The Rise of Dark Web Botnet Marketplaces

by Cognyte

The Rise of Dark Web Botnet Marketplaces Annual Cyber Threat Intelligence Report 2021

Page 1

TABLE OF CONTENTS 1 EXECUTIVE SUMMARY 3 1.1 Key Findings 5 1.2 Infostealers 6 1.3 Analysis Methodology 8 1.4 Dataset 8 2 BOT MARKET RESEARCH 9 2.1 Market Comparison 9 2.2 Infostealers Comparison 11 2.3 Country Comparison 12 2.4 Sector Comparison 14 2.4.1 The Banking Sector 16 2.4.2 The Telecom Sector 17 2.4.3 The Energy Sector 18 2.4.4 The Government Sector 19 2.5 Conclusions 20

Page 2

This report investigates the world of bot markets that emerged since 2018. In the last year we have seen this world evolving, with new markets opened, and a larger audience gained. The rise of botnet marketplace Bot markets are automated stores that sell stolen login credentials obtained from computers infected with an infostealer. These bot markets offer login credentials of several websites. When information is purchased, some stores will also provide a full system of fingerprints to help the threat actors mask themselves as the victims. Access to these markets is often invite-only or requires a one-time entrance payment. Each market offer contains information on a compromised system, including logins, passwords and cookies collected from websites a victim visited. The price of the login credentials starts as little as $2.5 and increases depending on the characteristics of the stolen data and the volume of data present on a device. The low cost of the login credentials makes it very accessible to criminals and provides them the possibility to buy in bulk. During 2021, the number of cyber-attacks that utilized compromised passwords has increased significantly. According to research conducted by Verizon, credentials are the main method for hackers to hack into an organization, with 61% of breaches attributed to leveraged credentials1. These breaches involve the use of brute force, trial and error to guess login info, or compromised credentials. Screenshot of one of the markets that sell login credentials https://www.verizon.com/business/resources/reports/dbir/ 1.1 2 Executive Summary 3 The Rise of Dark Web Botnet Marketplaces

Page 3

1 2 Executive Summary Trade of stolen credentials affects real life The cyberattack on the American oil infrastructure company, Colonial Pipeline, occurred in 2021 due to a single compromised password. The compromised password was possibly observed on the Dark Web and was used through a virtual private network account to gain entry to Colonial Pipeline’s network. The billing system was compromised and nearly 100 gigabytes of data were stolen. The pipeline was shut down as a precaution due to the concern that the attackers had obtained data that would allow them to carry out further attacks on vulnerable parts in the system. The fuel shortages affected the flight schedules in the Charlotte Douglas International Airport and in at least five other airports directly serviced by the pipeline. The average fuel prices rose to the highest since 2014 following the shortage, and $4.4 million was paid as ransom2. One of these markets, Genesis Market, had been linked to several breaches, including Electronic Arts (EA), the video game publisher. In this instance, the hacker exposed sensitive data and the source code of FIFA 213. The hacker admitted he purchased the login credentials for EA’s Slack account for $10 and then tricked EA’s IT support into granting him access to the company’s internal network4. In this report we investigate the markets from a macro level. We start by examination of the top four markets, the volume of each, the infostealers used in these markets. We continue with research of the top companies from four selected sectors, banking, telecommunication, government, and energy, from 20 different countries, primarily in Europe. 1 Of data stolen 100 GB Million ransom 4.4 $ Flights were rejected Fuel prices have risen Password https://www.cbsnews.com/news/genesis-cybercriminal-market-ransomware/ https://www.reuters.com/business/colonial-pipeline-ceo-tells-senate-cyber-defenses-were-compromised-ahead- hack-2021-06-08/ https://www.vice.com/en/article/n7b3jm/genesis-market-buy-cookies-slack?utm_source=motherboard_twitter 2. 3. 4. 4 The Rise of Dark Web Botnet Marketplaces

