https://krebsonsecurity.com/2021/01/hamas-may-be-threat-to-8chan-qanon-online/ Advertisement RSS Feed Subscribe to RSS Twitter Follow me on Twitter Facebook Join me on Facebook [84] Krebs on Security In-depth security news and investigation Brian Krebs About the Author Advertising/Speaking --------------------------------------------------------------------- 05 Jan 21 Hamas May Be Threat to 8chan, QAnon Online In October 2020, KrebsOnSecurity looked at how a web of sites connected to conspiracy theory movements QAnon and 8chan were being kept online by DDoS-Guard, a dodgy Russian firm that also hosts the official site for the terrorist group Hamas. New research shows DDoS-Guard relies on data centers provided by a U.S.-based publicly traded company, which experts say could be exposed to civil and criminal liabilities as a result of DDoS-Guard's business with Hamas. [qanon-8kun-map] Many of the IP address ranges in in this map of QAnon and 8Chan-related sites -- are assigned to VanwaTech. Source: twitter.com/ Redrum_of_Crows Last year's story examined how a phone call to Oregon-based CNServers was all it took to briefly sideline multiple websites related to 8chan/8kun -- a controversial online image board linked to several mass shootings -- and QAnon, the far-right conspiracy theory which holds that a cabal of Satanic pedophiles is running a global child sex-trafficking ring and plotting against President Donald Trump. From that piece: A large number of 8kun and QAnon-related sites (see map above) are connected to the Web via a single Internet provider in Vancouver, Wash. called VanwaTech (a.k.a. "OrcaTech"). Previous appeals to VanwaTech to disconnect these sites have fallen on deaf ears, as the company's owner Nick Lim reportedly has been working with 8kun's administrators to keep the sites online in the name of protecting free speech. After that story, CNServers and a U.K.-based hosting firm called SpartanHost both cut ties with VanwaTech. Following a brief disconnection, the sites came back online with the help of DDoS-Guard, an Internet company based in Russia. DDoS-Guard is now VanwaTech's sole connection to the larger Internet. A review of the several thousand websites hosted by DDoS-Guard is revelatory, as it includes a vast number of phishing sites and domains tied to cybercrime services or forums online. Replying to requests for comment from a CBSNews reporter following up on my Oct. 2020 story, DDoS-Guard issued a statement saying, "We observe network neutrality and are convinced that any activity not prohibited by law in our country has the right to exist." But experts say DDoS-Guard's business arrangement with a Denver-based publicly traded data center firm could create legal headaches for the latter thanks to the Russian company's support of Hamas. In a press release issued in late 2019, DDoS-Guard said its services rely in part on a traffic-scrubbing facility in Los Angeles owned by CoreSite [NYSE:COR], a real estate investment trust which invests in "carrier-neutral data centers and provides colocation and peering services." [ddosguad-map] This facilities map published by DDoS-Guard suggests the company's network actually has at least two points of presence in the United States. Hamas has long been named by the U.S. Treasury and State departments as a Specially Designated Global Terrorist (SDGT) organization. Under such a designation, any U.S. person or organization that provides money, goods or services to an SDGT entity could face civil and/or criminal prosecution and hefty fines ranging from $250,000 to $1 million per violation. Sean Buckley, a former Justice Department prosecutor with the law firm Kobre & Kim, said U.S. persons and companies within the United States "are prohibited from any transaction or dealing in property or interests in property blocked pursuant to an entity's designation as a SDGT, including but not limited to the making or receiving of any contribution of funds, goods, or services to or for the benefit of individuals or entities so designated." CoreSite did not respond to multiple requests for comment. But Buckley said companies can incur fines and prosecution for violating SDGT sanctions even when they don't know that they are doing so. In 2019, for example, a U.S. based cosmetics company was fined $1 million after investigators determined its eyelash kits were sourcing materials from North Korea, even though the supplier in that case told the cosmetics firm the materials had come from China. "U.S. persons or companies found to willfully violate these regulations can be subject to criminal penalties under the International Emergency Economic Powers Act," Buckley said. "However, even in the case that they are unaware they're violating these regulations, or if the transaction isn't directly with the sanctioned entity, these companies still run a risk of facing substantial civil and monetary penalties by the Department of Treasury's Office of Foreign Asset Control if the sanctioned entity stands to