UPDATE GIGS MEDIAUPDATE GIGS MEDIA
  • Home
  • Entertainment
  • Business & Finance
  • Education
    • Scholarships
  • Lifestyle
    • Health & Fitness
    • Travel
    • Dating & Relationships
    • Do it yourself
  • Tech
  • Privacy Policy
Facebook Twitter Instagram
Facebook Twitter Instagram
UPDATE GIGS MEDIAUPDATE GIGS MEDIA
CONTACT US
  • Home
  • Entertainment
  • Business & Finance
  • Education
    • Scholarships
  • Lifestyle
    • Health & Fitness
    • Travel
    • Dating & Relationships
    • Do it yourself
  • Tech
  • Privacy Policy
UPDATE GIGS MEDIAUPDATE GIGS MEDIA
Home » How a SA hacker group stole millions in cloud resources from Microsoft and Salesforce
Tech

How a SA hacker group stole millions in cloud resources from Microsoft and Salesforce

adminBy adminJanuary 10, 2023No Comments4 Mins Read
Facebook Twitter LinkedIn Telegram Pinterest Tumblr Reddit Email
SA-hacker.jpeg
Share
Facebook Twitter LinkedIn Pinterest Email


According to a report by cybersecurity firm Unit 42, South Africa based hacker group  “Automated Libra” is behind an elaborate crypto mining scheme referred to as “ PurpleUrchin”, which has cost major cloud providers, including Microsoft and Salesforce, millions of dollars in resources and unpaid bills.

Freejacking works by using free (or limited-time) cloud resources to perform crypto mining operations. Automated Libra’s scheme fraudulently used the cloud platforms’ resources to perform crypto mining operations then traded the mined cryptocurrencies.

Play and run tactics

According to Unit 42’s report, beyond exploiting the free trials, Automated Libra also employed what is referred to as a “play and run” tactic whereby the actors used cloud resources from the likes of Microsoft and Salesforce for the crypto mining operations without paying the requisite fees.

The group did this by creating and using fake accounts using falsified and stolen credit cards. Unit 42 further states that although one of the largest unpaid balances they uncovered on the fake accounts was $190, other accounts could have run up much larger bills.

“…we suspect the unpaid balances in other fake accounts and cloud services used by the actors could have been much larger due to the scale and breadth of the mining operation,” stated the report.

Creating the fake accounts

Unit 42’s report states that at the peak of the operation in November 2022, Automated Libra had created over 130,000 fake Github and Heroku accounts. Assuming that the accounts ran up an average of $100 in unpaid bills, the scheme cost Microsoft and Salesforce over $13 million in resources.

Microsoft-owned Github and Salesforce-owned Heroku are cloud platforms that enable developers to build, run, and operate applications entirely in the cloud, in this instance, crypto mining applications.

To create the accounts, the group used xdotool, a tool used to automatically generate keyboard and mouse inputs, to populate the Github account creation tool.

Advertisements
Advertisements

To complete the account creation process which requires correctly identifying a “CAPTCHA” image, the group employed ImageMagick tool kit, used to convert, edit and compose digital photos.

Through the tool, the hackers were able to correctly identify CAPTCHA images, allowing them to automatically complete the account creation process and proceed with the “freejacking” and “play and run” tactics.

Automated Libra hackers used xdotool and ImageMagict to automatically create over 130,000 fake Github and Heroku accounts which they used to run crypto mining applications (Image source:Unit 42)

According to Unit42, after mining the cryptocurrencies, Automated Libra also proceeded to automate the process of trading the collected cryptocurrencies across several crypto trading platforms including CRATEX ExchangeMarket, crex24, and Luno.

“Unit 42 researchers identified more than 40 individual crypto wallets and seven different cryptocurrencies or tokens being used within the PurpleUrchin operation,” the report adds.

Speaking to MyBroadband, Christo de wit, Luno country manager, stated that the exchange has not been contacted by any victims from the scheme and added that they would be able to identify the perpetrators behind the wallets should law enforcement require them to.

“Yes, with our KYC processes, we are able to provide relevant information to law enforcement agencies who request it while investigating this type of incident…Our FinCrime team also actively monitors transactions in accordance with regulations.” De Wit stated.

