Showing posts with label Dark Web. Show all posts
Showing posts with label Dark Web. Show all posts

Friday, April 21, 2017

Russian Hacker Selling Cheap Ransomware-as-a-Service On Dark Web

Tuesday, April 18, 2017 Swati Khandelwal


Ransomware has been around for a few years, but it has become an albatross around everyone's neck, targeting businesses, hospitals, financial institutions and individuals worldwide and extorting millions of dollars.

Forget about developing sophisticated banking trojans and malware to steal money out of people and organizations. Today, one of the easiest ways that can help cyber criminals get paid effortlessly is Ransomware.

This threat became even worse after the arrival of ransomware as a service (RaaS) – a variant of ransomware designed to be so user-friendly that anyone with little or no technical knowledge can also easily deploy them to make money.

Now, security researchers have uncovered an easy-to-use ransomware service that promises profit with just one successful infection.



Dubbed Karmen, the RaaS variant is based on the abandoned open-source ransomware building toolkit dubbed Hidden Tear and is being sold on Dark Web forums from Russian-speaking hacker named DevBitox for $175.

Like any typical ransomware infections, Karmen encrypts files on the infected PC using the strong AES-256 encryption protocol, making them inaccessible to the victim until he/she pays a large sum of money to obtain the decryption key from the attacker.

This new variant of ransomware-as-a-service (RaaS) provides buyers access to a web-based control panel hosted on the Dark Web with a user-friendly graphical dashboard that allows buyers to configure a personalised version of the Karmen ransomware.

The dashboard lets buyers keep a running tally of the number of infections and their profit in real time, allowing anyone with very minimal technical knowledge to deploy Karmen, threat intelligence firm Recorded Future said in a blog post published today.


Hacker: Don't Mess with my Malware; otherwise, Your Files are Gone!
Once infected, the Karmen ransomware encrypts the victim's files and shows a popup window with a threatening message warning users not to interfere with the malware; otherwise, they might lose all their files.



What's more interesting? Karmen automatically deletes its decryptor if a sandbox environment or analysis software is detected on the victim's computer to make security researchers away from investigating the threat.

Initial Karmen infections were reported in December 2016 by victims in Germany and the United States, while the sale in underground forums began in March 2017.

So far, 20 users have purchased copies of Karmen malware from DevBitox, according to Recorded Future, while three of those buyers have left positive reviews on their profile.

You can also watch a YouTube video demonstration which shows the RaaS in action.

How to Protect Yourself from Ransomware Threat?

Here are some important steps that should be considered safeguarding against ransomware infection:


Always keep regular backups of your important data.
Make sure you run an active anti-virus security suite of tools on your system.
Do not open email attachments from unknown sources.
Most importantly, always browse the Internet safely.

Tuesday, November 1, 2016

Tor: The smart person's guide





By Dan Patterson | October 31, 2016, 12:15 PM PST

This comprehensive guide covers everything you need to know about Tor, the onion router web browser that allows users to access the Dark Web and other encrypted websites.

When privacy is outlawed, only outlaws will have privacy. And digital outlawswill probably use Tor. An acronym for 'the onion router', Tor is a free web browser and suite of open source software that enhances user privacy by encrypting web packets and browsing activity.

Tor is complex, yet easy to install and operate. The tool is widely used by reporters, political dissidents, hackers, and Dark Web profiteers to communicate anonymously. Tor enabled the Arab Spring, is used by millions of Chinese users to skirt the Great Firewall, and helps sources and whistleblowers safely share vital information with reporters. Conversely, the encrypted browser also allows hackers to snoop safely, and has helped illicit Dark Web markets flourish.


TechRepublic's smart person's guide is a routinely updated "living" precis loaded with contemporary information about about how the onion router works, who Tor affects, and why privacy-enhancing software is important.
Executive summary
What is it: Though Tor is built on the Firefox open source protocol, it's actually actually a number of integrated technologies. The browser itself carefully mitigates common web tracking tools like cookies and analytics systems. The Tor network is composed of thousands of servers around the world. When a user browses with Tor, web activity and packets are bounced through each server, obfuscating the originating and destination IP address.
Why it matters: As web privacy erodes the Tor foundation argues that the platform helps preserve free speech free thought.
Who it affects: From activists to hackers to Dark Web surfers, many users depend on Tor to protect their identity, and often their lives. Companies and consumers may need Tor to protect sensitive web actions.
When it's happening: The tech powering the onion router was

Tuesday, September 27, 2016

Yahoo Confirms 500 Million Accounts Were Hacked by 'State Sponsored' Hackers


yahoo-data-breach
500 million accounts — that's half a Billion users!

That's how many Yahoo accounts were compromised in a massive data breach dating back to 2014 by what was believed to be a "state sponsored" hacking group.

Over a month ago, a hacker was found to be selling login information related to 200 million Yahoo accounts on the Dark Web, although Yahoo acknowledged that the breach was much worse than initially expected.

"A recent investigation by Yahoo! Inc. has confirmed that a copy of certain user account information was stolen from the company's network in late 2014 by what it believes is a state-sponsored actor," reads the statement.

Yahoo is investigating the breach with law enforcement agency and currently believes that users' names, email addresses, dates of birth, phone numbers, passwords, and in some cases, encrypted and unencrypted security questions-answers were stolen from millions of Yahoo users.

However, the company does not believe the stolen information includes credit card information or any bank details of the affected users.

Yahoo has been criticized for its slow response to the data breach, but it is now in the process of notifying affected customers via emails and asking them to change their passwords, as well as security questions.

At this moment Yahoo did not provide any evidence on why it believed the breach was work of state-sponsored hackers.

Despite millions of people affected by the breach, the biggest victim here seems to be Yahoo itself.

The data breach reports come just as the company is trying to negotiate a deal to sell itself to Verizon for $4.8 Billion. So, if the breach reports negatively impact its share price, even for the time being, it could cost the company and its shareholders a slice of its buyout value.

Over past few months, a large number of data breaches have been reported to plague companies likeLinkedIn, MySpace, Tumblr, and VK.com as hackers put up for sale massive data dumps of user credentials stolen earlier in the decade.

Change your Password and Use Password Manager


Needless to say, users should immediately change their Yahoo account password. The company will also be prompting anyone who hasn't changed their password since 2014 to do so now.
"Additionally, Yahoo asks users to consider using Yahoo Account Key, a simple authentication tool that eliminates the need to use a password altogether," Yahoo suggests.
Also make sure that you also change your passwords on other online accounts if they use the same password, and enable two-factor authentication for online accounts immediately.

And once again, a strong recommendation: Don't reuse passwords.

If you are unable to remember different passwords for each site, you can adopt a good password manager that allows you to create complex passwords for various sites as well as remember them for you.

We have recently listed some best password managers that could help you understand the importance of password managers and help you choose a suitable one, according to your requirement
Related Posts Plugin for WordPress, Blogger...