<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>admin, Author at Deliver Intelligence - Dibiz JSC</title>
	<atom:link href="https://dibiz.vn/en/author/admin/feed/" rel="self" type="application/rss+xml" />
	<link>https://dibiz.vn/en/author/admin/</link>
	<description></description>
	<lastBuildDate>Thu, 19 Jun 2025 17:05:15 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.9.4</generator>

<image>
	<url>https://dibiz.vn/wp-content/uploads/2025/06/cropped-cropped-cropped-cropped-3-1-32x32.png</url>
	<title>admin, Author at Deliver Intelligence - Dibiz JSC</title>
	<link>https://dibiz.vn/en/author/admin/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Telegram’s Policy Shift: How Cybercriminals Are Reacting to New Data Sharing Rules</title>
		<link>https://dibiz.vn/en/telegrams-policy-shift-how-cybercriminals-are-reacting-to-new-data-sharing-rules/</link>
		
		<dc:creator><![CDATA[admin]]></dc:creator>
		<pubDate>Tue, 08 Oct 2024 07:27:00 +0000</pubDate>
				<category><![CDATA[KELA]]></category>
		<guid isPermaLink="false">https://dbiz.vn/?p=989657</guid>

					<description><![CDATA[<p>Telegram recently made waves by updating its privacy policy, marking a significant departure from its long-standing reputation as a haven for privacy-focused users, including cybercriminals. The messaging platform, known for its hands-off moderation approach, will now share users’ phone numbers and IP addresses with law enforcement following court orders. This change applies to various criminal...</p>
<p>The post <a href="https://dibiz.vn/en/telegrams-policy-shift-how-cybercriminals-are-reacting-to-new-data-sharing-rules/">Telegram’s Policy Shift: How Cybercriminals Are Reacting to New Data Sharing Rules</a> appeared first on <a href="https://dibiz.vn/en/">Deliver Intelligence - Dibiz JSC</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div class="vgblk-rw-wrapper limit-wrapper">Telegram recently made waves by updating its privacy policy, marking a significant departure from its long-standing reputation as a haven for privacy-focused users, including cybercriminals. The messaging platform, known for its hands-off moderation approach, will now share users’ phone numbers and IP addresses with law enforcement following court orders. This change applies to various criminal investigations, expanding beyond the previous limit of only terror-related offenses. You can read the full details of the new policy on<a href="https://telegram.org/privacy?setln=fa"> Telegram’s Privacy Policy page</a>.</p>
<h4><b>What Telegram’s New Policy Means for Privacy and Security</b></h4>
<p>The update comes amidst increasing legal pressures on Telegram and its founder, Pavel Durov, after his recent detainment in France. Authorities have been pressuring Telegram to combat the illegal activities flourishing on the platform, which ultimately led to this sweeping policy update. For more context on Durov’s detainment, you can check out our blog post:<a href="https://www.kelacyber.com/blog/durov-telegram-ceo-under-arrest/"> Durov’s Arrest and Telegram’s Transformation</a>.</p>
<p>For years, Telegram was a go-to platform for those seeking to operate below the radar of law enforcement. For more context read our report: <a href="https://www.kelacyber.com/wp-content/uploads/2023/02/KELA_Telegram_CEBIN.pdf" data-lf-fd-inspected-lynor8xnwwn4wqjz="true">Telegram: How a messenger turned into a cybercrime ecosystem</a>. This update signals a turning point, as the platform will now cooperate with authorities in criminal investigations.</p>
<h4><b>How Cybercriminals Are Reacting to Telegram’s Policy Update</b></h4>
<p>KELA’s research reveals widespread unease within cybercriminal communities about these changes. Groups like <b>Ghosts of Palestine</b> have publicly declared their intentions to leave Telegram and seek out more privacy-centric platforms. <b>RipperSec</b>, another prominent hacktivist group, has already begun setting up backup channels on <b>Discord</b>, anticipating that Telegram’s cooperation with law enforcement will pose a threat to their anonymity​. <b>Al Ahad</b>, also hacktivists, created a Signal group and promised to close their Telegram channel soon. The <b>GlorySec</b> hacktivists even mentioned they “may or may not created” Facebook and Threads accounts, though without taking any actions.</p>
<p>&nbsp;</p>
