<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Law Enforcement Archives - International Finance</title>
	<atom:link href="https://internationalfinance.com/tag/law-enforcement/feed/" rel="self" type="application/rss+xml" />
	<link>https://internationalfinance.com/tag/law-enforcement/</link>
	<description>International Finance - Financial News, Magazine and Awards</description>
	<lastBuildDate>Mon, 18 Nov 2024 06:55:22 +0000</lastBuildDate>
	<language>en-GB</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.9.7</generator>

<image>
	<url>https://internationalfinance.com/wp-content/uploads/2020/08/favicon-1-75x75.png</url>
	<title>Law Enforcement Archives - International Finance</title>
	<link>https://internationalfinance.com/tag/law-enforcement/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Digital extortion: Doxing in the crypto era</title>
		<link>https://internationalfinance.com/magazine/technology-magazine/digital-extortion-doxing-in-the-crypto-era/#utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=digital-extortion-doxing-in-the-crypto-era</link>
					<comments>https://internationalfinance.com/magazine/technology-magazine/digital-extortion-doxing-in-the-crypto-era/#respond</comments>
		
		<dc:creator><![CDATA[IFM Correspondent]]></dc:creator>
		<pubDate>Tue, 12 Nov 2024 10:07:00 +0000</pubDate>
				<category><![CDATA[Magazine]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[cryptocurrency]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[Doxing]]></category>
		<category><![CDATA[email]]></category>
		<category><![CDATA[gaming]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[Law Enforcement]]></category>
		<category><![CDATA[passwords]]></category>
		<category><![CDATA[SIM-Swapping]]></category>
		<category><![CDATA[social media]]></category>
		<guid isPermaLink="false">https://internationalfinance.com/?p=51328</guid>

					<description><![CDATA[<p>Many doxing attempts revolve around Doxbin, a website that hosts over 176,000 public and private doxes</p>
<p>The post <a href="https://internationalfinance.com/magazine/technology-magazine/digital-extortion-doxing-in-the-crypto-era/">Digital extortion: Doxing in the crypto era</a> appeared first on <a href="https://internationalfinance.com">International Finance</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Since the early 1990s, doxing, the practice of revealing someone&#8217;s identity online and stealing their anonymity, has been utilised as a destructive form of online retaliation. However, the toxic practice has resurfaced in recent years, with victims being doxed, blackmailed, and threatened with physical harm in the worst situations, all in exchange for cryptocurrency.</p>
<p>Security researcher Jacob Larsen, who was doxed about ten years ago when someone tried to extort him for a gaming account, has been keeping an eye on doxing groups, observing the methods used to uncover identities, and speaking with well-known doxing community members for the past year.</p>
<p>According to Larsen&#8217;s interviews, &#8220;well over six figures annually&#8221; have been made as a result of doxing actions. One technique involves feigning law enforcement requests to obtain people&#8217;s personal information.</p>
<p>“The primary target of doxing, particularly when it involves a physical extortion component, is for finance,” says Larsen, who leads an offensive security team at cybersecurity company CyberCX but conducted the doxing research in a personal capacity with the support of the company.</p>
<p>Larsen conducted interviews with &#8220;Ego&#8221; and &#8220;Reiko,&#8221; two members of the doxing community, during several online chat sessions in August and September of 2023.</p>
<p>Reiko served as an administrator of Doxbin, the largest public doxing website, last year in addition to being involved in other groups. Ego is thought to have been a member of the five-person doxing group known as ViLe, though neither of their offline identities is known to the public.</p>
<p>In June 2024, two additional members of ViLe pleaded guilty to charges of identity theft and hacking. Larsen, Ego, and Reiko mentioned that both individuals deleted their social media accounts, which made it impossible for them to be interviewed.</p>
<p>People can be doxed for a variety of reasons, such as inciting political violence or harassing others in online gaming. According to Bree Anderson, a digital criminologist at Deakin University in Australia who has studied the issue with colleagues, doxing can &#8220;humiliate, harm, and reduce the informational autonomy&#8221; of those who are targeted.</p>
<p>According to Anderson, there are two types of harms: immediate or &#8220;first-order,&#8221; like risks to one&#8217;s safety, and longer-term or &#8220;second-order,&#8221; like worry about information disclosures in the future.</p>
<p>The majority of Larsen&#8217;s study was on people who were doxing for financial gain. Many doxing attempts revolve around Doxbin, a website that hosts over 176,000 public and private doxes. These doxes can include names, social media accounts, Social Security numbers, residential and workplace addresses, and other similar details belonging to an individual&#8217;s family.</p>
<p>Larsen believes that extortion is the primary motivator for most doxing incidents on Doxbin, although there are other reasons such as seeking attention. Unless the uploaded information violates the website&#8217;s terms of service, it will not be removed.</p>
<p>“It is your responsibility to uphold your privacy on the internet,” Reiko said in one of the conversations with Larsen, who has published the transcripts.</p>
