{"id":20876,"date":"2022-12-21T05:20:57","date_gmt":"2022-12-21T13:20:57","guid":{"rendered":"https:\/\/www.palada.net\/index.php\/2022\/12\/21\/news-14609\/"},"modified":"2022-12-21T05:20:57","modified_gmt":"2022-12-21T13:20:57","slug":"news-14609","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2022\/12\/21\/news-14609\/","title":{"rendered":"The scammers who scam scammers on cybercrime forums: Part 3"},"content":{"rendered":"<p><strong>Credit to Author: Matt Wixey| Date: Wed, 21 Dec 2022 11:00:08 +0000<\/strong><\/p>\n<div class=\"entry-content lg:prose-lg mx-auto prose max-w-4xl\">\n<p>In the <a href=\"https:\/\/news.sophos.com\/en-us\/2022\/12\/07\/the-scammers-who-scam-scammers-on-cybercrime-forums-part-1\/\">first chapter of this series<\/a>, we provided an overview of the hidden sub-economy of scammers who scam scammers, and <a href=\"https:\/\/news.sophos.com\/en-us\/2022\/12\/14\/the-scammers-who-scam-scammers-on-cybercrime-forums-part-2\/\">in the second<\/a> we examined the wide variety of scams and tricks within it.<\/p>\n<p>The third chapter is a little different. It covers a specific scam we uncovered during our research, which we highlight because of its scale, levels of coordination, and apparent success.<\/p>\n<h2>The curious case of twenty fake marketplaces<\/h2>\n<p>During <a href=\"https:\/\/news.sophos.com\/en-us\/2022\/08\/04\/genesis-brings-polish-to-stolen-credential-marketplaces\/\">our research into Genesis Market<\/a>, we found a clearnet site (<strong>genesismarket[.]org<\/strong>) that looked nothing like the genuine Genesis Market site but appeared prominently in search engine results.<\/p>\n<p><a href=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image1-3.png\"><img decoding=\"async\" loading=\"lazy\" class=\"alignnone wp-image-88730\" src=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image1-3.png\" alt=\"A screenshot of a fake Genesis Market site, showing a welcome message and a table of credit card numbers, blurred\" width=\"1108\" height=\"788\" srcset=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image1-3.png 1241w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image1-3.png?resize=300,213 300w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image1-3.png?resize=768,546 768w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image1-3.png?resize=1024,729 1024w\" sizes=\"auto, (max-width: 1108px) 100vw, 1108px\" \/><\/a><\/p>\n<p><em>Figure 1: The fake Genesis Market site<\/em><\/p>\n<p>We quickly determined that the site didn\u2019t seem to be connected to the genuine Genesis Market. For one thing, the site demands a $100 USD deposit, whereas the real Genesis is invitation-only.<\/p>\n<p><a href=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image2-3.png\"><img decoding=\"async\" loading=\"lazy\" class=\"alignnone wp-image-88731\" src=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image2-3.png\" alt=\"A demand for $100 on the fake Genesis site\" width=\"1052\" height=\"531\" srcset=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image2-3.png 1424w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image2-3.png?resize=300,151 300w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image2-3.png?resize=768,388 768w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image2-3.png?resize=1024,517 1024w\" sizes=\"auto, (max-width: 1052px) 100vw, 1052px\" \/><\/a><\/p>\n<p><em>Figure 2: The deposit demand on the fake Genesis site<\/em><\/p>\n<p>The site asks users to pay in Bitcoin or Monero:<\/p>\n<p><a href=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image3-3.png\"><img decoding=\"async\" loading=\"lazy\" class=\"alignnone wp-image-88732\" src=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image3-3.png\" alt=\"A Bitcoin deposit page, listing a BTC address\" width=\"1015\" height=\"479\" srcset=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image3-3.png 1492w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image3-3.png?resize=300,142 300w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image3-3.png?resize=768,362 768w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image3-3.png?resize=1024,483 1024w\" sizes=\"auto, (max-width: 1015px) 100vw, 1015px\" \/><\/a><\/p>\n<p><em>Figure 3: The fake site&#8217;s deposit page<\/em><\/p>\n<p>This, and a few other elements (such as the \u2018lost password\u2019 button not redirecting anywhere, and some falsified \u2018forum posts\u2019) led us to assume it was a crude, low-effort, one-off scam, designed to take advantage of inexperienced researchers, would-be threat actors, and the generally curious.