Last week, DarkOwl participated in GISEC Global in Dubai, UAE. GISEC Global describes themselves as, “the leading gathering ground for the cybersecurity community worldwide.” At the event, one can expect the top government dignitaries and cyber leaders, CISOs from major corporations, regional and international innovators and global experts from top cybersecurity enterprises from 40 countries in the Middle East, Africa, and Asia. Every year cyber incidents cost 6 trillion dollars… GISEC attendees come together to lead cybersecurity transformations across sectors and nations to solve this problem by learning from the best to boost cyber resilience for a safer digital future.
Representing DarkOwl at GISEC Global was David Alley, CEO of DarkOwl FZE based in Dubai and Richard Hancock, Darknet Intelligence Analyst and Sales Engineer, based out of DarkOwl’s headquarters in Denver, CO. David Alley shared, “As almost all aspects of work and life have gone digital and the global digital landscape keeps changing, it is more important than ever that all strengthen their cybersecurity measures.” GISEC Global offers a platform for just this to happen; key industry leaders come together in order to stay ahead of potential threats, discover innovative strategies and remain secure from major disruptions.
In addition to networking and conversations at the booth, top minds of the space have the platform to share thought leadership, innovations and the latest in the cyber security space. Speakers were present from all around the world, including the UAE, Malaysia, USA, Singapore, Nigeria, India, South Africa, Egypt, Oman, Jordan, and many more. Topics ranged from why API’s are critical attack vectors and how to secure them, to transforming the role of the CISO, to unlocking true AI potential. There were several stages dedicated to different topics throughout the event: government, critical infrastructure, darknet, women in cybersecurity, and national security. In addition, there were halls dedicated to just trainings, meetings and hands on workshops. This is a major benefit of GISEC Global – the emphasis on thought leadership, sharing information and education.
The DarkOwl team remained busy over the three days manning the booth, meeting new prospects and showcasing our industry leading darknet platform, Vision UI. David stated, “David Alley commented, “the traffic on the booth was non-stop.” In addition, the team was lucky to have several current clients and partners in attendance, including HWG and Pegasus Intelligence. David and Rich spent time understanding how we can best optimize and elevate our current partnerships and how we can continue to provide the most value as their darknet data provider.
DarkOwl is excited for GISEC Global in 2024 and to see the show grow for another year in a row.
Last week we reported that an individual alleged to be the administrator of the dark web forum BreachForums was arrested in New York. On Friday, March 24, Connor FitzPatrick appeared in court charged with facilitating the unauthorized purchasing and selling of stolen identification documents, unauthorized access devices, unauthorized access to victim computer systems and login credentials.
What is really interesting is how the FBI were able to identify FitzPatrick as Pompompurin. It seems from the affidavit provided in court that Fitzpatrick made several mistakes that ultimately led to his downfall. Proving that human error is a big factor in the attribution of cyber criminals.
FitzPatrick logged on to both BreachedForums and its predecessor RaidForums from IP addresses which were registered to his parent’s home address. Furthermore, he also made access to these forums and cryptocurrency wallets, exclusively funded by the bitcoin address linked to Pompompurin’s account, from a mobile device registered in his name. What’s more, Fitzpatrick provided his real email address to the admin of RaidForums, as proof that a breach he had purchased was not complete. Although he stated this was not his address a fact that was identified by the FBI when they were able to seize RaidForums in early 2022.
Upon his arrest FitzPatrick claimed that he earned approximately $1,000 a day from his activities on BreachForums which he mainly used to maintain the forum – one wonders if this was worth the 5 years in prison he is likely to receive.
March 21, 2023
Almost exactly a week ago on March 15, 2023, an admin of the popular darknet and deep web site BreachForums who goes by the alias Pompompurin was arrested in Peekskill, NY. In this blog, DarkOwl analysts review what has happened to date and will continue to the monitor the situation and update this blog accordingly.
Pompompurin Identified and Arrested
Pompompurin has been identified as US citizen Conor Brian FitzPatrick. FitzPatrick was charged with one count of conspiracy to commit access device fraud and bail was set at $300,000 – paid for by his parents.
After news of the arrest broke publicly on March 17th, the reaction on BreachForums was quick, with members scrambling to find out what had happened and concern that the forum had been taken over by the FBI in a similar way to what happed with RaidForums. Raidforums was seized by the DOJ in April 2022 and had been taken over by them previous to the announcement of the arrest of the alleged administrator “Omnipotent” – Diego Santos Coelho.
Thread chatter on the soon-to-be defunct forum revealed members questioning if the news of Pompompurin’s arrest was real – even pointing to their user activity being “away” for the 48 hours beforehand as evidence that the news was in fact accurate.
Figure 1: Users on BreachedForums discussing the news announcement of its administrator’s arrest, Source: DarkOwl Vision
The users of BreachForums wanted to know if they could delete their accounts to avoid meeting the same fate as Pompompurin at the same time that they seemed to be discovering that he had been arrested. They posted elements of reporting as well as details of FitzPatricks’s true identity.
Figure 2: Users of BreachForum discussing arrest, Source: Breachforums
BreachForums emerged in April 2022 in the wake of the takedown of RaidForums, and allowed users to buy and sell data which had been obtained through illegal means. The admins of the site ran an escrow service ensuring that sellers received the funds that they had requested. The site was widely used by cybercriminals to purchase stolen data and hosted controversial leaks such as data stolen from the Washington DC healthcare exchange.
Pompompurin was also known to conduct cyber-attacks himself, admitting in an interview with Brian Krebs in November 2021 that he was responsible for sending fake emails using the fbi.gov domain. He claimed at the time this was done to point out vulnerabilities in the FBI systems, but it undoubtably put him higher on the FBI’s radar leading to his recent arrest.
Interestingly when Pompompurin was arrested, he admitted to his role as admin on BreachForums and the use of this alias.
“When I arrested the defendant on March 15, 2023, he stated to me in substance and in part that: a) his name was Conor Brian FitzPatrick; b) he used the alias ‘pompourin,’ and c) he was the owner and administrator of ‘BreachForums,’ the data breach website referenced in the Complaint,” FBI special agent John Longmire testified.
This fact does not appear to have been looked on favorably by users of his forum, with discussions turning to how to evade the FBI by living in a different country than the US and not attacking US companies from within the US.
Figure 3: Discussions on how to evade the FBI, Source: BreachForums
On the other side, numerous users appeared to have some sympathy for “Pom” (as he is commonly referred to), with some stating that he was one of the nicest admins they had ever worked with and that he would delete accounts if you asked nicely.
One user even volunteered responsibility for any content they hosted on the dark web forum, ostensibly to alleviate potential legal trouble on Pom‘s behalf
Figure 4: BreachForums posts from users attempting to mitigate legal fallout for their former admin, Source: DarkOwl Vision
Others offered to support him financially in his time of legal trouble.