<p>Ego added, “It’s on the users to keep their online security tight, but let’s be real, no matter how careful you are, someone might still track you down.”</p>
<p><strong>Impersonating police, violence as a service</strong></p>
<p>It is nearly hard to be completely anonymous online, and many people don&#8217;t even try; instead, they frequently use their real names and other personal information in their online accounts and when sharing content on social media.</p>
<p>Some of the doxing techniques outlined in the charges against ViLe members include using shared passwords to access accounts, hacking into private and public databases, and using social engineering to carry out SIM-swapping attacks. There are also many malicious techniques in existence.</p>
<p>Additionally, Larsen notes that emergency data requests (EDR) can be misused. When there may be a risk to people&#8217;s safety, law enforcement officials can use EDRs to obtain the names and contact information of individuals from tech companies without a court order.</p>
<p>In general, these requests must originate from official government or law enforcement email addresses and are sent straight to tech platforms, frequently via specialised online portals.</p>
<p>“If a threat actor can intercept that process, it’s the fastest way for them to get highly accurate sensitive data on the victim. They’re stepping up and using that as their primary method for doxing victims,” Larsen explained.</p>
<p>In the past, this type of request has been used as a weapon against security researchers and to harass women and children.</p>
<p>Larsen claims to have infiltrated multiple Telegram groups during his research, where individuals were offering access to systems for creating EDRs and the government emails required to submit requests.</p>
<p>Using a United States Department of Justice email address and claiming to have an FBI email address, one person, according to screenshots released by Larsen, claimed to be selling access to TikTok&#8217;s law enforcement platform. Someone else asserted that they could create official email addresses for $125 per, originating from Mozambique, the Philippines, Pakistan, and Brazil.</p>
<p>According to Larsen, he gave law enforcement authorities the information. A representative for TikTok referred to the company&#8217;s public policies regarding emergency data requests and the procedures it follows to verify their validity, but the FBI declined to comment on fraudulent EDRs. A request for comment from the US Cybersecurity and Infrastructure Security Agency was not answered.</p>
<p>“Violence as a service” groups have appeared from SIM-swapping communities in recent years as well, allowing people to pay for violent acts to be carried out. Digital extortion can lead to physical extortion, Larsen says, adding that Doxbin doesn’t allow threats or discussions of violence to be posted on its platform.</p>
<p>“I’ve seen people get doxed and that ends up in them being bricked, getting their house shot up, getting a Molotov thrown through their windows, gang stalked, all in an attempt to extort them for money. Videos of attacks are sometimes posted online. Things get pretty wicked online, much more than people realise,” Ego said in a conversation with Larsen.</p>
<p>These incidents can involve people trying to extort cryptocurrency from people with large stashes—although some violence services have been used by feuding online groups.</p>
<p>“Unless these platforms get taken down, or more actors get punished, both in the US and abroad, it&#8217;s just going to continue to rise. Particularly as cryptocurrency becomes more adopted by more people,&#8221; Larsen said.</p>
<p><strong>Few doxing protections</strong></p>
<p>Although some aspects of doxing may be covered by laws about stalking, harassment, or data protection, there aren&#8217;t many legal safeguards against it worldwide.</p>
<p>“Laws worldwide are simply not fit to provide protection. Victims have no way to swiftly regain control of information that has been published with the intent to harass, intimidate, and/or harm them,&#8221; Amanda Manyame, digital rights adviser at Equality Now, a feminist human rights NGO said.</p>
<p>“The prompt takedown of doxing-related content is very important for victims, and governments need to enact laws that mandate the removal of such content within 24 hours, with Equality Now’s research stating that doxing can disproportionately impact women and girls,&#8221; Manyame added.</p>
<p>Doxbin releases a transparency report detailing the quantity of removal requests it receives, emulating the actions of Big Tech platforms and highlighting the difficulties in obtaining information removed.</p>
<p>According to Larsen, there are about 160 requests from lawyers and local and federal law enforcement agencies from 27 different countries. Most of these requests are turned down because they don&#8217;t violate Doxbin&#8217;s restrictive terms of service.</p>
<p>There are steps people can take to lessen some of the effects associated with doxing and other widespread online privacy abuses, even though there are few legal avenues to get data removed.</p>
<p>Common cybersecurity precautions, such as locking down social media accounts and refraining from posting images or personal information, turning on multi-factor authentication for as many accounts as possible, and not reusing passwords across apps and websites, can all be helpful on an individual basis, according to Larsen.</p>
<p>Using usernames and emails that aren&#8217;t connected to the same email address or online handle could be a good starting point for those who want to go further.</p>
