Showing posts with label Anonymous. Show all posts
Showing posts with label Anonymous. Show all posts

Friday, September 09, 2016

More "Crackas With Attitude" hackers arrested

The Department of Justice has announced the arrest of two North Carolina based members of the group "Crackas With Attitude" who famously broke into the AOL email account of CIA Director John Brennan and the Verizon account of Director of National Intelligence James Clapper last year.

Motherboard on Crackas With Attitude #CWA

Often hackers will find a sympathetic listening ear in the form of a journalist, and the original bad boy of CWA did so with Lorenzo Franceschi-Bicchierai, who writes for Motherboard at Vice.com.
Lorenzo's headlines about CWA tell the timeline of the case:
  • Teen Hackers: A '5-year-old' Could Have Hacked into CIA Director's Emails 
  • Alleged Hacker Behind John Brennan Email Breach: 'I Don't Want to go to Jail'
  • Teen Hackers Who Doxed CIA Chief Are Targeting More Government Officials 
  • Teenage Hackers Say They've Doxed More Than 2,000 Government Employees
  • The Dox of More than 2,300 Government Employees Might Be Worse Than We Thought
  • Teenage Hackers Return With New List of Government Employees
  • The FBI is Worried About Hacktivists Targeting Politicians and Cops
  • Teen Who Hacked CIA Email Is Back to Prank US Spy Chief
  • Teen Hacker Claims Another Victim in Campaign Against Government
  • Teens Who Hacked CIA Director Also Hit White House Official
  • Hackers Dox Miami Police Officers with Data Stolen from Government Database
  • Hacker Published Personal Info of 20,000 FBI Agents
  • Teen Allegedly Behind CIA, FBI Breaches: "They're Trying to Ruin My Life."
  • Teenage Hackers Promise More Government Hacks After Alleged Leader's Arrest
  • No One's Emails Are Safe, Says CIA Director Who Got Hacked
  • Police Arrest Second Alleged Member of Teen Group that Hacked CIA Director
  •  
All of the articles above can be found by using the Motherboard tag "Crackas With Attitude"
And then, finally, this one:

FBI Arrest Two Alleged Members of Group That Hacked the CIA Director

The Arrest of @Incursio and @_D3f4ult (Andrew Boggs and Justin Liverman)


The two Americans who were arrested were Andrew Otto Boggs, 22, from North Wilkesboro, North Carolina, who is behind the online moniker Incursio and Justin Gray Liverman, 24, from Morehead City, North Carolina, who is behind the online moniker @_D3F4ULT.

Like many hackers, Boggs and Liverman both lived with their parents.  In fact, Boggs was arrested because Twitter records showed that he created and frequently logged in from one of his several #CWA Twitter accounts, @GenuinelySpooky, from a Charter Communications IP address that subscriber records revealed was his father's home, where he lived.   Exactly the same thing happened to Liverman, who used the Twitter account @_D3F4ULT from an Time Warner Cable IP address that was registered to his mother, Edith Liverman, with whom he was living at the time.

While Twitter "private messages" are not revealed to the public at large, they still contained pretty damning information.  The 37 page criminal complaint, an affidavit prepared by a thorough FBI agent, reveals that the two adult Americans were participating in this conspiracy with three British teenagers who were known as CRACKA (AKA @PORNG0D, @PHPHAX, @DICKREJECT), who was 17 years old, DERP (AKA @DERPLAUGHING) also 17, and CUBED (AKA @FRUITYHAX) who was 15 years old.   The other three have all been identified and apprehended in the United Kingdom, where their identities are protected due to their minor status.

In addition to @_D3F4ULT, Liverman used the handles @BASHTIEN_ and @SH1N0D4.
Boggs also used the identities @INCURSIOSUBTER and @GENUINELYSPOOKY.

