Showing posts with label Carders. Show all posts
Showing posts with label Carders. Show all posts

Thursday, March 26, 2020

Following Putin Order, FSB Cracks Down on Russian Credit Card Marketplaces

Earlier this week I was chatting with one of the top experts on Russian Cybercrime (who has asked to remain anonymous here).  We were discussing the news that was released on 24MAR2020 that the FSB had raided 62 addresses in 11 regions of Russia arresting cybercriminals for their involvement in the online sales of stolen credit cards.

There are some GREAT videos of the FSB in action ... this first one from Gazeta.ru


 click to play



According to the Gazeta articles, the FSB arrested 30 members of an online hacking group, including programmers from Ukraine and Lithuania.  Twenty-five were charged with "Illegal circulation of a means of payment," which in Russia is a violation of Section 2 of Article 187.  Region15.ru adds that the raids were conducted at 62 different addresses, including operations in Crimea, North Ossetia, Kaluga, Leningrad, Moscow, Pskov, Samara and Tambov, Moscow, St. Petersburg, and Sevastopol.

An embeddable image (same video) from Kuban.kp.ru shows image after image of those being arrested in the raids ..



More than $1 million USD and 3 million Rubles were seized, as well as computer equipment, firearms, drugs, gold bullion and precious coins.  Many fake identity documents were also seized, including Russian Federation passports and counterfeit law enforcement officer IDs.  Several of those arrested had been previously prosecuted for similar crimes. Russia Today's coverage of the story cites a December 2019 report by Sberbank saying that criminals frequently convince victims to give up their card details through social engineering by telephone.  They also mention that in October at least 60 million Sberbank credit cards were being traded on the black market.  The FSB arrested a criminal who used the name "Anton 2131" and lived in Volgograd with regards to some of that data.

Other coverage by Scandaly.ru indicated that at least 15 men and 1 woman among the arrested were held without bail in a Moscow court, being accused of serious crimes that would have sentences of at least 7 years.  That article also mentioned that most of the 90 criminal marketplaces run by these criminals were taken offline on March 18th and March 19th.  FSB investigators are now going through these servers to identify "wholesalers." They say they are interested in any customers who purchased more than 500 credit cards from the shops.

A CyberCrime Crackdown in Russia?  What Happened?

When I asked my Russian Cybercrime Expert friend what was behind the large volume of raids, his reply was direct:  President Putin.  He shared with me this article from duma.gov.ru:

Вячеслав Володин принял участие в расширенном заседании коллегии Генеральной прокуратуры РФ  (Vyacheslav Volodin took part in an expanded meeting of the board of the Prosecutor General of the Russian Federation)


As President Putin addressed the board of the Ministry of Internal Affairs, he charged them strictly that they needed to pay "constant attention to the Internet" and "work to identify the organizers and instigators who should be deservedly punished" for their crimes.  The Duma article said it like this:

"[President Putin] demanded that law enforcement agencies develop a system to combat cybercrime. Speaking at an enlarged meeting of the board of the Prosecutor General’s Office of the Russian Federation, he noted that in recent years “extremely negative dynamics have been recorded in crimes related to the use of information technology”.

“I’m asking the Prosecutor General’s Office, together with the Ministry of Internal Affairs and other relevant structures, to analyze how efficiently the work in this area has been built, how the available procedural capabilities are being used, and in general I’m asking for a system, a set of measures to reduce the number of such crimes,” the head of state said.

Guess what happens when President Putin orders the Prosecutor General to do something to reduce the number of cybercrimes in Russia?  The FSB gets to work arresting people!

Russian Credit Card Criminals Detained

While the names of those arrested were not listed in any article, it was fairly simple to pull them together, once my Russian colleague showed me the ropes of the "mos-gorsud" site where federal charges are tracked.  By searching for "Article 187 Section 2" and limiting my scope to people arrested in March 2020, I came up with this list of likely players:

  • Шувалов А.В - Shuvalov A.V. -  in court 20MAR2020 - 77RS0027-01-2020-004928-65
  • Светличный Л.И. - Svetlichny L.I. - in court 21MAR2020 - 77RS0027-01-2020-004942-23
  • Малинин М.А. - Malinin M.A. - 20MAR2020 - 77RS0027-01-2020-004935-44
  • Строганов А.Т. -  Stroganov A.T.  - 20MAR2020 - 77RS0027-01-2020-004934-47
  • Ахметов В.А. - Akhmetov V.A. - 21MAR2020 - 77RS0027-01-2020-004946-11
  • Селиванов Г.В. - Selivanov G.V. - 20MAR2020 - 77RS0027-01-2020-004924-77 
  • Карпунин С.В. - Karpunin S.V. - 20MAR2020 - 77RS0027-01-2020-004936-41
  • Федотов И.О. - Fedotov I.O. - 20MAR2020 - 77RS0027-01-2020-004933-50 
  • Галкин А.В. - Galkin A.V. - 20MAR2020 - 77RS0027-01-2020-004929-62 
  • Синицын А.В. - Sinitsyn A.V. - 21MAR2020 - 77RS0027-01-2020-004944-17 
  • Смирнов А.М. - Smirnov A.M. - 21MAR2020 - 77RS0027-01-2020-004937-38 
  • Бобин А.С. - Bobin A.S. - 20MAR2020 - 77RS0027-01-2020-004926-71 
  • Мерлин Э.А. - Merlin E.A. - 21MAR2020 - 77RS0027-01-2020-004925-74 
  • Белай В.В.  - Belay V.V.  - 21MAR2020 - 77RS0027-01-2020-004945-14 
  • Васильев Р.Р.  - Vasiliev R.R. - 21MAR2020 - 77RS0027-01-2020-004943-20
  • Юшковский А.А. - Yushkovsky A.A. - 20MAR2020 - 77RS0027-01-2020-004897-61

Now my challenge, gentle reader, what were the hacker names of these individuals, and what shops did they run?  Please comment below or message me if you have more details!

Updates As We Find Them



Строганов is Alexey Stroganov aka Flint24 according to this post by Brian Krebs - Russians Shut Down Huge Card Fraud Ring

Селиванов is Gerasim Silivanon aka Gabrik according to the same post.

Some of the sites known to be offline now are MrWhite[.]biz, BingoDumps, DumpsKingdom, GoldenDumps, HoneyMoney, and HustleBank. 

Krebs also had the link to the FSB announcement from 24MAR2020


CyberScoop.com's piece, Rare cybercrime enforcement in Russia yields 25 arrests, shutters 'BuyBest' marketplace, mentions Flint24 as well and suggests that wuzzup[.]com, dumpsmania24[.]com were also part of the takedown. BuyBestCC and BuyBestBiz were two of the many mirror sites.

GeminiAdvisory's story "FSB Takes Down Top-Tier Marketplace, Arrests Admins" mentions that Flint24 was a character in Sergey Pavlovich's book, "How to Steal a Milion." They also list a couple additional BuyBest mirrors, BinGo and Yohoho. 

Saturday, July 16, 2016

Hacking, Carding, SWATting and OCD: The Case of Mir Islam

There can be no argument that Mir Islam is a hideous Internet Troll.  Part of a group of hackers who participated in elaborate scams that combined social engineering, hacking, and gaining credit reports under false pretenses to expose the personally identifiable information of "at least 50 celebrities" on the website "exposed.su."

On July 11, 2016, Islam was given a 2-year sentence for "SWATting and Doxing" Arizona victims.  On the Justice.gov website press release of the sentence (see: https://www.justice.gov/usao-dc/pr/new-york-man-sentenced-24-months-prison-internet-offenses-including-doxing-swatting ) it mentions that his false 9-1-1 calls to summon SWAT teams unnecessarily involved cases against at least 20 celebrities and state and federal officials, including an Assistant United States Attorney and a Congressman from Michigan.

The world's top cybersecurity journalist, Brian Krebs, was among the victims of Islam's group after revealing on his blog the methods used by the group to dox celebrities including Arnold Schwartzenegger, Ashton Kutcher, and Jay Z, and government officials including FBI Directory Robert Mueller, CIA Director John Brennan, and First Lady Michelle Obama.  Krebs revealed the methods at KrebsOnSecurity in 2013 -- Credit Reports Sold for Cheap in the Underweb.

JoshTheGod's prior Experience as a Credit Card Thief

Like so many other young cyber criminals,  Mir Islam had been active in the carding scene, stealing and selling credit card information, and after his arrest tried to work a deal to be an informant. And like Albert Gonzalez, Max Vision, and so many other cybercriminals, was a disaster as an informant.  Under the Alias of JoshTheGod, "Josh" had been previously arrested, tried, convicted, and sentenced for Attempted Access Device Fraud, Conspiracy to Commit Access Device Fraud, Aggravated Identity Theft, and Conspiracy to Commit Computer Intrusion.   He was a member of a group called "UGNazi" and admitted to being a co-founder of the credit card trading website "Carders.org."

He was arrested as part of  a massive action announced on June 26, 2012, that also included 404myth (Christian Cangeopol of Georgia), Cubby (Mark Caparelli of San Diego, CA), Kabraxis314 (Sean Harper of Albuquerque, New Mexico), kool+kake (Alex Hatala of Jacksonville, Florida), OxideDox (Joshua Hicks of Bronx, NY), xVisceral (Michael Hogue of Tucson, AZ), IwearaMAGNUM (Peter Ketchum of Pittsfield, MA), theboner1 (Steven Hansen of Wisconsin) (and two minors). The case also involved 13 other arrests overseas.

