{"id":36021,"date":"2020-07-11T13:53:39","date_gmt":"2020-07-11T13:53:39","guid":{"rendered":"https:\/\/packetstormsecurity.com\/news\/view\/31385\/The-Secret-Service-Tried-To-Catch-A-Hacker-With-A-Malware-Booby-Trap.html"},"modified":"2020-07-11T13:53:39","modified_gmt":"2020-07-11T13:53:39","slug":"the-secret-service-tried-to-catch-a-hacker-with-a-malware-booby-trap","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/the-secret-service-tried-to-catch-a-hacker-with-a-malware-booby-trap\/","title":{"rendered":"The Secret Service Tried To Catch A Hacker With A Malware Booby Trap"},"content":{"rendered":"<div><img decoding=\"async\" src=\"https:\/\/video-images.vice.com\/test-uploads\/articles\/5f088ef5e14272009db4066e\/lede\/1594396474491-encryption-art.png?crop=0.9924141008478359xw:1xh;center,center&amp;resize=1200:*\" class=\"ff-og-image-inserted\"><\/div>\n<div data-component=\"BodyComponentRenderer\" readability=\"113.1854199683\"><span class=\"abc__textblock size--article\" data-component=\"TextBlock\" readability=\"29\"><\/p>\n<p>A Seattle Police Department officer tried to unmask a ransomware attacker by deploying his own hack, according to newly unsealed court records.<\/p>\n<p><\/span><span class=\"abc__textblock size--article\" data-component=\"TextBlock\" readability=\"32\"><\/p>\n<p>Although in this case the officer&#8217;s attempt didn&#8217;t work, the news shows that the use of so-called network investigative techniques (NITs)\u2014the U.S. government&#8217;s general term for hacking tools deployed by law enforcement\u2014is not limited to the FBI. Here, the Seattle Police Department official was working in their capacity as a Task Force Officer for the U.S. Secret Service.<\/p>\n<p><\/span><span class=\"abc__textblock size--article\" data-component=\"TextBlock\" readability=\"30\"><\/p>\n<p>Seamus Hughes, deputy director of the program on extremism at George Washington University, discovered and shared the court docket with Motherboard.<\/p>\n<p><\/span><span class=\"abc__textblock size--article\" data-component=\"TextBlock\" readability=\"32.603571428571\"><\/p>\n<p>In 2016 the South Correctional Entity (SCORE) Jail in Des Moines, Washington found ransomware on its computer network, according to <a href=\"https:\/\/www.documentcloud.org\/documents\/6986753-Secret-Service-Seattle-NIT-Warrant-Application.html\">the warrant application<\/a> written by Chris Hansen, the Seattle Police Department detective and Secret Service Task Force Officer. Ransomware is a type of malware that generally encrypts files on a target&#8217;s system and then demands a bounty payment in cryptocurrency to unlock them. In some cases, ransomware attackers will offer to unlock a limited number of victim&#8217;s files to prove they do have the capability to recover the data.<\/p>\n<p><\/span><span class=\"abc__textblock size--article\" data-component=\"TextBlock\" readability=\"33\"><\/p>\n<p>Hansen spoke to the information technology director for the jail who&#8217;s listed in the court docket as &#8220;A.M.&#8221;, and reported that a user &#8220;was unable to access the user&#8217;s computer files on a server that the SCORE Jail uses to facilitate remote searches of jail records by law enforcement officers with accounts on the SCORE Jail computer system,&#8221; the document reads. The ransomware appeared to have infected the system through the account of an Auburn, Washington police officer who had been hacked himself.<\/p>\n<p><\/span><\/p>\n<blockquote data-component=\"QuoteBlock\" class=\"abc__quote abc__quote--blockquote\" readability=\"11.426751592357\">\n<p><strong>Do you know anything about law enforcement hacking? Who is using the tools, and who is selling them? We&#8217;d love to hear from you. Using a non-work phone or computer, you can contact Joseph Cox securely on Signal on +44 20 8133 5190, Wickr on josephcox, OTR chat on <a href=\"mailto:jfcox@jabber.ccc.de\">jfcox@jabber.ccc.de<\/a>, or email <a href=\"mailto:joseph.cox@vice.com\">joseph.cox@vice.com<\/a>.<\/strong><\/p>\n<\/blockquote>\n<p><span class=\"abc__textblock size--article\" data-component=\"TextBlock\" readability=\"35\"><\/p>\n<p>The impact was sizable, and majorly disrupted work for over 12 hours, infected a network share used by every employee in the jail, and the ransomware also &#8220;infected a software program used by several law enforcement agencies to create lineup montages, infecting the image files used for creating these lineups and preventing law enforcement officers from accessing the system to look up inmate booking photos and tattoo images,&#8221; the document reads.