135: The D.R. Incident

4 Jul 2023 · 43 min

Ask about this episode

Ask anything about it. ChatGPT or Claude reads this page and answers with the times it was said.

Connect VO and ask about every podcast you hear, including the moments you saved. Add to ChatGPT · Add to Claude

In short

Darknet Diaries Episode Summary

Episode Title

135: The D.R. Incident

Episode Description In this episode, host Jack Rhysider interviews Omar Avilez, a member of the Cybersecurity Incident Response Team (CSIRT) for the Dominican Republic, as he recounts a major cybersecurity incident that impacted the country. Omar discusses his experiences, the procedures followed during the incident, and sheds light on the evolving landscape of cyber threats.

---

Key Themes and Topics Discussed

  1. Setting the Scene
  2. Omar shares a recurring dream that symbolizes feelings of fear and helplessness, which parallels the cybersecurity challenges he faced.
  3. The episode emphasizes the vulnerability of organizations to cyber attacks.
  1. The Context of the Incident
  2. The narrative begins with a series of ransomware attacks in Costa Rica attributed to the Conti ransomware group, prompting concerns across Latin America.
  3. Omar, working in the Dominican Republic's CSIRT, was drawn to the unfolding crisis in Costa Rica, where 20 government organizations were affected.
  1. Incident Response Procedures
  2. Omar and his team began to scan the Dominican Republic's computer infrastructure for signs of the same malware.
  3. During this investigation, they discovered a long-term malware implant on a government website.
  1. Discovery of Multiple Threats
  2. The Dominican Republic faced ransomware attacks from the Quantum Ransomware Group, which affected crucial government services.
  3. Omar's team swiftly acted to halt the spread of this attack, showcasing the importance of rapid response.
  1. Emerging Threats and Collaborations
  2. Omar's efforts revealed a coordinated attack involving not only Quantum but also potential involvement from the Dark Caracal group and even ties to Russian cyber actors.
  3. The complexity of the attack included phishing emails in perfect Spanish, hinting at sophisticated planning by the attackers.
  1. Understanding Cybersecurity Landscape
  2. Different types of attackers were discussed: hacktivists, financially motivated groups, and state-sponsored hackers.
  3. The importance of attribution in understanding the motivations and potential future actions of attackers.
  1. Community and Collaboration
  2. Omar emphasizes the value of connections within the cybersecurity community and the importance of sharing information about threats.
  3. His proactive outreach to Costa Rica and other nations exemplifies the necessity for collaboration in cybersecurity.
  1. The Aftermath and Reflections
  2. After extensive work, Omar's team managed to clear the malware from the systems and prevent a significant ransomware execution.
  3. The episode concludes with reflections on the ongoing vulnerabilities in cybersecurity and the complexities of defending against sophisticated threats.

---

Key Takeaways

  • Vulnerability and Preparedness
  • Organizations must remain vigilant and prepared for potential cyber threats, especially in interconnected networks.
  • Importance of Rapid Response
  • Quick action in identifying and mitigating threats can prevent larger-scale damage, as demonstrated by Omar's team.
  • Collaboration is Crucial
  • Building relationships within the cybersecurity community can lead to better information-sharing and quicker incident responses.
  • Complexity of Cyber Threats
  • Cyber attacks are not always straightforward, with multiple actors and motivations complicating the response efforts.
  • Need for Constant Monitoring
  • With evolving threats, continuous monitoring and updating of cybersecurity measures are essential to safeguard sensitive information.

---

Conclusion This episode offers an in-depth look at the challenges faced by cybersecurity professionals in the Dominican Republic during a series of ransomware attacks. It underscores the need for vigilance, rapid response, and collaboration among nations to combat the ever-evolving landscape of cyber threats.

For more information on the episode, visit [Darknet Diaries](https://darknetdiaries.com/) and explore the resources discussed throughout the conversation.

Written by AI. May contain mistakes. Listen to the episode to check what was said.

Hear the part that matters, and keep it.Open this episode in VO. Double tap your headphones to save a moment as you listen.
Get VO free

Transcript

Automatic transcript. May contain errors.

0:00So throughout my life, I've had this recurring dream. It starts out with me being in my front yard. And coming down the street is a wild bull. It's typically white in color. And it's just on a terror, running around the neighborhood, smashing up cars, knocking down trees, trampling everything in its path. Nothing can stop it. And then it, for some reason, turns and looks at me. And I can tell it's coming from me. I mean, it's so wild. It's like falling down, tumbling, running into houses and stuff, trying to turn to come towards me. So I quickly run into the house, slam the door shut, lock it, and then go to the window to look to see what's going on.

0:42But the bull just runs right up to my house, hits the front door, and just busts through it like it's paper. It's suddenly in my house, and it's trying hard to turn corners and navigate through my house to get to me. But it's falling down and smashing into walls and furniture. And I'm frantically trying to find a safe place to go. but every room I go into, it just smashes through those doors or windows to get to where I am. I keep going into room after room, shutting doors, locking it, but it just keeps getting in. I usually wake up around here, heart racing. I'm in a panic. And what I often feel after this dream is helplessness, complete vulnerability.