Social Engineering the Law Enforcement Enterprise Portal (LEEP)

While the affidavit refers to "Victim 1" and "Victim 2", public reporting about these accounts make it clear that Victim 1 is CIA Director John Brennan and Victim 2 is FBI Deputy Director Mark Giuliano.  The affidavit explains that "In or about November 2015" the hackers used Victim 2's credentials to log in to the Law Enforcement Enterprise Portal.  LEEP is a Very Big Deal, because it has information to basically everything about federal law enforcement, including directories of law enforcement officers who have been granted access to the system to enhance their state and local policing capabilities.  The Joint Automated Booking System (JABS), the Internet Crime Complaint Center (IC3.gov) and the Virtual Command Center/Special Interest Group can all be access through LEEP.   Imagine that! Cybercriminals with full unlimited access to the details of every cybercrime complaint that has been made to the Internet Crime Complaint Center!

But that isn't how they used the information.
 
On November 4, 2015, Cracka sent a screen shot of the LEEP computer system login page, showing that he was logged in to Giuliano's account.  When Liverman asked what type of information was there, Cracka replied "every law enforcement info.  fucking shaking."   Liverman replied "holy fucking shittttttt."  Liverman then asks Cracka to search by state/city and requested the list of officers in Miami, which Cracka sent via Jabber message at 18:43 EST that evening.  This is the list of 80 Miami-area officers that was blasted out as their first LEET related "doxing."  The list was found on Liverman's hard drive, pursuant to a lawful search warrant, in a file named "miami_officers.txt".

The following day, Cracka posted links from his @PHPHAX twitter account to copies of the records for Jeremy Hammond (a hacker who participated in the Anonymous movement) that had been obtained through JABS.  He tied this event to November 5th, the date associated with the Anonymous/Guy Fawkes chant "Remember, remember, the fifth of November", a date associated with anti-government actions due to the Gunpowder Treason in 1605, when Guy Fawkes and others attempted to blow up the House of Lords.

In January 2016, they posted publicly the names, work telephone numbers, emails, and titles of 80 police officers in the Miami area, dumped from the LEEP system back in November.

After being locked out of the LEEP system, the hackers tried repeatedly to social engineer their way back in.  The FBI has recordings of 34 calls placed to the LEEP help desk and 56 calls placed to the CJIS (Criminal Justice Information System) help desk attempting to regain acess to the system.

Charges Against CWA Hackers

a. 18 USC § 912 - falsely assuming or pretending to be an officer or employee of the US Government to obtain money, paper, documents, or any thing of value

b. 18 USC § 1028A - knowingly transfering, possessing, or using without lawful authority a means of identification of another person during and in relation to the commission of a felony

c. 18 USC § 1030(a)(2)(B) - intentionally accessing a computer without authorization or exceeding authorized access to obtain information from any department or agency of the US Government

d. 18 USC § 1030(a)(2)(C) - intentionally accessing a computer without authorization or exceeding authorized access to obtain information from a protected computer

e. 18 USC § 1030(a)(3) - intentionally without authorization accessing a nonpublic computer of the United States that is exclusively for the use of the Government of the United States

f. 18 USC § 1038 - engaging in conduct with the intent to convey false or misleading information where such information may reasonably be believed that activity has taken, is taking, or will take place that would constitute a violation of chapter 40 of Title 18 (18 USC 40 is about explosives - so this is about making a bomb threat)

g. 47 USC § 223 - making a telephone call intented to abuse, threaten or harass any specific person without disclosing identity.

A Look Into Motivations

Here's an interesting example exchange between Boggs (@Genuinelyspooky) and Cracka (@PHPHax):

+++++++++++++++

@GenuinelySpooky: I'm going to help you with 0wning the [agency where Victim #1 worked]. I've been looking for evidence of aliens since Gary.

@PHPHax:  i fucking own this loser, i have just released emails of them admitting to torture.

@GenuinelySpooky: If you need any publishing done, let me know.  I'll go Charlotte and use public wifi to publish the stolen information.

