Announcement

Collapse
No announcement yet.

Blackshades Trojan Users Had It Coming

Collapse
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

  • Blackshades Trojan Users Had It Coming

    By Brian Krebs

    The U.S. Justice Department today announced a series of actions against more than 100 people accused of purchasing and using “Blackshades,” a password-stealing Trojan horse program designed to infect computers throughout the world to spy on victims through their web cameras, steal files and account information, and log victims’ key strokes.

    While any effort that discourages the use of point-and-click tools for ill-gotten gains is a welcome development, the most remarkable aspect of this crackdown is that those who were targeted in this operation lacked any clue that it was forthcoming.


    The Blackshades user forum.

    To be sure, Blackshades is an effective and easy-to-use tool for remotely compromising and spying on your targets. Early on in its development, researchers at CitzenLab discovered that Blackshades was being used to spy on activists seeking to overthrow the regime in Syria.

    The product was sold via well-traveled and fairly open hacker forums, and even included an active user forum where customers could get help configuring and wielding the powerful surveillance tool. Although in recent years a license to Blackshades sold for several hundred Euros, early versions of the product were sold via PayPal for just USD $40.

    In short, Blackshades was a tool created and marketed principally for buyers who wouldn’t know how to hack their way out of a paper bag. From the Justice Department’s press release today:

    “After purchasing a copy of the RAT, a user had to install the RAT on a victim’s computer – i.e., “infect” a victim’s computer. The infection of a victim’s computer could be accomplished in several ways, including by tricking victims into clicking on malicious links or by hiring others to install the RAT on victims’ computers.

    The RAT contained tools known as ‘spreaders’ that helped users of the RAT maximize the number of infections. The spreader tools generally worked by using computers that had already been infected to help spread the RAT further to other computers. For instance, in order to lure additional victims to click on malicious links that would install the RAT on their computers, the RAT allowed cybercriminals to send those malicious links to others via the initial victim’s social media service, making it appear as if the message had come from the initial victim.”

    News that the FBI and other national law enforcement organizations had begun rounding up Blackshades customers started surfacing online last week, when multiple denizens of the noob-friendly hacker forum Hackforums[dot]net began posting firsthand experiences of receiving a visit from local authorities related to their prior alleged Blackshades use. See the image gallery at the end of this post for a glimpse into the angst that accompanied that development.

    While there is a certain amount of schadenfreude in today’s action, the truth is that any longtime Blackshades customer who didn’t know this day would be coming should turn in his hacker card immediately.

    In June 2012, the Justice Department announced a series of indictments against at least two dozen individuals who had taken the bait and signed up to be active members of “Carderprofit,” a fraud forum that was created and maintained by the Federal Bureau of Investigation.

    Among those arrested in the CarderProfit sting was Michael Hogue, the alleged co-creator of Blackshades. That so many of the customers of this product are teenagers who wouldn’t know a command line prompt from a hole in the ground is evident by the large number of users who vented their outrage over their arrests and/or visits by the local authorities on Hackforums, which by the way was the genesis of the CarderProfit sting from Day One.

    In June 2010, Hackforums administrator Jesse Labrocca — a.k.a. “Omniscient” — posted a message to all users of the forum, notifying them that the forum would no longer tolerate the posting of messages about ways to buy and use the ZeuS Trojan, a far more sophisticated remote-access Trojan that is heavily used by cybercriminals worldwide and has been implicated in the theft of hundreds of millions of dollars from small- to mid-sized businesses worldwide.


    Hackforums admin Jesse “Omniscient” LaBrocca urging users to register at a new forum — Carderprofit.cc — a sting Web site set up by the FBI.

    That warning, shown in the screen shot above, alerted Hackforums users that henceforth any discussion about using or buying ZeuS was verboten on the site, and that those who wished to carry on conversations about this topic should avail themselves of a brand new forum that was being set up to accommodate them. And, of course, that forum was carderprofit[dot]eu.

    Interestingly, a large number of the individuals rounded up as part of the FBI’s CardProfit sting included several key leaders of LulzSec (including the 16-year-old individual responsible for sending a heavily armed police response to my home in March 2013).


    The CarderProfit homepage, which featured an end-user license agreement written by the FBI.

    In a press conference today, the FBI said its investigation has shown that Blackshades was purchased by at least several thousand users in more than 100 countries and used to infect more than half a million computers worldwide. The government alleges that one co-creator of Blackshades generated sales of more than $350,000 between September 2010 and April 2014. Information about that individual and others charged in this case can be found at this link.

    For a glimpse at what the recipients of all this attention went through these past few days, check out the images below.


    The Hackmaster

  • #2
    More than 90 people nabbed in global hacker crackdown

    By Evan Perez, Shimon Prokupecz and Tom Cohen, CNN

    Washington (CNN)

    It is nicknamed "creepware," and more than half a million people around the world have been prey to its silent computer snooping.Miss Teen USA Cassidy Wolf was one of them in a well-publicized case of hacking associated with the malware called Blackshades.

    Now, an international crackdown by the FBI and police in 19 countries has brought more than 90 arrests in what authorities say is a serious strike against a widespread and growing problem.

    U.S. Attorney Preet Bharara in New York told reporters the global investigation "exposed and crippled a frightening form of cybercrime that has affected hundreds of thousands of users around the world."

    The sweep, capping a two-year operation, was coordinated so suspects didn't have time to destroy evidence. It included the arrest of a Swedish hacker who was a co-creator of Blackshades, Alex Yucel, who was apprehended in Moldova.

    In total, one of the largest global cybercrime crackdowns has yielded the arrests of more than 90 people linked to the Blackshades malware, with more than 300 searches conducted, Bharara said.