<p>The post <a href="https://internationalfinance.com/magazine/technology-magazine/digital-extortion-doxing-in-the-crypto-era/">Digital extortion: Doxing in the crypto era</a> appeared first on <a href="https://internationalfinance.com">International Finance</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://internationalfinance.com/magazine/technology-magazine/digital-extortion-doxing-in-the-crypto-era/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>IF Insights: Is Telegram in trouble post Pavel Durov’s arrest?</title>
		<link>https://internationalfinance.com/technology/if-insights-telegram-trouble-post-pavel-durovs-arrest/#utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=if-insights-telegram-trouble-post-pavel-durovs-arrest</link>
					<comments>https://internationalfinance.com/technology/if-insights-telegram-trouble-post-pavel-durovs-arrest/#respond</comments>
		
		<dc:creator><![CDATA[IFM Correspondent]]></dc:creator>
		<pubDate>Thu, 05 Sep 2024 06:12:56 +0000</pubDate>
				<category><![CDATA[Featured]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[Dark Web]]></category>
		<category><![CDATA[Deepfake]]></category>
		<category><![CDATA[France]]></category>
		<category><![CDATA[internet]]></category>
		<category><![CDATA[Law Enforcement]]></category>
		<category><![CDATA[Pavel Durov]]></category>
		<category><![CDATA[Russia]]></category>
		<category><![CDATA[social media]]></category>
		<category><![CDATA[Telegram]]></category>
		<category><![CDATA[WhatsApp]]></category>
		<guid isPermaLink="false">https://internationalfinance.com/?p=50780</guid>

					<description><![CDATA[<p>With the help of the Telegram software, users can have one-on-one chats, group chats, and broadcast messages to a large number of subscribers through channels</p>
<p>The post <a href="https://internationalfinance.com/technology/if-insights-telegram-trouble-post-pavel-durovs-arrest/">IF Insights: Is Telegram in trouble post Pavel Durov’s arrest?</a> appeared first on <a href="https://internationalfinance.com">International Finance</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>The CEO and creator of the messaging service Telegram, <a href="https://internationalfinance.com/business-leaders/business-leader-telegram-founder-pavel-durov-uaes-richest-expat/"><strong>Pavel Durov</strong></a>, was detained in Paris over the weekend on suspicion of using his platform for illegal activities such as the dissemination of pictures of child abuse and the sale of drugs.</p>
<p>Durov has multiple citizenships spanning France, Russia, the Caribbean island nation of St. Kitts and Nevis, and the United Arab Emirates (UAE). He was born in Russia but lived much of his youth in Italy. After arriving from Azerbaijan, he was detained at Paris-Le Bourget Airport in France and freed following four days of interrogation. According to the Paris prosecutor&#8217;s office, he was told to go to a police station twice a week and was compelled to pay 5 million euros in bail.</p>
<p>Telegram maintained that it complies with European Union (EU) regulations and that its content filtering is &#8220;within industry standards and constantly improving&#8221; in a statement that was uploaded to its platform. The business continued by saying Durov &#8220;has nothing to hide and travels across Europe frequently.&#8221;</p>
<p>Here are some specifics about the Telegram app, which is the reason behind Durov&#8217;s detention.</p>
<p><strong>What is Telegram?</strong></p>
<p>With the help of the Telegram software, users can have one-on-one chats, group chats, and broadcast messages to a large number of subscribers through &#8220;channels.&#8221; In contrast to competitors like Meta&#8217;s <a href="https://internationalfinance.com/technology/whatsapp-communities-rolls-out-beta-users-all-you-need-know/"><strong>WhatsApp</strong></a>, Telegram supports up to 200,000 users in group chats, while WhatsApp only supports 1,024 users. Experts are worried that in group discussions, big, false information might spread quickly.</p>
<p>In contrast to widespread belief, Telegram does not automatically enable end-to-end encryption for user communications. Users must activate the option. Group conversations are not compatible with it either. This is in contrast to Facebook Messenger and rival Signal, where conversations are always end-to-end encrypted.</p>
<p>&#8220;Group conversations and channels—two popular Telegram features—are not end-to-end encrypted,&#8221; said John Scott-Railton, a senior researcher at Citizen Lab at the University of Toronto, explaining that their contents can be accessed through Telegram.</p>
<p>Similarly, user-to-user conversations are not end-to-end encrypted by default, which leaves Telegram with access to them as well. The only end-to-end encrypted function on Telegram is the opt-in &#8220;secret chat&#8221; option, which keeps Telegram from viewing the chat data.</p>
<p>According to Telegram, there are over 950 million active users. It is a popular messaging app in France, and some officials from the presidential palace and the ministry overseeing Durov&#8217;s probe use it as well. However, French police have also discovered that drug dealers and Islamic extremists have utilised the programme.</p>
<p>In 2013, Durov and his brother Nikolai founded Telegram. Pavel Durov backs the app &#8220;financially and philosophically, whereas Nikolai&#8217;s input is technological,&#8221; according to Telegram.</p>
<p>Durov established the biggest social network in Russia, VKontakte, before Telegram. The business faced pressure as a result of the Russian government&#8217;s crackdown following the large-scale pro-democracy demonstrations that shook Moscow at the end of 2011 and 2012.</p>
