Menu
Sign In Search Podcasts Charts People & Topics Add Podcast API Blog Pricing

Jack Rhysider

๐Ÿ‘ค Speaker
534 total appearances

Appearances Over Time

Podcast Appearances

Darknet Diaries
135: The D.R. Incident

We are seeing some bad weather on the horizon. Be very cautious of any phishing emails. And please, please, please report anything suspicious to the security team. Thank you.

Darknet Diaries
135: The D.R. Incident

We are seeing some bad weather on the horizon. Be very cautious of any phishing emails. And please, please, please report anything suspicious to the security team. Thank you.

Darknet Diaries
135: The D.R. Incident

Okay, wow, so they were seeing a lot of phishing attempts. Emails posing as someone else trying to get users to click links, open zip files or attachments. And in every one of these emails, the attackers spoke perfect Spanish. This is really curious since a lot of these ransomware gangs would be coming from Eastern Europe or Russia.

Darknet Diaries
135: The D.R. Incident

Okay, wow, so they were seeing a lot of phishing attempts. Emails posing as someone else trying to get users to click links, open zip files or attachments. And in every one of these emails, the attackers spoke perfect Spanish. This is really curious since a lot of these ransomware gangs would be coming from Eastern Europe or Russia.

Darknet Diaries
135: The D.R. Incident

They wouldn't have the ability to speak perfect Spanish on such a large scale with hundreds of phishing emails being written.

Darknet Diaries
135: The D.R. Incident

They wouldn't have the ability to speak perfect Spanish on such a large scale with hundreds of phishing emails being written.

Darknet Diaries
135: The D.R. Incident

Bandook. Okay, if I Google Bandook malware, I immediately get an article saying that this malware gives remote access to a computer, and it was written by someone named Prince Ali who's from Lebanon in the Middle East. More specifically, the Bandook malware has been known to be used by a group called Dark Caracol. Well, that's what the EFF named them, at least.

Darknet Diaries
135: The D.R. Incident

Bandook. Okay, if I Google Bandook malware, I immediately get an article saying that this malware gives remote access to a computer, and it was written by someone named Prince Ali who's from Lebanon in the Middle East. More specifically, the Bandook malware has been known to be used by a group called Dark Caracol. Well, that's what the EFF named them, at least.

Darknet Diaries
135: The D.R. Incident

And while we aren't sure exactly who they are, there are quite a bit of clues that lead us to believe that the Lebanese government is somehow behind this dark Caracol group. Now, I want to paint a clear picture for you.

Darknet Diaries
135: The D.R. Incident

And while we aren't sure exactly who they are, there are quite a bit of clues that lead us to believe that the Lebanese government is somehow behind this dark Caracol group. Now, I want to paint a clear picture for you.

Darknet Diaries
135: The D.R. Incident

Hundreds of phishing emails are flooding into different government agencies in the Dominican Republic, all of which are trying to get the recipient to open an attachment or click a link, which will infect them with this Banduk malware, which typically seems to be the work of this threat actor group called Dark Caracal. As Omar looked at these emails coming in, he noticed something even more scary.

Darknet Diaries
135: The D.R. Incident

Hundreds of phishing emails are flooding into different government agencies in the Dominican Republic, all of which are trying to get the recipient to open an attachment or click a link, which will infect them with this Banduk malware, which typically seems to be the work of this threat actor group called Dark Caracal. As Omar looked at these emails coming in, he noticed something even more scary.

Darknet Diaries
135: The D.R. Incident

So what happened here is that the attackers knew that the Dominican Republic was doing business with a certain company, and they infiltrated that company just to pose as people from there in order to trick the victims in the Dominican Republic government to open attachments.

Darknet Diaries
135: The D.R. Incident

So what happened here is that the attackers knew that the Dominican Republic was doing business with a certain company, and they infiltrated that company just to pose as people from there in order to trick the victims in the Dominican Republic government to open attachments.

Darknet Diaries
135: The D.R. Incident

I mean, this seems to be the start of a horror story where it feels like you're home alone at night and someone is throwing rocks at your window, at all your windows, at once, constantly pinging them. And you just know at any moment one of those windows is going to break. But there's just no way to secure everything at once.

Darknet Diaries
135: The D.R. Incident

I mean, this seems to be the start of a horror story where it feels like you're home alone at night and someone is throwing rocks at your window, at all your windows, at once, constantly pinging them. And you just know at any moment one of those windows is going to break. But there's just no way to secure everything at once.

Darknet Diaries
135: The D.R. Incident

It just takes one user in an agency to get infected, and then the attacker can jump off their machine to infect the whole agency. And for dozens of agencies to be attacked at the same time is horrifying. On top of that, the attackers are scanning web servers, looking for vulnerabilities, trying to find an exploit to get into the network that way.

Darknet Diaries
135: The D.R. Incident

It just takes one user in an agency to get infected, and then the attacker can jump off their machine to infect the whole agency. And for dozens of agencies to be attacked at the same time is horrifying. On top of that, the attackers are scanning web servers, looking for vulnerabilities, trying to find an exploit to get into the network that way.

Darknet Diaries
135: The D.R. Incident

So it's like endless banging on the doors and you know they're not going to hold. Where do you even put your attention in a situation like this? The bull is trying to get in your house and there's nothing you can do to stop it.

Darknet Diaries
135: The D.R. Incident

So it's like endless banging on the doors and you know they're not going to hold. Where do you even put your attention in a situation like this? The bull is trying to get in your house and there's nothing you can do to stop it.