{"id":20737,"date":"2022-12-07T15:22:21","date_gmt":"2022-12-07T23:22:21","guid":{"rendered":"https:\/\/www.palada.net\/index.php\/2022\/12\/07\/news-14470\/"},"modified":"2022-12-07T15:22:21","modified_gmt":"2022-12-07T23:22:21","slug":"news-14470","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2022\/12\/07\/news-14470\/","title":{"rendered":"The scammers who scam scammers on cybercrime forums: Part 1"},"content":{"rendered":"<p><strong>Credit to Author: Matt Wixey| Date: Wed, 07 Dec 2022 17:00:36 +0000<\/strong><\/p>\n<div class=\"entry-content lg:prose-lg mx-auto prose max-w-4xl\">\n<p>A scam lurks around every corner on criminal marketplaces. Way back in 2009, <a href=\"https:\/\/www.microsoft.com\/en-us\/research\/publication\/nobody-sells-gold-for-the-price-of-silver-dishonesty-uncertainty-and-the-underground-economy\/\">Microsoft pointed out that the underground economy was rife with dishonesty<\/a>, and in 2017, Digital Shadows reported on a database of \u2018rippers\u2019 (fraudsters who con criminals) created by marketplace users. In <a href=\"https:\/\/news.sophos.com\/en-us\/2022\/08\/04\/genesis-brings-polish-to-stolen-credential-marketplaces\/\">our recent coverage of Genesis Market<\/a>, we noted at least one scammy imitation of Genesis, designed to separate na\u00efve would-be cybercriminals (and possibly inexperienced security researchers and journalists) from their money.<\/p>\n<p>But generally, the topic hasn\u2019t received much attention. After all, why should it? If scammers target criminals, so much the better, right? At least they\u2019re attacking each other, not organizations or the general public.<\/p>\n<p>We thought there might be more to it, so we spent a few weeks digging into scammers who scam scammers on three prominent cybercrime forums \u2013 research we don\u2019t think has been done before. And we found five surprising things.<\/p>\n<p><strong>1. It\u2019s big business \u2013 a sub-economy in itself.<\/strong> In the last 12 months, cybercriminals have lost over $2.5 million USD to scams, just on those three forums. In fact, it\u2019s such a long-standing and prominent problem that forum administrators have created dedicated \u2018arbitration rooms\u2019 for users to report scams, attacks, and rippers.<\/p>\n<p><strong>2. Money isn\u2019t the only motive, and it\u2019s not just lower-tier threat actors involved.<\/strong> Personal beefs, rivalries, and wanting to destroy (or sometimes enhance) reputations can all result in scams. And it\u2019s not just small-time crooks. We saw prominent threat actors either accused of scamming or falling victim to scams themselves.<\/p>\n<p><strong>3. The attacks go beyond the usual \u2018rip-and-run.\u2019<\/strong> We saw referral cons, fake data leaks and tools, typosquatting, phishing, \u2018alt rep\u2019 scams (the use of sockpuppets to artificially inflate reputation scores), fake guarantors, blackmail, impersonated accounts, and backdoored malware. We even found instances where threat actors got revenge by scamming the scammers who scammed them.<\/p>\n<p><strong>4. We found examples of long-term, large-scale fraud.<\/strong> One of the biggest surprises came when we dug into that imitation Genesis site. With some detective work, we uncovered nineteen other sites all created by the same person or group, all imitating criminal marketplaces, and all intended to trick users into forking over a $100 \u2018activation fee.\u2019 We don\u2019t know for sure who\u2019s behind all those sites, but we discovered tentative links to a drug vendor who operates on several dark web sites.<\/p>\n<p>So far, so <em>schadenfreude<\/em> \u2013 but the big question is still: who cares? Why does it matter if criminals attack each other? This is where things get really fascinating.<\/p>\n<p><strong>5. Scam reports are a rich, and underexplored, source of intelligence.<\/strong> Threat actors are aware that criminal forums are monitored, and so often employ good operational security. When they\u2019re victims of crime themselves \u2013 well, not so much. Because forum rules demand proof to support scam allegations, wronged threat actors will often happily post screenshots of private conversations and source code, identifiers, transactions, chat logs, and blow-by-blow accounts of negotiations, sales, and troubleshooting.<\/p>\n<p>This hidden sub-economy isn\u2019t just a curiosity. It gives us insights into forum culture; how threat actors buy and sell; their tactical and strategic priorities; their rivals and alliances; their susceptibility to deception \u2013 and specific, discrete intelligence about them.<\/p>\n<p>Over the next few weeks, we\u2019ll share the findings of our extended investigation into this topic &#8211; starting with an overview of the forums involved, how they deal with scams, who\u2019s scamming who, and the size of the sub-economy.