Showing posts with label Gonzalez. Show all posts
Showing posts with label Gonzalez. Show all posts

Sunday, May 13, 2018

How to Steal a Million: The Memoirs of a Russian Hacker

As a University researcher specializing in cybercrime, I've had the opportunity to watch the Russian carding market closely and write about it frequently on my blog "Cybercrime & Doing Time."  Sometimes this leads to interactions with the various criminals that I have written about, which was the case with Sergey.  I was surprised last January to be contacted and to learn that he had completed a ten year prison sentence and had written a book.   I have to say, I wasn't expecting much.  This was actually the third time a cybercriminal had tried to get my interest in a book they had written, and the first two were both horrible and self-promotional.  I agreed to read his first English draft, which he sent me in January 2017.

I was absolutely hooked from page 1.  As I have told dozens of friends since then, his story-telling vehicle is quite good.  The book starts with him already in prison, and in order to teach the reader about carding and cybercrime, a lawyer visits him periodically in prison, providing the perfect foil  needed to explain key concepts to the uninitiated, such as interrupting one of Sergey's stories to ask "Wait.  What is a white card?"
My copy of the book!

As someone who has studied cybercrime for more than 20 years, I was probably more excited than the average reader will be to see so many names and criminal forums and card shops that I recognized -- CarderPlanet, and card shop runners such as Vladislav Khorokhorin AKA BadB, Roman Vega AKA Boa, and data breach and hacking specialists like Albert Gonzalez and Vladimir Drinkman who served as the source of the cards that they were all selling.  These and many of the other characters in this book appeared regularly in this blog.  (A list is at the bottom of this article)

Whether these names are familiar to the reader or not, one can't help but be drawn into this story of intrigue, friendship, and deception as Pavlovich and his friends detect and respond to the various security techniques that shopkeepers, card issuers, and the law enforcement world are using to try to stop them.  Sergey shows how a criminal can rise quickly in the Russian cybercrime world by the face-to-face networking that a $100,000 per month income can provide, jet-setting the world with his fellow criminals and using business air travel, penthouse hotel suites, cocaine and women to loosen the lips of his peers so he can learn their secrets., but he also shows how quickly these business relationships can shatter in the face of law enforcement pressure.

The alternating chapters of the book serve as a stark reminder of where such life choices lead, as Sergey reveals the harsh realities of life in a Russian prison.  Even these are fascinating, as the smooth-talking criminal does his best to learn the social structure of Russian prison and find a safe place for himself on the inside.  The bone-crushing beatings, deprivation of food and privacy, and the fear of never knowing which inmate or prison guard will snap next in a way that could seriously harm or kill him is a constant reminder that eventually everyone gets caught and when they do, the consequences are extreme.

Sergey's original English manuscript has been greatly improved with the help of feedback from pre-readers and some great editors. After my original read, I told Sergey "I LOVE the story delivery mechanism, and there are fascinating stories here, but there are a few areas that really need some work."  It's clear that he took feedback like this seriously.  The new book, released in May 2018, is markedly improved without taking anything away from the brilliant story-telling of a fascinating criminal career ending with a harsh encounter with criminal justice.

A purchase link to get the book from Amazon: How to Steal a Million: The Memoirs of a Russian Hacker

The book was extremely revealing to me, helping me to understand just how closely linked the various Russian criminals are to each other, as well as revealing that some brilliant minds, trained in Computer Science and Engineering, and left morally adrift in a land where corruption is a way of life and with little chance of gainful employment, will apply those brilliant minds to stealing our money.

I seriously debated whether I should support this book.  Many so-called "reformed" criminals have reached out to me in the past, asking me to help them with a new career by meeting with them, recommending their services, or helping them find a job.  It is a moral dilemma.  Do I lend assistance to a many who stole millions of dollars from thousands of Americans?  Read the book.  To me, the value of this book is that it is the story of a criminal at the top of his game, betrayed by his colleagues and getting to face the reality of ten years in a Russian prison.  I think the book has value as a warning -- "a few months or even a couple years of the high life is not worth the price you will pay when it all comes crashing down."

Links to selected blog articles that feature Pavlovich's cast of characters:

May 12, 2008 TJX and Dave and Busters - Maksym Yastremskiy (Maksik) Aleksandr Suvorov (JonnyHell) and Albert Gonzales (Segvec) and their role in the TJX Data Breach.