benefit from such a transaction." DDoS-Guard said its partnership with CoreSite will help its stable of websites load more quickly and reliably for people visiting them from the United States. It is possible that when and if CoreSite decides it's too risky to continue doing business with DDoS-Guard, sites like those affiliated with Hamas, QAnon and 8Chan may become more difficult to reach. Meanwhile, DDoS-Guard customer VanwaTech continues to host a slew of sites promoting the conspiracy theory that the U.S. 2020 presidential election was stolen from President Donald Trump via widespread voting fraud and hacked voting machines, including maga[.]host, donaldsarmy [.]us, and donaldwon[.]com. These sites are being used to help coordinate a protest rally in Washington, D.C. on January 6, 2021, the same day the U.S. Congress is slated to count electoral votes certified by the Electoral College, which in December elected Joseph R. Biden as the 46th president of The United States. In a tweet late last year, President Trump urged his supporters to attend the Jan. 6 protest, saying the event "will be wild." 8chan, which has rebranded as 8kun, has been linked to white supremacism, neo-Nazism, antisemitism, multiple mass shootings, and child pornography. The FBI in 2019 identified QAnon as a potential domestic terror threat, noting that some of its followers have been linked to violent incidents motivated by fringe beliefs. [58] Tags: 8chan, CoreSite, ddos-guard, Hamas, Kobre & Kim, Nick Lim, QAnon, Ron Guilmette, Sean Buckley, SpartanHost, VanwaTech This entry was posted on Tuesday, January 5th, 2021 at 2:27 pm and is filed under A Little Sunshine, The Coming Storm. You can follow any comments to this entry through the RSS 2.0 feed. You can skip to the end and leave a comment. Pinging is currently not allowed. 15 comments 1. [d4ba] Catwhisperer January 5, 2021 at 2:54 pm This is why Section 230 must go. It's intent was good, but the devil is in the implementation details. I don't think Congress had in mind enabling phishers, scammers, or other grifters to have free rein of the Internet with this Act... Reply + [ad6c] pdclarry January 5, 2021 at 3:05 pm If Section 230 goes, Trump's twitter account would have to be banned. Reply o [f958] Christoph Schmees PC-Fluesterer. info January 5, 2021 at 4:13 pm ... which would be no loss, would it? Reply o [b129] dtrdoc January 5, 2021 at 4:25 pm and...? Reply 2. [72e8] M Topp January 5, 2021 at 3:04 pm I think it's fair to point out that although the USA considers Hamas to be a terrorist organisation, they are also the elected government of the Gaza Strip. Reply 3. [ced9] I've Been Watching .... January 5, 2021 at 3:21 pm No one seems to consider the positive potential consequences of eliminating the liability immunity of Section 230 - at least not other than in a panic that such would stifle the "free flow of information". There are other possibilities. Including the possibility that putting platforms at risk could encourage other platforms to gain currency. Right now, the protection arguably empowers the powerful. Should Facebook, Twitter, etc., have to slow down to assess the risk of liability, other platforms with other assessments of risk might well come forth and "publish". The single greatest "barrier to entry" is impunity by immunity. That protects the powerful, not the new entrants. Why is it that the New York Times is exposed to liability for libel, but not Facebook? Why is Twitter free to ignore slander, but not the Washington Post? Why should the Washington Examiner or Drudge be exposed to the risk of judgment, but not Google? Each and every time the playing field is adjusted, new entrants come forth. Level the playing field for all, powerful establ9shed firms and new entrants. It ain't rocket science, it just take guts - and ignoring the lobbyists. Reply + [b904] JamminJ January 5, 2021 at 4:11 pm Section 230 has nothing to do with this. It's funny. Most IT privacy and security people never heard of Section 230 until Trump's personal vendetta against social media. Now so many are throwing the term around like candy, as if Section 230 is responsible for everything. It isn't. Reply 4. [daa9] Ron G January 5, 2021 at 3:40 pm Brian, you neglected to mention that VanWaTech is also still hosting the us-focused neo-NAZI web site dailystormer[.]su Also worthy of note is that the .SU suffix is actually the top-level domain for what used to be the Soviet Union. (That top level domain name nowadays belongs to Russia.) Thus, we have the rather humorous and entirely ridiculous spectacle of a neo-NAZI site which only exists due to the good graces of the government of Vladimir Putin. 