News: 1715945831

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

First LockBit, now BreachForums: Are cops winning the war or just a few battles?

(2024/05/17)


Interview On Wednesday the FBI and international cops celebrated yet another cybercrime takedown – of ransomware brokerage site BreachForums – just a week after doxing and imposing sanctions on the LockBit ransomware crew's kingpin, and two months after compromising the gang's website.

While the [1]BreachForums shutdown didn't have quite the [2]swagger of the LockBit seizure in February, it did brag the stolen data marketplace "is under control of the FBI" and include profile pics of website admins Baphomet and ShinyHunters.

This "more aggressive" method of takedown illustrates what has become the norm among law enforcement's approach to trolling cyber criminals over the last year or so, according to Michael McPherson, senior VP of security operations at ReliaQuest and a former FBI special agent.

[3]

"They're flouting it," he tells The Register . "It's we-hacked-the-hackers brash talk. Whereas a couple years ago, they'd be pretty happy if they put a banner up on a website, that website went down for a little bit, and they'd call that a victory."

[4]

[5]

Still, it's the second time in a year that cops have reportedly seized control of the criminal souk. A prior version of BreachForums was shut down in June 2023 after a similar law enforcement effort.

And it's worth noting that BreachForums took over from the previously taken down RaidForums, which [6]shuttered in 2022 following another joint police raid.

It's really difficult to dismantle an organization fully. If you can't identify the person at the keyboard and then take them offline, you just can't do it.

Plus, while law enforcement has [7]named and shamed the suspect they believe is LockBitSupp – Dmitry Yuryevich Khoroshev – he's not going to get cuffed anytime soon unless he's dumb enough to leave Russia. So it's plausible that if he is who they say he is, he'll spin up another ransomware-as-a-service operation soon enough.

Despite the seeming whac-a-mole nature of these takedowns, they "absolutely work," McPherson says.

[8]

McPherson was the agent in charge of the FBI Tampa field office when it became the first to come across the Hive ransomware variant – and eventually led the seizure of the criminal crew's network.

That operation – which shuttered the crew's websites and took control of its servers – was the culmination of a seven-month covert operation during which the [9]FBI hacked Hive's network and used that access to provide decryption keys to more than 300 victims.

When it comes to police takedowns of these criminal networks, "the level of effectiveness varies," McPherson concedes.

[10]

"It didn't take long for BreachForums last time to get back up after the last arrest," he adds – referring to the site's former admin Conor Brian Fitzpatrick, aka "Pompourin," who was [11]sentenced to 20 years of supervised release in January after [12]his arrest earlier that month. BreachForums resurfaced shortly after.

"It's still a disruptive event," McPherson says. "There's always a difference between a disruption and a dismantlement."

Disruption vs dismantlement

"Disruption is a temporary state: you're going to cause confusion, you're going to sow distrust, you're going to slow an organization down, you're going to cost them more money, you're going to put pain on the adversary," he says.

Meanwhile, dismantlement involves arrests and confiscating infrastructure.

"Any time you're going after an organization – whether you're talking about organized crime, terrorism, cyber crime nation-states — dismantlements are very hard, and they usually come at the end of multiple, multiple disruptions, a sustained effort of disruptions over time," McPherson explains. "It's a sustained pressure campaign."

Austin Berglas, also a former FBI agent who now works as global head of professional services at BlueVoyant, puts the BreachForum operation more in the potential dismantlement category.

"It remains to be seen, but it sounds like a dismantlement because it sounds like they've arrested the administrators," he tells The Register .

Berglas cites the website's seizure banner showing the admins locked up along with Telegram chatter. "If that's the case, it's closer to a dismantlement," Berglas observes. "It sounds like they're deep in, they have full access to the back end. And when you've got that administrator access on the back end, then you start getting into some of the non-anonymized communications – the personal private communications that administrators and site owners are sending to each other. That's really where the meat and potatoes are."

