News: 1625079664

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

International law enforcement op nukes Russian-language DoubleVPN service allegedly favoured by cybercriminals

(2021/06/30)


Europol, the US Department of Justice, and Britain's National Crime Agency have taken down a VPN service they claimed was mainly used by criminals – boasting that they hoovered up "personal information, logs and statistics" from the site.

The DoubleVPN site went dark yesterday after law enforcement agencies swooped on its servers, with a joint public statement this afternoon confirming that the takedown was genuine.

Led by the Dutch national police, servers behind DoubleVPN in multiple jurisdictions were seized by law enforcement.

[1]

Europol said the service was "heavily advertised on both Russian and English-speaking underground cybercrime forums," offering double, triple or even quadruple-layered VPN services to its customers.

[2]

[3]

This kind of setup is the old hacker joke about staying behind seven proxies put into practice: multiple VPN tunnels, onion-layered inside one another, were supposed to make accessing internet traffic inside them an extra difficult challenge for adversaries – whether law enforcement, criminals, or commercial rivals.

The operation began in October last year, a few months after a Franco-Dutch police operation to [4]take down encrypted comms app EncroChat .

DoubleVPN-dot-com's splash screen at the time of writing

Archive.org's [5]last capture of DoubleVPN-dot-com, on 28 June, shows it operating like most other VPN sites – complete with Russian text stating: "We have relatively high prices because customer payments for subscriptions are our only source of income. Ask yourself a question: where do free and cheap VPN services get money to pay for their expenses?"

[6]FBI paid renegade developer $180k for backdoored AN0M chat app that brought down drug underworld

[7]Hard cheese: Stilton snap shared via EncroChat leads to drug dealer's downfall

[8]Won't somebody please think of the children!!! UK to mount fresh assault on end-to-end encryption in Facebook

[9]Belgian police seize 28 tons of cocaine after 'cracking' Sky ECC's chat app encryption

Marketing text also said: "We can declare with full responsibility that there is no logging of client activity in our service," something which may or may not prove to be true when criminal charges are brought.

It seems unlikely that law enforcement would have killed off the service without finding a way of compromising it first – even if only to map out its infrastructure.

[10]

A UK-based node of the VPN service was the National Crime Agency's main target. John Denley, deputy director of the NCA's National Cyber Crime Unit, said in a [11]statement : "Double VPN was a multi-layered virtual private network service run by cyber criminals, to enable fellow cyber criminals to mask their identities online. It allowed them to anonymously communicate, identify victims then effectively sneak in and conduct reconnaissance on their systems as a precursor to launching a cyber attack."

NCA investigators also contacted a number of UK businesses that were apparently unlawfully accessed by DoubleVPN's operators.

The agency's deputy director added: "We know that criminal services such as DoubleVPN are used by the organised crime groups behind some of the world's most prominent ransomware strains, which have been used to steal data from and extort victims."

[12]

Alongside the EU coordinating agencies, the US and the UK's NCA were police agencies from Germany, the Netherlands, Canada, Sweden, Italy, Bulgaria, and Switzerland.

Police seizures of crime-linked web infrastructure has ramped up over the past year, with the EncroChat seizure followed by [13]the Anom chat app shutting down and revealing to its horrified criminal users that the whole service had been operated by the US FBI for years. ®

Get our [14]Tech Resources



[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YNzpfQcjyQpl5GMd5MpEBAAAAFM&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YNzpfQcjyQpl5GMd5MpEBAAAAFM&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YNzpfQcjyQpl5GMd5MpEBAAAAFM&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[4] https://www.theregister.com/2020/07/02/encrochat_op_venetic_encrypted_phone_arrests/

[5] https://web.archive.org/web/20210528044214/https://www.doublevpn.com/

[6] https://www.theregister.com/2021/06/08/fbi_trojan_shield/

[7] https://www.theregister.com/2021/05/25/cheese_fingerprint_prison/

[8] https://www.theregister.com/2021/04/19/uk_anti_encryption/

[9] https://www.theregister.com/2021/04/08/sky_ecc_drugs/

[10] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YNzpfQcjyQpl5GMd5MpEBAAAAFM&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[11] https://www.nationalcrimeagency.gov.uk/news/doublevpn-takedown-nca-takes-uk-server-of-criminal-network-offline

[12] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YNzpfQcjyQpl5GMd5MpEBAAAAFM&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[13] https://www.theregister.com/2021/06/08/fbi_trojan_shield/

[14] https://whitepapers.theregister.com/

Well done!

Eclectic Man

Congratulations to Europol and the other agencies, although I suspect that this is akin to 'a drop in the ocean' of Internet miscreant sites, I'm assuming it was tricky to track down the actual servers.

Re: Well done!

Pseudononymous Coward

It depends if it is the start of a general assault on VPNs or not. Label them "criminal services" to get the public onside and then take them down one by one.

Lots of governments find VPNs objectionable because it makes it harder to spy on their citizens - e.g. GCHQ’s Tempora programme works by intercepting data on most of the fibre-optic communications cables in and out of the UK. There are apparently around 300 GCHQ and 250 NSA staff processing all that luverly data to snoop on everyone.

All that is a bit screwed with VPNs, so altogether after me "if you have nothing to hide then you have nothing to fear" and "if you have something to hide then you are up to no good".

Pascal Monett

I have nothing to hide and I demand that you justify what right you have to ask.

Hubert Cumberdale

So... which VPN providers are actually legit and really don't log anything? I'm asking for my friend Dave.

Brian Miller

That would be the one you've set up by yourself, without telling anybody about it beforehand. Otherwise, I'm sure that all VPN providers log data. It's just a matter of who gets it, and when.

Anonymous Coward

I'd tell you but tbh I think there's a sort of vpn habitable zone between being too small and obscure and thus super easy to raid and squash, and too big to fly under the spooks radar any more and the visits by serious men with their own equpiment and documents you acknowlege to have received and be bound by terrible penalties if you ever tell anyone

mark l 2

Exactly what are the criminal charges for the DoubleVPN operators, as other than generic statement from the plod about being used mainly by criminals it doesn't really give any indication as to how it is breaking the law?

Seems like a fishing exercise to me where they don't actually have any evidence against the service. What the bet if they were truly not keeping logs as the operators of DoubleVPN claimed the servers will spring back to life in a few days controlled by the NSA/GHCQ and with logging enabled to try catch anyone still using.

Govern a great nation as you would cook a small fish. Don't overdo it.
-- Lao Tsu