Page 4

1.1 1.2 1.3 1.4Key Findings 5,250,773 stolen login credentials were investigated between 2019- 2021 as part of this research, 3,833,942 of them were collected in 2021 In 2021, the country that was the most exposed in these markets was France In 2020, the country that was the most exposed was Italy We found that the most exposed sector in 2021 was the telecom sector When looking at the banking sector, the country that was most exposed in 2021 was Spain When looking at the telecom sector, energy sector and government sector, the country that was the most exposed in 2021 is France Russian Market is the most dominant and active market out of the four markets that were investigated as part of this report Redline infostealer has been used the most, compared to the other infostealers, during 2021 by the markets analyzed 1 2 Executive Summary 5 The Rise of Dark Web Botnet Marketplaces

Page 5

1.11.2 1.3 1.4 Infostealers Vidar Redline Vidar is a widely used malware that has been active since October 2018. It is sold through Telegram and underground forums for as little as $1505. Aside from attempts to steal passwords, cookies, and history from infected machines, Vidar also looks for credit cards details, Cryptocurrency wallets, file transfer application information, mailing application information, etc. Once Vidar is finished obtaining the information, it wipes all the evidence of its presence from the victim’s machine. In addition to stealing information, Vidar can also be used as a downloader to infect the system with additional malware. Redline is available on underground forums for sale as a permanent version or on a subscription basis. This malware can upload and download files, execute commands, and periodically send back information about the infected computer6. Redline was first sold in the underground forums in February 20207. An infostealer, or information stealer, is a malicious software that aims to gather information, such as username and passwords, from a system. Infostealers are often sold on hacking forums for prices ranging from a few dollars to hundreds of dollars for permanent use or for a subscription. While bot markets use multiple kinds infostealers, our research focuses on the top five: Vidar, Redline, Racoon, AZORult, and Taurus. https://malpedia.caad.fkie.fraunhofer.de/details/win.redline_stealer https://www.bleepingcomputer.com/news/security/vidar-stealer-abuses-mastodon-to-silently-get-c2- configuration/ https://asec.ahnlab.com/en/26584/5. 6. 7. 1 2 Executive Summary 6 The Rise of Dark Web Botnet Marketplaces

Page 6

AZORult TaurusRacoon AZORult was first discovered in 2016. One version of this malware created a new, hidden administrator account on the machine that set a registry key to establish a Remote Desktop Protocol (RDP) connection. The malware is mostly deployed by exploit kits and phishing mails. Besides the malware has the capability to steal credentials, it also collects data on installed programs, cryptocurrency wallets, such as Monero and uCoin, Skype chat history and messages, and collects host Internet protocol (IP) information etc9. Taurus was first detected in April 202010. In addition to the theft of passwords and cookies, this malware can steal some cryptocurrency wallets, commonly used FTP client credentials, information on installed software, and system configurations. The malware is designed to not execute in countries of the Commonwealth of Independent States (CIS).Racoon is an infostealer focused on gathering sensitive and confidential information, financial information, and personal information8. Racoon was first seen in April 2019. It has a relatively low price of $75 for a ‘trial’ week, $200 per month or $499 for four months. The malware is mostly deployed by two methods, third-party exploit kits or phishing campaigns. Threat actors favour this infostealer due to its simplicity and its focus on ‘stealer tasks,’ rather than a focus on masking itself like other infostealers. https://success.trendmicro.com/solution/000146108-azorult-malware-information-kAJ4P000000kEK2WAM https://www.cyberark.com/resources/threat-research-blog/raccoon-the-story-of-a-typical-infostealer https://securityboulevard.com/2021/05/an-in-depth-analysis-of-the-new-taurus-stealer/ 8. 9. 10. 1.11.2 1.3 1.4 Infostealers1 2 Executive Summary 7 The Rise of Dark Web Botnet Marketplaces