<figure id="attachment_28782" class="wp-caption aligncenter" aria-describedby="caption-attachment-28782"><img fetchpriority="high" decoding="async" class="wp-image-28782 size-medium entered lazyloaded" src="https://www.kelacyber.com/wp-content/uploads/2024/09/Telegram-Picture1_very-first-300x195.png" sizes="(max-width: 300px) 100vw, 300px" srcset="https://www.kelacyber.com/wp-content/uploads/2024/09/Telegram-Picture1_very-first-300x195.png 300w, https://www.kelacyber.com/wp-content/uploads/2024/09/Telegram-Picture1_very-first.png 742w" alt="Ghost of Palestine announcing their intention to find alternative to Telegram" width="300" height="195" data-lazy-srcset="https://www.kelacyber.com/wp-content/uploads/2024/09/Telegram-Picture1_very-first-300x195.png 300w, https://www.kelacyber.com/wp-content/uploads/2024/09/Telegram-Picture1_very-first.png 742w" data-lazy-sizes="(max-width: 300px) 100vw, 300px" data-lazy-src="https://www.kelacyber.com/wp-content/uploads/2024/09/Telegram-Picture1_very-first-300x195.png" data-ll-status="loaded" /><figcaption id="caption-attachment-28782" class="wp-caption-text">Ghost of Palestine announcing their intention to find alternative to Telegram</figcaption></figure>
<p>&nbsp;</p>
<figure id="attachment_28776" class="wp-caption aligncenter" aria-describedby="caption-attachment-28776"><img decoding="async" class="wp-image-28776 size-medium entered lazyloaded" src="https://www.kelacyber.com/wp-content/uploads/2024/09/Telegram-Picture1-300x191.png" sizes="(max-width: 300px) 100vw, 300px" srcset="https://www.kelacyber.com/wp-content/uploads/2024/09/Telegram-Picture1-300x191.png 300w, https://www.kelacyber.com/wp-content/uploads/2024/09/Telegram-Picture1.png 487w" alt="Al Ahad claiming to leave Telegram in favor of Signal" width="300" height="191" data-lazy-srcset="https://www.kelacyber.com/wp-content/uploads/2024/09/Telegram-Picture1-300x191.png 300w, https://www.kelacyber.com/wp-content/uploads/2024/09/Telegram-Picture1.png 487w" data-lazy-sizes="(max-width: 300px) 100vw, 300px" data-lazy-src="https://www.kelacyber.com/wp-content/uploads/2024/09/Telegram-Picture1-300x191.png" data-ll-status="loaded" /><figcaption id="caption-attachment-28776" class="wp-caption-text">Al Ahad claiming to leave Telegram in favor of Signal</figcaption></figure>
<p>&nbsp;</p>
<p>Meanwhile, other groups are taking more pragmatic approaches. <b>UserSec</b>, for example, is now offering tutorials on how to maintain anonymity on Telegram, sharing tips on evading detection under the new data-sharing rules. On the <b>BF Repo V3 Chat</b> group, a Telegram chat related to BreachForums’ users, members have even floated the idea of creating a custom messaging platform using Telegram’s GUI as a foundation to continue their activities with less risk of exposure​.</p>
<p>Overall, KELA has witnessed different cybercriminals discussing <b>Jabber, Matrix</b>, and <b>Session</b> as alternatives to Telegram, however, mostly for private messaging or private groups — while Telegram provides them with an opportunity to create open communities around illegal activity. So far only <b>Discord</b> was mentioned as a platform that can provide the same functionality, as well as <b>Signal</b> groups.</p>
<p>Despite these initial responses, there hasn’t yet been a mass exodus of cybercriminals from Telegram. However, these discussions signal potential future movement as groups and individuals weigh their options in response to the platform’s shift.</p>
<h4><b>Will Telegram’s Policy Shift Impact Criminal Activity?</b></h4>
<p>It is yet unclear if this policy change has the potential to significantly disrupt criminal activity on Telegram and drive them to Discord or other platforms. While cybercriminals are definitely expressing their concerns on the matter, their operations on Telegram are just too scaled to be shifted to another platform right away.</p>
<p>For example, infostealers’ operations use Telegram not only to sell and share harvested data through “clouds of logs”. Read more in our blog: <a href="https://www.kelacyber.com/blog/telegram-clouds-of-logs-the-fastest-gateway-to-your-network/">Telegram Clouds of Logs – the fastest gateway to your network</a>. Commodity infostealers provoked the emergence of cybercriminal gangs and teams working together to infect as many people as possible. To coordinate their activities, many use Telegram, creating all types of tools: channels for hiring new traffers and advertising the team, public and private chats for coordinating activities and discussions, and Telegram bots for automating tasks, payments and more. Such behavior is common among many malware-as-a-service operations, as well as hacktivists and other cybercriminals.</p>