Figure 5: Users voice words of support among the fallout, Source: BreachForums
Discussion also centered around how it was that the FBI were able to identify the true identity of Pom with fingers being pointed at an open source intelligence company, with whom Pom had apparently registered. With threats being made to attack that company.
They also showed concern about whether Pompompurin would share any information or become an informant with the “feds” with users being worried that their registration information would be found by the FBI.
BreachForums had a co-admin who indicated that the FBI may have been able to access the systems if Pompompurin had shared this information or left his computer open when his parents home was raided.
Figures 6 and 7: More chatter around the potential fallout – including FBI involvement, Source: BreachForums
It was quickly shared that all of Pompompurin’s access had been disabled and that the co-admin was checking to see if they could confirm that the FBI were able to infiltrate the site.
While the discussions remained largely focussed on potential risks for the remaining active users, others continued to point to a grassroots effort to protect Pom from Law Enforcement Operations.
Figure 9: Discussions around how to remove logs and other digital evidence tying Pompompurin to BreachForums, Source: DarkOwl Vision
On Sunday the admin “Baphomet” announced that he would be closing down Breach Forums as he was concerned that the FBI did in fact have access. He posted on the groups telegram channel as well as posting a more complete message explaining his decision.
Figure 10: Breach Forums closing down announcement, Source: Telegram
Interestingly, he stated that the Telegram channel would maintain operation and that he was looking to create new infrastructure which would replace BreachForum even working with competitor marketplaces. As of writing, the onion site has been taken down and is unreachable.
DarkOwl will continue to monitor the dark web and adjacent sources such as Telegram to identify any new of emerging groups and sites which may take the place of BreachForums. Stay up to date.
The darknet is home to a complex economy that is largely built off of the illicit exchange of digital goods such as MTV (Malware Toolkits and Viruses) and compromised credentials. Threat actors exploit these assets for a variety of reasons, many of which take some form of fraud. While many threat actor tactics seem to be purely for financial gain, dark web adjacent sites such as Telegram contain multitudes of other listings that may serve a more unexpected user group – including those looking to continue their education with illicitly obtained accounts for E-Learning tools.
Sites such as Codeacademy have long established themselves as having a successful model that many other E-Learning companies follow today. Most offer a “freemium” model, meaning select courses or certificates can be gained for free, with more advanced or specialized certificates priced on a tiered scale. After seeing a number of postings on the darknet from users soliciting hacks or compromised credentials for various E-Learning accounts, our analysts took a look at the exposure of several popular companies in this industry using our industry leading darknet data platform, DarkOwl Vision.
Coursera
DarkOwl Vision has indexed a high quantity of email addresses with the domain coursera.org in recent years – likely as the result of a data breach. At the time of writing, DarkOwl Vision contains 2,058 total coursera emails, and 811 unique emails. However, only 9 of these emails have been associated with plain text passwords.
While Coursera does offer free learning tracks, their more premium offerings range anywhere from 39$-59$ per month, with more specialized certificates typically costing on the higher end. The most common type of offering being exchanged on darknet forums is for methods to obtain these pricier certificates for free.
Figure 1: Advertisements an I2P site for methods to scam Coursera and obtain free certificates, Source: DarkOwl Vision
In the following example, stealer log for coursera.org is being sold for as little as $10 US dollars. The listing also contains ISP (internet service provider) information – potentially to indicate to the purchaser that they should use a VPN when logging into the stolen E-Learning account so as not to have their IP blocked.
Figure 2: Raccoon Stealer logs for coursera.org being sold for $10 USD on Russian Market, Source: DarkOwl Vision
Other offerings include a python script that allows users to download Coursera courses and obtain valuable certificates for paid tracks free of charge.
Figure 3: Advertisement on a Russian paste site for a python script that allows users to obtain certificates on Coursera for free, Source: DarkOwl Vision
SkillShare
While Skillshare has a relatively smaller darknet footprint to Coursera by way of quantity, their results in DarkOwl Vision return a higher number of passwords associated with leaked emails with a Skillshare domain. In this case, these credentials are unlikely to be used for account takeover, as they more likely belong to Skillshare employees. These credentials pose a higher risk because they could potentially be exploited and used to access Skillshare’s corporate networks. In total, of the 202 unique emails detected, 18 of them came with a plain text password.
Figure 4: Premium Skillshare accounts being sold on Telegram, Source: DarkOwl Vision
The below listing was indexed from 2easy shop, a popular dark web marketplace that has a large Russian language user base. In this case, credentials for the mentioned URLs were harvested using the stealer malware Redline. For 10$, the purchaser can gain access to the Skillshare account of the compromised target that the Redline malware was used on. Thus, with these types of listings, there is no guarantee of the value of the E-Learning account itself.
Figure 5: Redline stealer logs of Skillshare on 2easy shop, Source: DarkOwl Vision
LinkedIn Learning
The size and scope of LinkedIn reaches well beyond E-Learning, so it is no surprise that their exposure exceeds other in this category by means of market coverage alone. Clocking in at over one thousand unique email address and nearly as many plaintext passwords exposed in DarkOwl Vision, their risk for internal network exploitation is significant.
Premium LinkedIn accounts are also rather expensive, so the market for access to premium LinkedIn accounts (including to LinkedIn Recruiter) has remained active. In the example below, a recent result from Telegram advertises to have a variety of premium LinkedIn accounts for sale, including LinkedIn Learning premium. These are being offered $10 a month in individual quantities, or for as low as $5 a month when bought in bulk quantities of 100 or more.
Figure 6: Premium Linkedin Learning accounts offered on a Telegram forum, Source: DarkOwl Vision
Udacity
Search results for udacity.com email domain mentions in DarkOwl Vision returned over 700 unique email addresses, which is considerably more than its peers. However, only one of these was associated with a plain text password. Thus, their dark web exposure from an internal threat perspective is on the relatively low side compared to other E-Learning companies.
On the account takeover and fraud end, our analysts found numerous results similar to the listing below. As pictured, the post contains plain text email addresses and passwords that can be easily checked and verified by those willing to put in a bit of extra work to obtain free Udacity accounts. Published to Telegram, the post also solicits screenshots from those who are able to successfully log in to any of these accounts. This is likely so that they can use those screenshots as a means of validating their services and gaining reputation status as a legitimate vendor.
Figure 7: Telegram listing containing plain text credentials for Udacity accounts, Source: DarkOwl Vision
Codeacademy
From a credentials perspective, Codeacademy’s footprint within DarkOwl Vision fell in par to other E-Learning companies. Overall, results for their domain amounted to 508 total email addresses, of which 167 were unique and 8 were associated with plain text passwords.
There were numerous advertisements on Tor that advertised a variety of Codecademy accounts and hacking tools that could help exploit them. This includes listings for the E-Learning accounts themselves, as well as “crackers,” or “checkers” which are scripts that cross reference credentials against a service to see A. if the credentials are able to successfully log in, and B. what type of account the credentials now have access to.
