News: 1648159999

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

British cops arrest seven in Lapsus$ crime gang probe

(2022/03/24)


British cops investigating a cyber-crime group have made a string of arrests.

Though City of London Police gave few details on Thursday, officers are said to be probing the notorious extortionware gang Lapsus$, and have detained and released seven people aged 16 to 21.

In a statement, the force said: "Seven people between the ages of 16 and 21 have been arrested in connection with an investigation into a hacking group. They have all been released under investigation. Our inquiries remain ongoing."

[1]

Among them is a 16-year-old boy from Oxford who has been accused of being one of the crew's leaders, the BBC [2]reported . He cannot be identified for legal reasons.

[3]

[4]

"I had never heard about any of this until recently," the boy's father was quoted as saying by the broadcaster. "He's never talked about any hacking, but he is very good on computers and spends a lot of time on the computer. I always thought he was playing games.

"We're going to try to stop him from going on computers."

[5]

Palo Alto Networks and infosec outfit Unit 221b, which have been tracking Lapsus$, believe the teen is the mastermind behind the [6]devil-may-care team of miscreants that have broken into major firms including [7]Microsoft , Samsung, [8]Okta , and others.

Bloomberg first [9]reported the boy's alleged involvement with the extortion gang on Wednesday. It is said he netted about $14m in Bitcoin from his online life before being doxxed after a falling out with his business partners.

"We've had his name since the middle of last year and we identified him before the doxxing," Allison Nixon, chief research officer at cyber-security investigation company Unit 221B, told the BBC, noting that her firm worked with Palo Alto Networks' Unit 42 to monitor the teen.

[10]

"Unit 42, together with researchers at Unit 221b, identified the primary actor behind the Lapsus$ Group moniker in 2021, and have been assisting law enforcement in their efforts to prosecute this group," Palo Alto Networks [11]added .

Lapsus$ rise and fall

The cyber-crime ring rose to fame in recent months for its brash tactics and its propensity to brag about its exploits on Telegram. Its standard operating procedure is to infiltrate a big target's network, steal sensitive internal data, make demands to prevent the public release of this material – and usually release some of it anyway.

[12]Devil-may-care Lapsus$ gang is not the aspirational brand infosec needs

[13]Okta now says: Lapsus$ may in fact have accessed customer info

[14]Microsoft investigates Lapsus$'s boasts of Bing, Cortana code heist

[15]Lapsus$ extortionists dump Samsung data online, chaebol confirms security breach

Lapsus$ was believed to be based in Brazil as its earliest victims included that country's Ministry of Health and Portuguese media outlets SIC Noticias and Expresso.

In February, however, the criminals [16]sneaked into Nvidia 's networks and stole one terabyte of data including employee credentials and proprietary information, and dumped some of it online.

Days later Lapsus$ said it had [17]raided Samsung and stole 190GB of internal files including some Galaxy device source code.

The criminal group followed that up by claiming it was responsible for a [18]cybersecurity incident at gaming giant Ubisoft.

'Motivated by theft and destruction'

Microsoft, in its [19]days-late confirmation that Lapsus$, which the Windows giant calls DEV-0537, did indeed steal some of its source code, and said the crime group seems to be "motivated by theft and destruction." Microsoft added:

Unlike most activity groups that stay under the radar, DEV-0537 doesn't seem to cover its tracks. They go as far as announcing their attacks on social media or advertising their intent to buy credentials from employees of target organizations. DEV-0537 also uses several tactics that are less frequently used by other threat actors tracked by Microsoft.

Their tactics include phone-based social engineering; SIM-swapping to facilitate account takeover; accessing personal email accounts of employees at target organizations; paying employees, suppliers, or business partners of target organizations for access to credentials and multifactor authentication (MFA) approval; and intruding in the ongoing crisis-communication calls of their targets.

In an email to The Register , endpoint security vendor Cybereason's Director of Security Strategy Ken Westin said he wouldn't be surprised if the notorious cyber-crime ring's bosses do turn out to be teenagers.

"The security community underestimates the younger generation," he wrote. "We forget teens today have not only grown up with computers, but also have access to an unprecedented number of educational resources on programming and offensive security."

Like others, Westin said he suspected the group was young "based on their modus operandi, or lack thereof."

"It was as if they were surprised by their success and were not sure what to do with it," he noted.

Today's teens can see how much money cyber-criminals make from ransomware and other destructive attacks. "They are the new rockstars," Westin said. "You pair this with the fact kids have been cooped up for years often with nothing but the internet to entertain themselves and we shouldn't be surprised we have skilled hackers." ®

Get our [20]Tech Resources



[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Yjz4Hhg2dxNSI-u5YvvqBQAAABI&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[2] https://www.bbc.com/news/technology-60864283

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Yjz4Hhg2dxNSI-u5YvvqBQAAABI&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Yjz4Hhg2dxNSI-u5YvvqBQAAABI&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Yjz4Hhg2dxNSI-u5YvvqBQAAABI&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[6] https://www.theregister.com/2022/03/17/lapsus-larger-companies/

[7] https://www.theregister.com/2022/03/21/microsoft_lapsus_breach_probe/

[8] https://www.theregister.com/2022/03/23/olkta_microsoft_lapsus/

[9] https://www.bloomberg.com/news/articles/2022-03-23/teen-suspected-by-cyber-researchers-of-being-lapsus-mastermind

[10] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Yjz4Hhg2dxNSI-u5YvvqBQAAABI&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[11] https://unit42.paloaltonetworks.com/lapsus-group/

[12] https://www.theregister.com/2022/03/17/lapsus-larger-companies/

[13] https://www.theregister.com/2022/03/23/olkta_microsoft_lapsus/

[14] https://www.theregister.com/2022/03/21/microsoft_lapsus_breach_probe/

[15] https://www.theregister.com/2022/03/07/samsung_lapsus_data_theft/

[16] https://www.theregister.com/2022/02/26/nvidia_security_breach/

[17] https://www.theregister.com/2022/03/07/samsung_lapsus_data_theft/

[18] https://news.ubisoft.com/en-gb/article/3tSsBh25mhHhlbGSy1xbRw/ubisoft-cyber-security-incident-update

[19] https://www.microsoft.com/security/blog/2022/03/22/dev-0537-criminal-actor-targeting-organizations-for-data-exfiltration-and-destruction/

[20] https://whitepapers.theregister.com/



Freaks In Linux Houses Shouldn't Throw FUD

By Mr. Stu Poor, technology pundit for the Arkansas "Roadkill
Roundup" newspaper. [Editor's Note: He's the local equivalent of Jesse
Berst].

As you all know, February 17th was the happy day that Microsoft officially
released Windows 2000. I went down to the local Paperclips computer store
and asked if they had any copies in stock.

One of the pimply-faced Linux longhairs explained that Paperclips didn't
carry Win2K because it is not intended for consumers. What FUD! I can't
believe the gall of those Linux Communists to spread such FUD (Fear,
Uncertainty, and Doubt) about Windows 2000, which is _the_ best, most
stable operating system ever produced in the history of mankind!