<p>Moreover, Telegram’s new dedicated team of moderators, leveraging AI, is stepping up efforts to monitor and remove illegal content from its search features. This heightened focus on moderation could make it more difficult for cybercriminals to operate openly on the platform​. However, many of them are used to deal with such barriers. As seen with groups like <b>UserSec</b>, some may attempt to exploit loopholes or develop strategies to continue their operations despite these new challenges. KELA is aware of cybercriminals maintaining backup Telegram channels for a while now; usually, once their main channel is banned, they will switch to another one, which was proactively advertised to their followers.</p>
<figure id="attachment_28778" class="wp-caption aligncenter" aria-describedby="caption-attachment-28778"><img decoding="async" class="wp-image-28778 size-medium entered lazyloaded" src="https://www.kelacyber.com/wp-content/uploads/2024/09/Telegram-Picture2-300x211.png" sizes="(max-width: 300px) 100vw, 300px" srcset="https://www.kelacyber.com/wp-content/uploads/2024/09/Telegram-Picture2-300x211.png 300w, https://www.kelacyber.com/wp-content/uploads/2024/09/Telegram-Picture2-450x316.png 450w, https://www.kelacyber.com/wp-content/uploads/2024/09/Telegram-Picture2.png 518w" alt="RipperSec listing their backup channel for subscribers" width="300" height="211" data-lazy-srcset="https://www.kelacyber.com/wp-content/uploads/2024/09/Telegram-Picture2-300x211.png 300w, https://www.kelacyber.com/wp-content/uploads/2024/09/Telegram-Picture2-450x316.png 450w, https://www.kelacyber.com/wp-content/uploads/2024/09/Telegram-Picture2.png 518w" data-lazy-sizes="(max-width: 300px) 100vw, 300px" data-lazy-src="https://www.kelacyber.com/wp-content/uploads/2024/09/Telegram-Picture2-300x211.png" data-ll-status="loaded" /><figcaption id="caption-attachment-28778" class="wp-caption-text">RipperSec listing their backup channel for subscribers</figcaption></figure>
<p>The policy shift won’t eliminate cybercrime on Telegram, but it’s likely to change how threat actors operate in the short and long term.</p>
<h4><b>What This Means for Threat Intelligence: Insights from KELA</b></h4>
<p>For companies like KELA, these changes present both challenges and opportunities. While some cybercriminals may move to other platforms, KELA’s unmatched coverage ensures we continue to track and monitor activity across a wide range of forums and messaging apps. It’s not just about knowing the right sources — it’s about gaining access to these underground communities. KELA’s combination of human expertise and advanced technology provides unique access to forums and channels that are often hidden from other intelligence providers.</p>
<p>This constant vigilance allows us to stay ahead of emerging trends, tracking where threat actors are moving and how they are attempting to evade detection. By adapting quickly to shifts in the cybercrime landscape, KELA ensures our clients receive actionable insights, helping them to stay proactive in their defense strategies, even as platforms like Telegram evolve.</p>
<p>&nbsp;</p>
<h4><b>Conclusion: The Future of Telegram and Cybercrime</b></h4>
<p>Telegram’s recent policy shift is a clear response to mounting legal pressure and a broader need to curb the platform’s use for illegal activities. While the new rules may drive some criminals to more secure platforms, Telegram’s 900 million active users mean it will likely remain a key player in the cybercrime ecosystem for the time being</p>
<p>As these changes take hold, KELA will continue to provide critical intelligence on how threat actors are adapting to the evolving landscape, ensuring that security teams stay one step ahead of malicious activity.</p>
<p style="text-align: right;">         Nguồn: kelacyber.com</p>
</div>
<p><!-- .vgblk-rw-wrapper --></p>
<p>The post <a href="https://dibiz.vn/en/telegrams-policy-shift-how-cybercriminals-are-reacting-to-new-data-sharing-rules/">Telegram’s Policy Shift: How Cybercriminals Are Reacting to New Data Sharing Rules</a> appeared first on <a href="https://dibiz.vn/en/">Deliver Intelligence - Dibiz JSC</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Telegram’s CEO and Founder Durov Under Arrest: Cybercriminals React</title>
		<link>https://dibiz.vn/en/telegrams-ceo-and-founder-durov-under-arrest-cybercriminals-react/</link>
		
		<dc:creator><![CDATA[admin]]></dc:creator>
		<pubDate>Tue, 08 Oct 2024 07:23:23 +0000</pubDate>
				<category><![CDATA[KELA]]></category>
		<guid isPermaLink="false">https://dbiz.vn/?p=989653</guid>

					<description><![CDATA[<p>Pavel Durov, the founder and CEO of Telegram, was arrested in Paris on August 25, 2024 on charges related to his platform allegedly being used for illegal activities. Three days later, he was indicted and released on bail, with six charges related to illicit activity on Telegram. While people all over the world discuss Telegram’s loose moderation measures...</p>
