Wednesday, June 23, 2021

Say $6 Trillion Again ... I DARE you: Examining the roots of a total BS Marketing Number

Disclaimer: The principle of Academic Freedom has been the same for 80 years or so.  I do not speak officially for my employer.  That isn't how Academic Freedom works.  This blog post represents my own thoughts and opinions.


How often have you heard the quote that the Cost of Cybercrime is $6 Trillion?

As I was doing some reading on Ransomware I came across this bolded quote yesterday: "Ransomware is set to cause $6 trillion in damages by 2021."  

Wow.  Makes you want to run right out and buy cybersecurity products, doesn't it?  Fear, Uncertainty, and Doubt, the marketing department's dream formula! You really can't fault the marketing folks who wrote that though ... every cybersecurity marketing department is jumping on the bandwagon.  And when dozens of journalists share the number blindly with no examination of the facts, how can they be blamed? 

Every time you see the preposterous number "$6 Trillion Dollars" with regards to cybercrime costs, even when mis-used, as above, the source will be traced to a Cybersecurity Ventures report. I did an analysis of that report back in October 2017 and wanted to walk you through it here, gentle reader, so that you would have a place to point people who quote the Six Trillion Dollar Charlatan.  Here is where things started for me, when I saw this report:The original $6 Trillion Charlatan

Whether I'm grading a student paper, or reviewing a journal article submission, my approach to facts is the same.  Check the source. I'm hardly the only academic that has pointed out the shoddiness of many of the claims such as this one.  For another example, see the Journal of National Security Law & Policy article, "Advancing Accurate and Objective Cybercrime Metrics" by Stephen Cobb.  I love this quote from his peer-reviewed article:

"There is no shortage of data pointing to a dire state of affairs in cyberspace, published under headlines like “Global Breach Costs Set to Top $5 Trillion By 2024,” or "Global Breach Costs Set to Top $5 Trillion By 2024," and “Mobile Cyberattacks on the rise.” The manner in which such numbers and claims are quoted – and requoted – may lead the casual observer to believe they are based on official cybercrime metrics, yet few if any of these reports are the product of a comprehensive effort to consistently and objectively catalogue cybercriminal activity over time." (emphasis mine)

(Full disclosure, Stephen quotes my blog in his article - specifically my 30SEP2018 article "FBI's Crime Data Explorer: What the Numbers Say about Cybercrime.")

A reasonable approach to estimating the impact of Cybercrime might be to create various categories, suggest a reasonable maximum for each of them, and add them all together to create your estimate. That is the approach taken by some of my greatest cybersecurity heroes, in their excellent paper, "Measuring the Changing Cost of Cybercrime," presented at the 18th Annual Workshop on the Economics of Information Security. Is that the approach taken by Cybersecurity Ventures?  No. Not even close.

The $6 Trillion number that seems to be the point of the entire report seems to hinge on a single blog post from Microsoft, entitled, "The Emerging Era of Cyber Defense and Cybercrime" published 27JAN2016.  The Cybersecurity Ventures article has a footnote listing this as their source for their $3 trillion base.  Their Editor-in-Chief, Steve Morgan, by the way, continues to reference this number and use it in his fresh forecast.  In his 13NOV2020 prognostication, he now claims "Cybercrime to Cost the World $10.5 Trillion Annually by 2025" and STILL references the Microsoft blog in the highlighted link "$3 Trillion USD in 2015." 

https://cybersecurityventures.com/hackerpocalypse-cybercrime-report-2016/

One would presume that the blog post linked by Steve to the words "$3 trillion USD in 2015" would make a claim that the cost of cybercrime in 2015 was $3 trillion.  But that isn't what the Microsoft article says at all!  What the Microsoft blog post by Pete Boden, General Manager of Cloud and Enterprise Security,  actually says is that "The World Economic Forum estimates the economic cost of cybercrime to be $3 trillion worldwide." 

But even that is a mis-statement.  The World Economic Forum certainly doesn't believe that the cost of cybercrime is two orders of magnitude higher than any reasonable estimate.  What did they actually say?

The report is "Risk and responsibility in a Hyperconnected World" published by the World Economic Forum, in collaboration with McKinsey & Company.  

World Economic Forum / McKinsey Report
Click image for report
from mckinsey.com 

Here's what they actually say ... 

"Current trends could result in a backlash against digitization, with huge economic impact.  Major technology trends like massive analytics, cloud computing, and big data could create between US $9.6 trillion and US $21.6 trillion in value for the global economy.  If attacker sophistication outpaces defender capabilities -- resulting in more destructive attacks -- a wave of new regulations and corporate policies could slow innovation, with an aggregate economic impact of around US $3 trillion." - p.3 

Three things to note: 

1) the loss they are forecasting is A REDUCTION IN FUTURE ECONOMIC VALUE of certain technologies (analytics, cloud computing, big data) DUE TO A SLOW DOWN IN INNOVATION.

2) that loss would only come about IF THERE ARE NEW REGULATIONS IMPOSED that would stifle creativity in these areas.

3) The CUMULATIVE EFFECT between the time of the report (2014) and SIX YEARS LATER (2020) was said to have a potential of reaching $3 Trillion. 

So how on earth did Cybersecurity Ventures reach their number?

First, they clearly never read the World Economic Forum / McKinsey report, or they would certainly have been unable to say that the impact of Cybercrime had been $3 trillion in 2015.  Again, the $3 trillion was OVER THE COURSE OF SIX YEARS (or $500 Billion per year on the average) and ONLY IF REGULATORY CONDITIONS CHANGED DRAMATICALLY causing "unrealized potential economic value" to the tech industry.

But how did they get from $6 Trillion to $3 Trillion, even if they wrongly believed that the $3 Trillion was an annual number?  Simple.  In their report, they say there were 2 billion Internet users in 2015, they predict there will be 6 billion Internet users by 2022. They then say "Like street crime, which historically grew in relation to population growth, we are witnessing a similar evolution of cybercrime.  It's not just about more sophisticated weaponry; it's as much about the growing number of human and digital targets."  (See: "2019 Official Annual Cybercrime Report," p.4).  In other words, since there are so many more people, the false $3 Trillion is now $6 Trillion, right? No. That isn't how crime works, and it isn't how cybercrime works either.