<p>According to Durov, representatives of the administration ordered VKontakte to remove the internet networks run by Russian opposition activists. Later, it demanded that the site provide the personal information of users who participated in the 2013 Ukrainian rebellion that resulted in the removal of a pro-Kremlin president.</p>
<p>However, in 2014, under pressure from Russian authorities, Durov sold his interest in VKontakte. He departed the nation as well. Currently headquartered in Dubai, Durov described the city as &#8220;the finest position for a neutral platform like ours to be in if we want to make sure we can preserve our users&#8217; privacy and freedom of speech&#8221; during an April 2024 interview with Tucker Carlson, host of a conservative talk programme.</p>
<p><strong>Why Did Durov Get Arrested?</strong></p>
<p>French officials detained Durov and charged him with a misdemeanour for permitting suspected illegal activities on Telegram. They also prohibited him from leaving the country while they conducted additional inquiries. Durov is accused of allowing drug trafficking and child abuse materials to be distributed on his platform, and of Telegram refusing to provide information or documents to law enforcement when asked to do so.</p>
<p>According to the prosecutor&#8217;s office, the first preliminary complaint against him was for &#8220;complicity in maintaining an online platform to allow unlawful transactions by an organized gang,&#8221; a crime that carries a maximum sentence of 10 years in prison and a fine of 500,000 euros.</p>
<p>French law defines preliminary charges as a magistrate&#8217;s strong suspicion of a crime, with the option to continue the inquiry at a later date.</p>
<p><strong>South Korea Gets Tough</strong></p>
<p>South Korean police have now launched an investigation into Telegram over deepfake online sex crimes, reported the Yonhap news agency.</p>
<p>South Korean authorities have called on Telegram and other social media platforms for cooperation in fighting sexually explicit deepfake content. A broadcaster reported in August 2024 about university students running an illegal Telegram chatroom, sharing deepfake pornographic material of female classmates, one of a slew of high-profile cases that have stoked public anger.</p>
<p>&#8220;In light of these (deepfake) crimes, the Seoul National Police Agency launched their probe last week&#8230; for abetting the crimes,&#8221; said Woo Jong-soo, head of the investigation bureau at the National Police Agency, according to a transcript of a press briefing.</p>
<p>Police received 88 reports of deepfake porn last week alone, Woo said, adding they have identified 24 suspects. As per the AFP, the authorities have pledged to &#8220;find ways to cooperate with various investigative bodies, including the French, to enhance&#8221; their investigation into the platform.</p>
<p>As per the activists, South Korea is reportedly suffering from &#8220;an epidemic of digital sex crimes,&#8221; including those involving spycams and revenge porn, with inadequate legislation to punish offenders.</p>
<p>Perpetrators of deepfake crimes have reportedly used social media platforms such as Instagram to save/screen-capture photos of victims, which were then used to create fake pornographic material.</p>
<p><strong>Dark Web Allegations Against Telegram</strong></p>
<p>Telegram&#8217;s lack of content filtering has drawn criticism from Western governments on several occasions. Experts claim this exposes the messaging app to possible uses in drug trafficking, money laundering, and the transmission of content related to the exploitation of kids.</p>
<p>In contrast to other messaging apps, David Thiel, a researcher at Stanford University&#8217;s Internet Observatory who has studied the use of online platforms for child exploitation, claimed that Telegram is &#8220;less secure (and) more lax in terms of policy and detection of unlawful information.&#8221;</p>
<p>Additionally, Thiel stated that WhatsApp, a messaging software, &#8220;submitted over 1.3 million CyberTipline reports in 2023 (while) Telegram submits none,&#8221; and that Telegram &#8220;appears basically unresponsive to law enforcement.&#8221;</p>
<p>Due to the Telegram operators&#8217; noncompliance with German legislation, Germany fined them 5.125 million euros (USD 5 million at the time). According to the Federal Office of Justice, Telegram has not designated a German company to receive official correspondence or established a legal mechanism for reporting illegal content.</p>
<p>Under German rules governing big internet platforms, both are necessary.</p>
<p>Due to Telegram&#8217;s refusal to provide information on neo-Nazi behaviour linked to a police investigation into school shootings in November 2023, Brazil temporarily blocked the messaging app.</p>
<p>As per Joe Tidy, Cyber correspondent, BBC World Service, criminals generally like the dark web because of the anonymity it provides: internet traffic is bounced around the world, obscuring people&#8217;s locations. Citing Researchers at cyber-security company Intel471, he said, “pre-Telegram this activity (cybercrime) was predominantly done in online markets hosted using hidden dark web services but for lower-level, lesser-skilled cyber-criminals, Telegram has become one of the most popular online destinations”.</p>
<p>The hacker group Qilin, which held United Kingdom&#8217;s NHS hospitals to ransom recently, notably chose to publish stolen blood test data on its Telegram channel before its dark web website. The deepfake service used to create fake vulgar images of teenagers in Spain and South Korea also runs its full service, including payment, on Telegram.</p>
<p>In January 2024, state police in Latvia set up a separate unit specialising in monitoring chat apps for drug trafficking and communication, and officials have named Telegram as a particular concern.</p>
