Wednesday, February 28, 2024

Today's Cryptocurrency Updates

Bitcoin Reaches $64K, Eyes New Peak Pre-Halving
Bitcoin price surged over 10% to a new 2024 high of $64,000 on Feb. 28, driven mainly by anticipation of the upcoming supply halving event, which often leads to significant price increases.

Sam Bankman-Fried Seeks Reduced Sentence Amid Fraud Conviction
Sam Bankman-Fried (SBF), the former FTX executive convicted of fraud, is appealing for a more lenient sentence of 63 to 78 months, as opposed to the 100-year recommendation by the Presentence Investigation Report (PSR).

Senator Warren Advocates for Fair Crypto Regulations
Senator Elizabeth Warren emphasized the need for a legal "level playing field" for crypto and advocated for restrictions on Big Tech's artificial intelligence models during a Feb. 27 Bloomberg Television interview.
Bitcoin Mining Strains Power Grid
The White House is concerned that Bitcoin mining could strain the U.S. power grid, signaling a price surge to a record $57,000 since 2021 as mining intensifies energy use.

Kraken Targets Bitcoin ETF Market
Crypto exchange Kraken has unveiled a new division for institutions, focusing on Bitcoin ETFs, with services in trading and staking. Tim Ogilvie heads the initiative, eyeing rapid institutional crypto adoption.


Tuesday, February 27, 2024

How do I find Bitcoin events in the UK?

No text found

What are some undervalued stocks 2024?

Stocks that are either worth more or on a dip right now. Stocks that haven't made their run yet or has alot more room to go for 2025-2026?

my thoughts if you wanna read it... (not advice, just my current opinion and am new)

I am looking for pypl, baba when they dip, I don't want to buy them on a risistance, they make alot of cash, and eventually the stock price will match their profits imo.

Am not sure if NFLX isn't overvalued, but its ATH is 700 at covid, because back then everybody was watching moveis and serieses in their homes. it is now sitting at 600 (28/02/2024) and also has PE of 49 which is very high. However they are gaining customers and doing some very smart moves like adding podcasts, WWE, and they still make movies themselves too. I see them getting monopolistic, but I am not sure how other competitors are doing. Might be a good buy if it dips.

BTC is rising and raising mining stocks (which are very volatile becasue they leverage alot) so clsk, mara, coin, riot are mining stock and they do gain massive growth if btc move up. However there will be halving which cut the profit of mining btc by half, so typically mining stocks tank around that time, but if btc moves up much, that will outweight the halving event. From what I have seen analysts are very very bullish on btc. so mining stocks are like a riskier bitcoin but risk reward is actually not bad, am not sure however when will the top be after this massive run, but if btc go up mining stocks gonna go up, might be cooldown on halving but still up if btc is up.

I would steer away from nvda due to how much hype there is around it, am not saying it is bad but i would be more interested in less hyped semiconductors. if we compare tsm latest quarter it did 7.5b profit and it is valued at 570b, nvda made 13b last quarter and is valued at 1.97t so tsm is twice as efficient at making profits. Although nvda has better growth potential, BUT it is 2t and I cant see it going to 3t as i see tsm go to 800b which is about 50% growth for each. nvda is so big that it won't have explosive growth, and there is a risk if they won't meet expectation they will drop hard. nvda isn't bad but i like other semi more, since they are smaller in cap with room to go. examples are smci (which is good but got overmemed and now is more like a casino for gamblers) and arm which had quite a big run already, my idea is that there might be more semi that will yet to get their run. BTW dell earnings coming in 2 days if am not mistaken, might provide info on how semi profits gonna be doing.

VISA, MA are quite a good for long term instead of spy imo.


Bitcoin and Gift Taxes (NJ, USA)

Can anyone help me understand the potential taxes of gifting?

I'm trying to understand gift taxes for bitcoin in the event I give my mom bitcoin for her birthday.

I bought $100 of bitcoin a ~year ago, and now it's worth $300. When I gift the $300 worth of bitcoin to my mom by transferring it to her. Does she, or I owe taxes on it?

Do long term gains taxes apply? I am aware that long term gains taxes vary from 0%,15%, 20% based on your tax bracket. I'm unsure about how it works for Crypto gifts. Is it handled the same way as if i were to gift stocks?


Monday, February 26, 2024

🏛️ The Wealth Gap & The Fall of Empires 🏛️

We speak often of the rise and fall of empires or the changing world order. The best summary and link to fuller explanations can be found here – a MUST READ in our opinion. What makes that link particularly powerful is it is the thoughts of possibly the most respected person on Wall Street, Ray Dalio, head of the world’s largest hedge fund. Not a ‘crack pot gold bug’, but an observer of history and deep thinker. Indeed, he is often quoted as once saying “If you don’t own gold you know neither history nor economics”. That was a few years back so where are we now?

The good people at Visual Capitalist have just updated their distribution of household wealth in the US graphic. To say it is shocking is an understatement…

https://preview.redd.it/ad4merotl1lc1.jpg?width=1200&format=pjpg&auto=webp&s=dfc63b7e8b09394f23f23962a2f2620c2a16a707

As you can see, the top 0.1% of American households just hit a new peak with around 131,000 households having a minimum of $38m in wealth and each earning around $3.3m per year. Where we see the societal tensions form that Dalio speaks to is the perverse divide between the ‘haves and have nots’. The chart above displays this in technicolour with the top 10% worth more than all the bottom 90% combined. More sadly, the bottom 50% own just 3% of US household wealth.