August 5, 2008 TJX Reminder: We Will Arrest You and We Will Send You To Jail - some of the legal aftermath of the case above.

August 8, 2008 TJX: the San Diego Indictments where the US government indicts:
  • SERGEY ALEXANDROVICH PAVLOVICH, aka Panther, aka Diplomaticos, aka PoL1Ce Dog, aka Fallen Angel, aka Panther757
  • DZMITRY VALERYEVICH BURAK, aka Leon, aka Graph, aka Wolf
  • SERGEY VALERYEVICH STORCHAK, aka Fidel
and charges them with violation of "18 USC Section 1029(b)(2) Conspiracy to Traffic Unauthorized Access Devices"

May 9, 2013 ATM Cashers in 26 Countries Steal $40M talks about BadB's role in "Unlimited" ATM cash-out schemes, and his arrest in 2010 and sentencing to 88 months in 2013.

Jan 14, 2014 Target Breach Considered in Light of Drinkman/Gonzalez Data Breach Gang talked about Albert Gonzales, Vladimir Drinkman, and how there seemed to be such a strong pattern of behavior - a script if you will - to how criminals were conducting the major data breaches of that time.

Jan 27, 2014 Roman Vega (CarderPlanet's BOA) Finally Gets His Sentence addressed the plight of Roman Vega, who had been drifting around in the American criminal justice system, unsentenced, from 2003 until 2013! Dmitry Golubov AKA Script, the "godfather of CarderPlanet" is also discussed in this post.



Sunday, February 18, 2018

Drinkman and Smilianets Sentenced: The End to Our Longest Databreach Saga?

On Thursday, February 15, 2018, we may have finally reached the end of the Albert Gonzalez Databreach Saga.  Vladimir Drinkman, age 37, was sentenced to 144 months in prison, after pleading guilty before U.S. District Judge Jerome Simandle in New Jersey.  His colleague, Dmitriy Smilianets, age 34, had also pleased guilty and was sentenced to 51 months and 21 days in prison (which is basically "time served", so he'll walk immediately).  The pair were actually arrested in the Netherlands on June 28, 2012, and the guilty pleas had happened in September 2015th after they were extradited to New Jersey.

Those who follow data breaches will certainly be familiar with Albert Gonzalez, but may not realize how far back his criminal career goes.

On July 24, 2003, the NYPD arrested Gonzalez in front of a Chase Bank ATM at 2219 Broadway found Gonzalez in possession of 15 counterfeit Chase ATM cards and $3,000 in cash. (See case 1:09-cr-00626-JBS).  After that arrest, Gonzalez was taken under the wing of a pair of Secret Service agents, David Esposito and Steve Ward.  Gonzalez describes some of the activities he engaged in during his time as a CI in his 53 page appeal that he files March 24, 2011 from his prison cell in Milan, Michigan.

At one point, he claims that he explained to Agent Ward that he owed a Russian criminal $5,000 and he couldn't afford to pay it.  According to his appeal, he claims Ward told him to "Go do your thing, just don't get caught" and that Agent Ward later asked him if he had "handled it." Because of this, Gonzalez (who again, according to his own sentencing memo, likely has Asperger's) claims he believed that he had permission to hack, as long as he didn't get caught.

Over Christmas 2007, Gonzalez and his crew hacked Heartland Payments Systems and stole around 130 million credit and debit cards.  He was also charged with hacking 7-Eleven (August 2007), Hannaford Brothers (November 2007) where he stole 4.2 million credit and debit cards. Two additional data breaches against "Company A" and "Company B" were also listed as victims.  In Gonzalez's indictment, it refers to "HACKER 1 who resided in or near Russia" and "HACKER 2 who resided in or near Russia."  Another co-conspirator "PT" was later identified as Patrick Toey, a resident of Virginia Beach, VA.  (Patrick Toey's sentencing memorandum is a fascinating document that describes his first "Cash out trip" working for Albert Gonzalez in 2003. Toey describes being a high school drop out who smoked marijuana and drank heavily who was "put on a bus to New York" by his mother to do the cash out run because she needed rent money.  Toey later moved in with Gonzalez in Miami, where he describes hacking Forever 21 "for Gonzalez" among other hacks.

