HN user

krebsonsecurity

242 karma
Posts1
Comments38
View on HN

Sometimes just a little bit DNS research can yield a lot of useful results.

Looking at the passive DNS records for the domain chanceletikva.org shows it references the email address davidm@yeahdim.co.il.That email address is tied to multiple website registrations for a person by the name of David Margaliot, and also Shoshana Margaliot.

A search on this name in Domaintools finds the name David Margaliot tied to at least 25 domains, including ezri.org.il, which is a very odd site that features a huge image of a young child who is apparently in the hospital holding a gift wrapped box with a teddy bear. The site asks for donations but has a strange mission statement: Ezri Association promotes life-saving innovation through a surveillance drone project for emergency response teams, the establishment of an international medical knowledge database, along with other technological initiatives".

I'll probably continue the rest of this in a follow-up story.

This is the way. You don't have to protect what you don't collect. Mullvad is an excellent example of this. They don't even want you to pick a password, and they're fine if you just mail them cash as payment.

Their earlier statement said they were aware of the CEO's history but were assured that part of his life was behind him. From that statement on March 15: “We were aware of the past affiliations with the entities named in the article and were assured they had ended prior to our work together,” the statement reads. “We’re now looking into this further. We will always put the privacy and security of our customers first and will provide updates as needed.”

https://krebsonsecurity.com/2024/03/ceo-of-data-privacy-comp...

Possibly useful info: A list of customer domains affected.

https://docs.google.com/spreadsheets/d/1wgKe1VrfNF8Afav1aJtM...

One caveat: This list should not be considered exhaustive or complete by any means. e.g. changing the URL slightly by incrementing or decrementing a number in the URL caused a slightly different set of customers to be listed. I didn’t have a chance to go through it all before they took it down (note to self: pillage BEFORE burning).

Some of the exposure in these cases is due to the fact that you have cybercriminals who've been doing the same things for more than a decade. That is a very long time in which to make just a few key opsec mistakes, and also most RU cybercriminals back then did not take as much care to cover their tracks as they do today.

Not sure if it's exactly the same thing as what you just mentioned, but I did write recently about criminals using paid Google ads to get their links for popular software downloads show up before even the first organic search result. And it includes the right icons and branding, and people click and are brought to a site that looks an awful lot like a site Microsoft might use to let you download Teams, and you get an information stealer program instead.

Tl;dr, there are multiple ransomware groups that are using this method to find new infostealer victims.

https://krebsonsecurity.com/2023/09/snatch-ransom-group-expo...

I thought about that also, and then one of the victims I talked to brought up a good point. An 8 character password with symbols and numbers doesn't sound like a great password today, but many of the accounts getting drained were tied to people who were very early LastPass users, and mostly longtime investors. Back then, affordable GPUs that can do 4 million hash cracking attempts per second weren't really a thing.

What I found was a lot of people made security assumptions and never revisited those assumptions. Or never fully did.

This is a fair assumption, although to be fair a botnet is essentially a collection of residential proxies.

And yes, Kopeechka controls the inbox, and only lets you see stuff going forward that matches the regex you specify.

Thank you for the reminder that I meant to add some of that context in the story (which I will do after finishing this comment). I've written several stories over the years about how the major email providers have erected various hurdles designed to increase the costs for spammers, most notably phone verification. However, much of the data I'm aware of on the topic of pricing is somewhat dated. Here's one study from 2011, which found Hotmail accounts were far cheaper than Gmail and others because they were basically way easier to register.

Accounts Craigslist PVA 10 (4) $4.25 [§B.1] Gmail Accounts 6 (5) $0.07 Hotmail Accounts* 21 (12) $0.007 Facebook Accounts* 24 (10) $0.07

I doubt these prices are relevant today, apart from the continued price disparity between email providers.

Source:

https://krebsonsecurity.com/wp-content/uploads/2011/07/sec11...