<\/p>\n<p><a href=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image4-3.png\"><img decoding=\"async\" loading=\"lazy\" class=\"alignnone wp-image-88733\" src=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image4-3.png\" alt=\"A forum post on one of the fake marketplaces which lists the forum 'rules'\" width=\"842\" height=\"622\" srcset=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image4-3.png 993w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image4-3.png?resize=300,222 300w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image4-3.png?resize=768,568 768w\" sizes=\"auto, (max-width: 842px) 100vw, 842px\" \/><\/a><\/p>\n<p><em>Figure 4: Some of the low-effort fake forum posts<\/em><\/p>\n<p>But three things piqued our curiosity.<\/p>\n<p>The first was that the onion link on the homepage doesn\u2019t link to an onion site at all, but to <strong>genesismarket[.]org\/benumbiernqlud55izbw4mdubush4zhzpg4rw3c2j6ew3ggpzbb7gdqd[.]onion<\/strong>. Benumb is a carding site, and we wondered if someone from that marketplace was running the scam and had made a mistake with the link.<\/p>\n<p>The second thing was that the <strong>Copy address<\/strong> button on the deposit page triggers some JavaScript, which copies a different Bitcoin address to the clipboard:<\/p>\n<p><a href=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image5-3.png\"><img decoding=\"async\" loading=\"lazy\" class=\"alignnone wp-image-88734\" src=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image5-3.png\" alt=\"A screenshot showing the Firefox browser inspector relating to the 'Copy Address' button\" width=\"953\" height=\"381\" srcset=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image5-3.png 1507w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image5-3.png?resize=300,120 300w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image5-3.png?resize=768,307 768w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image5-3.png?resize=1024,409 1024w\" sizes=\"auto, (max-width: 953px) 100vw, 953px\" \/><\/a><\/p>\n<p><em>Figure 5: Clicking the &#8216;Copy address&#8217; button results in a different address being copied to the clipboard<\/em><\/p>\n<p>And the third was that someone had actively advertised this site on Reddit, which suggested the scam might be more coordinated than we first thought:<\/p>\n<p><a href=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image6-3.png\"><img decoding=\"async\" loading=\"lazy\" class=\"alignnone wp-image-88735\" src=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image6-3.png\" alt=\"A Reddit post which advertises the fake Genesis Market site\" width=\"912\" height=\"426\" srcset=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image6-3.png 748w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image6-3.png?resize=300,140 300w\" sizes=\"auto, (max-width: 912px) 100vw, 912px\" \/><\/a><\/p>\n<p><em>Figure 6: A now-deleted Reddit post advertising the fake site<\/em><\/p>\n<p>We visited the \u2018Benumb\u2019 link and found a site set up in exactly the same way, with the same demand for $100 (albeit with different Bitcoin and Monero addresses):<\/p>\n<p><a href=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image7-3.png\"><img decoding=\"async\" loading=\"lazy\" class=\"alignnone wp-image-88736\" src=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image7-3.png\" alt=\"A fake Benumb site\" width=\"945\" height=\"499\" srcset=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image7-3.png 1636w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image7-3.png?resize=300,158 300w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image7-3.png?resize=768,406 768w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image7-3.png?resize=1024,541 1024w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image7-3.png?resize=1536,811 1536w\" sizes=\"auto, (max-width: 945px) 100vw, 945px\" \/><\/a><\/p>\n<p><em>Figure 7: The fake Benumb page, with an ironic phishing warning<\/em><\/p>\n<p><a href=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image8-2.png\"><img decoding=\"async\" loading=\"lazy\" class=\"alignnone wp-image-88737\" src=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image8-2.png\" alt=\"A Bitcoin deposit page for the fake Benumb site\" width=\"952\" height=\"394\" srcset=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image8-2.png 1354w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image8-2.png?resize=300,124 300w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image8-2.png?resize=768,318 768w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image8-2.png?resize=1024,424 1024w\" sizes=\"auto, (max-width: 952px) 100vw, 952px\" \/><\/a><\/p>\n<p><em>Figure 8: The fake Benumb&#8217;s wallet page<\/em><\/p>\n<p>And when we looked at the credit card numbers on the homepage, we discovered that they were identical to the ones listed on the fake Genesis site.