Skip to main content

Over 120,000 Computers Compromised by Info Stealers Linked to Users of Cybercrime Forums.


A "staggering" 120,000 computers infected by stealer malware have credentials associated with cybercrime forums, many of them belonging to malicious actors.

The findings come from Hudson Rock, which analyzed data collected from computers compromised between 2018 to 2023.

"Hackers around the world infect computers opportunistically by promoting results for fake software or through YouTube tutorials directing victims to download infected software," Hudson Rock CTO Alon Gal told The Hacker News.

"It is not a case of the threat actor infecting his own computer, it is that out of the 14,500,000 computers we have in our cybercrime database, some of them happen to be hackers that accidentally got infected."

Data retrieved from machines compromised by stealer malware is often expansive and wide-ranging, enabling the real-world identities of hackers to be discovered based on indicators such as credentials, addresses, phone numbers, computer names, and IP addresses.

Information stealers have also fueled the malware-as-a-service (MaaS) ecosystem, positioning them as one of the most lucrative initial attack vectors used by threat actors to infiltrate organizations and execute a variety of attacks, ranging from espionage to ransomware.

An examination of the pilfered information reveals that the cybercrime forum with the highest number of infected users is Nulled.to with an excess of 57,000 users, followed by Cracked.io (19,062) and Hackforums.net (13,366).

"The forum with the strongest user passwords is 'Breached.to,' while the one with the weakest user passwords is the Russian site 'Rf-cheats.ru,'" the company said, with over 41% of the credentials featuring at least 10 characters and containing four types of characters.

"Overall, passwords from cybercrime forums are stronger than passwords used for government websites, and exhibit fewer 'very weak' passwords than industries like the military."

A vast majority of the infections have been attributed to RedLine, Raccoon, and AZORult. The top countries from which hackers were infected and had at least one credential to a cybercrime forum include Tunisia, Malaysia, Belgium, the Netherlands, and Israel.

"The main takeaways from this finding is that although info stealer infections typically cause harm to companies due to hackers taking advantage of credentials to infiltrate employee and user accounts, they can also be useful for attribution against cyber criminals by law enforcement," Gal said.

The development comes as Flare's analysis of more than 19.6 million stealer logs found that 376,107 of them provide access to corporate SaaS applications and that logs containing financial services logins were listed at $112.27, in comparison to $14.31 for the rest.

It also follows the temporary shutdown of Discord.io after it suffered a data breach in which the details pertaining to no less than 760,000 users were leaked on the new Breach hacking forum, which officially resurfaced in June 2023 under the leadership of ShinyHunters.

By THN.

Comments

Popular posts from this blog

Vurra Constituency MP Adriko Yovan gets six months imprisonment for failing to repay loan.

📸: Hon Adriko Yovan. Story By Andrew Cohen Amvesi. ARUA . Yovan Adriko, the Vurra County Member of Parliament (MP) in Arua district has been committed to six months civil prison for failing to clear debts amounting to shs55,677,400. Adriko was on Thursday evening sent to Arua government prison to serve six months shortly after his arrest at Slumberland hotel in Arua City. MP Adriko warrant of committal judgement debtor to jail. Paul Mawa of T/A Vitality Associates, the court bailiff assigned to arrest the MP, duped him to come and pick some money for a land transaction at Slumberland hotel where he picked him like a baby after a long hunt. Adriko was immediately arraigned before Her Worship Karungi Leo, the Deputy Registrar of Arua High Court who later committed him to imprisonment not exceeding six months. Part of Adriko’s warrant of arrest issued b court Adriko was sent to the coolers for failing to clear shs48m which is the princip

Arrested Arua City Officials Taken to Kampala this Night.

Wednesday 8-November-2023. 📸: The arrest of Arua City Physical Planner Mr Findru Moses on 6-Nov-2023 at around 2pm. 📸: Mr Jobile Cornelius the City Deputy town clerk who was arrested on 7-Nov-2023 at around 4pm. 📸: Mrs Lillian Aleni (in red cloth) and Mr Edoni Benard being handcuffed by police officer on 6-Nov-2023 at around 6pm. The bail that was to be issued last night 8pm 7-Nov-2023 to release the arrested City Deputy town clerk Mr Jobile Cornelius and CFO Mr Sam Adriko over mismanagement of government properties and monies was canceled, and by this time of the night 11pm, highly placed sources leaked that, all the arrested suspects (Mr Findru Moses the Arua City Physical Planner, Mr Jobile Cornelius the Deputy City clerk, Mr Adriko Sam the CFO, Mr Edoni Benard the PDM BOG Chairperson for Pangisa ward and Mrs Lillian Aleni the parish chief for Pangisa ward) are being transported by State House Anti-corruption Unit officers who will soon be reac

Wedded Ayivu West MP Lematia John Fights Over Another Woman.

  📸: Hon Lematia John. By URN. Police in Arua district are investigating a case of assault and threatening violence involving the Member of Parliament for Ayivu West Constituency John Lematia and James Ariko, a DSTV technician in Arua city. Drama ensued on Easter Sunday 31-3-2024 at Dream Land Hotel located at Kuluva trading center along Arua-Nebbi highway in Arua district when the legislator and the technician engaged in a fight reportedly over a woman identified as Faith Eyotaru 25, a relationship officer at Victoria University Kampala. The scuffle started after Ayivu West Mp John Lematia went to swim at Dreamland Hotel with Faith Eyotaru only to find Ariko, who had gone to the same hotel earlier. However, upon seeing the duo coming out of the vehicle, Ariko confronted Lematia with both men claiming to be having a relationship with the lady. It took the intervention of the staff at the hotel who intervened and separated the fight between the men. Josephine Angucia, the West Nile re