Showing posts with label spam. Show all posts
Showing posts with label spam. Show all posts

Monday, September 22, 2025

Microsoft DCU's Takedown of RaccoonO365

 When I saw the name of the Microsoft Digital Crime Unit's latest target, "RaccoonO365" I probably reacted to it differently than most.  With the help of a friend in Lagos, we've been watching the money launderers and things have reached a point that they now refer to what we previously called "Business Email Compromise" or BEC as "O365 Jobs." 

from Microsoft's explainer on RaccoonO365

Microsoft DCU is famous for doing massive takedowns of the infrastructure used by cyber criminals via Civil action in the US courts.  This case is no different, as they filed for an Emergency Temporary Restraining Order in the Southern District of New York in a co-filing with the Health-ISAC.  The venue is justified in their filing in part by showing that New York City was one of the most targeted cities, based on victims that they were able to identify. 


From Microsoft DCU's "Complaint and Summons" against Joshua Ogundipe and John Does 1-4

Microsoft used several methods of determining that Joshua Ogundipe of Nigeria played a key role in this Phishing-as-a-Service enterprise, which began in the summer of 2024 after Microsoft had terminated a similar platform called Fake ONNX. 

A great deal of the infrastructure for RaccoonO365 was hidden behind Cloudflare's Reverse Proxy service and/or using Cloudflare's Domain Registration service, and Microsoft was able to determine that Joshua controlled the associated Cloudflare accounts. 

Microsoft also reveals the LinkedIn account of Joshua Ogundipe, which displays the logo of DIGIhubng and indicates that he lives in Benin City, Edo State, Nigeria. Yet another criminal who works for a company that claims to teach "Ethical Hacking"  ... 

Microsoft demonstrates Josha Ogundipe's LinkedIn Page


Digihubng's Ethical Hacking courses

DigihubNG, formerly "Simple Hacks Workshop" -- "Learn How Hackers Create a fake login page and use it to steal passwords

Microsoft & Health-ISAC's Interest in RaccoonO365

The Complaint filed by Microsoft and Health-ISAC, says that "at least 25 healthcare companies, including 9 organizations who are members of Health-ISAC have been hit by RaccoonO365 phishing kits."  In some cases the phishing emails were detected and blocked, while in other cases an employee fell victim to the phish, sharing their credentials to the criminal, however the organizations responded swiftly with password resets for those individuals. 

Microsoft and Health-ISAC charge that the following violations were performed by the RaccoonO365 co-conspirators, harming both organizations and their customers and members.

Count I: Violation of the Computer Fraud and Abuse Act, 18 USC § 1030. 
Count II: Racketeer Influenced and Corrupt Organizations Act, 18 USC § 1962. 
Count III: Conspiracy to Violate RICO, 18 USC § 1962(d). 
Count IV: Violation of Electronic Communications Privacy Act, 18 USC § 2701. 
Count V: (Microsoft only): False Designation of Origin under the Lanham Act, 15 USC § 1125(a). 
Count VI: (Microsoft only): Trademark Infringement Under the Lanham Act, 15 USC § 1114 et seq. 
Count VII: (Microsoft only): Trademark Dilution under the Lanham Act, 15 USC § 1125(c). 
Count VIII: Common Law Trespass to Chattels. 
Count IX: Conversion.
Count X: Unjust Enrichment. 

RaccoonO365 Crypto Addresses

When Microsoft made a test purchase by interacting with the "RaccoonO365" admin on Telegram, they were provided a Bitcoin address, bc1qmlsuqm4p6lme8e2qna3mkj07k8j7vttp0l7ydv, to make their payment.  That address is hosted at the Nigerian cryptocurrency exchange Bitnob.com, and had received deposits 132 times between October 16, 2024 and July 1, 2025, totaling just under $34,000. 

Cloudflare's "Cloudforce One" team also published a list of Indicators of Compromise for RaccoonO365.  They share a different Bitcoin address, bc1qjtlzug5wu7ag8yskn5h2xjd27uetq5cc4sahh5, which went live on July 3, 2025 and received payments through September 13, 2025.  An ERC20 address, also received $2800 between May 7, 2025 and August 29, 2025 (0xf5C2E3749F332175D94C7de7bf7AA8d679E460B7).  The USDT address, TBB5T28b9n2SK8shXb9oq867EcsNE5dZie, also went live the first week of July and received $7,448 through September 12, 2025. Those funds flow to a ChipperCash account, which has more than 5 million downloads in the Google Play Store. The animation on their home page shows people in the United States sending funds to people in Nigeria. 

Cloudflare's IOC list also provided a list of "EDF" - Email Detection Fingerprints - that mention several campaigns including a Maersk phishing campaign, a Zoom-branded phishing campaign, and campaigns imitating DocuSign, Sharepoint, and Adobe. 

The CloudForce One RaccoonO365 report is certainly worth reading in its entirety. They include a  pricing list from the Telegram channel showing the subscription plan rates from 30 days ($355) to 90 days ($999). 



The Taxman Spammeth 

During the 2025 US Tax Season, Microsoft put out an advisory that RaccoonO365 phishers, who are tracked within Microsoft as "Storm-0249", were delivering IRS-themed tax phish that were resulting in malware infections.  The Tax phish, claiming to be from the "IRS Audit Department," was linking to a fake Docusign website that asked the recipient to download and review "IRS Verification Form-2025." 

The same advisory warned that between February 12th and 28th, Microsoft observed at least 2,300 organizations targeted by another RaccoonO365 IRS-themed campaign.  This one had a PDF document that contained a QR-code.  Scanning the QR code forwarded the recipient to "SharedDocumentsO365CloudAuthStorage[.]com" which presented a fake Microsoft login page in an attempt to steal user credentials and cookies. 