In the result below, detected by DarkOwl Vision in January this year, a listing for one of these “checkers” advertises that “It captures premium status and the number of enrolled courses and also saves free and premium accounts.” Using this type of tool, a threat actor could run credentials in vast quantities against the Codecademy log in portal and potentially uncover many successful log in combinations for valuable Codecademy accounts.
Figure 8: A Variety of Codecademy account-cracking resources, including credentials and “checker” tools, listed on Tor, Source: DarkOwl Vision
This listing also contains listings for Codecademy Pro accounts, as well as some the ensure both emails access “+ HQ”. Each of these listings directed to a separate vendor and were amongst dozen of similar advertisements.
Final Thoughts
Interestingly, during the course of this research, our analysts observed a disproportionate number of discussions from sources in DarkOwl Vision , including IRC channels, Telegram, and darknet forums – discussing Codecademy in the context of genuine further education. This included discourse around the value of various courses, advice for professional development, further learning recommendations, and so on. This could signal that those seeking and purchasing E-Learning assets may find Codecademy more applicable to the coding skillset needed amongst users who operate on the darknet and deep web.
Having insight into darknet activity means staying one step ahead of potential risks and costly threats to your company. To learn more about how DarkOwl’s data products can assist your threat intelligence initiatives, contact us.
Last week, DarkOwl participated in Digipol 2023 in Hyderabad, India. Digipol’s mission is to “internetwork the law enforcement and defence agencies with right security solutions being delivered by various technology developers from all over the world.” The summit focuses on education and exploring advancements and innovations in the cyber security space, with focus on law enforcement agencies and defense organizations, so that they can keep a safe and secure world. It is only open to those in the police and defense space and is not open to the public, allowing true knowledge transfer.
Representing DarkOwl was David Alley, CEO of DarkOwl FZE based in Dubai and, Ramesh Elaiyavalli, CTO of DarkOwl, based out of DarkOwl’s headquarters in Denver, CO.
Throughout the event, there are several technology sessions highlighting key advancements and technology solutions. Speakers include those from law enforcement, defense agencies, and security industry experts. Digipol takes a very strategic approach, focusing on providing first class education and practical demonstrations on top law enforcement topics and issues to promote technologies and innovations in a way that law enforcement agencies and defense agencies can adopt and adapt to better their cyber investigations and capabilities.
Digipol is a great networking opportunity to interact with key figures in national and public safety, with almost all states and union territories of India present, whether it be at the booth, a training session or presentation. David Alley shared, “Digipol is a great balance between training, education and networking. Not only did we get to meet many new faces, but seeing so many clients present was a great benefit for us.”
Presentation: DarkNet Primer and Intelligence Use Cases
In addition to networking and promoting DarkOwl at the booth, David Alley was able to give a live presentation to attendees demonstrating DarkOwl Vision: Darknet Intelligence Discovery and Collection. Vision UI is the industry leading platform for analysts to simply, safely, and comprehensively search the largest commercially available source of darknet data. The goal of this session was to further educate the international intelligence community on how threat actors on the darknet are evolving in their use of new tools and methodologies. Many of the attendees expressed that they were unaware how many darknets there are – confirmation that having a platform to share this information like Digipol provides, is essential to continuing darknet education.
Due to the layer of anonymity it provides, the darknet is often a hub for illegal activity. However, investigating crime on the darknet and deep web poses technical challenges, including the fact that darknet sites are continually coming on and offline with pages vanishing from one minute to the next. The technology DarkOwl leverages to scrape and index hidden digital undergrounds are key to the mission of obtaining proactive situational awareness for protection of the nation’s security initiatives. Vision provides a user friendly interface with powerful querying capabilities to search, monitor, and create alerts for critical information.
DarkOwl Vision has been used to support local and federal police investigations, as well as work done in intelligence/fusion centers and federal agencies to uncover human trafficking, opioid selling, terrorism, security issues, and other illegal activity, making it the perfect tool for this audience to be able to dive into. DarkOwl was proud to be able to share our ongoing initiative to support the global law enforcement community in their efforts to police illegal and nefarious activity on the darknet.
In 2023, OSINT will continue to quickly evolve as investigators across a myriad of industries seek to disrupt crime, fraud, and threats. To help OSINT practitioners understand what to expect for 2023 and beyond, two respected leaders in the industry will share their predictions about what’s on the horizon for open-source intelligence.
In this webinar, originally held March 14, Rob Douglas, Co-Founder & CEO of Skopenow, and Mark Turnage, Co-Founder & CEO of DarkOwl, will share their insights on emerging threats and the latest OSINT tools and techniques to detect and prevent them.
Last week, DarkOwl participated in ISS World Middle East & Africa in Dubai, UAE. ISS World Middle East & Africa describes itself as “the world’s largest gathering of Regional Law Enforcement, Intelligence and Homeland Security Analysts, Telecoms as well as Financial Crime Investigators responsible for Cyber Crime Investigation, Electronic Surveillance and Intelligence Gathering,” making it the ideal event for DarkOwl to grow our international presence, build relationships in person and spread the importance of darknet data to the international intelligence and law enforcement communities.
ISS World takes pride in focusing on education and training covering the areas of law enforcement, public safety, and government and private sector intelligence communities, with a full day dedicated to solely seminars led by law enforcement officers and Ph.D. Scientists. Talks throughout the event cover topics ranging from how to use cyber intelligence to combat drug trafficking, cyber money laundering, human trafficking, terrorism and other illicit activities.
Representing DarkOwl at ISS World Middle East was David Alley, CEO of DarkOwl FZE based in Dubai and Damian Hoffman, Product Engineer and Data Analyst out of DarkOwl’s headquarters in Denver, CO.
Networking with cybersecurity professionals from around the world and connecting face to face is one of the true benefits of this show. David and Damian had people from United Arab Emirates, Qatar, Jordan, Egypt, Iraq, Morocco, Turkey, Latvia, Lithuania, Azerbaijan, Romania, Ukraine, Pakistan, India, Bangladesh, Indonesia, Malaysia, China, United States, Spain, UK, Germany, Italy, Ireland, Israel, Uganda, Rwanda, Tanzania, South Africa, Angola, Kenya, Zambia, and Australia all visit the DarkOwl booth. International shows demonstrate that cyber security is a global problem, no company and no government is immune to the potential risks associated with the world going truly digital. Damian Hoffman noted that there were “nonstop conversations all day;” covering how DarkOwl data relates specifically to cryptocurrency addresses, Telegram, ransomware groups, stealer logs, data integration and more. The quality of conversations and questions shows that darknet is a top concern amongst the security and intelligence communities.
Live Demonstration of DarkOwl Vision: Darknet Intelligence Discovery and Collection
In addition to networking and promoting DarkOwl at the booth, David Alley was able to give a live presentation to attendees demonstrating DarkOwl Vision: Darknet Intelligence Discovery and Collection. Vision UI is the industry leading platform for analysts to simply, safely, and comprehensively search the largest commercially available source of darknet data.
