An Interpol headline on November 25, 2020 announces "Three arrested as INTERPOL, Group-IB and the Nigeria Police Force disrupt prolific cybercrime group" however the article does not name the suspects. The Interpol article says the three are "believed to be members of a wider organized crime group responsible for distributing malware, carrying out phishing campaigns and extensive Business Email Compromise scams." Interpol's Craig Jones says the year-long investigation was known as "Operation Falcon."
Some of these domain names were used to anchor other types of fraud, for example "c-clh[.]com" was confirmed to be hosting malware on 17JUL2020 and 19JUL2020, and as recently as 22SEP2020, which VirusTotal says was detected as Andromeda, Fareit, or Lokibot by various anti-virus vendors.
He also used this domain to host phish, such as "www.hainanbank.com.cn.c-clh[.]com"
According to the ZoneCruncher tool from Zetalytics, At least 76 domains of his domains were observed resolving in their Passive DNS systems. Many of them were "look alike" domains, likely used for sending malicious email. Some xamples of these would include:
agogpharrna[.]com (the "rn" supposed to look like an "m" to imitate agogpharma)
iescornputers[.]com (the "rn" supposed to look like an "m" for iescomputers)
tataintiernational[.]com (an extra "i" to imitate tatainternational)
owenscorming[.]com (an "m" instead of an "n" for OwensCorning)
Others seem more targeted as general "technical" phish, such as "server-update-mail-verification[.]com" which he registered 12JUN2019, or "itbackupserver[.]com" registered the same day.
CeeCeeBossTMT liked to boast of his wealth on Instagram, although he gave God Almighty all the thanks for the proceeds of his crime. He also liked to imply that his hard work in the music studio was somehow the source of his wealth, rather than the millions he stole from innocent victims around the world.
The "TMT" coincides with his TMT Liquor Store, which he frequently tags in his posts. TMT Liquor shares their WhatsApp Number, +234 901 069 2587 on their Instagram Bio @tmtliquorstore.
We look forward to hearing more about how these three are tied into the larger infrastructure of cybercrime in Nigeria. If you have more information, please do reach out!
please visit my article if you guys don't mind! thanks!:)
ReplyDeleteCeltic Chrono
Celtic Chrono
2013 in womens's road cycling
Nice post keep it up and share more. home firewall device
ReplyDelete