Story image

Access to thousands of breached sites found on Russian underground market

09 Oct 2018

Access to approximately 3,000 breached websites has been discovered for sale on a Russian-speaking underground marketplace called MagBo.

Access to some of the sites is selling for as low as 50 cents (USD).

Analysts at Flashpoint who discovered the availability of access to the breached sites said that most of the victims come from e-commerce, while other victims in industries such as healthcare, legal, education, insurance, and government agencies were also found.

A number of the available servers investigated by Flashpoint led analysts to conclude that most of the breaches are from either US, Russian, or German hosting services. 

This particular market is populated by more than a dozen vendors and hundreds of buyers who sell and take part in auctions in order to gain access to breached sites, databases, and administrator panels.

Flashpoint has shared its findings with law enforcement, which is working to notify victims.

Access to breached sites an uneasy trend

Illicit access to compromised or backdoored sites and databases is used by criminals for a number of activities, ranging from spam campaigns to fraud, or cryptocurrency mining. These compromises have also been used to gain access to corporate networks.

This could potentially allow actors to access proprietary internal documents or resources, as well as entry points through which they can drop various malicious payloads.

The types of vulnerabilities present and the ways in which they can be exploited depending on the threat actor's specific capability, motivation, targeting, and goals. 

This is an uneasy trend that may have manifested itself already in a few high-profile publicly disclosed incidents.

A recent well-publicised breach, for example, involved custom-built infrastructure, according to researchers at RiskIQ, allowing the attackers to avoid detection and compromise the data of 380,000 customers.

Such an attack likely required compromised access and the ability to manipulate site content and inject code in order to steal customer data.

Today, a month-long breach at a computer retailer was disclosed.

Attackers were able to inject code into the retailer’s site that sniffed for payment card numbers.

In both breaches, researchers at RiskIQ and Volexity said the Magecart hacking group was behind the attacks. 

MagBo a recent development on the underground 

Flashpoint analysts say the earliest advertisements for the MagBo market were posted in March to a top-tier Russian-language hacking and malware forum.

The threat actor offered the market as a destination for sales of access to breached sites.

Posts advertise access to websites that were breached via:

●      PHP shell access

●      Hosting control access

●      Domain control access

●      File Transfer Protocol (FTP) access

●      Secure Socket Shell (SSH) access

●      Admin panel access

●      Database or Structured Query Language (SQL) access

Potential customers will also find descriptions of the privilege levels available from the market, with labels such as "full access permissions," "abilities to edit content," and "add your content.”

In addition to access to breached websites, this particular market also sells stolen photocopies of national documents for identity fraud, breached payment wallet access, compromised social media accounts, and Bitcoin mixer or tumbler services.

Prices for compromised websites range from $0.50 USD to $1,000 USD per access, depending on a website ranking listing various host parameters.

These parameters allow the buyer to purchase the exact breach they need depending on the website value as determined and checked by the store. 

High-value targets would obviously fetch a higher price and capabilities to inject payment card sniffers or other tools for deeper network penetration.

Sites with a lower ranking and a lesser perceived value are more likely to be abused for cryptocurrency mining or spam delivery.

Pre-emptive measures to protect against website exploitation include conducting audits and reviews of any externally accessible websites and their connections to any organisation networks.

Hackbusters! Reviewing 90 days of cybersecurity incident response cases
While there are occasionally very advanced new threats, these are massively outnumbered by common-or-garden email fraud, ransomware attacks and well-worn old exploits.
SEGA turns to Palo Alto Networks for cybersecurity protection
When one of the world’s largest video game pioneers wanted to strengthen its IT defences against cyber threats, it started with firewalls and real-time threat intelligence from Palo Alto Networks.
Forrester names Trend Micro Leader in email security
TrendMicro earned the highest score for technology leadership, deployment options and cloud integration.
LogRhythm releases cloud-based SIEM solution
LogRhythm Cloud provides the same feature set and user experience as its on-prem experience.
One Identity named Leader in PAM and IAM by KuppingerCole
KuppingerCole lead analyst Anmol Singh evaluated the strengths and weaknesses of 20 solution providers in the PAM market for the report.
Healthcare environments difficult to secure - Forescout
The convergence of IT, Internet of Things (IoT) and operational technology (OT) makes it more difficult for the healthcare industry to manage a wide array of hard-to-control network security risks.
Bitglass appoints new cloud, business development leaders
The cloud security company has appointed vice presidents for worldwide channels and worldwide business development.
Exploring the different needs for cloud services across Europe
Although digital transformation is happening across Europe, each country continues to have its own IT needs and the different cloud markets highlight this.