è membro della Commissione Cyber Threat Intelligence & Warfare presso la Società Italiana di Intelligence.

Condividi sui Social Network:

https://www.ictsecuritymagazine.com/articoli/il-social-engineering/




Casino Giant Crown Resorts Investigating Ransomware Group’s Data Theft Claims

Australian casino giant Crown Resorts this week confirmed that the Cl0p ransomware group contacted them to claim the theft of data as part of the GoAnywhere attack.

The incident occurred in late January, when a zero-day vulnerability in Fortra’s GoAnywhere managed file transfer (MFT) software was exploited to access files belonging to Fortra customers.

The exploitation of the bug – tracked as CVE-2023-0669 and patched in early February– was attributed to a Russian-speaking threat actor associated with the Cl0p ransomware, which recently started adding the names of alleged victims to its Tor-based leak site.

The Cl0p ransomware operators have claimed the theft of data from roughly 130 organizations that used GoAnywhere, with some of them already confirming potential impact, including Community Health Systems, Hitachi Energy, Hatch Bank, Rubrik, Atos, City of Toronto, Procter & Gamble, Pluralsight, Saks Fifth Avenue, UK’s PPF, Virgin Red, and Rio Tinto.

Several of the impacted organizations told SecurityWeek that the stolen data poses no threat to customers or employees.

In a public statement on its website, Crown Resorts this week confirmed that it was a Fortra customer and that the Cl0p ransomware operators contacted it to claim the theft of company data:

“We were recently contacted by a ransomware group who claim they have illegally obtained a limited number of Crown files. We are investigating the validity of this claim as a matter of priority.

“We can confirm no customer data has been compromised and our business operations have not been impacted. We are continuing to work with law enforcement and have notified our gaming regulators as part of the ongoing investigation and will provide relevant updates, as necessary.”

The largest gaming and entertainment group in Australia, Crown Resorts operates large complexes in Melbourne, Perth, and Sydney. It was acquired by US private equity firm Blackstone in 2022.

This week, German insurer giant Munich Re, which was also added to Cl0p’s leak site, stated that the incident only impacted some test files.

“Munich Re currently has no contractual relationship with the company affected. For test purposes, only test files with meaningless content were sent, i.e. containing no business, client or personnel data,” the company said.

Fortra may face a class action suit as a result of the cyberattack, a complaint filed with the US District Court for the District of Minnesota shows. Per the complaint, the company failed to properly secure the MFT service, which led to the January data breach that impacted over 139,000 individuals.

Related: GoAnywhere Zero-Day Attack Hits Major Orgs

Related:ChatGPT Data Breach Confirmed as Security Firm Warns of Vulnerable Component Exploitation

Related:14 Million Records Stolen in Data Breach at Latitude Financial Services

https://www.securityweek.com/casino-giant-crown-resorts-investigating-ransomware-groups-data-theft-claims/




Nigerian BEC Scammer Sentenced to Prison in US

A Nigerian national was sentenced this week to four years and one month in prison in the US for his role in a business email compromise (BEC) fraud scheme.

The man, Solomon Ekunke Okpe, 31, of Lagos, participated in multiple BEC, credit card, work-from-home, check-cashing, and romance scams targeting banks, businesses, and individuals in the US and abroad, including First American Holding Company and MidFirst Bank.

The schemes, the US Department of Justice says, were “intended to cause more than a million dollars in losses to US victims”.

According to the DoJ, Okpe and his co-conspirators sent out phishing emails to steal credentials and other sensitive information, hacked into online accounts, assumed fake identities and impersonated people, and trafficked and used stolen credit cards.

Posing as trusted individuals, the cybercriminals deceived banks and companies into transferring funds to bank accounts they controlled.

Posing as online employers on job websites and forums, the fraudsters claimed to hire work-from-home ‘employees’. These individuals were often directed to perform actions facilitating the fraud schemes, such as creating bank and payment processing accounts, cashing/depositing counterfeit checks, and transferring/withdrawing money.

Okpe and other participants in the scheme also conducted romance fraud, creating accounts on dating websites and engaging with individuals under fictitious identities, and then asking the intended victims to transfer money overseas or to receive proceeds from wire-transfer scams.

Arrested in Malaysia, Okpe was detained there for more than two years, contesting the extradition to the US.

Last week, Johnson Uke Obogo, one of Okpe’s co-conspirators, was sentenced to one year and one day in prison for his role in related fraud schemes. Obogo was arrested in the UK.

Okpe and Obogo were extradited to the US in 2022. In December, both pleaded guilty to wire, bank, and mail fraud charges.

