Showing posts with label Hack. Show all posts
Showing posts with label Hack. Show all posts

Thursday, August 10, 2017

Russian Hacker Sentenced To 4 Years in Prison For Spreading Linux Malware

Russian Hacker Sentenced To 4 Years in Prison For Spreading Linux Malware

Hacker in Action
A Russian man accused of infecting tens of thousands of computer servers worldwide to generate millions in fraudulent payments has been imprisoned for 46 months (nearly four years) in a United States' federal prison.

41-year-old Maxim Senakh, of Velikii Novgorod, was arrested by Finnish police in August 2015 for his role in the development and maintenance of the infamous Linux botnet called Ebury that siphoned millions of dollars from victims worldwide.

Senakh was extradited to the United States in February 2016 to face charges and pleaded guilty in late March this year after admitting of creating a massive Ebury botnet and personally being profited from the scheme.

First spotted in 2011, Ebury is an SSH backdoor Trojan for Linux and Unix-style operating systems, such as FreeBSD or Solaris, which gives attackers full shell control of an infected machine remotely even if the password for affected user account is changed regularly.

Senakh and his associates used the malware to build an Ebury botnet network of thousands of compromised Linux systems, which had the capacity of sending over 35 million spam messages and redirecting more than 500,000 online visitors to exploit kits every day.

Senakh fraudulently generated millions of dollars in revenue running spam campaigns and committing advertising click frauds.

Working within a massive criminal enterprise, Maxim Senakh helped create a sophisticated infrastructure that victimized thousands of Internet users across the world," said Acting U.S. Attorney Brooker.
"As society becomes more reliant on computers, cyber criminals like Senakh pose a serious threat. This Office, along with our law enforcement partners, is committed to detecting and prosecuting cyber criminals no matter where they reside.


Ebury first came into headlines in 2011 after Donald Ryan Austin, 27, of El Portal, Florida, installed the Trojan on multiple servers owned by kernel.org and the Linux Foundation, which maintain and distribute the Linux operating system kernel.

Austin, with no connection to the Ebury criminal gang, was arrested in September last year and was charged with 4 counts of intentional transmission causing damage to a protected computer.

Senakh was facing up to a combined 30 years in prison, after pleading guilty to conspiracy to commit wire fraud as well as violate the Computer Fraud and Abuse Act.

However, a US judge on Thursday sentenced Senakh to 46 months in prison, the Department of Justice announced on Thursday. The case was investigated by the Federal Bureau of Investigation's field office in Minneapolis.

Senakh will be deported back to Russia following his release from the U.S. prison

Monday, July 31, 2017

How Hackers Cash Out Massive Bitcoins Received From Ransomware Attacks

How Hackers Cash Out Massive Bitcoins Received From Ransomware Attacks

Hacker in action
Digital currencies have emerged as a favourite tool for hackers and cyber criminals, as digital currency transactions are nearly anonymous, allowing cyber criminals to use it in underground markets for illegal trading, and to receive thousands of dollars in ransomware attacks—WannaCry, Petya, LeakerLocker, Locky and Cerber to name a few.

Also, every other day we hear about some incidents of hacking of crypto currency exchange or digital wallets, in which hackers stole millions of dollars in Bitcoin or Ethereum.

The latest back-to-back series of thefts of Ethereum—one of the most popular and increasingly valuable cryptocurrencies—in which around half a billion dollars in total were stolen is the recent example of how much hackers are after crypto currencies.

It's obvious that after ripping off hundreds of thousands of cryptocurrencies from exchanges, wallets and ransomware victims, cyber criminals would not hold them in just digital form—the next step is to cash them out into real-world money.

But how do they cash out without getting caught by law enforcement?

If you are unaware, there are some crypto currency exchanges involved in money laundering, who are illegally-operating to help hackers and cyber criminals easily cash out their digital currencies without identifying them, i.e. anonymously.

According to a recent research paper presented by three Google researchers, more than 95% of all Bitcoin payments collected from ransomware victims have been cashed out via a Russian cryptocurrency exchange, called BTC-e, since 2014.

Interestingly, just two days before Google presentation, one of the founders of BTC-e exchange, Alexander Vinnik, was arrested by Greek police on charges of laundering over $4 Billion in Bitcoin for culprits.