@PHPHax:  that sounds great :)
++++++++++++++++

Really?  The reference to Gary is to Gary McKinnon, the UFO conspiracy theorist who was arrested for hacking NASA.  He has posted many things on social media claiming that while in the NASA systems he found "proof" that NASA knows all about the aliens living among us.

Cracka broke into John Brennan's account by calling Verizon technical support, impersonating a Verizon employee, and getting them to share certain information, including the last four digits of the credit card being used to pay the Verizon bill.  He then used that information in a call to AOL to convince them he was Brennan and get them to reset the AOL password.  WIRED tells more of that story in "Teen Who Hacked CIA Director's Email Tells How He Did It".

Cracka was thrilled with the publicity he was getting, boasting about his interview with the New York Times about the Brennan hack via Twitter direct messages with Boggs.

Cracka told Liverman about his access to the FBI Deputy Director's account, including the last four digits of his Social Security Number, access to his Comcast account and other information, including a screen shot of the Comcast billing information. Cracka revealed to Liverman that the Comcast account contained an address book with at least 200 contacts, including many government people.  Several of these screen shots were posted to a Facebook account using the name "Joseph Markowicz" that was registered using the same email address as the Twitter account @_D3F4ULT.  On several occasions, the same proxy IP address was used to access both the Twitter account and the Facebook account in close succession.   The Comcast details also provided the hackers with detailed call logs, showing who the FBI Deputy Director called and on what numbers.  By calling several of these telephone numbers, they were able to locate the government cell phone number of the FBI DD.  They paid $20 to launch a "phone-bombing" attack against the number, which caused anonymized calls to be placed to the phone every hour for thirty consecutive days.

They also sent insulting and threatening text messages to the cell phone, including one (using the redacting from the affidavit:

   "Listen here you fucking boomer, we will destroy your reputation.  Just like [two senior US government officials, including Victim 1]...I guess you couldn't handle us jacking your Comcast ISP accounts too many times so you actually canceled your account!  And telling me to 'watch my back' wasn't a good idea lol.  How is your [derogatory comment][incorrect spouse name]? We will keep a close eye on your family, especially your son!"

Liverman made a Bandicam (video screen capture recording software) video of himself creating a dark market account in Giuliano's name on the Abraxas Market (where drugs are often sold using Bitcoin.)  He also posted Facebook messages to many accounts inviting "sexy nudes" to be sent to the FBI-owned cell phone number and tweeted the same from the @_D3F4ULT account.

Ridiculing Federal government authorities and insulting them and their family members was part of the motivation.  The fact that the very first thing that crosses their minds when they had full access to every criminal record in the United States was to search for information about the arrested Anonymous hacker Jeremy Hammond helps to cast this as an "Us versus Them" battle between hackers and the U.S. Government.

DOJ Civil Division information

On February 3, 2016, Cracka and Liverman had a Jabber chat where Cracka reveals:

"...i owned the entire doj. like, all doj agencies so fbi, dea, Interpol, dhs.  i'm sitting here with 20k fbi employee names, country, email, phone number, title.  i have access to a doj computer"

As proof, Cracka shared screenshots of this with Liverman.

Tweets related to this data started showing up on January 30, 2016, when @DOTGOVS tweeted "9,000 @DHSGov employees." with a partial screenshot of personnel information.  About twenty minutes later the same account tweeted "Why do we have 20,000 @FBI employees: names, phone numbers, countries, and emails? Including ones abroad :)."

While this information is not supposed to be publicly available via the Internet, the DOJ Justice Security Operations Center determined that the DOJ Civil Division help desk had been socially engineered to provide a contract employee's credentials.  These credentials were used multiple times between Jan 27, 2016 and Feb 2, 2016 to access the CIMS (Case Information Management System)  application.

On February 7, @DOTGOVS tweeted links to the website "cryptobin.org" providing a password for decrypting the files, which included the 9,000 DHS.gov employees information and the 20,000 FBI employees' information.