FBI Press Release (Click to open)

 What were those charges based on?   Here's some from the charging document, filed May 28, 2013:

"From at least in or about 2009, through at least in or about June 2012, [the defendant and others] did willfully and knowingly did combine, conspire, confederate, and agree together and with each other to commit offenses under Title 18, United States Code Section 1029(a) to . . . "
  • (in 2010) Purchase at least 20 computer servers over the Internet using stolen credit card information belonging to other individuals
  • (in 2011) establish an Internet forum for other co-conspirators to buy, sell, and exchange stolen credit card information
  • (in Feb 2012) possess stolen credit card information belonging to OVER 50,000 OTHER INDIVIDUALS
  • use stolen bank account numbers to fraudulently make purchases
  • launch coordinated attacks on computer systems for the purpose of disabling those systems including (Jan 2012 - DDOS attacks against the Ultimate Fighting Championship; DDOS attacks against Coach, Inc; June 2012 - DDOS attacks against the Wounded Warrior Project

The FBI Press Release also projected what charges Mr. Islam may be facing:







10 years for Access Device Fraud and 15 years for Affecting Transactions with unauthorized devices.


Aggravated Identity Theft

Under the law, identity theft is considered a FELONY if the perpetrator is found to have been involved in "the production or transfer of MORE THAN FIVE identification documents."

Quick math check.  50,000 credit cards > 5.  Ok, we're good.

Despite the fact that the criminal code, 18 U.S. Code § 1028A -- Aggravated Identity Theft, was SPECIFICALLY CREATED via the "Identity Theft Penalty Enhancement Act of 2004" to give a MANDATORY SENTENCE of 2 years imprisonment in addition to any other sentence received, Mir Islam was convicted of Aggravated Identity Theft and sentenced to ONE DAY imprisonment and three years supervised release.  Wait!?!?!  How did we get from "probably 10-15 years" to ONE DAY?

Did I mention that the two year sentence is MANDATORY?  Let's make that even more clear:
(b) CONSECUTIVE SENTENCE -- Notwithstanding any other provision of law -- 
(1) a court SHALL NOT PLACE ON PROBATION any person convicted of a violation of this section.
(2) except as provided in paragraph (4), no term of imprisonment imposed on a person under this section shall run concurrently with any other term of imprisonment imposed on the person under any other provision of law, including any term of imprisonment imposed for the felony during with the means of identification was transferred, possessed, or used; 
(3) in determining any term of imprisonment to be imposed for the felony during which the means of identification was transferred, possessed, or used, a court shall not in any way reduce the term to be imposed for such crime so as to compensate for, or otherwise take into account, any separate term of imprisonment imposed or to be imposed for a violation of this section;
Gee!  It almost sounds like a person who commits Aggravated Identity Theft is not supposed to get Probation or a Reduced Sentence!   In fact, in 2015, the Congressional Research Service was specifically asked to examine this statute.  Their conclusion was that "More than half of the judges responding to the United States Sentencing Commission sruvey felt that the two-year mandatory minimum penalty was generally appropriate."  While they fell short of wildly praising the statute, they summarized their report as being "mildly complimentary of the provision." (see "Mandatory Minimum Sentencing: Federal Aggravated Identity Theft")

Unfortunately, in order for the Mandatory term to be considered in effect, the corresponding Felony has to receive a sentence of "greater than one year" (which is why we see so many sentences of "a year and a day".)  As part of a plea agreement, he agreed to the dramatically reduced sentence of ONE DAY for the carding charges, in exchange for cooperating in good faith with the Southern District of New York's office to cooperate to try to identify further co-conspirators in his case.  Because it was the desire of law enforcement to use Mr. Islam as a source, he was given a sentence of ONE DAY for the carding charges, meaning that the intention of the legislators was entirely thwarted.  Rather than cooperating, the Prosecution's sentencing memo indicates that Islam was "toying with his FBI handlers, and continued his criminal activity in the Exposed conspiracy and his cyber-stalking." 

One of the conditions of his supervised release was set as "No Use of Computer or Internet Access without the Permission of the Parole Officer," which condition Mir Islam agreed to and swore to obey before a judge on June 26, 2012.   

JoshTheGod Re-Offends

On June 10, 2013, US District Judge approved that the defendant's bail be modified to include mandatory mental health treatment, and that the defendant BE ALLOWED TO PROCESS CREDIT CARD TRANSACTIONS AT HIS PLACE OF EMPLOYMENT and be allowed to possess a computer and access the Internet under the supervision of a case agent. (See PACER -- Case 1:12-cr-00810-KMW Document 26)

Great idea. Let's give a convicted credit card criminal permission to process credit cards at work.  After all, it's been more than a year since he was arrested for STEALING FIFTY THOUSAND CREDIT CARDS and running a forum for selling them on the Internet.

He didn't quite make it 90 days.  He was re-arrested on September 4, 2013. 

His new case, (1:15-cr-00067-RDM) opens up with charges of Violations of 18 USC Section 371 (Conspiracy) 18 USC Section 844(e) (Threatening and Conveying False Information Concerning Use of Explosive), and 18 USC Section 2261A(2) (Stalking).

The Conspiracy charges include that he was still doing identity theft  and wire fraud (18 USC Sections 1343, 1030(a)(2), 1028(a)(7), 1028(b)(2)(B), and that once again it was "Aggravated Identity Theft" level -- "15 or more devices which are unauthorized access devices, to wit, social security numbers" -- 1029(a)(3) and 1029(c)(1)(A)(i). And that he used those SSNs to obtain a thing of value - 42USC Section 408(a)(7)(B), and that he accessed a computer without authorization (18 USC 1030(a)(2)(A) and 1030(c)(2)(A), and that he "devised a scheme to defraud and obtain property by means of materially false and fraudulent pretenses" (18 USC Section 1343) and that he used a "deadly or dangerous weapon to assault, impede, intimidate or interfere with an officer of empoyee of hte US Government" -- 18 USC Section 111(a), 111(b), and thta he transmitted a threat to injure the person of another via interstate commerce -- 18 USC Section 875c.

Some of the particulars from this second round of charges include:
  • March 2013 - purchasing stolen credit reports for US and State government officials and public celebrities from Exposed.su
  • March 22, 2013 - began stalking "A.R.T" (the Arizona cheerleader) via email, Facebook, Instagram, Text message, and telephone calls, and making false Twitter accounts in A.R.T's name.
  • March 23, 2013 - called in bomb threats to University of Arizona
  • March 31, 2013 - "Swatting" a US Government employee in Massachusetts
  • April 2013 - buying more credit reports for US and State government officials and public celebrities from "exposed.re"
  • April 19, 2013 - "Swatting" T.L. a state government official in California
  • April 27, 2013 - "Swatting" M.R. (that would be Mike Rogers, Congressman of Michigan)
  • July 22, 2013, bought more credit reports from "exposed.ws" 
  • August 12, 2013 - uploaded many sets of "Dox" to "exposed.ws" on a server in Washington DC

Mental Illness and Reducing Sentence

This week the sentence finally came down on Mir Islam.  He was sentenced to 24 months in prison to be followed by 36 months of supervised release, during which he will be required to participate in Education/Vocational training approved by Probations, participate in a Mental Health Treatment program, and consent to disclosing a list of all computer systems and internet capable devices and allowing them to be forensically searched or to have computer/internet monitoring program installed.

Why?   Partly because of an amazing 82 page "Defendant's Memorandum in Aid of Sentencing" that begins with:

Mr. Islam has matured immensely during his 34 months of incarceration and has taken great strides to atone for his behavior and overcome the mental health issues that contributed to it.  Accordingly, it is respectfully submitted that a sentence of time served and 36 months of supervised release would represent a sentence that is sufficient, but not greater than necessary to meet the purposes of sentencing reflected in 18 USC Section § 3353(a).  Such as sentence would be longer than many if not most sentences in similar cases, and would adequately punish conduct by an immature and mentally-ill teenager who, by the government's own admission, has earned a departure from the applicable guidelines range.
The memo then goes on to talk about his "Good Time Served" (meaning he was a model prisoner, which is not unexpected, given lack of access to a computer or telephone).  He then argues that the "doxing" was not really so bad, since "The Secret Files" were only accessible during three short periods, for 8 days, 20 days, and 20 days.

(Click to visit KrebsOnSecurity, source of this image)
He also claims that "Doxing" is not illegal (citing this The Daily Beast article, where all good legal theories should come from) and that we should consider the "veneer of legality, especially as perceived by the immature minds of the teenage co-conspirators."  He goes on to say that we should consider the "misguided but public-minded spirit and desire for attention not uncommon among teenagers."  Would that be the "public-minded spirit" that caused so many SWAT teams to waste their time and place innocent people in danger?   Just in the University of Arizona case, testimony was given that FIFTY-FOUR OFFICERS were involved in searching for the non-existent bomb while classes were canceled and students, staff and faculty faced the fear (and inconvenience) of potential death during the ensuing lockdown.

While the defense admits that swatting was "extremely traumatic and dangerous" he claims that "in the online gaming communities in which Islam practically lived and breathed, swatting was an unfortunately common tactic used by competitive gamers to harass their opponents."  Because of this we are to understand that this would have been considered "normal" behavior by "teenagers immersed in this new online world."

In the case of the swatting of an Assistant US Attorney, the government provides a transcript of the 9-1-1 call:
"Hello my wife is dead.  I shot her and now she's dead.  I don't know what to do.
I'm having thoughts of hurting people and I don't know what to do.  If anyone comes in my house I might shoot them.  I am just letting you know now if I see any police outside my house I will start shooting.  I will not be taken alive.  Mark my words. I am not going to prison for the rest of my life.  I will not.  Don't worry about where I am at in the house. If any cops are outside in my yard or on the street I will start shooting.  By the way I have a police scanner right next to me and I can hear everything and you guys  think I'm joking.  I will shoot anyone who comes near my property.  I see cars outside my house I swear I will shoot.  I am not playing.  I am not fucking around. I will shot them.  You know I work with the police a lot but I am not afraid to shoot them."
Youthful prank, right?