According to the Cybersecurity Ventures report, the $6 Trillion in damages would consist of: 

  • Damage and destruction of data
  • Stolen money
  • Lost productivity
  • Theft of intellectual property
  • Theft of personal and financial data
  • Embezzlement
  • Fraud
  • Post-attack disruption
  • Forensic investigation
  • Restoration and deletion of hacked data
  • Reputation harm
But is that what the World Economic Forum said? ABSOLUTELY NOT!!!  

Just to keep beating the point home - the WEF said that the FUTURE GROWTH of certain tech industries may be slowed by $3 Trillion between 2014 and 2020 IF AN ADVERSE REGULATORY ENVIRONMENT is created.

How Much Is $6 Trillion?

According to Steve, the annual Cost of Cybercrime is $6 Trillion (and increasing!)  Ask yourself this question:  

If you agree with Steve's number, you believe that the Cost of Cybercrime is greater than the TOTAL REVENUE of Citibank, JPMorgan Chase, Bank of America, and Wells Fargo.  

You also believe that the Cost of Cybercrime is greater than the TOTAL REVENUE of Volkswagen, Toyota, Daimler/Chrysler, Mitsubishi, Honda, BMW, and Nissan. 

Add Walmart and Amazon and Google and you STILL are not at $6 Trillion.  

It would take the total 2019 Annual Revenues of ALL of thirty-three of these global companies to make $6 Trillion.  Steve says that is how much the cost of cybercrime will be this year, and that it will be $10.5 Trillion by 2024!  Do you believe? I do not.

The Total Cost of Cybercrime? 

Ransomware Math 

Cybersecurity Ventures has expressed that Ransomware is a top concern.  On 21OCT2019, Steve Morgan's Cybercrime Magazine post was titled "Global Ransomware Damage Costs Predicted to Reach $20 Billion USD By 2021." And we've already seen that they say Cybercrime costs will be $6 Trillion by 2021. 

Here's a helpful pie chart to help illustrate that: 


Now if RANSOMWARE is the number one source of cybercrime damages, and ransomware is 0.33% of the total cost of cybercrime, what are the other 99.7% of the costs made of?  That's right.  Thin Air.

A Little Help?

Please do me a favor? If you see someone quote the $6 Trillion Cost of Cybercrime, please send them a link to this story.  The numbers just do not make any sense!

Have you seen a source quoting the $6 Trillion Cost of Cybercrime?  Please share it in the comments below!  And if you know the person who is spouting that nonsense, please send them a link to this article!


Thursday, June 03, 2021

PPP Fraud or How to Use the CARES Act to Go To Prison

 If you are one of the thousands of people who fraudulently filed for a Paycheck Protection Program or PPP Loan under the CARES Act, pay attention!  This blog post  is going to explain why you should return the money and turn yourself in.  The CARES Act provided $349 Billion in forgivable loans that a business could use to cover payroll, mortgage interest, rent, lease, or utilities during the trying times of the pandemic.  But many people are assuming they can just steal that money and never pay a penalty.

Let's use as our example the case of Zsa Zsa Bouvier Couch, whose case was just unsealed in the Middle District of Alabama.

Zsa Zsa Bouvier Couch

Zsa Zsa is an entrepreneur in the Montgomery area.  She operated seven businesses, according to the Alabama Secretary of State:

  • Trinity Christian Ministry, LLC, incorporated on 26MAR2008.
  • Kidz Academy Christian Child Care Center, Inc, incorporated as a non-profit on 12JUN2007.
  • Bouvier Hair Boutique LLC, incorporated 22JAN2008.
  • Slim Fit Weight Loss Medical Clinic & Spa I Inc, incorporated 07APR2020.
  • Zsa Zsa's Boutique, LLC, incorporated 02MAY2020.
  • ABC Christian Ministries, LLC, incorporated 22JAN2008.
  • Walters Academy Corporation, incorporated 26MAY1999.
Kidz Academy opened a new Regions Bank checking account on 25JUN2019.
Bouvier Hair opened a new Regions Bank checking account on 07MAY2020.
Slim Fit opened a new Trustmark checking account on 22APR2020.
Kidz Academy opened a new Trustmark checking account on 06MAY2020.

PPP Loan Time!

Then the PPP Loan Applications started.  To apply for a PPP Loan, the applicant has to tell the bank what their average monthly payroll was and how many employees they have on staff.  One of the checks that is used to compare the information on the application to the history of the bank account.  For example, if I regular issue payroll for $20k per month, and claim on the PPP Loan application that I have a $90k per month payroll, I'm going to quickly get caught.  Zsa Zsa perhaps believed that by opening new checking accounts, the bank would be unable to look at her previous payroll information.

On 22APR2020, Zsa Zsa asked Trustmark for $206,041.68, claiming that Slim Fit had 10 employees and an average payroll of $82,416.67.

To complete the application, she had to attest that the business existed on 15FEB2020 and that the received funds would only be used as allowed in the CARES Act.  She also had to state that this was the only PPP Loan she was applying for and that she did not own or manage any other businesses.

Since SlimFit was incorporated AFTER 15FEB2020, (on 22APR2020) that was a pretty easy one to detect.  Opening a new checking account and then applying for a PPP Loan the same day with your new bank is also a sort of risky move ... but ... she got the loan!  For more than she asked for!  $248,125.00!

On 23APR2020, Zsa Zsa asked Trustmark for $122,479.18, claiming that Trinity also had 10 employees, but had an average monthly payroll of $48,991.67.  Winner move attesting TO THE SAME BANK that you don't have any other businesses, when you just filed THE DAY BEFORE for another business.  But ... she got the loan (though only for $95,625.00).

On 23APR2020, Zsa Zsa also asked Trustmark for $186,664.38 for a third business, Kidz Academy.  She claimed they had 10 employees and a monthly payroll of $74,665.75. And ... she got the loan (for $83,437.47.)

Since things were going so well, Zsa Zsa decided to ask Trustmark for $964,371.88 for Zsa Zsa's Boutique.  She claimed she had 30 employees and an average monthly payroll of $385,748.75.  This time, the Alabama Department of Labor notified Trustmark that ZZB had ZERO employees.  When Trustmark informed Zsa Zsa of this, she responded "Just withdraw the application." 