<\/p>\n<p><\/span><span class=\"abc__textblock size--article\" data-component=\"TextBlock\" readability=\"28\"><\/p>\n<p>Along with the bevvy of encrypted material on the system sat another, new file.<\/p>\n<p><\/span><span class=\"abc__textblock size--article\" data-component=\"TextBlock\" readability=\"32\"><\/p>\n<p>&#8220;hallo, our dear friend! looks like you have some troubles with your security. all your files are now encrypted,&#8221; the message from the ransomware attackers read, which added they would only keep the keys to decrypt the files for no more than 72 hours.<\/p>\n<p><\/span><span class=\"abc__textblock size--article\" data-component=\"TextBlock\" readability=\"37.059405940594\"><\/p>\n<p>While Hansen and A.M. were on the phone, the ransomware kept spreading. As A.M. took a RAM image (essentially preserving what was currently in the system&#8217;s memory) of a computer with a suspicious process running on it, the ransomware then started locking down that system&#8217;s files too, the document reads. At Hansen&#8217;s direction, A.M. contacted one of the email addresses provided by the attackers in their original message, <a href=\"mailto:lavandos@dr.com\">lavandos@dr.com<\/a>, and asked for more information on how to retrieve the files. The ransomware attacker replied, and asked A.M. to send three of the encrypted files, the complaint adds.<\/p>\n<p><\/span><span class=\"abc__textblock size--article\" data-component=\"TextBlock\" readability=\"32\"><\/p>\n<p>Hansen checked the email headers of the reply, and found the attacker&#8217;s related IP address was a Tor exit node. Tor is an anonymity network that routes a user&#8217;s traffic through computers spread throughout the world. Because this clearly wasn&#8217;t an IP address that would help identify who the ransomware attacker really was, Hansen hatched a plan.<\/p>\n<p><\/span><span class=\"abc__textblock size--article\" data-component=\"TextBlock\" readability=\"34\"><\/p>\n<p>Hansen first took a NIT, which in this case was a program that once run on a target&#8217;s computer would connect back to a Secret Service server and reveal the IP address of the suspect&#8217;s machine. He then compressed the file, and with the cooperation of the jail, placed the file on the jail&#8217;s compromised network, deliberately exposing it to the ransomware and encrypting it.<\/p>\n<p><\/span><span class=\"abc__textblock size--article\" data-component=\"TextBlock\" readability=\"36\"><\/p>\n<p>The idea was that the jail would send this booby-trapped file, along with two others, to the attackers to decrypt, the document explains. Once the ransomware author sent back the unencrypted versions, the jail would reply saying that one of them\u2014the one including the NIT\u2014is not working, and ask the attackers to examine the unzipped file and repair it. The jail would also send them another, unencrypted copy of the file in case the attackers didn&#8217;t retain one.<\/p>\n<p><\/span><span class=\"abc__textblock size--article\" data-component=\"TextBlock\" readability=\"44\"><\/p>\n<p>&#8220;If the perpetrator(s), in fact, examine(s) the unzipped file, and in doing so attempt(s) to run the file, the action of pressing the &#8216;run&#8217; button will launch the NIT,&#8221; the complaint reads. Once activated, the NIT would not only tip-off investigators to the target&#8217;s IP address, but also collect some other basic information like the computer&#8217;s open communication ports, the type of operating system it was running, its language, timezone, wireless network information, and host and usernames. Armed with that sort of information, investigators may be able to identify where the attackers are located, or eventually who they are.<\/p>\n<p><\/span><span class=\"abc__textblock size--article\" data-component=\"TextBlock\" readability=\"27\"><\/p>\n<p>But this rather convoluted plan didn&#8217;t play out.<\/p>\n<p><\/span><span class=\"abc__textblock size--article\" data-component=\"TextBlock\" readability=\"24.203007518797\"><\/p>\n<p>&#8220;DEPLOYMENT OF NIT UNSUCCESSFUL; NO EVIDENCE SEIZED,&#8221; <a href=\"https:\/\/www.documentcloud.org\/documents\/6986522-Secret-Service-Seattle-NIT-Returned-Executed.html\">another document reads<\/a>. The documents don&#8217;t elaborate why the NIT did not work.