1:20There's no place that feels safe. And it doesn't matter how many locked doors I have or hiding places I know of, that bull always finds me and smashes its way to me. I tell you this because after listening to today's story, I get that same feeling of feeling afraid and helpless.

1:45These are true stories from the dark side of the internet.

1:51I'm Jack Recider. This is Darknet Diaries.

2:18cybersecurity industry since John Strand founded it in 2008. Through their anti-siphon training program, they teach you how to think like an attacker. From SOC analyst skills to how to defend your network with traps and deception, it's hands-on practical training built for defenders who want to level up. Black Hills loves to share their knowledge through webcasts, blogs, zines, comics, and training courses all designed by hackers. For hackers! But do you need someone to do a penetration test to see where your defenses stand? Or are you looking for 24-7 and monitoring from their active SOC team?

2:49Or maybe you're ready for continuous pen testing where testing never stops and your systems stay battle ready all the time. Well, they can help you with all of that. They've even made a card game. It's called Backdoors and Breaches. The idea is simple. It teaches people cybersecurity while they play. Companies use it to stress test their defenses. Teachers use it in the classroom to train the next generation. And if you're curious, there's a free version online that you can try right now. And this fall, they're launching a brand new competitive edition of Backdoors and Breaches, where you and your friends can go head-to-head hacking and defending just like the real thing.

3:21Check it all out at blackhillsinfosec.com slash darknet. That's blackhillsinfosec.com slash darknet.

3:35This episode of Darknet Diaries is brought to you by Flashpoint. 2025 has proven to be a pivotal year for security leaders. It's not just cyber threats anymore. Physical risks and geopolitical tensions are colliding. creating a web of challenges no one can afford to ignore. That's where Flashpoint comes in. As one of the largest private providers of threat intelligence, Flashpoint delivers what security teams need most, clarity. By combining cunning-edge technology with the expertise of world-class analyst teams, their Ignite platform gives organizations instant access to critical data, expertly analyzed insights, and real-time alerts, all in one seamless platform.

4:10From Fortune 500 companies to government agencies, Flashpoint is a name trusted to keep people, assets, and operations secure. To access some of the industry's best threat data and intelligence, visit flashpoint.io today. That's flashpoint.io.

4:29Okay, y 'all have seen this talk at the STIC conference earlier this year, right?

4:38I don't speak Spanish, so I have to use YouTube to auto-translate for me, but hmm. Now that I'm looking at it, there are only 115 views on this video. So, no, you absolutely have not seen this talk. Okay, let me find another. Okay, what about this one? This is a talk from Hack the Box Meetup in Santo Domingo in the Caribbean Sea.

5:05Ah, you know what? This video only has 500 views. So, no, you did not see this video either. Well, both of these talks are by a guy named Omar Aveles, and he's talking about the worst day of his life. It's a chilling story. But since you haven't seen this talk, I really want you to hear it. And since it's in Spanish, I'm going to have to call up Omar to see if he can tell us the story in English. This story started much earlier, you know, than we even knew that, you know, something was happening. So this started May 2022 on Costa Rica. Okay, so this is Omar, and he lives in the Dominican Republic, which is an island in the Caribbean Sea.

5:46Across the Caribbean Sea, next to Panama, is Costa Rica. And what Omar saw happening in Costa Rica struck his curiosity. The new president of Costa Rica has declared his country is at war with a ransomware group, which has been carrying out cyber attacks on the country's government. The cyber criminal gang known as Conti has disabled agencies across the government since April using ransomware attacks. Whoa. That's kind of dramatic, isn't it? Declared war? Seriously? Like, you go in to deploy troops and send fighter jets because someone put ransomware on your computers? Does Costa Rica even have fighter jets?

6:23Anyway, because Omar is in part of Latin America, he was watching this story unfold. Let me introduce myself before I started talking about the incidents. So I used to work in the Dominican Republic National Desert which is the National Cybersecurity Incident Response Team. Sorry, I had a bad connection with Omar when we were talking. So let me repeat that for you. Omar worked in the C-CERT for the Dominican Republic. C-CERT is an acronym which stands for Cybersecurity Incident Response Team. And this C-CERT unit falls under the Department of Defense in the Dominican Republic. So when cyberattacks threaten national security, Omar was there to review it.

7:08But what's more is the Dominican Republic's C-Cert is part of a community of other incident response teams within Latin America. So when the incident in Costa Rica happens, they contact us, you know, just to ask for help. What he saw was that 20 different government organizations in Costa Rica were hit with this Conti ransomware. This was a very widespread problem within their government. So it's no wonder they were reaching out for help anywhere they could. Many parts of the Costa Rican government came to a halt, and they were frantic over there. But this gave Omar the ability to research and understand this Conti ransomware better.