<p>The post <a href="https://dibiz.vn/en/telegrams-ceo-and-founder-durov-under-arrest-cybercriminals-react/">Telegram’s CEO and Founder Durov Under Arrest: Cybercriminals React</a> appeared first on <a href="https://dibiz.vn/en/">Deliver Intelligence - Dibiz JSC</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div class="vgblk-rw-wrapper limit-wrapper">
<div class="pagecon">
<p>Pavel Durov, the founder and CEO of Telegram, was <a href="https://apnews.com/article/france-russia-telegram-paris-durov-arrest-63cd8e5663c6b6f3404745866d662954">arrested</a> in Paris on August 25, 2024 on charges related to his platform allegedly being used for illegal activities. Three days later, he was indicted and released on bail, with six charges related to illicit activity on Telegram. While people all over the world discuss Telegram’s loose moderation measures and wonder if providers of web services should be liable for the actions of their users, a certain type of Telegram users — cybercriminals using the platform — have something to say too.</p>
<p>&nbsp;</p>
</div>
<div class="middle_content">
<div class="mcon ">
<p>In recent years, as detailed by KELA, Telegram has <a href="https://www.kelacyber.com/wp-content/uploads/2024/01/KELA_Telegram_CEBIN_24.pdf" data-lf-fd-inspected-lynor8xnwwn4wqjz="true">become popular</a> as a platform for a wide range of cybercrimes. These include selling illegally obtained data, such as personal information, sensitive documents, and compromised accounts, and using the platform to facilitate infostealer, ransomware, hacktivist and other operations. Among reasons why Telegram is attractive to cybercriminals are anonymity and the ability to build communities, enabling cybercriminals to both hide their identities from law enforcement and have access to multiple potential sellers.</p>
<p>Now these cybercriminals are concerned with repercussions that Durov’s arrest can cause to their operations. While some of them discuss additional safety precautions, others go on the offensive and support Durov with cyberattacks against France. KELA has reviewed cybercriminals’ actions and discussions on the matter.</p>
<h4>Threat Actors Supporting Durov</h4>
<p>After Durov’s arrest, many people all over the world have expressed their dissatisfaction with the Telegram CEO’s arrest, viewing it as unjustified. In response, a campaign using the hashtags #FreeDurov” and #FreePavel was initiated and spread across the internet. Public figures who participated in the campaign included <a href="https://x.com/elonmusk/status/1827572720936030703">Elon Musk</a> and <a href="https://twitter.com/RobertKennedyJr/status/1827540616282055012">Robert F. Kennedy</a>.</p>
<p>Some threat actors, mainly hacktivists who are actively using Telegram, were seen discussing the arrest and supporting Durov. For example, StucxTeam, a hacktivist group known for targeting Israeli organizations, was debating whether Durov is responsible for terrorism and other illegal activities that use Telegram as their communication platform, adding the “#freedurov” hashtag at the end of the message. This message was one of many supporting statements observed using the hashtag on different hacktivist channels.</p>
<div class="post_img ">
<div class="inner-wrapper"><img loading="lazy" decoding="async" class="entered lazyloaded" src="https://www.kelacyber.com/wp-content/uploads/2024/08/Picture1-932x420.png" alt="durov telegram cybercriminals react" width="932" height="420" data-lazy-src="https://www.kelacyber.com/wp-content/uploads/2024/08/Picture1-932x420.png" data-ll-status="loaded" /></div>
<div></div>
</div>
<p><i>StucxTeam commenting on Durov’s arrest: Source: KELA platform</i></p>
<p>Some actors went beyond using the hashtags to launch cyberattacks on France in response to the arrest. On August 25, the pro-Russian hacktivist group People’s Cyber Army of Russia posted “#freedurov” on their channel and then announced a week-long attack on French “internet portals” in reaction to the arrest. They invited other threat groups to join them in this activity. As their first action, the group claimed to have launched a DDoS attack on the website of the French National Agency for the Safety of Medicines and Health Products (ANSM), which is associated with the French government, causing the website to be inaccessible for a period of time, as noticed by KELA.</p>
<div class="post_img ">
<div class="inner-wrapper"><img loading="lazy" decoding="async" class="entered lazyloaded" src="https://www.kelacyber.com/wp-content/uploads/2024/08/Picture2.png" alt="durov telegram cybercriminals react" width="698" height="175" data-lazy-src="https://www.kelacyber.com/wp-content/uploads/2024/08/Picture2.png" data-ll-status="loaded" /></div>