If you want an explanation of this in one simple chart look no further than the following from Cross Border Capital and more fully explained in our monthly Global Liquidity update (the last one being here and the next (and new improved format) this Friday so don’t miss it!).

https://preview.redd.it/yddrbwvwl1lc1.png?width=3000&format=png&auto=webp&s=4a64ee8cefa67cfc0bc6219dc37de79079ee47c3

What you are looking at is the value of holding real hard monetary assets like gold, silver and bitcoin verses fiat currency, or not being able to own these assets at all. When you consider wages are generally pegged to CPI (inflation) and if you leave your money in the bank (where net interest rates rarely exceed inflation) you are inextricably tied to that bottom dotted line. Whilst people talk about gold being an inflation hedge, they are often thinking ‘main street’ or CPI inflation not ‘monetary inflation’. The solid black line is effectively tracking monetary inflation, the supply of new liquidity, largely off debt. Indeed it is no coincidence that this chart starts immediately after we left the gold standard and started on the credit cycle or debt cycle that inevitably follows the discipline of gold that Dalio talks to. Such cycles enrich the rich who own the benefiting assets and impoverish the rest who don’t or can’t. Inevitably we have the types of societal breakdowns or revolts that litter history and see entire empires fall and monetary (or more accurately, currency) resets. Every single time in 5000 years, those who held gold or silver survived or thrived.

Such historically generationally unprecedented events are hard to grasp and discounted as ‘couldn’t happen this time’ by most. When someone as ‘main stream’ as a Ray Dalio is shouting from the rafters its worth listening to. He maps out these cycles as follows:

https://preview.redd.it/fon6z88yl1lc1.png?width=898&format=png&auto=webp&s=f5d84aa499db535ce65e410bbf0a14a81cd2e8a8

You can decide yourself where we are on that curve on this cycle. What is just plain fact is:

  1. We have the highest debt burden in history

  2. We have had central banks printing money at an unprecedented rate, in large to pay the interest on that same debt pile they expand each time they print

  3. We have the largest economies in the world relying on government deficit spending (adding more debt)

  4. We have a simply massive wealth gap

  5. We have signs of societal revolt in the likes of Trump, Brexit, a huge far right move in European politics, and the likes of the new Argentinian President calling out the charade publicly.

  6. We have increasingly heightened external conflicts and geopolitical tensions.

What few understand is that anyone can own gold and silver, both available in small format bars or coins at relatively low cost or bitcoin at any fraction (8 decimal places!) and start protecting their wealth and joining that gold line in the chart above. The following quote cannot be ignored when considering where we are at this historic juncture.

Better a year too early than a day too late.


so you want to learn to daytrade:

if you don't have the patients to read this and do the required research to understand what it all mean: you should not consider this
this is the very basics
no I didn't wright this I used bard:

Day trading educational beginners guide

The stock market is a centralized exchange where buying, selling, and trading of stocks (also known as shares or equities) and other financial securities take place. It serves as a platform where investors, ranging from individuals to institutions, can participate in the buying and selling of ownership stakes in publicly traded companies. Leaving a sophisticated web of opportunities, a field where fortunes are made and lost in the blink of an eye. Welcome to the world of day trading – a thrilling journey into the heart of financial markets where every second counts, and every decision holds the potential for profit or loss.

What is Day Trading?

Day trading involves buying and selling financial instruments within the same trading day. Unlike traditional investors who might hold stocks for weeks, months, or even years, day traders aim to capitalize on short-term fluctuations in stock prices. They seek to leverage market volatility to generate profits, often closing all positions before the market closes for the day.

The Allure of Day Trading

The allure of day trading lies in its potential for quick profits. With advancements in technology, access to real-time market data, and online brokerage platforms, retail individuals now have the opportunity to participate actively in the market, all while making trades from the comfort of their homes.

However, this high potential for reward comes hand in hand with significant risks. Day trading demands discipline, knowledge, and a solid understanding of market dynamics. Emotions like fear, greed, and overconfidence can wreak havoc on a trader's success.

Risk Management: The Key to Survival

Successful day traders understand that managing risk is paramount. It's not just about making winning trades but also limiting losses. Implementing risk management strategies, such as setting stop-loss orders and diversifying one's portfolio, can safeguard against catastrophic losses and help maintain a trader's longevity in the market.

Education is Empowerment

Knowledge is the cornerstone of success in day trading. Learning about market indicators, technical analysis, chart patterns, and trading strategies is essential for making informed decisions. Continuous education, staying updated on market news, and learning from both successes and failures are vital components of a day trader's journey.

The Mental Game: Psychology

Moreover, day trading is not just about numbers and charts; it's about mastering the mental aspect. Keeping emotions in check, staying disciplined during volatile market conditions, and having the resilience to bounce back from setbacks are crucial elements of a trader's psychological makeup.

As we embark on this journey together, remember that day trading is not a get-rich-quick scheme. It requires dedication, continuous learning, discipline, and a resilient mindset. In the chapters ahead, we'll explore various day trading strategies, analyze market dynamics, and provide insights into developing a successful trading plan.

So, fasten your seatbelt and prepare to navigate the twists and turns of the stock market, as we unravel the art and science of successful day trading.

Chapter One: Mastering Your Mindset

In the high-stakes world of day trading, where fortunes can be made or lost in the blink of an eye, understanding the intricate interplay between your mind and the markets is paramount. This chapter delves into the psychology behind successful day trading, exploring the mental fortitude, emotional intelligence, and disciplined mindset required to navigate the turbulent waters of the financial markets.

The Psychological Battlefield

Day trading is a psychological battlefield where emotions play a pivotal role in determining success or failure. The ability to manage emotions and maintain a disciplined mindset is often the differentiator between profitable traders and those who struggle to find consistency in their results

The Psychological Landscape of Day Trading

Day trading isn't just about charts, numbers, and strategies; it's equally about mastering the mental game. The psychological landscape of day trading encompasses a myriad of emotions and mental states that can significantly impact trading decisions.