That application was withdrawn on 04MAY2020, but her Kidz Academy PPP loan was approved on 11MAY2020, her Trinity application was approved on 04MAY2020, and her Slim Fit application was approved on 03JUN2020.

So, after stealing $427,187.47 from the US Taxpayers via Trinity Bank, she realized the gig was up at Trinity and decided to start stealing via Regions Bank.

On 05MAY2020, just one day after learning that the Alabama Department of Labor was on to her and having her most audacious PPP Loan request denied, Zsa Zsa switched to Regions Bank and filed a PPP Loan for Kidz Academy.  This time she claimed to have 15 employees with a monthly payroll of $120,000 and asked for $66,700.00.  Regions approved the loan for the full amount.

On 03JUN2020, Zsa Zsa asked Regions for a PPP Loan for Bouvier Hair, claiming that she had 10 employees and $183,600 average monthly payroll.  She asked Regions for $115,800.  Regions approved the loan for the full amount.  

Zsa Zsa's total theft from the US Taxpayers then was $182,500 from Regions + $427,187.47 from Trustmark for a total of $609,687.47.

Time to Go Shopping!

After claiming that she only had one business, Zsa Zsa had two of her PPP Loans deposited into the same bank account at Trustmark.  Then our criminal mastermind paid for an Audi Q3 by sending a wire transfer from the account which was only funded via PPP Loans to the Rusnak Westlake Audi dealership.  She then wrote checks from the account to family members totaling $150,000.00.  She also wrote another $49,200 in checks to family members from one of her other PPP Loan accounts at Trustmark. 

The story in her Regions account was about the same.  She wrote out a $26,997.00 Cashier's Check and used it to pay cash for a Mercedes-Benz A-220 (VIN# WDD3G4EBCKW017692) which she registered to another family member.

Time to Go To Prison!

There were several other interesting purchases made with all of that money, as the Forfeiture requested by the court includes: 
  • a 2019 BMW 330 
  • a 2007 GMC Pickup truck 
  • a 2019 Mercedes Benz A220 
  • a 2017 Audi Q3 SUV 
  • a 2008 Ford Mustang GT 
  • and all the contents of eight bank accounts, $2400 seized when her house was searched and $1180 seized from her purse.

Let's Review . . . 

1. The banks have been encouraged -- HELP BUSINESSES SURVIVE -- if there is fraud, we will figure that out on the back end.  GET THE MONEY OUT THE DOOR and SAVE JOBS.

2. But they WILL FIND YOU.  If the number of employees you claim to have does not match the IRS tax records or the Alabama (or your state's) Department of Labor numbers, YOU WILL GET CAUGHT.

3. When your bank realizes your PPP Loan doesn't match your Payroll expenditures, YOU WILL GET CAUGHT.

4. If you attest (as required) that this is your ONLY PPP LOAN and then you file multiple applications, YOU WILL GET CAUGHT.

5. If you open new bank accounts to avoid payroll matching, the bank will eventually get around to checking that and YOU WILL GET CAUGHT.

6. And lastly, if you take your PPP Loan account and wire money to a car dealer, YOU WILL GET CAUGHT.

Don't be a Zsa Zsa.  If you committed fraud, return the funds and throw yourself on the mercy of the courts.



Wednesday, March 10, 2021

Microsoft Exchange: Patching Too Late If Already Compromised

On March 2, 2021, Microsoft accused a Chinese APT group which they name Hafnium of compromising 30,000 Exchange servers.  They announced four security vulnerabilities, known as 0-days, which refers to the fact that attackers had a reliable means of exploiting the vulnerability for which there was no patch.  In case your organization didn't go into full panic mode, GO PULL THE FIRE ALARM!  THIS IS SERIOUS!

Tom Burt, Microsoft's VP of Customer Security & Trust, released a blog post about Hafnium: New Nation-State Cyberattacks. Microsoft describes Hafnium as "primarily targeting entities in the United States for the purpose of exfiltrating information from a number of industry sectors, including infectious disease researchers, law firms, higher education institutions, defense contractors, policy think tanks and NGOs." According to my favorite APT Cross-reference chart, maintained by Florian Roth (Twitter: @Cyb3rOps) Hafnium is also referred to by Symantec as Ant. (They chose the name because one of the common webshells used for post exploitation was regularly hit by a web browser using the user agent "antSword/v2.1".  Both AntSword (中国蚁剑 ) and ChinaChopper (中国菜刀) are popular webshells used by Chinese attackers for many years.  

FireEye says there is no reason to believe the activity is limited to one threat actor and refers to the clusters of attacks as UNC2639, UNC2640, UNC2643.

FireEye associates UNC2639 with activity from IP addresses 165.232.154.116 and 182.18.152.105, both active at the time of the Microsoft announcement (March 2 and March 3).

FireEye associates UNC2640 with activity involving "web shell" files named "help.aspx" (MD5 4b3039cf227c611c45d2242d1228a121) and "iisstart.aspx" (MD5 0fd9bffa49c76ee12e51e3b8ae0609ac)

FireEye associates UNC2643 with the deployment of a Cobalt Strike Beacon (MD5 79eb217578bed4c250803bd573b10151) and the IP addresses 89.34.111.11 and 86.105.18.116.

FireEye says they began seeing this activity in January, which matches the reports from Microsoft that they were notified of this activity by security firm Volexity in January, however DEVCORE Research Team gets credit for trying to exploit marketing of the bug by calling the attack "ProxyLogon" and making a sexy webpage and logo for the attack, a la HeartBleed.  Fortunately, that really hasn't caught on, however their timeline is still very interesting. They found the first bug 10DEC2020 and the second 30DEC2020 and reported both to Microsoft on 05JAN2021 (as Tweeted by their Taiwanese researcher, Orange Tsai.)

Symantec makes clear that the actor which they call Ant (and Microsoft calls Hafnium) is definitely no longer the only attacker using these vulnerabilities. Symantec's diagram of the attack is useful:

Symantec's attack flow diagram 

Brian Krebs interviewed several researchers about the attack, including Steven Adair, who says his company, Volexity, has been seeing the bug since 06JAN2021.  See Krebs on Security: "At Least 30,000 US Organizations Newly Hacked via Holes in Microsoft's Email Software."