Several members of the conspiracy became involved with propagating these materials, sharing the information on Pastebin, Ghostbin, IndyBay and other locations.  While it seems the 17-year old "Cracka" was the primary person to infiltrate the DOJ systems, the others were certainly encouraging such activity, asking for custom searches within the data, and gleeful in their attempts to help leak sensitive government information to the public through their repeated posts and reposts of the information.










Monday, August 12, 2013

Anonymous, #OpBankster, and the Too Many Nancy's Problem

The current Anonymous "#OpBanksters" seems to have very little in common with the original operation by the Anonymous Portuguese group that was originally posted on YouTube back on April 14, 2013. However, the beginning of the current round started with an August 8th post by @AnonLegionPT (Anonymous Legion PT) inviting people to view the original video and then log on to AnonNet and join the "#opbanksters" chat room on Friday the 9th at 10 PM to discuss.

www.youtube.com/watch?v=9ZdMlgnvaqQ&feature=youtu.be

While we don't know what happened in the chat room, the result was that we began to see posts on PasteBin listing the email addresses and internet-facing IP addresses and hostnames of Portuguese banks.

An English translation of the Portuguese video reads:


Published on Apr 14, 2013

Greetings. We are Anonymous Portugal and this is the # banksters operation, a protest action against banks around the world, who have created a corrupt financial system based on debt-interest, speculation large sums with large multinationals and made the money a lucrative business that benefits a minority, but enslaves the rest of the population.

Banks extend credit to slashing with money created out of thin air, causing a snowball effect on the shortcomings of the banking system relative to the overall debt. With this system, banks enrich immeasurably, pay low interest on that deposit and charge high interest loans they make.

With this system of interest, speculation of the value of money and inflated product, it is easy to see where they come from debt, not only of companies and governments, but also emerge as the personal debt of each family. For years, banks eased lending by attracting people with the illusion of being able to have great purchasing power by easy access to money, and creating a debt trap from which many now can not get out. The social stratification, poverty, hunger and unemployment are therefore a consequence of the existing financial system, fatalities that may not disappear while this persists.

Banks in Portugal receive 8 billion state budget since 1999, are recapitalized with $ 12 billion in 2012 and are still saying that the people are having to endure? Portuguese people must know the true and the real gangsters responsible for the crisis, beyond the state. # OpBanksters: Portuguese and international banks, your time has come!

We are Anonymous!
We are Legion!
We do not forgive!
We do not forget!
Expect us!


While the original Twitter posts this week WERE from Anonymous Portugal, and the original PasteBin posts were also about Portuguese bank Credito Agricola, the Op quickly grew beyond its original intention of punishing Portuguese banks for being poor custodians of public funds.

The first three banks posted to the Operation's PasteBin page were:
Banco dos Espiritos Santos (BES) Portugal (110 emails / 62 hosts)
CreditoAgricola Portugal (136 emails)
and BBVA Portugal/Spain

On August 10th, with the exception of the European banking Authority (europa.eu) only Portuguese banks had their employee email addresses and hosts listed, including:

Cetelem PT
Credibom PT
Cofidis PT
Montepio PT
Banif PT
Bancobic PT
Banco BPI PT
Millennium BCP PT
Banco Popular PT/ES

On August 11th the information disclosure activity spread beyond the borders of Portugal.

Bank of America
Barclays
Lincoln State Bank
Deutsche Bank AG US
Dun & Bradstreet
FDIC
Federal Mortage Association
Federal Reserve Banks of Atlanta, New York, Richmond, and San Francisco
Fitch Rating
Goldman Sachs
Hartford Financial
Huntington Bank
Imperial Bank of Canada
London Stock Exchange

On August 12th (so far) we have seen added:

Moody's
Nasdaq
National Australian Bank
PNC
Royal Bank of Canada
Standard & Poors
SunTrust
M&T Bank
Royal Bank of Scotland
TD (Toronto Dominion)
Union Bank
Wall Street Insurance
Wall Street Journal
Citibank
JP Morgan Chase
Zurich Financial
were all added to the list. In the case of Bank of America, as one extreme example, more than 3700 named employees, with titles and emails, were listed.