Emotions are Double-Edged Sword, both a trader's greatest asset and their most formidable adversary. While confidence and intuition can be beneficial, emotions like fear, greed, and overconfidence often cloud judgment and lead to impulsive decisions. Understanding and managing these emotions is crucial for consistent success.

Emotions and Trading

Emotions like fear, greed, euphoria, and anxiety can significantly influence decision-making in the trading world. Fear of missing out (FOMO) may lead to impulsive trades, while greed can cause traders to overstay in winning positions, risking potential profits.

Overcoming Fear and Greed

Recognizing these emotions is the first step towards overcoming them. Implementing strategies such as setting predefined entry and exit points, using stop-loss orders, and adhering to a well-thought-out trading plan can help mitigate the impact of these emotions.

Developing Emotional Intelligence

Successful day traders possess a high degree of emotional intelligence. They can recognize their emotions, understand their triggers, and, most importantly, maintain emotional discipline in the face of market fluctuations. Techniques like mindfulness, meditation, and journaling can help cultivate emotional resilience and self-awareness.

The Role of Discipline and Patience

Discipline and patience are the cornerstones of a trader's psychological makeup. Following a well-defined trading plan, adhering to risk management strategies, and exercising patience to wait for the right opportunities are vital for long-term success. Avoiding impulsive actions driven by FOMO or panic is key.

1. Sticking to Your Plan:

Discipline is the backbone of successful trading. Creating a detailed trading plan that includes risk management strategies, entry and exit rules, and profit targets is crucial. However, sticking to this plan, even in the face of uncertainty or unexpected market movements, is where discipline truly shines.

2. Patience and Consistency:

Patience is a virtue in day trading. Waiting for the right setups and opportunities, rather than forcing trades, is key. Consistency in following the established plan, even during periods of losses, is what separates disciplined traders from the rest.

Managing Losses and Learning from Mistakes

In day trading, losses are inevitable. It's how traders handle these losses that sets them apart. Embracing losses as learning opportunities, rather than failures, is a hallmark of successful traders. Keeping a trading journal, analyzing mistakes, and continuously learning from experiences are integral parts of the journey.

Building a Resilient Mindset

1. Losses are an inevitable part of trading. Embracing them as learning opportunities rather than failures is crucial. It's essential to understand that even the most successful trader’s experience losses and use them as stepping stones towards improvement.

2. Cultivating mental toughness is vital in handling the emotional rollercoaster of trading. Techniques such as mindfulness, meditation, or having a support network of fellow traders or mentors can help in maintaining a resilient mindset during challenging times.

Psychological Biases Psychological biases are inherent tendencies in human thinking that can lead to systematic deviations from rationality and objective judgment. In day trading and investing, these biases can significantly influence decision-making, often leading to suboptimal outcomes. Let's look at three prevalent biases:

  1. Confirmation Bias: The tendency to seek, interpret, or remember information that confirms preconceptions while ignoring contradictory evidence.

  2. Anchoring Bias: Relying too heavily on the first piece of information encountered when making decisions or judgments.

  3. Herd Mentality (or Herd Behavior): Following the actions or decisions of a larger group without critical evaluation, often driven by a desire to conform or fear of missing out.

  4. Overconfidence Bias: Overestimating one's own abilities, knowledge, or judgments, leading to excessive risk-taking or unwarranted certainty in predictions.

  5. Loss Aversion: The tendency to prefer avoiding losses over acquiring equivalent gains, often leading to risk-averse behavior.

  6. Gambler's Fallacy: Believing that past events will influence future outcomes in random situations, such as assuming that a series of losses increases the likelihood of a future win.

  7. Recency Bias: Giving more weight to recent events or information while undervaluing historical data when making decisions.

  8. Availability Bias: Overestimating the significance of information readily available or easily recalled, leading to biased judgments.

  9. Disposition Effect: The tendency to sell winning investments too early while holding onto losing investments for too long.

  10. Framing Effect: Making decisions based on how information is presented or framed, rather than on the actual content of the information.

  11. Self-Serving Bias: Attributing successes to internal factors while blaming failures on external factors, preserving self-esteem.

  12. Sunk Cost Fallacy: Continuing an endeavor or investment based on the resources already invested (sunk costs) rather than on the expected future outcomes.

  13. Anchoring Effect: Allowing an initial piece of information to anchor subsequent decisions, influencing judgment.

  14. Social Proof: Making decisions based on the actions or beliefs of others, assuming that the majority must be correct.

  15. Narrative Fallacy: Creating a story or narrative to explain events or outcomes, often simplifying complex situations and oversimplifying cause-and-effect relationships.

Mitigating the Impact:

Recognizing these biases is the first step toward mitigating their impact on trading decisions. Strategies like maintaining a trading journal, actively seeking out contradictory information, setting predefined entry and exit points, and conducting thorough research can help counteract these biases. Additionally, having a well-defined trading plan and sticking to it, regardless of market sentiment, can assist in making more rational and less biased decisions.

Understanding and actively working to mitigate these biases are crucial for traders seeking to make informed and objective decisions in the dynamic and often unpredictable world of day trading.

Cultivating a Winning Mindset

Mastering the psychology of day trading isn't an overnight achievement; it's a continuous journey. It requires self-awareness, emotional resilience, discipline, and a commitment to ongoing personal development. By understanding and nurturing a winning mindset, traders can navigate the complexities of the market with greater confidence and success.

