Feds shutter xDedic, a black market used to commit $68 million in fraud
Full article572 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
No arrests were reported as part of the operation. U.S. authorities worked closely with law enforcement in Belgium, Ukraine and the European police agency Europol to orchestrate the takedown.
An online marketplace that facilitated more than $68 million in fraud and cybercrime has been shut down following an international law enforcement operation, the U.S. Department of Justice announced Monday.
Hackers and thieves used the website, known as xDedic, to sell access to compromised computers located around the world and personal information belonging to U.S. residents, prosecutors said. Buyers could search the site by price, operating system or by the geographic region from where it was stolen, prosecutors said. The method of access was usually through credentials for Remote Desktop Protocol (RDP) servers.
The DOJ didn’t name any victims, but said they included major metropolitan transit organizations, emergency services, government agencies, pension funds, universities and others.
The site was shut down in 2016, only to re-emerge soon after on the dark web with the new stipulation that members pay $50 to enter.
“The xDedic marketplace operated across a widely distributed network and utilized bitcoin in order to hide the locations of its underlying servers and the identities of its administrators, buyers, and sellers,” the DOJ said in a statement.
No arrests were reported as part of the operation. U.S. authorities worked closely with law enforcement in Belgium, Ukraine and the European police agency Europol to orchestrate the takedown.
The xDedic site first entered the public consciousness in 2016 when security researchers from Kaspersky Lab showed that the site offered access to hacked servers from well known sites including Target and PayPal. By promising to let its users into such known websites via an easy-to-understand search function, xDedic lowered the barrier to entry for wannabe cybercriminals, Kaspersky said. For example, purchasing access to a European country’s network would have cost a buyer $6 at the time.
“The one-time cost gives a malicious buyer access to all the data on the server and the possibility to use this access to launch further attacks,” reported SecureList, Kaspersky’s blog. “It is a hacker’s dream, simplifying access to victims, making it cheaper and faster, and opening up new possibilities for both cybercriminals and advanced threat actors.”
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
Jail time for Maine child in 764 marks turning point in federal law enforcement
Technology
Threats
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/xdedic-shut-down-doj-europol/