From the Microsoft Tax Phishing report

RaccoonO365 Domain Registration Insights

Both Microsoft and Cloudflare provide longs lists of domains used by the RaccoonO365 phishers, many of which share gmail or yahoo email accounts for the registrants. Some of the R-O365 customer clearly have targets within a certain demographic when we look for other domains registered with the same email address.  A few examples: 

"Nawty Boss" is the name used by edmblais@gmail.com.  Some of the domains created by Mr. Boss indicate that he is a long-time Microsoft phisher, who targets law firms and "conveyancing" companies. He registered a clear Microsoft-targeting phishing domain owa-outlookaccess-login[.]us - all the way back on August 8, 2022, but during the time period of R-O365, some of his domains include: 

prioritylegals[.]com
bytheruleslegal[.]com 
bandhlawyers[.]com 
oconnorharis[.]com 
proctorgraham[.]com 
shamonlawyers[.]com 
aslegals[.]com 
boylandlawyers[.]com 
1836conveyancing[.]com 
crystalconveyancing[.]com
nestconveyancing[.]com 
raywardconveyancing[.]com 
keysconveyancing[.]com and many more - at least 27 domains! 

Cheryl Sharp is the name used by oodybugs53@gmail.com to register several construction-themed companies, such as: 

turnerconstructLons[.]com (the real Turner Construction builds things like NFL stadiums and hospitals)
turnerconsstruction[.]com 
turrnerconstructions[.]com 
clarkconstructLion[.]com (the real Clark Construction builds things like Naval Bases and high rises)
clarkconstructionproject[.]com
truxobuild[.]com and several others. 

Many more just stick to Microsoft imitation. For example, Dave White, the name used by thceneda@gmail.com, registered domains such as: 

officedocdrivecloudfile[.]com
officedocdrivecloud[.]com 
officeclouddriveshared365[.]com and others.  

Michael Previte, using the email mchlprevite@gmail.com registered domains such as: 

MSGReceivedAlert[.]com 
Documents-flip[.]com 
Microsoft-Voicemail-EDriveOnline[.]com and others. 

Other gmail accounts of registrants included: drstacywalter, drstacywalterofficial, elaindnck, sjone0884, bruceandrews21, officebox3585, tarakent60, oodybugs53, rmcy987, redirecting.com@gmail.com, jcllay07, rarejnr, keedew12, kimmit205, marketingchairman50, megatechblock247, nwfamsp000, michaelwesleysullivan, rmcy987, jennix18, woodlandmech, keedew12, mbookpro115, owolabimoney31, moorejulian659, theonlyzeus1999, blaketurner826, genedurgin2, goldenheart3890, ky0dx2024, donald.bill100, crasengan073, nwfamsp000.  (And a few non-gmail: loaann1@outlook.com, bclarknorwood@outlook.com, tfloy03@yahoo.com. ) The majority of the domains listed were hiding behind Cloudflare's registration services, which lists "Registrant emails" in the form: hxxps://domaincontact.cloudflareregistrar[.]com/scammerdomain[.]tld (a couple hundred times.)

RaccoonO365 Telegram Channel Insights

The R-O365 Telegram channel made frequent boasts about the ways they were improving their services.

In April they started a Beta of their "RaccoonO365 Mailer" where there service not only helped you with cookie and credential capture, but sent your spam for you as well. 



The price for the new service was either $500 per year. $1000 per year, or $1500 per year, depending on the options selected. 

In August they announced that they were now "a bulletproof cPanel provider." 


In early September they redid their subscription services, (charging a LOT more money!) 

Their last big improvement was announced September 15th.  Just in time for all of their major infrastructure to be kicked off Cloudflare and/or seized by Microsoft's court order!


Raccoon365 Still Kicking 

After Microsoft's court action, the Telegram channel went dark (the last post we saw was September 17, 2025.)  For the sake of completeness, I messaged the admin, whose account is still live, and asked him if there were plans for a new channel. 




It looks like his current focus is selling access to the accounts that he's already compromised.  The pricing plan for phishing has changed considerably as well.  Rather than buying unlimited spamming for a flat monthly rate, now he is charging by the number of "leads" that he sends your phish to, but with guaranteed success rates.  He'll send 50,000 messages, guaranteeing successful log harvesting on 300 accounts, for $1,000.  For $1,500 you get 100,000 messages with 700 guaranteed logs, and for $2,000 you get 200,000 messages sent with 1500 guaranteed logs. 

Current plan as of 22SEP2025


Joshua Kayode Ogundipe?

Goodnews Eguabs is the founder of DigiHubng. He has one Ogundipe friend, James.  
James has a friend named Joshua Kayode Ogundipe.  Could this be our guy?  Inconclusive. 


Microsoft noted that this seemed to be a continuation of the phishing kits created by Abanoud Nady, known online as MRxC0DER who used the brand name "ONNX" to sell his Phishing-as-a-Service. 
While there are many similarities, including the seizure of 240 domains in a very similar TRO, Abanoud Nady was an Arabic-speaking Egyptian. (See:  https://noticeofpleadings.com/fakeonnx/ for more details.) 

An Interesting Associate: TopBoy7x and Phishing Intelligence 

Curiously, one of the users who was authorized to post in the RaccoonO365 Telegram channel was @Topboy7x. TopBoy has paid for an exclusive Telegram-provided "+888" telephone number (+888 0926 4717) and has an Arabic-language Bio on Telegram. 


Top Boy runs the 15,966 subscriber Telegram channel "MiddleMen" and has paid to have several desirable usernames as aliases to his account, including: @safedealagent, @awsfather, @finalizer, @commandment, and @paywithusdt.  By rotating through these accounts in his channels, he may be fooling some users into believing there are multiple vendors vouching for one another.  Nope, its all the same guy. He offers Escrow Services, Corporate Intelligence Services, and Spamming services in many criminal channels, including RaccoonO365.  Why does he have the alias @awsfather?  Because one of his specialty services is selling hacked AWS accounts. 

The messages below are from TopBoy's Telegram channel hxxps://t.me/verticals, where he has been selling hacked accounts since at least July 2024. 

https://t.me/verticals/706

TopBoy's screenshots make it clear that he sells AWS accounts to use as spamming engines.  In this screenshot, the AWS account has "451,323 Remaining Sends" on its daily email limit. 