<div></div>
</div>
<p><i>The People’s Cyber Army of Russia statement and attacks announcement (auto-translated by KELA platform)</i></p>
<p>Another pro-Russian hacking group called UserSec initiated an attack campaign named “#FreeDurov” on their Telegram channel and urged other threat groups to unite in cyberattacks against France, citing their use of Durov’s messenger: “It will not be better for any of us if Durov is imprisoned on the charges that they want to bring against him. I invite all interested groups to join. Don’t forget that we use Durov’s messenger.”</p>
<p>Later, UserSec announced that, in collaboration with the People’s Cyber Army of Russia, they had carried out DDoS attacks on specific French targets. The first target was the website of the National Court of France, which was down on August 27, following the attack, and the second target was the website of the Paris tribunal. UserSec also claimed to deploy their “stealer” on French targets (possibly a stealer targeting Google Chrome that was mentioned on their channel a year ago). Other gangs, such as CyberDragon and OverFlame, have joined the campaign, while others have reposted the call.</p>
<div class="post_img ">
<div class="inner-wrapper"><img loading="lazy" decoding="async" class="entered lazyloaded" src="https://www.kelacyber.com/wp-content/uploads/2024/08/Picture3.png" alt="durov telegram cybercriminals react" width="698" height="127" data-lazy-src="https://www.kelacyber.com/wp-content/uploads/2024/08/Picture3.png" data-ll-status="loaded" /></div>
<div></div>
</div>
<p><i>UserSec initiating the #FreeDurov campaign on their Telegram channel (auto-translated by KELA platform)</i></p>
<p>Not only pro-Russian hacktivists have joined the efforts: the pro-Palestinian hacktivist group RipperSec conducted cyberattacks targeting various French websites, including PriceBank. RipperSec shared a message from the CGPLLNET threat group, announcing a new alliance and their plans to target France, and calling for more participants. On August 27, 2024, the group claimed responsibility for another cyberattack on France, and mentioned the groups involved in carrying out the attacks.</p>
<div class="post_img ">
<div class="inner-wrapper"><img loading="lazy" decoding="async" class="entered lazyloaded" src="https://www.kelacyber.com/wp-content/uploads/2024/08/Picture4-594x420.png" alt="durov telegram cybercriminals react" width="594" height="420" data-lazy-src="https://www.kelacyber.com/wp-content/uploads/2024/08/Picture4-594x420.png" data-ll-status="loaded" /></div>
<div></div>
</div>
<p><i>RipperSec is crediting other threat groups on helping to attack France</i></p>
<p>Based on this activity, it seems that hacktivists’ attacks on French organizations could be intensified in the near future, depending on how Durov’s case unfolds.</p>
<p>Interestingly, some cybercriminals have decided to support Telegram financially, for example, by investing in Telegram Stars, a recently introduced virtual items that allow users to purchase digital goods and services from bots and mini apps, as well as assist with channels’ monetization.</p>
<div class="post_img ">
<div class="inner-wrapper"><img loading="lazy" decoding="async" class="entered lazyloaded" src="https://www.kelacyber.com/wp-content/uploads/2024/08/image-fix-resize-final.png" alt="" width="600" height="248" data-lazy-src="https://www.kelacyber.com/wp-content/uploads/2024/08/image-fix-resize-final.png" data-ll-status="loaded" /></div>
<div></div>
</div>
<p><i>An owner of Deanon club project and Killnet Telegram channel invests in Telegram stars to support Durov (auto-translated by KELA platform)</i></p>
<p>&nbsp;</p>
<h4>Cybercriminals’ Concerns</h4>
<p>For many other cybercriminals and their customers using Telegram, Durov’s arrest caused concerns about the platform’s safety and possible changes in moderation. Users of different cybercrime forums have created multiple threads mentioning the arrest, expressing mixed reactions.</p>
<p>Some users of cybercrime/drugs supply services are taking precautions communicating with these services, with several pausing their activities on the Telegram platform. The services suppliers are concerned about the security of their operations, particularly those who have stored sensitive information on Telegram, recognizing that this could expose them to significant risks if authorities gain access. KELA has also noticed instructions on how to prevent data loss on Telegram in case the authorities seize the servers circulating across different platforms.</p>
<div class="post_img ">