[13]FBI takes down BreachForums ransomware website and Telegram channel

[14]Cops finally unmask 'LockBit kingpin' after two-month tease

[15]A tale of 2 casino ransomware attacks: One paid out, one did not

[16]RSA Conference 2024: The good, the bad, and the downright worrying

Part of the reason why dismantlement is so hard has to do with Russia and other countries providing safe harbor for cyber criminals – essentially making it impossible to arrest them, Berglas adds.

"That's the key: the more pressure, sanctions, government political pressure that you can put on these nations to stop being safe harbors and start giving people up – that's what it's going to take," he says.

And he admits this is probably unrealistic.

"I'm not a politician. All I know is the difficulty from experiencing it firsthand," Berglas explains. "It's really difficult to dismantle an organization fully. If you can't get the individuals, can't identify the person at the keyboard and then take them offline, you just can't do it."

From LulzSec to Silk Road

Berglas is a former assistant special agent in charge of the FBI's New York Office Cyber Branch – a post he held for more than a decade. During that time, "we did numerous disruptions, and a few dismantlements," he recalls.

One of these dismantlements was LulzSec – the group linked to Anonymous, and its leader Sabu, who was arrested in June 2011.

"We turned [Sabu]. He became an informant, we put him back online and we were able to arrest the rest of that crew," Berglas says. Sabu was also [17]important in the government's case against Julian Assange.

[18]Silk Road , the notorious online drug market shut down by the FBI in 2013, is another one Berglas was involved with during his time at the bureau.

"That was a full dismantlement. We took that site down and arrested the site's administrator and owner and creator," he recalls. "Disruptions are more common because they're easier. And I'm doing air quotes around 'easier,' because it's not easy to identify the infrastructure, get access to that infrastructure, be able to take it down, and make everybody who's on that site scamper like mice to another site."

Is Scattered Spider next?

After [19]LockBit , and the earlier [20]ALPHV disruption in December 2023 – before an affiliate from that crew came back to extort Change Healthcare for [21]$22 million – the big target remains on [22]Scattered Spider . That's the crew that famously broke into two [23]Las Vegas casinos' networks over the summer and remains at large – except for one arrest, a 19-year-old suspect from Florida.

Private security researchers have tracked this crew of teens and 20-somethings, believed to be in the US and the UK, since at least 2022 – but so far they have mostly managed to evade the cops.

"These investigations can be years in the making, unfortunately," Jon Clay, Trend Micro's VP of threat intel, tells The Register . "It's not like you do it in a week."

However, there are indications that the FBI is getting closer to nabbing key members of this group – including [24]comments made by Brett Leatherman, the FBI's cyber deputy assistant director, to [25]reporters during last week's RSA Conference.

"Brett Leatherman is out there talking publicly about [how] we're going to do something – the FBI never talks like that," McPherson observes, adding that he has no insider knowledge of plans regarding Scattered Spider.

"But they're under tremendous pressure to do something," he says. "I think that was a signal to say, 'we got it, just give us a little bit of time.' Or sometimes it's because they're doing something else. Maybe they penetrated the group, maybe they're talking to people, maybe they found people already."

In other words: wait and see. And hope that these criminals are doing a little more looking over their shoulders and second-guessing their communications in light of the last couple weeks. ®

Get our [26]Tech Resources



[1] https://www.theregister.com/2024/05/15/fbi_breachforums_ransomware/

[2] https://www.theregister.com/2024/02/20/nca_lockbit_takedown/

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Zkd-KDUIzb-PPchRtKjUxAAAANI&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Zkd-KDUIzb-PPchRtKjUxAAAANI&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Zkd-KDUIzb-PPchRtKjUxAAAANI&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[6] https://www.theregister.com/2022/04/12/raidforums_market_arrest/

[7] https://www.theregister.com/2024/05/07/alleged_lockbit_kingpin_charged_sanctioned/

[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Zkd-KDUIzb-PPchRtKjUxAAAANI&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[9] https://www.theregister.com/2023/01/26/fbi_hive_ransomware/