TopBoy also sells corporate intelligence services, such as selling hacked accounts from Grata.  This screenshot from TopBoy demonstrates how this can be used to research companies in the "Energy" industry, for example, however he also sells hacked account at Pitchbook and Apollo for your intelligence needs. 


Pitchbook offers sales people (or criminal spammers in this case) contact details and job titles for 4.5 million business people.


Other spamming services he sells include Neverbounce Pro, where again, he is selling access to someone else's hacked account: 







Saturday, December 30, 2023

Vietnam's Massive CAPTCHA crackers vs. Microsoft DCU

Earlier this month, Microsoft's Digital Crimes Unit was featured in a WIRED article by Lily Hay Newman - Microsoft’s Digital Crime Unit Goes Deep on How It Disrupts Cybercrime. In part, the article discusses MS-DCU's case against the hackers that they call Storm-1152. According to DCU, Storm-1152 used their CAPTCHA-cracking capabilities to assist other criminals in the massive creation of Microsoft email accounts, such as Hotmail and Outlook accounts. How many? How about 750 MILLION email accounts created for illicit purposes! In their announcement about Storm-1152, DCU's Amy Hogan-Burney calls out several of the websites run by the group, including Hotmailbox[.]me, 1stCAPTCHA[.]com, AnyCAPTCHA[.]com, and NoneCAPTCHA[.]com.   (I'm not familiar with NoneCAPTCHA, but it looks like it was just a redirect domain to 1stCAPTCHA.)  Amy shares that the group is based in Vietnam and names three of their operators: Duong Dinh Tu, Linh Van Nguyễn (also known as Nguyễn Van Linh), and Tai Van Nguyen.

hotmailbox[.]me

1stCaptcha[.]com

AnyCaptcha[.]com

Some example code is still on github that illustrates how these massive CAPTCHA solvers were used.  For example "CuongPhan1408" has a 1stCaptcha written in GoLang and shows examples in his code of solving Discord account creations using "HCaptchaTaskProxyless" and using "FunCaptchaTaskProxyless" to defeat Microsoft's Live signups.  FunCaptcha is the tool created by Arkose Labs which is currently used by Microsoft to confirm that emails are only created by humans. 

Github user HecTran12 shares code that links to the now-seized-by-Microsoft website 1stcaptcha[.]com which could previously be installed with "pip install 1stcaptcha." HecTran12's FunCaptcha example solves Outlook[.]com captchas to make new Outlook accounts. 

Github user "Xtekky" shares his AnyCaptcha[.]com-based code called "Outlook Gen" which is Python code that links to the Microsoft-seized website "AnyCaptcha[.]com" to create Outlook accounts in volume.  The code has 45 stars and 15 forks on Github.

Clearly the USERS of Outlook Gen, based on the forks, included many people from many parts of the world.  XTekky has many interesting tools on his Telegram and Discord channels, including "tools" for creating views and likes on TikTok using bots. He demonstrates by sharing a "why so many likes?" video on his TikTok which has been liked 912,400 times.  This relies on his TikTok Slider CAPTCHA Solver, which he claims has 100% accuracy in defeating the TikTok captcha.  XTekky also has a Discord "Question-based" CAPTCHA solver, which uses OpenAI's ChatGPT to solve the questions and provide the answers.  

With three major CAPTCHA-solving tools taken down by Microsoft, what's filling their place?  Based on examining new starring and forking from Github users who liked the old projects, it looks like Russia-based "AntiCaptchaOfficial" is the likely leader.  It claims to solve images with text, Recaptcha v2/v3 Enterprise or non-Enterprise, Funcaptcha Arcoselabs, GeeTest and hCaptcha Enterprise or non-Enterprise, and currently charges rates averaging $0.0005 per solved CAPTCHA. That would be 2,000 account creations per $1. 

Microsoft credits Arkose Labs with their help in investigating the case against Storm-1152, but if the stats page at "anti-Captcha[.]com" can be believed, their site is currently cracking 10,000+ Arkose Labs CAPTCHAs per minute.  Only reCAPTCHA v2 is experiencing more cracks per minute (currently 19,000+). Arkose should be pleased that they are one of the most expensive CAPTCHAs to solve.  Anti-Captcha is currently charging $3 per 1,000.  Their website claims that they are helping disadvantaged workers around the world. 


"With your help, they now have a choice between working in toxic factory conditions or on a computer." 

Their stories don't seem to say "Rather than work in a toxic factory, I help cybercriminals commit fraud and theft by making fake accounts on Outlook, Google, TikTok, Discord and more."





Sunday, November 15, 2020

ENISA: Top 15 Threats: Spam, Phishing, and Malware!

Part One of this post, describing the many components of "The Enisa Cybersecurity Threat Landscape" went over ENISA's Year in Review, the emphasis on Cyber Threat Intelligence, Sector specific threats, Research Topics, and Emerging Trends.  This is "Part Two" where we review the 16 documents that ENISA released to cover their "Top 15 Cyber Threats" report. In particular, we look at the Top 5.

ENISA's Top 15 Threats report starts with this summary document: 


The list of the Top 15 Threats is an annual list from ENISA, with only slight changes in positions for the various threats since last year. Malware remains in the Number 1 spot, and Web-based attacks remains Number 2. Phishing actually increased from 4th to 3rd position. Spam also rose this year, from 6th to 5th position. The threat making the greatest movement was Identity Theft, jumping from 13th to 7th position!
    