At that point, we thought there may be a major problem with email-based security about to be unleashed!

As I discussed on Hacker HotShots this week, the Verizon Data Breach Investigations Report quotes "ThreatSim.com" as saying that when a hostile email is sent to three employees of an organization, there is a 50% chance that someone will click on it, but when an email is sent to TEN employees, there is nearly a "Guarantee" that someone will click on it! I couldn't imagine how bad things could go if 3700 employees were being targeted by hand-crafted malicious emails!

That seemed to be the what was happening already in Portugal, as we began to see defacements appear, such as this one hosted on the website "www.cie.com.pt" which is the "Centro de Intervenção Empresarial" showing "#opBankster" branded defacements:

The Anonymous Portugal Blog is here:

anonymouspt.blogspot.com/2013/08/op-banksters-part-ii.html

Their Facebook page is here:

https://www.facebook.com/AnonymousLegionPt

They claim to have successfullly DDOSed:

www.complemento-vintage.pt
www.lusonegocio.com
www.credibom.pt
www.flexibom.pt
www.cofidis.pt
www.cetelem.pt
and have confirmed that they are behind the PasteBin handle "#opBanksters"

The Too Many Nancy's Problem

As I started looking through the list of so many leaked addresses for all of these North American banks, I realized there might be a problem. The naming convention for each of the banks was "First Name, Last Initial" @ domain.com, so if I were on the lists, Gary Warner, my email would be given as "garyw@zurichna.com" or "garyw@frbatlanta.org" or "garyw@tdbank.ca". Obviously there would be collisions if that were the case, but I didn't see any attempt to avoid them. I also correspond regularly with many of the brands attacked, and realized that in many cases the domain listed is NOT the domain name where individuals who work for that organization receive their emails.

I decided to do a frequency distribution on the first names and look for "over-represented" names that seemed unlikely to me. I won't go into all the details here, but I looked at female first names from the 1990 US Census and compared them to distributions here. (A 1990 census person would be at least 23, so may be well represented in the work force. Anyone older than 23 would also be listed in the 1990 census, so it seemed as good a source as any.

MARY           2.629  2.629      1
PATRICIA       1.073  3.702      2
LINDA          1.035  4.736      3
BARBARA        0.980  5.716      4
ELIZABETH      0.937  6.653      5
JENNIFER       0.932  7.586      6
MARIA          0.828  8.414      7
SUSAN          0.794  9.209      8
MARGARET       0.768  9.976      9
DOROTHY        0.727 10.703     10
LISA           0.704 11.407     11
NANCY          0.669 12.075     12
On the first file I reviewed, I had, instead of the distribution above:
6 Mary's
1 Patricia
10 Linda's
7 Barbara's
9 Elizabeth's
14 Jennifer's
5 Maria's
7 Susan's
3 Margaret's
2 Dorothy's
6 Lisa's 
14 Nancy's
Now that may not be the most scientific of comparisons, but as a genealogist, I was confident I was dealing with TOO MANY NANCY'S!

Focusing in on the Nancy's the problem really started showing up. In each of the bank email lists I reviewed, the distribution of names was wildly out of line, and for popular names included many duplicate email addresses that would further confirm these were fakes. For example, just at Toronto Dominion, we had people with the email address "nancym@tdbank.ca" in the following positions and locations:

nancym@tdbank.ca == A Financial Planner in Richmand Hill, Ontario
nancym@tdbank.ca == A Merchant Risk Analyst II in Lewiston, Maine
nancym@tdbank.ca == A Recruitment manager in Toronto, Ontario
nancym@tdbank.ca == A Senior Compliance Officer in Hagersville, Ontario

Malcovery Security specializes in dealing with Email-based threat intelligence. We've got some great ideas for dealing with this current situation. Please reach out to us if you'd like to discuss.