<\/p>\n<p>You can also check out <a href=\"https:\/\/www.blackhat.com\/eu-22\/briefings\/schedule\/index.html#scammers-who-scam-scammers-hackers-who-hack-hackers-exploring-a-hidden-sub-economy-on-cybercrime-forums-and-marketplaces-28427\">our Black Hat talk<\/a> on this research.<\/p>\n<h2>Welcome to the jungle<\/h2>\n<p>To kick off our investigation, we examined scams on two of the oldest and most prominent Russian-language cybercrime forums, Exploit and XSS. We also included scams from BreachForums, the successor to RaidForums, which launched in April 2022.<\/p>\n<h3>The forums<\/h3>\n<p>Exploit is relatively exclusive, and is a popular marketplace for <a href=\"https:\/\/www.trendmicro.com\/vinfo\/pl\/security\/news\/cybercrime-and-digital-threats\/investigating-the-emerging-access-as-a-service-market\">Access-as-a-Service (AaaS) listings<\/a>, where <a href=\"https:\/\/news.sophos.com\/en-us\/tag\/iabs\/\">initial access brokers (IABs) sell access to compromised networks<\/a>. But threat actors buy and sell a lot of other illicit content there too \u2013 malware, data leaks, infostealer logs, credentials, and more. Historically, ransomware groups and affiliates frequented Exploit, although that became more covert after the Colonial Pipeline attack in 2021, when <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/ransomware-ads-now-also-banned-on-exploit-cybercrime-forum\/\">both Exploit and XSS publicly banned ransomware discussion to avoid negative attention<\/a>. Nowadays, ransomware affiliate recruitment continues on both forums, although it tends to be under the cover of euphemisms like \u2018pentesters.\u2019<\/p>\n<p>XSS, formerly known as DaMaGeLaBs, is also well-established, although membership is less exclusive than Exploit. It also hosts a lot of AaaS listings and various other content.<\/p>\n<p>Finally, BreachForums is the successor to RaidForums, a marketplace that ran for seven years <a href=\"https:\/\/www.bbc.co.uk\/news\/technology-61082144\">before it was seized by law enforcement earlier in 2022<\/a>. Like RaidForums, BreachForums is an English-language cybercrime forum and marketplace specializing in data leaks, including personal data, credit cards, credentials, and identity documents.<\/p>\n<p>All three sites have dedicated arbitration rooms \u2013 Exploit (with approximately 2500 reported scams) and XSS (with around 760) have had them since the mid-2000s, and BreachForums since its creation in April 2022. Other criminal marketplaces, such as Verified, have them too.<\/p>\n<p>In fact, Exploit has two rooms \u2013 one for open claims, and another, called the \u2018Black List,\u2019 which documents confirmed scam cases.<\/p>\n<p><a href=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image1.png\"><img decoding=\"async\" loading=\"lazy\" class=\"alignnone wp-image-88489\" src=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image1.png\" alt=\"A screenshot from the Exploit forum showing two rooms: &quot;Arbitration&quot; and &quot;Black List&quot;\" width=\"1356\" height=\"287\" srcset=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image1.png 1326w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image1.png?resize=300,64 300w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image1.png?resize=768,163 768w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image1.png?resize=1024,217 1024w\" sizes=\"auto, (max-width: 1356px) 100vw, 1356px\" \/><\/a><\/p>\n<p><em>Figure 1: Exploit&#8217;s arbitration section<\/em><\/p>\n<p>In addition to a dedicated arbitration room, XSS also maintains a long \u2018ripper list,\u2019 an index of scam sites.<\/p>\n<p><a href=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image2.png\"><img decoding=\"async\" loading=\"lazy\" class=\"alignnone wp-image-88494\" src=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image2.png\" alt=\"A list of so-called 'ripper sites' - fake marketplaces - in a forum post\" width=\"1071\" height=\"606\" srcset=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image2.png 1251w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image2.png?resize=300,170 300w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image2.png?resize=768,435 768w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image2.png?resize=1024,580 1024w\" sizes=\"auto, (max-width: 1071px) 100vw, 1071px\" \/><\/a><\/p>\n<p><em>Figure 2: XSS&#8217;s ripper list<\/em><\/p>\n<h3>An overview of scam statistics<\/h3>\n<p>We looked at all scam reports citing monetary amounts in the last 12 months. (With BreachForums we went back to the first recorded scam, as the forum hasn\u2019t been around that long.)<\/p>\n<p><em>Table 1: A summary of 12 months of scam reports (all amounts in USD)<\/em><\/p>\n<p>While this is only a snapshot, it does give us some useful insights. First, the total amount lost to scams (and remember, this only involves scam reports which mention specific amounts \u2013 some don\u2019t) is $2,538,945. That\u2019s a significant amount, bearing in mind it\u2019s on just three forums.