dark web

us-sting-of-online-gun-part-sales-started-with-a-shipment-marked-“fidget-spinner”

US sting of online gun part sales started with a shipment marked “fidget spinner”

Hidden cargo —

US seizes 350 sites that masked gun part imports from China as toys, jewelry.

US sting of online gun part sales started with a shipment marked “fidget spinner”

Federal authorities have seized more than 350 websites after an undercover investigation revealed that the sites were used to illegally import gun parts into the US from China. To get the illegal items through customs, the sites described the items as toys, necklaces, car parts, tools, and even a fidget spinner.

The sites violated import bans and the National Firearms Act by selling switches—which are “parts designed to convert semiautomatic pistols into fully automatic machineguns”—and silencers—which “suppress the sound of a firearm when discharged,” a Department of Justice press release said.

Some sites also marketed counterfeit Glock parts, infringing trademark laws, including a phony Glock switch that Glock confirmed to investigators was “never manufactured.”

To mask the illegal sales, some sites used domain names referencing “auto parts,” “fuel filters,” or “solvent traps,” a special agent with Homeland Security Investigations (HSI) assigned to the Boston Field Office, Adam Rayho, wrote in an affidavit supporting the domain seizures. Further, some sites actually sold legitimate merchandise, including car products and home supplies, seemingly to obscure the illegal sales.

Others further infringed on Glock trademarks by including Glock or Glock products in the domain names, Rayho wrote.

“The seizure of these domains is a critical step in disrupting the flow of dangerous contraband that threatens public safety,” Acting US Attorney Joshua S. Levy said in the DOJ’s press release. “Those who attempt to exploit online platforms to traffic in highly lethal firearm parts will be held accountable. We will continue to pursue and dismantle these illicit networks wherever they operate to uphold the integrity of our laws and safeguard our communities.”

Feds increasingly seize sites to stop gun part sales

Rayho’s focus is on investigating “crimes that have a nexus to the clearnet or dark web” as part of HSI’s cybercrimes group. His team’s investigation began in August 2023, when the DOJ said that “federal authorities began targeting multiple websites, businesses, and individuals selling, offering for sale, importing, and exporting machinegun conversion devices in violation of federal law.”

This followed through on a HSI promise in 2020 to continue seizing websites to “suppress illicit commerce.” That’s when HSI first used the “novel approach” to shut down a website “wholly dedicated to illegal arms components.” Like many uncovered by Rayho’s team’s sting, that first site seized was disguised as an auto parts site. Previously, HSI had only been “aggressive in the seizure of Internet sites used to facilitate the sale of counterfeit goods.”

To shut down more sites masking illegal gun part sales, Rayho alleged that “an HSI agent acting in an undercover capacity” began visiting the targeted sites in August 2023. The agent found that some sites clearly marketed illegal gun parts while others used false descriptions with pictures and videos of the illegal merchandise. Many sites prompted users to inquire about illegal items on Telegram or WhatsApp and enabled payments by credit card, Apple Pay, or Google Pay. Some sites asked for payment in bitcoins.

Soon after learning how the websites worked, the agent began ordering gun parts, paying between $30 and $200 for shipments. By September 11, 2023, the agent received the first shipment, which contained a phony Glock switch and a silencer. US Customs and Border Protection confirmed that the cargo description for the package claimed that it contained a fidget spinner. Some sites promoted even faster delivery, promising to ship within 24 hours. Every package used a false description to fool customs, successfully pushing gun parts into the US by simply labeling them as objects unlikely to arouse suspicions, such as a tool, a motor, or a necklace. The most common false label was seemingly “toy.”

Also by September, Rayho wrote that HSI had confirmed that several of the seized domains that had been registered on GoDaddy.com appeared to be linked together, “as they had all been purchased by the same Shopper ID.” The agents “also identified additional domains purchased by the Shopper ID.” Rayho suspected that these additional domains were registered to quickly move sites to prevent forfeitures if the original domains were “seized by law enforcement or otherwise shut down.”

“Neither a restraining order nor an injunction is sufficient to guarantee” that sites would be available for forfeiture, Rayho wrote. The site owners “have the ability to move them to another computer/server or a third-party hosting service outside of the United States beyond this Court’s jurisdiction to anywhere in the world,” Rayho wrote, supporting HSI’s bid to seize the websites to prevent illegal gun part sales.

Federal authorities are unlikely to stop seizing domains, as the tactic has proven successful in improving gun safety in the US. Levy confirmed Wednesday that his office “remains committed to protecting our communities from the dangers posed by illegal firearms and firearm accessories, wherever the evidence takes us.”

Ketty Larco-Ward, the inspector in charge of the Boston division of the US Postal Inspection Service (PIS), promised that the PIS is also “committed” to helping federal authorities to “identify those who use the Postal Service to traffic these weapons, remove these illicit items from the mail, and increase the safety of our communities and the Postal Service employees who serve them.”

US sting of online gun part sales started with a shipment marked “fidget spinner” Read More »

investigation-shows-how-easy-it-is-to-find-escorts,-oxycodone-on-eventbrite

Investigation shows how easy it is to find escorts, oxycodone on Eventbrite

Eventbrite headquarters in downtown San Francisco

This June, approximately 150 motorcycles will thunder down Route 9W in Saugerties, New York, for Ryan’s Ride for Recovery. Organized by Vince Kelder and his family, the barbecue and raffle will raise money to support their sober-living facility and honor their son who tragically died from a heroin overdose in 2015 after a yearslong drug addiction.