  A full report from ENISA is available for each of the topics below. Click to access each one. I'll only comment on a few in this blog post!
    1. Malware
    2. Web-based Attacks
    3. Phishing
    4. Web Application Attacks
    5. Spam 
    6. DDOS 
    7. Identify Theft
    8. Data Breach 
    9. Insider Threat
    10. Botnets
    11. Physical manipulation, damage, theft and loss
    12. Information Leakage 
    13. Ransomware
    14. Cyber espionage
    15. Cryptojacking 

#1 Cyber Threat - Malware


ENISA ranks Malware as the #1 threat again, pointing out several troubling trends.  Detection of malware on Business-owned Windows computers went up 13% from the previous year, and 71% of malware infections had spread from one infected user to another.  46.5% of malware delivered by email used a ".docx" file extension, indicating that our continued unsafe business practice of sharing Word documents by email continues to put our organizations and our employees at risk!  Another change was that 67% of malware was delivered via an encrypted HTTPS connection -- the "increased safety" of having encrypted web pages has also greatly increased our difficulty in understanding when an employee is receiving malware by visiting a webpage.

The number one malware family in this reporting period was Emotet, which targeted US-based businesses 71% of the time and UK targets 24% of the time.  

An increasing number of banking trojans were also seen that targeted the Android operating system.  Top families included Asacub, SVPeng, Agent, Faketoken, and HQWar.

 The so-called File-less Malware was also a significant attack method, often using Windows Management Instrumentation or PowerShell scripts to perform complex attacks more or less "at the command line" rather than by downloading a Windows PE Executable.

For C2-based malware, a growing trend in having Russian-based Command & Control servers was observed, with the likelihood of a Russian-host going up 143% from the previous reporting period.  these malware families included Emotet, JSECoin, XMRig, CryptoLoot, Coinhive, Trickbot, Lokibot, and AgentTesla (according to MalwareBytes, quoted in the report.)

ENISA says that 94% of all malware deliveries were via email during 2019, quoting from the EC3 Internet Organised Crime Threat Assessment.   Many such attacks were enabled by employee behavior and gained extended reach due to vulnerabilities in Windows, several of which allowed Remote Code Execution, making malware attacks "wormable" and able to spread throughout the enterprise, often due to poor patch management.

Proposed actions in this report include the need for better in-bound screening, including the ability to decrypt and inspect SSL/TLS traffic as it comes into the network, including web, email, and mobile applications.  Security policies must also be updated to include what processes and escalations must occur "post-detection" in the case of an infection.  Log monitoring must be improved.  

One suggestion that I strongly agree with -- "Organizations need to disable or reduce access to PowerShell functions" -- so much malware this year, especially ransomware, would be stopped cold in its tracks if PowerShell were not so prevalently deployed and enabled in our organizations!  

Although it is not mentioned by ENISA, my favorite document for understanding PowerShell threats is "The art and science of detecting Cobalt Strike" from our friends at Talos Intelligence!  More than any other attack platform, Cobalt Strike is being abused by malicious actors in order to fully compromise domains, often for the purpose of exfiltrating and encrypting for ransomware.

Please refer to the full report for additional recommendations.

#2 Cyber Threat - Web-Based Attacks


Web-Based Attacks are broken into four main vectors by ENISA.  Drive-by downloads, Watering hole attacks, Form-jacking, and Malicious URLs. 

As noted in part one, due to the age of the reporting window (January 2019 to April 2020) some of the particular attacks noted are more historical and of less keen interest by this time, however a couple trends are worth calling attention to.

"MageCart" attacks continue to be a prominent method for acquiring financial credentials.  Because of the vast popularity of a small handful of online "checkout" systems, many organized crime groups are investing heavily in hackers who have "nation-state" level capabilities in order to create new zero day attacks into these systems.  Shoppers are basically defenseless as their order information is transparently transmitted to criminals while they shop at even the largest and most prominent "trust-worthy" online vendors. 

In addition to browser vulnerabilities that can make watering hole attacks quite successful, attackers are also attacking popular web browser extensions, which often have less rigorous security updates than the base browser products themselves.

Content Management Systems also present an enormous footprint of vulnerability as platforms such as WordPress provide millions of vulnerable websites that can be used at will by hackers to host both phishing sites and malware payload files.

#3 Cyber Threat - Phishing


Phishing has historically been email-based crime that lures a target to an illicit website via a social engineering email.  It is the key to $26 Billion in losses due to Business Email Compromise, as well as to a growing number of scams linked to the COVID-19 Pandemic.  In the FIRST MONTH of the COVID-19 Pandemic, ENISA reports that phishing attacks increased 667%!  As previously mentioned, these dangerous emails are now very likely to contain a trojaned Microsoft Office family document.  

ENISA warns that phishing URLs are now being seen more frequently delivered via SMS, WhatsApp, and Social Media platforms, expanding beyond the original email platform.

While phishing historically targeted financial institutions, ENISA says that webmail became the leading target of phishing in Q1 of 2019, with Microsoft 365 services being particularly targeted.

User education and user reporting remains a critical strategy, especially as ENISA says that 99% of phishing emails require human interaction in order to be effective.

The most effective means to combat phishing continues to be the implementation of 2FA. If a phisher cannot gain access to an account with simple userid and password, many schemes would be immediately blocked.

From a financial perspective, wiring money should ALWAYS require out of band confirmation.  The cost of not getting the confirmation is simply too high, with some Business Email Compromise attacks costing tens of millions of dollars!

#5 Cyber Threat - Spam 


As the ENISA report on Spam menions, after 41 years of dealing with spam, "nothing compared with the spam activity seen this year with the COVID-19 pandemic!"

During the reporting period, Emotet, Necurs, and Gamut were some of the top spamming families.

Some other findings: 
85% of all emails exchanged in April of 2019 were spam, a 15-month high.
13% of data breaches could be traced back to malicious spam.
83% of companies were unprotected against email-based brand impersonation (DMARC)
42% of CISOs reported dealing with at least one spam-based security incident.

To bring this category up to date, we noticed that ENISA was fond of the Quarterly Spam & Phishing reports from Kaspersky.  Please find below links to the 2020 Q1, Q2, and Q3 reports from Kasperky, which will technically be part of NEXT year's ENISA reporting:

Kaspersky found that throughout the third quarter, spam was at least 48.9% of all email sent, a slight decline from Q2, however the portion of spam containing malicious emails was up significantly.  Kaspersky identified 51 Million malicious attachments in that quarter, with 8.4% of them being the keylogger commonly known as Agent Tesla (Kaspersky uses the name "Trojan-PSW.MSIL.Agensla.gen"). Microsoft Office documents exploiting CVE-2017-11882 were the second most common.

