The Dark Nexus Between Harm Groups and The Com Krebs on Security

pA cyberattack that shut down two of the top casinos in Las Vegas last year quickly became one of the most riveting security stories of 2023 It was the first known case of native Englishspeaking hackers in the United States and Britain teaming up with ransomware gangs based in Russia But that madeforHollywood narrative has eclipsed a far more hideous trend Many of these young Western cybercriminals are also members of fastgrowing online groups that exist solely to bully stalk harass and extort vulnerable teens into physically harming themselves and othersppImage ShutterstockppIn September 2023 a Russian ransomware group known as ALPHVBlack Cat claimed credit for an intrusion at the MGM Resorts hotel chain that quickly brought MGMs casinos in Las Vegas to a standstill While MGM was still trying to evict the intruders from its systems an individual who claimed to have firsthand knowledge of the hack contacted multiple media outlets to offer interviews about how it all went downppOne account of the hack came from a 17yearold in the United Kingdom who told reporters the intrusion began when one of the Englishspeaking hackers phoned a tech support person at MGM and tricked them into resetting the password for an employee accountppThe security firm CrowdStrike dubbed the group Scattered Spider a recognition that the MGM hackers came from different cliques scattered across an ocean of Telegram and Discord servers dedicated to financiallyoriented cybercrimeppCollectively this archipelago of crimefocused chat communities is known as The Com and it functions as a kind of distributed cybercriminal social network that facilitates instant collaborationppBut mostly The Com is a place where cybercriminals go to boast about their exploits and standing within the community or to knock others down a peg or two Top Com members are constantly sniping over who pulled off the most impressive heists or who has accumulated the biggest pile of stolen virtual currenciesppAnd as often as they extort victim companies for financial gain members of The Com are trying to wrest stolen money from their cybercriminal rivals often in ways that spill over into physical violence in the real worldppCrowdStrike would go on to produce and sell Scattered Spider action figures and it featured a lifesized Scattered Spider sculpture at this years RSA Security Conference in San FranciscoppppBut marketing security products and services based on specific cybercriminal groups can be tricky particularly if it turns out that robbing and extorting victims is by no means the most abhorrent activity those groups engage in on a daily basisppKrebsOnSecurity examined the Telegram user ID number of the account that offered media interviews about the MGM hack which corresponds to the screen name Holy and found the same account was used across a number of cybercrime channels that are entirely focused on extorting young people into harming themselves or others and recording the harm on videoppHoly was known to possess multiple prized Telegram usernames including bomb halo and cute as well as one of the highestpriced Telegram usernames ever put up for sale nazippIn one post on a Telegram channel dedicated to youth extortion this same user can be seen asking if anyone knows the current Telegram handles for several core members of 764 an extremist group known for victimizing children through coordinated online campaigns of extortion doxing swatting and harassmentppPeople affiliated with harm groups like 764 will often recruit new members by lurking on gaming platforms social media sites and mobile applications that are popular with young people including Discord Minecraft Roblox Steam Telegram and TwitchppThis type of offence usually starts with a direct message through gaming platforms and can move to more private chatrooms on other virtual platforms typically one with video enabled features where the conversation quickly becomes sexualized or violent warns a recent alert from the Royal Canadian Mounted Police RCMP about the rise of sextortion groups on social media channelsppOne of the tactics being used by these actors is sextortion however they are not using it to extract money or for sexual gratification the RCMP continued Instead they use it to further manipulate and control victims to produce more harmful and violent content as part of their ideological objectives and radicalization pathwayppThe 764 network is among the most populated harm communities but there are plenty more Some of the largest such known groups include CVLT Court Kaskar Leak Society 7997 8884 2992 6996 555 Slit Town 545 404 NMK 303 and H3llppIn March a consortium of reporters from Wired Der Spiegel Recorder and The Washington Post examined millions of messages across more than 50 Discord and Telegram chat groupsppThe abuse perpetrated by members of com groups is extreme Wireds Ali Winston wrote They have coerced children into sexual abuse or selfharm causing them to deeply lacerate their bodies to carve cutsigns of an abusers online alias into their skin The story continuesppVictims have flushed their heads in toilets attacked their siblings killed their pets and in some extreme instances attempted or died by suicide Court records from the United States and European nations reveal