Gonzalez's extracurricular activities caught up with him when Maksym Yastremskiy (AKA Maksik) was arrested in Turkey.  Another point of Gonzalez's appeal was to say that Maksik was tortured by Turkish police, and that without said torture, he never would have confessed, which would have meant that Gonzalez (then acting online as "Segvec") would never have been identified or arrested.  Gonzalez claims that he suffered from an inadequate defense, because his lawyer should have objected to the evidence "obtained under torture."  These charges against Gonzalez were tried in the Eastern District of New York (2:08-cr-00160-SJF-AKT) and proved that Gonzalez was part of the Dave & Buster's data breach

On December 15, 2009, Gonzalez tried to shrug off some of his federal charges by filing a sentencing memo claiming that he lacked the "capacity to knowingly evaluate the wrongfulness of his actions" and asserting that his criminal behavior "was consistent with description of the Asperger's discorder" and that he exhibited characteristics of "Internet addiction."  Two weeks later, after fighting that the court could not conduct their own psychological exam, Gonzalez signed a guilty plea, agreeing that the prosecutor would try to limit his sentence to 17 years. He is currently imprisoned in Yazoo, Mississippi (FBOP # 25702-050) scheduled to be released October 29, 2025.

Eventually "HACKER 1" and "HACKER 2" were indicted themselves in April 2012, with an arrest warrant issued in July 2012, but due to criminals still at large, the indictment was not unsealed until December 18, 2013. HACKER 1 was Drinkman.  HACKER 2 was Alexandr Kalinin, who was also indicted with Drinkman and Smilianets.

Shortly after the Target Data Breach, I created a presentation called "Target Data Breach: Lessons Learned" which drew heavily on the history of Drinkman and Smilianets. Some of their documented data breaches included:
VictimDateDamages
NASDAQMay 2007  loss of control
7-ELEVEN August 2007
Carrefour October 2007 2 million cards
JCPenneyOctober 2007
HannafordNovember 2007 4.2 million cards
Wet SealJanuary 2008
CommideaNovember 2008 30 million cards
Dexia Bank BelgiumFeb'08-Feb'09
Jet BlueJan'08 to Feb '11
Dow Jones2009
EuroNetJul '10 to Oct '11  2 million cards
Visa JordanFeb-Mar '11  800,000 cards
Global Payments SystemsJan '11 to Mar '12
Diners Club SingaporeJun '11
IngenicardMar '12 to Dec '12

During the time of these attacks, Dimitry Smilianets was also leading the video game world.  His team, The Moscow 5, were the "Intel Extreme Masters" champions in the first League of Legends championship, also placing in the CounterStrike category.   Smilianets turned out not to be the hacker, but rather specialized in selling the credit cards that the other team members stole.  Steal a few hundred million credit cards and you can buy a nice gaming rig!

Smilianets with his World Champion League of Legends team in 2012

 How did these databreaches work?


Lockheed Martin's famous paper "Intelligence-Driven Computer Network Defense Informed by Analysis of Adversary Campaigns and Intrusion Kill Chains" laid out the phases of an attack like this:

But my friend Daniel Clemens had explained these same phases to me when he was teaching me the basics of Penetration Testing years before when he was first starting Packet Ninjas!

1. External Recon - Gonzalez and his crew scan for Internet-facing SQL servers
2. Attack (Dan calls this "Establishing a Foothold") - using common SQL configuration weaknesses, they caused a set of additional tools to be downloaded from the Internet
3. Internal Recon - these tools included a Password Dumper, Password Cracker, Port Scanner,  and tools for bulk exporting data
4. Expand (Dan calls this "Creating a Stronghold")  - usually this consisted with monitoring the network until they found a Domain Admin userid and password.  (for example, in the Heartland Payments attack, the VERITAS userid was found to have the password "BACKUP" which unlocked every server on the network!
5. Dominate - Gonzalez' crew would then schedule an SQL script to run a nightly dump their card data
6. Exfiltrate - data sent to remote servers via an outbound FTP.

In Rolling Stone, Gonzalez claims he compromised more than 250 networks
In the Rolling Stone article, "Sex, Drugs, and the Biggest Cybercrime of All Time" , Steven Watt, who was charged in Massachusetts for providing attack tools to Gonzalez in October 2008.  Watt's tools were used in breaches, including BJ's Wholesale Club, Boston Market, Barnes & Noble, Sports Authority, Forever 21, DSW, and OfficeMax.  As part of his sentencing, Watt was ordered to repay $171.5 Million dollars.