They also noted 103 million phishing attacks, with the top targeted sectors being Online Stores (19.2%) and Global Web Portals (14.48%) which would include Office365.  Only 10.8% of the phishing attacks observed by Kaspersky targeted banks!


My favorite spam campaign here was the "FTC Official Personal Data Protection Fund" which claimed that the Federal Trade Commission had found that the recipient was a victim of "personal data leakage" and they were eligible to be compensated for that loss, if they just filled out a simple form on their website (which harvested personal data, including credit card and social security number.) 


Friday, October 16, 2020

Trickbot On The Ropes: Microsoft's Case Against Trickbot

 Trickbot is having a truly bad time this month!  While as of today, Trickbot binaries are being delivered by Emotet, there is every sign that they are struggling.   Emotet's daily activities are best documented by a team of researchers using the collective identity "Cryptolaemus" and sharing news of IOCs and URLs on their website: https://paste.cryptolaemus.com/.  With no activity from October 6th to 12th, there was every indication a "change" was coming, and beginning on 14OCT2020, researchers such as our friends at @CofenseLabs and @Malware_Traffic are both reporting that Trickbot is now being delivered by the Emotet spam-sending botnet.  

This post examines Microsoft's case against Trickbot. However, there are also reports of U.S. Cyber Command taking a role in disrupting Trickbot, as reported by the Washington Post and security journalist Brian Krebs. In the "take-down" attempt, as described by Krebs, the bot began propagating to other bots that its new controller IP address should be "127.0.0.1:1" - which would result in the bot-infected computer stopping communication with the criminals.  There was also an attempt to flood the criminals with millions of fake "stolen credentials" hoping to confuse their ability to sort out "true victims."  As Krebs also reported, the fabulous Trickbot C&C tracker at FEODOTracker is reporting many live C&C addresses for Trickbot.  (Also see Trickbot On the Ropes Part 2: the QQAAZZ Money Laundering Ring.) 

The Microsoft Trickbot Case

On October 12, 2020, Microsoft announced "New action to combat ransomware ahead of U.S. election" describing Trickbot as malware that "has infected over a million computing devices around the world since late 2016." By filing a lawsuit in the U.S. District Court for the Eastern District of Virginia, Microsoft received permission for a Temporary Restraining Order (TRO).  The Digital Crimes Unit (much love, guys!) worked with the FS-ISAC, ESET, Symantec, the Microsoft Defender team, NTT, and Lumen's Black Lotus Lab and others to lay out their case. 

The legal documents surrounding the case are on the Microsoft website: NoticeOfPleadings.com/trickbot/

Microsoft and the FS-ISAC bring the case with a 60 page complaint, demonstrating harm to their respective customers in the Eastern District of Virginia, and demanding that "John Doe 1" and "John Doe 2" appear in court for a Jury Trial.

They charge them with violations of: 

  • The Copyright Act - 17 USC § § 101 
  • The Computer Fraud and Abuse Act 18 USC § 1030
  • The Electronic Communications Privacy Act 18 USC § 2701
  • Trademark Infringement under the Lanham Act 15 USC § 1114
  • False Designation of Origin under the Lanham Act 15 USC § 1125(a)
  • Trademark Dilution under the Lanham Act 15 USC § 1125(c) 
  • Common Law Trespasses to Chattels 
  • Unjust Enrichment 
  • and Conversion 
To do so, Microsoft asked the court to force hosting providers to suspend services and block and monitor traffic for the customers who were using particular IP addresses within their organizations.  The list included: 

  • Input Output Flood, LLC of Las Vegas, for IP addresses: 
    • 104.161.32[.]103, .105, .106, .109, and .118.
  • Hosting Solution Ltd (Hurricane Electric of Fremont, California) for IP address:
    •  104.193.252[.]221.
  • Nodes Direct Holdings of Jacksonville Florida for IP addresses: 
    • 107.155.137[.]7, .19, and .28,
    • 162.216.0[.]163, 
    • 23.239.84[.]132, .136
  • Virtual Machine Solutions, LLC of Los Angeles, California for IP addresses: 
    • 107.174.192[.]162 and 
    • 107.175.184[.]201
  • Hostkey USA of New York for IP address: 
    • 139.60.163[.]45 
  • Fastlink Network Inc, of Los Angelese for IP address: 
    • 156.96.46[.]27
  • Green Floid LLC for IP addresses: 
    • 195.123.241[.]13 and .55 
  • Twinservers Hosting of Nashua, New Hampshire for IP address: 
    • 162.247.155[.]165  

Each team made significant contributions to the effort, and most have published their own Trickbot blogs, which I link below, with regards to the case, their most important function was to provide professional analysis in the form of a Declaration in Support of Motion for TRO: 

