Operation Onymous
   HOME

TheInfoList



OR:

Operation Onymous was an international law enforcement operation targeting darknet markets and other
hidden service Tor, short for The Onion Router, is free and open-source software for enabling anonymous communication. It directs Internet traffic through a free, worldwide, volunteer overlay network, consisting of more than seven thousand relays, to conc ...
s operating on the
Tor network Tor, short for The Onion Router, is free and open-source software for enabling anonymous communication. It directs Internet traffic through a free, worldwide, volunteer overlay network, consisting of more than seven thousand relays, to conc ...
.


Background

Operation Onymous was formed as a joint law enforcement operation between the Federal Bureau of Investigation (FBI) and the European Union Intelligence Agency Europol. The international effort also included the
United States Department of Homeland Security The United States Department of Homeland Security (DHS) is the U.S. federal executive department responsible for public security, roughly comparable to the interior or home ministries of other countries. Its stated missions involve anti-terr ...
, Immigration and Customs Enforcement (ICE), and
Eurojust Eurojust is an agency of the European Union (EU) dealing with judicial co-operation in criminal matters among agencies of the member states. It is seated in The Hague, Netherlands. Established in 2002, it was created to improve handling of seriou ...
. The operation was part of the international strategies that address the problems of malware,
botnet A botnet is a group of Internet-connected devices, each of which runs one or more bots. Botnets can be used to perform Distributed Denial-of-Service (DDoS) attacks, steal data, send spam, and allow the attacker to access the device and its conn ...
schemes, and illicit markets or darknets. It was also linked with the war on drugs effort with the participation of the U.S. Drug Enforcement Administration (DEA).


Raids

On 5 and 6 November 2014, a number of websites, initially claimed to be over 400, were shut down including drug markets such as Silk Road 2.0, Cloud 9 and Hydra. Other sites targeted included money laundering sites and " contraband sites". The operation involved the police forces of 17 countries. In total there were 17 arrests. A 26-year-old software developer was arrested in
San Francisco San Francisco (; Spanish for " Saint Francis"), officially the City and County of San Francisco, is the commercial, financial, and cultural center of Northern California. The city proper is the fourth most populous in California and 17th ...
and accused of running Silk Road 2.0 under the pseudonym 'Defcon'. Defcon was "one of the primary targets". Within hours of the seizure a third incarnation of the site appeared, 'Silk Road 3.0'; Silk Road had previously been seized in October 2013, and then resurrected, weeks later, as 'Silk Road 2.0'. $1 million in Bitcoin was seized, along with
The euro sign () is the currency sign used for the euro, the official currency of the eurozone and unilaterally adopted by Kosovo and Montenegro. The design was presented to the public by the European Commission on 12 December 1996. It consists ...
180,000 in cash, gold, silver and drugs. Of the "illicit services" that were initially claimed to have been shut down, few were online marketplaces like Silk Road. A complaint filed on 7 November 2014 in the
United States District Court for the Southern District of New York The United States District Court for the Southern District of New York (in case citations, S.D.N.Y.) is a federal trial court whose geographic jurisdiction encompasses eight counties of New York State. Two of these are in New York City: New ...
, "seeking the forfeiture of any and all assets of the following dark market websites operating on the Tor network", referred to just 27 sites, fourteen of which were claimed to be drug markets; the others allegedly sold counterfeit currency, forged identity documents or stolen credit cards. US and European agencies sought to publicise the claimed success of their six-month-long operation, which "went flawlessly". The UK
National Crime Agency The National Crime Agency (NCA) is a national law enforcement agency in the United Kingdom. It is the UK's lead agency against organised crime; human, weapon and drug trafficking; cybercrime; and economic crime that goes across regional and in ...
sent out a tweet mocking Tor users. The official Europol
press release A press release is an official statement delivered to members of the news media for the purpose of providing information, creating an official statement, or making an announcement directed for public release. Press releases are also considere ...
quoted a US
Homeland Security Investigations The U.S. Immigration and Customs Enforcement (ICE) is a federal law enforcement agency under the U.S. Department of Homeland Security. ICE's stated mission is to protect the United States from the cross-border crime and illegal immigration tha ...
official, who stated: "Our efforts have disrupted a website that allows illicit black-market activities to evolve and expand, and provides a safe haven for illegal vices, such as weapons distribution, drug trafficking and murder-for-hire." Other leading drug markets in the Dark Web were unaffected, such as Agora,
Evolution Evolution is change in the heritable characteristics of biological populations over successive generations. These characteristics are the expressions of genes, which are passed on from parent to offspring during reproduction. Variation ...
and Andromeda. Whereas Silk Road did not in fact distribute weapons, or offer contract killings, Evolution did allow trade of weapons as well as drugs. Prior to the closure of Silk Road 2.0, Agora already carried more listings than Silk Road, and Evolution was also expected to overtake it. Agora and Evolution are more professional operations than Silk Road, with more advanced security; the arrest of the alleged Silk Road manager is thought to have been largely due to a series of careless mistakes. The figure of 414 dark net sites, which was widely reported internationally, and appeared in many news headlines, was later adjusted without explanation to "upward of 50" sites. The true figure is thought to be nearer to 27 sites, to which all 414
.onion .onion is a special-use top level domain name designating an anonymous onion service, which was formerly known as a "hidden service", reachable via the Tor network. Such addresses are not actual DNS names, and the .onion TLD is not in the I ...
addresses direct. Australian journalist
Nik Cubrilovic Nik Cubrilovic is an Australian former hacker and leading internet security blogger. __NOTOC__ Personal life Nik Cubrilovic ( sr, Čubrilović) is an ethnic Serb. Work In 2011 he successfully forced Facebook to address a privacy flaw whereby t ...
claimed to have discovered 276 seized sites, based on a crawl of all onion sites, of which 153 were scam, clone or phishing sites.