Related:Australia Dismantles BEC Group That Laundered $1.7 Million

Related: Fugitive Arrested After 3 Years on Charges Related to BEC Scheme

Related:Three Nigerian BEC Fraudsters Extradited From UK to US

https://www.securityweek.com/nigerian-bec-scammer-sentenced-to-prison-in-us/




Thousands Access Fake DDoS-for-Hire Websites Set Up by UK Police

The UK’s National Crime Agency (NCA) has been running several fake DDoS-for-hire websites in an effort to infiltrate the cybercrime marketplace and collect information on individuals engaging in these types of activities.

The law enforcement agency has set up an unspecified number of websites that claim to allow users to launch distributed denial-of-service (DDoS) attacks against a specified target. 

These types of services, also known as ‘booter’ or ‘stresser’ services, have posed a significant problem to many organizations around the world, as they allow individuals with limited skills and financial resources to launch highly disruptive attacks. 

The fake DDoS-for-hire websites run by the NCA were set up as part of an international law enforcement operation named ‘Power Off’. Last year, the same operation resulted in the seizure of 46 internet domains associated with booter services. 

The NCA recently decided to replace the homepage of one of its fake websites with a page informing visitors that their information has been collected and that they should expect to be contacted by law enforcement.

Fake DDoS for hire website

“All of the NCA-run sites, which have so far been accessed by around several thousand people, have been created to look like they offer the tools and services that enable cyber criminals to execute these attacks,” the agency said. “However, after users register, rather than being given access to cyber crime tools, their data is collated by investigators.”

The identified users of the fake DDoS-for-hire websites who are located in the UK will be contacted by the NCA or police and warned about the consequences of their actions. Information about users in other countries will be passed on to their respective law enforcement agencies. 

Given that minimal technical skills are required to launch DDoS attacks through booter services, it’s likely that many of the users of these websites don’t have the knowledge to hide their true identity from a well-resourced law enforcement agency. 

Related: US Authorities Seize Domains Selling Stolen Data, DDoS Services

Related: DDoS-for-Hire Service Admin Gets 13 Months in Prison

Related: Man Sentenced to 5 Years in Prison for DDoS Attacks

https://www.securityweek.com/thousands-access-fake-ddos-for-hire-websites-set-up-by-uk-police/




Australia Dismantles BEC Group That Laundered $1.7 Million

The Australian Federal Police on Friday announced the arrest of four individuals accused of being involved in business email compromise (BEC) and other types of online fraud.

The group, authorities say, orchestrated more than 15 sophisticated cybercrime attacks and allegedly operated approximately 180 bank accounts to support criminal activities.

Between January, 2020, and March, 2023, police say the cybercriminals created more than 80 bank accounts using stolen identities, to transfer stolen money out of Australia. Bank accounts in South Africa were used to launder roughly $1.1 million.

Overall, the group is believed to have laundered more than $1.7 million from BEC attacks, Facebook marketplace scams, and fraudulent superannuation investments.

Individual losses ranged between $2500 and close to $500,000, with one Indonesian company losing over $100,000 in a BEC attack.

The suspects, two men and two women, are charged with possessing and producing false documents, dishonestly dealing in personal financial information, and dealing in proceeds of crime.

The arrests were announced alongside a fresh warning from the U.S. Federal Bureau of Investigation (FBI) about BEC schemes where cybercriminals use spoofed email domain addresses to initiate the bulk purchase of goods from vendors in the US.

According to the FBI, the orders seem legitimate, but the cybercriminals provide fake credit references and fraudulent forms to vendors and ask for credit repayment terms, which allows them to place orders without providing upfront payment.

“Victimized vendors ultimately discover the fraud after attempts to collect payment are unsuccessful or after contacting the company they believed had initially placed the purchase order, only to be notified that the source of the emails was fraudulent,” FBI’s alert explains (PDF).

As part of the observed attacks, the cybercriminals ordered construction materials, agricultural supplies, computer technology hardware, and solar energy products.

Related:US Food Companies Warned of BEC Attacks Stealing Food Product Shipments

Related: Fugitive Arrested After 3 Years on Charges Related to BEC Scheme

Related: Three Nigerian BEC Fraudsters Extradited From UK to US

https://www.securityweek.com/australia-dismantles-bec-group-that-laundered-1-7-million/




‘Grim’ Criminal Abuse of ChatGPT is Coming, Europol Warns    

Criminals are set to take advantage of artificial intelligence like ChatGPT to commit fraud and other cybercrimes,
Europe’s policing agency warned on Monday.

From phishing to disinformation and malware, the rapidly evolving abilities of chatbots will be used not only to better mankind, but to scam it too, Europol said in a new report.

Created by US startup OpenAI, ChatGPT appeared in November and was quickly seized upon by users amazed at its ability to answer difficult questions clearly, write sonnets or code, and even pass exams.

“The potential exploitation of these types of AI systems by criminals provides a grim outlook,” The Hague-based Europol said. Europol’s new “Innovation Lab” looked at the use of chatbots as a whole but focused on ChatGPT during a series of workshops as it is the highest-profile and most widely used, it said.

