extortion – Earlybirds Invest https://earlybirdsinvest.com Latest Crypto News Mon, 11 Aug 2025 09:48:23 +0000 en-US hourly 1 https://wordpress.org/?v=6.9.7 https://i0.wp.com/earlybirdsinvest.com/wp-content/uploads/2024/12/cropped-New-Project-2024-12-17T235703.455.png?fit=32%2C32&ssl=1 extortion – Earlybirds Invest https://earlybirdsinvest.com 32 32 240146708 Embargo’s Double Extortion Play Bags $34 Million From US Victims https://earlybirdsinvest.com/embargos-double-extortion-play-bags-34-million-from-us-victims/ https://earlybirdsinvest.com/embargos-double-extortion-play-bags-34-million-from-us-victims/#respond Mon, 11 Aug 2025 09:48:23 +0000 https://earlybirdsinvest.com/embargos-double-extortion-play-bags-34-million-from-us-victims/

Embargo, a cybercrime group, has collected more than $34 million in cryptocurrency from ransom payments since April 2024, according to an August 8 report by TRM Labs.

Embargo operates a ransomware-as-a-service model, where it partners with other groups to carry out attacks using its tools and share the profits.

Victims have included American Associated Pharmacies, Memorial Hospital and Manor in Georgia, and Weiser Memorial Hospital in Idaho. Some ransom requests have been as high as $1.3 million.

What is Algorand? ALGO Coin Explained With Animations

Did you know?

Want to get smarter & wealthier with crypto?

Subscribe – We publish new crypto explainer videos every week!

According to TRM, Embargo uses a double extortion method. First, it encrypts the victim’s systems. Then it threatens to publish sensitive data if payment is not made.

In some cases, the group has named organizations or individuals on its website to increase pressure. While it may not operate as openly as groups like LockBit or Cl0p, its methods are still effective.

TRM’s findings suggest Embargo could be linked to the now-defunct BlackCat (ALPHV) group, which disappeared earlier this year after a suspected exit scam. Both groups use the Rust programming language, run similar websites for leaking stolen data, and appear to share some cryptocurrency wallet infrastructure.

TRM said roughly $18.8 million of the group’s earnings remain in wallets not tied to any known service.

When Embargo transfers money, it often uses multiple wallet addresses, high-risk exchanges, and even sanctioned platforms. Between May and August, TRM tracked about $13.5 million moving through different virtual asset service providers, with over $1 million going through Cryptex.net.

On August 7, Koi Security reported that a cybercrime group named GreedyBear has stolen more than $1 million in cryptocurrency. How? Read the full story.


]]>
https://earlybirdsinvest.com/embargos-double-extortion-play-bags-34-million-from-us-victims/feed/ 0 52627
Bitcoin Extortion Duo Walks Free, Judge Sets $1 Million Bail Each https://earlybirdsinvest.com/bitcoin-extortion-duo-walks-free-judge-sets-1-million-bail-each/ https://earlybirdsinvest.com/bitcoin-extortion-duo-walks-free-judge-sets-1-million-bail-each/#respond Sun, 27 Jul 2025 20:55:32 +0000 https://earlybirdsinvest.com/bitcoin-extortion-duo-walks-free-judge-sets-1-million-bail-each/

John Woeltz and William Duplessie have been released on $1 million bail each after being accused of kidnapping and harming an Italian man in a Manhattan townhouse, according to a report by ABC News.

The next court hearing is scheduled for October 15. In the meantime, both men are required to wear ankle monitors, hand over their passports, and report for security checks every 72 hours.

Crime reporter Lauren Conlin, who was present at the hearing, shared on X that the defense described the situation as a form of hazing, not a crime, by referring to it as “17 days of shenanigans”.

What is a Liquidity Pool in Crypto? (Animated)

Did you know?

Want to get smarter & wealthier with crypto?

Subscribe – We publish new crypto explainer videos every week!

The case began on May 6 when a cryptocurrency trader from Italy arrived in New York. Prosecutors said he was taken after landing and held against his will for several weeks.

During that time, the suspects allegedly tried to force him to give up access to his Bitcoin
BTC


$116,559.70

by using violence and threats.