<div class="inner-wrapper"><img loading="lazy" decoding="async" class="entered lazyloaded" src="https://www.kelacyber.com/wp-content/uploads/2024/08/Picture6.png" alt="durov telegram cybercriminals react" width="538" height="164" data-lazy-src="https://www.kelacyber.com/wp-content/uploads/2024/08/Picture6.png" data-ll-status="loaded" /></div>
<div></div>
</div>
<p><i>A user plans to stop their regular communications with their “dealer” to lower the risk of them being caught</i></p>
<h2></h2>
<div class="post_img ">
<div class="inner-wrapper"><img loading="lazy" decoding="async" class="entered lazyloaded" src="https://www.kelacyber.com/wp-content/uploads/2024/08/Picture7.png" alt="durov telegram cybercriminals react" width="624" height="171" data-lazy-src="https://www.kelacyber.com/wp-content/uploads/2024/08/Picture7.png" data-ll-status="loaded" /></div>
<div></div>
</div>
<p><i>A user planning to delete their Telegram archives, containing stolen information from credit cards, bank accounts and more</i></p>
<p>Some threat actors are discussing alternative platforms, such as Tox, Session or Jabber for private messaging, due to their fear of being exposed if law enforcement gets access to some conversations. However, it does not seem that cybercriminals are actively leaving Telegram, with such activity merely related to setting up back up channels. For example, the actor claiming to be associated with the Lapsus$ group has set up an XMPP-protocol based channel, and shared a link on their Telegram channel for others to join.</p>
<div class="post_img ">
<div class="inner-wrapper"><img loading="lazy" decoding="async" class="entered lazyloaded" src="https://www.kelacyber.com/wp-content/uploads/2024/08/Picture8.png" alt="durov telegram cybercriminals react" width="347" height="240" data-lazy-src="https://www.kelacyber.com/wp-content/uploads/2024/08/Picture8.png" data-ll-status="loaded" /></div>
<div></div>
</div>
<p><i>Lapsus$-related channel announces a back-up XMPP conference channel</i></p>
<p>In general, long before Durov’s arrest, many cybercriminals avoided using Telegram for sensitive private conversations, claiming it is not safe. While some suspected Telegram of cooperation with Russian or other authorities, others pointed out the lack of end-to-end encryption on most of the chats (except so-called Secret chats). Therefore, the most cautious actors appear to have quit Telegram for a while now: for example, most of active RaaS operations now list only TOX, Jabber and Session as their contact methods.</p>
<div class="post_img ">
<div class="inner-wrapper"><img loading="lazy" decoding="async" class="entered lazyloaded" src="https://www.kelacyber.com/wp-content/uploads/2024/08/Picture9.png" alt="durov telegram cybercriminals react" width="814" height="298" data-lazy-src="https://www.kelacyber.com/wp-content/uploads/2024/08/Picture9.png" data-ll-status="loaded" /></div>
<div></div>
</div>
<p><i>A user discussing dangers of using Telegram</i></p>
<h4>What’s Next</h4>
<p>The recent attacks and discussions indicate that cybercrime users are concerned about Pavel Durov’s arrest, with some being concerned that his arrest may affect their primary communication platform. The arrest is likely to have a dual impact on cybercriminal activities on Telegram.</p>
<p>On one hand, it may lead to some actors taking precautions or considering alternative communication platforms, probably till the arrest’s full consequences will be clear. However, unlikely those who currently rely on Telegram will conduct a massive exodus, as many use it to form communities, advertise their product to multiple potential buyers and automate their operations, highly depending on Telegram’s channels, groups and bots. Currently, alternative platforms discussed by cybercriminals do not provide such functionality.</p>
<p>On the other hand, the arrest has inflamed certain hacktivist groups, leading to an increase in retaliatory cyberattacks, particularly against French organizations. The situation could evolve depending on the outcomes of ongoing legal actions.</p>
<h4>Update &#8211; September, 25th</h4>
<p>Telegram has updated its terms of use claiming the company will now disclose users’ phone numbers and IP addresses to law enforcement. This is a change from its previous policy, which limited data sharing to cases involving terrorism. The update clarifies that Telegram will only comply with court orders confirming a user’s involvement in criminal activities that violate the platform’s Terms of Service to sell illegal goods. Additionally, Telegram has reportedly enhanced its search feature to prevent its misuse for promoting illegal goods and encourages users to report illicit content via the SearchReport bot.</p>