[10] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Zkd-KDUIzb-PPchRtKjUxAAAANI&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[11] https://www.theregister.com/2024/01/22/infosec_news_roundup/

[12] https://www.theregister.com/2024/01/05/breachforums_admin_arrested_again/

[13] https://www.theregister.com/2024/05/15/fbi_breachforums_ransomware/

[14] https://www.theregister.com/2024/05/07/alleged_lockbit_kingpin_charged_sanctioned/

[15] https://www.theregister.com/2023/12/28/casino_ransomware_attacks/

[16] https://www.theregister.com/2024/05/14/rsa_conference_kettle/

[17] https://www.theregister.com/2020/06/25/assange_wikileaks_sabu/

[18] https://www.theregister.com/2013/10/02/silk_road_shutdown/

[19] https://www.theregister.com/2024/02/20/lockbit_down_operation_cronos/

[20] https://www.theregister.com/2023/12/19/blackcat_domain_seizure/

[21] https://www.theregister.com/2024/04/30/unitedhealth_ceo_ransom/

[22] https://www.theregister.com/2023/09/15/scattered_spider_snares_100_victims/

[23] https://www.theregister.com/2023/12/28/casino_ransomware_attacks/

[24] https://therecord.media/scattered-spider-challenge-for-FBI

[25] https://www.reuters.com/world/us/fbi-working-towards-nabbing-scattered-spider-hackers-official-says-2024-05-10/

[26] https://whitepapers.theregister.com/



Doctor Syntax

Arrest, trial and lengthy sentences would be what I'd term a "more aggressive" method of takedown.

20 years of supervised release doesn't seem as much of a deterrent as 20 years imprisonment although I suspect there might have been quite a bit of trading to get there.

And with a $10m reward I wouldn't rule out someone ordinarily resident in Russian suddenly turning up somewhere more accessible to arrest.

Pascal Monett

i agree completely with hard prison sentences for this kind of scum.

I'm just not convinced that any Russian national is going to give up one of his compatriots to the country that has been Russia's enemy since the Cold War.

Would you give up some hacker you knew to Xi Ping ?

Plus : a reward in dollars isn't going to be much of an incentive to a Russian, these days . . .

Peter2

Given that one US dollars trades at like a hundred rubles after Putin reduced the ruble to rubble, I think it probably would be quite an incentive.

Lurko

"20 years of supervised release doesn't seem as much of a deterrent as 20 years imprisonment although I suspect there might have been quite a bit of trading to get there."

The deterrent is mainly in the perp's view of the probability of being caught rather than the sentence. If there were a 100% chance of being caught, then really light sentences would suffice. Say it was 200 hours litter picking - not much of sentence, yet if EVERY time you tried to commit a crime that was your outcome, you'd soon learn the game wasn't worth the candle. If there's a 50% chance of being caught then criminals may well see that as a chance worth taking if the potential payoff is high, for lower payoffs they'd be more circumspect. As the expected probability of conviction declines, the potential maximum sentence becomes less and less relevant.

Note as well that the perp's view of probability is not going to be informed by common sense or facts. I suspect all cyber crims think they're genius hackers, able to ghost in and out of systems without leaving a trace, truly untouchable. So I don't believe a few big takedowns are going to have any deterrent effect. The fact that online fraud in the UK doubled year on year in 2023 to a value of £2.3bn shows that there's more cyber crims and they're mostly getting away with it.

Make paying ransom a crime.

VicMortimer

The ONLY way ransomware is going to be stopped is to make paying ransom a crime. And it's got to come with actual prison time for CEOs who pay, not just fines that companies will treat as a cost of doing business.

Sure, keep going after the perps, but it's not going to fix the problem, you're just playing whack-a-mole.

Re: Make paying ransom a crime.

Lurko

And make concealing a ransom payment, or attempting to get any third party to pay on your behalf should attract even more stringent penalties (as already happens with bribery laws).

* Twilight1 will have to hang his Mozilla beanie dinosaur in effigy if
Netscape sells-out to Alot Of Losers..