<\/p>\n<p><a href=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image9-2.png\"><img decoding=\"async\" loading=\"lazy\" class=\"alignnone wp-image-88738\" src=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image9-2.png\" alt=\"The fake Benumb homepage, with credit card numbers in the background\" width=\"974\" height=\"609\" srcset=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image9-2.png 1334w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image9-2.png?resize=300,188 300w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image9-2.png?resize=768,480 768w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image9-2.png?resize=1024,640 1024w\" sizes=\"auto, (max-width: 974px) 100vw, 974px\" \/><\/a><\/p>\n<p><em>Figure 9: The credit card numbers and details on the fake Benumb homepage&#8230;<\/em><\/p>\n<p><a href=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image10-2.png\"><img decoding=\"async\" loading=\"lazy\" class=\"alignnone wp-image-88739\" src=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image10-2.png\" alt=\"The same credit card numbers on the fake Genesis Market site\" width=\"1018\" height=\"679\" srcset=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image10-2.png 1327w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image10-2.png?resize=300,200 300w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image10-2.png?resize=768,513 768w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image10-2.png?resize=1024,684 1024w\" sizes=\"auto, (max-width: 1018px) 100vw, 1018px\" \/><\/a><\/p>\n<p><em>Figure 10: &#8230;which are exactly the same as those on the fake Genesis site<\/em><\/p>\n<p>We started querying search engines for portions of the text, the credit card details, and the cryptocurrency addresses, to find other sites created by the same scammer.<\/p>\n<p>All in all we found <em>twenty<\/em> sites, registered between August 2021 and June 2022, which we assess with high confidence are operated by the same individual or group. Virtually all of them imitate existing or defunct criminal marketplaces (including multiple scam versions of Genesis, Benumb, UniCC, and Pois0n), ask for an activation deposit of $100, and have a similar look and feel. Some employ the same clipboard substitution quirk, and some don\u2019t. We also observed a few other minor differences, like background color or slight modifications to the spiel.<\/p>\n<p><a href=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image11-2.png\"><img decoding=\"async\" loading=\"lazy\" class=\"alignnone wp-image-88740\" src=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image11-2.png\" alt=\"The fake Yale Lodge homepage\" width=\"914\" height=\"520\" srcset=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image11-2.png 1463w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image11-2.png?resize=300,171 300w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image11-2.png?resize=768,437 768w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image11-2.png?resize=1024,582 1024w\" sizes=\"auto, (max-width: 914px) 100vw, 914px\" \/><\/a><\/p>\n<p><em>Figure 11: A scam version of YaleLodge, a criminal marketplace<\/em><\/p>\n<p><a href=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image12-2.png\"><img decoding=\"async\" loading=\"lazy\" class=\"alignnone wp-image-88741\" src=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image12-2.png\" alt=\"The fake WWH Club site, with the same activation notice\" width=\"915\" height=\"446\" srcset=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image12-2.png 1581w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image12-2.png?resize=300,146 300w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image12-2.png?resize=768,375 768w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image12-2.png?resize=1024,499 1024w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image12-2.png?resize=1536,749 1536w\" sizes=\"auto, (max-width: 915px) 100vw, 915px\" \/><\/a><\/p>\n<p><em>Figure 12: A scam version of another marketplace, WWH Club<\/em><\/p>\n<p><a href=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image13-2.png\"><img decoding=\"async\" loading=\"lazy\" class=\"alignnone wp-image-88742\" src=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image13-2.png\" alt=\"The