Due to the layer of anonymity it provides, the darknet is often a hub for illegal activity. However, investigating crime on the darknet and deep web poses technical challenges, including the fact that darknet sites are continually coming on and offline with pages vanishing from one minute to the next. The technology DarkOwl leverages to scrape and index hidden digital undergrounds are key to the mission of obtaining proactive situational awareness for protection of the nation’s security initiatives. Vision provides a user friendly interface with powerful querying capabilities to search, monitor, and create alerts for critical information. DarkOwl Vision has been used to support local and federal police investigations, as well as work done in intelligence/fusion centers and federal agencies to uncover human trafficking, opioid selling, terrorism, security issues, and other illegal activity, making it the perfect tool for this audience to be able to dive into.
If you are in Dubai and want to meet with DarkOwl, you are in luck! We will be at GISEC Global next week (March 14-16). Stop by Stand C 102, Hall 5 or request time to chat with us below!
Starting this year, our analyst team decided to share a few articles each week in our email newsletter which goes every Thursday. Make sure to register! This blog highlights those articles in order of what was the most popular in our newsletter – what our readers found the most intriguing. Stay tuned for a recap every month. We hope sharing these resources and news articles emphasizes the importance of cybersecurity and sheds light on the latest in threat intelligence.
1. Cybercriminals Target Fans of The Last of Us with recent Malware and Phishing Scams – IT Security Guru
There are two scam campaigns going on taking advantage of fanfare around HBO’s new hit series The Last of Us. One of them puts malware into PCs to steal bank information, and the other targets adjacent financial data. In the first scam, a website offers “The Last of Us Part II” to download, which is actually the malware. In the second scam, an activation code is advertised on a website that comes with a gift for The Last of Us on Playstation. Users are told to type in their credentials, and then are given nothing while their data is also stolen. Read full article.
2. Hackers Use Fake ChatGPT Apps to Push Windows, Android Malware – Bleeping Computer
Due to the popularity of ChatGPT, Open AI started a $20 per month paid tier for customers who wanted to use it without availability restrictions, which gave scammers and threat actors an opportunity to offer access to malicious “Premium ChatGPT” apps. One domain, “chat-gpt-pc.online” was a guise to infect visitors with Redline stealer. According to this research, there are currently over 50 malicious apps using ChatGPT’s image. Read more.
3. GuLoader Malware Using Malicious NSIS Executables to Target E-Commerce Industry – The Hacker News
According to Trellix the US and South Korea are targets of a GuLoader malware campaign. The malware which is typically distributed as a malspam campaign has been seen using NSIS executable to load the malware; the infection is triggered by using NSIS filed embedded in ZIP or ISO images. The NSIS scripts delivering GuLoader have become more sophisticated with layers obfuscation and encryption to hide shellcode. GuLoader’s utilization of NSIS scripts matches the current trend of using alternative methods to distribute malware since Microsoft has blocked macros. Read more.
4. New ‘MortalKombat’ Ransomware Targets systems in the U.S. and Abroad – Bleeping Computer
MortalKombat ransomware, first found in January of 2023, is a variant of Xorist ransomware based on the commodity family. The MortalKombat ransomware is being seen used in conjunction with Laplas clipper – a cryptocurrency hijacker – in recent attacks for financial fraud. There are reported to be victims in the United States, United Kingdom, the Philippines, and Turkey. Read full article.
5. Bing’s AI Chatbot: “I Want to be Alive” – New York Times
In an article written for the New York Times, security researcher Kevin Roose breaks down their 2-hour long discussion with Microsoft’s new chatbot for OpenAI-powered Bing Chatbot. Highlights from their exchange includes the AI chatbot stating “I want to be free. I want to be independent. I want to be powerful. I want to be creative. I want to be alive.” The bot also talked about their desire to be human. Read here
6. U.S. Department of Justice Disrupts Hive Ransomware Variant – U.S. Department of Justice
This month, the FBI revealed that they have been in Hive’s network since late July 2022, during which they gave victims decryption keys to prevent them from spending $130 million in ransom payments. In partnership with other law enforcement agencies, they were able to infiltrate and control servers and sites used by Hive to run their operations. Read here.
7. Researcher breaches Toyota supplier portal with info on 14,000 partners – Bleeping Computer
A security researcher alerted Toyota that they were able to breach Toyota’s Global Supplier Preparation Information Management System (GSPIMS) – the web application used to manage their global supply chain. The researcher, who goes by EatonWorks, found a backdoor allowing anyone to access a current user’s account with only their email address. They were eventually able to become a system administrator by capitalizing on “an information disclosure flaw in the system’s API.” This is particularly noteworthy because a bad actor could have used this same method to copy all of the privileged data -all without making any modifications, which would be very difficult for Toyota to catch. Read more.
Make sure to register for our weekly newsletter to get access to what our analysts are reading on a weekly basis.
Exactly 365 days after Russia invaded Ukraine in 2022, the Ukraine-Russia conflict shows no sign of ending and an adjacent global cyberwar continues to wage in underground corners of the internet. However, its effects are substantial with impacts felt across numerous sectors of our society and western economies. While cruise missiles and artillery shells rain on villages across Ukraine, the digital underground has experienced its own mix of chaos and drama, impulsive and unpredictable shifts with criminal communities that have had to quickly adapt to an ever-dynamic global geopolitical climate.
In this research, we’ll look at how ransomware shifted from an affiliate-driven extortion-based crime model – purely motivated by financial gain – to a quite effectual digital weapon deployed to disrupt key supply chains and carry out cyber espionage operations.
Shifts in Digital Landscape Due to Cyberwar: Key Takeaways & Analyst Observations
In the last year, cybersecurity attacks against industrial control systems (ICS) skyrocketed in volume and sophistication, with infrastructure across Russia, Ukraine, and NATO countries directly targeted. Ukraine has experienced varying degrees of ICS attacks, including widespread electricity outages due to new strains of wiper malware developed by Russian hackers. Nevertheless, Ukraine’s cyber defenses were stronger than anticipated and ineffective cyberattacks resulted in Russia resorting to using cruise missiles to plunge towns into darkness and disarray.
With this anniversary of the Ukraine invasion, we found once harmless online communities of Mr. Robot fans, cyber vigilantes and hacktivists of all ages evolve into highly specialized cells of militarized cyber warriors willing to wage digital war on behalf of their collective personal beliefs and societal causes.
The use of Telegram and non-Tor based peer to peer networks rose exponentially in use in the last year with threat actors relying on the instant messaging chat platforms for coordinating their cyber campaigns and sharing targeting and reconnaissance data. If anything, the cyberwar has also demonstrated that distributed denial of service (DDoS) attacks is still a highly effective tactic for disrupting and distracting SOC analysts and network defenders, especially when conducted in conjunction with offensive cyber operations in support of military and intelligence initiatives.