7:47You know, it was like a massive malware campaign in Costa Rica. They were targeting government organizations through phishing, exploring vulnerabilities, but they, you know, compromised all the departments separately. Wow, that's really remarkable. See, when I hear that 20 departments were hit, I immediately think that there must be some central connection that allowed the malware to spread internally. You know, like if you can get in through the front door, now you can take a tunnel to all the other buildings or something. But no, what Omar saw was that each of these 20 departments were infected separately, some of which were infected through phishing emails and some from malware put right on systems that were connected to the internet.

8:26But just because the malware got inside each of these places, it didn't actually turn on until the right time. it was coordinated that when enough systems got infected, it would trigger the ransomware to lock all the computers at once and demand payment to unlock them. Now, the motive behind putting ransomware on systems like this is typically just to make money. I believe they were asking for$20 million to unlock Costa Rica's systems. So whoever did this seemed to be there only for financial gain. Costa Rica got their systems fixed up, and I don't think they paid the ransom. They had backups and restored, but Omar saw how this malware operated and worked.

9:04And he saw the methods they used to get in and took this new knowledge to scan the Dominican Republic's national computer infrastructure to see if anything matched what was on Costa Rica's systems. After all, the malware seemed to be present in Costa Rica's network for a while before it actually executed. So he looked through computer after computer and scanned lots of systems looking for things that matched what he saw in Costa Rica. He didn't find anything, actually, which seemed like the Conte ransomware gang wasn't targeting the Dominican Republic, which was good. But then, while looking for malware in the network, he noticed something.

9:40Someone had defaced a Dominican Republic government's website. They found a vulnerability on the web server and changed the pictures and text to something else. So he zoomed into this to investigate. We found an implant, a piece of malware. Now, typically when someone defaces a website, it's a small time hacker. Being able to show your friends that you changed the text on a government website makes you look cool in some hacker circles. But it wasn't this person who defaced the website that put the malware on that computer. See, when Omar was investigating the defacement, he checked to see if any malware was left behind.

10:17And it was, just not by this person. One of the places Omar likes to look for malware is in the temp directory. The temp directory is used by programs to temporarily hold data. And it's kind of a free space for any app to use to dump data in there if it needs it. So this directory often has open permissions. Anyone can read or write to it. Not many directories are like that on a computer. So that's why Omar looked in the temp directory. And that's where he saw that someone had stuck this malware in there. But the malware, the implant was on the system from 10 to 11 months ago. So someone had exploited this system 10 months ago, stuck some malware in there, and then left quietly.

10:59And when someone else came and defaced the site, that's when he discovered that it was there. And just imagine that sinking feeling for a moment. Malware had been here for 10 months and nobody noticed. Your worst fears start racing through your head at this point. Did they steal anything? Did they access stuff they shouldn't? Did they jump around to other computers? It was a malware that did privilege escalation. So it exploded a window vulnerability that was unknown to the Windows people. So we may call that a zero day. Okay, this just got worse. A zero day means that not even Microsoft knows about this vulnerability.

11:40And the reason why it's worse is because whoever left this here must have access to some pretty advanced malware. It's not easy to find a zero-day exploit, because if it was, Microsoft would find it too and put a fix out for it. So it's supposed to be secret. Now, specifically, this malware's purpose was to escalate privileges. So that means if you get on a system as a low-level user, it'll promote you to a user with administrator rights. So now you can do anything you want on that system. Kind of like if you were to just walk into the front door of a prison and convince the guards that you actually own the prison and to give you all the keys.

12:14being able to escalate your privileges is a crucial step at getting full control of a computer. And this could be the beginning of a big deal. And just as Omar was about to tell someone about this, news broke out. The Dominican Republic's Agricultural Department has suffered a ransomware attack by the Quantum Ransomware Group. The attack disrupted multiple services by encrypting four physical and eight virtual servers, compromising most of the information, including databases, email, and applications. Wait, quantum ransomware? Gosh, a totally different group hit them? It makes me want to make a meme out of all this ransomware news.

12:51Enough is enough. I've had it with this mother-flippin' ransomware on these mother-flippin' computers. Just when you tune your eyes to be able to see and detect a certain kind of malware, you get blindsided by a totally different kind. And whatever that malware was that Omar found on that web server, that had nothing to do with this quantum ransomware. They exploited a vulnerability in our 14th firewall that allowed them to have VPN access to the infrastructure. So with the VPN access, they managed to compromise the entire organization and then try to ransom the organization. Luckily, they detected this quite quickly and called Omar in very early.

13:34He got in his car and drove down to the data center that was infected. and when he got on the systems there, he was able to see the people who were behind the quantum ransomware typing out commands infecting more systems. So because he reacted so quickly, he was able to stop the spread of it from getting on more machines. And this is a stressful situation. I don't know if you've ever gotten your computer or phone infected, but anytime this happens, you have to wonder, did you clean your device good enough? Are they still in there? And you never actually know. you sort of have to cross your fingers and hope the attackers will let you know if they're in there still.