fake Brian's Club, with a similar template to the other scam sites\" width=\"959\" height=\"544\" srcset=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image13-2.png 1516w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image13-2.png?resize=300,170 300w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image13-2.png?resize=768,436 768w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image13-2.png?resize=1024,582 1024w\" sizes=\"auto, (max-width: 959px) 100vw, 959px\" \/><\/a><\/p>\n<p><em>Figure 13: A scam version of Brian&#8217;s Club, yet another criminal marketplace<\/em><\/p>\n<p><a href=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image14-2.png\"><img decoding=\"async\" loading=\"lazy\" class=\"alignnone wp-image-88744\" src=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image14-2.png\" alt=\"The fake UniCC site, again with a similar template\" width=\"950\" height=\"533\" srcset=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image14-2.png 1528w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image14-2.png?resize=300,168 300w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image14-2.png?resize=768,431 768w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image14-2.png?resize=1024,575 1024w\" sizes=\"auto, (max-width: 950px) 100vw, 950px\" \/><\/a><\/p>\n<p><em>Figure 14: A scam version of the UniCC carding site (<a href=\"https:\/\/www.bbc.co.uk\/news\/technology-59983950\">the genuine site closed in January 2022<\/a>). Note that this site also contains a link to the fake Benumb site<\/em><\/p>\n<p><a href=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image15-2.png\"><img decoding=\"async\" loading=\"lazy\" class=\"alignnone wp-image-88745\" src=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image15-2.png\" alt=\"The fake Pois0n CC site, again using a similar template\" width=\"955\" height=\"549\" srcset=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image15-2.png 1499w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image15-2.png?resize=300,173 300w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image15-2.png?resize=768,442 768w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image15-2.png?resize=1024,589 1024w\" sizes=\"auto, (max-width: 955px) 100vw, 955px\" \/><\/a><\/p>\n<p><em>Figure 15: A scam version of Pois0n, another criminal marketplace<\/em><\/p>\n<p>Along the way, we found evidence that the scammer was advertising other sites on Reddit:<\/p>\n<p><a href=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image16-1.png\"><img decoding=\"async\" loading=\"lazy\" class=\"alignnone wp-image-88746\" src=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image16-1.png\" alt=\"A Reddit post advertising the fake Benumb[.]cards site\" width=\"821\" height=\"654\" srcset=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image16-1.png 1013w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image16-1.png?resize=300,239 300w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image16-1.png?resize=768,612 768w\" sizes=\"auto, (max-width: 821px) 100vw, 821px\" \/><\/a><\/p>\n<p><em>Figure 16: A Reddit post promoting one of the fake Benumb sites<\/em><\/p>\n<p>We did find one anomaly \u2013 a site called \u2018Cashout Guide\u2019, which claims to teach users carding and fraud (for a fee, naturally) \u2013 which nonetheless has a similar appearance to the scam marketplaces:<\/p>\n<p><a href=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image17-2.png\"><img decoding=\"async\" loading=\"lazy\" class=\"alignnone wp-image-88747\" src=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image17-2.png\" alt=\"The cashout[.]guide site\" width=\"876\" height=\"656\" srcset=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image17-2.png 1128w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image17-2.png?resize=300,225 300w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image17-2.png?resize=768,575 768w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image17-2.png?resize=1024,767 1024w\" sizes=\"auto, (max-width: 876px) 100vw, 876px\" \/><\/a><\/p>\n<p><em>Figure 17: Available tiers on the Cashout Guide site<\/em><\/p>\n<p>Of the twenty sites we found, thirteen are no longer active. Most are clearnet sites, although we discovered three onion sites (and one clearnet site masquerading as an onion site).