<\/p>\n<p>Second, Exploit is the worst for scams, both in terms of numbers of reports and money lost to scammers. It does have around twice as many members as XSS, and may also attract more scammers because of its reputation.<\/p>\n<p>Third, the mean average amount reported as stolen is similar across all three forums, as is the range \u2013 which suggests that the scale of scams is consistent regardless of the forum.<\/p>\n<p>Victims have filed scam reports for as little as $2; threat actors seem to be as indignant about having their money stolen as anyone else, no matter the amount.<\/p>\n<p>At the higher end, scams on all three marketplaces go into six figures, although these are the exceptions. Many scams net relatively insignificant amounts.<\/p>\n<p><a href=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image3.png\"><img decoding=\"async\" loading=\"lazy\" class=\"alignnone size-full wp-image-88495\" src=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image3.png\" alt=\"A snapshot of forum threads showing claim amounts\" width=\"640\" height=\"799\" srcset=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image3.png 676w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image3.png?resize=240,300 240w\" sizes=\"auto, (max-width: 640px) 100vw, 640px\" \/><\/a><\/p>\n<p><em>Figure 3: Low claim amounts in the XSS arbitration room<\/em><\/p>\n<p><a href=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image4.png\"><img decoding=\"async\" loading=\"lazy\" class=\"alignnone size-full wp-image-88496\" src=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image4.png\" alt=\"A snapshot of threads showing claim amounts\" width=\"640\" height=\"591\" srcset=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image4.png 666w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image4.png?resize=300,277 300w\" sizes=\"auto, (max-width: 640px) 100vw, 640px\" \/><\/a><\/p>\n<p><em>Figure 4: Low claim amounts in the BreachForums arbitration room<\/em><\/p>\n<p><a href=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image5.png\"><img decoding=\"async\" loading=\"lazy\" class=\"alignnone wp-image-88497\" src=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image5.png\" alt=\"A long forum post detailing a scam involving the sale of an exploit\" width=\"974\" height=\"604\" srcset=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image5.png 1398w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image5.png?resize=300,186 300w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image5.png?resize=768,476 768w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image5.png?resize=1024,635 1024w\" sizes=\"auto, (max-width: 974px) 100vw, 974px\" \/><\/a><\/p>\n<p><em>Figure 5: An example of a larger scam claim on Exploit ($130,000). Note the amount of detail in this scam claim, which includes information about negotiations and projects<\/em><\/p>\n<p>Before we examine the arbitration process, it\u2019s worth looking at why scams are so prevalent. Back in 2009, Microsoft argued that the underground cybercrime economy was not an \u201ceasy money criminal Utopia\u201d but a \u201clemon market,\u201d in which the presence of rippers effectively introduced a tax on every transaction.<\/p>\n<p>While times have changed, and cybercrime is more commoditized than it was, criminal marketplaces are still the perfect breeding ground for scammers and rippers. There\u2019s no recourse to law enforcement; it\u2019s a (semi) anonymous culture which emphasizes privacy; sites are exclusive enough that there\u2019s at least a degree of implicit trust; they\u2019re populated by criminals, who are arguably unlikely to consider themselves potential victims and may therefore be less wary of scams; it\u2019s an open market with no regulation or quality assurance; transactions are conducted with cryptocurrencies, which can be made effectively untraceable; and safeguards such as guarantors are optional (and, as we\u2019ll see in the next part of our series, can themselves be weaponized in the service of scams).<\/p>\n<h3>What are criminal marketplaces doing about scams?<\/h3>\n<p>The administrators of criminal forums are well aware that scams are a problem. In addition to arbitration rooms, most marketplaces have visible warnings about scammers, and advocate using guarantors (sometimes called \u2018middlemen\u2019 or \u2018middles\u2019) during sales \u2013 a form of escrow.