Taking responsibility in the stock market without blaming the market itself is a cornerstone of a resilient trading mindset.

In the world of stock trading, the market's volatility is a constant. It fluctuates, surprises, and sometimes defies predictions. Yet, in this dynamic environment, I've learned the crucial art of taking full responsibility for my decisions without laying blame on the market.

Embracing Uncertainty as a Constant

From the outset, I acknowledged the unpredictability of the market. Instead of seeing it as an adversary to blame for losses or unexpected turns, I viewed it as an uncontrollable force—a factor I could not change. This realization led to a fundamental shift in my mindset.

Focus on What I Can Control

Understanding that the market's movements are beyond my control, I redirected my focus inward. I took charge of what I could control: my research, strategy, risk management, and emotional responses. I honed my skills and knowledge, aiming to make informed decisions based on thorough analysis and discipline.

Viewing Setbacks as Learning Opportunities

When faced with setbacks or unexpected market shifts, I refrained from blaming the market. Instead, I scrutinized my approach. Did I follow my strategy diligently? Did I conduct thorough research? Could I have managed risks more effectively? These questions became my compass for learning and growth.

Adapting to Market Conditions

Rather than blaming the market for unexpected movements, I adapted my strategies to accommodate different scenarios. I accepted that the market's whims could present challenges but refrained from using it as an excuse for poor decisions.

Learning Resilience Through Responsibility

Assuming responsibility without blaming the market became a lesson in resilience. It wasn’t about avoiding losses at all costs; it was about navigating the market’s uncertainties while staying committed to my trading principles and continuous improvement.

In the stock market, taking responsibility without blaming the market fosters a resilient and proactive mindset. It's about understanding the uncontrollable nature of the market, focusing on what I can control, and using setbacks as stepping stones for growth. By embracing responsibility, I've learned that success in trading isn’t about blaming external factors; it is about owning every decision, learning from experiences, and adapting to thrive in the ever-evolving landscape of the stock market.

Taking ownership of decisions in trading without attributing blame to market conditions is a powerful mindset that empowers traders to navigate uncertainties and cultivate a proactive approach towards success

The stock market is a centralized marketplace where buying, selling, and trading occurs.
Markets play a pivotal role in the global economy by facilitating investment, capital formation, and wealth creation. It serves as a platform where companies can access funds for growth and where individuals and institutions can invest and trade in securities, aiming to achieve their financial goals.

  1. Listed Companies: Companies that want to raise capital can issue stocks, which represent ownership in the company. When a company decides to go public, it offers shares of its ownership for sale to the public via an Initial Public Offering (IPO).

  2. Investors and Traders: Individuals or entities interested in buying stocks can do so through brokerage firms or online trading platforms. Investors purchase stocks with the intention of holding them for an extended period, potentially benefiting from dividends and capital appreciation. Traders, on the other hand, frequently buy and sell stocks in the short term to capitalize on price fluctuations.

  3. Price Determination: The price of a stock is determined by supply and demand dynamics in the market. Factors such as company performance, economic conditions, industry trends, and investor sentiment can influence stock prices.

  4. Stock Exchanges: These are platforms where stocks are bought and sold. Well-known exchanges include the New York Stock Exchange (NYSE), NASDAQ, London Stock Exchange (LSE), and Tokyo Stock Exchange (TSE). These exchanges act as a marketplace where buyers and sellers are matched together, facilitating transactions.

Why it Matters:

· Capital Formation: Companies raise funds by selling stocks, allowing them to expand, invest in new projects, or undertake research and development.

· Investor Opportunities: Investors have the opportunity to own a part of a company and potentially benefit from its growth, receiving dividends and enjoying capital gains if the stock price increases.

· Economic Indicators: The stock market is often seen as a barometer of overall economic health. Market movements and indices can reflect broader economic trends and investor confidence.

The stock market comprises several interconnected aspects that collectively contribute to its functioning and influence investment decisions:

1. Stock Exchanges:

· Primary Exchanges: Platforms where stocks are listed and traded, such as:

  1. New York Stock Exchange (NYSE) - United States: One of the largest and most well-known exchanges, trading a wide range of stocks and securities.

  2. NASDAQ - United States: Known for technology and growth-oriented companies, trading in stocks, options, and other financial instruments.

  3. Tokyo Stock Exchange (TSE) - Japan: The largest stock exchange in Japan, facilitating the trading of stocks, bonds, and other financial products.

  4. Shanghai Stock Exchange (SSE) - China: One of China's two major stock exchanges, playing a significant role in the country's financial market.

  5. London Stock Exchange (LSE) - United Kingdom: Operating multiple markets and trading services for various types of securities.

  6. Hong Kong Stock Exchange (HKEX) - Hong Kong: A major hub for international companies, especially those looking to access Asian markets.

  7. Euronext - European Union: Operating in multiple European countries, including Amsterdam, Brussels, Dublin, Lisbon, Milan, Oslo, and Paris.

  8. Toronto Stock Exchange (TSX) - Canada: Canada's largest stock exchange, trading in a broad range of sectors, including energy, mining, and technology.

  9. Bombay Stock Exchange (BSE) - India: One of India's oldest stock exchanges, playing a significant role in the country's financial market.

  10. Deutsche Börse - Germany: Operating multiple trading platforms and serving as one of the largest securities trading organizations in Europe.

· Secondary Exchanges: Other trading venues where stocks may also be bought and sold, including electronic communication networks (ECNs) and alternative trading systems (ATSs).

2. Participants:

· Retail Investors: Individuals who buy and sell stocks for personal investment.

· Institutional Investors: Entities like mutual funds, pension funds, hedge funds, and banks that trade on behalf of clients or manage large investment portfolios.