The defense then moves on to address the cyberstalking of A.R.T., which he admits "subjected her to emotional distress, anxiety, and fear for her safety" and was "extremely serious."  HOWEVER, he goes on, "Islam was suffering from untreated obsessive-compulsive disorder (OCD) which fueled his obsession for A.R.T. and drove him to try to contact her through any and all means."  Islam "believed at the time that he had communicated and developed a relationship with A.R.T. through weeks of online conversations, causing him extreme confusion and anxiety with her refusal to interact with him in the non-virtual world."

The document then goes on to explain Islam's life, immigrating at age six from Bangladesh to Bronx, New York. They say he had untreated bipolar disorder, chronic depression, OCD, and ADHD, which led to him dropping out of high school to spend 15-18 hours per day online without interruption or parental intervention.  They then go on to explain his "carding" as a "seductive playground that allowed them to purchase food and electronics with stolen credit card numbers" and that Islam viewed these activities as "adolescent pranks."

Next we turn to his prison hardships, including the fact that he was denied a lower bunk even though he was a restless sleeper (which the defense says led to a herniated disc, nerve damage, and chronic pain after falling from a top bunk.)  He also claims he was given "vitamins contaminated by mold" that damaged his cartilage in his wrists and knees, discolored his skin, and exacerbated his chronic pain.  That is some mighty powerful Vitamin Mold!  Islam also filed charges against the prison for denying him Kosher food.  (These examples are to use the sentencing reduction of "Harsh conditions of confinement."  Not sure if "denied lower bunk" and "given moldy vitamins" are what that the term "Harsh conditions" normally means.)

CyberCrime: The World Where Sentencing Guidelines Don't Matter At All

The strongest and most unforgivable argument the defense makes is that Section 3553(a) directs courts to consider the need to avoid unwarranted sentencing disparities.  In the government's sentencing memo they had made the assertion that they were "unaware of any individuals sentenced for conduct similar to Islam's."  The defense jumps on that and waves it in their faces!  The defense  argues that because Hector "Sabu" Monsegur of Lulzsec got RIDICULOUS [my term] sentencing departures (a 97% reduction in the minimum sentencing) and that Sabu and JoshTheGod were both people who violated their release conditions and were remanded back into custody for very similar crimes, the Federal Government themselves had basically established precedence that hacker sentencing guidelines are worthless and not to be taken at face value.


The defense also argues "The need to avoid unwarranted sectencing disparities" with regard to other swatting cases.  They cite Tollis (1 year and 1 day for numerous swattings of schools and universities) and James Eli Shiffer (15 months for multiple doxing, swatting, and cyberstalking incidents.)  That argument is strengthened even more by the government's failure to observer proper sentencing for many of those arrested at the same time as Islam.  The defense gives examples  including Christian Cangeopol (3 years probation), Harper (time served), Joshua Hicks (2 years probation), Michael Hogue (5 years probation) and Peter Ketchum (2 years probation).  The LulzSec slap-on-the-wrist cases were also used in the Defense's argument - Cody Krestsinger (1 year imprisonment, 1 year home detention), Raynoldo Rivera (1 year and 1 day, 13 months home detention), Matthew Flannery (15 months home detention) and Hector Xavier Monsegur, already mentioned, (7 months.)

 Part of the Defendant's package was a letter to the judge praising Mir Islam for being a successful graduate of The Focus Forward class, where he studied the book A Long Way Gone and learned public speaking, conflict resolution, and resume writing skills.  He brought "light-hearted humor and laughter to class discussions" and "displayed humility, opening up to the group about the frustration and disappointment he felt about finding himself in this situation."  

Would that be the same "light-hearted humor" that he used when telling University of Arizona police that he was holding a rifle to the head of a woman that he was planning to kill if he did not receive $50,000 in ransom, and that he had placed explosives in eight campus buildings and was going to blow them up and start shooting?

Mir himself wrote a letter to the judge about how he wants to make a project "similar to PayPal" to help the members of my society stop getting ripped off.  Excuse me.  You can read his letter while I go get a tissue:


Chance of Re-offending?

Really?   This letter comes from the kid who arranged a ONE DAY sentence for all of his credit card crimes in exchange for giving his "Full Cooperation" to the SDNY FBI Office. Despite the prosecution's Sentencing Memo pointing out that "Based on Islam's duplicity in his SNY case, any expression of remorse or contrition by Islam should be viewed with a great deal of skepticism" the judge chose to ignore this and issue Yet Another Slap On The Wrist.

 Anyone taking bets on how many months it takes for Mir Islam to re-offend when he is released?  Put me down for "thirty-days or less."


Thursday, April 10, 2014

The Carder.su indictment: United States v. Kilobit et. al.

Today the U.S. government unsealed its indictment against Fifty-Five members of the Carder.su carding forum. We wrote about Carder.su before on this blog, back in March 2009 when a rival gang was trying to call attention to Carder.su by sending out spam advertising the site. (See: Carders do battle through spam - carder.su. No wonder they were jealous! Today's indictment shows the Carder.su guys performed over $50 Million in fraudulent charges!

Named in the indictment were 39 individuals, all charged with "General Allegations" called:

Count One (Participate in a Racketeer Influenced Corrupt Organization [RICO])
and
Count Two (Conspiracy to Engage in a Racketeer Influenced Corrupt Organization).

The whole group are described in the indictment like this:

"The defendants herein, and others known and unknown, are members of, employed by, and associates of a criminal organization, hereafter referred to as "the Carder.su organization," whose members engage in acts of identity theft and financial fraud, including, but not limited to, acts involving trafficking in stolen means of identification; trafficking in, production and use of couterfeit identification documents; identity theft; trafficking in, production and use of unauthorized and counterfeit access devices; and bank fraud; and whose members interfere with interstate and foreign commerce through acts of identity theft and financial fraud. Members and associates of the Carder.su organization operate principally in Las Vegas, Nevada, and elsewhere.

Here's the list:

NAMEAKA ListCounts Charged
Roman ZolotarevAdmin, Support1-2, 19
Konstantin LopatinGraf1-2, 33, 44, 47
Alexander Kostyukov *Temp, KLBS1-2, 3-17
Maceo Boozer IIIXXXSimone, G4, El Padrino, Mr. Right, MRDC871-2, 3-17
Tin-Yueng WongRay Wong, Ray1-2, 3-17
Edward Montecalvo *N1ghtmare, Tenure441-2, 3-17, 22-55
Yu Feng Wang Ibatistuta1-2
Mohamed Amr Mahmoud Amr Mahmoud, CC--Trader, Kengza1-2, 20, 22-55
Jermaine Smith SirCharlie57, FairBusinessman 1-2, 61-62
Makyl Haggerty Wave 1-2
Aladelola Teslim Ajayi Bank Manager, Document Manager, Corey 1-2, 61-62
Alexandru Ion AbagnaleFrank 1-2
Jordan Georgievski Devica 1-2
Roman Seleznev Track2, Bulba, NCUX 1-2, 22-55
Qasir Mukhtar Caliber 1-2, 56-60
Roy Ayad Rabie Ayad, Patistota 1-2, 22-55
Mina MorrisSource 1-2, 22-55
Rachid Idaali C4rd3r 1-2, 22-55
Liridon Musliu Bowl 1-2, 22-55
Sergei Litvinenko Dorbik, Matad0r 2
Michael Lofton Killit, Lofeazy 1-2, 3-17
Shiyang GouCDER 1-2, 3-17
David Ray CamezBadman, DoctorSex 1-2, 3-17
Cameron Harrison Kilobit1-2, 3-17
Aleksandar BesarovicQiller 1-2, 3-17
Duvaughn Butler Mackmann 1-2, 21, 61-62
Fredrick Thomas 1Stunna 1-2
John Doe 1 Senna0711-2, 3-17
John Doe 2 Morfiy 1-2, 3-17
John Doe 3 Gruber 1-2, 18
John Doe 4 Maxxtro 1-2
John Doe 5 Elit3 1-2
John Doe 6 Fozzy 1-2, 22-55
John Doe 7 Vitrum, Lermentov 1-2, 22-55
Andrei BolovanPanther, Euphoric, Darkmth 1-2, 22-55
John Doe 8 TM 1-2, 22-55
John Doe 9 Zo0mer, Deputat 1-2, 22-55
John Doe 10 Centurion 1-2, 22-55
John Doe 11 Consigliori 1-2, 61-62
While it is true that many carders are Russian, several folks on this list reside in the United States. This case, which DHS ICE calls "Operation: Open Market", has already seen 19 arrested in the United States, primarily in Las Vegas, where LOFTON, CAMEZ, BUTLER, LAMB, and VERGNETTI were arrested. (Some of those arrested are indicted separately and do not appear above.

KOSTYUKOV was arrested in Miami from his home at 1100 Washington Avenue, Miami Beach. (He sent a letter to the judge asking for his property back, including his Hookah pipe and his Dr. Dre Beats headphones.

KOSTYUKOV, 27, was arrested in Miami, Florida.
Boozer, 23, was arrested in Detroit, Michigan.
Montecalvo, 20, was arrested in Morgantown, WV.
Jermaine Smith, 31, was arrested in Newark, NJ
Makyl Haggerty, 22, lived in San Francisco,
Qasir Mukhtar, 27, in New York
Shiyang Gou, 27, in New York
Cameron Harrison, 25, in Augusta, GA
Fredrick Thomas, 31, in Orlando, FL
Omar Butt, 28, in New York
Bill Steffey, 33, in Sacramento,
Jason Maclaskey, 32, (at large?)
Derek Carder, 38, Sacramento
Robert Kephart, 38, Sacramento
Heather Dale, 21, Springfield, Orlando
Herbert Morrell, 50, Orlando
Roger Grodesky, 49, Warren, Ohio
John Holsheimer, 53, San Diego

David Ray Camez, a Nevada resident, for example, was convicted and was due to be sentenced today. (You may enjoy reading his Forfeiture document which includes ATM machines, PVC Card Embossers, dozens of phones and computers as well as printers, cameras, and video games. Camez was already serving a seven year sentence in the State of Arizona for fraud charges he was convicted of there.