<p>On &#8220;Chila Abuse Materials,&#8221; Telegram says that its content moderation is “within industry standards”, but BBC has found evidence to the contrary related to &#8220;an area of criminality far less visible.&#8221;</p>
<p>The BBC learnt that while Telegram does respond to some takedown requests from police and charities, it does not participate in programmes aimed at proactively preventing the spread of images and videos of child abuse. Not doing enough to police CSAM has been one of the allegations French prosecutors have brought against the platform.</p>
<p>“At the heart of this case is the lack of moderation and co-operation of the platform, in particular in the fight against crimes against children,” said Jean-Michel Bernigaud, the secretary general of French child protection agency Ofmin, on LinkedIn.</p>
<p>Moderation is not the only part of the problem for Telegram. The platform&#8217;s approach to police requests to remove illegal content and pass on evidence is another criticism.</p>
<p>Brian Fishman, a co-founder of Cinder, a software platform for trust and safety, posted, “Telegram is another level: it has been the key hub for Isis for a decade. It tolerates CSAM. It&#8217;s ignored reasonable law enforcement engagement for years. It’s not &#8216;light&#8217; content moderation; it’s a different approach entirely.”</p>
<p>&#8220;Some might argue that Telegram’s privacy features mean that the company does not have much data about this activity to report to police. This is the case with ultra-private apps like Signal and WhatsApp. Telegram offers users similar levels of privacy if they opt to create a &#8216;Secret Chat&#8217; which uses the same end-to-end encryption that those apps do. It means the activity inside a conversation is completely private and not even Telegram itself can view the contents. However, this function is not set as default on Telegram, and it seems that most of the activity on the app &#8211; including on those illicit channels I was added to &#8211; are not set as secret,&#8221; Joe Tidy noted.</p>
<p>Telegram could read all content and pass it on to the police if it wanted to, but it states in its terms and conditions that it does not. In June 2024, Pavel Durov told journalist Tucker Carlson that he only employs “about 30 engineers” to run his platform. Telegram’s cold approach to law enforcement is something that Tidy cited by frustrated police officers on the fringes of press events.</p>
<p>French authorities also noted in their statements about Mr Durov’s charges that police there and in Belgium had historically an “almost total lack of response from Telegram to legal requests”.</p>
<p>The post <a href="https://internationalfinance.com/technology/if-insights-telegram-trouble-post-pavel-durovs-arrest/">IF Insights: Is Telegram in trouble post Pavel Durov’s arrest?</a> appeared first on <a href="https://internationalfinance.com">International Finance</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://internationalfinance.com/technology/if-insights-telegram-trouble-post-pavel-durovs-arrest/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>LockBit ransomware: The global cyber menace</title>
		<link>https://internationalfinance.com/magazine/technology-magazine/lockbit-ransomware-the-global-cyber-menace/#utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=lockbit-ransomware-the-global-cyber-menace</link>
					<comments>https://internationalfinance.com/magazine/technology-magazine/lockbit-ransomware-the-global-cyber-menace/#respond</comments>
		
		<dc:creator><![CDATA[IFM Correspondent]]></dc:creator>
		<pubDate>Mon, 17 Jun 2024 18:30:51 +0000</pubDate>
				<category><![CDATA[Magazine]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[Boeing]]></category>
		<category><![CDATA[cybercrime]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[data]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[Law Enforcement]]></category>
		<category><![CDATA[LockBit]]></category>
		<category><![CDATA[LockBitSupp]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[ransomware]]></category>
		<category><![CDATA[Russia]]></category>
		<category><![CDATA[United States]]></category>
		<guid isPermaLink="false">https://internationalfinance.com/?p=50198</guid>

					<description><![CDATA[<p>The LockBit group managed to extort at least $500 million from victims in 120 countries</p>
<p>The post <a href="https://internationalfinance.com/magazine/technology-magazine/lockbit-ransomware-the-global-cyber-menace/">LockBit ransomware: The global cyber menace</a> appeared first on <a href="https://internationalfinance.com">International Finance</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>A Russian national named Dmitry Yuryevich Khoroshev has hit the headlines, for all the vile reasons, as law enforcement authorities in the United States, United Kingdom, and Australia have jointly named the person as the alleged operator of the LockBitSupp handle and the organisational mastermind behind the notorious LockBit ransomware group, which has been on a multiyear hacking rampage exporting an estimated USD 500 million from its victims.</p>
<p>&#8220;LockBit ransomware is malicious software designed to block user access to computer systems in exchange for a ransom payment. LockBit will automatically vet for valuable targets, spread the infection, and encrypt all accessible computer systems on a network. This ransomware is used for highly targeted attacks against enterprises and other organisations,&#8221; States Kaspersky.</p>
<p>LockBit attackers have been on the news frequently for threatening global organisations, disrupting their operations, extorting the victims financially, stealing data and illegally publishing them on the dark web.</p>
