pwshub.com

Sinister sysadmin allegedly locked up thousands of PCs

A former infrastructure engineer who allegedly locked IT department colleagues out of their employer's systems, then threatened to shut down servers unless paid a ransom, has been arrested and charged after an FBI investigation.

Daniel Rhyne, 57, of Kansas City, Missouri, now faces up to 35 years behind bars for the failed ransom attempt after being charged with one count of extortion in relation to a threat to cause damage to a protected computer, one count of intentional damage to a protected computer, and one count of wire fraud.

According to court documents [PDF], Rhyne hatched the scheme in November 2023 while working for an unnamed industrial company, headquartered in Somerset County, New Jersey.

His extortion scheme commenced at around 4:00 PM EST on November 25, 2023, when network admins received password reset notifications for a domain administrator account and hundreds of user accounts. About 44 minutes later, the company's employees received an email with the subject line: "Your Network Has Been Penetrated."

The email warned workers that all IT admins were locked out, or had their accounts deleted, and all backups had been erased. Then came the threat to shut down 40 servers a day until a ransom was paid.

Rhyne allegedly scheduled tasks to delete 13 domain administrator accounts and change the passwords belonging to 301 domain user accounts and two local admin accounts. This would lock these users out of 254 Windows servers.

The sinister sysadmin also changed passwords for two other local admin accounts that would affect 3,284 workstations, and shut down "several" servers and workstations over several days beginning in December 2023, we're told.

Rhyne reportedly used Windows' net user and Sysinternals Utilities' PsPasswd tool to modify these accounts and change the passwords to "TheFr0zenCrew!"

Very creative. But perhaps he should have let it go because Police traced a hidden virtual machine used to remotely access an admin account back to Rhyne's company-issued laptop. He also used the same password, "TheFr0zenCrew!" for this compromised account.

  • Brain Cipher claims attack on Olympic venue, promises 300 GB data leak
  • Iran's Pioneer Kitten hits US networks via buggy Check Point, Palo Alto gear
  • Dick's Sporting Goods discloses cyberattack
  • Volt Typhoon suspected of exploiting Versa SD-WAN bug since June

The court documents also detail Rhyne's web search history, which included lookups for phrases including : "command line to change password," "command line to change local administrator password," and "command line to remotely change local administrator password."

(Note to self: stop Googling "how to dispose of a body without getting caught.")

Additionally, the firm's security cameras and access logs recorded Rhyne entering the building immediately before logging into his company laptop, conducting suspicious searches and looking at company password spreadsheets, while also accessing the hidden VM.

Rhyne made his initial court appearance in Kansas City federal court on August 27.

The charge of extortion in relation to a threat to cause damage to a protected computer carries a maximum penalty of five years in prison and a $250,000 fine. The charge of intentional damage to a protected computer carries a max penalty of 10 years and a $250,000 fine. And the wire fraud offense carries a max sentence of 20 years behind bars and a $250,000 fine. ®

Source: theregister.com

Related stories
2 weeks ago - Sordid search history 'evidence' in case that could see him spend 35 years for extortion and wire fraud A former infrastructure engineer who allegedly locked IT department colleagues out of their employer's systems, then threatened to...
1 month ago - The suit was the idea of Yvonne Meré, chief deputy city attorney in San Francisco, who had read about boys using "nudification" apps to turn photos of their fully clothed female classmates into deepfake pornography. As the mother of a...
1 month ago - From witches and dragons to monster hunters and pirates, Netflix's fantasy library is on point.
3 days ago - From the Upside Down to far off galaxies, these Netflix entries are out of this world.
1 month ago - Plus a bonus featurette introducing various exotic creatures—including a young Shelob.
Other stories
1 minute ago - Many left reeling from July's IT meltdown, but not to worry, it was all unavoidable Germany's Federal Office for Information Security (BSI) says one in ten organizations in the country affected by CrowdStrike's outage in July are dropping...
1 hour ago - Experts at the Netherlands Institute for Radio Astronomy (ASTRON) claim that second-generation, or "V2," Mini Starlink satellites emit interference that is a staggering 32 times stronger than that from previous models. Director Jessica...
1 hour ago - The PKfail incident shocked the computer industry, exposing a deeply hidden flaw within the core of modern firmware infrastructure. The researchers who uncovered the issue have returned with new data, offering a more realistic assessment...
1 hour ago - Nighttime anxiety can really mess up your ability to sleep at night. Here's what you can do about it right now.
1 hour ago - With spectacular visuals and incredible combat, I cannot wait for Veilguard to launch on Oct. 31.