Back in 2012, ICE agents announced that they had arrested 19 in the US in an operation called "Operation: Open Market."


The full Fifty-one page indictment, originally introduced in court on January 10, 2012, and finally unsealed April 10, 2014, goes on to describe additional charges and activities, sometimes in great detail. The case against "Defendant 24, Cameron Harrison, AKA Kilobit" is being tried in Las Vegas, Nevada as CASE #: 2:12-cr-00004-APG-GWF-24.

The event that triggered the unsealing of the indictment was that Cameron Harrison pleaded guilty, WITHOUT BENEFIT OF A PLEA AGREEMENT! His nineteen page guilty plea. In addition to Count One and Count Two above, Cameron plead guilty to:

Count Sixteen: Trafficking in and Production of False Identification Documents and Aiding and Abetting, in violation of 18 U.S.C. § 1028(a)(1), (b)(1)(A)(ii), and (c)(3) and 18 U.S.C. § 2.

The Sentencing Guidelines that the prosecution is asking for are HUGE because they are describing the "Total amount of actual loss involved in the offense as $50,893,166.35" which gives a +24 to the Sentencing guidelines just for the financial losses!

Base Offense Level = 7
+ 24 (offense involved more than $50 Million of actual loss)
+6 (offense involved more than 250 victims)
+2 (offense involved receiving stolen property and the defendant was a person in the business of receiving and selling stolen property)
+2 (fraud committed from outside the US, involving a sophisticated means)
+2 (fraud involving possession of device-making equipment and trafficking in unauthorized and counterfeit access devices)
-3 (Acceptance of Responsibility)

Total Offense Level = 40

Restitutions that are declared in the Plea include:

American Express = $3,299,210.90

Discover Financial Services = $2,202,429.00

Master Card = $15,496,221.00

Visa Inc. = $29,895,305.45

Total = $50,895,305.45

Because this is a RICO case, EACH member of the Conspiracy can be found responsible for the full restitution. The Indictment requests that each have $20 million of their assets seized to help cover the costs. (Most have nowhere near that amount, of course...).

Roles of the Defendants

Despite the news headlines being about Kilobit (Cameron Harrison) today, Harrison was only a "Member" of the board. Far more important members are listed below by their roles on the various Carder.su websites.

Administrator = "Roman ZOLOTAREV was the head of Carder.su.

As the head of the governing council, the administrator handles day to day management decisions of the organizatoin, as well as long-term strategic planning for its continued viability. Zolotarev was the leader of the enterprise, appointing moderators, and directing other members and associates of the enterprise in carrying out unlawful and other activities in futherance of the conduct of the enterprise's affiars. In addition, ZOLOTAREV:

  • determines which individuals can become and remain members of the Carder.su organization.
  • regulates the functions, responsibilities, and levels of access to information accorded to each member.
  • bestows the rewards accorded members for their loyalty to the Carder.su organization, and sets the punishments to be meted out to members evidencing disloyalty to the organization.
  • decides when, how, and under what circumstances to attack and to retaliate against members of rival criminal organizations and their associated Internet website forums.
  • has full access to, and privileges on, the computer servers hosting the Carder.su organization's websites.
  • has ultimate responsibility for the administration, maintenance, anonymity and security of ther Carder.su organization's computer servers
Moderators = Konstantin LOPATIN and MAXXTRO

These defendants act as leaders of the enterprise, directing other members and associates in carrying out unlawful and other activities in furtherance of the conduct of the enterprise's affairs. Moderators are members of the Carder.su organization's governing counsel. They oversee and manage one or more subject matter specific areas on the Carder.su organization's websites. Their jobs included assisting Zolotarev by:

  • monitoring and policing websites by editing and deleting members' posts and mediating disputes among members.
  • serve as Reviewers for products or services through the enterprise with which they have expertise.
  • Both LOPATIN and MAXXTRO possessed at least 15 counterfeit or unauthorized access devices.
Reviewers

Members are allowed to sell contraband, including counterfeit documents, stolen bank accounts, and credit card information. Reviewers examine and test products and services that members wish to advertise and sell on the websites. A favorable review is a prerequisite to to selling contraband. Any member can be appointed to do a review, although they are usually done by Moderators or the Administrator.

Vendors

Vendors advertise and sell products, services, and other contraband after receiving a favorable review.

Vendors among the defendants included:

Alexander KOSTYUKOV (Temp/Klbs) - a vendor of Cashout services. Cashout vendors remove funds from bank and credit card accounts and receive a fee between 45% and 62% of the funds received.

Maceo BOOZER (XXXSimone / G4 / El Padrino / Mr. Right / mrdc87) is a vendor of dumps. "Dumps" are stolen credit and debit card account data. They sold for between $15 and $150 per card, depending on the quantity purchased and the geographic location. United States cards are least expensive, and European cards are most expensive.

Ray WONG is a vendor of counterfeit plastic. A device-making implement used to produce counterfeit credit cards. WONG sold blank counterfeit plastic cards for $20 to $25 each, with a minimum order of 50 cards. Embossed counterfeit cards were $65 to $75 each with a minimum order of ten. Wong was also a vendor of dumps.

MONTECALVO (N1ghtmare / Tenure44) is a vendor or dumps, but also offered a dump checking service. He had the ability to validate a card against a real financial institution.

Yu Feng WANG (Ibatistuta) is a vendor of counterfeit cards, counterfeit holograms, and signature panels used to manufacture counterfeit credit cards. He sold blanks for $10-$15 each.

Mohamed Amr Mahmoud (AMR Mahmoud / CC--Trader / Kengza) is a vendor of CVV. While dumps are magnetic card stripe reads, CVVs are all of the account holder information - such as Name, DOB, SSN, address, telephone number, mother's maiden name, and the CVV2 code from the back of the card. MAHMOUD also sold Paypal accounts, Fullz (all of the above plus expiration date and PIN), and Enroll/COBs. The latter included all of the previous data, as well as username and password for the account's online access. Depending on the online balance, he would charge $140 to $200 per account.

Jermaine SMITH (Sircharlie57 / Fairbusinessman) is a vendor of plastic and counterfeit cards.

Makyl HAGGERTY (Wave) is a vendor of counterfeit identification documents and counterfeit cards. He sold counterfeit drivers license for between $100 and $200 each, depending on state, including CA, TX, WI, OH, RI, NV, PA, IL, FL, LA, AZ, HA, SC, GA, NJ, as well as BC Canada. He also sold blank counterfeit plastics and embossed cards.

Aladelola Teslim AJAYI is a vendor of counterfeit identification documents, stolen corporate account information, dumps, and counterfeit credit cards.

ALEXANDRUION (Abagnalefrank) is a vendor of dumps. He sells 100 mixed Visa and Master Card accounts for $1,500 or 100 AmEx cards for $1,000.

Jordan GEORGIEVSKI is a vendor of counterfeit credit cards and blank plastic, as well as embossed cards for $75 each.

Roman SELEZNEV (Track2 / Bulba / Neux ) is a vendor of dumps. He sold very large volume product through an automated website where members could load their desired cards into a shopping cart. Accounts sold for $20 each.

Qasir MUKHTAR (Caliber) is a vendor of counterfeit plastics, holograms, and signature panels.

Roy AYAD (Rabie Ayad / Patistota) is a vendor of CVVs, selling through an automated website.

Mina MORRIS (Source) is a vendor of dumps. Morris had an automated website to sell dumps.

Rachid IDAALI (C4rd3r) is a vendor of Fullz.

Liridon MUSLIU (Bowl) is a vendor of CVVs.

Sergei Litvinenko (Dorbik / Matad0r ) is a vendor of Bullet Proof Hosting services and infrastructure for criminal websites. These are ISPs that allow criminals to run illegal websites used for phishing, carding forums, or dump sites.

GRUBER is a vendor of counterfeit identification documents including drivers licenses ranging from $150 to $200 each.

ELIT3 is a vendor of Fullz. He also sells Enroll/COBs.

FOZZY is a vendor of dumps ranging from $12 to $100 each, depending on quantity and location.

VITRUM (Lermentov) is a vendor of dumps.

Andrei BOLOVAN (Panther / Euphoric / Darkmth) is a vendor of dumps.

TM is a vendor of dumps and CVVs, which he sells to members through an automated website.

Zo0mer (Deputat) is a vendor of stolen PayPal accounts, Proxies, Fullz, Credit Card Checking and Information Lookups.

CENTURION is a vendor of dumps.

CONSIGLIORI is a vendor of dumps and blank plastic.

Members

Members must successfully complete a number of security features intended to keep out law enforcement and rival criminal organizations. Teams use a number of Carder.su websites as "virtual clubhouses" to gather with other members in order to share information, solicit and recruit other members and to achieve the common objectives of the enterprise.