  • Lyons is Jason Lyons, a Senior Manager of Investigations at the DCU Malware & Cloud Crimes Team.  Lyons, who served in the Cyber CounterIntelligence unit of the U.S. Army, provides 25 pages of testimony and ten "Exhibits." Part of his testimony included the proof of 25 million Gmail, 19 million Yahoo, 11 million Hotmail, 7 million AOL, 3.5 million MSN, and 2 million Yahoo.co.uk addresses known to have been targeted by Trickbot (based on reporting from Deep Instinct)
  • Finones is Rodelio Finones, a Senior Security Software Engineer and Malware Researcher at the Microsoft DCU. He provides a 21 page testimony of his own investigation into Trickbot, 
  • Thakur is Vikram Thakur, the Technical Director of Symantec Enterprise, where he has been a major rockstar for more than a dozen years!  He provides a 20 page testimony.
  • Garlow is Kevin Garlow, Lead Information Security Engineer at LUMEN (formerly CenturyLink). His testimony includes the fact that he has identified 502 distinct IP addresses that had acted as Trickbot controllers, but that 40 of them have remained online despite more than 30 abuse notifications and that 9 of them have been sent more than 100 such notifications.  He states that "We confirmed 55 new Trickbot controller IPs in September 2020 and 99 new Trickbot controller IPs in August."  It is these long-lived "bullet-proof" controllers that Microsoft is targeting.  It is also likely that revealing whoever is paying the bills for those long-lived services may be a path to identifying John Doe 1 and John Doe 2.  Garlow's testimony that he has sent so many notices for take-down which have been ignored is a powerful part of this package!
  • Silberstein is Steven Silberstein, the CEO of the FS-ISAC.  He provides testimony to more than 500 fraud attempts against FS-ISAC member institutions over an 18 month period, with $7 Million in attempted fraud.  One FS-ISAC member had dozens of attempts in a two week period with an average fraud attempt of $268,000!  

  • Ghaffari is Kayvan M. Ghaffari, an attorney with Crowell & Moring LLP for Microsoft and the FS-ISAC.  His testimony calls out the particular web hosting companies that were hosting the machines targeted by the TRO, including Colocrossing, IOFlood, HostKey, VDI-Network, ENET-2, and King Servers, pointing out that all of these organizations have Terms of Service which are clearly violated by the Trickbot controllers.  He then attaches as exhibits more than 650 pages of similar cases and the related court documents from them.
  • Boutin is Jean-Ian Boutin, the Head of Threat Research, calls Trickbot "one of the most prolific and frequently encountered types of malware on the Internet."

Related TrickBot Blogs

ESET analyzed 125,000 malware samples and downloaded and decrypted 40,000 configuration files used by Trickbot modules, helping to map out the C&C servers by the botnet. While Trickbot can drop many "modules" these are not one-size-fits-all.  Trickbot modules were sometimes dropped in phases after an initial assessment of the network on which the bot found itself, and other times varies by the "gtag" -- the unique label used to sign the infection, thought to be related to affiliates who paid the Trickbot operators.

gtag timeline by ESET


Lumen's Black Lotus provided C2 timelines, demonstrating which IP addresses in which countries were active in which timeframes.  Indonesia, for example, hosted active C2 servers on 1,362 days!  Colombia and Ecuador, which by their count were #2 and #3 had only 652 and 637 C2 days by comparison.  They shared 95 C2 addresses in their recent Look Inside the Trickbot Botnet blog post. Many of these IP addresses are also called out in Lyons testimony as Exhibit 2.

5.152.210[.]18845.89.127[.]2796.9.77[.]56129.232.133[.]39185.172.129[.]100194.87.236[.]171
5.182.210[.]22451.77.112[.]252103.111.83[.]246131.161.253[.]190185.234.72[.]114195.123.238[.]83
5.182.211[.]12451.83.196[.]234103.12.161[.]194139.60.163[.]45185.234.72[.]35195.123.239[.]193
5.182.211[.]13851.89.215[.]186103.196.211[.]120156.96.46[.]27185.236.202[.]249195.123.240[.]18
27.147.173[.]22762.108[.]35.9103.221.254[.]102158.181.155[.]153185.25.51[.]139195.123.240[.]93
36.66.218[.]11780.210.32[.]67103.36.48[.]103176.31.28[.]85185.99.2[.]106195.123.241[.]224
36.89.182[.]22583.220.171[.]175103.76.169[.]213177.190.69[.]162185.99.2[.]115195.123.241[.]229
36.89.243[.]24185.204.116[.]117104.161.32[.]108179.127.88[.]41186.159.8[.]218195.161.62[.]25
36.91.45[.]1089.249.65[.]53104.161.32[.]118180.211.170[.]214190.136.178[.]52200.116.159[.]183
36.91.87[.]22791.200.100[.]71107.155.137[.]15181.112.157[.]42190.145.83[.]98200.116.232[.]186
36.94.33[.]10291.200.103[.]236110.93.15[.]98181.129.104[.]139190.152.182[.]150200.171.101[.]169
45.127[.]222.892.38.135[.]61112.109.19[.]178181.129.134[.]18190.214.28[.]74200.29.119[.]71
45.138.158[.]3392.62.65[.]163117.252.214[.]138181.143.186[.]42190.99.97[.]42201.231.85[.]50
45.148.10[.]17493.189.42[.]225121.100.19[.]18182.253.113[.]67192.3.246[.]216212.22.70[.]59
45.66.10[.]2296.9.73[.]73121.101.185[.]130185.14.30[.]247194.5.249[.]214220.247.174[.]12
45.89.125[.]14896.9.77[.]142122.50.6[.]122185.142.99[.]94194.5.249[.]215

Symantec's blog post "Trickbot: U.S. Court Order Hits Botnet's Infrastructure" has a great infographic about "How Trickbot Works": 


Microsoft on Trickbot's use of Covid-19 Lures

Microsoft is in a unique position to take action against malware, having visibility to so much malware-related traffic from browser telemetry, Microsoft Defender reports, and Office365 scans.  In the past year, they have evaluated 6 Trillion messages and blocked 13 Billion malicious emails that used 1.6 Billion URLs to try to infect the email recipients!

Microsoft's Digital Defense Report 2020 points out that Trickbot began using COVID-19 spam lures on March 3, 2020, and went on to become the most prominent spam botnet using COVID-19 themes.

From MS Digital Defense Report 2020 

We've long argued that if the lure is timely and controversial, people will click on it.  That seems to be the case even today as ProofPoint's @ThreatInsight has pointed out, documenting that a recent malware campaign, first seen October 6, 2020, is using President Trump's diagnosis as a lure to infect people with additional malware, using the subject line "Recent material about the president's situation" and the promise of additional details in a password-protected email attachment.