The Kelders established Raising Your Awareness about Narcotics (RYAN) to help others struggling with substance-use disorder. For years, the organization has relied on Eventbrite, an event management and ticketing website, to arrange its events. This year, however, alongside listings for Ryan’s Ride and other addiction recovery events, Eventbrite surfaced listings peddling illegal sales of prescription drugs like Xanax, Valium, and oxycodone.

“It’s criminal,” Vince Kelder says. “They’re preying on people trying to get their lives back together.”

Eventbrite prohibits listings dedicated to selling illegal substances on its platform. It’s one of the 16 categories of content the company’s policies restrict its users from posting. But a WIRED investigation found more than 7,400 events published on the platform that appeared to violate one or more of these terms.

Among these listings were pages claiming to sell fentanyl powder “without a prescription,” accounts pushing the sale of Social Security numbers, and pages offering a “wild night with independent escorts” in India. Some linked to sites offering such wares as Gmail accounts, Google reviews (positive and negative), and TikTok and Instagram likes and followers, among other services.

At least 64 of the event listings advertising drugs included links to online pharmacies that the National Association of Boards of Pharmacy have flagged as untrustworthy or unsafe. Amanda Hils, a spokesperson for the US Food and Drug Administration, says the agency does not comment on individual cases without a thorough review, but broadly some online pharmacies that appear to look legitimate may be “operating illegally and selling medicines that can be dangerous or even deadly.”

Eventbrite didn’t just publish these user-generated event listings; its algorithms appeared to actively recommend them to people through simple search queries or in “related events”—a section at the bottom of an event’s page showing users similar events they might be interested in. As well as posts selling illegal prescription drugs in search results appearing next to the RYAN event, a search for “opioid” in the United States showed Eventbrite’s recommendation algorithm suggesting a conference for opioid treatment practitioners between two listings for ordering oxycodone.

Robin Pugh, the executive director of nonprofit cybercrime-fighting organization Intelligence for Good, which first alerted WIRED to some of the listings, says it is quick and easy to identify the illicit posts on Eventbrite and that other websites that allow “user-generated content” are also plagued by scammers uploading posts in similar ways.

Investigation shows how easy it is to find escorts, oxycodone on Eventbrite Read More »

4chan-daily-challenge-sparked-deluge-of-explicit-ai-taylor-swift-images

4chan daily challenge sparked deluge of explicit AI Taylor Swift images

4chan daily challenge sparked deluge of explicit AI Taylor Swift images

4chan users who have made a game out of exploiting popular AI image generators appear to be at least partly responsible for the flood of fake images sexualizing Taylor Swift that went viral last month.

Graphika researchers—who study how communities are manipulated online—traced the fake Swift images to a 4chan message board that’s “increasingly” dedicated to posting “offensive” AI-generated content, The New York Times reported. Fans of the message board take part in daily challenges, Graphika reported, sharing tips to bypass AI image generator filters and showing no signs of stopping their game any time soon.

“Some 4chan users expressed a stated goal of trying to defeat mainstream AI image generators’ safeguards rather than creating realistic sexual content with alternative open-source image generators,” Graphika reported. “They also shared multiple behavioral techniques to create image prompts, attempt to avoid bans, and successfully create sexually explicit celebrity images.”

Ars reviewed a thread flagged by Graphika where users were specifically challenged to use Microsoft tools like Bing Image Creator and Microsoft Designer, as well as OpenAI’s DALL-E.

“Good luck,” the original poster wrote, while encouraging other users to “be creative.”

OpenAI has denied that any of the Swift images were created using DALL-E, while Microsoft has continued to claim that it’s investigating whether any of its AI tools were used.

Cristina López G., a senior analyst at Graphika, noted that Swift is not the only celebrity targeted in the 4chan thread.

“While viral pornographic pictures of Taylor Swift have brought mainstream attention to the issue of AI-generated non-consensual intimate images, she is far from the only victim,” López G. said. “In the 4chan community where these images originated, she isn’t even the most frequently targeted public figure. This shows that anyone can be targeted in this way, from global celebrities to school children.”

Originally, 404 Media reported that the harmful Swift images appeared to originate from 4chan and Telegram channels before spreading on X (formerly Twitter) and other social media. Attempting to stop the spread, X took the drastic step of blocking all searches for “Taylor Swift” for two days.

But López G. said that Graphika’s findings suggest that platforms will continue to risk being inundated with offensive content so long as 4chan users are determined to continue challenging each other to subvert image generator filters. Rather than expecting platforms to chase down the harmful content, López G. recommended that AI companies should get ahead of the problem, taking responsibility for outputs by paying attention to evolving tactics of toxic online communities reporting precisely how they’re getting around safeguards.

“These images originated from a community of people motivated by the ‘challenge’ of circumventing the safeguards of generative AI products, and new restrictions are seen as just another obstacle to ‘defeat,’” López G. said. “It’s important to understand the gamified nature of this malicious activity in order to prevent further abuse at the source.”

Experts told The Times that 4chan users were likely motivated to participate in these challenges for bragging rights and to “feel connected to a wider community.”

4chan daily challenge sparked deluge of explicit AI Taylor Swift images Read More »