Darket Diaries
Darket Diaries

135: The D.R. Incident

Omar Avilez worked in the CSIRT of the Dominican Republic when a major cyber security incident erupted. Omar walks us through what happened and the incident response procedures that he went through. Breakmaster Cylinder’s new album: https://breakmastercylinder.bandcamp.com/album/the-moon-all-that. S

Featured Speakers

Jack Rhysider HostOmar Avales Guest

Topics Discussed

Episode Summary

Executive Summary: The episode follows Omar Avales, a Dominican Republic C-CERT analyst, as he investigates a wave of sophisticated ransomware and intrusion activity affecting Costa Rica and then the Dominican Republic in 2022. The story highlights multi-stage attacks, zero-days, phishing, cross-border intelligence sharing, attribution uncertainty, and the shift from prevention to detection/response in modern cybersecurity.

Main Topics: Recurring dream as metaphor for helplessness (Priority: 5/5): The host opens with a vivid dream about an unstoppable bull breaking into his home, framing the episode’s emotional theme: vulnerability and the sense that cyber threats can penetrate any barrier. Costa Rica ransomware crisis and regional spillover (Priority: 5/5): Conti ransomware crippled about 20 Costa Rican government organizations, prompting regional CERT collaboration and giving Omar insight into attacker methods and coordination. Dominican Republic intrusions, defacement, and zero-day discovery (Priority: 5/5): While hunting for similar malware in Dominican networks, Omar finds a government website defacement and malware planted in a temp directory for 10–11 months, including a privilege-escalation zero-day. Quantum ransomware incident and rapid containment (Priority: 4/5): A separate Dominican agricultural-sector ransomware event used a Fortinet firewall/VPN path; Omar and his team responded quickly enough to stop spread and limit damage. Phishing campaigns, Bandook malware, and Dark Caracal overlap (Priority: 5/5): Hundreds of Spanish-language phishing emails used banking/payment lures and a Bandook backdoor, tying into Dark Caracal-style tradecraft and showing broad compromise across agencies. Attribution uncertainty and geopolitical speculation (Priority: 4/5): The episode explores how Conti, Dark Caracal, possible Russian involvement, and regional politics may intersect, but emphasizes that attribution remains murky and evidence is often incomplete. Defense through monitoring, intelligence sharing, and hardening (Priority: 5/5): Omar shifts from trying to block everything to improving detection and response: DNS monitoring, malware analysis, vendor coordination, ISP blocking, and international sharing of indicators of compromise.

Key Arguments: Modern government networks are vulnerable to coordinated, multi-vector attacks that can bypass traditional defenses; Omar’s investigations repeatedly found intrusions that had been present for months before discovery. Cross-border collaboration is essential: regional CERTs, vendors, and conference networks enabled faster detection, better attribution hypotheses, and more effective remediation. Ransomware groups are not always simple criminals; some campaigns may blend financially motivated crime with state-aligned or geopolitical objectives, making response harder. Attackers exploit human and technical weaknesses simultaneously, including phishing, exposed services, internet-facing vulnerabilities, and zero-days. When prevention fails, the best practical defense is strong monitoring, rapid incident response, and raising the attacker’s cost through coordinated cleanup and blocking. The attacks affected more than just government offices; critical infrastructure and banks were also threatened, making cyber incidents potentially national-security events.

Data Points: Costa Rican government organizations impacted: 20 - Conti ransomware campaign reportedly hit 20 separate government organizations in Costa Rica. Ransom demand: $20 million - Approximate ransom amount mentioned for unlocking Costa Rica’s systems. Malware dwell time on Dominican government server: 10–11 months - A malicious implant was found in a temp directory long after initial compromise. Phishing emails analyzed: 500–600 - Omar’s team reviewed hundreds of Spanish-language phishing emails during the campaign. Organizations compromised in Dominican campaign: 30+ - A broad Dark Caracal-related campaign reportedly compromised over 30 government organizations. Teams at the Dominican C-CERT: 7–8 people - Omar described his core incident response team size while handling the crisis. Bank outage duration: Over a month - A major bank reportedly stopped working for more than a month during the broader incident environment. Dark web identity records: 63.8 billion - Cited in a SpyCloud ad about stolen identity data circulating online. Corporate users exposed to infostealers: Nearly half - SpyCloud ad statistic about historical identity exposure. Organizations able to detect historical identity exposures: 38% - SpyCloud ad statistic about limited detection capability. Organizations affected by ransomware in past year: 85% - SpyCloud ad statistic used to underscore ransomware prevalence. Conti leak size: 60,000 messages - Referenced as leaked communications involving Conti and related actors.

Pivotal Quotes: "You can't defend. You can't protect. The only thing you can do is detect and respond." — Bruce Schneier (quoted by host): Used to frame the episode’s central cybersecurity lesson after repeated intrusions and partial containment efforts. "It was not just Taikarakov, it was not just Conti but also it was Russia was also involved." — Omar Avales: Omar describes how partners interpreted the campaign as potentially involving multiple actors and possible state involvement. "We found out that the threat actor was on their system over 10 months ago." — Omar Avales: Reveals the long dwell time of the intrusion and the scale of missed detection.

Implications: The episode shows that national cyber defense now depends on intelligence sharing, continuous monitoring, and cross-border coordination. For listeners, it’s a warning that compromise may be invisible for months and that attribution can be politically messy.

🔓 Sign Up for Unlimited Episode Search

About Darket Diaries

Explore true stories of the dark side of the Internet with host Jack Rhysider as he takes you on a journey through the chilling world of hacking, data breaches, and cyber crime.

View all episodes from Darket Diaries