Criminals could use ChatGPT to “speed up the research process significantly” in areas they know nothing about, the agency found.
This could include drafting text to commit fraud or give information on “how to break into a home, to terrorism, cybercrime and child sex abuse,” it said.

The chatbot’s ability to impersonate speech styles made it particularly effective for phishing, in which users are tempted to click on fake email links that then try to steal their data, it said.

ChatGPT’s ability to quickly produce authentic sounding text makes it “ideal for propaganda and disinformation purposes, as it allows users to generate and spread messages reflecting a specific narrative with relatively little effort.”

ChatGPT can also be used to write computer code, especially for non-technically minded criminals, Europol said.

“This type of automated code generation is particularly useful for those criminal actors with little or no knowledge of coding and development,” it said.

An early study by US-Israeli cyber threat intel company Check Point Research (CPR) showed how the chatbot can be used to infiltrate online systems by creating phishing emails, Europol said.

While ChatGPT had safeguards including content moderation, which will not answer questions that have been classified harmful or biased, these could be circumvented with clever prompts, Europol said.

AI was still in its early stages and its abilities were “expected to further improve over time,” it added.

“It is of utmost importance that awareness is raised on this matter, to ensure that any potential loopholes are discovered and closed as quickly as possible,” Europol said.

Related: ChatGPT and the Growing Threat of Bring Your Own AI to the SOC

Related: ChatGPT Integrated Into Cybersecurity Products as Industry Tests Its Capabilities

Related: Malicious Prompt Engineering With ChatGPT

Related: Cyber Insights 2023 | Artificial Intelligence

https://www.securityweek.com/grim-criminal-abuse-of-chatgpt-is-coming-europol-warns/




US Charges 20-Year-Old Head of Hacker Site BreachForums

The US Justice Department said Friday it had charged the founder of BreachForums, a major underground website for computer hackers that had published large amounts of data stolen from Twitter.

Conor Brian Fitzpatrick, 20, of Peekskill, New York, was charged with hacking conspiracy for running BreachForums, which the Justice Department said claimed to have more than 340,000 members.

The forum was shut down on Tuesday, just days after Fitzpatrick — known online as pompompurin — was arrested on March 15.

For the past year BreachForums has been one of the leading dark web hacker sites, a virtual marketplace for people to buy, sell and trade hacked or stolen data.

It had filled the role played by another such marketplace, RaidForums, seized by US authorities in April 2022.

BreachForums, like its predecessor, offered bank account information, social security numbers, other personally identifying information and means of identification, hacking tools, breached databases, login information for compromised online accounts, and hacking services for hire, the Justice Department said.

On January 4, a BreachForums user posted the names and contact information for around 200 million members of a US social network, the Justice Department said.

A number of specialist websites on computer security identified the information as having come from Twitter.

Weeks earlier, another released the details of nearly 88,000 members of InfraGuard, a partnership between private companies and the FBI focused on protecting critical infrastructure.

According to a court filing, Fitzpatrick admitted to the FBI that he owned and administered BreachForums and previously had an account on RaidForums.

He called himself a middleman and earned up to $1,000 a day, it said.

“Today, we continue our work to dismantle key players in the cybercrime ecosystem,” said Deputy Attorney General Lisa Monaco in a statement.

Fitzpatrick was charged with one count of conspiracy to commit access device fraud, which can bring up to five years in prison.

https://www.securityweek.com/us-charges-20-year-old-head-of-hacker-site-breachforums/




Siamo “dataconsapevoli”? Il cybercrime al tempo dell’economia data-driven


Quanto siamo “dataconsapevoli”? Con questa domanda si è aperto l’evento Attiva Incontra di Attiva Evolution, un’occasione di confronto per cercare di capire se le aziende sono consapevoli del valore dei propri dati e se hanno intrapreso il cammino giusto per gestirli e proteggerli.

L’incontro, che ha avuto luogo presso Ruote da sogno a Reggio Emilia, ha visto alternarsi le opinioni di tre figure provenienti da mondi diversi ma in qualche modo affini: Filippo Zizzadoro, psicologo e speaker; Giorgia Paola Dragoni, ricercatrice Senior Osservatorio Cybersecurity & Data Protection Politecnico di Milano; Matteo Zambon, CTO & Co-Founder di Tag Manager Italia.