· Market Makers and Brokers: Individuals or firms facilitating trade execution by providing liquidity and connecting buyers with sellers.

3. Financial Instruments:

· Stocks (Equities): Ownership shares in a company, entitling shareholders to dividends and voting rights.

· Bonds: Debt securities issued by companies or governments, representing a loan that pays periodic interest.

· Derivatives: Contracts who assign leverage and whose value derives from an underlying asset (e.g., options, futures, swaps).

5. Regulation and Oversight:

· Regulatory Bodies: Agencies (e.g., SEC in the U.S., FCA in the UK) responsible for overseeing and regulating market activities to ensure fairness, transparency, and investor protection.

The stock market is a multifaceted ecosystem involving exchanges, diverse participants, financial instruments, indices, mechanisms for trading and analysis, and regulatory oversight. Understanding these interconnected aspects is crucial for investors seeking to navigate the complexities of the market and make informed investment decisions.

Specialized markets encompass a range of specific sectors, instruments, or trading methodologies within the broader financial landscape. Here's a breakdown of various specialized markets and different types of markets available:

1. Equity Markets:

· Primary Market: Where initial offerings of stocks (IPOs) occur.

· Secondary Market: Platforms for buying and selling previously issued stocks (e.g., major stock exchanges like NYSE, NASDAQ).

2.Derivatives Markets:

· Options Market: Contracts granting the right (but not obligation) to buy or sell an asset at a specific price within a set time.

· Futures Market: Contracts obligating buyers and sellers to trade an asset at a predetermined price and date.

3. Commodity Markets:

· Agricultural Commodities: Trading in products like wheat, corn, soybeans, etc.

· Energy Commodities: Including oil, natural gas, and electricity.

· Precious Metals: Gold, silver, platinum, etc.

4. Foreign Exchange (Forex) Markets:

· Currency Trading: Trading pairs of currencies, such as USD/EUR or GBP/JPY.

5. Cryptocurrency Markets:

· Cryptocurrencies: Digital blockchain currencies like Bitcoin, Ethereum, and numerous others traded on various cryptocurrency exchanges.

6. Fixed Income Markets:

· Bond Markets: Trading debt securities issued by governments, municipalities, or corporations.

· Money Markets: Dealing in short-term, low-risk debt securities like Treasury bills, certificates of deposit, etc.

7. Alternative Investment Markets:

· Private Equity: Investments in private companies or assets not traded on public exchanges.

· Venture Capital: Investments in early-stage startups with high growth potential.

8. Real Estate Markets:

· Residential Real Estate: Buying and selling homes, apartments, etc.

· Commercial Real Estate: Investing in properties like office buildings, retail spaces, etc.

9. Over-the-Counter (OTC) Markets:

· Unlisted Securities: Trading securities not listed on formal exchanges, often facilitated by dealers or market makers.

10. Regional and Emerging Markets:

· Developing Markets: Investing in emerging economies' stock markets (e.g., BRICS countries - Brazil, Russia, India, China, South Africa).

· Frontier Markets: Investing in less developed and smaller markets with growth potential.


Sunday, February 25, 2024

The United States health care system was attacked this week Pt.2: ConnectWise

This sub is described to be for discussions about issues which have captured your imagination; this story has been a fun ride and certainly did for me. There is this whole underground criminal ecosystem that just runs in the background, raking in hundreds of millions of dollars a year, and almost no one really knows it's happening. In this post, I offer articles available to everyone in the timeline they occurred over the last week. Additionally, I am only moderately educated in tech- so some of the jargon I use may not be the usual standard. Conclusions about the situation I outline here and its potential outcome I leave to you.

‘It's odd because now our work has shifted to not getting ahead of the vulnerability and understanding it and sharing the intel, it's watching the internet burn and trying to respond and remediate the best we can. We're watching the world burn.’

John Hammond

Principal Security Researcher at threat hunting firm Huntress

02/23.

02/19 Not a Bug, a Feature

On February 13th, a crowdsourced research team reached out to major IT company ConnectWise explaining a Proof of Concept (PoC) vulnerability within the company's flagship product ScreenConnect; the PoC outlines that these servers could be breached using a very simple flaw that allows hackers to create an Administrative account inside the server; by creating an administrative account, the hacker is then able to essentially do whatever they want with the machines connected to them. ScreenConnect servers host hundreds of thousands of endpoints (other PCs) across the world, the majority of these servers are used by local governments, emergency systems, and healthcare organizations.

This flaw is being tracked as CVE-2024-1709 (also called "the ScreenConnect Authentication Bypass") and described in a security bulletin by ArcticWolf as "embarrassingly easy" to execute. A video here posted on 02/20 shows how simple it is to accomplish- the ethical hacker finishes the exploit's steps in under 30 seconds and ends with "PLEASE PATCH". A detailed analysis of the bug by Huntress says

Once you have administrative access to a compromised instance, it is trivial to create and upload a malicious ScreenConnect extension to gain Remote Code Execution (RCE). This is not a vulnerability, but a feature of ScreenConnect, which allows an administrator to create extensions that execute .Net code as SYSTEM on the ScreenConnect server

CVE-2024-1709 has been listed to have a Common Vulnerability Scoring System (CVSS) score of 10. IT experts use the CVSS to identify the scope and impact.

It is very common to see vulnerabilities with a base score of 9.8, but much less common to see any with CVSS 10.0. The difference in CVSS score is primarily due to the scope metric.....A vulnerability with CVSS 9.8 has the most severe exploit-ability and impact metrics, but its impact does not extend beyond the vulnerable component. However, while a vulnerability with CVSS 10.0 also has the most severe exploit-ability and most often the highest impact metrics, its impact extends also beyond the vulnerable component.