participants in this network have also been accused of robberies inperson sexual abuse of minors kidnapping weapons violations swatting and murderppSome members of the network extort children for sexual pleasure some for power and control Some do it merely for the kick that comes from manipulation Others sell the explicit CSAM content produced by extortion on the dark webppKrebsOnSecurity has learned Holy is the 17yearold who was arrested in July 2024 by the UKs West Midlands Police as part of a joint investigation with the FBI into the MGM hackppEarly in their cybercriminal career as a 15yearold Holy went by the handle Vsphere and was a proud member of the LAPSUS cybercrime group Throughout 2022 LAPSUS would hack and social engineer their way into some of the worlds biggest technology companies including EA Games Microsoft NVIDIA Okta Samsung and TMobileppAnother timely example of the overlap between harm communities and top members of The Com can be found in a group of criminals who recently stole obscene amounts of customer records from users of the cloud data provider SnowflakeppAt the end of 2023 malicious hackers figured out that many major companies have uploaded massive amounts of valuable and sensitive customer data to Snowflake servers all the while protecting those Snowflake accounts with little more than a username and password no multifactor authentication required The group then searched darknet markets for stolen Snowflake account credentials and began raiding the data storage repositories used by some of the worlds largest corporationsppAmong those that had data exposed in Snowflake was ATT which disclosed in July that cybercriminals had stolen personal information and phone and text message records for roughly 110 million people nearly all its customersppA report on the extortion group from the incident response firm Mandiant notes that Snowflake victim companies were privately approached by the hackers who demanded a ransom in exchange for a promise not to sell or leak the stolen data All told more than 160 organizations were extorted including TicketMaster Lending Tree Advance Auto Parts and Neiman MarcusppOn May 2 2024 a user by the name Judische claimed on the fraudfocused Telegram channel Star Chat that they had hacked Santander Bank one of the first known Snowflake victims Judische would repeat that claim in Star Chat on May 13 the day before Santander publicly disclosed a data breach and would periodically blurt out the names of other Snowflake victims before their data even went up for sale on the cybercrime forumsppA careful review of Judisches account history and postings on Telegram shows this user is more widely known under the nickname Waifu an early moniker that corresponds to one of the more accomplished SIMswappers in The Com over the yearsppIn a SIMswapping attack the fraudsters will phish or purchase credentials for mobile phone company employees and use those credentials to redirect a targets mobile calls and text messages to a device the attackers controlppSeveral channels on Telegram maintain a frequently updated leaderboard of the 100 richest SIMswappers as well as the hacker handles associated with specific cybercrime groups Waifu is ranked 24 That leaderboard has long included Waifu on a roster of hackers for a group that called itself BeigeppBeige members were implicated in two stories published here in 2020 The first was an August 2020 piece called Voice Phishers Targeting Corporate VPNs which warned that the COVID19 epidemic had brought a wave of voice phishing or vishing attacks that targeted workfromhome employees via their mobile devices and tricked many of those people into giving up credentials needed to access their employers network remotelyppBeige group members also have claimed credit for a breach at the domain registrar GoDaddy In November 2020 intruders thought to be associated with the Beige Group tricked a GoDaddy employee into installing malicious software and with that access they were able to redirect the web and email traffic for multiple cryptocurrency trading platformsppThe Telegram channels that Judische and his related accounts frequented over the years show this user divides their time between posting in SIMswapping and cybercrime cashout channels and harassing and stalking others in harm communities like Leak Society and CourtppMandiant has attributed the Snowflake compromises to a group it calls UNC5537 with members based in North America and Turkey KrebsOnSecurity has learned Judische is a 26yearold software engineer in Ontario CanadappSources close to the investigation into the Snowflake incident tell KrebsOnSecurity the UNC5537 member in Turkey is John Erin Binns an elusive American man indicted by the US Department of Justice DOJ for a 2021 breach at TMobile that exposed the personal information of at least 766 million customersppBinns is currently in custody in a Turkish prison and fighting his extradition Meanwhile he has been suing almost every federal agency and agent that contributed investigative resources to his caseppIn June 2024 a Mandiant employee told Bloomberg that UNC5537 members have made death threats against cybersecurity experts investigating the hackers and that in one case the group used artificial intelligence to create fake nude photos of a researcher to harass themppIn June 2024 