Almost all of those databreaches followed the same model ... scan, SQL Inject, download tools, plant a foothold, convert it to a stronghold by becoming a domain admin, dominate the network, and exfiltrate the data. 

How did the TARGET Data breach happen, by the way?  Target is still listed as being "Unsolved" ...   but let's review.  An SQL injection led to downloaded tools, (including NetCat, PSExec, QuarksPWDump, ElcomSoft's Proactive Password Auditor, SomarSoft's DumpSec, Angry IP Scanner (for finding database servers), and Microsoft's OSQL and BCP (Bulk Copy)), a Domain Admin password was found (in Target's case, a BMC server monitoring tool running the default password), the POS Malware was installed, and data exfiltration begun. 

Sound familiar???

Justice?

With most of Gonzalez's crew in prison by 2010, the data breaches kept right on coming, thanks to Drinkman and Smilianets. 

Drinkman, the hacker, was sentenced to 144 months in prison.
Smilianets, the card broker, was sentenced to 51 months and 21 days, which was basically "time served" -- he was extradited to the US on September 7, 2012, so he'll basically walk.

Will Smilianets return to video gaming? to money laundering? or perhaps choose to go straight?

Meanwhile, Alexandr Kalinin, of St. Petersburg, Russia; Mikhail Rytikov, of Odessa, Ukraine; and Roman Kotov, of Moscow, Russia, are all still at large.  Have they learned from the fate of their co-conspirators? or are they in all likelihood, scanning networks for SQL servers, injecting them, dropping tools, planting footholds, creating strongholds, and exfiltrating credit card data from American companies every day?

Kalinin (AKA Grig, AKA "g", AKA "tempo") is wanted for hacking NASDAQ and planting malware that ran on the NASDAQ networks from 2008 to 2010.  (See the indictment in the Southern District of New York, filed 24JUL2013 ==> 1:13-cr-00548-ALC )

Mykhailo Sergiyovych Rytikov is wanted in the Western District of Pennsylvania for his role in a major Zeus malware case.  Rytikov leased servers to other malware operators.  Rytikov is also indicted in the Eastern District of Virginia along with Andriy DERKACH for running a "Dumps Checking Service" that processed at least 1.8 million credit cards in the first half of 2009 and that directly led to more than $12M in fraud.  ( 1:12-cr-00522-AJT filed 08AUG2013.)  Rytikov did have a New York attorney presenting a defense in the case -- Arkady Bukh argues that while Rytikov is definitely involved in web-hosting, he isn't responsible for what happens on the websites he hosts.

Roman Kotov, and Rytikov and Kalinin, are still wanted in New Jersey as part of the case 1:09-cr-00626-JBS (Chief Judge Jerome B. Simandle ). This is the same case Drinkman and Smilianets were just sentenced under.

Monday, January 20, 2014

Target Breach considered in light of Drinkman / Gonzalez data breach gang

Everyone is talking about the Target data breach these days, but unfortunately our collective memory is sometimes too short to connect the dots.

Back in August of 2008 this blogger, like so many others, was focused on Albert Gonzalez after the TJX Arrests were made. Attorney General Michael Mukasey said that the message from the arrests was that if you do Data Breaches We Will Arrest You, and We Will Send You To Jail!. We followed up that post with a deeper look at two sets of indictments issued at the same time, TJX Update: The Boston Indictments and TJX Update: The San Diego Indictments. (The San Diego ones included the famous hackers Aleksander Suvorov, AKA JonnyHell from Estonia, and Maksym Yastremskiy, AKA Maksik). Maksik and JonnyHell were part of the Dave & Busters Point-of-Sale terminal hacks indicted in May 2008.( 23 page Dave & Busters Indictment against Maksik and JonnyHell)

In the Gonzalez case, it was mentioned that his gang had targeted "at least nine major retail corporations: including the TJX Corporation, whose stores include Marshalls and TJ Maxx; BJ's Wholesale Club; Barnes and Noble; Sports Authority; Boston Market; Office Max; Dave & Buster's restaurants; DSW shoe stores; and Forever 21."