ConnectWise posted a public notice on February 19th, recommending that clients update to a new patch (23.9.8) that corrected this issue. Prior to this update (which is now being offered for free as of 02/23) clients needed to pay a monthly maintenance fee to continue to receive updates. By the end of the day Monday, several thousands online-connected servers were identified to still be operating on patch 23.9.7 or earlier. Making these servers and all their endpoints vulnerable to intrusion.

02/20 Operation Cronos

The United States' Cybersecurity and Infrastructure Security Agency (CSIA), Federal Bureau of Investigations (FBI), The National Crime Agency (NCA), in a joint effort with 9 other countries; released information about the completion of a few year investigation code-named 'Cronos' into a online cyber-gang named "LockBit" that specializes in Ransom as a Service (RaaS) attacks. Operation Cronos reportedly resulted in international arrests, shuttered 35 servers in the UK and US, 2 official arrests, and seizure of millions in crypto currency assets.

Authorities digging through the Bitcoin addresses are beginning to think the organization may have generated more than $1 billion in ransom since it's inception 4 years ago because of the ~20% cut they usually take with their investors; meaning the seized cryptocurrency likely amounted to significantly more in actual income.

Ransomware as a Service

Over the years cyber-gangs like LockBit have acted as threat actors for nation-state governments such as Russia, Korea, China, and Iran. The service they provide works like this:

  1. A entity hires a Cyber gang like LockBit to attack vulnerabilities in systems when they become available. The hiring entity pay a small commission to the cyber-gang, and then they get to work.
  2. The hackers install malware with these vulnerabilities that encrypts the victim's entire drive aside from the base configuration files. Allowing the user to still have access to their computer; but losing their data. The user is then prompted with an ominous message explaining the situation, and that they have a certain amount of days to pay LockBit or their information will be lost permanently.
  3. If the victim pays the attackers in time; the money is split with the entity that hired them and the decryption key is provided to the victim. If the allotted time passes with no payment or action, the victim loses their chance to recover the data on their drive. Their organization still profits as they keep the initial contract fee and will now attempt to sell the victim's data online.

The LockBit 3.0 Ransom screen

Depending on the victim, these costs can be rather "reasonable" compared to something you'd expect in a movie; that's because they want you to actually be able to pay. They usually target companies that would provide valuable data to sell if payment isn't sent; but individual users have been attacked as well. They also do not usually attack the same place twice- all in the pursuit of handling this business professionally so they do not damage their "reputation"; and again, it's just so they will get paid. They usually do; this is because these organizations operate out of countries such as Russia, where these crimes are not against-the-law when they are targeted at western countries.

Adjacent cyber-gangs that also offer similar services include names like Cl0p, Akira, Play, ALPHV/Blackcat, and Rhyside.

DoT Sanction Press Release

The US Department of the Treasury and the Office of Foreign Assets Control posted trade sanctions that afternoon against hackers Ivan Kondratiev and Artur Ravilevich; announcing that any US based assets in their name would be seized and must be reported to the OFAC, anyone caught conducting trade with these individuals would be subject to arrest and potentially have the same sanctions posted on them. Additionally they posted a listing containing what they said to be the names of every individual associated with the cyber-gang.

List of LockBit affiliates released by Operation Cronos 02/21

The Cronos strike team claimed they only released one name per individual, with the reason they've shared it is to prove to the LockBit gang that they know who they are, and they are coming for them.

In addition to the seizures and arrests; Japan's National Police Agency claimed they were able to create a free decryptor for the LockBit 3.0 malware or LockBit Black from the software found in the confiscated hardware, and is asking that any victims of this malware reach-out for assistance in unlocking their data.

Tokyo-based cybersecurity firm Trend Micro which assisted with the Project Cronos LockBit investigation also had this to add

The ransomware operation was working on the "next-generation" crypto-locking malware, dubbed LockBit-NG-Dev*, "which could be an upcoming version the group might consider as a true 4.0 version once complete,"*

The language suggests that although 3.0 was used to create a decryptor, this is not the case with the new LockBit-NG-Dev variant.

LockBit Ethics

LockBit in the past has explained they have strict rules as to what targets are allowed by their members; one of those being that Hospitals are strictly off the table-

In December 2022, a LockBit member attacked a the Toronto Children's hospital SickKids. LockBit shortly after provided the decryption key to the hospital and released an apology statement on Twitter.

We formally apologize for the attack on sikkids(.)ca and give back the decryptor for free, the partner who attacked this hospital violates our rules, is blocked and is no longer in our affiliate program.

However now, the crime organization has appeared to have backtracked on those rules. In late January 2024, two Chicago hospitals were attacked using the LockBit software. On January 31st, the hospital's data was posted to their catalog with the remaining time left for the hospitals to pay, the ransom price ($895,294 USD), and the first few sentences of the description of the hospital's data

Screenshot captured from LockBit stolen data listing - Jan, 31st, 2024

The listing appears to have captured a new perspective the LockBit organization has taken up in regards to the United States' Healthcare system.

Later that day- Yossi Rachman senior Director of Research at Semperis; a IT security and recovery platform told InformationWeek:

It is possible individuals involved with LockBit could attempt to reorganize under the same name or a different name. It is also possible they will seek retaliation after the disruption of operations.

02/21 A $15 Million Reward

The morning of February 21st, Unitedhealth Group; a mega-corporation that deals primarily in medical services. Submitted a 8-K Form to the Security Exchange Commission explaining an ongoing situation in relation to one of their child companies Change Healthcare:

(United Healthgroup) identified a suspected nation-state associated cyber security threat actor had gained access to some of the Change Healthcare information technology systems. Immediately upon detection of this outside threat, the Company proactively isolated the impacted systems from other connecting systems in the interest of protecting our partners and patients, to contain, assess and remediate the incident.