<\/p>\n<p>Here\u2019s a full list, along with the associated Bitcoin addresses and registration information (where available):<\/p>\n<p><em style=\"font-size: 1em\">Table 1: The sites we discovered<\/em><\/p>\n<p>When we collated information from all the Bitcoin addresses (by design, the balances of Monero addresses are hidden), we found that this scam network has been lucrative. Together, those addresses have received over $132,000 \u2013 and most of it has been withdrawn, leaving a total balance of only $1,633.34.<\/p>\n<p>We can\u2019t say for certain whether all the inputs to those addresses are related to the scam (i.e., we don\u2019t know if the scammer has used them for other business), and in a few cases, the timelines didn\u2019t add up (a few addresses made their first transaction before the associated site(s) were registered, so some inputs may have been unrelated to the scam). But even taking those examples out, there was still $87,676 going into those wallets.<\/p>\n<p>One big question remained: who was behind the scam?<\/p>\n<p>We found something we thought might be a clue: on some sites, the footer contains a link to a website called <strong>darknet[.]markets<\/strong> (there appear to be a few versions of this site with very similar content, including <strong>darknetmarket[.]org<\/strong> and <strong>dark[.]markets<\/strong>).<\/p>\n<p><a href=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image19-2.png\"><img decoding=\"async\" loading=\"lazy\" class=\"alignnone wp-image-88748\" src=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image19-2.png\" alt=\"A screenshot of one of the scam marketplaces, with a prominent footer linking to darknet[.]markets\" width=\"843\" height=\"651\" srcset=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image19-2.png 1131w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image19-2.png?resize=300,232 300w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image19-2.png?resize=768,593 768w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image19-2.png?resize=1024,790 1024w\" sizes=\"auto, (max-width: 843px) 100vw, 843px\" \/><\/a><\/p>\n<p><em>Figure 18: A link to darknet[.]markets on the scam site unic[.]cards<\/em><\/p>\n<p>These sites are indexes of dark web criminal marketplaces, for visitors interested in drugs sales, carding, and cryptocurrency exchanges. Not only do they look similar to the scam marketplaces (and with similar hosting\/registration details), they also list several of the fake marketplaces we discovered.<\/p>\n<p><a href=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image20-2.png\"><img decoding=\"async\" loading=\"lazy\" class=\"alignnone wp-image-88749\" src=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image20-2.png\" alt=\"The carding section on one of the index sites, which prominently lists some of the scam marketplaces\" width=\"766\" height=\"741\" srcset=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image20-2.png 845w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image20-2.png?resize=300,290 300w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image20-2.png?resize=768,743 768w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image20-2.png?resize=32,32 32w\" sizes=\"auto, (max-width: 766px) 100vw, 766px\" \/><\/a><\/p>\n<p><em>Figure 19: The &#8216;carding&#8217; section on dark[.]markets<\/em><\/p>\n<p>Most of the activation notices on the scam marketplaces mention a carding forum on the criminal marketplace Dread (also known as Caf\u00e9 Dread). We searched the names of the index sites on Dread, and found a post by a user called <strong>waltcranston <\/strong>(the username is likely inspired by the television series <em>Breaking Bad<\/em>), who claimed to have created them:<\/p>\n<p><a href=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image21-2.png\"><img decoding=\"async\" loading=\"lazy\" class=\"alignnone wp-image-88750\" src=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image21-2.png\" alt=\"A Cafe Dread post by waltcranston in which the user says they have made a website and want it to become a 'one-stop shop for everything related to darknet markets'\" width=\"856\" height=\"198\" srcset=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image21-2.png 1274w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image21-2.png?resize=300,69 300w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image21-2.png?resize=768,178 768w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image21-2.png?resize=1024,237 1024w\" sizes=\"auto, (max-width: 856px) 100vw, 856px\" \/><\/a><\/p>\n<p><em>Figure 20: waltcranston&#8217;s post (now deleted)<\/em><\/p>\n<p>We also found at least one Dread user who seemed to fall for one of the scams:<\/p>\n<p><a href=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image22-2.png\"><img