<\/p>\n<p><\/span><span class=\"abc__textblock size--article\" data-component=\"TextBlock\" readability=\"27.717622080679\"><\/p>\n<p>U.S. law enforcement has increasingly turned to NITs, especially in cases that involve the Tor network or other anonymity systems. The FBI has used NITs to unmask people <a href=\"https:\/\/www.wired.com\/2009\/04\/fbi-spyware-pro\/\">making bomb threats<\/a>, other <a href=\"https:\/\/www.vice.com\/en_us\/article\/d3b3xk\/the-fbi-created-a-fake-fedex-website-to-unmask-a-cybercriminal\">financially-driven cybercriminals<\/a>, and <a href=\"https:\/\/www.vice.com\/en_us\/article\/wnxbqw\/unsealed-court-docs-show-fbi-used-malware-like-a-grenade\">child predators<\/a>. Whereas some cases are highly targeted in nature, some operations have also been exceptionally broad. <a href=\"https:\/\/www.vice.com\/en_us\/article\/53d4n8\/fbi-hacked-over-8000-computers-in-120-countries-based-on-one-warrant\">Motherboard previously revealed<\/a> how the FBI hacked over 8,000 computers based in 120 countries based on one warrant.<\/p>\n<p><\/span><span class=\"abc__textblock size--article\" data-component=\"TextBlock\" readability=\"27.322580645161\"><\/p>\n<p>That was a legally contentious warrant, <a href=\"https:\/\/www.vice.com\/en_us\/article\/gv5yqj\/in-a-first-judge-throws-out-evidence-obtained-from-fbi-malware\">as many defense lawyers argued<\/a> that the judge who signed it did not have the authorization to green-light searches outside of her own district. Shortly after in December 2016, long-planned changes to the rules around warrants came into effect, meaning that magistrate judges <a href=\"https:\/\/www.vice.com\/en_us\/article\/yp3kz5\/us-judges-can-now-sign-global-hacking-warrants\">could authorize hacking operations<\/a> anywhere in the world.<\/p>\n<p><\/span><\/p>\n<blockquote data-component=\"QuoteBlock\" class=\"abc__quote abc__quote--pullquote\" readability=\"5\">\n<p>&#8220;DEPLOYMENT OF NIT UNSUCCESSFUL; NO EVIDENCE SEIZED.&#8221;<\/p>\n<\/blockquote>\n<p><span class=\"abc__textblock size--article\" data-component=\"TextBlock\" readability=\"28\"><\/p>\n<p>Hansen deployed his NIT a few weeks after those changes, according to the court records.<\/p>\n<p><\/span><span class=\"abc__textblock size--article\" data-component=\"TextBlock\" readability=\"32.760663507109\"><\/p>\n<p>Ahmed Ghappour, associate professor of law at Boston University, who has studied the legal issues around NITs and in particular their geopolitical ramifications, <a href=\"https:\/\/www.vice.com\/en_us\/article\/xygwbz\/dark-web-policing-threatens-national-sovereignty-researcher-argues\">previously told Motherboard<\/a> that hacking suspects who use Tor is &#8220;like playing Russian Roulette with cross-border cyber operations,&#8221; primarily because investigators ultimately don&#8217;t know where the NIT is going to end up, outside the United States or otherwise.<\/p>\n<p><\/span><span class=\"abc__textblock size--article\" data-component=\"TextBlock\" readability=\"30.656934306569\"><\/p>\n<p>And law enforcement NITs have failed in the past. When trying to unmask Buster Hernandez, a particularly egregious child abuser targeting people on Facebook, the FBI tried, and failed, to unmask him with a NIT. But as <a href=\"https:\/\/www.vice.com\/en_us\/article\/v7gd9b\/facebook-helped-fbi-hack-child-predator-buster-hernandez\">Motherboard revealed last month<\/a>, Facebook&#8217;s own security team then purchased a much more effective piece of malware and provided it to the FBI, <a href=\"https:\/\/www.vice.com\/en_us\/article\/gyyxb3\/the-fbi-booby-trapped-a-video-to-catch-a-suspected-tor-sextortionist\">which successfully deployed it<\/a> against Hernandez.<\/p>\n<p><\/span><span class=\"abc__textblock size--article\" data-component=\"TextBlock\" readability=\"30\"><\/p>\n<p>The Seattle Police Department did not respond to a request for comment. The Department of Homeland Security, of which the Secret Service is a part, also did not respond.<\/p>\n<p><\/span><span class=\"abc__textblock size--article\" data-component=\"TextBlock\" readability=\"24.95652173913\"><\/p>\n<p><strong><em>Subscribe to our cybersecurity podcast, <a href=\"https:\/\/itunes.apple.com\/gb\/podcast\/cyber\/id1441708044?mt=2\">CYBER<\/a>.