Members charged in this conspiracy include:

Michael LOFTON (Killit / Lofeazy

Shiyang GOU (Cder)

David Ray CAMEZ (Bad Man / DoctorSex )

Cameron HARRISON (Kilobit)

Alexsandar BESAROVIC (Qiller)

Duvaughn BUTLER (Mackmann)

Fredrick THOMAS (1STunna )

SENNa071

MORFIY


The Charges

Count One and Two given above deal with Racketeering:

COUNT ONE:

Acts 1 through 15 - Unlawful Trafficking In and Production of False Identification Documents

Acts 16, 17, 19 - Attempt to Unlawfully Produce False Identification Documents

Acts 18, 20, 21 - Conspiracy to Unlawfully Produce False Identification Documents

Act 22 - Conspiracy to Unlawfully Transfer False Identification Documents

Act 23 - Possession of Document-Making Implements

Act 24 - Conspiracy to Unlawfully Transfer, Possess, and Use a Means of Identification

RACKETEERING ACTS 25 through 36

Acts of Wirefraud by MAXXTRO, MAHMOUD, HARRISON, ELIT3, LOFTON, THOMAS, MAHMOUD, ION, AYAD

RACKETEERING ACTS INVOLVING COUNTERFEIT AND UNAUTHORIZED ACCESS DEVICES

Act 37 - Using and Trafficking in Unauthorized Access Devices

Acts 38 through 97 - Possession of 15 or more Unauthorized Access Devices

Acts 98 through 103 - Trafficking In and Possessing Access Device-Making Equipment

Acts 104 through 109 - Conspiracy to Trafficking In and Possess Access Device-Making Equipment

COUNT TWO

Dealing with General Allegations from November 22, 2005 through June 2011. Counts Three Through Seventeen - Trafficking in and Production of False Identification Documents

Count Eighteen - Attempting to Unlawfully Produce False Identification Documents, Aiding and Abetting

Count Nineteen - Conspiracy to Unlawfully Transfer False Identification Documents

Count Twenty - Unlawful Transfer, Possession and Use of a Means of Identification, Aiding and Abetting

Count Twenty-One - Trafficking in and Use of Counterfeit and Unauthorized Access Devices, Aiding and Abetting

Counts Twenty-Two through Fifty-Five - Possession of Fifteen or More Counterfeit and Unauthorized Access Devices, Aiding and Abetting

Counts Fifty-Six through Sixty - Trafficking In and Possessing Access Device-Making Equipment; Aiding and Abetting

Counts Sixty-One and Sixty-Two - Conspiracy to Traffick In and Possess Access Device-Making Equipment


Monday, January 27, 2014

Roman Vega (CarderPlanet's Boa) Gets His Sentence!

For some time now I have been following with anticipation the case of Roman Vega, the hacker who went by the pseudonym BOA and ran the notorious BOAFactory website prior to helping spear-head the creation of Carder Planet, a specialty site created by and for credit card thieves that at its peak was servicing more than 6,000 members who brokered, bartered and sold their stolen cards.

In December 2013 it appeared that Vega, who had been in custody since 2003, was finally about to be sentenced. Vega was originally arrested while traveling in Cyprus and is said to have had in possession at the time of his arrest information on more than 500,000 credit card accounts. The New York court sentenced him December 18, 2013, but then it was time to find out what would happen in California.

On January 22, 2014, the Honorable Charles R. Breyer, Senior United States District Judge accepted Vega's plea bargain and in exchange for pleading guilty to 18 USC 1343 and 2, "Wire Fraud, Aiding and Abetting" (Counts 1-20), Counts 21-40 of his original charges were dismissed.

Boa was sentenced (by this Judgement Against Roman Vega document) to serve forty-six (46) months on counts one through twenty, all counts to be served concurrently, and also to be served concurrently with Docket #07-CR-707 (ARR) from the Eastern District of New York.

Vega will also have to pay restitution as follows:

  • Bank of America - $23,371.86
  • Bank of Cyprus - $92.63
  • Canadian Imperial Bank of Commerce - $681.56
  • Capital One - $15,039.56
  • Chase Bank - $16,223.74
  • Citibank - $29,284.42
  • Fla Card Services - $7,695.04
  • JP Morgan Chase - $1,849.27
  • Merrill Lynch Fraud Control - $6,118.54
  • National City Card Services - $614.84
  • PNC Bank - $3,144.92
  • Royal Bank of Canada - $488.49
  • USAA Federal Savings Bank - $89,294.75
  • Wachovia Bank - $13,303.35
  • Washington Mutual Bank - $12,525.60
With some fees, he is ordered to make a lump sum payment of $221,728.57 (including all the above) to the court.

The early court documents in the Boa case, including this Roman Vega Criminal Complaint from 2007 (25 page PDF) make fascinating reading, walking through how a dispute on the ShadowCrew Carding Site between Boa and others on the site that lead Boa to spawn his own website, www.boafactory.to. Boa worked closely with other famous carders, including Gollum and Script.

Roman Vega (Boa) was arrested February 26, 2003 in Nicosia, Cyprus. his laptop was imaged and shared with the US Secret Service and the US Postal Inspection Service, which revealed hundreds of email messages and thousands of pages of ICQ chats. The laptop also had 500,000 credit cards issued by 7,000 different financial institutions! Vega was flown from Cyprus to Minneapolis, Minnesota on June 3, 2004. He plead guilty in November 2006 to twenty counts of wire fraud in the Northern District of California. One of the especially interesting chats was between ICQ 107711 (Vega) and ICQ 100630 (Script) where Vega claims his "boys" have cracked a database containing 2 million credit card accounts in the United States. Script and RyDen said that was too large a volume for them to handle. Later Script sent an article about the hack to Vega about a breach against Data Processors International (DPI).

Although the court documents do not specify which article it was, it may have been this CNN article Hacker hits up to 8M credit cards. Vega confesses to Script that the article is wrong - they actually got 14 million cards, including 450,000 just from Capital One!

Boa was arrested after a large number of cards from the breach were found to be used at a particular POS terminal in Cyprus.

Now, if you'll forgive me, we'll go back to the New York case. Things did not go well for BOA in New York. He insisted on dismissing his counsel, who he did not trust, and defending himself, which did not go well. Vega had a limited command of English and his defense seemed to be a mix of magazine articles, things other prisoners told him and watching too much television. Here's one example transcript from a hearing where he is trying to say that he wants access to thirty boxes worth of notes and files, including everything the government found on his hard drive.

According to the sentencing memorandum from the US, Script was Dimitry Golubov, the Godfather of CarderPlanet. But Boa played a key role in making CarderPlanet the "go to place" for cards. It was Boa who instituted the "Card Review" process by which vendors had to ensure that their cards were original and had not been previously sold. The vendor ranking system, copied to so many other boards today, originated on CarderPlanet, and it was Boa's key contribution to the new system.

More than half of the sentencing memo from the US lists the many ways in which Vega misbehaved and violated his agreements to cooperate with the US in exchange for leniency. These include:

  • having a letter sent from Italy to the private unlisted address of a government analyst that insulted Vega by saying he no longer had contact or influence in the criminal world.
  • sending money to his girlfriend and then "not being able to recall" anything about that when asked repeatedly by the government.
  • consulting on Misha Glenny's book "Dark Market: Cyberthieves, CyberCops and You".
  • withdrawing his guilty plea
  • having a powerful cell phone antenna in his cell. Although no phone was ever found, Vega was somehow
  • able to maintain several blogs about his life in prison, despite theoretically having no access to computers or phones.
Some of CarderPlanet's top customers were Cumbajonny AKA Albert Gonzalez, now serving twenty years. Maksim Yastremskiey (Maksik) sentenced to 30 years for hacking by the Turkish police. Cesar Carranza, a money launderer to the carders, now serving six years in New York for laundering $2.5 million.

Here is the sentencing "point calculator" used in the case:

Base Offense Level 2B1.1(a)(2) 6
Loss between $200 and $400 Million 2B1.1 (b)(1)(O) 28
Stolen Property Business 2B1.1(b)(4) 2
Fraud from Outside US and Sophisticated Means 2B1.1(b)(9) 2
Use of Device Making Equipment 2B1.1(1) 2
Organizer and Leader of 5 or more Participants 3B1.1(a) 4
Adjusted Offense Level for Count One 44
Base Offense Level 2S1.1(a)(1)
See also 1B1.5(b)(1)
40
Specific Offense Characteristic
USC 1956
2S1.1(b)(2)(B) 2
Organizer and Leader of 5 or more Participants 3B1.1(a) 4
Adjusted Offense Level for Count Two 46

To show consistency with the sentence, the New York Sentencing Memo (10MB PDF) also lists previously sentenced carders and hackers and their respective sentences as a means of justifying the requested sentence:

1. Albert Gonzalez - 20 years (sentenced September 11, 2009)

2. Edwin Pena - 10 years and $1M restitution (sentenced September 24, 2010)

3. Lin Mun Poo - 10 years (sentenced November 4, 2011)

4. Tony Perez - 14 years (sentenced September 9, 2011)

5. Jonathan Oliveras - 12 years (sentenced December 9, 2011)

6. Adriann-Tiberiu Oprea - 15 years (sentenced for hacking into 800 US Merchants' systems resulting in $17.5 million in unauthorized charges on more than 100,000 cards.) Oprea was known as "the Subway Hacker" for stealing card data from hundreds of Subway restaurants.

(to read about other famous hackers and their sentences, see Major Achievements in the Courtroom.)

In New York 1:07-cr-00707-ARR, Vega was sentenced to 216 months for Count One and 90 months on Count two, to run concurrently for a total of 216 months or 18 years. Since that is longer than the California sentence, he'll pay the California restitution and serve the 18 years courtesy of the Bureau of Prisons in Lompoc.

Monday, January 20, 2014

Target Breach considered in light of Drinkman / Gonzalez data breach gang

Everyone is talking about the Target data breach these days, but unfortunately our collective memory is sometimes too short to connect the dots.

Back in August of 2008 this blogger, like so many others, was focused on Albert Gonzalez after the TJX Arrests were made. Attorney General Michael Mukasey said that the message from the arrests was that if you do Data Breaches We Will Arrest You, and We Will Send You To Jail!. We followed up that post with a deeper look at two sets of indictments issued at the same time, TJX Update: The Boston Indictments and TJX Update: The San Diego Indictments. (The San Diego ones included the famous hackers Aleksander Suvorov, AKA JonnyHell from Estonia, and Maksym Yastremskiy, AKA Maksik). Maksik and JonnyHell were part of the Dave & Busters Point-of-Sale terminal hacks indicted in May 2008.( 23 page Dave & Busters Indictment against Maksik and JonnyHell)

In the Gonzalez case, it was mentioned that his gang had targeted "at least nine major retail corporations: including the TJX Corporation, whose stores include Marshalls and TJ Maxx; BJ's Wholesale Club; Barnes and Noble; Sports Authority; Boston Market; Office Max; Dave & Buster's restaurants; DSW shoe stores; and Forever 21."

