loader from loading.io

Introduction to Cryptocurrency Investigations

the CYBER5

Release Date: 01/03/2022

Insider Threats and Social Engineering Tactics by Counterintelligence Institute’s Peter Warmka show art Insider Threats and Social Engineering Tactics by Counterintelligence Institute’s Peter Warmka

the CYBER5

In Episode 90 of TheCyber5, we are joined by , founder of the Counterintelligence Institute. Warmka is a retired senior intelligence officer with the U.S. Central Intelligence Agency (CIA) where he specialized in clandestine HUMINT (human intelligence) collection. With 20+ years of breaching security overseas for a living, Warmka now teaches individuals and businesses about the strategy and tactics of “human hacking”.  Warmka highlights how insiders are targeted, the methods used by nationstates for committing crimes, and what organizations need to help focus their security training...

info_outline
The Top Nisos Investigations Of the Last Seven Years with Nisos Research Principal Vincas Ciziunas show art The Top Nisos Investigations Of the Last Seven Years with Nisos Research Principal Vincas Ciziunas

the CYBER5

In Episode 89 of TheCyber5, we are joined by Nisos Research Principal,  It was 7 years ago, at a restaurant in Ashburn, Virginia, when Nisos’ co-founders Justin Zeefe and Landon Winkelvoss met Vincas. At the time, Vincas was working as a contractor for the US government but was considering a pivot into the private sector.  It was Vincas’ impressive intellect, strategic thinking, and technical capabilities that made him the ideal intelligence operator on whom to depend for the launch of Nisos. Over the course of several years, Vincas’ experience, as a developer, open threat...

info_outline
The Vital Role of Customer Success in Intel Programs with Senior Director of Nisos Brandon Kappus show art The Vital Role of Customer Success in Intel Programs with Senior Director of Nisos Brandon Kappus

the CYBER5

In Episode 88 of TheCyber5, we are joined by Nisos Senior Director for Customer Success, .   Here are five topics we discuss in this episode:   Intelligence Playbooks Start with Education to the Customer  Playbooks should include three major steps. The first step is education on how intelligence is going to be consumed and not be nonstop noise. Discussions between customers and vendors should start around requirements that customers are trying to address with business stakeholders.    Understanding Commercially and Publicly Available Data to Avoid Noise The next...

info_outline
Identifying When Attribution of Threat Actors Matters and How to Track the Outcomes with Senior Information Security Leader Charles Garzoni show art Identifying When Attribution of Threat Actors Matters and How to Track the Outcomes with Senior Information Security Leader Charles Garzoni

the CYBER5

In Episode 87 of TheCyber5, we are joined by senior information security leader . Here are five topics we discuss in this episode: Defining When Attribution is Relevant and Necessary  Many corporations are not overly concerned with attribution against cyber adversaries, they just want to get back to business operations. However, if someone robbed your house, you would want to know if it was a random drive-by, or if it was your neighbor because that will inform your defenses much more appropriately.  Defending Against Nation States Versus Crime Groups The ability to attribute...

info_outline
Properly Defining a Threat Management Department within Enterprise with Senior Manager of Nvidia Chris Cottrell show art Properly Defining a Threat Management Department within Enterprise with Senior Manager of Nvidia Chris Cottrell

the CYBER5

In Episode 86 of TheCyber5, we are joined by Senior Manager of Threat Management for Nvidia .   Here are six topics we discuss in this episode:   What is a threat management department within enterprise security? Threat management departments are usually formed when security teams become mature and have table stakes functions within threat intelligence, red team, penetration testing, and threat hunting. These functions are usually formed after compliance, risk, governance, vulnerability management, and security operations center (SOC) are operational. Unfortunately, threat...

info_outline
Operational Resiliency Framework Pertaining to Supply Chains by Foundation for Defense of Democracies George Shea show art Operational Resiliency Framework Pertaining to Supply Chains by Foundation for Defense of Democracies George Shea

the CYBER5

In Episode 85 of TheCyber5, we are joined by Chief Technologist of Transformative Cyber Innovation Lab for the Foundation for Defense of Democracies (FDD) Here are four topics we discuss in this episode: What is the Operational Resiliency Framework (ORF)?  The Operational Resiliency Framework (ORF) is a framework that is intended to be used by executives to ensure business continuity processes when their suppliers are knocked offline during natural disasters and cyber attacks.  Defining Minimum Viable Services Step one, and the most important step, is defining a minimum level of...

info_outline
Integrating Attack Simulation with Intelligence to Provide Actionable Outcomes with CrossCountry Consulting show art Integrating Attack Simulation with Intelligence to Provide Actionable Outcomes with CrossCountry Consulting

the CYBER5

In Episode 84 of TheCyber5, we are joined by members of the CrossCountry Consulting team:  , Offensive R&D Lead, , Associate Director, and , Director, Cyber and Privacy.  Here are five topics we discuss in this episode: Adversary Emulation vs. Simulation and Use of Threat Intelligence Replaying attacks from adversaries is considered . The pros of emulation are you can react and defend against threat intelligence and the actual techniques during a penetration test. The cons are that many times these are yesterday’s threats. Simulation is the art of coming up with new attack...

info_outline
Data Governance and Threat Intelligence Converge with Egnyte’s Chief Governance Officer Jeff Sizemore show art Data Governance and Threat Intelligence Converge with Egnyte’s Chief Governance Officer Jeff Sizemore

the CYBER5

Topic: Title: Data Governance and Threat Intelligence Converge In Episode 83 of TheCyber5, we are joined by our guest, Egnyte’s Chief Governance Officer, Jeff Sizemore. We discuss the Cybersecurity Maturity Model Certification (CMMC) and the impact on Department of Defense (DOD) contractors to mature their cybersecurity hygiene in order to compete for US government contracts. CMMC was based on NIST Standards 800-71.  Here are 4 topics we discuss in this episode: Why Does CMMC Matter? In the near future, contracts are going to be rated L1-3 and if contractors are not certified up to a...