As Krebs and others have since pointed out, while 30,000 US-based organizations were known to be victims of Hafnium/Ant, now that the vulnerability is known, the attacks have grown to an astronomical number.  Why is this a problem?  The companies most likely to be running their own unpatched mail servers are also the least likely to be clueful enough to patch.

Both Forbes and WIRED now say that hundreds of thousands of servers have been compromised and the compromise count at one point was growing by "thousands per hour."


What To Do?  PATCH! (But it is quite possibly too late...)

Obviously, the most important thing to do is apply Microsoft's patches.  However it is VERY IMPORTANT TO UNDERSTAND that you may already be compromised.  Patching DOES NOT make you "un-hacked!"  Patch, but also follow the guidance from CISA on determining if you are already hacked.

The vulnerabilities are listed here, each linking to the Microsoft security alert associated with the CVE.


Unfortunately, smaller organizations tend not to patch, and rogue organizations within large organizations often run their own Exchange servers rather than following guidance to centralize. In a presentation I did for the Merchant Risk Council back in September 2020, we talked about the fact that CISA had put out a critical alert related to Office 365, calling it a "Top 10 Routinely Exploited Vulnerability" as well as its own alert, CISA Alert AA20-120A.  In that talk, we also mentioned how Rapid7's Tom Sellers had warned about unpatched Exchange Servers.  Sellers was actually talking about the "Critical" Exchange Server bug CVE-202-0688.  

In Rapid7's look at the data, "Phishing for SYSTEM on Microsoft Exchange (CVE 2020-0688)" originally published on 06APR2020 explained that a 24MAR2020 scan of the Internet found 357,629 vulnerable servers, 82.5% of those reachable from the public Internet, were unpatched for a CRITICAL vulnerability with a patch available since 11FEB2020.  EIGHT MONTHS LATER, Rapid7 repeated the test, and still found that 61% of those servers were still online and still vulnerable!  Further, 31,000 servers had not been patched since 2012, and 800 servers had NEVER been patched!

What do you think the chances are that they suddenly became patch-conscious on 02MAR2021?

It is quite likely, in this author's opinion, that MOST Internet-facing Exchange servers have been compromised.  How do you test to see if you are one of them?  Read on ...

WHAT TO DO?  SEE IF YOU ARE HACKED!



The CyberSecurity & Infrastructure Security Agency, CISA, part of the Department of Homeland Security, has provided comprehensive information on how to detect the attack, including a nice guide on how to use FTK Imager to capture memory from your Exchange Server and where to look for evidence of being compromised.

Please thoroughly review their recommendations found as Alert AA21-062A.

Many of their indicators come from Volexity, who also shares a video explaining the attack in their blog post from 02MAR2021, "Operation Exchange Marauder."  It should be noted that neither of the IP addresses from FireEye are included on this list.

In addition to the CISA guidance, Microsoft has released a script which can be run on your Exchange Server to look for signs of being compromised.  Their script is described in their Hafnium Targeting Exchange Servers blog post, but a direct link to the script is: 

https://github.com/microsoft/CSS-Exchange/tree/main/Security

This script scans the HttpProxy logs, the Exchange logs, and the Windows Application event logs for signs of exploitation.  Hopefully the bad guys haven't WIPED the logs!






Thursday, February 18, 2021

Mystery Shoppers Challenge Gift Card Warnings

 Have you ever seen those spam messages claiming they have a great job for you as a Mystery Shopper?  After seizing a check from a client (and then shredding it) a local bank let us check out the scam!  In this scam, a company claiming to be "Private Mart Auditors" says they have been contracted by WalMart to try to identify stores that are violating their policies by refusing to sell Gift Cards!  The project claims to actually be a partnership with the gift card companies themselves and the major retailers who sell them.


The criminals know that many companies have trained their personnel that if someone comes in and says "I'd like to buy $2,000 worth of Gift Cards!" they should ask probing questions to try to save someone from being scammed.  Some companies even have big signs on their registers, check-cashing terminals and gift card sales racks warning about scammers.  When we reviewed our Mystery Shopper instructions, we were told to validate our check by visiting their website ==> verifycheckatmet[.]org or verifycheckatbictoin[.]org.  (The instructions actually provide both URLs.)

What we learned at the website is that Wal-Mart's Audit Team had contracted our new employer to conduct an audit.  We were selected because some of the stores in our area were discouraging people from purchasing gift cards, despite the "Federal Reserve Global Campaign on Securities on Mobile Payments" requiring stores to encourage Gift Card purchases!


We wanted to proceed cautiously, so we validated each of the facts in our instructions just as they requested.  A few red flags came up, but these were easily explained by our new supervisor, Paul Newton.  Paul sends and receives texts from 574-777-6314 and uses the gmail account paulnewt005@gmail.com.  




First question -- why was this package, which claims to be from GNT Solutions at 5201 Thurman Way in Sacramento, California, being mailed through the US Postal Service from the Orlando, Florida area?

Second question -- if they are in Sacramento OR Orlando, why is the routing number on their check used exclusively for TD Bank branches in Maine?

Fortunately, we had an easy way to validate that OUR check was legitimate.  If we clicked the "Verify Cheque" button on the website, we could enter our name and check number.  If it was a valid check that had been issued by the company, it would instruct us to Proceed with Deposit.  If it was NOT a valid check it would tell us so, and instruct us what to do next.  So, we carefully entered our information: 

And ... we were in luck!  The check was totally valid!

According to our instructions, here's what we needed to do next:

1. Cash check or deposit at your Bank, then text your supervisor immediately via 574-777-6314 to receive further instructions.

2. Deduct your Salary $350 while you withdraw $2000 for your assignment.

3. Locate any 2 Wal-Mart stores near you.

4. Visit the first store and purchase 3 Wal-Mart gift card worth $400 each.

5. After purchasing the 3 cards successfully scratch each of the cards to reveal its code, take CLEAR pictures and send to your Supervisor on 574-777-6314.

6. Proceed to the second Wal-Mart store to purchase 2 cards worth $400 each, scratch each & take pictures to be sent to your supervisor.

7. With the help of your supervisor answer questions from the WAL-CARD AUDITORIA EVALUATION FORM then take a picture & sent to your assigned grading personnel via email to paulnewt005@gmail.com 

8. Keep the cards safely as they will be used for your second assignment provided you meet the pass mark otherwise you will be mailng them back to an address to be provided by your supervisor.