But what is perhaps most important is that when it comes to gangs stealing millions of credit cards, there are no one-man operations, or even ten-man operations. These type of breaches are pulled off by crews. We learned much more about Gonzalez's crew in the recently unsealed documents from the case against Vladimir Drinkman, Aleksandr Kalinin, Roman Kotov, Mikhail Rytikov, and Dmitriy Smilianets. The order to Unseal the Drinkman et. al. case was only given on December 17, 2013. Several items on the docket remain sealed to this day, but one of special interest was the Second Superseding Indictment, which has been unsealed, although several points remain redacted.

Here's what we learn in the Drinkman indictment.

  • Drinkman resided in or near Syktyvkar and Moscow, Russia, and was "a sophisticated hacker, who specialized in penetrating and gaining access to the computer networks of multinational corporations, financial institutions, and payment processors; harvesting data, including, among other things, credit card, debit card, and other customer account information, from within the compromised networks; and exfiltrating that data out of the compromised networks.
  • Kobov resided in or near Moscow, Russia, and "specialized in harvesting data from within the computer networks that Drinkman and Kalinin had penetrated, and exfiltrating that data.
  • Co-conspirators named in the indictment include Albert Gonzalez (segvec), Damon Patrick Toey, and Vladislav Anatolievich Horohorin (BadB).
  • The hacking conspiracy is described as "a prolific hacking organization" "responsible for several of the largest known data breaches" and that it operated "from August 2005 through at least July 2012."
Data breaches that were described as being part of this case, include:

  • NASDAQ - (from at least May 2007 - SQL Injection lead to malware that extracted login credentials from databases)
  • 7-Eleven - (at least August 2007 - SQL Injection lead to malware that extracted card data from databases)
  • Carrefour S.A - (2 million credit cards - October 2007 - SQL injection lead to malware that extracted card data from databases)
  • JCPenney - (October 2007 - SQL Injection lead to malware placed on the network that extracted card data from databases)
  • Hannaford Brothers - (4.2 million credit cards - November 2007 - SQL Injection lead to malware placed on the network that extracted card data from databases)
  • Heartland Payment Systems (130 million card numbers, estimated losses of $200 Million - December 2007 - SQL Injection lead to malware placed on the network that extracted card data from databases)
  • Wet Seal - (January 2008 - SQL Injection lead to malware placed on the network that extracted card data from databases)
  • Commidea Ltd. - (30 million Credit cards - March-November 2008 - malware was used to extract card data and exfiltrate the data)
  • Dexia Bank Belgium - ($1.7 Million loss - February 2008 to February 2009 - SQL Injection resulted in malware placed on the network that exfiltrated card data)
  • JetBlue Airways - (Jan 2008 - February 2011 - malware placed on network exfiltrated Personal Data of employees)
  • Dow Jones, Inc. - (2009 - at least 10,000 sets of Log-In Credentials stolen via malware placed on network)
  • "Bank A" - (Dec 2010 to March 2011 - malware placed on an unnamed bank HQ'ed in Abu Dhabi, United Arab Emirates used to facilitated theft of Card Numbers.)
  • Euronet - (2 million cards - July 2010 to October 2011 - SQL injection lead to malware that extracted login credentials from databases.)
  • Visa Jordan Card Services - (800,000 cards - Feb 2011 to March 2011 - SQL Injection lead to malware placed on network that exfiltrated card data.)
  • Global Payment Systems - (950,000 cards - $92.7 Million in losses - January 2011 to March 2012 - SQL Injection lead to malware placed on network that exfiltrated card data.)
  • Diners Club International, Singapore - (500,000 Diners Credit cards - $312,000 in losses - June 2011 - SQL Injection lead to malware placed on network that exfiltrated card data)
  • Ingenicard US, Inc. - ($9 million in 24 hours - March 2012 to December 2012 - SQL Injection resulted in malware placed on the network that was used to facilitate ATM withdrawals.)
Although it is true that several of the members named above are now in custody, it is also true that several are NOT in custody.

Given what is known about these previous attacks, might it be reasonable to consider that the Target breach may also be related?

Given the similarity in methods used in ALL of the cases above, what "Lessons Learned" might we hope other retailers and large network owners might be observing?

That's the focus of our latest Malcovery White Paper - "Target Hacker Tools Provide Breach Insight". I hope you'll take a chance to review it.

Monday, August 12, 2013

Anonymous, #OpBankster, and the Too Many Nancy's Problem

The current Anonymous "#OpBanksters" seems to have very little in common with the original operation by the Anonymous Portuguese group that was originally posted on YouTube back on April 14, 2013. However, the beginning of the current round started with an August 8th post by @AnonLegionPT (Anonymous Legion PT) inviting people to view the original video and then log on to AnonNet and join the "#opbanksters" chat room on Friday the 9th at 10 PM to discuss.

www.youtube.com/watch?v=9ZdMlgnvaqQ&feature=youtu.be

While we don't know what happened in the chat room, the result was that we began to see posts on PasteBin listing the email addresses and internet-facing IP addresses and hostnames of Portuguese banks.

An English translation of the Portuguese video reads:


Published on Apr 14, 2013

Greetings. We are Anonymous Portugal and this is the # banksters operation, a protest action against banks around the world, who have created a corrupt financial system based on debt-interest, speculation large sums with large multinationals and made the money a lucrative business that benefits a minority, but enslaves the rest of the population.

Banks extend credit to slashing with money created out of thin air, causing a snowball effect on the shortcomings of the banking system relative to the overall debt. With this system, banks enrich immeasurably, pay low interest on that deposit and charge high interest loans they make.

With this system of interest, speculation of the value of money and inflated product, it is easy to see where they come from debt, not only of companies and governments, but also emerge as the personal debt of each family. For years, banks eased lending by attracting people with the illusion of being able to have great purchasing power by easy access to money, and creating a debt trap from which many now can not get out. The social stratification, poverty, hunger and unemployment are therefore a consequence of the existing financial system, fatalities that may not disappear while this persists.

Banks in Portugal receive 8 billion state budget since 1999, are recapitalized with $ 12 billion in 2012 and are still saying that the people are having to endure? Portuguese people must know the true and the real gangsters responsible for the crisis, beyond the state. # OpBanksters: Portuguese and international banks, your time has come!

We are Anonymous!
We are Legion!
We do not forgive!
We do not forget!
Expect us!


While the original Twitter posts this week WERE from Anonymous Portugal, and the original PasteBin posts were also about Portuguese bank Credito Agricola, the Op quickly grew beyond its original intention of punishing Portuguese banks for being poor custodians of public funds.

The first three banks posted to the Operation's PasteBin page were:
Banco dos Espiritos Santos (BES) Portugal (110 emails / 62 hosts)
CreditoAgricola Portugal (136 emails)
and BBVA Portugal/Spain

On August 10th, with the exception of the European banking Authority (europa.eu) only Portuguese banks had their employee email addresses and hosts listed, including:

Cetelem PT
Credibom PT
Cofidis PT
Montepio PT
Banif PT
Bancobic PT
Banco BPI PT
Millennium BCP PT
Banco Popular PT/ES

On August 11th the information disclosure activity spread beyond the borders of Portugal.

Bank of America
Barclays
Lincoln State Bank
Deutsche Bank AG US
Dun & Bradstreet
FDIC
Federal Mortage Association
Federal Reserve Banks of Atlanta, New York, Richmond, and San Francisco
Fitch Rating
Goldman Sachs
Hartford Financial
Huntington Bank
Imperial Bank of Canada
London Stock Exchange

On August 12th (so far) we have seen added:

Moody's
Nasdaq
National Australian Bank
PNC
Royal Bank of Canada
Standard & Poors
SunTrust
M&T Bank
Royal Bank of Scotland
TD (Toronto Dominion)
Union Bank
Wall Street Insurance
Wall Street Journal
Citibank
JP Morgan Chase
Zurich Financial
were all added to the list. In the case of Bank of America, as one extreme example, more than 3700 named employees, with titles and emails, were listed.

At that point, we thought there may be a major problem with email-based security about to be unleashed!

As I discussed on Hacker HotShots this week, the Verizon Data Breach Investigations Report quotes "ThreatSim.com" as saying that when a hostile email is sent to three employees of an organization, there is a 50% chance that someone will click on it, but when an email is sent to TEN employees, there is nearly a "Guarantee" that someone will click on it! I couldn't imagine how bad things could go if 3700 employees were being targeted by hand-crafted malicious emails!

That seemed to be the what was happening already in Portugal, as we began to see defacements appear, such as this one hosted on the website "www.cie.com.pt" which is the "Centro de Intervenção Empresarial" showing "#opBankster" branded defacements:

The Anonymous Portugal Blog is here:

anonymouspt.blogspot.com/2013/08/op-banksters-part-ii.html

Their Facebook page is here:

https://www.facebook.com/AnonymousLegionPt

They claim to have successfullly DDOSed:

www.complemento-vintage.pt
www.lusonegocio.com
www.credibom.pt
www.flexibom.pt
www.cofidis.pt
www.cetelem.pt
and have confirmed that they are behind the PasteBin handle "#opBanksters"

The Too Many Nancy's Problem

As I started looking through the list of so many leaked addresses for all of these North American banks, I realized there might be a problem. The naming convention for each of the banks was "First Name, Last Initial" @ domain.com, so if I were on the lists, Gary Warner, my email would be given as "garyw@zurichna.com" or "garyw@frbatlanta.org" or "garyw@tdbank.ca". Obviously there would be collisions if that were the case, but I didn't see any attempt to avoid them. I also correspond regularly with many of the brands attacked, and realized that in many cases the domain listed is NOT the domain name where individuals who work for that organization receive their emails.

I decided to do a frequency distribution on the first names and look for "over-represented" names that seemed unlikely to me. I won't go into all the details here, but I looked at female first names from the 1990 US Census and compared them to distributions here. (A 1990 census person would be at least 23, so may be well represented in the work force. Anyone older than 23 would also be listed in the 1990 census, so it seemed as good a source as any.

