HomeTechnologyOperation Cookie Monster: FBI...

Operation Cookie Monster: FBI dismantles largest forum due to stolen passwords

The joint work of various authorities made it possible to close Genesis.Market | Fountain: Europol

adUnits.push({
code: ‘Rpp_tecnologia_mas_tecnologia_Nota_Interna1’,
mediaTypes: {
banner: {
sizes: (navigator.userAgent.match(/iPhone|android|iPod/i)) ? [[300, 250], [320, 460], [320, 480], [320, 50], [300, 100], [320, 100]] : [[300, 250], [320, 460], [320, 480], [320, 50], [300, 100], [320, 100], [635, 90]]
}
},
bids: [{
bidder: ‘appnexus’,
params: {
placementId: ‘14149971’
}
},{
bidder: ‘rubicon’,
params: {
accountId: ‘19264’,
siteId: ‘314342’,
zoneId: ‘1604128’
}
},{
bidder: ‘amx’,
params: {
tagId: ‘MTUybWVkaWEuY29t’
}
},{
bidder: ‘oftmedia’,
params: {
placementId: navigator.userAgent.match(/iPhone|android|iPod/i) ? ‘22617692’: ‘22617693’
}
}]
});

A heavy blow to cybercrime. Dismemberment of the largest forum on stolen passwords, genesis.market, were the latest news in the world of cybersecurity. This market It has been active since 2017 and allowed cybercriminals not only to sell access to stolen credentials from infected systems, but also to gain direct access to those systems through the parallel sale of cookies and session tokens.

Last Wednesday, the FBI announced that it had seized his web domains, deactivating the forum and dismantling the criminal organization that supported it. This intervention took place as part of Operation Cookie Monster, which involved various European, Canadian and American institutions.

Now, when you enter these sites, the description “This website has been changed” appears, a message posted by the FBI on the pages it tampers with.

“Through the combined efforts of all involved law enforcement agencies, we have seriously disrupted the cybercrime ecosystem by removing one of its main drivers,” mentions Edvardas Šileris, head of the Europol European Cybercrime Center. “With victims all over the world, strong relationships with our international partners have been critical to the success of this case.”

Genesis.Market how dangerous was this group?

Genesis Market was primarily in the business of selling stolen digital identities. The marketplace offered for sale what the owners called “bots” that would infect victims’ devices with malware or account takeover attacks.

By purchasing one of these bots, the criminals gained access to all the data it collects, such as fingerprints, cookies, saved passwords, and autofill form data. This information was collected in real time and buyers were notified of any password changes, etc.

The price of each bot ranged from $0.70 to several hundred dollars, depending on the amount and nature of the stolen data. The most expensive contained financial information that allowed access to online banking accounts.

The criminals who bought these special bots received not only the stolen data, but also the funds to use it. They were given their own browser that mimicked their victim’s browser, allowing them to access their account without activating any of the security measures of the platform that hosted the credentials to be used. These security measures include recognizing different login locations, a different browser fingerprint, or a different operating system.

My account was hacked?

If you are concerned that your data has been affected, the Netherlands Police have set up a website where users can check if their Genesis.market access credentials have been sold. Just enter your email address and if the answer is yes, you will receive a message in the corresponding account’s inbox.

If you suspect that your accounts have been stolen, here are some recommendations:

change your passwords right away and make sure they are secure and unique for each account.

Enable two-factor authentication on all your accounts, which allow you to add an extra layer of security.

Monitor your accounts regularly to detect any suspicious activity.

Consider using a password manager to create and manage strong passwords for all your accounts.

Source: RPP

- A word from our sponsors -

Most Popular

LEAVE A REPLY

Please enter your comment!
Please enter your name here

More from Author

- A word from our sponsors -

Read Now

Archie from the Russian Federation wears a “printer”

The invaders use the silence regime to clean the river. .in_text_content_22 {width: 300px; Height: 600px; } @Media (min-width: 600px) {.in_text_content_22 {width: 580px; Height: 400px; }} .Adsbygoogle {Touch-Action: Manipulation; } The Russian army organizes heavy equipment routes, hiding and using the so...

APU boys fell based on Toretsky, ES from Bend – Zelensky

The Ukrainian military was ambushed in the direction of Toretsky. .in_text_content_22 {width: 300px; Height: 600px; } @Media (min-width: 600px) {.in_text_content_22 {width: 580px; Height: 400px; }} .Adsbygoogle {Touch-Action: Manipulation; } There are victims among the defenders. The invaders will be destroyed, and...

Russian Federation Throw Dronov from Curtains to Donbass – ISW

The country of the aggressor turned off the units of drones from the Kursk region to Donbas. .in_text_content_22 {width: 300px; Height: 600px; } @Media (min-width: 600px) {.in_text_content_22 {width: 580px; Height: 400px; }} .Adsbygoogle {Touch-Action: Manipulation; } The uncertain units of the...