5 ms·
> Today’s announcement proves that cybercriminals can no longer hide behind perceived global anonymity Anyone know what the loose end was that got these guys b
by par 6y ago
> Today’s announcement proves that cybercriminals can no longer hide behind perceived global anonymity
Anyone know what the loose end was that got these guys busted?
- koolba 6y agoIf they were dumb enough to waste such a high value target on a small scale bitcoin scam then I wouldn’t be surprised if they were dumb enough to perform the malicious actions from their home IP address.
- SV_BubbleTime 6y agoDidn’t the hack need internal access? VPN maybe?
- function_seven 6y agoSure, but if they connected to the VPN from their own IP, then that's not going to hide anything.
- ehsankia 6y agoReally seems like a modern day MafiaBoy.
- focus2020 6y agoWhat else could have been done other than crypto scam to get away without being caught ?
- jeherr 6y agoI thought I read a blog post detailing a link to the OGUsername discord.
- Shared404 6y ago> > Today’s announcement proves that cybercriminals can no longer hide behind perceived global anonymity ThorSquint.jpeg I'd love to know as well.
- waihtis 6y agoGuess is there was some opsec failures, and this is typical scaremongering with intent to deter future to-be-hackers
- tptacek 6y agoDidn't Krebs run a story about these people a week or so ago? It looks like it was 100% loose ends.
- elmo2you 6y agoI don't remember if he was reporting on any of these 3 guys. But I do remember that a huge media outlet/conglomerate was quick to accuse Krebs of wrongfully accusing somebody (no idea how they got that, behind a paywall) and how he had previously wrongfully accused people. Felt a lot like a hit piece to me, at the time. It would be interesting to know if Krebs turned out to be right. That could say a thing or two about that news paper.
- coldpie 6y agoOne of the people mentioned in Krebs's article is being charged, but not all of them: https://krebsonsecurity.com/2020/07/whos-behind-wednesdays-epic-twitter-hack/ https://krebsonsecurity.com/2020/07/whos-behind-wednesdays-e...
- libraryatnight 6y agoIf there was any merit to the articles where people in the media were put in contact with people involved (and it seems so, now) then they left tracks all over the place. A) reaching out to the media at all. B) sharing screens of the OGUsername boards they hung out on C) Bragging.
- coldpie 6y agoYeah, as soon as that Vice article came out it was clear they were toast. You don't brag like that and get away with it.
- athyuttamre 6y agoThis report has some details: https://www.justice.gov/usao-ndca/press-release/file/1300126/download https://www.justice.gov/usao-ndca/press-release/file/1300126...
- kevin_thibedeau 6y ago> On April 2, 2020, the administrator of the OGUsers forum publicly announced that OGUsers website was successfully hacked. Shortly after the announcement, a rival criminal hacking forum publicly released a link to download the OGUsers forum database, claiming it contained all of the forum’s user information. The publicly released database has been available on various websites since approximately April 2020. On or about April 9, 2020, the FBI obtained a copy of this database. Seems very convenient. Parallel construction?
- ramimac 6y agoWhat about this implies parallel construction to you? The OGUsers databases (well, actually a couple, they've been hacked multiple times) has been publicly available for a while. Also, the discord chats and Vice article include details on selling accounts with desirable names - even if not explicitly linked to OGUsers (I don't recall off the top of my head if it was called out), you could track hacked accounts, see they were sold or discussed on OGUsers, and then give a look at the DB. That seems an obvious route of investigation to me?
- subculture 6y agoReading the two complaints, it seems that they basically obtained Discord chat records and tied those usernames to an OGUsers db that was hacked & leaked in April. Seems like the OGUsers database was the key piece of info, but it was 'a rival criminal hacking forum' that actually got the db and the FBI 'obtained' a copy of it.
- sepulchers 6y ago> In the days leading up to Wednesday’s attack on Twitter, there were signs that some actors in the SIM swapping community were selling the ability to change an email address tied to any Twitter account. In a post on OGusers — a forum dedicated to account hijacking — a user named “Chaewon” advertised they could change email address tied to any Twitter account for $250, and provide direct access to accounts for between $2,000 and $3,000 apiece. - Brian Krebs [https://krebsonsecurity.com/2020/07/whos-behind-wednesdays-epic-twitter-hack/#comments https://krebsonsecurity.com/2020/07/whos-behind-wednesdays-e...]
- deleted 6y ago[deleted]
- josu 6y agoIt seems that they mixed the stolen bitcoins with bitcoins that they withdrew from Coinbase. So law enforcement probably knew who they were from day 1. I feel that this is the time it took them to put together a case. https://twitter.com/ErgoBTC/status/1283561433972846592?s=19 https://twitter.com/ErgoBTC/status/1283561433972846592?s=19
- ACS_Solver 6y agoI just read one of the complaints, against the 22 year old "Rolex". It's not so much loose ends as loose everything. He didn't use a VPN or anything to mask his home IP, he discussed the hack on Discord, an unencrypted third-party platform, and reused a gmail address for the hack that he also used for a Coinbase account. Said Coinbase account being verified with his driver's license... I shouldn't be too surprised, but I still am. I would have expected, at the very least, all discussion being handled on Signal or similar, all access to involved accounts to be exclusively via a regular VPN or Tor, and only using a brand-new fastmail email for anything to do with the hack. Those are the very basic precautions. Curious aside: there's a bug in the complaint document. The affidavit is by a Special Agent with the US Secret Service, but the title page lists him as "Special Agent, FBI".
- dmitryminkovsky 6y agoI don't know, tbh I'm still surprised. The Discord connection was known early on. I was really surprised anyone would do something like this and communicate over Discord about it. The fact that no VPN/Tor were involved, the fact that Gmail was involved... that's really crazy. It's hard to tell when being dumb ends and being self destructive begins? Is it possible to be this ignorant about the Internet while perpetrating something so big?
- rootsudo 6y agoYes, many people consider facebook and Twitter "The Internet." and while they are just two giant tech companies publishing web apps. Networking Layer is invisible to 99% of users nowadays. "it just works."
- Sebb767 6y ago> Networking Layer is invisible to 99% of users nowadays. "it just works." Yes, but the problem is that it didn't take someone who knows better to hack what is (used as) an official government communication platform. Or one of the largest social networks, or a company with thousands of engineers - take your pick; it's hard to put this in a good light.