info_outline
Driving Diversity in Cyber Security and Intelligence with BGH Security CEO Tennisha Martin show art Driving Diversity in Cyber Security and Intelligence with BGH Security CEO Tennisha Martin

the CYBER5

In episode 82 of The Cyber5, we are joined by guest moderator and senior intelligence analyst for Nisos, Valerie G., and CEO of BGH Security, Tennisha Martin.   In this episode, we discuss the challenges and opportunities of promoting and enabling diversity and inclusion in cyber security.   Key Takeaways:   Showing Impact for Diversity and Inclusion (D&I) within Security   Beyond filling cyber security skills gaps, some metrics that show success in D&I include: Jobs Feeling more confident in interviews Recommending minorities for employment opportunities...

info_outline
Leveraging Open Source Intelligence in Insider Threat Programs with Vaillance Group CEO, Shawnee Delaney show art Leveraging Open Source Intelligence in Insider Threat Programs with Vaillance Group CEO, Shawnee Delaney

the CYBER5

In episode 81 of The Cyber5, we are joined by the Head of Insider Threat at Uber and CEO of Vaillance Group, Shawnee Delaney.  In this episode, we provide an overview of different functions within an insider threat program. We also discuss the support open source intelligence provides to such programs and how to change company culture to care about insider threats. We also discuss the ROI metrics that are important to different stakeholders when implementing an insider threat program.  Three Takeaways: Departments and Functions within Insider Threat  Insider threat programs...

info_outline
 
More Episodes

In episode 62 of The Cyber5, we are again joined by Charles Finfrock, CEO and Founder of Black Hand Solutions. Charles was previously the Senior Manager of Insider Threat and Investigations at Tesla and prior to that, he worked as an Operations Officer for the Central Intelligence Agency. 

We discuss the generalities of cryptocurrency and go into the tactics, techniques, and procedures for conducting cryptocurrency investigations. We also discuss some case studies and what proper outcomes look like for making it more expensive for the adversaries to conduct their operations in this generally unregulated world.

Three Key Takeaways:

 

  • Generalities, Functionalities, and Value of Bitcoin and Cryptocurrency

 

In its simplest form, Cryptocurrency is digital coins or money (Bitcoin and Ethereum being the most popular). It is not run or governed by a central authority, but by a mathematical algorithm that verifies the transactions, controls the supply of the certain coin, and runs on the blockchain.

Blockchain, as it pertains to Cryptocurrency, is a ledger that verifies what has been sent and received from an account. It is pseudo-anonymous, it is not anonymous - which is why criminals have been leveraging it so aggressively. 

When Bitcoin is transacted, the amount sent and received are recorded on the Bitcoin ledger (Blockchain) and associated with a Cryptocurrency wallet address. Criminals think they can hide their identities as a result of not needing a formally validated identity through a central authority. 

Since Cryptocurrency is not controlled by a central government no one can modify the supply of the particular cryptocurrency. It derives value in the same way the US dollar used to derive value from gold - scarcity. The argument for Bitcoin's value is similar to that of gold—a commodity that shares characteristics with the Cryptocurrency. The cryptocurrency is limited to a quantity of 21 million. Bitcoin's value is a function of this scarcity.

2) Conducting Cryptocurrency Investigations - Decreasing Return on Investment to Criminals

When criminals first started using Cryptocurrency in 2012 it was because they thought they could hide their identity. At the time, tools were not available to law enforcement to unmask and attribute actions to persons. That has changed. 

The two kinds of investigations that clients engage in are reactive and proactive. Reactive are when scams have already been perpetrated against their brand. Proactive are when security teams engage with actors to derive the scam before a significant amount of loss occurs.

Legal and technical methods can be deployed to “burn down the infrastructure” to decrease the return on investment for online criminals. Oftentimes an outcome can be to contact a centralized bank or Cryptocurrency exchange (i.e. Coinbase) that is linked to the Cryptocurrency as a means to “cash out” the criminal proceeds, report the fraud, and disrupt the activity, thus increasing the costs to the criminals. 

3) Provenance and Repudiation To Understand Truth, Accuracy, and Completeness

As with any online crime investigation, investigative techniques identify stylometric attributes of the criminal infrastructure that reveal the provenance of data by the malicious actor. The end provides authorities the ability to repudiate this scheme in the future.

Often what we look for are lapses in operational security by the threat actors, which include but are not limited to the following:

  • An actor registered a domain and failed to enable private registration before correcting their mistake.
  • An actor forgot to use their VPN or proxy to connect to their C2 infrastructure and revealed their source IP range.
  • An actor reused certificates on different infrastructure or failed to properly encrypt their C2 traffic.

 

Going a step further, we pivot from technical analysis to open source intelligence (OSINT) to add valuable context to the nature of the threat an organization faces. By exposing network infrastructure and drawing associations using threat information and other technology-enabled OSINT connections, we can determine the motivation and sophistication of the threat. We assess characteristics such as: 

  • Content, stylometric attributes, and similarities between criminal persona accounts and true-name accounts.
  • Re-use of content in a spearphish that was similar to content existing elsewhere, such as blog or social media posts.
  • Re-use of usernames or email addresses to register a malicious domain or subscribe to a third-party file server or virtual private server.
  • Photographs that provide traceable location details such as landmarks or geographical attributes.
  • Screenshots, files, or photos used by the actor that leave vital forensic clues revealing real identity or location. 
  • Details ascertained through direct engagement with the threat actor.