two American men pleaded guilty to hacking into a US Drug Enforcement Agency DEA online portal that tapped into 16 different federal law enforcement databases  Sagar Weep Singh a 20yearold from Rhode Island and Nicholas Convict Ceraolo 25 of Queens NY were both active in SIMswapping communitiesppSingh and Ceraolo hacked into a number of foreign police department email accounts and used them to make phony emergency data requests to social media platforms seeking account information about specific users they were stalking According to the government in each case the men impersonating the foreign police departments told those platforms the request was urgent because the account holders had been trading in child pornography or engaging in child extortionppEventually the two men formed part of a group of cybercriminals known to its members as ViLE who specialize in obtaining personal information about thirdparty victims which they then used to harass threaten or extort the victims a practice known as doxingppThe US government says Singh and Ceraolo worked closely with a third man referenced in the indictment as coconspirator 1 or CC1 to administer a doxing forum where victims could pay to have their personal information removedppThe government doesnt name CC1 or the doxing forum but CC1s hacker handle is Kayte aka KT which corresponds to the nickname of a 23yearold man who lives with his parents in Coffs Harbor Australia For several years with a brief interruption KT has been the administrator of a truly vile doxing community known as the DoxbinppA screenshot of the website for the cybercriminal group ViLE Image USDOJppPeople whose names and personal information appear on the Doxbin can quickly find themselves the target of extended harassment campaigns account hacking SIMswapping and even swatting which involves falsely reporting a violent incident at a targets address to trick local police into responding with potentially deadly forceppA handful of Com members targeted by federal authorities have gone so far as to perpetrate swatting doxing and other harassment against the same federal agents who are trying to unravel their alleged crimes This has led some investigators working cases involving the Com to begin redacting their names from affidavits and indictments filed in federal courtppIn January 2024 KrebsOnSecurity broke the news that prosecutors in Florida had charged a 19yearold alleged Scattered Spider member named Noah Michael Urban with wire fraud and identity theft That story recounted how Urbans alleged hacker identities King Bob and Sosa inhabited a world in which rival cryptocurrency theft rings frequently settled disputes through socalled violenceasaservice offerings hiring strangers online to perpetrate firebombings beatings and kidnappings against their rivalsppUrbans indictment shows the name of the federal agent who testified to it has been blacked outppThe final page of Noah Michael Urbans indictment shows the investigating agent redacted their name from charging documentsppIn June 2022 this blog told the story of two men charged with hacking into the Ring home security cameras of a dozen random people and then methodically swatting each of them Adding insult to injury the men used the compromised security cameras to record live footage of local police swarming those homesppMcCarty in a mugshotppJames Thomas Andrew McCarty Charlotte NC and Kya Chumlul Nelson of Racine Wisc conspired to hack into Yahoo email accounts belonging to victims in the United States The two would check how many of those Yahoo accounts were associated with Ring accounts and then target people who used the same password for both accountsppThe Telegram and Discord aliases allegedly used by McCarty Aspertaine and Couch among others correspond to an identity that was active in certain channels dedicated to SIMswappingppWhat KrebsOnSecurity didnt report at the time is that both ChumLul and Aspertaine were active members of CVLT wherein those identities clearly participated in harassing and exploiting young teens onlineppIn June 2024 McCarty was sentenced to seven years in prison after pleading guilty to making hoax calls that elicited police SWAT responses Nelson also pleaded guilty and received a sevenyear prison sentenceppIn March 2023 US federal agents in New York announced theyd arrested Pompompurin the alleged administrator of Breachforums an Englishlanguage cybercrime forum where hacked corporate databases frequently appear for sale In cases where the victim organization isnt extorted in advance by hackers being listed on Breachforums has often been the way many victims first learned of an intrusionppPompompurin had been a nemesis to the FBI for several years In November 2021 KrebsOnSecurity broke the news that thousands of fake emails about a cybercrime investigation were blasted out from the FBIs email systems and Internet addressesppPompompurin took credit for that stunt and said he was able to send the FBI email blast by exploiting a flaw in an FBI portal designed to share information with state and local law enforcement authorities The FBI later acknowledged that a software misconfiguration allowed someone to send the fake emailsppIn December 2022 KrebsOnSecurity detailed how hackers active on BreachForums had infiltrated the FBIs InfraGard program a vetted network designed