Change Healthcare hosts services that handle mission critical data such as medical delivery logistics, financial data/transactions, insurance claims, and storage of electronic medical health records which amount to 85 million patients in the US (25% of the population) among dozens of other services. These services handled 15 billion medical related transactions last year alone. Change Healthcare is also the sole provider for prescription medications to the United States' military worldwide, and handles data services for these bases as well.

Tricare news, an official military medical news source posted an announcement from "Military Health System Communications" not long after the SEC submission.

On Feb. 21, Change Healthcare disconnected their systems to protect patient information. This is impacting all military pharmacies worldwide and some retail pharmacies nationally.

A post from Navel Hospital Camp Pendleton corroborated this statement with a bulletin to their official website

A reported cyberattack on the nation’s largest commercial prescription processor, Change Healthcare, has affected military clinics and hospitals worldwide.

After Unitedhealth Group submitted the SEC form- The United States' Department of State posted a reward for information up to $15 million USD for any tip that leads to the arrest of a LockBit associated affiliate.

Reward for Information posted by Department of State 02/21

The Bugs Out the Bag

IT security newsletter TechCrunch talked to ConnectWise spoke person Amanda Lee that afternoon. Amanda declined to say how many of their customers had been attacked by this point; but said that ConnectWise has seen "limited reports" of suspected intrusions. She added

We have received updates of compromised accounts that our incident response team have been able to investigate and confirm (were attacked).” but also said that "there has been no data exfiltration reported to us.

In contrast- Cybersecurity Company Huntress' CEO Kyle Hanslovan told TechCrunch

I can’t sugarcoat it — this shit is bad. We’re talking upwards of ten thousand servers that each control hundreds of thousands of endpoints

Noting that as of that time Huntress' telemetry could identify 8,800+ ConnectWise servers that still remain vulnerable to the CVE-2024-1709 exploit (This number was corroborated by the Censys platform; another Cybersecurity agency), and added

Due to the sheer prevalence of this software and the access afforded by this vulnerability signals we are on the cusp of a ransomware free-for-all.

When ConnectWise posted the advisory on Monday 02/19 regarding the ScreenConnect Authentication Bypass; the information as to the extent of the defect was vague and did not provide details on how serious of an exploit this is. Their excuse for not releasing the specifics was:

There should not be public details about the vulnerability until there had been adequate time for the industry to patch. It would be too dangerous for this information to be readily available to threat actors.

Unfortunately, by end of day 02/21; information on how to utilize the exploit was already being regularly shared and discussed.

02/22 The Calm Before the Storm

Around 1pm CST; a nonprofit security organization called Shadowserver, which declares itself to be "altruistically working behind the scenes to make the internet more secure for everyone" posted an update to Twitter about an analysis from the previous day:

We've improved the scanning/detection for vulnerable instances of ConnectWise ScreenConnect (CVE-2024-1709/CVE-2024-1708) - we now see over 8200 vulnerable instances (on 2024-02-21).

Shadowserver Map displaying vulnerable servers

As Shadowserver is a third-party investigator, these 8,200 instances are publicly-visible servers and are open to attack; any seasoned hacker would be able to easily find and exploit these machines. Shadowserver also added that 643 IP addresses had already been attacked at the time of their review which was handled the previous day.

Government Info Security, a cyber security newsletter posted that the official LockBit leak site (a site the crime organization used to make threats, list their victim's information, and release public statements) was then seized by the Operation Cronos team.

The LockBit victim data listing site on 02/22

Shortly after the seizure, authorities posted to the leak website that they had identified, but only referred for removal of more than 14,000 email accounts. Accounts hosted by peer-to-peer email encryption providers like Mega, Tutanota, and Protonmail.

Apply the patch, or throw it away

In an Alert posted by CISA addressed to ConnectWise clients, they write

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable before February 29th

John Hammond; principal security researcher at threat hunting firm Huntress told CRN

“This demonstrates the severity and the impact that we do really need to take this one seriously,” Hammond said. “They've updated it now to include that they are seeing it used to deploy ransomware. It’s very, very stern,” he added. “They’re saying, ‘Take care of this right now or pack it up and put it away.’ They’re trying to talk to the whole world or any business that uses this on-premise instance. It’s a slap in the face, the wake-up call, that says take action now or seriously just pull it off the shelf.”

Patrick Beggs, ConnectWise CISO, told CRN Friday in an apparent attempt to mitigate perception of the situation

We uplifted the [cloud] version. Sometimes the version updates just weren't showing, it’s literally that simple. There were a few glitches and we had to kind of re-push and then it happened.

But because every on-site server hasn’t been updated, exploits have now been reported.

Hammond, however, believes the exploitation to be a large cyberattack.

We were not going to release our proof of concept because that's just enabling threat actors,” Hammond said. “Then a proof of concept got out. It's odd because now our work has shifted to not getting ahead of the vulnerability and understanding it and sharing the intel, it's watching the internet burn and trying to respond and remediate the best we can. We're watching the world burn.

SlashAndGrab

By mid-day Wednesday, the tech community began to identify a series of reported attacks using the ScreenConnect Authentication Bypass exploit in conjunction with another ScreenConnect defect tracked as CVE-2024-1708. This technique was labeled the "SlashAndGrab".

