- Gone Phishing
- Posts
- Shakeeb Ahmed gets 3 years for $12.3M theft
Shakeeb Ahmed gets 3 years for $12.3M theft

Slight technical hitch with yesterdays mailer, its ok we werenโt hackedโฆ. ๐
Welcome to Gone Phishing, your daily cybersecurity newsletter thatโs angling to keep you hooked on staying cyber-safe while youโre surfing the net ๐ฃ๐ฃ๐ฃ
Todayโs hottest cybersecurity news stories:
๐ฎโโ๏ธ Former security engineer Shakeeb Ahmed gets 3 years for $12.3M theft ๐ฐ
โ ๏ธ Facebook users beware! Credit card skimmer LARPs as harmless tracker ๐ณ
๐ช XZ utils backdoor files infects popular liblzma-sys Rust crate in version 0.3.2 ๐ฆ
What is this, Ahmed robbery? ๐๐๐
๐จ Former Engineer Sentenced for Cryptocurrency Exchange Hacks ๐ก๏ธ
๐ Former security engineer Shakeeb Ahmed has been sentenced to three years in a U.S. prison for hacking two decentralised cryptocurrency exchanges in July 2022, pocketing over $12.3 million. Ahmed, who previously worked as a senior security engineer, utilised his expertise in smart contracts and blockchain audits to execute the hacks, as revealed by the U.S. Department of Justice.
๐๏ธ While Ahmed's employer remains undisclosed, it's known that he resided in Manhattan and previously worked at Amazon. Court documents indicate that Ahmed exploited security flaws in smart contracts, allowing him to inflate fees and syphon funds from the exchanges. He even attempted to negotiate with one exchange, offering to return most funds in exchange for their silence.
๐ธ CoinDesk reported that a portion of the stolen funds was returned anonymously, resembling a "white hat" gesture. In addition to targeting Crema Finance, Ahmed attacked Nirvana Finance, resulting in its shutdown after syphoning $3.6 million. Despite a bug bounty offer, Ahmed demanded more, leaving Nirvana uncompensated.
๐ To cover his tracks, Ahmed laundered the stolen assets across different blockchains, using mixers like Samourai Whirlpool. As part of his sentence, he must serve jail time, undergo supervised release, and forfeit $12.3 million, paying over $5 million in restitution.

Learn AI in 5 minutes a day. We'll teach you how to save time and earn more with AI. Join 400,000+ free daily readers for trending tools, productivity boosting prompts, the latest news, and more.

Skim, skimmer, who's got the keys to my bimmer? ๐ถ๐๐
๐จ Facebook-dwelling Credit Card Skimmer Disguised as Meta Pixel Tracker ๐ณ
๐ก๏ธ Cybersecurity researchers have unearthed a cunning credit card skimmer concealed within a counterfeit Meta Pixel tracker script, aiming to elude detection. Injected into websites via customizable code tools like WordPress plugins and Magento admin panels, this malware masquerades as benign scripts, leveraging popular naming conventions like Google Analytics or JQuery.
๐ต๏ธโโ๏ธ The bogus Meta Pixel tracker script mimics its authentic counterpart but harbours JavaScript code that substitutes genuine domain references with malicious ones. Instead of "connect.facebook[.]net," it loads from "b-connected[.]com," hosting a malicious script ("fbevents.js") that stealthily snatches credit card details when users reach checkout pages.
๐ผ The compromised "b-connected[.]com" redirects data to another compromised site, "www.donjuguetes[.]es," highlighting the interconnected web of cyber threats.
๐ก๏ธ To thwart such attacks, experts recommend keeping websites updated, reviewing admin accounts regularly, and frequently updating passwords. Weak passwords and plugin vulnerabilities are often exploited by threat actors to gain elevated access and execute malicious activities.
๐ This revelation coincides with Sucuri's disclosure of Magento Shoplift malware targeting WordPress and Magento sites. These sophisticated attacks, like the MageCart e-commerce malware, underscore the evolving tactics of cybercriminals, necessitating heightened vigilance and proactive security measures.