Page 7

1.1 1.1 1.2 1.21.3 1.3 1.4 1.4 2021Analysis Methodology DatasetIn our research we focused on four dominant markets: Genesis Market, Russian Market, 2easy, and Amigos. These markets are quite active, updated daily, and well known. We wanted to understand which sectors of the selected sectors and countries are the most exposed, which country is the most exposed in each sector, and which country is the most exposed in the bot markets worldwide. This report focuses on 20 countries, mostly European countries, and four sectors: banking, telecommunication, government, and energy. Additionally, we wanted to understand which of the four markets is the most active. Finally, we collected data on the infostealers mentioned on these markets to determine the most widely used. To understand the markets and the sectors by country, we had to retrieve an enormous amount of data, which was divided to months and years. We focused our report and investigations on data from 2021, which was collected until October 2021. To understand the trend line, we also collected data from the markets from the years 2019-2020. We collected data on the top five banks, three major energy suppliers, three major telecom suppliers and the government top level domains (TLDs) in each selected country. After receiving all the data, we analyzed it according to our questions and drew conclusions. Markets4 Countries20 Sectors41 2 Executive Summary 8 The Rise of Dark Web Botnet Marketplaces

Page 8

12Bot Market Research 2.1 2.2 2.3 2.4 2.5Market Comparison As part of our research, we collected 3,833,942 sale offers that were published during 2021 in four markets, Genesis, Russian Market, 2easy and Amigos. As shown in the graph below, Russian Market is far more active than the others with 71% of the login credentials offered for sale on that platform. The next active market is 2easy with 13% followed by Amigos Market with 10% and Genesis with only 5%. When looking at the number of the offers by months, we notice that a large drop was demonstrated in February compared to January 2021 in Russian Market. Continuously low numbers were kept over the rest of the year. Login credentials offers divided by markets Login credentials offered during 2021 by the different markets10% | Amigos 13% | 2easy5% | Genesis 71% | Russian Market January Februrary March April May June July August September October1,600,000 1,200,000 800,000 400,000 02easyAmigos Russian Market Genesis 9 The Rise of Dark Web Botnet Marketplaces

Page 9

2019 2020 2021 January Februrary March April May June July August September October November December60,000 50,000 40,000 30,000 20,000 10,000 0Another matter that we found interesting was how this trend gained momentum over the years. For that purpose, we collected and analysed all the data from Genesis, which is the first of this kind of market, between the years 2019-2020. In 2019 the number of sales of login credentials on Genesis Market rose dramatically from October. The peak was observed in January 2020, when 52,004 records were offered for sale. Since January 2020, the login credentials have not increased as much, a drop was noticed in February and a larger drop was demonstrated in March 2020. In May 2020, a small peak was noticed but the numbers provided by Genesis Market did not rise dramatically again and were steady at several 20,000-30,000 login credentials sold on the market each month. login credentials offered for sale in Genesis Market between 2019-2021 12 2.2 2.3 2.4 2.5Bot Market Research 2.1Market Comparison 10 The Rise of Dark Web Botnet Marketplaces

Page 10

2.12.2 2.3 2.4 2.5 Infostealers Comparison The second matter we wanted to examine was the popularity of different infostealers in the markets. Data was collected between January and October 2021 for five different infostealers, Vidar, Redline, Taurus, AZORult and Racoon. We noticed that in the beginning of the year, Vidar was the most used infostealer, followed by Taurus infostealer. Racoon infostealer was mainly used in March, with 152,508 records gathered in that month. In April, we noticed a rise in records stolen by Redline and since then, Redline surpassed all others to become the main infostealer. When comparing the popularity of infostealers during 2021, we observed that the most active was Redline, with 32% of sale offers, followed by Vidar with 29%, Taurus with 20%, Racoon with 16% and AZORult, the least active, with 2% of sale offers.Login credentials offered for sale divided by the infostealers during 2021 Login credentials offers divided by infostealers 16% | Racoon 20% | Taurus2% | AZORult 29% | Vidar32% | Redline 12Bot Market Research VidarTaurus RedlineAZORult Racoon January Februrary March April May June July August September October700,000 600,000 500,000 400,000 300,000 200,000 100,000 0 11 The Rise of Dark Web Botnet Marketplaces