<p>LockBit has transformed itself into a subclass of ransomware known as a ‘crypto virus’ due to its ability to form its ransom requests around financial payment in exchange for decryption. The element focuses mostly on enterprises and government organisations rather than individuals.</p>
<p>&#8220;Attacks using LockBit originally began in September 2019, when it was dubbed the “.abcd virus.” The moniker was in reference to the file extension name used when encrypting a victim’s files. Notable past targets include organisations in the United States, China, India, Indonesia, and Ukraine. Additionally, various countries throughout Europe (France, UK, Germany) have seen attacks,&#8221; Kaspersky commented.</p>
<p>&#8220;Viable targets are ones that will feel hindered enough by the disruption to pay a heavy sum — and have the funds to do so. As such, this can result in sprawling attacks against large enterprises from healthcare to financial institutions. In its automated vetting process, it seems to also intentionally avoid attacking systems local to Russia or any other countries within the Commonwealth of Independent States. Presumably, this is to avoid prosecution in those areas,&#8221; the cybersecurity firm added further.</p>
<p>LockBit functions as ransomware-as-a-service (RaaS). Willing parties put a deposit down for the use of custom for-hire attacks, and profit under an affiliate framework. Ransom payments are divided between the LockBit developer team and the attacking affiliates, who receive up to three-fourths of the ransom funds.<br />
How LockBit hit the news?</p>
<p>As recent as May 2024, reports emerged about the cybercriminals targeting American aviation giant Boeing using the LockBit ransomware platform in October 2023, during which these threat actors also demanded a $200 million extortion payment.</p>
<p>Boeing reportedly did not pay any ransom to LockBit after roughly 43 gigabytes of company data was posted to LockBit’s website in November 2023, according to BleepingComputer. Boeing, however, confirmed a “cyber incident” and said the incident was impacting elements of its parts and distribution business. The company refrained from commenting publicly in detail about the incident. However, they eventually admitted the episode during a US Justice Department indictment, which identified Dmitry Yuryevich Khoroshev as the main administrator and developer behind the LockBit ransomware operation.</p>
<p>&#8220;The reference in the indictment to the unnamed company (read Boeing) was an example of the ‘extremely large’ ransom demands made by Khoroshev and his co-conspirators, as they racked up more than $500 million in ransoms paid by victims since late 2019 or early 2020,&#8221; Cyberscoop reported further.<br />
“I believe this may be the second biggest ransom demand to date — or, perhaps more accurately, to have become public knowledge,” said Brett Callow, a ransomware analyst with the cybersecurity firm Emsisoft, while interacting with Cyberscoop.</p>
<p>Callow said that it was “unlikely” that LockBit “had the ability to accurately determine just how sensitive that data was — or how much Boeing may be willing to pay to prevent it being published — and so made a ridiculously high demand simply to see what would happen. They probably had no realistic expectation of actually being paid that amount.”</p>
<p>LockBitSupp, the online persona that communicates with journalists and others online on behalf of LockBit, also confirmed to CyberScoop that Boeing was the unnamed company.</p>
<p>&#8220;US and British law enforcement authorities said that Khoroshev is LockBitSupp. A message posted to LockBitSupp’s account on the messaging platform said the authorities identified the wrong person,&#8221; Cyberscoop commented further.</p>
<p><strong>Meet Dmitry Yuryevich Khoroshev</strong></p>
<p>Has LockBitSupp played a mind game by stating Khoroshev as the &#8220;Wrong Person?&#8221; There is no definitive answer to this question, except the fact that the Russian individual we are talking about has been named by the American and British law enforcement authorities behind the LockBit ransomware attacks.<br />
The Wired states, &#8220;LockBitSupp has evaded identification and bragged that people wouldn’t be able to reveal their offline identity—even offering a $10 million reward for their real name.&#8221;</p>
<p>Law enforcement’s linking of Khoroshev to LockBitSupp comes after the UK police infiltrated the LockBit group’s systems and made several arrests—taking its servers offline, gathering the group’s internal communications, and putting a stop to LockBit’s hacking spree. The law enforcement takedown, dubbed “Operation Cronos” and led by the UK’s National Crime Agency (NCA), has essentially neutralised the hacking group and sent ripples through the wider Russian cybercrime ecosystem. Not only Boeing, LockBitSupp even targeted sandwich chain Subway.</p>
<p>In addition to being named, Khoroshev has also been sanctioned by the US, UK, and Australia. According to the United States Office of Foreign Assets Control, Khoroshev is 31 and lives in Russia, with details of his sanction designation also listing multiple email addresses and cryptocurrency addresses, alongside his Russian passport details. Washington has also filed an indictment against him.</p>
<p>The indictment says Khoroshev has acted as the LockBit group&#8217;s “developer and administrator” since around September 2019, designing and developing its “control panel” used within ransomware attacks. The LockBit group managed to extort at least $500 million from victims in 120 countries, including Khoroshev&#8217;s home country Russia.  The indictment further says that he received around $100 million from this activity.</p>