According to the Manhattan District Attorney’s Office, the man was reportedly beaten, shocked with wires, and hit with a gun. The attackers also told him they would hurt his family if he did not cooperate.

The victim eventually escaped and asked a traffic officer for help. He was taken to the hospital with injuries that matched his story.

Police later arrested Woeltz at the scene. Duplessie turned himself in several days after the escape. Investigators noted that the kidnapping was carefully planned.

Meanwhile, the London gang was convicted after abducting a Belgian barber they wrongly believed was rich in crypto. How did that happen? Read the full story.

Having completed a Master’s degree in Economics, Politics, and Cultures of the East Asia region, Aaron has written scientific papers analyzing the differences between Western and Collective forms of capitalism in the post-World War II era.
With close to a decade of experience in the FinTech industry, Aaron understands all of the biggest issues and struggles that crypto enthusiasts face. He’s a passionate analyst who is concerned with data-driven and fact-based content, as well as that which speaks to both Web3 natives and industry newcomers.
Aaron is the go-to person for everything and anything related to digital currencies. With a huge passion for blockchain & Web3 education, Aaron strives to transform the space as we know it, and make it more approachable to complete beginners.
Aaron has been quoted by multiple established outlets, and is a published author himself. Even during his free time, he enjoys researching the market trends, and looking for the next supernova.


]]>
https://earlybirdsinvest.com/bitcoin-extortion-duo-walks-free-judge-sets-1-million-bail-each/feed/ 0 50010
Coinbase Hit by $20 Million Extortion Plot After Insider Data Leak https://earlybirdsinvest.com/coinbase-hit-by-20-million-extortion-plot-after-insider-data-leak/ https://earlybirdsinvest.com/coinbase-hit-by-20-million-extortion-plot-after-insider-data-leak/#respond Sun, 18 May 2025 03:49:33 +0000 https://earlybirdsinvest.com/coinbase-hit-by-20-million-extortion-plot-after-insider-data-leak/

The cryptocurrency exchange Coinbase



$718.37M

was recently targeted in a scheme where attackers tried to extort $20 million after gaining access to some internal tools.

According to the company, several overseas support contractors were bribed by outsiders to leak limited customer data.

In a blog post published on May 15, Coinbase explained that the attackers convinced a few support agents to misuse their access and retrieve information from a small number of user accounts.

What Are Crypto Quests? EASIEST Ways to Earn Rewards Explained

Did you know?

Want to get smarter & wealthier with crypto?

Subscribe – We publish new crypto explainer videos every week!

No login credentials, private keys, funds, or Prime accounts were exposed. The company said that less than 1% of active monthly users were affected.

After collecting the stolen data, the group demanded $20 million worth of Bitcoin
BTC


$102,888.78

to keep the breach private. However, Coinbase offered a $20 million reward for information that could help identify and convict the individuals involved.

Coinbase said it plans to refund those users, and estimated that the total cost of reimbursements and other related actions could reach between $180 million and $400 million. The financial estimate was shared in a filing with the US Securities and Exchange Commission (SEC), where Coinbase described the costs as part of a “voluntary reimbursement” effort.

Coinbase CEO Brian Armstrong stated in a post on X that the attackers had been contacting support staff abroad for several months by offering money in exchange for customer data.

In response, Coinbase plans to improve how it handles customer data and move parts of its support operations to new locations.

On May 13, ZKsync and its development team, Matter Labs, experienced a security incident. How did it happen? Read the full story.

Having completed a Master’s degree in Economics, Politics, and Cultures of the East Asia region, Aaron has written scientific papers analyzing the differences between Western and Collective forms of capitalism in the post-World War II era.
With close to a decade of experience in the FinTech industry, Aaron understands all of the biggest issues and struggles that crypto enthusiasts face. He’s a passionate analyst who is concerned with data-driven and fact-based content, as well as that which speaks to both Web3 natives and industry newcomers.
Aaron is the go-to person for everything and anything related to digital currencies. With a huge passion for blockchain & Web3 education, Aaron strives to transform the space as we know it, and make it more approachable to complete beginners.
Aaron has been quoted by multiple established outlets, and is a published author himself. Even during his free time, he enjoys researching the market trends, and looking for the next supernova.