Page 11

2.1 2.22.3 2.4 2.5 Country Comparison When looking at the data collected from the selected 20 countries, we noticed that France was the country with the most shared login credentials offered, with 108,174 offers, or 14% of the total login credentials collected this year. Italy followed closely, with 101,632 (13%) offers, Germany was next with 93,247 (12%) and Spain came in last with 86,407 (11%). *The graphs show only countries that receive 1% and above out of the total login credentials investigatedLogin credentials offered for sale- 2021 12Bot Market Research France 14% Italy 13% Germany 12% Spain 11%Poland 10%Romania 10%Portugal 7%Hungary 6%Netherlands 4%Belgium 3%Bulgaria 3%Slovakia 2%Croatia 2%Austria 1%Albania 1% Czech 1%Macedonia 1%Switzerland 1% Spain 86,407 Portugal 51,171 Slovakia 19,451 Croatia 14,999 Austria 10,491 Switzerland 4,702Macedonia 5,538Albania 6,138 Cyprus 2,107France 108,174 Netherlands 33,889Bulgaria 19,999 Belgium 20,835Italy 101,632Romania 74,371 Hungary 44,420 Germany 93,247 Poland 74,546 Czech 9,656 12 The Rise of Dark Web Botnet Marketplaces

Page 12

When we look at the data collected from 2020, we notice that the order of the top countries was slightly different, Italy was rated in first place with 34,287 offers (20%), Spain with 28,445 offers (17%), France with 24,428 offers (14%), Germany with 12,633 offers (7%), etc. The numbers are not surprising. Italy, Spain, France, and Germany are the largest countries out of the investigated countries. They are all western, very developed countries that have been extensively targeted in the past by hackers and APT groups. Login credentials offered for sale- 2020 Italy 20% Spain 17% France 14% Germany 7%Romania 7%Greece 6%Portugal 6%Netherlands 4%Poland 4%Belgium 3% Hungary 4%Bulgaria 2%Austria 1%Slovakia 1%Croatia 1% Czech 1% 2.1 2.22.3 12Bot Market Research *The graphs show only countries that receive 1% and above out of the total login credentials investigated Czech 1,554 Spain 28,445 France 24,428Italy 34,287 Romania 12,264Germany 12,633Portugal 10,228 Netherlands 6,847 Hungary 6,464Poland 6,564Greece 10,860 Slovakia 1,738 Austria 2,455 Bulgaria 3,055Belgium 4,778 Croatia 1,555Switzerland 373 Macedonia 35 Albania 0 Cyprus 134 2.4 2.5Country Comparison 13 The Rise of Dark Web Botnet Marketplaces

Page 13

2.1 2.2 2.32.4 2.5 Sector Comparison To compare between the selected sectors, we collected sectorial data from 20 countries. We collected data for the top five banks, the top three telecom companies, the top three energy companies, and the largest government top level domain (TLD) of each country. For the comparison between sectors, we filtered the offers to the top one bank, telecom company, energy company and government TLD of each country. Analysing the gathered data, we concluded that the telecom sector was the most exposed, with 45% of the login credentials collected. The government sector was next, with 36% of the login credentials, then the banking sector and the energy sector, each with 10%. Login credentials offered for sale, divided by selected sectors 10% | Banks 36% | Governments10% | Energy 45% | Telecom Telecom 165,643Governments 131,601Banks 35,599Energy 35,590 12Bot Market Research 14 The Rise of Dark Web Botnet Marketplaces