<p>KELA has reviewed cybercriminals’ reactions to this change and found that multiple threat actors are dissatisfied with it, being unsure what to do and seeking alternatives to Telegram, with some mentioning Signal and Discord. Some hacktivist groups, such as Ghosts of Palestine, announced on their Telegram channel their decision to transition away from Telegram, citing concerns following the changes. The group claimed they are currently evaluating alternative platforms with stronger privacy features. The pro-Palestinian hacktivist group RipperSec announced that the group is creating a backup channel on Discord. Interestingly, the UserSec hacktivist group leader offered for sale lessons on how to stay anonymous online, including how to secure personal data on Telegram. Multiple other discussions were started in different groups, for example, members of BF Repo V3 Chat also expressed concerns about the changes, with some of them discussing a possibility to create their own messaging based on Telegram’s GUI. While currently KELA did not observe mass migration to other platforms, the change has raised significant concerns among cybercriminals and could affect activity of some of them on Telegram.</p>
<p style="text-align: right;">Nguồn: kelacyber.com</p>
</div>
</div>
</div>
<p><!-- .vgblk-rw-wrapper --></p>
<p>The post <a href="https://dibiz.vn/en/telegrams-ceo-and-founder-durov-under-arrest-cybercriminals-react/">Telegram’s CEO and Founder Durov Under Arrest: Cybercriminals React</a> appeared first on <a href="https://dibiz.vn/en/">Deliver Intelligence - Dibiz JSC</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>What is Ransomware? And Why is it Such a Big Business?</title>
		<link>https://dibiz.vn/en/what-is-ransomware-and-why-is-it-such-a-big-business/</link>
		
		<dc:creator><![CDATA[admin]]></dc:creator>
		<pubDate>Tue, 08 Oct 2024 07:15:19 +0000</pubDate>
				<category><![CDATA[KELA]]></category>
		<guid isPermaLink="false">https://dbiz.vn/?p=989649</guid>

					<description><![CDATA[<p>Between Q2 2023 and Q2 2024, KELA has tracked more than 5,000 victims of ransomware and extortion actors, and the numbers are only growing year-on-year. Ransomware has become a huge business, and monetization opportunities are far broader than just the ransom demand itself.  Our latest eBook takes a deep dive into the business of the...</p>
<p>The post <a href="https://dibiz.vn/en/what-is-ransomware-and-why-is-it-such-a-big-business/">What is Ransomware? And Why is it Such a Big Business?</a> appeared first on <a href="https://dibiz.vn/en/">Deliver Intelligence - Dibiz JSC</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div class="vgblk-rw-wrapper limit-wrapper">
<div class="post_top">
<p class="text-body"><span style="color: var(--vamtam-widget-text-lighter); letter-spacing: var(--vamtam-primary-font-letter-spacing-desktop,normal); text-transform: var(--vamtam-primary-font-transform,none);">Between Q2 2023 and Q2 2024, KELA has tracked more than 5,000 victims of ransomware and extortion actors, and the numbers are only growing year-on-year. Ransomware has become a huge business, and monetization opportunities are far broader than just the ransom demand itself. </span></p>
</div>
<div class="native--content">
<p>Our latest eBook takes a deep dive into the business of the ransomware supply chain, looking at headline-grabbing attacks, key personas that leverage the cybercrime underground for financial gain, and best practices for protecting your own organization. <a href="https://www.kelacyber.com/resources/guides/the-complete-guideto-combating-ransomware/">Download the eBook here</a>, or keep reading for some choice highlights.</p>
<h4>How Does Ransomware Work?</h4>
<p>When we think of ransomware, we imagine the end game — where attackers encrypt data and demand a ransom for its return. In a double extortion attack, the threat actors threaten to leak the stolen data, and in a triple extortion attack, additional methods are used such as DDoS attacks or a spam campaign, usually intended to up the pressure.</p>
<p>&nbsp;</p>
<p>However, by the time any of these tactics become apparent to the victim, the ransomware attack is at its final stages.</p>
<p>&nbsp;</p>
<p>A ransomware attack begins long before an organization has any idea that they are under fire. First, attackers <b>gather intelligence</b> and conduct active reconnaissance, picking an organization that they believe may lead to a large pay-day. Attackers then need to <b>obtain initial access </b>to the victims’ network<b>.</b> They can do this by purchasing initial access from Initial Access Brokers (IABs) who have done the majority of the legwork, or through compromised employee accounts mostly obtained through infostealers which often infect a system via malicious links and attachments hidden in emails, social engineering, malvertising or perhaps as a result of software vulnerabilities.</p>