<\/p>\n<p><a href=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image6.png\"><img decoding=\"async\" loading=\"lazy\" class=\"alignnone wp-image-88498\" src=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image6.png\" alt=\"A warning about scams on the BreachForums homepage\" width=\"924\" height=\"182\" srcset=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image6.png 802w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image6.png?resize=300,59 300w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image6.png?resize=768,151 768w\" sizes=\"auto, (max-width: 924px) 100vw, 924px\" \/><\/a><\/p>\n<p><em>Figure 6: A warning about scams on the front page of BreachForums<\/em><\/p>\n<p>Other forums go further. Verified, for example, explicitly warns users about fake links to its forum, and advocates using a custom plugin to detect such scams:<\/p>\n<p><a href=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image7.png\"><img decoding=\"async\" loading=\"lazy\" class=\"alignnone wp-image-88499\" src=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image7.png\" alt=\"A forum post in Russian which advises users to be wary of scams\" width=\"932\" height=\"150\" srcset=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image7.png 1466w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image7.png?resize=300,48 300w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image7.png?resize=768,124 768w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image7.png?resize=1024,166 1024w\" sizes=\"auto, (max-width: 932px) 100vw, 932px\" \/><\/a><\/p>\n<p><em>Figure 7: Verified&#8217;s scam warning<\/em><\/p>\n<p>In a similar vein, BreachForums publishes a list of all its legitimate domains, as well as a monthly \u2018transparency report\u2019, to confirm that the site and related infrastructure remain under its control and have not been compromised (although this is probably also a precautionary measure because of <a href=\"https:\/\/arstechnica.com\/tech-policy\/2022\/04\/us-seizes-raidforums-the-go-to-site-for-hackers-selling-stolen-login-details\/\">what happened to RaidForums<\/a>):<\/p>\n<p><a href=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image8.png\"><img decoding=\"async\" loading=\"lazy\" class=\"alignnone wp-image-88500\" src=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image8.png\" alt=\"A forum post which tells users there will be a monthly transparency report \" width=\"941\" height=\"219\" srcset=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image8.png 1299w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image8.png?resize=300,70 300w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image8.png?resize=768,179 768w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image8.png?resize=1024,239 1024w\" sizes=\"auto, (max-width: 941px) 100vw, 941px\" \/><\/a><\/p>\n<p><em>Figure 8: Details about BreachForums&#8217; monthly transparency report<\/em><\/p>\n<p>But arbitration rooms are the main method for dealing with scams. The process is relatively simple. Users who wish to report a scam must create a new thread, call out the user who allegedly scammed them, and provide as much detail as possible about the incident. BreachForums provides a template for this, whereas XSS simply lists the details needed.<\/p>\n<p><a href=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image9.png\"><img decoding=\"async\" loading=\"lazy\" class=\"alignnone wp-image-88501\" src=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image9.png\" alt=\"A forum post which details what needs to be included in a scam report\" width=\"934\" height=\"318\" srcset=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image9.png 1204w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image9.png?resize=300,102 300w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image9.png?resize=768,262 768w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image9.png?resize=1024,349 1024w\" sizes=\"auto, (max-width: 934px) 100vw, 934px\" \/><\/a><\/p>\n<p><em>Figure 9: The BreachForums scam report template<\/em><\/p>\n<p><a href=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image10.png\"><img decoding=\"async\" loading=\"lazy\" class=\"alignnone wp-image-88502\" src=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image10.png\" alt=\"A forum post in Russian which details the content needed in a scam report\" width=\"934\" height=\"197\" srcset=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image10.png 945w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image10.png?resize=300,63 300w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image10.png?resize=768,163 768w\" sizes=\"auto, (max-width: 934px) 100vw, 934px\" \/><\/a><\/p>\n<p><em>Figure 10: The data required in XSS scam reports: nick, link to profile, contact details, evidence (chat logs, screenshots, wallets, transfers), any additional information<\/em><\/p>\n<p>A moderator then reviews the report, asks for more information if needed, and tags the accused, giving them a deadline by which to respond (commonly 24 hours, but can be between 12 and 72 hours).<\/p>\n<p><a href=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image11.png\"><img decoding=\"async\" loading=\"lazy\" class=\"alignnone wp-image-88503\" src=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image11.png\" alt=\"A moderator responds to a scam report, in Russian\" width=\"897\" height=\"478\" srcset=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image11.png 1184w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image11.png?resize=300,160 300w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image11.png?resize=768,409 768w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image11.png?resize=1024,545 1024w\" sizes=\"auto, (max-width: 897px) 100vw, 897px\" \/><\/a><\/p>\n<p><em>Figure 11: An Exploit moderator gives an accused scammer 24 hours to respond to an allegation<\/em><\/p>\n<p>The accused may accept the claim, in which case they make restitution to the victim. This is rare. More commonly, the accused disputes the claim (in which case the moderator arbitrates) or doesn\u2019t respond at all (in which case they may be temporarily or permanently banned from the forum).