<p>In early 2024, before the crackdown by Western authorities, LockBit had risen to become one of the most prolific ransomware groups ever, launching hundreds of attacks on a monthly basis and ruthlessly publishing stolen data from companies if they refused to pay.</p>
<p>As per the Wired, investigators are also starting to unpick more details about the scale and scope of LockBit’s operations. An unnamed UK National Crime Agency (NCA) senior investigating officer, who is involved with the probe, says LockBit listed 2,350 victims publicly on its leak site up to the end of December 2023, but that this is just a small fraction of its hacking activity.</p>
<p><strong>Judging gravity of the situation</strong></p>
<p>As per Kaspersky, LockBit attacks are self-spreading in nature, when they target an organisation, meaning they don&#8217;t require manual direction from the human threat agents. The attacks don&#8217;t happen in a scattershot manner like spam malware, and the acts can be conducted through tools like Windows Powershell and Server Message Block (SMB).</p>
<p>During the attack stage, LockBit can self-propagate itself, meaning the malware spreads on its own. In its programming, LockBit is directed by pre-designed automated processes. This makes it unique from many other ransomware attacks that are driven by manually living in the network, sometimes for weeks, to complete reconnaissance and surveillance tasks.</p>
<p>&#8220;After the attacker has manually infected a single host, it can find other accessible hosts, connect them to infected ones, and share the infection using a script. This is completed and repeated entirely without human intervention,&#8221; Kaspersky described the nature of LockBit attacks exactly in these words.</p>
<p>&#8220;Furthermore, it uses tools in patterns that are native to nearly all Windows computer systems. Endpoint security systems have a hard time flagging malicious activity. It also hides the executable encrypting file by disguising it as the common .PNG image file format, further deceiving system defences,&#8221; it added further.</p>
<p>Breaking down the stages of LockBit attacks, the initial breach looks much like other malware attacks. An organisation may be exploited by social engineering tactics like phishing, in which attackers impersonate trusted personnel or authorities to request access credentials. Equally viable is the use of brute force attacks on an organization’s intranet servers and network systems. Without proper network configuration, attack probes may only take a few days to complete. Once LockBit makes its way into the network, the ransomware prepares the system to release its encrypting payload across every device it can.</p>
<p>In stage two, LockBit infiltrates deeper to complete the attack setup if needed. From here onwards, the LockBit programme directs all activity independently.</p>
<p>&#8220;It is at this stage that LockBit will take any preparative actions before deploying the encryption portion of the ransomware. This includes disabling security programmes and any other infrastructure that could permit system recovery,&#8221; it continued further, while adding, “the goal of infiltration is to make unassisted recovery impossible, or slow enough that succumbing to the attacker’s ransom is the only practical solution. When the victim is desperate to get operations back to normal, this is when they will pay the ransom fee.&#8221;</p>
<p>In the third stage, the malware deploys the encryption payload. Once the network has been prepared for LockBit to be fully mobilised, the ransomware will begin its propagation across any machine it can touch. A single system unit with high access can issue commands to other network units to download LockBit and run it.<br />
The encryption portion will place a “lock” on all the system files. Victims will only be able to unlock their systems via a custom key created by LockBit’s proprietary decryption tool. The process also leaves copies of a simple ransom note text file in every system folder. It provides the victim with instructions to restore their system and has even included threatening blackmail in some LockBit versions.</p>
<p>&#8220;With all the stages completed, the next steps are left up to the victim. They may decide to contact LockBit’s support desk and pay the ransom. However, following their demands is not advised. Victims have no guarantee that the attackers will follow through on their end of the bargain,&#8221; Kaspersky remarked.</p>
<p><strong>Rise of LockBit</strong></p>
<p>The malware first emerged in 2019 as a fledgling “ransomware-as-a-service” (RaaS) platform. Under this setup, a core handful of individuals, organised by the LockBitSupp handle, created the group’s easy-to-use malware and launched its leak website. This particular group is still reportedly licencing LockBit’s code to “affiliate” hackers who launch attacks and negotiate ransom payments, eventually providing LockBit with around 20% of their profits.</p>
<p>Despite launching thousands of attacks, the group, in its starting days, maintained a low-profile, compared to other threat actors. Over time, as the malware started to dominate the cybercrime ecosystem, its members became more brazen and careless. As per an unnamed NCA senior investigator, these individuals pulled data about 194 affiliates from LockBit’s systems and were piecing together their offline identities. </p>
<p>The NCA investigator further pointed out “numerous” examples of the LockBit administrator directly “taking responsibility” for high-profile/high-ransom negotiations after affiliates had initially attacked the companies or organisations.</p>