๐ฃ Catch of the Day!! ๐๐๐ฆ
๐ The Motley Fool: โFool me once, shame on โ shame on you. Fool me โ you can't get fooled again.โ Good olโ George Dubya ๐ Let us tell whoโs not fooling around though; thatโs the Crรผe ๐ at Motley Fool. Youโd be a fool (alright, enough already! ๐) not to check out their Share Tips from time to time so your savings can one day emerge from their cocoon as a beautiful butterfly! ๐ Kidding aside, if you check out their website theyโve actually got a ton of great content with a wide variety of different investment ideas to suit most budgets ๐ค (LINK)
๐ต Wander: Find your happy place. Cue Happy Gilmore flashback ๐๏ธโณ๐๐๏ธ Mmmm Happy Placeโฆ ๐ So, weโve noticed a lot of you guys are interested in travel. As are we! We stumbled upon this cool company that offers a range of breath-taking spots around the United States and, honestly, the website alone is worth a gander. When all you see about the Land of the free and the home of the brave is news of rioting, looting and school shootings, itโs easy to forget how beautiful some parts of it are. The awe-inspiring locations along with the innovative architecture of the hotels sets Wander apart from your run of the mill American getaway ๐๏ธ๐ (LINK)
๐ Digital Ocean: If you build it they will come. Nope, weโre not talking about a baseball field for ghosts โพ๐ป๐ฟ (Great movie, to be fair ๐). This is the Digital Ocean whoโve got a really cool platform for building and hosting pretty much anything you can think of. If you check out their website youโll find yourself catching the buzz even if you canโt code (guilty ๐). But if you can and youโre looking for somewhere to test things out or launch something new or simply enhance what youโve got, weโd recommend checking out their services foโ sho ๐ And how can you not love their slogan: Dream it. Build it. Grow it. Right on, brother! ๐ฟ (LINK)

Updating Rust is a must, must, MUST โ ๏ธโ ๏ธโ ๏ธ
๐จ Backdoor Alert: XZ Utils Compromised by Test Files in Rust Crate ๐ป
๐ต๏ธโโ๏ธ Test files linked to the XZ Utils backdoor have infiltrated a Rust crate called liblzma-sys, according to recent revelations from Phylum. liblzma-sys, boasting over 21,000 downloads, offers Rust developers bindings to the liblzma implementation, a core component of XZ Utils data compression software. The affected version, 0.3.2, was singled out for scrutiny.
๐ก๏ธ "The current distribution (v0.3.2) on Crates.io contains the test files for XZ that contain the backdoor," Phylum highlighted in a GitHub issue filed on April 9, 2024.
๐ผ In response to responsible disclosure, the contentious files ("tests/files/bad-3-corrupt_lzma2.xz" and "tests/files/good-large_compressed.lzma") were promptly removed from version 0.3.3 of liblzma-sys, released on April 10. The preceding version was swiftly withdrawn from the registry.
๐ "The malicious tests files were committed upstream, but due to the malicious build instructions not being present in the upstream repository, they were never called or executed," stated Snyk in its advisory.
๐ The XZ Utils backdoor saga began when Microsoft engineer Andres Freund detected nefarious commits impacting versions 5.6.0 and 5.6.1, released in February and March 2024, respectively. The backdoor circumvented SSH authentication controls, potentially granting remote code execution privileges to attackers.
๐ก๏ธ According to SentinelOne researchers, the actor behind the backdoor, operating under the alias Jia Tan, gradually gained trust within the XZ Utils community over two years. The modus operandi involved subtle code changes aimed at enhancing the backdoor's sophistication and evading detection.
๐ The multifaceted operation involved social engineering tactics, suggesting a coordinated effort using phoney developer accounts. Despite the early discovery and restoration of the XZ Utils repository, the intricate nature of the backdoor hints at a state-sponsored threat actor's involvement, raising concerns about future supply chain attacks.

๐๏ธ Extra, Extra! Read all about it!
Every few weeks, we carefully select three hot newsletters to show you. Reputation is everything, so any links we share come from personal recommendation or carefully researched businesses at the time of posting. Enjoy!
๐ก๏ธ Tl;dr sec: Join 30,000+ security professionals getting the best tools, blog posts, talks, and resources right in their inbox for free every Thursday ๐
๐ต Crypto Pragmatist: Crypto made simple. Actionable alpha in 5 minutes, 3x a week. Join 47,000+ investors and insiders, for ๐
๐ Bitcoin Breakdown: The best in Bitcoin, carefully curated by an alien from the future ๐พ
Let us know what you think!
So long and thanks for reading all the phish!
Give us a rating? |