<\/p>\n<p><a href=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image12.png\"><img decoding=\"async\" loading=\"lazy\" class=\"alignnone wp-image-88504\" src=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image12.png\" alt=\"Two users argue about a scam report\" width=\"962\" height=\"290\" srcset=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image12.png 1568w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image12.png?resize=300,90 300w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image12.png?resize=768,231 768w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image12.png?resize=1024,308 1024w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image12.png?resize=1536,462 1536w\" sizes=\"auto, (max-width: 962px) 100vw, 962px\" \/><\/a><\/p>\n<p><em>Figure 12: A disputed claim on XSS relating to AaaS listings<\/em><\/p>\n<p>In disputed claims, the moderator may find for one party, or decide there is no case to answer due to a lack of evidence. In some cases, one or both parties will receive warnings, or temporary or permanent bans.<\/p>\n<p><a href=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image13.png\"><img decoding=\"async\" loading=\"lazy\" class=\"alignnone wp-image-88505\" src=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image13.png\" alt=\"An administrator closes a scam report because of a lack of evidence\" width=\"919\" height=\"507\" srcset=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image13.png 1348w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image13.png?resize=300,165 300w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image13.png?resize=768,423 768w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image13.png?resize=1024,564 1024w\" sizes=\"auto, (max-width: 919px) 100vw, 919px\" \/><\/a><\/p>\n<p><em>Figure 13: The BreachForums administrator closes a scam report due to lack of evidence<\/em><\/p>\n<p><a href=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image14.png\"><img decoding=\"async\" loading=\"lazy\" class=\"alignnone wp-image-88506\" src=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image14.png\" alt=\"Two users argue over a scam report\" width=\"921\" height=\"344\" srcset=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image14.png 1548w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image14.png?resize=300,112 300w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image14.png?resize=768,287 768w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image14.png?resize=1024,382 1024w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image14.png?resize=1536,574 1536w\" sizes=\"auto, (max-width: 921px) 100vw, 921px\" \/><\/a><\/p>\n<p><em>Figure 14: A disputed claim on Exploit, regarding a crypter for use with <a href=\"https:\/\/news.sophos.com\/en-us\/2022\/07\/20\/ooda-x-ops-takes-on-burgeoning-sql-server-attacks\/\">Remcos<\/a><\/em><\/p>\n<p>These discussions are sometimes civil, and settled amicably to the satisfaction of both parties. We noted an example where the arbiter ruled that the accused should pay back 50% of the claimed amount:<\/p>\n<p><a href=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image15.png\"><img decoding=\"async\" loading=\"lazy\" class=\"alignnone wp-image-88507\" src=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image15.png\" alt=\"An administrator rules that an accused scammer has to pay back 50% of the claimed amount to the claimant\" width=\"923\" height=\"225\" srcset=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image15.png 1036w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image15.png?resize=300,73 300w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image15.png?resize=768,187 768w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image15.png?resize=1024,249 1024w\" sizes=\"auto, (max-width: 923px) 100vw, 923px\" \/><\/a><\/p>\n<p><em>Figure 15: An Exploit moderator gives the accused 24 hours to pay back 50% of the claimed amount<\/em><\/p>\n<p>In one case, the administrator of BreachForums even compensated a scam victim out of their own pocket:<\/p>\n<p><a href=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image16.png\"><img decoding=\"async\" loading=\"lazy\" class=\"alignnone wp-image-88508\" src=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image16.png\" alt=\"An administrator says they will personally refund a scam victim\" width=\"925\" height=\"360\" srcset=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image16.png 1368w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image16.png?resize=300,117 300w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image16.png?resize=768,299 768w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image16.png?resize=1024,398 1024w\" sizes=\"auto, (max-width: 925px) 100vw, 925px\" \/><\/a><\/p>\n<p><em>Figure 16: The BreachForums administrator personally compensates a scam victim to the tune of $200<\/em><\/p>\n<p>But scam reports more commonly descend into insults and counteraccusations. In some cases, the alleged victims were themselves later banned for scamming.