<\/em><\/strong><\/p>\n<p><\/span><\/div>\n<div readability=\"31.5\">\n<div class=\"article-newsletter-signup__content\" readability=\"33\">\n<h3 class=\"article-newsletter-signup__title\">Get a personalized roundup of VICE&#8217;s best stories in your inbox.<\/h3>\n<p>By signing up to the VICE newsletter you agree to receive electronic communications from VICE that may sometimes include advertisements or sponsored content.<\/p>\n<\/div>\n<\/div>\n<p>READ MORE <a href=\"https:\/\/packetstormsecurity.com\/news\/view\/31385\/The-Secret-Service-Tried-To-Catch-A-Hacker-With-A-Malware-Booby-Trap.html\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>READ MORE HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":36022,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[277],"tags":[1093],"class_list":["post-36021","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity-blogs","tag-headlinehackergovernmentmalwareusa"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.8 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>The Secret Service Tried To Catch A Hacker With A Malware Booby Trap 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/the-secret-service-tried-to-catch-a-hacker-with-a-malware-booby-trap\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"The Secret Service Tried To Catch A Hacker With A Malware Booby Trap 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/the-secret-service-tried-to-catch-a-hacker-with-a-malware-booby-trap\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2020-07-11T13:53:39+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2020\/07\/the-secret-service-tried-to-catch-a-hacker-with-a-malware-booby-trap.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1482\" \/>\n\t<meta property=\"og:image:height\" content=\"834\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"6 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/the-secret-service-tried-to-catch-a-hacker-with-a-malware-booby-trap\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/the-secret-service-tried-to-catch-a-hacker-with-a-malware-booby-trap\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"The Secret Service Tried To Catch A Hacker With A Malware Booby Trap\",\"datePublished\":\"2020-07-11T13:53:39+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/the-secret-service-tried-to-catch-a-hacker-with-a-malware-booby-trap\\\/\"},\"wordCount\":1278,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/the-secret-service-tried-to-catch-a-hacker-with-a-malware-booby-trap\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/07\\\/the-secret-service-tried-to-catch-a-hacker-with-a-malware-booby-trap.jpg\",\"keywords\":[\"headline,hacker,government,malware,usa\"],\"articleSection\":[\"CyberSecurity Blogs\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/the-secret-service-tried-to-catch-a-hacker-with-a-malware-booby-trap\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/the-secret-service-tried-to-catch-a-hacker-with-a-malware-booby-trap\\\/\",\"name\":\"The Secret Service Tried To Catch A Hacker With A Malware Booby Trap 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/the-secret-service-tried-to-catch-a-hacker-with-a-malware-booby-trap\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/the-secret-service-tried-to-catch-a-hacker-with-a-malware-booby-trap\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/07\\\/the-secret-service-tried-to-catch-a-hacker-with-a-malware-booby-trap.jpg\",\"datePublished\":\"2020-07-11T13:53:39+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/the-secret-service-tried-to-catch-a-hacker-with-a-malware-booby-trap\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/the-secret-service-tried-to-catch-a-hacker-with-a-malware-booby-trap\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/the-secret-service-tried-to-catch-a-hacker-with-a-malware-booby-trap\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/07\\\/the-secret-service-tried-to-catch-a-hacker-with-a-malware-booby-trap.