A technical Analyst Max Rogers working with a team including Analysts from Huntress Labs identified that critical systems such as Vet Offices, Health Clinics, and Local governments were being actively attacked using the LockBit malware and other techniques

Technical Analyst Max Rogers' post to X

In a post on BleepingComputer a tech related news source, described a report from Sophos, a Security management and operations company:

On February 22, 2024, Sophos X-Ops reported through our social media handle that despite the recent law enforcement activity against the LockBit threat actor group we had observed several attacks over the preceding 24 hours that appeared to be carried out with LockBit ransomware, built using a leaked malware builder tool

According to another BleepingComputer report; an ex-LockBit developer released the LockBit 3.0 software to GitHub available to the public in 2022. Sophos suggest that the attacks they are seeing are variants of this version.

It appears that our signature-based detection correctly identified the payloads as ransomware generated by the leaked LockBit builder, but the ransom notes dropped by those payloads identified one as “buhtiRansom,” and the other did not have a name in its ransom note.

As the night faded into the next day- the amount of attacks increased.

02/23 The Free for All

In Sophos X-Ops director Christopher Budd told Madrastribune a tech newsletter based out of the UK

We’ve seen multiple attacks involving ScreenConnect in the past 48 hours. The most noteworthy has been a malware that was built using the LockBit 3 ransomware builder tool leaked in 2022: this may not have originated with the actual LockBit developers. But we’re also seeing RATs [remote access Trojans], infostealers, password stealers and other ransomware. All of this shows that many different attackers are targeting ScreenConnect

The majority of these hackers were able to successfully install administrative accounts on the servers being attacked.

On an upbeat note; Sophos states in an official report on the situation:

most of the post-compromise activities we have documented in this article aren’t novel, original, or outstanding. Most threat actors simply don’t know what to do beyond the same usual, procedural tradecraft; cybercriminals are rarely sophisticated, and the infosec community can beat them together.

(That link I have attached above to the Sophos official report about SlashAndGrab is actually a really interesting read; they go on to explain the different types of attacks they witnessed during the free for all and explain how they worked. I recommend it.)

In a report by BleepingComputer; at this point 119 Change Healthcare and Optum services were experiencing outages due to attacks utilizing the SlashAndGrab vulnerability; as I described before, each of these services are mission critical to the medical infrastructure, and especially so to the US Military.

Columbia University shuttered their website due to ties to with Unitedhealth and Optum healthcare

Columbia University Bulletin

In a email to their employees Columbia University states

Additionally, to minimize the risk this external cyber security event presents to our computing environment, we have taken the extraordinary precaution of blocking email from the following domains: Optum, Changehealthcare, Caremount, Unitedhealthgroup, Uhc, and Uhg

As the day went on- cyberattack related reports began to pour i

  • State of Emergency - Oakley, California
  • City Computer Infrastructure - Pleasant Hill, California
  • Royal Canadian Police Force
  • I linked almost a dozen other articles here originally, but they broke the character count.

(News from the rest of the day became sleepy... And so did I)

02/24 LockBit Comes Back Online

Despite having it's servers and millions of dollars in assets seized. LockBit reestablished its Dark Web Data Leak site.

LockBitSupp, the gang's apparent leader- posted a update to their page, along with brand new stolen data that could very well have occurred during the ScreenWise error. They go on to say that authorities didn't actually make a decryption tool for LockBit Black as Operation Cronos claimed, but instead captured 1,000 decryption keys that the team may use to help those specific victims (if they can find them).

The lengthy missive says that was only 1k of 20k existing decryption keys; and that additionally, no servers were actually seized as a result of Operation Cronos. But instead the information that the strike team obtained was from using a PHP zero day default, and utilized that vulnerability to appear as though the operation was a success.

A post from LockBitSupp 02/24

Why did it take 4 days to recover? Because I had to edit the source code for the latest version of PHP, as there was incompatibility

He goes on to say that the only reason the website was seized was in an attempt to block LockBit from selling data that was stolen from Fulton County, Ga earlier this month. Fani Willis, District Attorny for Fulton County is currently pursuing a case against former president Donald Trump. It begs the question- who hired the attack on Fulton County in the first place?

The data from the Fulton County heist has been posted to the LockBit data leak site as of this afternoon and is available for sale.

While LockBit's site was under-lock- the Operation Cronos team had this posted about LockBitSupp

We know who he is. We know where he lives. We know how much he is worth. LockbitSupp has engaged with law enforcement

In the message posted Saturday night; LockBitSupp calls bullshit

All FBI actions are aimed at destroying the reputation of my affiliate program, my demoralization, they want me to leave and quit my job, they want to scare me because they can not find and eliminate me, I can not be stopped, you can not even hope, as long as I am alive I will continue to do pentest with postpaid

He even contests in his message, that the lists of names submitted from Operation Cronos are irrelevant as every name they shared is only an alias.

In the end- what is described by Leader LockBitSupp as apparent lies from the Operation Cronos team now leaves questions as to what was/wasn't actually achieved by its "success"; the LockBit organization is now back to life after being quiet for only 4 days; all while a critical error still exists in the majority of the United States' data infrastructure...

This situation is continuing to unfold, and as of this message, over 3000 ConnectWise servers still remain unpatched.

The original post I made was immediately deleted by the reddit auto mod; I believe because of the nearly 100 links I had in the post. I can't parse through them all. So I've attached a google drive link to a PDF of my crazy board of the situation. Most of the information provided here can be seen in that board, I don't have all the original links from this post, but it's most of the important ones. If you can't find it there, look it up- I hate having to say that, but I cant put in more effort to this post; I also did not make the thing "pretty" because I didn't expect I would have to provide it... sorry y'all.

Here is the link to my crazy-board PDF I've uploaded to my google drive.