to build cyber and physical threat information sharing partnerships with experts in the private sector The hackers impersonated the CEO of a major financial company applied for InfraGard membership in the CEOs name and were granted admission to the communityppThe feds named Pompompurin as 21yearold Peekskill resident Conor Brian Fitzpatrick who was originally charged with one count of conspiracy to solicit individuals to sell unauthorized access devices stolen usernames and passwords But after FBI agents raided and searched the home where Fitzpatrick lived with his parents prosecutors tacked on charges for possession of child pornographyppppRecent actions by the DOJ indicate the government is well aware of the significant overlap between leading members of The Com and harm communities But the government also is growing more sensitive to the criticism that it can often take months or years to gather enough evidence to criminally charge some of these suspects during which time the perpetrators can abuse and recruit countless new victimsppLate last year however the DOJ signaled a new tactic in pursuing leaders of harm communities like 764 Charging them with domestic terrorismppIn December 2023 the government charged PDF a Hawaiian man with possessing and sharing sexually explicit videos and images of prepubescent children being abused Prosecutors allege Kalana Limkin 18 of Hilo Hawaii admitted he was an associate of CVLT and 764 and that he was the founder of a splinter harm group called Cultist Limkins Telegram profile shows he also was active on the harm community Slit TownppThe relevant citation from Limkins complaint readsppMembers of the group 764 have conspired and continue to conspire in both online and inperson venues to engage in violent actions in furtherance of a Racially Motivated Violent Extremist ideology wholly or in part through activities that violate federal criminal law meeting the statutory definition of Domestic Terrorism defined in Title 18 United States Code 2331ppExperts say charging harm groups under antiterrorism statutes potentially gives the government access to more expedient investigative powers than it would normally have in a runofthemill criminal hacking caseppWhat it ultimately gets you is additional tools you can use in the investigation possibly warrants and things like that said Mark Rasch a former US federal cybercrime prosecutor and now general counsel for the New Yorkbased cybersecurity firm Unit 221B It can also get you additional remedies at the end of the case like greater sanctions more jail time fines and forfeitureppBut Rasch said this tactic can backfire on prosecutors who overplay their hand and go after someone who ends up challenging the charges in courtppIf youre going to charge a hacker or pedophile with a crime like terrorism thats going to make it harder to get a conviction Rasch said It adds to the prosecutorial burden and increases the likelihood of getting an acquittalppRasch said its unclear where it is appropriate to draw the line in the use of terrorism statutes to disrupt harm groups online noting that there certainly are circumstances where individuals can commit violations of domestic antiterrorism statutes through their Internet activity aloneppThe Internet is a platform like any other where virtually any kind of crime that can be committed in the real world can also be committed online he said That doesnt mean all misuse of computers fits within the statutory definition of terrorismppThe RCMPs advisory on sexual extortion of minors over the Internet lists a number of potential warning signs that teens may exhibit if they become entangled in these harm groups The FBI urges anyone who believes their child or someone they know is being exploited to contact their local FBI field office call 1800CALLFBI or report it online at tipsfbigovpp
This entry was posted on Friday 13th of September 2024 0816 AM
ppHello Brian Id like to contact you regarding inside information relating to this Can you leave a form or contactppYes there is a contact form here pphttpskrebsonsecuritycomaboutppMy email address is also linked at the bottomppExcellent journalism as usual KrebsppThank you Wassil This is the result of much research over the last six months at least but weve been tracking a few of these actors for yearsppWonder if they could get some of these internet terrorists interrorist on RICO
Seems like they are conspiring to do bad things to people and companies Would that put more teeth into the charges and sentencesppThe idea with RICO is charging everyone involved in x org with a default sentence for conspiracyfraud One trial vs multiple individual trials That may or may not make sense of course individual trials certainly could consume more judicial resources overall but its not the only consideration re actually proving your case in court I believe the CFAA penalty is the same and individually applied it leaves room for more serious charges for individuals involved in the things beyond just hacking as described in the article threats menacing blackmail solicitation murder whatever it is Most members of the groups do not seem to have been involved in all of those aspects directly Certainly prosecutors will consider all details in deciding how to charge it for their reasonsppAll the new kids joining the underground after the pandemic are disgusting sex offenders that deserve to go to Guantanamo Bay Make hacking great again Fuck 764ppPreying on children for LOLz How sad and disgusting IMHO As with some of our political figures sometimes when I think Ive hit bottom with humanity you realize there is no bottom and that feeling of hitting something was just the shock wave of going supersonic as you fallppdont worry the bottom is muerte and like fire it can never be quenched by more idiots willig to run