Page 14

2.1 2.2 2.32.4 2.5 Sector Comparison The graph below demonstrates the trendline of each sector per year. The exposure of all the sectors grew over the years and is now in its peak. It seems that over the years, the order has not changed. Telecom sector demonstrated higher numbers of offers compared to the other sectors in all researched years. The government sector demonstrated relatively similar numbers to the telecom sector. The banking and energy sectors demonstrated similar numbers that increased in almost the same rate over the years. It is worth mentioning in this context that Cognyte detected an overall increase in cybercrime and nation-state activities against the telecommunications sector11. During 2021, databases of multiple telecommunications companies were traded or offered for free on Dark Web hacking forums, while nation-state groups continued to target telecommunications companies worldwide. The group that was behind the publication of a major breach in 2021 was also responsible for at least 12 more breaches on telecommunication companies across the world since 2019. VoIP companies were also targeted during 2021 by a series of DDoS attacks that disrupted their services. APT Groups targeting sectors is not a new trend. These APT groups are usually state-sponsored, and their motivation is typically political or economic. For example, a group dubbed APT38, or ‘Lazarus Group’ has targeted mainly the banking and financial institution sector, in 2017 the group was linked to multiple attacks on Cryptocurrency coins such as Monero and Bitcoin. A relatively new group named ChamelGang has been focusing on fuel and energy organizations as they attacked the Russian energy organization, the origin of the group is still unknown.Growth of login credentials offered for sale, divided by selected sector, 2019-2021 12Bot Market Research https://www.cognyte.com/blog/telecom-cyber-attack11.TelecomEnergy BanksGovernment 2019 2020 2021180,000 160,000 140,000 120,000 110,000 80,000 60,000 40,000 20,000 0 15 The Rise of Dark Web Botnet Marketplaces

Page 15

2.1 2.2 2.32.4 2.4.1 2.4.2 2.4.3 2.4.4 2.5Sector Comparison The Banking Sector 12Bot Market Research The banking sector As part of our research, we investigated 5,250,773 login credentials, 3,833,942 of them were offered for sale during 2021 and 72,608 were part of our investigated banks. While collecting data from five major banks in the investigated countries, we noticed that the highest number of login credentials offered for sale belonged to banks located in Spain, with 12,008 login credentials being offered online in 2021. The next highest were Hungary, Italy and Greece, with a range of 8,000-9,000 login credentials. The lowest number of login credentials related to banks was observed in Cyprus, with 352. Italy and Spain appeared in the top four countries with information traded in both the banking sector and in the general analysis. France and Germany were also part of the top four exposed countries in general but received relatively low numbers in the banking sector. Hungary and Greece did not receive overall high numbers for the number of login credentials offered for sale online but did receive high numbers in the banking sector.Banking login credentials traded in bot markets, traded by country Spain 17% Hungary 13% Italy 11% Greece 11%Portugal 7%France 7%Germany 6%Slovakia 5%Poland 5%Bulgaria 3%Czech 2% Romania 3%Austria 2%Switzerland 2%Croatia 2%Belgium 1%Netherlands 1% Macedonia 1% *The graphs show only countries that receive 1% and above out of the total login credentials investigated 16 The Rise of Dark Web Botnet Marketplaces

Page 16

2.1 2.2 2.32.4 2.4.1 2.4.2 2.4.3 2.4.4 2.5Sector Comparison The Telecom Sector 12Bot Market Research The telecom sector In the telecom sector we examined 275,739 login credentials associated with three telecom companies in each of the 20 countries. Overall, the numbers examined in this sector were significantly high compared to those in the banking sector. In this sector, France received the highest number of login credentials (44,255) offered for sale online for its dominant telecom companies. Austria and Italy were next with 38,000-39,000 offers. Albania received the lowest number of offers in 2021 with only 214 offers. France received the highest number of login credentials offers in the Telecom sector; this corresponds to the highest value the country received in total offers observed in 2021. We noticed that Italy, which appeared in the top four in the general country analysis, also demonstrated high values in the telecom sector. Spain and Germany also received high values in total and received relatively low numbers in this sector. Austria and Portugal received high values in the telecom sector but demonstrated relatively low numbers of login credentials overall.Telecom login credentials sold in bot markets, divided by country France 16% Austria 14% Italy 14% Portugal 10%Spain 9%Hungary 5%Romania 5%Poland 5%Germany 5%Greece 4%Belgium 3%Netherlands 2%Czech 2%Bulgaria 2%Slovakia 1%Croatia 1% Switzerland 1% *The graphs show only countries that receive 1% and above out of the total login credentials investigated 17 The Rise of Dark Web Botnet Marketplaces