But what is perhaps most important is that when it comes to gangs stealing millions of credit cards, there are no one-man operations, or even ten-man operations. These type of breaches are pulled off by crews. We learned much more about Gonzalez's crew in the recently unsealed documents from the case against Vladimir Drinkman, Aleksandr Kalinin, Roman Kotov, Mikhail Rytikov, and Dmitriy Smilianets. The order to Unseal the Drinkman et. al. case was only given on December 17, 2013. Several items on the docket remain sealed to this day, but one of special interest was the Second Superseding Indictment, which has been unsealed, although several points remain redacted.

Here's what we learn in the Drinkman indictment.

  • Drinkman resided in or near Syktyvkar and Moscow, Russia, and was "a sophisticated hacker, who specialized in penetrating and gaining access to the computer networks of multinational corporations, financial institutions, and payment processors; harvesting data, including, among other things, credit card, debit card, and other customer account information, from within the compromised networks; and exfiltrating that data out of the compromised networks.
  • Kobov resided in or near Moscow, Russia, and "specialized in harvesting data from within the computer networks that Drinkman and Kalinin had penetrated, and exfiltrating that data.
  • Co-conspirators named in the indictment include Albert Gonzalez (segvec), Damon Patrick Toey, and Vladislav Anatolievich Horohorin (BadB).
  • The hacking conspiracy is described as "a prolific hacking organization" "responsible for several of the largest known data breaches" and that it operated "from August 2005 through at least July 2012."
Data breaches that were described as being part of this case, include:

  • NASDAQ - (from at least May 2007 - SQL Injection lead to malware that extracted login credentials from databases)
  • 7-Eleven - (at least August 2007 - SQL Injection lead to malware that extracted card data from databases)
  • Carrefour S.A - (2 million credit cards - October 2007 - SQL injection lead to malware that extracted card data from databases)
  • JCPenney - (October 2007 - SQL Injection lead to malware placed on the network that extracted card data from databases)
  • Hannaford Brothers - (4.2 million credit cards - November 2007 - SQL Injection lead to malware placed on the network that extracted card data from databases)
  • Heartland Payment Systems (130 million card numbers, estimated losses of $200 Million - December 2007 - SQL Injection lead to malware placed on the network that extracted card data from databases)
  • Wet Seal - (January 2008 - SQL Injection lead to malware placed on the network that extracted card data from databases)
  • Commidea Ltd. - (30 million Credit cards - March-November 2008 - malware was used to extract card data and exfiltrate the data)
  • Dexia Bank Belgium - ($1.7 Million loss - February 2008 to February 2009 - SQL Injection resulted in malware placed on the network that exfiltrated card data)
  • JetBlue Airways - (Jan 2008 - February 2011 - malware placed on network exfiltrated Personal Data of employees)
  • Dow Jones, Inc. - (2009 - at least 10,000 sets of Log-In Credentials stolen via malware placed on network)
  • "Bank A" - (Dec 2010 to March 2011 - malware placed on an unnamed bank HQ'ed in Abu Dhabi, United Arab Emirates used to facilitated theft of Card Numbers.)
  • Euronet - (2 million cards - July 2010 to October 2011 - SQL injection lead to malware that extracted login credentials from databases.)
  • Visa Jordan Card Services - (800,000 cards - Feb 2011 to March 2011 - SQL Injection lead to malware placed on network that exfiltrated card data.)
  • Global Payment Systems - (950,000 cards - $92.7 Million in losses - January 2011 to March 2012 - SQL Injection lead to malware placed on network that exfiltrated card data.)
  • Diners Club International, Singapore - (500,000 Diners Credit cards - $312,000 in losses - June 2011 - SQL Injection lead to malware placed on network that exfiltrated card data)
  • Ingenicard US, Inc. - ($9 million in 24 hours - March 2012 to December 2012 - SQL Injection resulted in malware placed on the network that was used to facilitate ATM withdrawals.)
Although it is true that several of the members named above are now in custody, it is also true that several are NOT in custody.

Given what is known about these previous attacks, might it be reasonable to consider that the Target breach may also be related?

Given the similarity in methods used in ALL of the cases above, what "Lessons Learned" might we hope other retailers and large network owners might be observing?

That's the focus of our latest Malcovery White Paper - "Target Hacker Tools Provide Breach Insight". I hope you'll take a chance to review it.

Friday, August 08, 2008

TJX Update: The San Diego Indictments

As promised, here is the update regarding the eight individuals charged in San Diego in connection with "the TJX bust".