14:12Even though he's kicked them out of this one system, it's hard to tell if they just come right back in or what other systems they may have access to. It's like trying to build a dam in the dark with just sticks and rocks. So that went very public. So on the investigation, we found out the attacker got into the network via a phishing attack, but that didn't tell us much information. So we concluded the investigation or the report without any attribution. So we just know that somebody compromised the system. No attribution on the final report for the quantum ransomware infection. Okay, hmm. Attribution means figuring out who did this.

15:02And they couldn't figure it out. There just simply wasn't enough clues. It seemed to be fairly common malware with no clear path leading to anyone in particular. All it seemed was that it was financially motivated. They wanted money, and that's the whole reason why they did this. And I think there's three main categories for different types of attackers. There's the hacktivist type people who are hacking into things just for fun or to make a point, like those defacing websites. And then there are people who are financially motivated. They're only there to make money. And then there are more sophisticated groups there trying to steal state secrets or something.

15:37I mean, they might even have spies on the ground of the place they're trying to break into. If you know who your adversary is, you can combat against that particular threat more effectively. You can prepare better and be more alert. So it's important to understand the landscape of who can and who is and who should and who would be attacking you. When you're dealing with ransomware, you're typically up against someone who just wants money. And if you don't pay it or make it really hard for them, they'll probably just move on to an easier target. So after this attack, things settled down. Omar went back to his normal duties.

16:12One day, we got a tool to analyze all the DNS queries that the organization made. So we implemented that technology all around all government organizations so we can have a full visibility of what was happening on the government. Okay, so they got a new tool to look at the domains that each organization is reaching out to and each domain that's connecting into the government's network. Now, they took this data and cross-referenced it with known malicious domains in the world. And this is called threat intelligence. There are companies out there that try to classify every single IP address and domain name to try to determine if it's malicious or not.

16:54So if you see computers on your network contacting known malicious domains, then you can double click on that and see what's going on. While he's scanning the network, I want to take a quick ad break. But stay with us because you're going to want to hear what he found. This episode is sponsored by DeleteMe. Delete.me makes it easy, quick, and safe to remove your personal data online at a time when surveillance and data breaches are common enough to make everyone vulnerable. Delete.me does all the hard work of wiping you and your family's personal information off of data brokers' websites, and then continues to monitor and remove personal info you don't want on the web.

17:31Privacy is a super important topic to me. So a few years ago, I signed up. Delete.me immediately got busy scouring the internet for my name and gave me reports on what they found. Then they got busy deleting things. It's great to have someone on my team when it comes to my privacy. And the New York Times Wirecutter has named Delete Me their top pick for data removal services. Take control of your data and keep your private life private by signing up for Delete Me. Now at a special discount for my listeners, get 20 % off your Delete Me plan when you go to joindeleteme.com slash darknetdiaries and use promo code DD20 at checkout.

18:05The only way to get 20 % off is to go to joindeleteme.com slash darknetdiaries and enter code DD20 at checkout. That's joindeleteme.com slash darknetdiaries, code DD20.

18:21Omar was scanning the Dominican Republic's DNS queries to see if anything unusual was going on. So we discovered a C2 server that was, you know, utilized by Conti. Oh, no. A computer within the Dominican Republic government was connecting to a command control server, otherwise known as a C2 server, that is known to control systems infected by the Conti ransomware. This is bad. This indicates that the government is about to get hit. Someone has them in their crosshairs and just needs to pull the trigger. And perhaps they're going to get hit as hard as Costa Rica got hit. Whoever was behind that attack on Costa Rica clearly had a lot of time and resources to make a very deep and wide impact there, crippling their systems and government.

19:14But lucky that Omar has such a keen eye and is tuned into the threats of his government so he can detect this early. So he zoomed into this alert and he saw that, Yes, in fact, a system did get infected, and it reached out to the command and control server to download Cobalt Strike. Cobalt Strike is like a full suite of hacker tools. It's equivalent to finding a bad guy in your building and also finding his huge sack of tactical spy tools. But because they spotted this, as it was unfolding, they were able to delete those tools and clean that system and start hardening that system so it doesn't get infected again.

19:53On top of that, with this newfound activity on their network, knowing that they're in the crosshairs of somebody, it was important to start alerting the users in the government agencies. Be on alert. We are seeing some bad weather on the horizon. Be very cautious of any phishing emails. And please, please, please report anything suspicious to the security team. Thank you. So that's when everybody started sending us emails and emails and emails. We analyzed hundreds of emails, literally hundreds of emails. So the weird thing is about these emails that they were reading perfect Spanish, like they were not English, but perfect Spanish, like perfect Spanish.

20:42Okay, wow, so they were seeing a lot of phishing attempts. Emails posing as someone else, trying to get users to click links, open zip files or attachments. And in every one of these emails, the attackers spoke perfect Spanish. This is really curious, since a lot of these ransomware gangs would be coming from Eastern Europe or Russia. They wouldn't have the ability to speak perfect Spanish on such a large scale with hundreds of phishing emails being written. At that time, it was June 2022, we had over 500 to 600 emails, different emails, and all of them were different. So we didn't have one single email that was the same.