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/07\\\/the-secret-service-tried-to-catch-a-hacker-with-a-malware-booby-trap.jpg\",\"width\":1482,\"height\":834},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/the-secret-service-tried-to-catch-a-hacker-with-a-malware-booby-trap\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"headline,hacker,government,malware,usa\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/tag\\\/headlinehackergovernmentmalwareusa\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"The Secret Service Tried To Catch A Hacker With A Malware Booby Trap\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"The Secret Service Tried To Catch A Hacker With A Malware Booby Trap 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/the-secret-service-tried-to-catch-a-hacker-with-a-malware-booby-trap\/","og_locale":"en_US","og_type":"article","og_title":"The Secret Service Tried To Catch A Hacker With A Malware Booby Trap 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/the-secret-service-tried-to-catch-a-hacker-with-a-malware-booby-trap\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2020-07-11T13:53:39+00:00","og_image":[{"width":1482,"height":834,"url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2020\/07\/the-secret-service-tried-to-catch-a-hacker-with-a-malware-booby-trap.jpg","type":"image\/jpeg"}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"6 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/the-secret-service-tried-to-catch-a-hacker-with-a-malware-booby-trap\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/the-secret-service-tried-to-catch-a-hacker-with-a-malware-booby-trap\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"The Secret Service Tried To Catch A Hacker With A Malware Booby Trap","datePublished":"2020-07-11T13:53:39+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/the-secret-service-tried-to-catch-a-hacker-with-a-malware-booby-trap\/"},"wordCount":1278,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/the-secret-service-tried-to-catch-a-hacker-with-a-malware-booby-trap\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2020\/07\/the-secret-service-tried-to-catch-a-hacker-with-a-malware-booby-trap.jpg","keywords":["headline,hacker,government,malware,usa"],"articleSection":["CyberSecurity Blogs"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/the-secret-service-tried-to-catch-a-hacker-with-a-malware-booby-trap\/","url":"https:\/\/www.threatshub.org\/blog\/the-secret-service-tried-to-catch-a-hacker-with-a-malware-booby-trap\/","name":"The Secret Service Tried To Catch A Hacker With A Malware Booby Trap 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/the-secret-service-tried-to-catch-a-hacker-with-a-malware-booby-trap\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/the-secret-service-tried-to-catch-a-hacker-with-a-malware-booby-trap\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2020\/07\/the-secret-service-tried-to-catch-a-hacker-with-a-malware-booby-trap.jpg","datePublished":"2020-07-11T13:53:39+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/the-secret-service-tried-to-catch-a-hacker-with-a-malware-booby-trap\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/the-secret-service-tried-to-catch-a-hacker-with-a-malware-booby-trap\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/the-secret-service-tried-to-catch-a-hacker-with-a-malware-booby-trap\/#primaryimage","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2020\/07\/the-secret-service-tried-to-catch-a-hacker-with-a-malware-booby-trap.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2020\/07\/the-secret-service-tried-to-catch-a-hacker-with-a-malware-booby-trap.jpg","width":1482,"height":834},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/the-secret-service-tried-to-catch-a-hacker-with-a-malware-booby-trap\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"headline,hacker,government,malware,usa","item":"https:\/\/www.threatshub.org\/blog\/tag\/headlinehackergovernmentmalwareusa\/"},{"@type":"ListItem","position":3,"name":"The Secret Service Tried To Catch A Hacker With A Malware Booby Trap"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/36021","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=36021"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/36021\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media\/36022"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=36021"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=36021"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=36021"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}