The location supplied by the LastPass notification for these login attempt IPs seems off. E.g., just taking some of the IPs most frequently posted here as sources of master password login attempts:

196.19.204.79 Stated location: India WHOIS: Poland Warszawa Unit 117, Seychelles (Legacy) AFRINIC AS202769 COOP, US

160.116.206.37 Stated location: Germany WHOIS: Affiliated Computing Services, South Africa AFRINIC AS262287 Maxihost LTD, BR

168.81.122.153 Stated location: Germany WHOIS: Seychelles AFRINIC 202769 COOP, US

Someone is probably putting bogus information into the routes for these IP ranges. But what do all of these IPs have in common? According to my records, they are all related to a dodgy hosting provider in the Netherlands called Ecatel, now called Qasi Networks or IP Volume. And this is all disputed AFRINIC IP space, as per:

https://krebsonsecurity.com/2019/12/the-great-50m-african-ip...

That's nice to hear. So the SIM swappers have to double their bribes.

I think the best solution is to cut the mobile providers out of the equation altogether. I've long advised removing your phone number from anything you can, or at least substituting a voip service that can't be social engineered over the phone. Some services don't let you use voip services for multi-factor or signup, so your mileage may vary.

Also, it's important where possible to use types of multi-factor that don't rely on your phone number. The tricky part is, so many sites will let you reset your password if you can receive a link via SMS at the phone number on file for the account. Which means anyone who SIM-swaps you then can reset the passwords on those accounts that allow SMS resets (which is a lot, still).

I actually wrote about that guy not long ago. His name is Mike O'Connor, and he owns bar.com, grill.com, place.com, and television.com, among others.

Probably his most famous domain was corp.com, which was recently bought by Microsoft because it turns out that older versions of Windows and other Microsoft products actually invited people to use corp.com for their internal Active Directory names. Problem is, when those machines are outside the internal network, they're constantly trying to share passwords and other sensitive data with corp.com.

More here:

https://krebsonsecurity.com/2020/02/dangerous-domain-corp-co...

https://krebsonsecurity.com/2020/04/microsoft-buys-corp-com-...

The story was clear that this was only an estimate of damages. It also stated clearly that the investigators were somewhat constrained by the fact that Ngo's services did not keep reliable records of sales -- only what customers searched for.

I should add that in this case, a search for John Smith in Massachusetts would turn up all the John Smiths in Mass. The resulting sale (if there was one) could have been for all of the John Smiths in Mass, some of them, or just one. We don't know. This also made the notification of victims much more difficult.

Spend a few minutes looking at the spam list threads linked in the article. This is not just a few people complaining. E.g.:

https://www.mail-archive.com/search?l=mailop%40mailop.org&q=...

There was a ton of material I did not include in the story, including a story from a company that had a client have 40 million phishing emails sent through their Sendgrid account, which it turns out was set up by an employee long ago who was no longer with the company and had not turned on 2FA (and probably was re-using passwords).

I started reporting this story almost a month ago after receiving more than 3 emails from different IT experts who were really frustrated with the amount of malware and phishing coming from Sendgrid accounts. They were frustrated because they couldn't block Sendgrid outright because too many companies they were expecting regular emails from used the platform.

The day before I published the story, I head from someone else who was getting phishing attacks spoofing Aruba Networks.

With the exception of Amex and Discover and a few others that issue their own cards, Visa and MasterCard don't issue the cards. Thousands of banks and credit unions do. They're the ones responsible for managing fraud on those accounts.

The banks decided the PIN part of chip and PIN only protects against physical theft -- what they call "lost and stolen" fraud.

Assuming that is accurate, given the costs associated in dealing with customers who forget their PINs, and the fact that Visa massively pushed for chip and signature, it's not hard to see why none of the banks wanted to be the hardest card to use in the wallet: Lost and stolen is an infinitesimal amount of loss for them when compared to counterfeits and e-commerce fraud.