21:24But all of them, you know, shared one thing. All of them were about banking transactions or money or payments, something related to money. And also all of them had a backdoor that the attackers were using, which was a backdoor known as Banduk. Banduk. Okay, if I Google Banduk malware, I immediately get an article saying that this malware gives remote access to a computer, and it was written by someone named Prince Ali, who's from Lebanon in the Middle East. More specifically, the Banduk malware has been known to be used by a group called Dark Caracol. Well, that's what the EFF named them, at least.

22:11And while we aren't sure exactly who they are, there are quite a bit of clues that lead us to believe that the Lebanese government is somehow behind this Dark Caracol group. Now, I want to paint a clear picture for you. Hundreds of phishing emails are flooding into different government agencies in the Dominican Republic, all of which are trying to get the recipient to open an attachment or click a link, which will infect them with this Banduk malware, which typically seems to be the work of this threat actor group called Dark Caracol. As Omar looked at these emails coming in, he noticed something even more scary.

22:47They compromised a company, so it was an important target. So what happened here is that the attackers knew that the Dominican Republic was doing business with a certain company and they infiltrated that company just to pose as people from there in order to trick the victims in the Dominican Republic government to open attachments. What they did is that they used a user that was having a conversation with the existing administrator. So the existing administrator was waiting for that user to send him an attachment. So in a step of the legitimate attachment, the existing administrator received the backdoor.

Read the full transcript

23:28I mean, this seems to be the start of a horror story where it feels like you're home alone at night and someone is throwing rocks at your window, at all your windows, at once, constantly pinging them. And you just know at any moment, one of those windows is going to break. but there's just no way to secure everything at once. It just takes one user in an agency to get infected and then the attacker can jump off their machine to infect the whole agency. And for dozens of agencies to be attacked at the same time is horrifying. On top of that, the attackers are scanning web servers looking for vulnerabilities, trying to find an exploit to get into the network that way.

24:14So it's like endless banging on the doors and you know they're not going to hold? Where do you even put your attention in a situation like this? The bull is trying to get in your house and there's nothing you can do to stop it. And we found out, you know, something that was very terrifying for us. Over 30 government organizations were compromised by that campaign, like really big organizations. The hacker group Dark Caracal had successfully made their way into 30 different government agencies. And each came in through a different entry point, too. And to see that this was coming, to know the bull was headed towards you, but to have no ability to stop it, has got to be one of the most terrifying feelings.

25:06The feeling of helplessness, despair, vulnerability. Suddenly, a huge portion of the Dominican Republic government's network is now in the control of someone else? Someone you have no idea who they are, but may be related to the Lebanese government? Let me tell you, you know, it was not just government organizations, but also critical infrastructure. Holy flip! Critical infrastructure is things like power plants, water treatment facilities, or dams. disrupting or destroying these systems would absolutely bring this country to its knees. Yeah, it was a very complicated moment. We didn't know what to do.

25:48Now, of course, Omar isn't working by himself on this when he says that he did all these things. It was obviously a team effort. And his team consisted of like seven or eight people, but then every agency in the government has their own IT department. And some, of course, are bigger than others, but everyone was working extra hours to help out. But it just makes me wonder, you know, How robust is the Dominican Republic's cybersecurity? I mean, they may not be able to afford the most up-to-date network infrastructure, and they may be running old systems in place. They may not have the funds to employ high-quality employees to react to this.

26:24But when you're on the internet, it means you're only one click away for every threat actor in the world. So you absolutely need to secure your government's networks just as well as the largest governments in the world. Just because you're a small island doesn't mean you get to skimp on cybersecurity. You need to be just as good as everyone else. And it feels asymmetric in so many ways. You have to be prepared for the most sophisticated threat actors in the world. And I just wonder, how advanced was the cybersecurity of the Dominican Republic? But after, you know, they did some things on the system, they now downloaded or installed a second malware, which was a Kovaleh strike implant, which was communicating to Conti C2.

27:17C2 means command and control server, but I mean, what? You're telling me that some advanced adversary who may be in the Middle East is now starting to install the Conti ransomware on these systems? This is boggling because Conti has been widely attributed to be from Russia. So first of all, why are these two groups even allies or working together? Second, holy crap, you now have two sophisticated attack teams working together to attack your entire country, national agencies and critical infrastructure? Just when you thought you were in the thick of the storm, the storm got worse. It was, man, on that moment, we wanted to disappear.

28:02Then he got alerted of another problem. A big bank overnight stopped working for over a month. So if that bank cannot operate, all the people that have the money on that bank, how they are going to get their money out or how that can affect the government or the economy. So that was something big, and we involved even more people to investigate. The Dominican Republic was in trouble, and Omar's job was to help. So one of the first things that I did or I tried to do was call the people in Costa Rica, because that happened to them. And I wanted to know, you know, all about the incident. Now, this is what I love about Omar, is his awareness and his social skills.