8kun[.]top meanwhile exists in the .TOP top-level domain, which is owned & operated by a commercial enterprise in mainland China. Thus, the great U.S. "patriots" behind the whole QAnon farce are in fact beholden to BOTH the Russians (for connectivity) AND the Chinese (for their domain name). With U.S. "patriots" like these, who needs enemies? Reply + [16a7] Wads January 5, 2021 at 5:49 pm "Any port in storm" Pretty sure you could find sites banned by china/russia/hamas /etc operating in west... Reply 5. [ed35] The Sunshine State January 5, 2021 at 3:49 pm In the article it states "convinced that any activity not prohibited by law in our country has the right to exist." The key words here are "our country" which mean the Russian federation and we all know that country has very lax cyber-crime laws Reply 6. [78be] Steve J January 5, 2021 at 4:18 pm Count me as one who thinks our country's greatest and most violent challenge is from within (sponsored by Putin and Trump). Getting that Qanon, proud (aka poor boy), and other white supremacist stuff under wraps will be our biggest challenges. Putin has been a direct sponsor of it. Reply + [e085] TBJ January 5, 2021 at 4:27 pm Steve J, Proud Boys aren't White Supremacists, but your statement does show how colossally ignorant you are of the situation as a whole. Didn't you also back Chris Krebs as a vanguard of ITSEC despite his abject failure in the role? Also Steve J: "Count me as one who thinks....". No, you clearly don't. Reply o [a6f3] ShutYerPieHole January 5, 2021 at 4:47 pm Liar. Reply o [af6e] Jay January 5, 2021 at 5:40 pm One would have to be naive, blind or an agent of those who would benefit directly from a civilian revolution in the USA. The Russians and others are sinking every resource at their control to maintaining the state of chaos in the USA. Proud Boys, Qanon, Nazism, White Supremacists and the rest of the fringe are looking to paint our soil with blood..they are all willfully ignorant and players who are being easily manipulated by the Russians and others. The USA it's on its way to a very violent end if the stupid like TBJ don't wake up. Reply 7. [77b9] Stu Nowlin January 5, 2021 at 5:01 pm TBJ, Proud boys current leader (after a "coup" against Enrique Tarrio, the former leader) Kyle Chapman, is "is trying to rebrand the organization as explicitly white supremacist and anti-Semitic" according to multiple news sources including the Sun Sentinal. Chris Krebs said before a Senate committee, ""The trick about elections is that you're not so much trying to convince the winner that they won, it's the loser that they lost," he said. "You need willing participants on both sides. I think we've got to get back to that point, otherwise we're going to have a very difficult time going forward maintaining confidence in this American experiment." Krebs has never been accused of abject failure at protecting elections except by Trump and his lawyers. Steve J clearly thinks, TBJ. You react. Look it up. There is a difference. Stu Reply Leave a comment Click here to cancel reply. Name (required)[ ] Email (required)[ ] Website[ ] Comment [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [Submit Comment] Advertisement [11] * [ ] [search_mag] [89] * Mailing List Subscribe here * Recent Posts + Hamas May Be Threat to 8chan, QAnon Online + Happy 11th Birthday, KrebsOnSecurity! + VMware Flaw a Vector in SolarWinds Breach? + Malicious Domain in SolarWinds Hack Turned into 'Killswitch' + SolarWinds Hack Could Affect 18K Customers * * All About Skimmers All About Skimmers Click image for my skimmer series. * Donate to Krebs On Security * Spam Nation Spam Nation A New York Times Bestseller! * * The Value of a Hacked PC valuehackedpc Badguy uses for your PC * Tools for a Safer PC Tools for a Safer PC Tools for a Safer PC * The Pharma Wars The Pharma Wars Spammers Duke it Out * Badguy Uses for Your Email Badguy Uses for Your Email Your email account may be worth far more than you imagine. * eBanking Best Practices eBanking Best Practices eBanking Best Practices for Businesses * Most Popular Posts + Sextortion Scam Uses Recipient's Hacked Passwords (1076) + Online Cheating Site AshleyMadison Hacked (798) + Sources: Target Investigating Data Breach (620) + Trump Fires Security Chief Christopher Krebs (534) + Cards Stolen in Target Breach Flood Underground Markets (445) + Reports: Liberty Reserve Founder Arrested, Site Shuttered (416) + Was the Ashley Madison Database Leaked? (376) + True Goodbye: 'Using TrueCrypt Is Not Secure' (363) + Who Hacked Ashley Madison? (361) + Following the Money, ePassporte Edition (353) * Category: Web Fraud 2.0 Criminnovations Innovations from the Underground * [shreddedID-copy-285x189] ID Protection Services Examined * Is Antivirus Dead? Is Antivirus Dead? The reasons for its decline * The Growing Tax Fraud Menace The Growing Tax Fraud Menace File 'em Before the Bad Guys Can * Inside a Carding Shop Inside a Carding Shop A crash course in carding. * Beware Social Security Fraud Beware Social Security Fraud Sign up, or Be Signed Up! * How Was Your Card Stolen? How Was Your Card Stolen? Finding out is not so easy. * Krebs's 3 Rules... Krebs's 3 Rules... ...For Online Safety. --------------------------------------------------------------------- (c) 2021 Krebs on Security. Powered by WordPress. Privacy Policy