MARY           2.629  2.629      1
PATRICIA       1.073  3.702      2
LINDA          1.035  4.736      3
BARBARA        0.980  5.716      4
ELIZABETH      0.937  6.653      5
JENNIFER       0.932  7.586      6
MARIA          0.828  8.414      7
SUSAN          0.794  9.209      8
MARGARET       0.768  9.976      9
DOROTHY        0.727 10.703     10
LISA           0.704 11.407     11
NANCY          0.669 12.075     12
On the first file I reviewed, I had, instead of the distribution above:
6 Mary's
1 Patricia
10 Linda's
7 Barbara's
9 Elizabeth's
14 Jennifer's
5 Maria's
7 Susan's
3 Margaret's
2 Dorothy's
6 Lisa's 
14 Nancy's
Now that may not be the most scientific of comparisons, but as a genealogist, I was confident I was dealing with TOO MANY NANCY'S!

Focusing in on the Nancy's the problem really started showing up. In each of the bank email lists I reviewed, the distribution of names was wildly out of line, and for popular names included many duplicate email addresses that would further confirm these were fakes. For example, just at Toronto Dominion, we had people with the email address "nancym@tdbank.ca" in the following positions and locations:

nancym@tdbank.ca == A Financial Planner in Richmand Hill, Ontario
nancym@tdbank.ca == A Merchant Risk Analyst II in Lewiston, Maine
nancym@tdbank.ca == A Recruitment manager in Toronto, Ontario
nancym@tdbank.ca == A Senior Compliance Officer in Hagersville, Ontario

Malcovery Security specializes in dealing with Email-based threat intelligence. We've got some great ideas for dealing with this current situation. Please reach out to us if you'd like to discuss.

Wednesday, June 05, 2013

Vietnamese Carders arrested in MattFeuter.ru case

Eleven Cyber criminals Arrested

I'm always pleased to see international cooperation in cybercrime investigations! This afternoon we received the news from the UK's SOCA, (the Serious Organised Crime Agency) that there were eleven arrests globally in a case involving cooperation from the Vietnamese High-Tech Crime Unit (HTCU), the Criminal Investigative Division of the the Ministry of Public Security of Vietnam (MPSVN CID), SOCA, the Metropolitan Police Central e-Crime Unit (PCeU), and the FBI. Eight criminals were arrested in Vietnam and three additional arrests were made in the UK.

All of these criminals were associated with the "mattfeuter" family of websites (mattfeuter.ru, mattfeuter.cc, mattfeuter.su, mattfeuter.com, etc.) where approximately 16,000 members bought and sold stolen credit card data in bulk. It is believed that purchases from the website had facilitated more than $200M worth of credit card fraud worldwide through the sale of more than 1.1 million credit cards.

SOCA and the PCeU are joining forces to create the new National Crime Agency later this year, but are already performing joint operations such as this investigation in anticipation of the UK's new National Cyber Crime Unit. Andy Archibald, who is the interim Deputy Director of the National Cyber Crime Unit, where the "Dedicated Cheque and Plastic Crime Unit" is housed, had this to say:

“One of the world’s major facilitation networks for online card fraud has been dismantled by this operation, and those engaged in this type of crime should know that that they are neither anonymous, nor beyond the reach of law enforcement agencies. We and our partners, in the UK and abroad, continue to protect the public and legitimate businesses by targeting websites trading in stolen card data, and relentlessly pursuing those who operate and frequent them."

Operations of this nature would not be possible without the support of private sector partners, in this case primarily Visa and MasterCard.

In keeping with UK law, the names of the three arrested there are not given, only their names and locations:

  • 37 year old man from West Ham
  • 34 year old man from Thornton Heath
  • 44 year old man from Manor Park
In the US, the New Jersey US Attorney's office has filed charges on 23 year old Duy Hai Truong, of Ho Chi Minh City, in Vietnam.

Vietnamese media has identified those arrested in Vietnam, and have named as their ringleader Van Tien Tu. The full list of those arrested include:

  • Ngo Thi Quynh Anh
  • Tran Thi Dieu Hien
  • Van Tien Tu
  • Truong Hai Duy
  • Le Van Kieu, those five all from Ho Chi Min City
  • Trinh Khac Duong
  • Dao Ba Bang
  • Doan Van Chuc, those three from Hanoi
The HCM City five are charged with illegally posting and using information from the Internet.

The Hanoi three are charged with using the credit card data for online gambling.

The ringleader, Van Tien Tu, is charged with having created the Mattfeuter websites, where credit cards are sold for between $2 and $20 per card. As the operator of the site, Van Tien Tu and his group earned approximately $1.5 million in commissions on their sales.

Although we haven't yet heard of many cases with Vietnamese cyber crime yet, the improvements in Vietnamese law passed in 2009 made it a criminal offense to fraudulently obtain card dat from overseas targets, as well as from victims in Vietnam.

The New Jersey case focuses on Duy Hai Truong, pictured below:

In a statement from the New Jersey US Attorney's Office, Paul Fishman announced that Truong was charged with "conspiracy to commit bank fraud. From 2007 until his recent arrest, Truong allegedly defrauded financial institutions as part of the massive scheme, in which personal identifying information relating to more than 1.1 million credit cards was stolen and resold to criminal customers worldwide." The New Jersey statement alludes to "arrests made over the past week in the United Kingdom, Vietnam, Italy, Germany, and elsewhere" so I am sure there will be additional news in the near future as the details of the case unfold.

The Official Complaint against Duy Hai Truong reveals that fees on the mattfeuter.biz and mattfeuter.com websites varied from $1 to $300 per "dump" (a dump referring to a magnetic card stripe read from a Credit or Debit Card), and that the fees were usually paid through Western Union or Liberty Reserve.

Truong is being held in Vietnam pending the settlement of charges in the UK, but if convicted in the US, Truong could face up to 30 years in prison and a fine of either $1 million or twice the gain from the offense, or twice the losses caused by the offense, whichever is greater.

New Jersey has also released the Sworn Complaint by FBI Special Agent Russell Ficara, who testifies that he reviewed over 1100 bank accounts and many searches of email accounts, residences, offices, and drop addresses related to this case. His testimony includes many of the email accounts used, including mattfeuter123@gmail.com, augustino267@gmail.com, ho.robbie@gmail.com, and included more than 150,000 email messages with more than 1.1 million credit card numbers being traded, including cards and personally identifiable information (PII) related to many victims residing in New Jersey.

As with so many criminals, Truong also had a Facebook account that referred to his real name, made references to the conspiracy, and contained photos of messages to and from Dump Purchasers and making reference to stolen credit cards!

A single Western Union location "in or around Ho Chi Minh City, Vietnam" was documented to have received more than $1.9 million in payments just related to MTCNs (Money Transfer Control Numbers) documented in the emails from the three referenced accounts, all controlled by Truong.

Thursday, May 09, 2013

ATM Cashers in 26 Countries steal $40M

CBS News in New York has a video on their website this morning title Cyber-attacks behind possibly record-breaking bank heist. Former FBI Assistant Director John Miller shares the story and says "We've learned how they carried out this cyber-attack, and it's unlike anything ever seen before."

Except it isn't. In fact, on Tuesday morning this week I was sharing a presentation about financial cyber crimes with Iberia Bank in New Orleans, LA. I mentioned that one of the things that banks still need to be on the lookout for is true "intrusions" into their system. By planting malware on internal bank systems, criminals can gain deep penetrating access to the internal workings of the bank and take their time, recruiting specialists to help them learn the inner workings of the bank to coordinate very elaborate schemes.

The attack described by Miller involves a group who had partnered together around the world calling themselves the "Unlimited Operation". In the scheme he describes, hackers gain internal access to a bank, or in the most recent case "a Visa/MasterCard processing Center," and gain the ability to manipulate the withdrawal limit on certain ATM Debit cards. These card numbers are then distributed around the world to "Cashing Gangs" that make local copies of the ATM cards and build a network of cashers who "work the machines."

One of the most notorious hacking operations in U.S. History was "Solar Sunrise" - a deep penetration into the Pentagon's computer operations that served as a wake up call for the U.S. Government and lead to the production of a video (now available on YouTube) called

(YouTube video: Solar Sunrise: Dawn of a New Threat
.

The hacker mastermind behind Solar Sunrise was an Israeli hacker, Ehud Tenenbaum, who called himself The Analyzer. In September of 2008 we wrote about him on this blog in the story Is The Analyzer Really Back? (The return of Ehud Tenenbaum) because Tenenbaum was the mastermind behind an attack against a Calgary-based financial services company. In that case, Tenenbaum penetrated the company's internal systems and gained the ability to alter or remove the ATM withdrawal limits. Then, teams of cashers, armed with counterfeit ATM cards bearing the magnetic stripe information corresponding to those accounts, hit the streets withdrawing $2 Million dollars in a blitz of ATM-withdrawals.

But that's not the only time it happened. This blog also ran the story in November 2009 called The $9 Million World-Wide Bank Robbery that shared the details of exactly the same type of raid being performed against RBS WorldPay, headquartered in Atlanta, Georgia. In that case, Estonian hackers penetrated the financial services company, that specializes in "Payroll Debit Cards". After doing so, they contracted with fellow-criminals in Russia, Yevgeny Anikin and Viktor Pleschcuk, who have both confessed their crimes, and received suspended sentences in the Russian bribery-based version of Justice. (See article: Hacker3 escapes jail time in RBS WorldPay ATM heist.) Anikin and Pleschuk worked with the famous Credit Card trading criminal BadB (Vladislav Horohorin) to build a network of cashers operating in 280 cities. Over the course of 12 hours, 2100 ATM machines in 280 cities allowed more than $9 Million in withdrawals from those 44 accounts.