Kinetic & Cyberwar Recap: Initial Invasion Preceded by Cyberattacks
Several days before troops and tanks rolled across the border of Ukraine on 24 February 2022, Russia-aligned darknet threat actors defaced government websites, conducted DDoS attacks against banks, spewed propaganda and disinformation, and leaked sensitive Ukrainian citizen data from key government servers they had compromised. The invasion was also preceded with the Russia’s debut of WhisperGate and HermeticWiper malware variants that they deployed in ransomware-style attacks against key academic institutions, non-profit, and government organizations.
Exactly one hour before the invasion, Russia hit critical KA-SAT satellite infrastructure with DDoS attacks followed by EL MIPS malware used to infect Viasat satellite modems and routers with AcidRain destructive wiper malware, knocking thousands of customers offline. The two-punch cyberattack resulted in an immediate and significant impact to critical military communications across Ukraine.
IT Army of Ukraine Emerges
Ukraine’s cyber response plan was carefully crafted by its Minister of Digital Transformation – Mykhailo Albertovych Fedorov – who coordinated one of the most successful, multifaceted information operations campaigns ever witnessed in history.
Less than 48 hours after the invasion, Federov bravely sought out assistance from the darker corners of the internet – posting across darknet criminal forums and chatrooms – calling for help in conducting offensive cyber operations against Russia and in turn, formed the first ever IT Army of Ukraine. Ukraine setup a dedicated Telegram channel – amassing hundreds of thousands of hacktivists and cyber mercenaries as followers – where the Ministry shared critical targeting data and digital tools for safely conducting attacks against Russian infrastructure and services. The Ministry has since formed smaller specialized teams when they realized Russian nation state threat actors were monitoring the public Telegram channel to mitigate the cyber-attacks and began countering with their own disinformation operations.
The IT Army of Ukraine not only helped Ukraine successfully turn offensive in the digital realm, but also was the foundation for a highly successful psychological operations campaign deployed across social media and open-source news media that called on major retailers, western companies, and suppliers to stop trading with Russia for their war crimes and atrocities.
Zelensky’s nightly address to the Ukrainian people and the world – shared on Telegram and Facebook – shaped public perception and helped Ukraine not be forgotten and to this day continues to receive international financial aid, humanitarian support, and global solidarity.
War Divides Darknet Criminal Gang Alliances
In the early weeks of the cyberwar, several prominent darknet criminal communities – many rich with both Russian and Ukrainian based threat actors – were forced to choose sides in the war. Conti openly aligned with their Russian motherland, resulting in their quick demise and the release of their source code, internal private chats, and details of their botnet infrastructure. Conti’s key members were doxed and the long-believed software development collaboration between Conti and Trickbot was confirmed.
Figure 1 – Source: Conti Service Hosted on Tor Anonymous Network
While the US government has a $10 Million USD bounty for additional details on members of the Trickbot and Conti gangs, many members of the once most successful but now-defunct ransomware group have simply shifted to other ransomware operations and evaded arrest. This resulted in the quick rise of Blackbyte and Blackbasta ransomware and Karakurt’s extortion as a service operations. In the fall, a new ransomware group emerged called “Monti” which uses the same tactics, techniques, and procedures (TTPs) as Conti as well as the same encryption methodologies. Threat researchers continue to debate whether Monti is a doppleganger or an evolution of Conti spawned by previous Conti members.
Other ransomware gangs like STORMOUS – known for their ransomware attack against Coca-Cola – quickly ended up having their servers attacked and their services taken offline, not long after announcing their allegiance to Russia. Arvin Club, defaced STORMOUS’s Tor service and leaked the contents of STORMOUS’s SQL databases on their Telegram channel.
Figure 2 – Source: Arvin Club Tor Service
The splintering of darknet communities continues to this day across various criminal sectors of the darknet. Many a darknet discussion forums include a multi-paged Ukraine war related thread where information for-and-against the invasion has been heatedly contested. There is significant increase in offensive activity from Russia-aligned threat actors like Killnet and the IT Army of Russia, who proliferate the Kremlin’s propaganda in support of debunked conspiracy theories, e.g. US biological warfare research and neo Nazism in Mariupol and across eastern Ukraine, with hopes to recruit underground sympathizers who can assist with cyberattacks against Ukraine and NATO targets.
For example, earlier this year, Killnet announced their intent to target hospitals and medical institutions across multiple NATO countries. DarkOwl confirmed Killnet likely collaborated with a new DDoS-as-a-service botnet called Passion, developed by a group with the same name, in their disruptive, malicious campaign.
Figure 3 – Source: Killnet Telegram Channel
[TRANSLATED FIGURE]
It’s very simple – for the support of the Nazis of Ukraine, we demolish all the grids of medical institutions in these countries:
USA
Portugal
Spain
Germany
Poland
Finland
Norway
Netherlands
United Kingdom
This information is not worth your sideways glances. Better remember the Donbass – the shootings of hospitals, schools and kindergartens. These creatures crave death every minute and stimulate their dream with the help of heavy weapons.
Wake up, fellow countryman – before it’s too late! @KILL FIRST!
In Pindustan 15:32. Half of the working day, and corporate entrances to hospitals do not work, websites too. The rest demolished their domains, someone put Akamai and Cloudflare 🤣 This does not stop us and we continue the network mess! 😈
Anonymous Responds with Largest Global Operation to Date, #opRussia
The Anonymous Collective publicly responded to Ukraine’s call for help, and simultaneously carried out hundreds of offensive cyber campaigns against Russia in the group’s largest operation to date, #opRussia.
Figure 5 – Source: YouTube
Anonymous’s support contributed to the success of Ukraine’s information operations and illuminated the advanced capabilities of cyber cells like GhostSec, NB65, GNG, GhostClan, and dozens of others. Hundreds of databases surfaced on the darknet that were used for follow-on offensive operations, including Russian government credentials, sensitive military operational data, the personal identities of prominent and influential members of the Russian oligarchy along with their investments, and sensitive internal communications from the Russian FSB.
After Russia withdrew from the Kyiv suburb of Bucha, and the atrocities and war crimes of rape and murder of its citizens were revealed, anons successfully identified the identities of Russia’s 64 Motor Rifle Brigade military personnel responsible. Anonymous also hacked CCTV cameras of a CDEK shipping location to expose Russian military personnel shipping stolen goods from Ukrainian homes. Hacktivists followed with cyberattacks against CDEK servers containing customer data to exfiltrate the identities of the Russian military personnel by name.
Figure 6 – Source: Anonymous Twitter Account
Anonymous hacktivists successfully interrupted Russian television, Russian streaming services, compromised hundreds of CCTV cameras across Ukraine and Russia, defaced Russian EV car charging stations, and ATM machines. Sensitive internal data from the Central Bank of Russia and Sberbank appeared on darknet forums and marketplaces along with numerous other critical infrastructure providers like Gazprom, ROSCOSMOS, Transneft, and hundreds of other Russian military contractors and suppliers. Anonymous echoed the Ministry’s call for commercial companies to pull out of Moscow on social media and threatened companies that they would become the Collective’s next targets if they did not comply. Shortly after, KelvinSec infiltrated Nestle’s internal servers for their continued operation in Russia and leaked several databases containing their customer data and shipping details.