<p>The US DOJ indictment claims Khoroshev, as LockBitSupp, kept a close track of his affiliates, keeping databases of each affiliate and the victims they had targeted. In some cases, the Russian demanded identification documents from his affiliate co-conspirators, which he also maintained on his infrastructure.<br />
Jon DiMaggio, a researcher at cybersecurity firm Analyst1, who has been aggressively researching LockBit, apart from communicating with the LockBitSupp handle, told Wired, “He (Khoroshev) treated it like a business and often sought out feedback from his affiliate partners on how he could make the criminal operation more effective.&#8221;</p>
<p>&#8220;The LockBitSupp character would ask affiliates what they needed in order to more effectively do their work. He did not simply take money for himself, but he reinvested it into developing his operation and making it more desirable to criminals,&#8221; DiMaggio noted.</p>
<p>DiMaggio says the person he was speaking to privately using the LockBitSupp moniker was “arrogant but all business and very serious,” apart from sending cat stickers as part of chats.</p>
<p>&#8220;Publicly, on Russian language cybercrime forums where hackers trade data and discuss hacking politics and news, LockBitSupp was entirely different. The persona he amplified on the Russia hacking forums was a mix of a supervillain and Tony Montana from Scarface. He flaunted his success and money, and it rubbed people the wrong way at times,&#8221; DiMaggio continued further.</p>
<p>&#8220;In addition to setting a bounty on their own identity, LockBitSupp’s more innovative and erratic side also organised an essay-writing competition on the hacking forums, offered a bug bounty if people found flaws in LockBit’s code, and said they would pay $1,000 to anyone who got the LockBit logo as a tattoo. Around 20 people posted pictures and videos of their tattoos,&#8221; Wired continued.</p>
<p>Immediately after law enforcement claimed to reveal LockBitSupp’s identity, DiMaggio published new research about Khoroshev. Using a tip he received, plus open source intelligence and leaked dark web information, DiMaggio found social media profiles and extra personal information allegedly linked to the Russian national.<br />
LockBitSupp was reportedly banned from two prominent Russian-language cybercrime forums in January 2024 after a complaint was made about their behaviour.</p>
<p><strong>And the downfall finally came</strong></p>
<p>In February 2024, an international task force of law-enforcement agencies from 10 countries, dubbed &#8220;Operation Cronos,&#8221; disrupted LockBit&#8217;s operations. LockBit’s technical infrastructure and its public-facing leak site on the dark web were seized after a months-long operation.</p>
<p>On 20 February, the NCA published details of the operation, and replaced content on the LockBit website, with an expose on LockBit’s operations and capabilities, including decryption keys, news of two arrests and a $10 million reward for information on ‘LockBitSupp’.</p>
<p>However, the battle was far from over, as it took LockBitSupp only five days to create replica versions of the group’s leak site. The website then started to be filled with apparent victims and it seemed like the LockBit group hadn’t been impacted by having all of its internal secrets accessed by Law enforcement agencies.<br />
The NCA says the number of LockBit affiliates has dropped to 69 since its February takedown, while the DOJ indictment says LockBit’s victim count has “greatly diminished” since then.</p>
<p><strong>What to expect now?</strong></p>
<p>As per the DOJ indictment, post &#8220;Operation Cronos,&#8221; Khoroshev got in touch with law enforcement, in an attempt to “stifle his competition.”</p>
<p>&#8220;He offered his services in exchange for information regarding the identity of his RaaS competitors. Specifically, Khoroshev asked law enforcement during that exchange to, in sum and substance, give me the names of my enemies,” the indictment mentioned further.</p>
<p>Ahead of law enforcement naming Khoroshev, a countdown appeared on the website, and LockBitSupp responded by publishing scores of victims.</p>
<p>“LockBitSupp has a lot of enemies and people waiting to take his place,” said DiMaggio, the Analyst1 researcher, while adding that the group would unlikely stop their actions.</p>
<p>As per the NCA, the task force has seized LockBit’s bespoke data exfiltration tool, Stealbit, which was based in three countries and used to steal data, as well as 28 servers belonging to the group’s affiliates.</p>
<p>Europol, on the other hand, coordinated the arrest of two LockBit members in Poland and Ukraine and froze 200 cryptocurrency accounts linked to the group.<br />
In the United States, indictment charges were brought against Russian nationals Artur Sungatov and Ivan Kondratyev, aka ‘Bassterlord’, for using LockBit against businesses globally.</p>
<p>Operation Cronos has also obtained more than 1,000 decryption keys, which can help victims recover their data. All these coordinated actions from the legal authorities are hitting LockBit hard. How long will the group remain defiant? Let’s wait and watch.</p>
<p>The post <a href="https://internationalfinance.com/magazine/technology-magazine/lockbit-ransomware-the-global-cyber-menace/">LockBit ransomware: The global cyber menace</a> appeared first on <a href="https://internationalfinance.com">International Finance</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://internationalfinance.com/magazine/technology-magazine/lockbit-ransomware-the-global-cyber-menace/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