<\/p>\n<p><a href=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image17.png\"><img decoding=\"async\" loading=\"lazy\" class=\"alignnone wp-image-88509\" src=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image17.png\" alt=\"A user accused of being a scammer accuses the complainant of being a scammer\" width=\"925\" height=\"331\" srcset=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image17.png 1557w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image17.png?resize=300,108 300w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image17.png?resize=768,275 768w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image17.png?resize=1024,367 1024w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image17.png?resize=1536,550 1536w\" sizes=\"auto, (max-width: 925px) 100vw, 925px\" \/><\/a><\/p>\n<p><em>Figure 17: A scam report on Exploit results in the accuser accusing the accuser of scamming<\/em><\/p>\n<h3>Consequences<\/h3>\n<p>Bans (and to a lesser extent, warnings) seem to be the most common outcome in arbitrations, but BreachForums takes a slightly different approach. Perhaps to deter future scammers, its moderators publish banned users\u2019 sign-up email addresses and registration and last-seen IP addresses, thus partially doxing them:<\/p>\n<p><a href=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image18.png\"><img decoding=\"async\" loading=\"lazy\" class=\"alignnone wp-image-88510\" src=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image18.png\" alt=\"A screenshot of a banned user's profile\" width=\"918\" height=\"188\" srcset=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image18.png 873w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image18.png?resize=300,62 300w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image18.png?resize=768,157 768w\" sizes=\"auto, (max-width: 918px) 100vw, 918px\" \/><\/a><\/p>\n<p><em>Figure 18: An example of a banned user, complete with published sign-up email address, and registration and last known IP addresses<\/em><\/p>\n<p>We noticed a couple of cases involving serial scammers who, after being banned, simply created a new profile with a new identity, paid a new registration fee, and began scamming again.<\/p>\n<h3>Not just small-time crooks<\/h3>\n<p>We noted a few examples where more prominent threat actors were involved. For instance, here\u2019s a curious case which wasn\u2019t so much a scam, but involved a user who wanted to negotiate with the Conti ransomware group on behalf of a victim:<\/p>\n<p><a href=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image19.png\"><img decoding=\"async\" loading=\"lazy\" class=\"alignnone wp-image-88511\" src=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image19.png\" alt=\"A scam report against the Conti ransomware group which asks for a ransomed victim's network to be decrypted\" width=\"968\" height=\"360\" srcset=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image19.png 1555w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image19.png?resize=300,112 300w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image19.png?resize=768,286 768w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image19.png?resize=1024,381 1024w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image19.png?resize=1536,572 1536w\" sizes=\"auto, (max-width: 968px) 100vw, 968px\" \/><\/a><\/p>\n<p><em>Figure 19: A user opens an arbitration claim to try and negotiate with the Conti groupabout decryption of a company&#8217;s assets<\/em><\/p>\n<p>This report was closed by Exploit moderators because it related to ransomware, which is ostensibly banned on that forum. But what\u2019s interesting is that the complainant appears to be a threat actor in their own right, and had joined the Exploit forum over three years before opening the above claim \u2013 with multiple posts expressing an interest in purchasing data. Their relationship to Conti\u2019s victim in this case isn\u2019t clear.