Saturday, April 11, 2020

SEC Suspends CoronaVirus Stock Pump-n-Dump Scammers

Last month we shared information on the blog about spam-driven affiliate programs who were selling a variety of shady "anti-Coronavirus" products, including immunity oils, masks, disinfectants, and no-touch thermometers. (See: CAUCE Spamfighters Rally Against Corona Health Fraud Affiliate programs ).  Today I wanted to share an update regarding another type of spam and the SEC's actions related to stock market symbols being manipulated through "pump-n-dump" scams.

Over the past several weeks, the SEC announced the suspension of trading of several stock symbols due to illegal attempts to manipulate the value of those stocks, often by driving the stock value up ("pumping") by making untrue claims about how the company was involved in helping fight the Coronavirus, Covid19.  We'll just dive into two of the most recent ones here.

Turbo Global Partners, Inc ("TRBO")

On April 9, 2020, the SEC suspended trading of Turbo Global Partners, Inc ("TRBO"), a company based in Tampa, Florida.  The suspension is due to claims made by the company that it had entered into agreement with BeMotino, Inc to provide non-contact human temperature screening and facial recognition technology, and that it had the ability to ship the technology to customers within five days of receiving an order.  Press Releases on March 30th and April 3rd made these claims.


The small spike to .0074 cents per share on February 7th corresponded with the announcement that the company was doing a pilot to place indoor digital billboards in 100 pharmacies in Florida in 2020 with aggressive expansion predicted:

 Singerman continues, "BeMotion's Mobile Commerce Network 'MCN' and the DCN Vending & Marketplace 'DCN-V' is the solution we are bringing to the global market under our joint TURBO - BeMotion brand. Our initial effort will be integrating both MCN and DCN-V technologies into our independent pharmacy silo in 3 Phases of our 2020 Strategic and Tactical Plan:

"Phase 1: Integrating our Co-Brand Solutions into our 100-Pilot pharmacy locations in Florida to be deployed during Quarter 2, 2020.

"Phase 2: Deploying the DCN Vending into 1,000+ pharmacy locations in the U.S. deployed with the TURBO - BeMotion Co-Brand by 2021.

"Phase 3: Deploying the DCN Vending into 5,000+ pharmacy locations by 2023."

On March 14th someone buys nearly 120 million shares of the company for between .0016 and .0055 cents per share.  Then this press release is splashed around the Internet in penny stock forums and "investor tip" messages:


The company that was previously saying it was a marketing company selling indoor billboards is suddenly selling "non-contact human body scanning technology" that can scan "up to 320 people per minute" saying "Imagine Law Enforcement with our Technology version for vehicles being able to scan like RADAR a cluster of people or a homeless encampment in minutes for elevated temperatures." and that "THIS IS THE KEY TOOL ... THAT CAN HELP BREAK THE CHAIN OF VIRUS TRANSMISSION."

If we guess that the average purchase price for that stock was .003 cents per share, immediately after this press release, the stock booms to six times that value.  The investors who are "in on the deal" and bought 120 million shares on March 16th to March 18th and sold on April 4th and 5th would have paid around $360,000 and sold for right at $2 Million.  This is how Stock Pump n Dump works.

Where did that garish and false ad come from?  This copy was posted in an investment board run by "SHEEPWOLF" 


But was Sheepwolf heavily pushing this stock?  Let's look at his recent posts on the site:

Do you get the feeling that SHEEPWOLF really wants the value of $TRBO to increase?  Hmmm... I wonder why. Between March 27, 2020 and April 7, 2020, SHEEPWOLF posted EIGHTY-ONE MESSAGES about this stock!

There was a clear change in marketing via Press Releases that occurred beginning March 13th, according to OTC Markets:

https://www.otcmarkets.com/stock/TRBO/news

And that was just ONE of the recent SEC Suspensions. If you have more information about this case, please contact Justin Jeffries, Associate Regional Director for the SEC, at (404) 842-5750.

BioELife Corp f/k/a U.S. Lithium Corp ("LITH") 

On April 8, 2020, the SEC suspended trading of BioELife Corp f/k/a U.S. Lithium Corp ("LITH").  The SEC has "questions and concerns regarding the accuracy and adequacy of publicly available information concerning LITH, including public statements made by LITH in press releases issued on March 12, 2020 and March 16, 2020 and reinforced by third-party stock promoters, regarding a purported new Coronavirus (COVID-19) Prevention Products Line, together with potentially manipulative trading activity between October 2019 and present."

That is certainly an understatement!  Let's look at the recent press releases, indicating that BioELife had a sudden change in product direction, from selling CBD Pain treatments, to suddenly preventing the spread in CoronaVirus.

https://www.otcmarkets.com/stock/LITH/news
Some of those recent statements were things like this:

The initial purchase order from Group Buying Club- GPOCBD, covers all current BioELife products – lotions, tinctures, flower and gummies as well as the BioEDefense product line: Sanitizers, RespiPro Virus Killer Masks, and the R-Shield (a reusable nanofiber scarf designed for 50 wash cycles). GPOCBD is marketing CBD products directly to wholesalers, consumers and affiliates looking to supplement their sales of BioELife products which offer natural products to fight pain and infection, as well as help defend against the growing global concerns regarding bacteria and virus’s contamination.

That's funny. Respilon R Shield is a Czech mask created for fighting smog and marketed primarily through their Instagram page:  https://www.instagram.com/respilon_r_shield/.  They have converted Czech prisons into mask factories, because it seems the masks are in high demand.  Definitely a more "Lit" mask than most people are wearing these days.  But since they are still in KickStarter mode, I don't think there is much chance that US Lithium is involved with them. I don't believe they are at any way to fault for $LITH's bad marketing!


Here's an example of how these press releases are then turned into "BUZZ" by newsletters, such as this one from "Make Penny Stocks Great Again" one of many such services that provide "free" newsletters to people who are trying to make a quick buck daytrading.


Ooh!  CBD-fortified hand-sanitizer!  Where do I sign up?