to itppi have more backstory for you on this waifu character he was also known as cj or morningstar from an HCF group called criminal and who lived somewhere around toronto metro gta he was known as being best friends with that kayte person and another guy named austin who owned that criminal domain after someone from moneyteam called callan sold it to him for their hcf group for 5k i can send you an email with even more intel if youd like but id imagine you already know most of thisppCJ is the one from moneyteamdatawagon and Callan is a CUCK waifuppWait THAT CJ Krebs has written about him in the past hes been a nuisance for a very long time Even 8 years ago I knew him as yet another script kiddie who would log IPs via hackforums image embed signatures DDoS them as well as steal CSGO itemsppNo its a detraceppTrue waifu is actually janit0r aka Wicked and was friends with Ankit Anubhav the fireeye employeeppim interested on hearing more about thisppSwatting should be prosecuted as attempted murder not a technological prank as it has already led to people being killedppChild porn is especially insideous because it involves actual children being molested or worse Possession of child porn needs to be punished much more severelyppAIdeepfakes should have been banned as soon as it became a thing The MSM was apoplectic over deepfake nudes of Taylor Swift but everyday victims are far more numerous and vulnerableppThe dark webs disadvantages outweigh its advantages Eliminate itppAnother good post by Brian KrebsppI agree with what you say about swatting and think LE should also be held accountable Theyre too quick on the trigger LiterallyppMMMUUUUH THE CURRENT BAD THING IS BAD ELIMINATE IT
Typical comment written on emotions
suitcase wagon redditppThe security firm CrowdStrike
I vaguely remember a fascinating happening featuring this security firm which made a blast a month ago or soppBrian Thank you so much for exposing my best friend on the planets adress I have been searching for years now I can finally visit KT in Pearl harbor or whatever its called I looked up the locations and there is a cool Amusement park called The Big Banana Fun Park I cant wait to invite him for a lovely day outppThe name Judische is German for Jewish Its pronounced YOU dish uhppYoure antisemistic I bet u hoholppactually it is more a bumpy translation jüdische with Umlaut would be the adjective for someone or something female as in the jewish woman or the jewish newspaper The correct generic German adjective is jüdisch still needs the Umlaut of course Used as a name tag it seems to me someone found the German word cool or whatever and only halfway remembered it hence the justslightlywrong typingppNobody cares about umlautsppAs someone who in their early teens was involved in the scene which later grew to be the com and later on became a researcher in right wing extremism its been pretty sad these past few years seeing the two increasingly blur together While the scene was definitely god awful back then as well it wasnt riddled with the disgusting O9A stuff which really brought it closer to producing hurtcore contentppsounds to me like youre a skidppsounds like youre a yahudi death to israelppDear KenppIm in pieces why the cold shoulderppLove BarbieppI hate to be the one to bring you the news Barbie Hes with Adam and SteveppThe funniest part of all of this is that the law cant have ANY exceptions made at all
That 17 year old Hes been arrested twice and released after brief questioning No sir I did not do this I have an alibi and youre home free to do more cybercrime for a few more months till youre of age
Same deal with Arion but the difference with him is that he managed to convince the government that hes special needs but right after hes done pretending to drool all over himself in some institution hes coming home to a trove of terabytes of data on some locked up S3 bucket as well as potentially still millions of money hes stolen Even 3 year old data still has extortion valueppSpecial needs alrightppNeeds to be in prisonppWtf did I just see kt at the hoey moeyppMight be funny andor interesting for you
httpswwwchangeorgpfreeuppompompurinppI already flagged that as spam but you might want to claim identity theft there too
Youre obviously often the target of such shenanigansppGreat reporting Krebs Sincere thankspp4200 IDK to each their own I guessppPlease expose Flar Hes the most vile sextorterppI didnt understand everything in that mind map dump but now I am certain Krebs is not and cannot be replaced by an AIppI see that Conor Brian Fitzpatrick pled guilty but received no jail time Just supervised release and has been ordered to refrain from using the internet for one yearppThatll show emppComments are closedppMailing ListppSearch KrebsOnSecurityppRecent PostsppStory CategoriesppWhy So Many Top Hackers Hail from Russiap