LockBit Gang Uses Musks Internet Services and Launders Bitcoin in Hong Kong, China

[ad_1]

A security strategist who has spent months undercover on the darkweb released a report on Monday that provides insight into one of the world’s most notorious ransomware groups, claiming its members use internet services owned by billionaire Elon Musk. and launder money through Hong Kong and China.

LockBits’ online PR stunts have notably encouraged dark web subscribers to get union logo tattoos. (Photo: Courtesy of Jon DiMaggio, Analyst1) Jon DiMaggio, chief security strategist at threat intelligence platform Analyst1, released his findings on LockBit in a report titled Ransomware Diaries: Volume 1. said he used fake personas to communicate with members of the cybercriminal syndicate. and learn more about their operations.

LockBit is, right now, by far the worst among all ransomware gangs, DiMaggio told OCCRP. They have the most attacks by far, and that’s a fact. They lead the ransomware scene.

He explained that so far, relatively little effort has gone into profiling the actors behind these cybercriminal syndicates. I believe this is the first detailed, publicly available profile of a ransomware group, he said.

We need to get more people doing this, collecting data from the dark web, from these private channels, from press releases on their websites. All these fruits at hand, it helps us to better understand the opponent, said the expert.

According to its report, LockBits management interacted with the wider cybercriminal community through dark web forums and private channels under the pseudonym LockBitSupp. This character claims that the group accesses its back-end infrastructure through Starlink, a US satellite internet service owned by Musks SpaceX, and relies primarily on Bitcoin exchanges located in Hong Kong and China to launder the proceeds. of their ransomware campaigns.

The report also reveals LockBits’ close association with several other high profile ransomware gangs. While these relationships remain largely adversarial, due to the increasingly competitive nature of the global cybercriminal services market, LockBits executives appear to maintain a direct line of communication with several other criminal syndicates, including BlackCat, Hive, REvil, and DarkSide. /BlackMatter, widely recognized. having been responsible for the US Colonial Pipeline cyberattack in 2021.

Most of these relationships, not all of them, but most started out pretty well. But criminals have no ethics, so it’s usually only a matter of time before they step on each other’s toes and start getting angry, DiMaggio said. But at the end of the day, you still have a lot of people who all know each other, who all run in the same circles, and who stay in communication with each other.

LockBit also has ties to ransomware group Blackbasta, formerly Conti, which was behind a series of large-scale cyberattacks that effectively crippled the Costa Rican government last year. According to LockBitSupp, says DiMaggio, Blackbasta works for the Russian government, providing direct technical support to the FSB.

OCCRP has previously reported how Moscow is likely to turn to cybercriminal proxies to launch future attacks on critical infrastructure in the West. Partly because of the scale and sophistication of the Russian market for cybercriminal services, but also because of the plausible deniability offered by such tactics.

Beyond that, experts have also expressed concern over the growing diversification of services and operating models within the cybercriminal community in recent years. Competition in this increasingly reputation-driven criminal industry is fierce and has also created opportunities for accomplished hackers to work effectively as freelancers for multiple groups. This is a trend clearly reflected by LockBits’ operations over the past few months, during which the group’s management has engaged in multiple smear campaigns against rival ransomware gangs, as well as launching several stunts. public relations to promote their services and attract new blood.

The latter included a summer paper competition, in which contestants were encouraged to submit academic-style papers on different hacking techniques, with the winner receiving a cash prize. According to DiMaggio, this is a testament to LockBits’ original approach to educating potential customers about their operations, as well as identifying and recruiting smart, up-and-coming cybercriminals, although their executives’ showmanship apparently prompted censorship from other members of the cybercriminal community. .

At the end of the day, she’s a very successful person, but also very arrogant and insecure, says DiMaggio. They play a good game of chess, but there is a growing negative feeling among the other criminals, tired of the ego and the constant thumping of their chests.

Sources

1/ https://Google.com/

2/ https://news.google.com/__i/rss/rd/articles/CBMiiwFodHRwczovL3d3dy5vY2NycC5vcmcvZW4vMjctY2N3YXRjaC9jYy13YXRjaC1icmllZnMvMTcyNDQtbG9ja2JpdC1nYW5nLXVzaW5nLW11c2stcy1pbnRlcm5ldC1zZXJ2aWNlcy1sYXVuZGVyaW5nLWJpdGNvaW4taW4taG9uZy1rb25nLWNoaW5h0gEA?oc=5

The mention sources can contact us to remove/changing this article

[ad_2]

Leave a Reply

Your email address will not be published. Required fields are marked *

Related Posts