<\/p>\n<p><a href=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image20.png\"><img decoding=\"async\" loading=\"lazy\" class=\"alignnone size-full wp-image-88512\" src=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image20.png\" alt=\"A summary of a user's previous posts in the forum, which show they are interested in buying and selling illicit data\" width=\"640\" height=\"583\" srcset=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image20.png 915w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image20.png?resize=300,273 300w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image20.png?resize=768,699 768w\" sizes=\"auto, (max-width: 640px) 100vw, 640px\" \/><\/a><\/p>\n<p><em>Figure 20: Some of the complainant&#8217;s previous posts on the Exploit forum<\/em><\/p>\n<p>Another case involved \u2018Alan Wake\u2019 (a name taken from a video game), who sponsored the most recent <a href=\"https:\/\/www.digitalshadows.com\/blog-and-research\/competitions-on-russian-language-cybercriminal-forums-sharing-expertise-or-threat-actor-showboating\/\">contest on XSS<\/a>, and was previously <a href=\"https:\/\/twitter.com\/S0ufi4n3\/status\/1552584941040504833\">accused by a Lockbit operator of being the leader of the Conti and BlackBasta ransomware groups<\/a>. A user accused Alan Wake of not paying their salary for \u2018making traffic from shells\u2019:<\/p>\n<p><a href=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image21.png\"><img decoding=\"async\" loading=\"lazy\" class=\"alignnone wp-image-88513\" src=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image21.png\" alt=\"A scam report, in Russian, against the user 'Alan Wake'\" width=\"772\" height=\"316\" srcset=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image21.png 901w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image21.png?resize=300,123 300w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image21.png?resize=768,315 768w\" sizes=\"auto, (max-width: 772px) 100vw, 772px\" \/><\/a><\/p>\n<p><em>Figure 21: The XSS scam report against &#8216;Alan Wake&#8217;<\/em><\/p>\n<p>Alan Wake disputed the allegation, and the case was closed by the administrator and the complainant banned \u2013 not for scamming, but for &#8220;insults, assaults, threats, etc\u2019 and \u2018extremely inappropriate behavior.&#8221;<\/p>\n<p>Finally, All World Cards (also a previous sponsor of XSS contests), a prominent carding group, were themselves victims of a scam involving a fake vulnerability, losing $2000 USD.<\/p>\n<p><a href=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image22.png\"><img decoding=\"async\" loading=\"lazy\" class=\"alignnone wp-image-88514\" src=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image22.png\" alt=\"A scam report from All World Cards, about a vulnerability which cost them $2000\" width=\"802\" height=\"168\" srcset=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image22.png 1456w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image22.png?resize=300,63 300w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image22.png?resize=768,160 768w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image22.png?resize=1024,214 1024w\" sizes=\"auto, (max-width: 802px) 100vw, 802px\" \/><\/a><\/p>\n<p><em>Figure 22: The All World Cards group report a scam in which they lost $2000<\/em><\/p>\n<p>If there\u2019s a takeaway from all this, it\u2019s that no user is immune; any trade on criminal forums involves an inherent risk of scams. While there are both proactive (warnings, plugins, guarantors) and reactive (arbitration rooms) measures in place, scammers are not only common, but \u2013 judging by the data we gathered \u2013 often successful. One of the reasons for their success is the sheer diversity of the scams they pull.<\/p>\n<p>In the second part of our investigation, due out this time next week (Wednesday 14 December), we\u2019ll cover the different types of scams we observed.<\/p>\n<\/p><\/div>\n<p><a href=\"https:\/\/news.sophos.com\/en-us\/2022\/12\/07\/the-scammers-who-scam-scammers-on-cybercrime-forums-part-1\/\" target=\"bwo\" >http:\/\/feeds.feedburner.com\/sophos\/dgdY<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/shutterstock_1547115068.jpg\"\/><\/p>\n<p><strong>Credit to Author: Matt Wixey| Date: Wed, 07 Dec 2022 17:00:36 +0000<\/strong><\/p>\n<p>A shadowy sub-economy is more than just a curiosity \u2013 it\u2019s booming business, and also an opportunity for defenders. In the first of a four-part series, we look at the forums involved, and how they deal with scammers scamming scammers<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10378,10377],"tags":[28038,28039,11638,129,28040,21828,10574,27030,16771,15775],"class_list":["post-20737","post","type-post","status-publish","format-standard","hentry","category-security","category-sophos","tag-aaas","tag-breachforums","tag-exploit","tag-featured","tag-marketplaces","tag-raidforums","tag-scams","tag-sophos-x-ops","tag-threat-research","tag-xss"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/20737","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=20737"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/20737\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=20737"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=20737"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=20737"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}