Tor 0-day exploit

The number of sites initially claimed to have been infiltrated led to the speculation that a
zero-day vulnerability A zero-day (also known as a 0-day) is a computer-software vulnerability previously unknown to those who should be interested in its mitigation, like the vendor of the target software. Until the vulnerability is mitigated, hackers can exploit it t ...
in the Tor network had been exploited. This possibility was downplayed by Andrew Lewman, a representative of the not-for-profit
Tor project Tor, short for The Onion Router, is free and open-source software for enabling anonymous communication. It directs Internet traffic through a free, worldwide, volunteer overlay network, consisting of more than seven thousand relays, to conc ...
, suggesting that execution of traditional police work such as tracing Bitcoins was more likely. Lewman suggested that such claims were "overblown" and that the authorities wanted to simply give the impression they had "cracked" Tor to deter others from using it for criminal purposes. A representative of Europol was secretive about the method used, saying: "This is something we want to keep for ourselves. The way we do this, we can’t share with the whole world, because we want to do it again and again and again." It has been speculated that hidden services could have been deanonymized if law enforcement replicated the research by CERT at Carnegie Mellon University up until the July 30th patch that mitigated the issue. If sufficient relay nodes were
DDOS In computing, a denial-of-service attack (DoS attack) is a cyber-attack in which the perpetrator seeks to make a machine or network resource unavailable to its intended users by temporarily or indefinitely disrupting services of a host connec ...
ed which would force traffic to route over the attacking nodes, an attacker could perform traffic confirmation attacks aided by a
Sybil attack Sibyls were oracular women believed to possess prophetic powers in ancient Greece. Sybil or Sibyl may also refer to: Films * ''Sybil'' (1921 film) * ''Sybil'' (1976 film), a film starring Sally Field * ''Sybil'' (2007 film), a remake of the 19 ...
. Logs released by the administrator of Doxbin partially supported this theory. Court documents released in November 2015 generated serious research ethics concerns in the Tor and security research communities about the warrantless exploit (which presumably had been active in 2014 from February to 4 July). The Tor Project patched the vulnerability and the FBI denied having paid Carnegie Mellon $1 million to exploit it. Carnegie Mellon also denied receiving money.


See also

*
Anonymizer An anonymizer or an anonymous proxy is a tool that attempts to make activity on the Internet untraceable. It is a proxy server computer that acts as an intermediary and privacy shield between a client computer and the rest of the Internet. It acce ...
* Operation DisrupTor


References


External links

*
United States of America – v. – Blake Benthall a/k/a "Defcon," Defendant.
' – sealed complaint
Operator Of "Silk Road 2.0" Website Charged In Manhattan Federal Court
US Department of Justice The United States Department of Justice (DOJ), also known as the Justice Department, is a federal executive department of the United States government tasked with the enforcement of federal law and administration of justice in the United Stat ...
press release
Dozens of Online "Dark Markets" Seized Pursuant to Forfeiture Complaint Filed in Manhattan Federal Court in Conjunction with the Arrest of the Operator of Silk Road 2.0
US Department of Justice press release
Tag Archives: Operation Onymous
DeepDotWeb DeepDotWeb was a news site dedicated to events in and surrounding the dark web featuring interviews and reviews about darknet markets, Tor hidden services, privacy, bitcoin, and related news. The website was seized on May 7, 2019, during an ...
{{Use dmy dates, date=June 2020 2014 in law Cybercrime Dark web Law enforcement operations Tor (anonymity network)