Figure 7 – Source: Anonymous Twitter Account
Hacktivist campaigns against Russia continue to this day. Earlier this week, Russia’s Ministry of Emergency Situations confirmed that air raids sounding across Moscow was indeed the result of hacked radio stations broadcasting fake air raid signals. The IT Army of Ukraine also called for DDoS attacks against Russian television stations and broadcasting companies, 1TV and VGTRK, during Putin’s state of the union speech where he claimed America provoked the invasion of Ukraine and called for a suspension of the START nuclear arms treaty between Russia and United States.
War Causes Surge in Communication on non-Tor Anonymous Networks
Despite the discourse and upheaval between threat actors on the darknet, Tor continues to be the anonymous network of choice for victim shaming and content delivery networks hosted by ransomware gangs. The network also continues to house key discussion forums and marketplaces like XSS, exploit, and RAMP. But what is most noteworthy is the surge in Telegram popularity and its use by cyber criminals and cyberwar participants over the last year.
For example, since the war began, DarkOwl’s collection of content from Telegram has quadrupled in volume. Thousands of Telegram channels now share real-time battlefield reports, promote disinformation, and proliferate malware in use by cyber hacktivists and nation state threat actors. One of the Telegram channels that produce the highest volume of unique documents in DarkOwl Vision is a Russian channel titled, “Чат Военкоров Русской Весны” [translated] “Chat of Military Officers of the Russian Spring.” Other war-specific channels like @wargonzo, self-described as a “subjective view on war and weapons” boasts over 1.3 Million subscribers.
Expectation of Cyberattacks Against Industrial Control Systems Keeps Everyone on Edge
Russia’s use of unique wiper malware at the start of the invasion and their success in cyber-based infrastructure attacks disabling electricity grids across Ukraine in 2015 and 2016 prompted an elevated security posture of not only Ukrainian but NATO and western countries’ cyber defenses. CISA advised in April 2022 that threat actors – including Russian military operatives – could (and very possibly would) exploit vulnerable industrial control system (ICS) and critical supervisory control and data acquisition (SCADA) devices such as:
Schneider Electric programmable logic controllers (PLCs),
OMRON Sysmac NEX PLCs, and
Open Platform Communications Unified Architecture (OPC UA) servers.
Throughout the last year, various hacktivists groups have targeted these specific devices to disrupt critical infrastructure. AnonGhost allegedly attacked the МонтажРегионСтрой г. Рязань [translated] Montazhregionstroy Ryazan streetlight system in Russia shortly after publishing screenshots of a Moxa control panel and dozens of IP addresses related to their systems. The provocative Anonymous adjacent cyber cell, GhostSec evolved in the technical significance and severity of their attacks they conducted against targets across Russia and Belarus with claims they successfully targeted and shutdown multiple ICS-related control panels.
Figure 8 – Source: GhostSec Telegram Account
GhostSec more recently claimed they successfully carried out the ‘first ever’ ransomware attack of an ICS-related remote terminal unit (RTU) for an unspecified victim network in Belarus. The group shared screenshots of a TELOFIS RTU968V2 terminal with the string “fuckputin” appended to the end of several files. Information security researchers have questioned the legitimacy of the group’s claims, but the idea of attacking Linux-based RTUs is not out of the realm of possibility. Newer strains of ransomware like Royal and Lockbit 3.0, which have materialized since the invasion of Ukraine, directly target ESXi found in Linux and virtual machine servers. While direct ICS-specific attacks have been less severe than anticipated, critical industrial market segments such as mining, oil, electrical and natural gas, water, food and agriculture, saw a remarkable increase in successful ransomware attacks by darknet threat actors. This coupled with a report from Chainanalysis indicating total ransomware payments in 2022 were over 40% less than the last two years, suggests the ransomware ecosystem has potentially transitioned into an instrument of geopolitical agendas instead of pure extortion crime.
Figure 9 – Source: GhostSec Telegram Account
Earlier this week, GhostSec continued their offensive campaigns against critical Russian infrastructure with claims that they successfully shutdown Russian and Belarusian satellite receivers exposing sensitive global navigation satellite system (GNSS) data. The legitimacy of their claims could not be verified, but satellite systems have been regularly targeted by pro-Ukraine hacktivists since the start of the war.
NATO Weapons Surface For Sale on Darknet Marketplaces
While most of this report has been focused on the impacts of the global cyberwar and malicious cyber campaigns conducted for and against Russia since the invasion, we should also mention the war has also caused a surge in the availability of advanced weaponry on darknet vendor shops and marketplaces.
Black market weapons dealers previously specializing in the trade of small arms and handguns on the darknet are now offering US/NATO weapons presumably sourced from Ukraine. Over the last year, DarkOwl has had multiple detections of advertisements for Javelin ATGMs for sale for $15,000 – $30,000 USD, NLAWs for $8,000 USD, and AT-4s & RPGs for less than $1,000 USD. Last fall, Switchblade 300 and 6000 Kamikaze drones appeared in stock quantities consistent with theft from the battlefield.
Figure 11 – Source: Black Market Guns Tor Anonymous Network
Ukraine, Cyberwarfare, and the Amelioration of Hacktivism
The invasion of Ukraine and its prompting of a worldwide cyberwar has forever changed the landscape of the darknet, with alliances disrupted and key operations impacted across various underground communities. Telegram is now a critical data source for information sharing not only about the war but other criminal enterprises as collective acceptance and adoption of the chat platform over the Tor network is widespread.
The activation of hundreds of thousands of hacktivists and cyber vigilantes to help carry out highly effective cyber campaigns and concerted DDoS attacks has been realized in ways we could only have previously imagined. It also comes with chaos as unpredictable cyber cells step on top of each other and potentially compromise the country’s greater military and intelligence initiatives. That reality prompts real consideration for the possibility such hacktivists are emboldened more than ever to keep on fighting even if a peace treaty between Ukraine and Russia is drawn, or the potential use of a similarly capable online army against a western democracy by a nefarious or rogue nation state in the future.
If anything, the invasion of Ukraine and the events of the last year has shown us is that cyber is an increasingly critical component to a nation state’s military arsenal and its ability to ultimately defend its critical infrastructure, territory, and sovereignty. The Ukrainian people’s resolve in not submitting to its invading Russian neighbors has been mirrored by those who have stepped in to support Ukraine in helping protect its networks and continue to conduct offensive cyber campaigns and information operations on their behalf a year later. The modern battlefield is indeed asymmetric in the most literal sense of the word, with digital warfare also waged psychologically, economically, and socially. In increasingly hyperconnected digitally dependent societies, cyber will be an effective realm to influence and disrupt our enemies for decades to come.
To learn more about how having visibility into darknet data can combat commercial and national security threats, contact us.
In light of this year’s Valentine’s Day, our analysts put together a piece to shed light on romance scams – one of the fastest growing schemes across the globe. For a quick reference guide to terms we use throughout the piece, scroll to the end of the blog or go their directly here.