If anyone has more information about the $LITH pump, "they should immediately contact Celeste A. Chase, Assistant Regional Director, at (212) 336-0049, or Jason R. Berkowitz, Assistant Regional Director, at (305) 982-6309." (from: https://www.sec.gov/litigation/suspensions/2020/34-88607.pdf )

Spotting the Scammers

There are some members of these "stock promotion" investor boards that try to warn others.  My favorite right now is "reverse_long" who shares information about stocks that are in "PAID PUMP N DUMP" scams ... I love the tagline he uses on his profile! "Shorting Paid Pump and Dumps to Make The World A Better Place"  (He also has a great Twitter feed:  @reverse_long)


And, sure enough, one of the 80 Paid Pump And Dump scams he has been warning his fellow investors about was $LITH: 


Which was also on his Twitter feed back on March 4th: 



Honestly, I believe if we wanted to find more of these, it would probably be as easy as doing this Google Search:

site:www.otcmarkets.com inurl:news inurl:stock COVID-19

Then I would take the resulting symbols and check them against these bogus stock promoter sites.  Let me assure you there are some DOOZIES in there!  But subscribing to many of these Stock Tip Newsletters might be another way to do so.

Other SEC Actions

(Quoting from the SEC Suspension Orders, linked to each company's name below: ) 

Feb 7, 2020 = $AEMDAethlon Medical - Concerns regarding the accuracy and adequacy of information in the marketplace since at least January 22, 2020 that appears to be disseminated by third party promoters that are purportedly not affiliated with AEMD about, among other things the viability of the company's products to treat the coronavirus.

Feb 24, 2020 = $ETBI - Eastgate Biotech Corp - Concerns about the adequacy and reliability of publicy available information concerning ETBI since at least January 30, 2020, among other things, statements about the company's purported international marketing rights to an approved coronavirus treatment to potentially combat the Wuhan Coronavirus.  

Mar 25, 2020 - $ZOOM - Zoom Technologies, Inc - This one seems to be because of the name confusion of their stock symbol and the "similarly-named NASDAQ-listed" video conferencing company.

Mar 25, 2020 - $PXYN - Praxsyn Corporation - Questions  regarding the accuracy and adequacy of information in the marketplace since at least February 27, 2020.  Statements about PXYN having and being able to obtain large quantities of N95 masks used to protect wearers from COVID-19. 

https://www.karmadata.com/Entity/Sponsor/praxsyn.com
One of the places $PXYN was being pumped was "Investors Hangout" ... "hotforpenny" was pumping the Corona run, but a review of messages shows that the company had been pumped before as a medical marijuana company in 2018:


HotforPenny also participates on "Sheepwolf's 1,000,000.00 Journey" that was referenced above.  He's currently pumping (excuse me, "discussing")  $GRYN, $SING, $BCCI, $BTFH, $AYTU, $BWVI, and $RJDG ... 

https://investorshangout.com/profile/latestposts/id/14192

April 3, 2020 - $NBDR
- No Borders, Inc - Questions and concerns regarding the adequacy and accuracy of publicly available information concerning NBDR.  STatements about NBDR's products and business activities related to the COVID-19 pandemic, including NBDR's COVID-19 specimen collection kits, an agreement to bring COVID-19 test kits to the United States, and NBDR's activities related to the distribution of personal protective equipment. 

Example: 
https://investorshub.advfn.com/No-Borders-Inc-NBDR-3988/

April 3, 2020 - $SSTUSandy Steele Unlimited Inc - questions regarding the accuracy and adequacy of information in the marketplace since at least March, 2020. Those questions relate to apparent promotional activity, including e-mail stock promotions from unknown sources directed to investors, which claim that Sandy Steele is an operational garment manufacturer producing various clothing items and that it has the ability to produce protective masks that are in high demand due to the COVID-19 crisis.

InvestorsHub has over 700 messages related to this company, with many referring to the pump and dump.  See: https://investorshub.advfn.com/Sandy-Steele-SSTU-3697/ 

April 7, 2020 - $WMGR - Wellness Matrix Group, Inc - questions regarding the accuracy and adequacy of information in the marketplace since at least March 19, 2020. Those questions relate to statements WMGR made through affiliated websites and a company consultant about selling at-home COVID-19 testing kits that had been approved by the FDA.

NPR reported on this company's fraudulent behavior - See: SEC Suspends Trading of Company That Sold 'At-Home' COVID-19 Tests 

Ten months ago, they named a new VP of marketing (David Saltrelli) and a new president (Joshua Patterson) and a change in direction - developing "technologically advanced health care models in a Virtual Reality, Augmented Reality, and Creative Artificial Intelligence Platform." Kind of a jump from their origins as Fuhuiyuan International Holdings, which was mostly a real estate management company working with KWest Alberta in Canada.  When you issue 190,000,000 shares of stock to be valued at $0.0001 each and switch from real estate to Artificial Intelligence Health Care, something odd may be afoot.

April 7, 2020 - $PGEC - Prestige Capital Corp. -  concerns about the adequacy and accuracy of publicly available information concerning PGEC, including its financial condition and its operations, if any, in light of concerns about investors confusing this issuer with a similarly-named private company that is a manufacturer of N95 masks and the subject of increased media attention during the ongoing COVID-19 pandemic.

April 7, 2020 - $KCPC - Key Capital Corporation - questions regarding the accuracy and adequacy of information in the marketplace since at least March 5, 2020. Those questions relate to statements KCPC made about developing, and being able to make available to the mass market within three to six months, a vaccine to treat COVID-19 in press releases issued by the Company on March 5, 2020 and March 10, 2020.

Another company with a very interesting change in focus.  Recently this was a company who had announced a "Unique Digital Gold Standard Cryptocurrency" ... and now they have a vaccine for Corona?  

https://finance.yahoo.com/news/key-capital-seeks-partners-development-194915606.html

Quite a change from being the gold mining company behind the GoldCrypto ICO!

https://www.otcmarkets.com/stock/KCPC/news/GoldCrypto-Launching-Worlds-First-Hackproof-Cryptocurrency-Tokens?id=195885