]]>
https://earlybirdsinvest.com/coinbase-hit-by-20-million-extortion-plot-after-insider-data-leak/feed/ 0 36857
Luna Moth extortion hackers pose as IT help desks to breach US firms https://earlybirdsinvest.com/luna-moth-extortion-hackers-pose-as-it-help-desks-to-breach-us-firms/ https://earlybirdsinvest.com/luna-moth-extortion-hackers-pose-as-it-help-desks-to-breach-us-firms/#respond Tue, 06 May 2025 03:01:02 +0000 https://earlybirdsinvest.com/luna-moth-extortion-hackers-pose-as-it-help-desks-to-breach-us-firms/

Mothman

The data-theft extortion group known as Luna Moth, aka Silent Ransom Group, has ramped up callback phishing campaigns in attacks on legal and financial institutions in the United States.

According to EclecticIQ researcher Arda Büyükkaya, the ultimate goal of these attacks is data theft and extortion.

Luna Moth, known internally as Silent Ransom Group, are threat actors who previously conducted BazarCall campaigns as a way to gain initial access to corporate networks for Ryuk, and later, Conti ransomware attacks.

In March 2022, as Conti started to shut down, the BazarCall threat actors separated from the Conti syndicate and formed a new operation called Silent Ransom Group (SRG).

Luna Moths’s latest attacks involve impersonating IT support through email, fake sites, and phone calls, and rely solely on social engineering and deception, with no ransomware deployment seen in any of the cases.

“As of March 2025, EclecticIQ assesses with high confidence that Luna Moth has likely registered at least 37 domains through GoDaddy to support its callback-phishing campaigns,” reads the EclecticIQ report.

“Most of these domains impersonate IT helpdesk or support portals for major U.S. law firms and financial services firms, using typosquatted patterns.”

Luna Moth targets in the past 12 months
Luna Moth targets in the past 12 months
Source: EclecticIQ

The latest activity spotted by EclecticIQ starts in March 2025, targeting U.S.-based organizations with malicious emails that contain fake helpdesk numbers recipients are urged to call to resolve non-existent problems.

A Luna Moth operator answers the call, impersonating IT staff, and convinces the victim to install remote monitoring & management (RMM) software  from fake IT help desk sites that gives the attackers remote access to their machine.

The fake help desk sites utilize domain names that follow naming patterns like [company_name]-helpdesk.com and [company_name]helpdesk.com.

Fake IT support site
Fake IT support site
Source: EclecticIQ

Some tools abused in these attacks are Syncro, SuperOps, Zoho Assist, Atera, AnyDesk, and Splashtop. These are legitimate, digitally signed tools, so they’re unlikely to trigger any warnings for the victim.

Once the RMM tool is installed, the attacker has hands-on keyboard access, allowing them to spread to other devices and search local files and shared drives for sensitive data. 

Having located valuable files, they exfiltrate them to attacker-controlled infrastructure using WinSCP (via SFTP) or Rclone (cloud syncing).

After the data is stolen, Luna Moth contacts the victimized organization and threatens to leak it publicly on its clearweb domain unless they pay a ransom. The ransom amount varies per victim, ranging from one to eight million USD.

Luna Moth's victim extortion site
Luna Moth’s extortion site
Source: BleepingComputer

Büyükkaya comments on the stealth of these attacks, noting that they involve no malware, malicious attachments, or links to malware-ridden sites. The victims simply install an RMM tool themselves, thinking they are receiving help desk support. 

As the enterprise commonly uses these RMM tools, they are not flagged by security software as malicious and are allowed to run.

Indicators of compromise (IoCs), including IP addresses and phishing domains that should be added to a blocklist, are available at the bottom of EclecticIQ’s report.

Apart from the domains, it is also recommended to consider restricting the execution of RMM tools that are not used in an organization’s environment.

Red Report 2025

Based on an analysis of 14M malicious actions, discover the top 10 MITRE ATT&CK techniques behind 93% of attacks and how to defend against them.

]]>
https://earlybirdsinvest.com/luna-moth-extortion-hackers-pose-as-it-help-desks-to-breach-us-firms/feed/ 0 34624