9. We encourage giving back to the society as such the moment result is sent to email, you are to purchase a Cashier's Check worth $30 at your bank in the name KIDNEY FOUNDATION. After purchase text your supervisor for further instructions on the purchased Cashier's check.

If we pass our "grade" we might be able to become a Permanent Contract employee, where we would earn $450 per assignment and do 3-4 assignments each week!  If we do well with that, we might become a "WAL-CARD-AUDITORIA CONTRACT" employee!  Then we would earn $600 per assignment and could do MORE than four assignments a week!

Now, if you are an unemployed person due to Covid and someone gives you a clear path to earning $150,000 per year, might you be tempted?  Other than our Check, here are the instructions and the PMA Evaluation Form that were also in our US Postal Service Priority Mail package.  (Click for full-size)


The Website - and possibly related scams!

Of course we also wanted to look into that website!  We used the Zetalytics Zonecruncher tool to check it out.  The domain name was registered at Public Domain Registrar, which wasn't shocking.  The last APWG report showed that with the exception of cyber criminal's FAVORITE Registrar NameCheap, PDR has recently been the second most common Registrar for BEC attacks, and this scam is definitely related, as we'll see.

APWG 4th Quarter 2020 Report

It is hosted at 67.220.184.146, and its nameservers, ns5.doveserver.com and ns6.doveserver.com are also located on 67.220.184.146 and .147.

ZoneCruncher data

One of my favorite things about ZoneCruncher's data is that it shows the "Start of Authority" record.  In this case it is telling us that the reseller to which this IP address space is assigned is "csf@smartweb.com.ng" 

One of the most common West African scams, besides the shipping of counterfeit checks, is various "delivery" scams.  These started with the earliest Nigerian Prince scams, but more frequently today involve a package of value (a box of diamonds, for example) that a soldier finds overseas and wants to ship to you to sell and split the profits.  Other times it is a "pet delivery" scam, where you anticipate having a pet shipped to you and the pet gets caught up in shipping.  As anticipated, we had plenty of these on this IP address.

One of the things that all of these sites have in common is a "TRACK Your Package" option.  This is where the scammers match pre-assigned tracking numbers to various conditions which require your payment to break a shipment free.  Pets may be "quarantine hold in customs" or valuables may be "inspection hold in customs."  Your scammer will send the website address with a tracking number so that you can look up "proof" of the situation.
  • https://regalcourierservice[.]com/track/
  • http://cargoexpedite[.]com/tracking.php
  • https://submarinecourierservice[.]com/track-your-shipment.php
  • https://www.safecargoeslogistics[.]com/?page_id=3731
Often you can find many websites with identical content but a different company name. Also a red flag.  For example:

http://ftcouriercompany[.]com/about.html (hosted on "our" IP address)
http://logitrex[.]net/about.html (hosted on 104.194.9.169, which leads to a whole new cluster of badness: 
==> https://wpsdelivery[.]com/
==> https://nexaglobalexp[.]com/tracking.html 
==> https://aimsair-ways[.]com/

But then we hit a gold mine!  The complete Soldier Romance Scam Support site!  (but that's the next blog post ...)









The Complete Soldier Romance Scam Support Site

 Yesterday we were reviewing a Work From Home "Mystery Shopper" scam, and ended by pointing out some of the scam shipping companies hosted on the same IP address.  But still on our same IP address, we hit a gold mine!  The complete Romance Scam with an Imaginary Soldier support site!  The webpage is: usmdept.com ... you know? the US Military Department?


This website has EVERYTHING an imaginary soldier might need in order to extract funds from his Romance Scam victim!

Let's start with the basics.  Do you love your soldier? At great risk to themselves, you can have a care package deployed, even into a combat zone!  If you REALLY love your soldier, you'll choose the $1700 Premium Care Package. (but if you're cheap, the $800 Mini Care package and the $1200 Airbourne Care Package are also available.)  What? He didn't get it? Do you have a Tracking Number? It's probably been held up in customs ...

https://usmdept.com/care-package/

Next, you'll want to chat with your soldier, right?  Because he is deployed on a Top Secret Mission, that's only possible if you purchase a Communication Permit.  You can buy Communication Permit cards ranging from the "Military Small Card" for $680 all the way up to the "Military Large Global Card" for $1150!


Of course, what you REALLY want is to have your soldier boyfriend or girlfriend come home and visit you, right?  Fortunately, there are several leave options available, including 3-week, 4-week, 2-month, and 6-month (Honeymoon Leave) durations.  "The above leave Duration are made available for you to choose and after you choose we would tell you the fee involved. ... The reasons of payment for emergency leave Application is to assist the USA military authority in replacement expenses and supporting of troops coming to take over duties for anyone going on emergency leave ... ensuring that our troops are protected and allowed to judiciously make use of their times for reasons they have applied and paid for."

Under the old military system, if a soldier refused to take a deployment to an area where they may be killed, they were just kicked out.  Good News!  "This policy has been mauled and we've been directed by the Department of Defense to bring forth the Deployment Declination option. ... Unfortunately, a deployed soldier is ineligible to apply ... Only a loved one, family, child, fiance, sibling, or close friend is eligible to apply." 



But wait, you thought that would be free?  "after the DOD spending weeks, even months, preparing for the mission, putting everything in place, setting all up having you in mind, the wasted resources and finances already made, because of this a fee is attached for the declination form to be processed and accepted." Just email support@usamilitarysupport.com to get the process started.



The real goal of having an Imaginary Soldier Boyfriend or Girlfriend is marriage though, right?  Good News!  That is TOTALLY OK with the US Military Department of Scammers!

Although, "There are also rules on who can receive a military ID card and military benefits. To receive a military ID card and benefits, including health care, a military spouse must be legally married to the service member. The military does not recognize common law marriage or engagements.  Registering a spouse for benefits has its fee."  Just click "Contact Us" and the scammers will gladly walk you through the process of getting a MILITARY Marriage License, based entirely on how much money they think you might have, of course.



Although it should not be necessary, if you really need your Imaginary Soldier to resign from the military, that is possible as well.  Doing so, however, "attracts a one time fee, which will be needed to process the request."  As with declination of deployment, "only a loved one ... is eligible to apply."