    Others arrested included Michael Hogue, who was nabbed in Arizona in 2012, pleaded guilty last year and now was cooperating with federal authorities, according to Bharara. Two arrests in New York picked up Kyle Fedorek and Marlen Rappa, who both were charged with conspiracy to commit computer hacking and computer hacking, said documents posted on the website of Bharara's office.

    Fedorek also faces a charge of access device fraud, his charging document said.

    'Creepware'The malware, which sells for as little as $40, can be used to hijack computers remotely and turn on computer webcams, access hard drives and capture keystrokes to steal passwords - without the victim ever knowing it.

    According to Bharara and the FBI, criminals have used Blackshades for everything from extortion to bank fraud, and it has become one of the world's most popular remote administration tools, or RATs, used for cybercrime in just a few years.

    "The RAT is inexpensive and simple to use, but its capabilities are sophisticated and its invasiveness breathtaking," Bharara said. "For just $40, the BlackShades RAT enabled anyone anywhere in the world to instantly become a dangerous cybercriminal, able to steal your property and invade your privacy."

    To prove his point, the FBI released screen grabs showing how the malware works, including an ungrammatical message that would pop up on the computer screens of victims that said: "Your computer has basically been hijacked, and your private files stored on your computer has now been encrypted, which means they are impossible to access, and can only be decrypted/restored by us."

    Leo Taddeo, chief of the FBI's cybercrime investigations in New York, said the unprecedented coordination with so many police agencies came about because of concern about the fast growth of cybercrime businesses.

    "These cybercriminals have paid employees, they have feedback from customers - other cybercriminals - to continually update and improve their product," Taddeo said recently. While he spoke, agents took calls from counterparts working the case in more than 40 U.S. cities.

    Blackshades had grown rapidly because it was marketed as off-the-shelf, easy-to-use software, much like legitimate consumer tax preparation software. "It's very sophisticated software in that it is not very easy to detect," Taddeo said. "It can be installed by somebody with very little skills."

    Miss Teen USA spied on at home

    For victims whose personal computers were turned into weapons against them, the arrests bring reassurance. Wolf, the reigning Miss Teen USA, received an ominous e-mail message in March 2013.The e-mail, from an unidentified sender, included nude photos of her, obviously taken in her bedroom from her laptop. "Either you do one of the things listed below or I upload these pics and a lot more ... on all your accounts for everybody to see and your dream of being a model will be transformed into a porn star," the e-mail said.

    And so began what Wolf describes as three months of torture.

    The e-mail sender demanded better-quality photos and video, and a five-minute sex show via Skype, according to FBI documents filed in court. He told her she must respond to his e-mails immediately - software he had installed told him when she opened his messages.

    "It was traumatizing," Wolf told CNN's "Anderson Cooper 360." "It's your bedroom. That's your most private, intimate space and that's where you should feel the most safe."

    She now has a new laptop and covers the webcam with a sticker. A former classmate she knew, Jared Abrahams, had installed Blackshades malware on Wolf's laptop. In March, the 20 year old computer science student was sentenced to 18 months in prison after pleading guilty to extortion and unauthorized access of a computer. Abrahams had been watching her from her laptop camera for a year, Wolf later learned. The laptop always sat open in her bedroom, as she played music or communicated with her friends.

    According to FBI documents, Abrahams had used Blackshades to target victims from California to Maryland, and from Russia to Ireland. He used the handle "cutefuzzypuppy" to get tips on how to use malware and told the FBI he had controlled as many as 150 computers.

    Hackers issued warnings

    Computer hacker forums lit up last week as law enforcement officials around the world began knocking on doors, seizing computers and making arrests around the world.On the popular websites where cyber-criminals buy and sell software kits and help each other solve problems, hackers issued warnings about police visits to their homes. The hackers quickly guessed that a major crackdown was under way on users of Blackshades.

    In New York City, about two dozen FBI cyber-crime investigators holed up in the bureau's special operations center tracked the investigation.Rows of computer screens flickered with updates from police in Germany, Denmark, Canada, the Netherlands and elsewhere. Investigators followed along in real time as hundreds of search warrants were executed and suspects were interviewed.

    Six large computer monitors displayed key parts of the investigation. Agents kept an eye on one screen showing a popular website where Blackshades was sold. The FBI has taken down the site. Another monitor showed a map of the world displaying the locations of the 700,000 estimated victims whose computers have been hijacked by criminals using the Blackshades software.

    Splotches of green on the map indicated concentrations of infected computers in highly populated parts of the United States, Europe, Asia and Australia.

    Weak security, victims' mistakes

    Cybercriminals often rely on weak links in computer security and mistakes by victims to infect computers. Many computer users don't update anti-virus software. Many click on links sent in messages on social media sites such as Facebook or in e-mail without knowing what they're clicking on. In seconds, malware is downloaded.

    Often, computer users have no idea infection has taken place. Taddeo, the FBI cybercrime chief, said the most common way criminals have used Blackshades to target victims is by sending e-mails that seem legitimate, perhaps with a marketing offer, and with a link to click. "Anyone who signs on to the Internet is potentially a victim of this tool," he said.

    In Wolf's case, she received a Facebook message related to teen pageants. When her computer was infected, it sent messages to other friends, whose computers also became infected. The episode has made Wolf a campaigner to urge young people to be better educated about online safety. She said her passwords are now more complicated and unique for each account, and she changes them often. She uses updated security software.

    "I really didn't think that everything I worked for could be lost because of this," she said. "This can happen to anybody."
    Last edited by dlevere; 05-20-2014, 07:34:15 AM.
    The Hackmaster

    Comment

    Working...
    X