Welcome to DU! The truly grassroots left-of-center political community where regular people, not algorithms, drive the discussions and set the standards. Join the community: Create a free account Support DU (and get rid of ads!): Become a Star Member Latest Breaking News General Discussion The DU Lounge All Forums Issue Forums Culture Forums Alliance Forums Region Forums Support Forums Help & Search

Jilly_in_VA

(10,075 posts)
Wed Dec 8, 2021, 12:00 PM Dec 2021

This Small Tech Company May Be a Ransomware Front Group

It seems innocent enough: a little-known Canadian company that offers an array of tech and consulting services. But a certificate from that company—a sort of signature that can be tacked onto malware—showed up in two pieces of ransomware last month and leading experts told The Daily Beast they believe the small company is actually a front for at least two Russian ransomware gangs.

The company—cheerily named “SpiffyTech”—has a number of red flags. For one, if you want to look at SpiffyTech’s leadership team, you’re out of luck. They don’t exist.

The site does list four top staffers next to their stylish headshots. But the SpiffyTech operators appear to have stolen each and every photo.

A reverse image search on Google shows the headshots come from a professional photographer’s website. The photographer, Kirill Tigai, confirmed the photos in question were part of a shoot for a different company and said he did not give SpiffyTech permission to use them.

“I think… this website SpiffyTech is a fraud,” Tigai told The Daily Beast. “They just use photos that I made for my clients under different names.”

Another reason experts believe “SpiffyTech” is a front is far more technical.

Hackers frequently steal certificates from actual businesses in order to help their attacks fly under the radar and trick computers into thinking their malware is legitimate. And while it’s possible the hackers did the same here—or tricked a real company into sharing a legitimate “cert”—the shadiness of the site, and its apparent connection to ransomware, leads cybersecurity analysts to believe SpiffyTech is a disguise for something more sinister.

https://www.thedailybeast.com/this-small-tech-company-spiffytech-may-actually-be-a-ransomware-front-group?ref=home

5 replies = new reply since forum marked as read
Highlight: NoneDon't highlight anything 5 newestHighlight 5 most recent replies
This Small Tech Company May Be a Ransomware Front Group (Original Post) Jilly_in_VA Dec 2021 OP
The very name sounds like a company name in a cartoon channel episode. halfulglas Dec 2021 #1
Kinda like Jilly_in_VA Dec 2021 #4
Tech companies should be certified. Tetrachloride Dec 2021 #2
Uhhhmmm...I think that was the whole purpose of the "cert". ret5hd Dec 2021 #3
To get to my new home, i had to show my passport over 15x, Tetrachloride Dec 2021 #5

halfulglas

(1,654 posts)
1. The very name sounds like a company name in a cartoon channel episode.
Wed Dec 8, 2021, 12:06 PM
Dec 2021

Does anybody really use spiffy any longer? I can't remember the last time somebody said to me "That's really spiffy."

Tetrachloride

(7,963 posts)
5. To get to my new home, i had to show my passport over 15x,
Wed Dec 8, 2021, 12:50 PM
Dec 2021

not to mention the recertification, driver’s license, birth certificate, certification fees, PCR results and the goodwill of one of the immigration officers. I was certified.

The original Apple App Store developer certificate originally was also fairly thorough. Apple called me personally to say I passed. (I don’t know what they do these days.) Then, Every line of code had to pass certain tests.

That company was never certified in person.

A digital certificate is only electrons.

Same word, different quality.

Latest Discussions»General Discussion»This Small Tech Company M...