While this is the first time that *I* saw a site like this, as usual, FireFly and the experts at ScamSurvivors.com had already seen the pattern.  A great post there which talks about a previous or similar version of this site from August 2020 is here on her forum ==> Article: US Military Welfare - usamilitarywelfare.com


Friday, February 12, 2021

Phone Company Insiders Helped Global Sim-Swapping Gang Steal Millions in Cryptocurrency

 This week law enforcement agencies around the world made press releases about the arrest of SIM Swapping criminals.  The UK's National Crime Agency says "eight men have been arrested in England and Scotland as part of an investigation into a series of SIM swapping attacks, in which criminals illegally gained access to the phones of high-profile victims in the US.  They say these attacks targeted "numerous victims throughout 2020, including well-known influencers, sports stars, musicians, and their families."  NCA credits the US Secret Service, Homeland Security Investigations, the FBI, and the Santa Clara California District Attorney's Office for helping to uncover the network.

Paul Creffield, head of operations in the NCA's National Cyber Crime Unit and Assistant Director Michael D'Ambrosio were quoted in the NCA's press release, "Brits arrested for sim swapping attacks on US celebs" on February 9th.  The @NCA_UK Twitter thread shared the additional details that the men were between the ages of 18 and 26.

https://twitter.com/NCA_UK/status/1359232883118981133


Meanwhile, a 10FEB2021 press release from Europol proclaimed "Ten hackers arrested for string of sim-swapping attacks against celebrities." The EU report says that 8 criminals were arrrested on 09FEB2021 (presumably those in the UK) with earlier arrests of one criminal in Malta and one in Belgium of members "belonging to the same criminal network."  

A SIM, or Subscriber Identity Module, is the little chip that goes inside a phone and ties that phone to a particular account at a particular mobile provider.  If the phone provider believes you have a new phone, they can tell their system, this is the new SIM number that should be linked to your account.  They don't actually need to know what model of phone it is, or where in the world it is.  If your account says your phone number is assigned to a new SIM, your phone stops ringing and the new phone starts.

The group used SIM swapping to intercept SMS messages intended for the true owner of the phone and route those messages to a phone controlled by the criminals.  This allowed them to access many apps and ask for password resets, which often confirm the request is intended for the correct user by sending a "Two Factor Authentication" request in the form of an SMS message.  Some crypto currency exchanges use an even stronger method, of requiring confirmation both by an SMS to the phone and by email. Unfortunately, if the criminals have SIM-swapped the phone, they also may have used it to gain control of the email used by the victim as well!  

Europol correctly describes the primary method of SIM-swapping when they say in the press release above, "This is typically achieved by the criminals exploiting phone service providers to do the swap on their behalf, either via a corrupt insider or using social engineering techniques."

How do Phone Company Insiders enable these scams? In a case that was curiously released to the public simultaneously with those above, we get a US-based example.

The simultaneous announcement by the FBI of charges against a Verizon Customer Service employee, Stephen DeFiore of Brandon, Florida is curiously timed, given that his charges thus far were based on crimes from 2018.  According to Stephen's LinkedIn, he worked from 2014 to 2017 as a Verizon Customer Service Rep in  Rochester, New York, and afterwards in Bradon, Florida:



On February 8, 2021, the US Attorney in the Eastern District of Louisiana announced charges against Stephen Daniel Defiore "for his role in a SIM Swap scam that targeted at least nineteen people, including a New Orleans-area physician."  It goes on to say "From August 2017 until November 2018, DEFIORE worked as a sales representative for Phone Company A. In that capacity, DEFIORE had access to the accounts of Phone Company A's customers, including the ability to switch the subscriber identification module (SIM) card linked to a customer's phone number to a different phone number.  Between October 20, 2018 and November 9, 2018, DEFIORE accepted multiple bribes, typically in the amount of approximately $500 per day, to perform SIM swaps of Phone Company A customers identified by a co-conspirator."

DEFIORE would receive a message telling him a customer's phone number, their four-digit PIN, and a SIM card number to which the phone number was to be swapped.  Defiore received his payments via CashApp to his account: $Beefy123.  H

The New Orleans doctor lost his Binance, Bittrex, Coinbase, Gemini, Poloniex, ItBit, and Neo Wallet accounts.  In this case, Defiore swapped his SIM card address to one that was actually in an Apple iPhone 8 with the IMEI (Interrnationa Mobile Equipment Identity number) 356703087816582, which was in the possession of Richard Li. 

His co-conspirator in the US, Richard Li, was actually charged by the Department of Justice on 09JUN2020.  Li is why the UK case mentions California, rather than Louisiana or Florida.  Richard Yuan Li was a 20 year old college student in San Diego, California, living in a dorm room in Argo Hall on the campus of UCSD (The University of California San Diego). He registered the cell phone to which the SIM swap occurred using his own "me.com" email address, which began with "ryli" (Richard Yuan Li).

According to the charges against Li, he participated in at least 28 SIM swaps between 11OCT2018 and 06DEC2018. In the case of the Louisiana doctor, even after the doctor regained his cell phone, he was contacted by Li who said he had accessed nude photos on the doctor's gmail account that was also linked to the phone and that he demanded 100 Bitcoins or he would release the photos.

My favorite photo of the US SIM swapper.  (Sorry, couldn't resist!)  Master criminal? Or dumb kid who happened to work at a phone store and couldn't resist the temptation of $500 per day.  You decide.


This case would not be the first linking UK criminals with US Phone company employees.  In 2019, a hacking group calling itself "The Community" paid bribes to three phone company employees, Jarratt White and Robert Jack, both 22 year-olds working at phone stores in Tucson, Arizona, and Fendley Joseph, a 28 year-old in Murrietta, California, to carry out SIM swaps for their group.  Ireland-based hacker Conor Freeman, aged 20, was charged in that case for seven SIM-swaps that led to the theft of $2,416,352 worth of cryptocurrency.  It is unknown at this time if the current cases are further work of "The Community" or its former members.  The Community wasn't a place online, just the name of their group.  Most of their members were participants on the OG Users forum. For example Jarratt White, who worked at an AT&T store, used the handle ".O." on Telegram and received payments via LocalBitcoins and PayPal, where his email "jarrattw@gmail.com" was linked.  AT&T confirmed that WHITE had performed 29 unauthorized SIM swaps.  Robert JACK, also an AT&T contractor who worked in their store in Tucson, also performed 12 SIM swap.  Fendley JOSEPH worked at a Verizon store in Murrietta and also communicated with The Community members via Telegram. He was also identified by his PayPal account where he received $3,500 in bribes (fendleyvzw@gmail.com) 

Ireland's Conor Freeman was ultimately not extradited to the US, although he was arrested by the Garda at his home in Glenageary Court, Dun Laoghaire in May 2019, based on the US charges.  The failure to extradite was another example of the US Attorney's boasts of maximum sentence backfiring.  They often will make public threats at the time of arrest such as "if the maximum sentence is given, they will face 108 years in prison!"  Then when the actual sentence is handed out, they get six years.  Or two.  The threat, however, is enough that European courts say "what a cruel and unusual sentence!" and argue that sentencing a SIM swapper to a greater sentence than a rapist or murdered is ludicrous.  