Page 17

2.1 2.2 2.32.4 2.4.1 2.4.2 2.4.3 2.4.4 2.5Sector Comparison The Energy Sector 12Bot Market Research The energy sector For each country, we collected data pertaining to the three dominant energy companies in the country. The country that had the highest sale offers was France with 13,229 during the year 2021. Next is Romania with 8,768 and Portugal with 5,764 login credentials offered for sale. The least amount of offers related to Cyprus, with 13 offers. Energy login credentials sold in bot markets, divided by country France 27% Romania 18% Portugal 12%Netherlands 9%Belgium 8%Greece 7%Poland 4%Spain 3%Czech 3%Hungary 2%Italy 1%Bulgaria 1%Austria 1%Macedonia 1% Croatia 2% *The graphs show only countries that receive 1% and above out of the total login credentials investigated 18 The Rise of Dark Web Botnet Marketplaces

Page 18

2.1 2.2 2.32.4 2.4.1 2.4.2 2.4.3 2.4.4 2.5Sector Comparison The Government Sector 12Bot Market Research The government sector When investigating the government sector, we collected data for the countries’ government top level domains (TLDs). The government’s domain in France, gouv. fr, received the most offers on the collected markets with 47,218 offers. Next was Portugal with 20,092 offers and Spain with 15,344 offers. Bulgaria and Netherlands received zero offers for their government domains. Govenment login credentis offerd for sale in bot markets, divided by country France 36% Portugal 15%Spain 12%Italy 10%Hungary 9%Poland 7%Romania 2%Albania 1%Austria 1%Croatia 1%Macedonia 1% Belgium 1%Cyprus 1% Greece 3% *The graphs show only countries that receive 1% and above out of the total login credentials investigated 19 The Rise of Dark Web Botnet Marketplaces

Page 19

2.1 2.2 2.3 2.42.5 Conclusions 12Bot Market Research As part of this report, we wanted to better understand the new evolving world of the bot markets. We collected an enormous amount of data to answer several questions: which market is the most dominant, which infostealer is used the most, which sector is the most exposed and what country is the most exposed in each sector and in general in these markets. Dominant market Dominant sectorAs we have seen, Russian Market is the most dominant out of the four investigated markets, accounting for 71% of the login credential sale offers observed in 2021. The next more active market was 2easy Market with 13% of the login credentials offered for sale, followed by Amigos Market with 10% and lastly Genesis with 5%. When it comes to infostealers, not all markets expose which stealers are behind the collected login credentials. As discovered, Redline infostealer provided 32% of the login credentials, making it the top infostealer as compared to the others. Due to the malware’s accessibility and reliability, we believe we will keep seeing it as a prime source on the bot markets in the future. In the matter of sectors, we found that the telecom sector was the most exposed sector in the markets out of the investigated sectors with 45% of the login credentials relating to this sector in 2021. We also compared the data over the years and discovered that the telecom sector demonstrated higher numbers of offers compared to the other sectors between 2019 and today. Spain was the most exposed country at the banking sector. France was the country that was most exposed at the telecom, energy, and government sectors. As we expected, the large western countries, such as France, Italy, Germany and Spain, received the highest number of login credentials offers traded online. These countries are more developed, their number of customers is higher compared to the least developed countries, and therefore they possess a higher risk and a higher value target for criminals. We expect to see these countries, along with other western countries, such as Canada and the USA, being a main target of hackers and APT groups in the future. 20 The Rise of Dark Web Botnet Marketplaces The Rise of Dark Web Botnet Marketplaces 20

Page 20

2.1 2.2 2.3 2.42.5 Conclusions 12Bot Market Research Finally We believe the trend of bot markets will increase in the coming years and will be the source of many future breaches. It is important to be aware of this threat and to be familiar with the mitigation methods to protect your organization or your private computer. We have a few recommendations for dealing with these risks: Implement two-factor or multi-factor authentication, that way access to your network will not depend on a compromised username and password. Train employees to detect phishing attacks, the main method of malware delivery. In case of a breach, all passwords must be reset. Ensure that both internal and external users reset their passwords every 90 days and that passwords contain all kinds of characters. Do not reuse the same password for all accounts, that way if password is stolen it would only allow the attacker to access one platform.+ + + + + 21 The Rise of Dark Web Botnet Marketplaces The Rise of Dark Web Botnet Marketplaces 21