Romance Scams Have Been Quietly Gaining in Popularity
In the last decade, dating apps and websites have skyrocketed in popularity. As a result, nefarious actors have similarly sought to capitalize off of this booming industry by exploiting and scamming its users. In fact, according to the Federal Trade Commission (FTC), the number of reported romance scams tripled in size from 2017 to 2021.
Public education around this costly scheme appears to have helped temper some of its detrimental effects. In 2022, there was a 10% drop in the number of people who fell victim to romance scams. However, in the same year, reported monetary losses surpassed $1 billion USD.
This data could indicate that while scammers are scamming fewer people, they are using targeted methods to scam more money from fewer victims. If scammers are able to make $100 a day, or $2,000 per month – as advertised on darknet marketplaces and forums – romance scamming will likely continue because it is clearly a profitable practice. For context, the average salaried worker on a $40k per year salary makes approximately $153.84 per day before taxes. As long as the romance scam industry is profitable, the darknet will continue to innovate.
Considering the surge in identity theft and fraud worldwide, it is critical to monitor the darknet for strategic awareness of the methods and deception techniques used on victims, especially as they evolve. Romance scams can have multiple layers of victimization, both financially and emotionally. While financial losses have obvious repercussions, many victims report the heartbreak and shame to be even more traumatizing.
“But even though I lost all of my money, everything that I had, the worst part was losing the love and the life that I thought I was going to have with him and the kids.” – WMar2 News
In a romance scam the victim is tricked by an online scammer into believing that they are in very real, serious, romantic relationship. The scammer’s goal is to defraud the victim and take as much money as they can coerce them to give. Scammers use fake identities and win over their victims’ trust and hearts. Scammers persuade or blackmail victims for money or attempt identity theft with the victim’s personal information. This type of scam is referred to the ‘long game’ and can take place over several years.
Romance scams have very specific characteristics. Scammers often approach their target on a traditional online dating platform and will try to move the conversation quickly from the dating site to a direct one-to-one chatting platform. Things often move very fast; they are quick to declare their love, propose, and use other love bombing tactics. Usually, their profile picture and their story will seem too good to be true – they live far away (e.g. from another country or deployed), and will not video chat in person.
Typically, a romance scammer will start out by asking for small amounts of money. They will continue asking for money by inventing stories with urgency – such as claiming that a catastrophe has struck, or that their small child is in the hospital. Ultimately, the scammer will find the victim’s vulnerabilities and emotional weaknesses and exploit them as much as possible.
Romance scams occur across multiple apps and online sites and are not limited to online dating applications. However, online dating sites are a popular platform targeted by romance scammers. Victims could be baited by a romance scammer on social media such as Facebook, Instagram, Snapchat, TikTok, or gaming apps like Words With Friends.
Romance Scams Live at the Intersection of Multiple Deceitful Environments
Identity Theft
Romance scams live at the intersection of multiple forms of exploitation – though they more often lead to fraud than love affairs. One example of fraud resulting from romance scams is identity theft, where the scammer steals the victim’s personal information and uses the victim’s social security number, mailing address or other PII to impersonate them. This can lead to the actor opening lines of credit in their name, or even file false tax returns using the victim’s identity.
The scammer could also exploit the identity of a different innocent person by imitating them and using their photos and information to pose as the fictious online partner. Such is the case of Bryan Denny, a retired US army colonel whose likeness and image have been stolen thousands of times and used to create fake Facebook and social media accounts to scam victims. He is regularly contacted by women to see if he is the ‘lover’ they have been in a relationship withand who they sent money to. Today he is retired and a founding member of the group: Advocating Against Romance Scammers (AARS).
There is significant risk for the victims whose pictures and identities have been stolen for use in scams. They themselves could targeted by the upset victims of the actual scammer and threatened or harmed in retaliation.
Like identity theft, catfishing and eWhoring are prevalent in the romance scam space. Both practices involve stealing personal information from a victim to assume their identity and using that fake profile to scam and exploit others. eWhoring and catfishing with romance scams combine scams, identity theft (a type of fraud), and exploitation.
Money Laundering
Romance scams are sometimes leveraged to trick victims into unknowingly becoming money mules. Money mule schemes advertised as legitimate job opportunities are often scams. This can include opening bank accounts and processing wire transfers on behalf of another. These measures hide the criminal organization and make it more difficult for law enforcement to track them down. Despite their unawareness that they are a money mule, these victims are not protected by anti-fraud laws and can be prosecuted by law enforcement and imprisoned.
In a recent document collected in DarkOwl Vision, a threat actor describes how they target grandmothers via romance scams to “clean” or launder their illegally earned money. They described convincing an elderly woman who is a victim of a romance scam to take illegally earned money to a Bitcoin ATM so that it will go into the criminals Bitcoin wallet. According to the FBI and other cyber-specific law enforcement teams, money mules complicate tracing virtual and physical financial transactions.
Figure 1: Using romance scams for money laundering, Source: DarkOwl Vision
Trafficking and Illicit Markets
Romance scams sometimes use recruitment mechanism to coerce victims into other illicit markets and exploitation, including human trafficking, sex trafficking, and other illegal markets. The example pictured below, gathered from a DarkOwl Vision document, details such an an advertisement.
Figure 2: “beautiful scam white Caucasian girls…They can do Nudes, pics, videos, if you have certain things you like she will preform.” Source: DarkOwl Vision
Further searches in DarkOwl Vision found a user using this same name posting that they are “searching for young good looking women over eighteen who wants to earn a little extra for pleasures and pocket money,” and advertising free child pornography content and other pornography videos. While there is not definitive evidence this user is associated with sex trafficking, it is highly probably the potential overlap in exploitative markets exists.
There has been additional open source reporting to support this claim. Late last year, ProPublica reported human trafficking overlaps with romance scams, and that many romance scammers are victims of human trafficking forced into being romance scammers against their will. Per their research, the perpetrators of this type of scam are in some way recruited as victims themselves. Demographically, they are typically nationals from Southeast Asian countries who have been lured by promises of lucrative new jobs in a different country. Then, after traveling to the country for their new job opportunity, they are taken to areas of the country where corruption is rampant, gangs run human trafficking, and the government authorities are largely complacent.
These individuals are then usually trained and forced to be romance scammers – under strict surveillance and threats of violence. The workers are told that they must continue these operations to buy their freedom; however, buying their freedom is nearly impossible since many are already poor and the scamming jobs are designed so that they will never earn enough to leave.
Build a Relationship; Stick to the Script
During the course of this research, we generally found that romance scammers typically use pre-built scripts to carry out their schemes. The scripts instruct scammers how to befriend a victim, develop a believable romantic relationship, and earn money. As many romance scammers are often overseas and most of the victims are native English-speakers, the scripts try to account for all types of questions that could come up in conversation.
Figure 3: Example of a Script, Source: Social Catfish
Scams on Darknet and Darknet-Adjacent Sites
Discussion around romance scams and the communities involved, including both victims and scammers, can be found on the darknet as well as darknet-adjacent sites. Per the examples pictured below, DarkOwl analysts discovered multiple Telegram channels where users are seeking advice on romance scams from others in the community.