<p>&nbsp;</p>
<p>Once inside, attackers use<b> lateral movement</b> and privilege escalation to expand their reach, finding sensitive data or gaining control over endpoints. This puts them where they need to be for <b>data exfiltration, </b>which they can then leverage when they threaten to leak the data, or sell it on. Only then do attackers <b>deploy their ransomware</b>, encrypting files and making them inaccessible, and establish a communication channel to<b> demand a ransomware payment. </b></p>
<h4>The Evolution of Ransomware Attacks</h4>
<p>Historically, a single hacker or group might have targeted an enterprise, going through all of these steps in their own silo. However, today ransomware attacks are predominantly the work of different people with different specializations, coming together to make an attack possible through the cybercrime ecosystem.</p>
<p>&nbsp;</p>
<p>Those who have the expertise to build the malware can focus there — while others may be hired as traffers, individuals whose role it is to spread the malware far and wide, or as negotiators, who are highly-skilled in getting ransoms paid quickly. Ransomware-as-a-Service is a growing trend, and Autoshops are also more common than ever — allowing hackers to simply ‘click-to-buy’ what they need, whether that’s attack tools, initial access, or lists of credentials.</p>
<p>&nbsp;</p>
<p>The cybercrime ecosystem isn’t only used to buy things, it’s also a community of threat actors who can use it to recruit and coordinate for attacks, negotiate with victims, and share their own methodologies and support for one another.</p>
<p>&nbsp;</p>
<p>These changes have allowed ransomware efforts to scale beyond what anyone could have imagined, giving attackers many more opportunities to target organizations, and providing a greater chance of financial gain.</p>
<h4>Where Do Criminals Find Initial Access in the Cybercrime Ecosystem?</h4>
<p>&nbsp;</p>
<p>In the past year compromised valid accounts (<a href="https://attack.mitre.org/techniques/T1078/">MITRE ID: 1078</a>) and user credentials have become the <a href="https://www.ibm.com/reports/threat-intelligence">top initial access vector</a> for cyber attacks. Criminals can find<a href="https://www.kelacyber.com/from-data-leaks-to-bot-led-takeovers-understanding-leaked-credentials-vs-compromised-accounts/"> credentials and compromised accounts</a> from a combination of four main sources:</p>
<p>&nbsp;</p>
<ul>
<li aria-level="1"><b>Botnet markets:</b> These offer threat actors a list of data and logs to sift through and choose from, starting from as little as $0.50.</li>
<li aria-level="1"><b>Telegram cloud of logs:</b> By subscribing to a monthly channel, criminals can gain access to all credentials from compromised machines.</li>
<li aria-level="1"><b>ULP files: </b>These credential lists can often contain millions of plaintext credentials, which are usernames and passwords with a corresponding URL.</li>
<li aria-level="1"><b>Initial access brokers:</b> IABs directly sell remote access to a compromised organization, so criminals can step in at the final stage and launch the attack.</li>
</ul>
<h4>Identity Security Offers Proactive Defense against Ransomware</h4>
<p>Keeping a spotlight on these sources is a core part of protecting your organization against ransomware. After all, your attack surface is no longer about perimeter security — it’s about knowing what the attackers know about you. By onboarding a robust identity security platform like KELA Identity Guard, you get exactly this vantage point.</p>
<p>&nbsp;</p>
<p>KELA Identity Guard monitors illicit dark web marketplaces, cybercrime forums, and messaging and bot marketplaces, so that any compromised credentials related to organizational domains, SaaS tools and IP addresses can be intercepted in real-time. It offers a wide range of insights into infostealer and bot-related information, including threat trends, compromised service categories, and more.</p>
<p style="text-align: right;">Nguồn: kelacyber.com</p>
</div>
</div>
<p><!-- .vgblk-rw-wrapper --></p>
<p>The post <a href="https://dibiz.vn/en/what-is-ransomware-and-why-is-it-such-a-big-business/">What is Ransomware? And Why is it Such a Big Business?</a> appeared first on <a href="https://dibiz.vn/en/">Deliver Intelligence - Dibiz JSC</a>.</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