Page 21

Disclaimer and Limitation of Liability Copyright and License of Product This report (the “Product”) is the property of Cognyte and is protected by Israel and international copyright law and conventions. User acknowledges that access to the Product is limited to the License terms set forth herein and any expansion must be in writing. The granting of the License to access and use the Product is conditioned on User's agreement not to disclose, copy, disseminate, redistribute, or publish the Product, or any portion of or excerpts thereof to any other party. All materials included in this report were collected by using legal Open Source Intelligence methodologies and supporting technologies. This report does not include interrogation of any specific entity and/or individual. User shall have the right to use the Product solely for its own internal information purposes. Reproduction of the Product in any form or by any means is forbidden without Cognyte's written permission. User agrees to maintain all copyright, trademark and other notices contained in the Product. User agrees that it shall not use Cognyte's name or any excerpts from the Product in the promotion of its products or services. Disclaimer of Warranties Cognyte does not make any warranties, express or implied, including, without limitation, those of merchantability and fitness for a particular purpose, with respect to the Product. Although Cognyte takes reasonable steps to screen the Product for infection by viruses, worms, Trojan horses or other code manifesting contaminating or destructive properties before making the Product available, Cognyte cannot guarantee that the Product will be free of infection. Cognyte does not make any warranties, express or implied, of whatsoever nature with respect to the Product or to the accuracy of any conclusions set out in the Product. Accuracy of Information The information contained in the Product has been obtained from sources believed to be reliable and are provided by Cognyte on an "as is" basis. To the full extent permissible by applicable law, Cognyte disclaims all warranties, express or implied, of whatsoever nature including, but not limited to any warranties as to the accuracy, completeness, quality or adequacy of any such information, any conclusions set out in the Product and any translations in the Product. The reader assumes sole responsibility for the selection of the Product to achieve its intended results. The opinions expressed in the Product are subject to change at any time without notice. 22 The Rise of Dark Web Botnet Marketplaces

Page 22

Limitation of Liability To the extent permitted under applicable law, in no event will Cognyte be liable in any way for:

  1. damages of any kind, including without limitation, direct, incidental punitive, special or consequential damages (including, but not limited to, damages for lost profits, business interruption and loss of programs or information) arising out of the use of or inability to use the Product, or any information provided in the Product, regardless of whether or not Cognyte has been advised of the possibility of such damages;
  2. any claim attributable to errors, omissions or other inaccuracies in the Product or interpretations thereof; and
  3. actions taken or not taken by any person or entity as a result of the review by such person or entity of the Product or information contained therein or as a result of the interpretation of the Product or information contained therein by such person or entity. Indemnification User agrees to indemnify, defend and hold harmless Cognyte, its affiliates, licensors, and their respective officers, directors, employees and agents from and against all losses, expenses, damages and costs, including reasonable attorneys' fees, arising out of the use of the Product by User or User's account. Third Party Rights The provisions regarding Disclaimer of Warranty, Limitation of Liability and Indemnification are for the benefit of Cognyte, and its licensors, employees and agents. Each shall have the right to assert and enforce those provisions against a User. General Provisions Any provision in any memorandum received by Cognyte in connection with the Product which is inconsistent with, or adds to, the provisions of this Agreement is void. Neither the parties' course of conduct or trade practice will modify the terms of this Agreement. If any provision of this Agreement is determined by a court of competent jurisdiction to be invalid, all other terms and conditions shall remain in full force and effect. Governing Law This Agreement and the resolution of any dispute arising hereunder shall all be governed and construed in accordance with the laws of the state of Israel, without regard to its conflicts of law principles. User consents to the jurisdiction of the courts of Tel-Aviv. © 2022 Cognyte Technologies Israel Ltd. All rights reserved worldwide. 23 The Rise of Dark Web Botnet Marketplaces

Page 23