We uncover the cash-out points, tracking how the money exits the Bitcoin network, enabling the authorities to pick up the money trail using conventional financial tracing means,

the trio researchers, Luca Invernizzi, Kylie McRoberts and Elie Bursztein said.

Key Points — Tracking Ransomware Payments

The researchers followed the step-by-step money trail and got a look at the evolving ecosystem of ransomware families, which already helped make cyber-thieves at least $25 Million in the last two years.

✔ Most Damaging Ransomware Families: According to the research, two families of ransomware strain helped hackers made most of the money — Locky and Cerber — while other variants are also starting to emerge.

✔ Criminals looted In Millions: Locky has been the overall biggest earner for hackers at $7.8 Million and was the first ransomware infection to earn above $1 million a month to date, while Cerber has made $6.9 million to date with consistently making more than $200,000 a month.

✔ Victim's Favorite Places to Buy Bitcoins : Obviously, victims also need BTC to pay out criminals, and most victims choose LocalBitcoins, Bithumb, and CoinBase to buy BTC, where 90% victims pay in a single transaction.

✔ How Criminals Cash Out Cryptocurrency : According to the research, more than 95% of all Bitcoin payments for ransomware were cashed out via BTC-e, a service operational since 2011.

✔ Criminals Renting Out Botnets: Cybercriminal gangs behind Dridex, Locky and Cerber have taken Necurs botnet—army of compromised machines—on rent to distribute their ransomware infections on a massive scale.

Google conducted the research in collaboration with the researchers from New York University, University of California San Diego and blockchain analyst firm Chainalysis.

When talking about BTC-e, the cryptocurrency exchange is believed to have been involved in cashing out Bitcoins stolen from the once-very popular Japanese bitcoin exchange Mt. Gox, which was shut down in 2014 following a massive series of mysterious robberies.

Source: thehackersnew.com

Sunday, July 30, 2017

U.S. Army Teaching Kids Hacking At DEF CON

U.S. Army Teaching Kids Hacking At DEF CON

U.S. Army
The U.S. Army in partnership with the security firm Synack is teaching these children “white hat,” or ethical hacking skills, says Daniel Lim, first lieutenant of the U.S. Army Cyber Command, who is leading the workshop.

“We’ll be teaching basic exploitation using open source tools and basic command line tools,” Lim said. “This is designed for complete beginners.”

The training is similar to what the Army teaches its soldiers at the U.S. Army Cyber School, where Lim was an instructor.

Eventually, some of these kids might one day hack the government. And that’s a good thing.

To bolster its cyber defenses, the Army and other government agencies try to penetrate their own systems through hacking. But the talent pool needs to grow.

It’s expected that there will be a job shortage of almost 2 million cybersecurity professionals by 2022. This event can help train the next generation of cybersecurity experts who will help keep companies, people, and even the country safe.

At least one of these kids is already leading the effort.

A 16-year-old known as Gadget Girl is practically a veteran of DEF CON hacking events. She volunteered at the Las Vegas r00tz Asylum event this week, teaching kids of all ages programming and 3D-printing skills.

Gadget Girl, who prefers to use the pseudonym instead of her real name, says one of the most beneficial parts of the conference is learning from security experts about the opportunities to put technical skills to real world use — both creatively and professionally.

More than half of the attendees come to DEF CON just for the r00tz Asylum kids program, asking their parents to spend summer vacation in a packed meeting room in the Caesars Palace hotel.

Last year, 500 kids showed up, said Nico Sell, founder and CEO of the secure messaging app Wickr.

She created r00tz Asylum event seven years ago.

The event starts by explaining the ethics code, and kids are taught to understand what type of hacking they can and can’t legally, and ethically do.

While it might seem weird to those unfamiliar with hacking conferences to have government representatives speak to and work with the hackers, Sell said the government is an important part of the community.

“Feds are people, too,” Sell said. “They’re hackers at the core.”
One year, the NSA hosted a recruiting booth right next to the Electronic Frontier Foundation, a privacy advocacy group.

Sell said that despite their differences, one thing everyone can agree on is that teaching kids to hack is one of the most important things the security community can do.