28:47I used to work for a company doing incident response. and guess how much cybersecurity news my boss paid attention to? None. Guess how many other companies my boss interacted with to understand what threats they were facing? None. The attitude in our company was to put your head down and do your work, not look around to see what everyone else is doing or meet other people in the field. And I hated that. I can't stress this enough, that having allies in this business and going to conferences and meeting people and sharing stories with them will help you do your job so much better. So please, IT managers, stop thinking you're in some silo and your problems are just yours.

29:27Encourage and support your IT employees to go to conferences, meetups, talks, and workshops. It will help your business. Trust me. Omar has gone to conferences. You heard two of his talks at the beginning of this episode even. And he's gone to meetups and he's made friends across the sea in Costa Rica. Specifically, it was the conference called FIRST where he met them. You can learn more about this at FIRST.org. FIRST is a forum for instant response. So like all the instant response teams on the world just have a conference once or twice a year. So we all go to the conference and know each other.

30:04So if anybody needs help, we know who we can call. While FIRST is just one conference in the world, there are so many more going on these days. In fact, I think any given week, you can find two or three security conferences going on somewhere in the world. So just Google cybersecurity conference near me and see what's coming up near you. And having these connections were very valuable in this situation. I mean, it was a force multiplier even. Dominican Republic doesn't have the biggest cybersecurity incident response team in the world. And so knowing who to tap for help creates a battalion of people who can help you in different ways.

30:41One thing they did was compare their malware and indicators with other countries in Latin America to see who else has seen anything like this. Then he started creating a playbook with help from other nations to start remediating this. Of course, he was also calling up security vendors, the people who made the software that was supposed to be securing his network. He'd call up and say things like, hey, we pay you to block these attacks and you didn't. Please help us fix it. And of course, the security vendors want to make their tools better. So they wanted like a sample of the malware and what methods they used to get in.

31:14And we're working quickly to fix their software so they would be able to block these attacks from continuing. And this was happening on Windows machines. They were getting infected even though they were fully patched and updated. So a call to Microsoft was important to show them what they were dealing with and to ask, how can you fix this? They were calling out to other network vendors too because their systems were compromised. And by the way, when you call up one of these companies to try to report a zero-day exploit, it's not easy. The first person that you get, the first tier support, tells you stupid things like, okay, sir, did you try rebooting the system?

31:48And you're like, come on, please, please, please, please, please connect me to somebody who knows what they're doing over there. And they simply cannot. So you need to ask for a manager. And then the manager doesn't know how to fix it. and they don't want to admit that their software has vulnerabilities in it. So you go back and forth trying to troubleshoot it for days. It's tedious and time-consuming before they escalate it to the next tier support and eventually you get an engineer or a developer who knows this system inside and out and can recognize the problem and replay it and fix it right away.

32:21It's just that that person is behind like eight layers of support tiers before you can get to them. Now there's this quote from Bruce Schneier that has frustrated me, but also educated me on the reality of cybersecurity. The quote goes like this. You can't defend. You can't protect. The only thing you can do is detect and respond. I get frustrated from that quote because I feel like we should be able to defend and protect. Why don't we have secure software that can do that? I mean, how many more years and technical advancements do we need before we can defend our networks. But the sad truth is we may never get there.

33:00And so what Bruce is saying is we need to be assuming we're breached and to work on improving our ability to detect and respond to cyber threats. Somewhere in the middle of the storm, Omar realized that too. Instead of trying to build those walls up higher and higher to stop people from getting in, he needed to get better at detecting when they did get in. So he started installing more monitoring tools into the network so that he could watch more closely what was going on in there. And this allowed him to understand where Cobalt Strike was and Spot It and the Bandook malware and Conti ransomware and Dark Caracol and where it was in the network and how it was moving around, giving him a beautiful view into which systems were infected.

33:45We found out that the threat actor was on the system over 10 months ago. They were in these agencies for 10 months? Jeez. So when we discovered that, we tried to get to somebody else that may have more information than us. We get to our partners. So when we reached out to them and we showed them, you know, all the information that we have, they told us something that, you know, made me very afraid. So they told us that it was not just that catacop, it was not just country, but also it was Russia was also involved. Russia as in the Russian government. It was very strange for me why Russia would compromise the Dominican Republic in that way, what interest they would have here, because in the Dominican Republic we have a lot of Russians, like a lot of Russians living here.

34:50What would be their intention? And what that organization told us is that they were trying to experiment with some countries, something that may do on a bigger scale. so they could not target some more mature countries like the United States or the United Kingdom because they have better defense. So they were trying to do it in this part of the world. So what happened in Costa Rica, even though it's not public, and I'm not saying that on behalf of the government, it's just my opinion. And what I know from what happened and from what I learned on the process, what happened in Costa Rica was part of that.

35:30and what was happening in the Dominican Republic was part of that. And it was not just Costa Rica and the Dominican Republic, but also other countries in the Latin American region were involved on that. So as soon as we knew that, we started reaching out to those countries to let them know that this was happening, to send them in the curse of compromise. So that way they find out even earlier than us that something dangerous dangerous what's happening in their country. So they were able to do things, you know, before something really bad happened. There's now a third threat actor involved in this attack?