Thursday, November 26, 2020

Major Nigerian Phishing and BEC Actors, SSGToolz and CeeCeeBossTMT, Arrested by Nigerian Police and Interpol

 An Interpol headline on November 25, 2020 announces "Three arrested as INTERPOL, Group-IB and the Nigeria Police Force disrupt prolific cybercrime group" however the article does not name the suspects.  The Interpol article says the three are "believed to be members of a wider organized crime group responsible for distributing malware, carrying out phishing campaigns and extensive Business Email Compromise scams."  Interpol's Craig Jones says the year-long investigation was known as "Operation Falcon."

The Nigerian Police actually did a press release about the trio on November 19th.  From that we find photos of the three criminals and more information about their crimes and names. The leader of the trio, Onuegwu Ifeanyi, is known online as SSGToolz.  According to the Nigerian Police, he "specializes in creating, designing, and selling phishing links and hosting malware on websites used by the gang for phishing and hacking purposes.  He collects charges running into several millions of naira from other fraudsters he mentors and improves their phishing capabilities."
Onwuka Emmanuel Chidiebere, also known as Ceeceeboss TMT, graduated from Imo State University and specializes in Business Email Compromise (BEC) and hacking. His laptop had over 50,000 email accounts with passwords harvested from various individuals and businesses worldwide.
CeeCeeBoss TMT recruited the third of the trio, Ikechukwu Ohanedozie, who was known as Dozzy. A medical school student also from Imo State, Dozzy's job was sorting out the email accounts and doing research "to determine financial strengths of prospective victims and pass the information to Ceeceeboss.
SSGToolz was not at all discrete with his work, creating his own domain for his tools, appropriately named ssgtoolz[.]net.  From there we see that he also used the gmail account ssgtoolz@gmail.com, which was associated with the creation of 85 domain names.

Some of these domain names were used to anchor other types of fraud, for example "c-clh[.]com" was confirmed to be hosting malware on 17JUL2020 and 19JUL2020, and as recently as 22SEP2020, which VirusTotal says was detected as Andromeda, Fareit, or Lokibot by various anti-virus vendors.

He also used this domain to host phish, such as "www.hainanbank.com.cn.c-clh[.]com" 

According to the ZoneCruncher tool from Zetalytics, At least 76 domains of his domains were observed resolving in their Passive DNS systems.  Many of them were "look alike" domains, likely used for sending malicious email.  Some xamples of these would include: 

agogpharrna[.]com (the "rn" supposed to look like an "m" to imitate agogpharma) 
iescornputers[.]com (the "rn" supposed to look like an "m" for iescomputers) 
tataintiernational[.]com (an extra "i" to imitate tatainternational) 
owenscorming[.]com (an "m" instead of an "n" for OwensCorning) 

Others seem more targeted as general "technical" phish, such as "server-update-mail-verification[.]com" which he registered 12JUN2019, or "itbackupserver[.]com" registered the same day.


CeeCeeBossTMT liked to boast of his wealth on Instagram, although he gave God Almighty all the thanks for the proceeds of his crime.  He also liked to imply that his hard work in the music studio was somehow the source of his wealth, rather than the millions he stole from innocent victims around the world.


Gotta admit, I'm thinking of finding that green track suit and shoes combo for myself.  What do you think?  Also, can anyone tell me which South African airport that top left shot was taken in?

The "TMT" coincides with his TMT Liquor Store, which he frequently tags in his posts.  TMT Liquor shares their WhatsApp Number, +234 901 069 2587 on their Instagram Bio @tmtliquorstore.

We look forward to hearing more about how these three are tied into the larger infrastructure of cybercrime in Nigeria.  If you have more information, please do reach out!



Sunday, November 15, 2020

ENISA: Top 15 Threats: Spam, Phishing, and Malware!

Part One of this post, describing the many components of "The Enisa Cybersecurity Threat Landscape" went over ENISA's Year in Review, the emphasis on Cyber Threat Intelligence, Sector specific threats, Research Topics, and Emerging Trends.  This is "Part Two" where we review the 16 documents that ENISA released to cover their "Top 15 Cyber Threats" report. In particular, we look at the Top 5.

ENISA's Top 15 Threats report starts with this summary document: 


The list of the Top 15 Threats is an annual list from ENISA, with only slight changes in positions for the various threats since last year. Malware remains in the Number 1 spot, and Web-based attacks remains Number 2. Phishing actually increased from 4th to 3rd position. Spam also rose this year, from 6th to 5th position. The threat making the greatest movement was Identity Theft, jumping from 13th to 7th position!
    
  A full report from ENISA is available for each of the topics below. Click to access each one. I'll only comment on a few in this blog post!
    1. Malware
    2. Web-based Attacks
    3. Phishing
    4. Web Application Attacks
    5. Spam 
    6. DDOS 
    7. Identify Theft
    8. Data Breach 
    9. Insider Threat
    10. Botnets
    11. Physical manipulation, damage, theft and loss
    12. Information Leakage 
    13. Ransomware
    14. Cyber espionage
    15. Cryptojacking 

#1 Cyber Threat - Malware


ENISA ranks Malware as the #1 threat again, pointing out several troubling trends.  Detection of malware on Business-owned Windows computers went up 13% from the previous year, and 71% of malware infections had spread from one infected user to another.  46.5% of malware delivered by email used a ".docx" file extension, indicating that our continued unsafe business practice of sharing Word documents by email continues to put our organizations and our employees at risk!  Another change was that 67% of malware was delivered via an encrypted HTTPS connection -- the "increased safety" of having encrypted web pages has also greatly increased our difficulty in understanding when an employee is receiving malware by visiting a webpage.