decoding=\"async\" loading=\"lazy\" class=\"alignnone wp-image-88751\" src=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image22-2.png\" alt=\"A Cafe Dread user asks if it's normal to wait for 2 hours when they've sent $100 for Benumb activation\" width=\"853\" height=\"172\" srcset=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image22-2.png 881w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image22-2.png?resize=300,61 300w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image22-2.png?resize=768,155 768w\" sizes=\"auto, (max-width: 853px) 100vw, 853px\" \/><\/a><\/p>\n<p><em>Figure 21: A Dread user&#8217;s post\u00a0<\/em><\/p>\n<p>We dug further into the index sites, and found waltcranston listed prominently in the \u2018Drug Markets\u2019 section:<\/p>\n<p><a href=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image23-1.png\"><img decoding=\"async\" loading=\"lazy\" class=\"alignnone wp-image-88752\" src=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image23-1.png\" alt=\"The 'drugs' section on one of the index sites, which advertises 'Walt Cranston's Meth Delivery Service'\" width=\"832\" height=\"602\" srcset=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image23-1.png 945w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image23-1.png?resize=300,217 300w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image23-1.png?resize=768,555 768w\" sizes=\"auto, (max-width: 832px) 100vw, 832px\" \/><\/a><\/p>\n<p><em>Figure 22: waltcranston&#8217;s onion link on one of the index sites<\/em><\/p>\n<p>waltcranston is a self-proclaimed methamphetamine dealer on both Dread and other marketplaces such as Alphabay. By their own admission they\u2019re based in the US:<\/p>\n<p><a href=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image24-1.png\"><img decoding=\"async\" loading=\"lazy\" class=\"alignnone wp-image-88753\" src=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image24-1.png\" alt=\"A post by waltcranston in which the user says &quot;They are getting stricter here in the US too...&quot;\" width=\"1148\" height=\"113\" srcset=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image24-1.png 1302w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image24-1.png?resize=300,29 300w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image24-1.png?resize=768,76 768w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image24-1.png?resize=1024,101 1024w\" sizes=\"auto, (max-width: 1148px) 100vw, 1148px\" \/><\/a><\/p>\n<p><em>Figure 23: waltcranston claims to be based in the US<\/em><\/p>\n<p>Their website appears to use a similar template to the scam marketplaces, and the clearnet version has similar hosting and registration details:<\/p>\n<p><a href=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image25-1.png\"><img decoding=\"async\" loading=\"lazy\" class=\"alignnone wp-image-88754\" src=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image25-1.png\" alt=\"waltcranston's meth delivery site, which offers methamphetamine for sale\" width=\"998\" height=\"638\" srcset=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image25-1.png 1321w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image25-1.png?resize=300,192 300w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image25-1.png?resize=768,491 768w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image25-1.png?resize=1024,654 1024w\" sizes=\"auto, (max-width: 998px) 100vw, 998px\" \/><\/a><\/p>\n<p><em>Figure 24: waltcranston&#8217;s vendor site<\/em><\/p>\n<p>We also found that one of the fake forum posts on at least one of the scam marketplaces was written by a waltcranston:<\/p>\n<p><a href=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image26-1.png\"><img decoding=\"async\" loading=\"lazy\" class=\"alignnone wp-image-88755\" src=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image26-1.png\" alt=\"A screenshot of one of the fake forum posts from a scam marketplace, which was written by a waltcranston\" width=\"778\" height=\"625\" srcset=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image26-1.png 770w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image26-1.png?resize=300,241 300w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image26-1.png?resize=768,617 768w\" sizes=\"auto, (max-width: 778px) 100vw, 778px\" \/><\/a><\/p>\n<p><em>Figure 25: A forum post on one of the fake Benumb marketplaces<\/em><\/p>\n<p>waltcranston uses both Bitcoin and Monero, as shown in this post:<\/p>\n<p><a href=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image27-1.png\"><img decoding=\"async\" loading=\"lazy\" class=\"alignnone