Il cybercrime conosce già l’importanza dei dati

Il quadro che è emerso dalla discussione è piuttosto preoccupante: le aziende non hanno ancora compreso l’importanza dei dati, e di conseguenza non hanno implementato misure adeguate per proteggerli. Il cybercrime, al contrario, ha ben chiaro qual è il vero valore delle informazioni e sta concentrando tutti i suoi sforzi per trafugarli e ottenere un guadagno economico. Come ha spiegato Dragoni, il cybercrimine è diventato un vero e proprio business, nel quale i gruppi criminali collaborano, vendono e acquistano prodotti, permettendo anche ai meno esperti di sferrare attacchi.

cybercrime dataconsapevoli attiva evolution

Riccardo Meggiato, moderatore, con Filippo Zizzadoro, Giorgia Paola Dragoni e Matteo Zambon – Attiva Evolution

Il contesto geopolitico attuale ha aumentato la consapevolezza delle aziende riguardo la centralità dei dati e l’importanza di avere una buona linea difesa: tra il 2021 e il 2022 c’è stato un aumento di spesa in cybersecurity del 18%, l’incremento più rilevante dall’inizio delle osservazioni.

È il settore manifatturiero a investire più degli altri: le aziende vogliono ripensare i processi, valutare i nuovi rischi e rivedere la catena di approvvigionamento scegliendo fornitori e collaboratori più vicini ai propri ideali.

Ma se si guarda ai governi del G8, l’Italia è il paese che investe di meno in cybersecurity: soltanto lo 0,10% del PIL nazionale, la metà rispetto a paesi come Francia o Germania. La spesa sta crescendo di anno in anno, ma i numeri non sono ancora sufficienti per poterci confrontare con le altre realtà internazionali.

Una transizione lenta

L’Agenzia per la Cybersicurezza Nazionale nel suo primo anno di attività è riuscita a dare una direzione strategica per aumentare la sicurezza e resilienza nazionali; inoltre, l’introduzione del NIS2 sta spingendo molte realtà a investire per adeguarsi alle nuove normative ed evitare sanzioni.

cybercrime

Il motore principale del cambiamento per ora è proprio quello della compliance normativa. Nonostante l’obiettivo finale sia lo stesso, serve in primis costruire una cultura del dato e della cybersecurity per far sì che le misure di sicurezza vengano applicate e mantenute con piena coscienza, e non solo perché imposte dall’alto.

Siamo sulla strada giusta, ma c’è ancora molto da fare.  Le imprese stanno cominciando a capire quali sono gli impatti del cybercrime e della perdita di dati, ma mancano ancora dei piani di difesa e budget adeguati.

Condividi l’articolo



Articoli correlati

Altro in questa categoria


https://www.securityinfo.it/2023/03/24/dataconsapevoli-cybercrime-data-driven/?utm_source=rss&utm_medium=rss&utm_campaign=dataconsapevoli-cybercrime-data-driven




BreachForums Shut Down Over Law Enforcement Takeover Concerns

An administrator of the popular cybercrime forum BreachForums has announced the shutdown of the website following the arrest of Conor Brian Fitzpatrick, who was allegedly running the portal.

Also known as Breached, BreachForums was launched roughly a year ago, as an alternative to the cybercrime marketplace RaidForums, which was seized by US authorities in February 2022.

Nearly identical to RaidForums in appearance, Breached quickly became an appealing alternative to the dismantled marketplace, especially since it promised incentives such as the ability to retain the paid ranking users previously held.

Between March 2022 and November 2022, BreachForums went from 1,500 members to more than 192,000, cybersecurity firm Flashpoint notes.

Last week, US authorities announced the arrest of Conor Brian Fitzpatrick, 21, of Peekskill, New York, for allegedly running BreachForums. Court documents revealed that he admitted to the investigators that he owned and administered the cybercriminal forum, using the online moniker Pompompurin.

This week, BreachForums administrator ‘Baphomet’ posted a message on the forum’s Telegram channel to announce the website’s shutdown due to concerns that law enforcement may be in control of some backend servers. 

“Please consider this the final update for Breached. I will be taking down the forum, as I believe we can assume that nothing is safe anymore,” Baphomet wrote.

Initially, the administrator said that they would keep the forum alive, as they had access to all infrastructure.

However, this does not appear to be the end for the Breached community. In fact, Baphomet made it clear that the plan is to create a new Telegram group for the interested users and to relaunch the forum in another format.

“The cybercrime underground has continually demonstrated resilience. While an arrest or takedown can result in a short-term disruption, its activity will likely be replaced by some alternative. However, given the takedown of Raid Forums and arrest of their administrator, and seeing history almost repeat itself with pompompurin’s arrest, it is unclear what threat actor would be willing to take on that risk,” Flashpoint notes.

Related: Alleged NetWire RAT Operator Arrested in Croatia as FBI Seizes Website

Related: Two Men Arrested for JFK Airport Taxi Hacking Scheme

Related:US Announces Charges, Arrests Over Multi-Million-Dollar Cybercrime Schemes

https://www.securityweek.com/breachforums-shut-down-over-law-enforcement-takeover-concerns/