The number one malware family in this reporting period was Emotet, which targeted US-based businesses 71% of the time and UK targets 24% of the time.  

An increasing number of banking trojans were also seen that targeted the Android operating system.  Top families included Asacub, SVPeng, Agent, Faketoken, and HQWar.

 The so-called File-less Malware was also a significant attack method, often using Windows Management Instrumentation or PowerShell scripts to perform complex attacks more or less "at the command line" rather than by downloading a Windows PE Executable.

For C2-based malware, a growing trend in having Russian-based Command & Control servers was observed, with the likelihood of a Russian-host going up 143% from the previous reporting period.  these malware families included Emotet, JSECoin, XMRig, CryptoLoot, Coinhive, Trickbot, Lokibot, and AgentTesla (according to MalwareBytes, quoted in the report.)

ENISA says that 94% of all malware deliveries were via email during 2019, quoting from the EC3 Internet Organised Crime Threat Assessment.   Many such attacks were enabled by employee behavior and gained extended reach due to vulnerabilities in Windows, several of which allowed Remote Code Execution, making malware attacks "wormable" and able to spread throughout the enterprise, often due to poor patch management.

Proposed actions in this report include the need for better in-bound screening, including the ability to decrypt and inspect SSL/TLS traffic as it comes into the network, including web, email, and mobile applications.  Security policies must also be updated to include what processes and escalations must occur "post-detection" in the case of an infection.  Log monitoring must be improved.  

One suggestion that I strongly agree with -- "Organizations need to disable or reduce access to PowerShell functions" -- so much malware this year, especially ransomware, would be stopped cold in its tracks if PowerShell were not so prevalently deployed and enabled in our organizations!  

Although it is not mentioned by ENISA, my favorite document for understanding PowerShell threats is "The art and science of detecting Cobalt Strike" from our friends at Talos Intelligence!  More than any other attack platform, Cobalt Strike is being abused by malicious actors in order to fully compromise domains, often for the purpose of exfiltrating and encrypting for ransomware.

Please refer to the full report for additional recommendations.

#2 Cyber Threat - Web-Based Attacks


Web-Based Attacks are broken into four main vectors by ENISA.  Drive-by downloads, Watering hole attacks, Form-jacking, and Malicious URLs. 

As noted in part one, due to the age of the reporting window (January 2019 to April 2020) some of the particular attacks noted are more historical and of less keen interest by this time, however a couple trends are worth calling attention to.

"MageCart" attacks continue to be a prominent method for acquiring financial credentials.  Because of the vast popularity of a small handful of online "checkout" systems, many organized crime groups are investing heavily in hackers who have "nation-state" level capabilities in order to create new zero day attacks into these systems.  Shoppers are basically defenseless as their order information is transparently transmitted to criminals while they shop at even the largest and most prominent "trust-worthy" online vendors. 

In addition to browser vulnerabilities that can make watering hole attacks quite successful, attackers are also attacking popular web browser extensions, which often have less rigorous security updates than the base browser products themselves.

Content Management Systems also present an enormous footprint of vulnerability as platforms such as WordPress provide millions of vulnerable websites that can be used at will by hackers to host both phishing sites and malware payload files.

#3 Cyber Threat - Phishing


Phishing has historically been email-based crime that lures a target to an illicit website via a social engineering email.  It is the key to $26 Billion in losses due to Business Email Compromise, as well as to a growing number of scams linked to the COVID-19 Pandemic.  In the FIRST MONTH of the COVID-19 Pandemic, ENISA reports that phishing attacks increased 667%!  As previously mentioned, these dangerous emails are now very likely to contain a trojaned Microsoft Office family document.  

ENISA warns that phishing URLs are now being seen more frequently delivered via SMS, WhatsApp, and Social Media platforms, expanding beyond the original email platform.

While phishing historically targeted financial institutions, ENISA says that webmail became the leading target of phishing in Q1 of 2019, with Microsoft 365 services being particularly targeted.

User education and user reporting remains a critical strategy, especially as ENISA says that 99% of phishing emails require human interaction in order to be effective.

The most effective means to combat phishing continues to be the implementation of 2FA. If a phisher cannot gain access to an account with simple userid and password, many schemes would be immediately blocked.

From a financial perspective, wiring money should ALWAYS require out of band confirmation.  The cost of not getting the confirmation is simply too high, with some Business Email Compromise attacks costing tens of millions of dollars!

#5 Cyber Threat - Spam 


As the ENISA report on Spam menions, after 41 years of dealing with spam, "nothing compared with the spam activity seen this year with the COVID-19 pandemic!"

During the reporting period, Emotet, Necurs, and Gamut were some of the top spamming families.

Some other findings: 
85% of all emails exchanged in April of 2019 were spam, a 15-month high.
13% of data breaches could be traced back to malicious spam.
83% of companies were unprotected against email-based brand impersonation (DMARC)
42% of CISOs reported dealing with at least one spam-based security incident.

To bring this category up to date, we noticed that ENISA was fond of the Quarterly Spam & Phishing reports from Kaspersky.  Please find below links to the 2020 Q1, Q2, and Q3 reports from Kasperky, which will technically be part of NEXT year's ENISA reporting:

Kaspersky found that throughout the third quarter, spam was at least 48.9% of all email sent, a slight decline from Q2, however the portion of spam containing malicious emails was up significantly.  Kaspersky identified 51 Million malicious attachments in that quarter, with 8.4% of them being the keylogger commonly known as Agent Tesla (Kaspersky uses the name "Trojan-PSW.MSIL.Agensla.gen"). Microsoft Office documents exploiting CVE-2017-11882 were the second most common.

They also noted 103 million phishing attacks, with the top targeted sectors being Online Stores (19.2%) and Global Web Portals (14.48%) which would include Office365.  Only 10.8% of the phishing attacks observed by Kaspersky targeted banks!


My favorite spam campaign here was the "FTC Official Personal Data Protection Fund" which claimed that the Federal Trade Commission had found that the recipient was a victim of "personal data leakage" and they were eligible to be compensated for that loss, if they just filled out a simple form on their website (which harvested personal data, including credit card and social security number.)