wp-image-88756\" src=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image27-1.png\" alt=\"A post by waltcranston on Cafe Dread\" width=\"1300\" height=\"321\" srcset=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image27-1.png 1431w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image27-1.png?resize=300,74 300w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image27-1.png?resize=768,190 768w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image27-1.png?resize=1024,253 1024w\" sizes=\"auto, (max-width: 1300px) 100vw, 1300px\" \/><\/a><\/p>\n<p><em>Figure 26: In a post relating to their methamphetamine business, waltcranston confirms they use both Bitcoin and Monero<\/em><\/p>\n<p>And several of waltcranston\u2019s posts indicate a familiarity with criminal marketplaces and an open-minded attitude towards phishing and scamming, particularly when it comes to imitating specific marketplaces:<\/p>\n<p><a href=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image28-1.png\"><img decoding=\"async\" loading=\"lazy\" class=\"alignnone wp-image-88757\" src=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image28-1.png\" alt=\"A post by waltcranston on Cafe Dread\" width=\"1077\" height=\"340\" srcset=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image28-1.png 905w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image28-1.png?resize=300,94 300w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image28-1.png?resize=768,242 768w\" sizes=\"auto, (max-width: 1077px) 100vw, 1077px\" \/><\/a><\/p>\n<p><em>Figure 27: waltcranston recommends Genesis Market to another user<\/em><\/p>\n<p><a href=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image29-2.png\"><img decoding=\"async\" loading=\"lazy\" class=\"alignnone wp-image-88758\" src=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image29-2.png\" alt=\"A post by waltcranston on Cafe Dread\" width=\"1067\" height=\"150\" srcset=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image29-2.png 1148w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image29-2.png?resize=300,42 300w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image29-2.png?resize=768,108 768w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image29-2.png?resize=1024,145 1024w\" sizes=\"auto, (max-width: 1067px) 100vw, 1067px\" \/><\/a><\/p>\n<p><em>Figure 28: waltcranston passes on some advice regarding phishing sites &#8220;tailor-made to a specific market or shop&#8221;<\/em><\/p>\n<p><a href=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image30-1.png\"><img decoding=\"async\" loading=\"lazy\" class=\"alignnone wp-image-88759\" src=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image30-1.png\" alt=\"A post by waltcranston on Cafe Dread\" width=\"1067\" height=\"100\" srcset=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image30-1.png 1306w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image30-1.png?resize=300,28 300w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image30-1.png?resize=768,72 768w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image30-1.png?resize=1024,96 1024w\" sizes=\"auto, (max-width: 1067px) 100vw, 1067px\" \/><\/a><\/p>\n<p><em>Figure 29: waltcranston suggests running a phishing site to another user<\/em><\/p>\n<p><a href=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image31-1.png\"><img decoding=\"async\" loading=\"lazy\" class=\"alignnone wp-image-88765\" src=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image31-1.png\" alt=\"A post by waltcranston on Cafe Dread\" width=\"1064\" height=\"241\" srcset=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image31-1.png 821w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image31-1.png?resize=300,68 300w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image31-1.png?resize=768,174 768w\" sizes=\"auto, (max-width: 1064px) 100vw, 1064px\" \/><\/a><\/p>\n<p><em>Figure 30: waltcranston with a tongue-in-cheek quote about vendors turning to scamming<\/em><\/p>\n<p>A Dread user had come to the same conclusion as us, publicly posting this accusation:<\/p>\n<p><a href=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image32-1.png\"><img decoding=\"async\" loading=\"lazy\" class=\"alignnone wp-image-88761\" src=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image32-1.png\" alt=\"A post by a user on Cafe Dread which accuses waltcranston of running multiple scam sites\" width=\"1063\" height=\"294\" srcset=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image32-1.png 1448w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image32-1.png?resize=300,83 