OXFORD, U.K. — 十二月 21, 2022 —

Sophos, a global leader in innovating and delivering cybersecurity as a service, today revealed details of how it tracked down the likely culprit behind more than 20 fake criminal marketplaces designed to con cyberscammers in part three of Sophos’ series, “The Scammers Who Scam Scammers on Cybercrime Forums.” After stumbling upon a surface website mimicking the real criminal underground site Genesis, Sophos researchers further uncovered the 20 fake marketplaces dating back to August 2021. All of the fake sites appeared to be run by a scammer who uses the handle “waltcranston,” a likely riff on the television show “Breaking Bad.”

“While investigating this huge sub-economy of scammers scamming other scammers, we examined about 600 scams of varying types. Out of all the scams investigated, this operation stood out for its sheer scope and intricacy. The scammer advertises the fake marketplaces on Reddit and replicates not just Genesis, which was the first scam site we ran across, but numerous other prominent or defunct marketplaces, such as Benumb, UniCC, and PoisOn. While at a technical level these scam sites are not sophisticated, the scam operation has been highly successful. In fact, seven of these fake sites are still active, and, to date, the cryptocurrency wallets associated with the scams have received at least $132,000,” said Matt Wixey, senior threat researcher, Sophos.

All 20 of the fake sites followed a similar scheme. Criminals were offered a chance to activate an account on the fraudulent version of a dark web marketplace with $100. The criminals expected their $100 would be deposited in either Bitcoin or Monero, and they would receive activation credentials. However, as part of the scam, once the criminals paid, their account would never activate.

Screenshot: The deposit demand from the fake Genesis site


Sophos X-Ops: The deposit demand from the fake Genesis site

 

One common denominator among the 20 fake sites was a link to a website called darknet[.]markets—a site that lists dark web criminal marketplaces for visitors interested in drugs sales, carding, and cryptocurrency exchanges. This site ultimately led Sophos to a criminal forum called Café Dread—and a user going by the name of waltcranston.

Screenshot: A post on Dread Cafe

Sophos X-Ops: A post on Dread Café by waltcranston (now deleted)


“We started searching Dread for any mentions of the marketplaces mentioned on the darknet[.]markets, and we found multiple posts by the handle waltcranston talking about dark web marketplaces, as well as discussing how to scam people and recommending other users set up phishing sites. His own website, which sells meth, also shared some similarities with the fake marketplaces. We even found posts by Dread users who fell for the scam websites, and accusations by a Dread user that waltcranston was the culprit behind the scheme. While we can’t be 100% certain that those behind the handle waltcranston is indeed the culprit, there is strong circumstantial evidence. The entire operation and our investigation is an example of how much rich intelligence there is about cybercriminals hidden in these scams against other scammers, which the security community can leverage to help develop stronger defenses,” said Wixey.

Read more about these 20 fake marketplaces in Scammers Scamming Scammers Part 3 on Sophos.com.

关于 Sophos

Sophos 是全球领先的网络安全公司,凭借其人工智能驱动的平台和专家主导的服务,保护着全球 60 万家组织的安全。Sophos 根据各组织在不同安全成熟度的各式各样的需求提供支持,并与其共同成长,携手应对日益严峻的网络攻击。其解决方案结合机器学习、自动化、实时威胁情报以及来自 Sophos X-Ops 的前线真人专家的专业知识,提供 24/7 全天候高级威胁监控、侦测与响应服务。
Sophos 提供行业领先的托管式侦测与响应 (MDR) 服务,同时配备一整套全面的网络安全技术组合,包括端点、网络、电子邮件和云安全、扩展式侦测与响应 (XDR)、身份辨识威胁侦测与响应 (ITDR),以及下一代 SIEM。结合专家咨询服务,这些能力帮助组织主动降低风险,并更迅速地响应,提供力求在不断变化的威胁面前保持领先所需的可见性和可扩展性。
Sophos 通过全球合作伙伴生态系统进入市场,包括托管式服务提供商 (MSPs)、托管式安全服务提供商 (MSSPs)、经销商、分销商、市场集成商以及网络风险合作伙伴,为组织提供灵活的选择,使其能够在保护业务安全的同时建立值得信赖的合作关系。  Sophos 总部位于英国牛津。如欲了解更多信息,请访问 www.sophos.cn。