That doesn't mean Cyber Criminals can't go to jail though! Vladislav Horohorin was arrested in Nice, France as he prepared to return to Moscow. (See the Daily Mail story, One of world's most wanted cyber criminals caught on French Riviera.) Horohorin, or "BadB" was the founder of Carder Planet, and was actually returned to the US, where he was tried and in April 2013 Sentenced to 88 Months in Prison.

For a look at one of the US-based casher rings in the RBS WorldPay case, we could also consider the case of Sonya Martin, a Nigerian woman, who ran the Chicago casher gang used in that case. Sonya's ring only withdrew $89,120 in Chicago, but she still got a 30 month sentence back in August 2012. See: Cell leader in RBS WorldPay fraud scheme sentenced.

One other case that used this methodology, and also had New York City ties, was the case that charged Ukrainians Yuriy Ryabinin and Ivan Biltse with performing $750,000 in ATM withdrawals. BankInfoSecurity.com reported the story in 2008, which documented that $5 million was withdrawn in more than 9,000 withdrawals "all around the world" on September 30th and October 1st of that year. According to an affidavit shared by Wired Magazine, this case was tied to a breach of a Citibank server that processed ATM withdrawals at 7-Eleven convenience stores.

In the current case described this morning by CBS, it was described that later today New York U.S. Attorney's office prosecutor Loretta Lynch would announce the arrest of seven members of a New York casher gang that hit ATM's up and down Broadway for almost $2 million during the most recent "Unlimited Operation" case. "Unlimited" was involved in a similar $5 Million raid against a financial institution in India. CBS shared a graphic of the location of ATM machines that were used in the arrests that will be announced later today.

In the New York case, the arrested cashers were:

  • ALBERTO YUSI LAJUD-PEÑA, 23 (deceased)
  • JAEL MEJIA COLLADO, 23
  • JOAN LUIS MINIER LARA, 22
  • EVAN JOSE PEÑA, 35
  • JOSE FAMILIA REYES, 24
  • ELVIS RAFAEL RODRIGUEZ, 24
  • EMIR YASSER YEJE, 24
  • CHUNG YU-HOLGUIN, 22

The Eastern District of New York's Press Release, Eight Members of New York Cell of Cybercrime Organization Indicted in $45 Million Cybercrime Campaign, released today, May 09, 2013, explains the details of how the cashers above, who withdrew $2.8 Million in New York, fit in to the larger "Unlimited Operations." In the first operation, the New York crew withdrew $400,000 from 140 ATMs in New York City in two hours and 25 minutes. In the second operation, February 19-20, 2013, the crew performed 3,000 ATM withdrawals, scoring $2.4 Million in cash between 3 PM on the 19th and 1:26 AM on the 20th, stealing about $240,000 per hour!

The worldwide take on the Feb 19-20 raid included 36,000 transactions and $40 million!

Alberto Yusi Lajud-Peña, the leader of the New York casher ring, laundered the cash, in one case depositing 7,491 $20 bills in a single transaction in Miami, Florida. The crew bought and sold "portable luxury goods" with the cash, including luxury watches and cars, including a Mercedes SUV and a Porsche Panamera valued at $250,000 between the two. Alberto, also known as "Prime" online, was murdered in the Dominican Republic sometime after these robberies occurred.

U.S. Attorney Lynch says that law enforcement authorities in Japan, Canada, Germany, and Romania made great contributions in the case, but that they also received cooperation from the authorities in the UAE, Dominican Republic, Mexico, Italy, Spain, Belgium, France, United Kingdom, Latvia, Estonia, Thailand, and Malaysia.

What these cases are intended to demonstrate is the importance of closely monitoring the internal corporate network for signs of a breach. In a presentation at ITWeb Security Summit this week, "Formulating an attack-focused security plan", Mandiant CSO Richard Bejtlich shares that 75% of break-ins happen through someone clicking on or responding to a malicious email, and that in 2/3rds of incidents, the breach isn't discovered by the company but is reported by a third party organization. Bejlitch says that by the time the attacker is discovered "they will have been inside your company for around eight months."

That's what Malcovery's Today's Top Threats report is intended to address. What is that Top Threat email that is going to lead to criminals having control of one or more of your internal employees? It takes time for the criminal to learn enough about your organization's internal workings to be able to take over and reset ATM balances. Quick detection of the breach is key to preventing problems like those described above.

Tuesday, May 07, 2013

Cyber Aspects of the Pentagon's new China report (A2/AD, CNE)

This week the Pentagon released their Annual Report to Congress, Military and Security Developments Involving the People's Republic of China 2013. While the 83-page report details all aspects of military and security, our readership will of course be most interested in the Cyber aspects. For their convenience I've just copied the portions most relevant to that target audience.

Starting at the beginning, "China's leaders in 2012 sustained investment in [missiles and counter-space weapons] and military cyberspace capabilities that appear designed to enable anti-access/area-denial (A2/AD) misisons (what PLA strategists refer to as "counter-intervention operations").

(For more on A2/AD, please see this excellent Q&A on the topic from the Center for Strategic and International Studies (CSIS), The Emerging Anti-Access Area-Denial Challenge.) Chapter 3 of the report, "Force Modernization Goals and Trends," mentions that "Beijing is investing in military programs and weapons designed to improve extended-range power projection and operations in emerging domains such as cyber, space, and electronic warfare.

Anti-Access/Area Denial (A2/AD)

(Begin Quote) As part of its planning for military contingencies, China continues to develop measures to deter or counter third-party intervention, particularly by the United States. China's approach to dealing with this challenge is manifested in a sustained effort to develop the capability to attack, at long ranges, military forces that might deploy or operate within the western Pacific, which the DoD characterizes as "anti-access" and "area denial" (A2/AD) capabilities. China is pursuing a variety of air, sea, undersea, space and counter-space, information warfare systems and operational concepts to achieve this capability, moving toward an array of overlapping, multilayered offensive capabilities extending from China's coast into the western Pacific. China's 2008 Defense White Paper asserts, for example, that one of the priorities for the development of China's armed forces is to "increase the country's capabilities to maintain maritime, space, and electromagnetic space security."

An essential element, if not a fundamental prerequisite, of China's emerging A2/AD regime is the ability to control and dominate the information spectrum in all dimensions of the modern battlespace. PLA authors often cite the need in modern warfare to control information, sometimes termed "information blockade" or "informaiton dominance," and to seize the initiative and gain an information advantage in the early phases of a campaign to achieve air and sea superiority. China is improving information and operational security to protect its own information structures, and is also developing electronic and information warfare capabilities, including denial and deception, to defeat those of its adversaries. China's "information blockade" likely envisions employment of military and non-military instruments of state power across the battlespace, including in cyberspace and outer space. China's investments in advanced electronic warfare systems, counter-space weapons, and computer network operations (CNO) -- combined with more traditional forms of control historically associated with the PLA and CCP systems, such as propaganda and denial through opacity, reflect the emphasis and priority China's leaders place on building capacity for information advantage.

(...)

Information Operations

New technologies allow the PLA to share intelligence, battlefield information, logistics information, weather reports, etc., instantaneously (over robust and redundant communications networks), resulting in improved situational awareness for commanders. In particular, by enabling the sharing of near-real-time ISR data with commanders in the field, decision-making processes are facilitated, shortening command timelines and making operations more efficient.

(...)

Cyber Activities Directed Against the Department of Defense

In 2012, numerous computer systems around the world, including those owned by the U.S. government, continued to be targeted for intrusions, some of which appear to be attributable directly to the Chinese government and military. These intrusions were focused on exfiltrating information. China is using its computer network exploitation (CNE) capability to support intelligence collection against the U.S. diplomatic, economic, and defense industrial base sectors that support U.S. national defense programs. The information targeted could potentially be used to benefit China’s defense industry, high technology industries, policymaker interest in US leadership thinking on key China issues, and military planners building a picture of U.S. network defense networks, logistics, and related military capabilities that could be exploited during a crisis. Although this alone is a serious concern, the accesses and skills required for these intrusions are similar to those necessary to conduct computer network attacks. China’s 2010 Defense White Paper notes China’s own concern over foreign cyberwarfare efforts and highlighted the importance of cyber-security in China’s national defense.

Cyberwarfare in China’s Military

. Cyberwarfare capabilities could serve Chinese military operations in three key areas. First and foremost, they allow data collection for intelligence and computer network attack purposes. Second, they can be employed to constrain an adversary’s actions or slow response time by targeting network-based logistics, communications, and commercial activities. Third, they can serve as a force multiplier when coupled with kinetic attacks during times of crisis or conflict.

Developing cyber capabilities for warfare is consistent with authoritative PLA military writings. Two military doctrinal writings, Science of Strategy, and Science of Campaigns identify information warfare (IW) as integral to achieving information superiority and an effective means for countering a stronger foe. Although neither document identifies the specific criteria for employing computer network attack against an adversary, both advocate developing capabilities to compete in this medium.

The Science of Strategy and Science of Campaigns detail the effectiveness of IW and CNO in conflicts and advocate targeting adversary C2 and logistics networks to affect their ability to operate during the early stages of conflict. As Science of Strategy explains, “In the information war, the command and control system is the heart of information collection, control, and application on the battlefield. It is also the nerve center of the entire battlefield.”

In parallel with its military preparations, China has increased diplomatic engagement and advocacy in multilateral and international forums where cyber issues are discussed and debated. Beijing’s agenda is frequently in line with Russia’s efforts to promote more international control over cyber activities. China and Russia continue to promote an Information Security Code of Conduct that would have governments exercise sovereign authority over the flow of information and control of content in cyberspace. Both governments also continue to play a disruptive role in multilateral efforts to establish transparency and confidence-building measures in international fora such as the Organization for Security and Cooperation in Europe (OSCE), ASEAN Regional Forum, and the UN Group of Governmental Experts. Although China has not yet agreed with the U.S. position that existing mechanisms, such as international humanitarian law, apply in cyberspace, Beijing’s thinking continues to evolve. (End Quote)