300w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image32-1.png?resize=768,212 768w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image32-1.png?resize=1024,283 1024w\" sizes=\"auto, (max-width: 1063px) 100vw, 1063px\" \/><\/a><\/p>\n<p><em>Figure 31: A Dread user calls out waltcranston for running some of the scam marketplaces we discovered<\/em><\/p>\n<p>waltcranston did not confirm or deny the allegation in his responses, although other Dread users chipped in:<\/p>\n<p><a href=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image33-2.png\"><img decoding=\"async\" loading=\"lazy\" class=\"alignnone wp-image-88766\" src=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image33-2.png\" alt=\"Reactions from Dread users to the allegations against waltcranston\" width=\"1067\" height=\"220\" srcset=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image33-2.png 1329w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image33-2.png?resize=300,62 300w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image33-2.png?resize=768,158 768w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image33-2.png?resize=1024,211 1024w\" sizes=\"auto, (max-width: 1067px) 100vw, 1067px\" \/><\/a><\/p>\n<p><em>Figure 32: Some Dread users condemned scammers<\/em><\/p>\n<p>In the above conversation, the accuser suggests a possible motivation for waltcranston running these scamming sites \u2013 retirement from dealing methamphetamine.<\/p>\n<p>Other Dread users were more apathetic about the situation:<\/p>\n<p><a href=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image34-1.png\"><img decoding=\"async\" loading=\"lazy\" class=\"alignnone wp-image-88763\" src=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image34-1.png\" alt=\"More reactions from Cafe Dread users on the allegation\" width=\"1076\" height=\"148\" srcset=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image34-1.png 1279w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image34-1.png?resize=300,41 300w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image34-1.png?resize=768,106 768w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/image34-1.png?resize=1024,141 1024w\" sizes=\"auto, (max-width: 1076px) 100vw, 1076px\" \/><\/a><\/p>\n<p><em>Figure 33: Two Dread users less concerned about scammers<\/em><\/p>\n<p>We should point out here that most of this evidence is circumstantial, and we didn\u2019t find any discrete identifiers which link waltcranston to the fake marketplaces.<\/p>\n<p>In the final part of our series, due out Wednesday 28 December, we\u2019ll show why this subject matters. Scam reports are a rich, and underexplored, source of intelligence; threat actors are aware that criminal forums are monitored, and so often employ good operational security \u2013 but when they\u2019re victims of crime themselves, not so much. Because forum rules demand proof to support scam allegations, wronged threat actors will often post screenshots of private conversations and source code, identifiers, transactions, chat logs, and blow-by-blow accounts of negotiations, sales, and troubleshooting. We\u2019ll share some case studies and wrap up our series with some recommendations and ideas for future research.<\/p>\n<\/p><\/div>\n<p><a href=\"https:\/\/news.sophos.com\/en-us\/2022\/12\/21\/the-scammers-who-scam-scammers-on-cybercrime-forums-part-3\/\" target=\"bwo\" >http:\/\/feeds.feedburner.com\/sophos\/dgdY<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/12\/shutterstock_772227661.jpg\"\/><\/p>\n<p><strong>Credit to Author: Matt Wixey| Date: Wed, 21 Dec 2022 11:00:08 +0000<\/strong><\/p>\n<p>A shadowy sub-economy is more than just a curiosity \u2013 it\u2019s booming business, and also an opportunity for defenders. In the third part of our series, we look at the curious case of twenty fake marketplaces.<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10378,10377],"tags":[28217,129,25788,28040,10574,27030,16771],"class_list":["post-20876","post","type-post","status-publish","format-standard","hentry","category-security","category-sophos","tag-dread","tag-featured","tag-genesis","tag-marketplaces","tag-scams","tag-sophos-x-ops","tag-threat-research"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/20876","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=20876"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/20876\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=20876"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=20876"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=20876"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}