RE: https://infosec.exchange/@BleepingComputer/115588709520660643
BleepingComputer says Crowdstrike has confirmed that an "insider" was caught sharing screenshots taken on internal systems. Bleeping reports that those ended up in the hands of Scattered Lapsus$ Hunters.
I'm guessing someone at Crowdstrike was responding to the group's recent posts on Telegram, where they said they were buying insider access to large companies. Here's the text of one recent solicitation:
"DM us to sell your IA on % locking with all major lockers depending on target; must be ready to run AD commands or Okta commands, or show /etc/openldap/ldap.conf /var/log and ip -a addr && ssh -i /home/$$/.ssh/*pem $$@(ip addr ip's) or anything else you find relevant to showing us
Rules:
- no companies under 500M revenue
- no RF/PRC/DPRK/Belarus companies
IA rates:
25% for any AD joined system.
10% for Okta, Azure portal, AWS IAM root, etc
were also recruiting employees/insider at the following!!!!
- Any company providing Telecommunications (Claro, Telefoinica, ATT, and other similar)
- Large software/gaming corporations (Microsoft, Apple, EA, IBM, other similar)
- Callcenter/BPM (Atento, Teleperformance, and other similar)
- Server hosts (OVH, Lcaweb, and other similar)
If you are not sure if you are needed then send a DM and we will respond!!!!
If you are not a employee here but have access such as VPN or VDI then we are still interested!!
You will be paid if you would like. Contact us to discuss that"