36:13Ah! Just before all this happened in the Dominican Republic, there was some crazy drama going on in the Conti ransomware gang. So Conti, we know, is based in Russia. and they came out publicly in support of Russia's invasion of Ukraine. Well, I guess someone close to Conti did not like this and decided to publicly leak 60 ,000 messages between the Conti group and other people. And these leaked messages showed that the Russian government had been hacking into places that just seemed to be in poor taste, you know, like hacking medical researchers. So it's not a far-fetched to think that Conti may be working with the Russian government, or that the Russian government would be attacking smaller countries sort of as a testing ground to practice their hacking skills.

37:03But I mean, an infiltration at this level really can pose as a whole new type of ransomware. Like, just hypothetically, imagine a phone call from Putin to the president of the Dominican Republic where Putin could say something like, listen, we want you to support our war with Ukraine, And if you don't, we'll turn your whole country off. Because they can. With their hand in so many agencies, networks, and critical infrastructure, they could just shut down the Dominican Republic. And that would be a form of ransomware, wouldn't it be? No, this was just a hypothetical. I have no idea if Putin has any relations with the Dominican Republic.

37:42At some point, do you contact the president and say, hey, we've got a really big deal. It's not just your normal malware, but this is a geopolitical problem. Yes, we did. So we called a national meeting with the big persons for the government. So we informed the president, the intelligence agencies about what we discovered. Of course, attribution is very hard when it comes to cyber attacks. It's incredibly easy to hide in the shadows on the Internet. So even though there are some things that point to this being Russia and Darkerical, how confident can you really be? Especially when you're on the phone briefing the president.

38:27Maybe someone else just got a hold of the Banduk malware or Conti ransomware. Maybe someone wants you to think that it was those threat actors attacking you just to throw you off the scent. Because we've seen threat actors put in fake clues to do just that before. For this situation, there were a lot more questions than there were answers. If Dark Karakal is Lebanese-based, why would they be working with Russia or Conti? Was this financially motivated or politically motivated? This attribution wasn't exactly clear, and neither are the motives. Yeah, so they're not supposed to work together, so nothing went over our head over and over.

39:09We overthink it, so why, why, why? Does Lebanon and Dominican Republic have any relations? We do. So our current president, his family is from Lebanon. What? Hold on. How can the president of the Dominican Republic be from Lebanon? Let me look this up. Okay, his grandfather was born in Lebanon and moved to the Dominican Republic in the 1800s. It was not clear to me, at least, if he's still tied to Lebanon in any way, shape, or form. I mean, I couldn't even find out if he can speak Lebanese, you know? But it seems like only weeks after he was elected as president is when this attack happened. So maybe this has something to do with Lebanon sending a message to the president?

39:55My mind is spinning here, and I don't want to make any wild assumptions. At the very least, I'm reminded of how Costa Rica's president declared war on Conti. And now I can see that that's not so far-fetched of an idea anymore. At this point, Omar had a very good understanding of this campaign and malware. And he even reversed engineered some of the malware, inspected it for clues, and looked at their command and control servers, and had a full map of where the infections were and how they were moving around the network. On top of that, vendors started to improve their systems, issuing patches and updates and better ways to detect this.

40:28So he got together with all the teams inside the agencies that were infected and explained the remediation process. Step by step, he walked them through how to remove this and stop this from happening again. And he also called the ISP to have them block certain domains. And he was actively cleaning up the mess. Of course, any good threat actor is not going to go down without a fight. So while they'd block a domain or a command and control server, a new one would just spin up. And they had to keep blocking and updating their detection methods. And you know, the goal for security isn't always to stop all the threats permanently.

41:03but instead just to make it as hard as you can for the bad guys to get in. Because it takes work to spin up new domains. It takes work to pull out a new zero-day, to infect more systems. And it takes work to regain access once you get kicked out. So having this coordinated effort to shut them out started to exhaust the attacker's resources. And do they really want to put a lot more work and effort into getting back in or just move on to the next target? There's a concept called the pyramid of pain when defending a network, and it's basically the more painful you can make it for the attackers to get in, the less likely they'll actually do it.

41:41You never will become fully secure, but at least you can make them work for it. So after a massive coordinated effort to clean up the government agencies and a big bank and critical infrastructure, they were able to successfully clear everything off and keep it off. In fact, they seem to have stopped the Conti ransomware attack before it actually triggered ransomware on any systems. It was only staging the ransom, but never actually executed it. Omar also looked to see if any data got exfiltrated from the network, but it didn't. So it doesn't seem like Russia or Dark Caracall stole any information out of the government.

42:18Did they disrupt critical infrastructure? They tried to, but they could not. But, you know, the critical infrastructure works in what we call OT, which is operational technology. Yeah, to control a dam or a water pump or electrical transformer, it doesn't use like a typical Windows computer or something. It's a different system called OT, which is operational technology, which is opposed to IT, information technology. And OT takes a completely different skill set. And it sounds like whoever got into these systems didn't quite have the skill set to control OT systems. which was good that they didn't get disrupted.