Over the last two years, South Africa has experienced its fair share of crypto scams. Last year, the US Commodities Futures Trading Commission (CFTC) charged South African resident Cornelius Johannes Steynberg in a bitcoin fraud scheme case totalling $1.7 billion.

In October last year, the National Consumer Commission (NCC) also announced that 4,000 South Africans had lost R112 million ($6.1 million) in a bitcoin mining pyramid scheme called Obelisk.

Get the best African tech newsletters in your inbox

More latest updates

  • 👨🏿‍🚀TechCabal Daily – Content moderators sue Meta in Kenya
    👨🏿‍🚀TechCabal Daily – Content moderators sue Meta in Kenya
    by admin●March 23, 2023
  • 🚀Entering Tech #24: Breaking down software engineering
    🚀Entering Tech #24: Breaking down software engineering
    by admin●March 22, 2023
  • How WomHub wants to facilitate female entrepreneurship in Cape Town
    How WomHub wants to facilitate female entrepreneurship in Cape Town
    by admin●March 22, 2023
  • Factor[e] launches $600,000 venture studio for Africa
    Factor[e] launches $600,000 venture studio for Africa
    by admin●March 22, 2023

Share this:

  • Tweet
Advertisements

Advertisements

Related

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
admin
  • Website

Related Posts

Atiku says INEC rigged the election with software 

March 25, 2023

The rise of Whatsapp chatbots in southern Africa

March 25, 2023

Rwazi raises $4m to penetrate emerging markets and offer insights

March 24, 2023

54gene’s workforce got leaner amid a fresh change in management

March 24, 2023

Mstudio is replicating anglophone’s success in the francophone

March 24, 2023

ChatGPT can now help you shop, travel and do more work

March 24, 2023
Stay In Touch
  • Facebook
  • Twitter
  • Instagram
  • YouTube
Don't Miss
Tech

Has NFT found its biggest mainstream proponent yet in Africa?

By adminApril 13, 2022

The past few days have been good for NFT in Africa—Nigeria and Ghana, to be…

Share this:

  • Tweet

👨🏿‍🚀 TechCabal Daily – MTN is accelerating mobile money in Nigeria

April 13, 2022

Didi shuts down operations in South Africa

April 13, 2022

Back from the future: How embedded finance changed the world

April 13, 2022

Can Hytch succeed where GoMyWay failed?

April 13, 2022

More African central banks are considering digital currencies

April 13, 2022

This bootstrapped drone startup is promoting smart farming in Zimbabwe

April 13, 2022

The Next Wave: Africa does not know itself

April 13, 2022

TechCabal Daily – Kenya’s new law for content creators

April 14, 2022

INDUSTRY EXPERTS DISCUSS THE GROWTH AND FUTURE OF FINTECH IN NIGERIA AND INDIA IN SYMPOSIUM BY CLI COLLEGE, NIGERIA AND CHRIST UNIVERSITY, INDIA

April 14, 2022

28 days after launching investment arm, Luno crosses 10m user base

April 14, 2022

👨🏿‍🚀 TechCabal Daily – The war for Twitter

April 15, 2022

Digital Nomads: Julian Owusu’s journey from football to fintech

April 15, 2022

In the wake of explosive accusations against Africa’s most valuable startup, Flutterwave co-founder speaks

April 16, 2022
Advertise with us
update gigs advert images
LATEST

Atiku says INEC rigged the election with software 

March 25, 2023

The rise of Whatsapp chatbots in southern Africa

March 25, 2023

Rwazi raises $4m to penetrate emerging markets and offer insights

March 24, 2023
About Us
About Us

We are dedicated to bringing you news from around the world that is entertaining, educative, informative and self inspiring.. Your source for the lifestyle news.

We're accepting new partnerships right now.

Email Us: updatemedia050@gmail.com

Subscribe to Updates

Get the latest news from Update Gigs Media about entertainment, sports, lifestyle, art, design and business.

Facebook Twitter Instagram
© 2023 Designed by Ntechy Digital System.

Type above and press Enter to search. Press Esc to cancel.