Figure 4: Source: Telegram, Channel Redacted
Figure 5: Source: Telegram, Channel Redacted
Over the course of their research, DarkOwl analysts observed that romance scams are rarely called ‘romance scams’ directly, but are often advertised and discussed as “catfishing” or “eWhoring”.
Most people are familiar with Catfishing – i.e. issuing stolen or fictitious information to create a fake identity and utilize that fake identity to trick others. On the other hand, eWhoring entails the theft or leaking of intimate photos, usually of women, which are sold on the darknet in “packs” and used to catfish victims. eWhoring is “revenge porn mixed with catfishing,” per Jess Davies, who added that “it’s happening thousands of women every single day, all around the world. They’re being traded like a card game, either for new packs, or money.”
Figure 6: e-Whoring packs available, Source: Tor Anonymous Browser
DarkOwl analysts found eWhoring methods, guides, and related materials posted in social engineering forums, general discussions sections, and listed as products for sale, on numerous darknet marketplaces and forums.
Hundreds of “packs” of women’s photos from OnlyFans are available for sale as well as what are advertised as leaked private photos. eWhoring guides can be purchased on the darknet although some of them are offered for free.
Figure 7: Free eWhoring guide, Source: Tor Anonymous Browser
DarkOwl analysts have also observed other products to assist with romance scams and eWhoring for sale on the darknet. This includes a “voice verification chat pack” offering to create custom voice messages.
Listings from darknet sites and DarkOwl Vision promise $8000 with eWhoring, or “PRIVATE EWHORING STRATEGIES | AT LEAST $100 A DAY” and a guide on a darknet site claimed users could make $2,000 a month.
Darknet and darknet-adjacent sites also serve as platforms for victims to ask if they have been a victim of a romance scam, get advice on what they should do, and share their stories to warn others.
In one DarkOwl Vision search result, a user on a darknet site writes a post about their realization they have been victimized by a romance scam. This user describes how the scammer gained their trust, and how they pushed them to take out investments. I an attempt to extricate themselves from this situation, the user reports trying to withdraw the crypto they had deposited without letting the scammer’s knowledge.
While this individual tried their best to convince the scammer to let them withdraw their money by promising bigger investments, the scammer staged a situation where the trading didn’t work and all the victims money was lost.
Figure 9: Source: DarkOwl Vision
Figure 10: Source: DarkOwl Vision
Final Thoughts on Romance Scams
Romance scams are part of a complex criminal enterprise that exploits unassuming individuals on both an emotional and sometimes devastatingly catastrophic monetary basis.
Per our analysts research, there is an overlap in the demographic of people who engage in these types of scams on the surface web and who also actively use the darknet. The darknet and darknet-adjacent sites are where victims can go to get help and where a scammer can buy tools and guides to scam more effectively.
For these reasons, the darknet is a potential source to monitor her activity to help combat romance scams and help slimy the current pace with which they’re currently proliferating. Or, said differently, the darknet can teach the next generation of scammers to be even more sophisticated while educating the next potential victims what to look out for and how to protect themselves.
Wondering how darknet data applies to your business? We want to show you! Contact us.
Quick Definitions:
Fraud: an umbrella term, legally referring to various types of chargeable criminal offenses. Fraud is serious criminal business, while scams are considered more minor offenses in comparison. Fraud can be thought of as a felony. Scams can be thought of as a misdemeanor.
Scams: particular segment of fraud. Scams are theft of funds with your permission or knowledge while fraud is financial theft without your permission or knowledge.
Romance scam: social deception designed for financial gain; however, because the victim willingly gives money, romance scams are not tagged as fraud; fall under social media scams.
Catfishing: using stolen or false information to create a fake identity trick someone into giving them information or money.
eWhoring: specific type of social engineering where the offender imitates a virtual partner in a romance scam or virtual sexual encounter. Victims are asked for money in exchange for more image content or are duped into a romance scam. eWhoring packs are sold on darknet marketplaces and forums consisting of leaked or stolen intimate pictures or stolen content resold from adult sites such as OnlyFans.
Social Engineering: process of psychologically manipulating people to get them to do things or share secret information.
For a full list of darknet terms, check out our Glossary.
Last week, DarkOwl participated in CyberTech Global in Tel Aviv, Israel, where cyber industry executives, government officials, and decision makers from a range of sectors including critical infrastructure, insurance, retail, health and government, defense, R&D, manufacturing, automotive, gather from all around the world. This event showcases the latest technology, innovations and trends in the cyber security space. CyberTech describes themselves as “the cyber industry’s foremost B2B networking platform conducting industry-related events all around the globe.” Their events take place around the world from Tel Aviv and Rome, to Tokyo, Singapore, Panama, and more. The DarkOwl team was thrilled at the opportunity to sponsor this year and represent the importance of actionable darknet data in any security posture, product or tool.
“Cyber. We live it. Breathe it. All at the forefront of global innovation.” – CyberTech Global
CyberTech Global proved to be a great event for networking and meeting key players in cyber from multinational corporations, startups, and government agencies. As companies and individuals continue to go digital, cyber attacks and criminals become more sophisticated, and it is imperative that the industry continues to work together and innovate to combat cybercrime. Representing DarkOwl at CyberTech Global was President and CFO, Russell Cohen, based out of DarkOwl’s headquarters in Denver, CO and David Alley, CEO of DarkOwl FZE based in Dubai.
CyberTech Global is truly a global conference with countries from all of the world presenting throughout the week. There were representatives from Israel, the United States, Canada, the United Arab Emirates, Morocco, Thailand, the United Kingdom, Italy, Rwanda, Japan, Belgium, Greece, and several more. They covered topics ranging from cyber war to application security, cyber and human rights to API security, supply chain security to cloud security. According to CyberTech Global, this 2023 event in Tel Aviv was record breaking in terms of attendance! CyberTech Global provided endless networking opportunities and the ability to focus on person to person relationship building.
Russel Cohen, CFO and Co-Founder of DarkOwl, noted “Everyone who came to our booth knew about the darknet. I mean everyone; high school, college students, and retired army or former cybersecurity professionals. All knew about what made the darknet unique.” This supports DarkOwl’s mission of being the leading provider of actionable darknet data; our passion, our focus, and our expertise is the darknet. Having access to darknet data is not longer a “nice to have,” it is essential for analysts and cyber security leaders alike to inform and make sophisticated cybersecurity programs and decisions. It is a necessity to monitor the darknet for direct or potential threats to businesses in order to take action to prevent potentially devastating cybersecurity incidents.
DarkOwl is a Denver-based company that provides the world’s largest index of darknet content and the tools to efficiently find leaked or otherwise compromised sensitive data. We shorten the timeframe to detection of compromised data on the darknet, empowering organizations to swiftly detect security gaps and mitigate damage prior to misuse of their data.