42:59What a whirlwind story this was, huh? To have a government completely cracked open like that, with no way to stop the attackers, in my opinion at least, but then to gain back control of it and lock them out. Omar likes sharing this story with others so that they can be aware that this kind of stuff goes on in the world. And in fact, as I'm looking things up here, it seems like Venezuela also got targeted with the same group or groups. So in 2022, Latin American countries were hit hard with these huge coordinated attack campaigns that may have been unstoppable due to the sophistication and breadth of the attack.

43:38And I wonder if Haiti got hit, you know? The president of Haiti has been assassinated in the place as a barely functioning government and it's kind of been taken over by gangs. Would you expect their cybersecurity posture to be strong or lacking? I mean, if Russia infiltrated Haiti's networks, is there anyone there to even notice it and clean it up? And I just wonder about Haiti because they share the same island as the Dominican Republic. I don't know. In some ways, I hate that our world is so vulnerable digitally still that our most critical systems are still susceptible to attack. My knee-jerk reaction is to say something like, take your systems offline if you can't secure them properly.

44:19But that's the opposite of technological progress. So that kind of attitude or strategy just isn't going to fly today. I just feel like when our systems get too complicated, they become insecure. And we certainly live in a very complicated network of computers now, don't we? But the thing is, even in my dreams, I still can't find a safe place to hide.

44:49a huge thank you to Omar Aveles for coming on the show and sharing this story with us the easiest way to find Omar to connect with him is by looking him up on LinkedIn I'll have a link to his LinkedIn in the show notes in this episode we talked about the threat actor Dark Caracol and I actually did a full episode on them a while back and that's episode 38 it's a really fascinating group so go check out that episode just as a reminder this show is now on a monthly release schedule. So look for new episodes on the first Tuesday of every month. I also have a store where you can buy cool shirts to support the show.

45:19It's not all branded with Darknet Diaries logos. There are some there, but there are a ton of shirts that I just know you'll absolutely love the design and want to wear these shirts. So please go visit shop.darknetdiaries.com and thanks for supporting the show. The show is made by me, the bullfighter, Jack Recider. Editing helped this episode by the bipedal Tristan Ledger, mixing done by proximity sound and our theme music was created by the mysterious breakmaster cylinder who just released a new album and i'll have a link in the show notes if you want to take a listen now even though when i see people rate this show a 10 i always assume it's in binary and they're really giving it a two this is darknet diaries

46:10Thank you.

From the publisher

Omar Avilez worked in the CSIRT of the Dominican Republic when a major cyber security incident erupted. Omar walks us through what happened and the incident response procedures that he went through.


Breakmaster Cylinder’s new album: https://breakmastercylinder.bandcamp.com/album/the-moon-all-that.


Sponsors

Support for this show comes from Varonis. Do you wonder what your company’s ransomware blast radius is? Varonis does a free cyber resilience assessment that tells you how many important files a compromised user could steal, whether anything would beep if they did, and a whole lot more. They actually do all the work – show you where your data is too open, if anyone is using it, and what you can lock down before attackers get inside. They also can detect behavior that looks like ransomware and stop it automatically. To learn more visit www.varonis.com/darknet.


Support for this show comes from Axonius. The Axonius solution correlates asset data from your existing IT and security solutions to provide an always up-to-date inventory of all devices, users, cloud instances, and SaaS apps, so you can easily identify coverage gaps and automate response actions. Axonius gives IT and security teams the confidence to control complexity by mitigating threats, navigating risk, decreasing incidents, and informing business-level strategy — all while eliminating manual, repetitive tasks. Visit axonius.com/darknet to learn more and try it free.


Support for this show comes from Flare. Flare automates monitoring across the dark & clear web to detect high-risk exposure, before threat actors have a chance to leverage it. Their unified solution makes it easy to rapidly identify risks across thousands of sources, including developers leaking secrets on public GitHub Repositories, threat actors selling infected devices on dark web markets, and targeted attacks being planned on illicit Telegram Channels. Visit https://flare.io to learn more.


Sources

https://www.wired.com/story/costa-rica-ransomware-conti/

https://malpedia.caad.fkie.fraunhofer.de/details/win.bandook

https://www.youtube.com/watch?v=QHYH0U66K5Q

https://www.youtube.com/live/prCr7Z94078

https://www.eff.org/deeplinks/2023/02/uncle-sow-dark-caracal-latin-america

https://www.bleepingcomputer.com/news/security/quantum-ransomware-attack-disrupts-govt-agency-in-dominican-republic/

https://www.welivesecurity.com/2021/07/07/bandidos-at-large-spying-campaign-latin-america/


Attribution

Darknet Diaries is created by Jack Rhysider.

Assembled by Tristan Ledger.

Episode artwork by odibagas.

Mixing by Proximity Sound.

Theme music created by Breakmaster Cylinder. Theme song available for listen and download at bandcamp. Or listen to it on Spotify.

More from Darknet Diaries

All 50 episodes
135: The D.R. IncidentDarknet Diaries · 43 min
Listen in VO