The Shadow Brokers Offering Is Launching new Monthly Subscription Model

Discussion in 'other security issues & news' started by hawki, May 16, 2017.

  1. hawki

    hawki Registered Member

    Joined:
    Dec 17, 2008
    Posts:
    6,077
    Location:
    DC Metro Area
    "TheShadowBrokers is launching new monthly subscription model...

    'Each month peoples can be paying membership fee, then getting members only data dump each month...'

    It claimed to have exploits for web browsers, routers, operating systems (including Windows 10), compromised data from banks and Swift providers and stolen network data from Russian, Chinese, Iranian, and North Korean nuclear missile programs..."

    http://www.ibtimes.co.uk/mysterious...r-carnage-stolen-nuclear-missile-data-1621797

    The Shadow Brokers Original Post:

    "OH LORDY! Comey Wanna Cry Edition

    ...In June, TheShadowBrokers is announcing "TheShadowBrokers Data Dump of the Month" service. TheShadowBrokers is launching new monthly subscription model. Is being like wine of month club. Each month peoples can be paying membership fee, then getting members only data dump each month. What members doing with data after is up to members.

    TheShadowBrokers Monthly Data Dump could be being:

    web browser, router, handset exploits and tools

    select items from newer Ops Disks, including newer exploits for Windows 10

    compromised network data from more SWIFT providers and Central banks

    compromised network data from Russian, Chinese, Iranian, or North Korean nukes and missile programs
    More details in June...

    https://steemit.com/shadowbrokers/@theshadowbrokers/oh-lordy-comey-wanna-cry-edition
     
  2. emmjay

    emmjay Registered Member

    Joined:
    Jan 26, 2010
    Posts:
    1,548
    Location:
    Triassic
    There is a lot to read into those statements. It is chess.

    The Shadow Brokers have introduced a foil to trick you into divorcing them from the ransomware thuggery that created havoc on May 12th. However, it was the Shadow Brokers who released that code for free after they could not get the price they wanted for it.

    We are acting very predictably. Microsoft has publicly denounced the NSA for hoarding exploits, posters and bloggers have torn strips off the UK's NHS (many referring to them as incompetent idiots), and Win/XP users have been called a danger to public safety. We are cannibalizing ad nauseam. Now it is their move.

    The escalation, taunts and threats are all meant to create more internal turmoil in the west and we are all too willing to participate. Checkmate.
     
  3. itman

    itman Registered Member

    Joined:
    Jun 22, 2010
    Posts:
    8,593
    Location:
    U.S.A.
    https://www.bleepingcomputer.com/ne...-data-from-nuke-programs-windows-10-exploits/
     
  4. Minimalist

    Minimalist Registered Member

    Joined:
    Jan 6, 2014
    Posts:
    14,883
    Location:
    Slovenia, EU
    https://www.infosecurity-magazine.com/news/shadow-brokers-warn-of-june-data/
     
  5. hawki

    hawki Registered Member

    Joined:
    Dec 17, 2008
    Posts:
    6,077
    Location:
    DC Metro Area
  6. guest

    guest Guest

    They don't have to...they have their own backdoor...
     
  7. itman

    itman Registered Member

    Joined:
    Jun 22, 2010
    Posts:
    8,593
    Location:
    U.S.A.
    https://www.bleepingcomputer.com/ne...-details-about-upcoming-monthly-dump-service/
     
  8. Minimalist

    Minimalist Registered Member

    Joined:
    Jan 6, 2014
    Posts:
    14,883
    Location:
    Slovenia, EU
    https://arstechnica.com/security/20...ription-forces-high-risk-gamble-on-whitehats/
     
  9. hawki

    hawki Registered Member

    Joined:
    Dec 17, 2008
    Posts:
    6,077
    Location:
    DC Metro Area
    "Cash for hacking tools' sparks debate

    Security researchers are considering buying undetected software security vulnerabilities from a notorious group of hackers.

    The Shadow Brokers group has previously leaked exploits allegedly stolen from the US National Security Agency (NSA), and is offering more for sale.

    Some researchers want to buy the next batch of hacking tools, and help fix them before cyber-criminals strike.
    But critics argue that the Shadow Brokers should not be funded..."

    http://www.bbc.com/news/technology-40107093

    "There's now a crowdfunding campaign to buy stolen hacking tools...

    The researchers behind the Patreon campaign, Hacker Fantastic and x0rz, hope that by purchasing the data they will be able to analyze it and possibly prevent another attack like the WannaCry ransomware..."

    http://mashable.com/2017/05/30/shadow-brokers-nsa-exploits-hacking-wannacry/#JOJszsOfsmqP
     
  10. Minimalist

    Minimalist Registered Member

    Joined:
    Jan 6, 2014
    Posts:
    14,883
    Location:
    Slovenia, EU
    Possible solution: US government buys those bugs (since they lost them) and then releases them for free to vendors and security companies to patch and protect their software and services.
     
  11. cruelsister

    cruelsister Registered Member

    Joined:
    Nov 6, 2007
    Posts:
    1,649
    Location:
    Paris
    Minimalist- they already do (and have) bought exploit data- sadly often from folks that were trained in the Security services (usually former TAO staffers). Zerodium, Endgame, and Exodus have been using this business model for years; Endgame charges in the 7 figures USD for their data.

    I'll bet buying from Shadow Brokers will be a bargain in comparison.
     
  12. Minimalist

    Minimalist Registered Member

    Joined:
    Jan 6, 2014
    Posts:
    14,883
    Location:
    Slovenia, EU
    Yes 20k is not much if they have good exploits on sale. As you said some of those exploits could be sold for millions.
     
  13. hawki

    hawki Registered Member

    Joined:
    Dec 17, 2008
    Posts:
    6,077
    Location:
    DC Metro Area
    "'Cash for hacks' crowd-funding campaign abandoned

    Security researchers have cancelled plans to buy potentially undetected software security vulnerabilities from a notorious group of hackers...

    One of the researchers behind the plan said the scheme was being abandoned for 'legal reasons'..."

    http://www.bbc.com/news/technology-40107099
     
  14. hawki

    hawki Registered Member

    Joined:
    Dec 17, 2008
    Posts:
    6,077
    Location:
    DC Metro Area
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.