There were actually four separate indictments filed, and now that we have the indictments, we'll hopefully be able to learn more about some of these more mysterious criminals.

In the first indictment, the UNITED STATES OF AMERICA v. MAKSYM YASTREMSKIY

the charges are:

18 USC Section 1029(a)(2), and (c)(1)(A)(i) - Trafficking in Unauthorized Access Devices
18 USC Sections 1028(a)(7) and (b)(1)(D) - Identity Theft
18 USC Section 1028A(a)(1) - Aggravated Identity Theft
18 USC Section 1956(h) - Conspiracy to Launder Monetary Instruments
18 USC Section 982 - Criminal Forfeiture

As we saw in the first part of today's post, TJX Update: The Boston Indictments, when Albert Gonzalez and friends didn't know how to turn their stolen credit cards into money, they reached out to Eastern Europe for advice. When they didn't know how to crack their PINs, they reached out to Eastern Europe for advice. When they didn't know how to make sure their sniffer programs would remain undetected, they reached out to Eastern Europe for advice.

Much of that time, they were reaching out to Maksym Yastremskiy.

From May 31, 2005 until May 30, 2006, Yastremskiy, operating in the Southern District of California and elsewhere, sold approximately 155,000 credit card numbers "with intent to defraud", for $98,000 in cash.

Maskym ran a website which was his primary mechanism for selling cards. Prices varied by the bulk, and quantities of cards were advertised on the website (presumably by himself and others) in batches from ten or a dozen, up to several hundred thousand cards or even several million.

The general practice was that Maksym would be contacted by email or chat and the subject of how to make the purchase would be discussed. Unknown buyers would wire a cash payment, usually with Western Union, to Yastremskiy or an accomlpice. Trusted purchasers were allowed to wire directly into Yastremskiy's various bank accounts.
Once the funds transfer was complete, the purchaser would be granted the requested number and type of cards through the website. The indictment gives examples such as "10 Citibank Visa (Gold)" or "20 Royal Bank of Hong Kong Master Card (Platinum)" or "12 Chase Visa (Classic)".

Maksym's charges do not specifically reference Gonzalez from Miami, nor do they name the source of the cards.

Forfeiture claim is made to property derived from many payments, including but not limited to:

$846,762.18 in E-Gold accounts
$ 87,517.36 in Parex Bank account
$3,781,436.36 in an Asia Universal Bank account
$4,862,884.96 in Western Union money transfers
$1,931,047 in US currency




The second indictment is the UNITED STATES OF AMERICA v. ALEKSANDR SUVOROV, aka Lifestyle, aka JohnnyHell, aka Dantist.

The charges brought against Suvorov are:

18 USC Section 1029(b)(2) - Conspiracy to Possess Unauthorized Access Devices and to Traffic Unauthorized Access Devices
18 USC Section 1029(a)(3) and (c)(1)(A)(i) - Possession of Unauthorized Access Devices
18 USC Section 1029(a)(2) and (c)(1)(A)(i) - Trafficking in Unauthorized Access Devices
18 USC Section 1028(a)(7) and (b)(1)(D) - Identity Theft
18 USC Section 1028A(a)(1) - Aggravated Identity Theft
18 USC Sec 2 - Aiding and Abetting

Suvorov's Conspiracy charges name Maksym as his co-conspirator (however Maksym was not charged with Conspiracy in his indictment).

The Overt Acts in the conspiracy are:

On February 10, 2006, Maksym Yastremskiy agreed to sell 160,000 unauthorized credit card account numbers to a purchaser located in San Diego, California.

On February 20, 2006, Sukorov provided Maksym (AKA Maksik) with 160,000 unauthorized credit card account numbers for purpose of re-sale.

On March 17, 2006, in exchange for $10,000 in US Currency, Maksik transferred the first 6,798 of the negotiated 160,000 unauthorized credit cards.

Suvorov received occasional payments from Maksik from May 2, 2005 until May 1, 2006 as the cards were slowly bought and the funds were received back. Over the course of this time, Suvorov received from Maksik approximately $75,000.




In the third indictment, The UNITED STATES OF AMERICA has three Defendants:

SERGEY ALEXANDROVICH PAVLOVICH, aka Panther, aka Diplomaticos, aka PoL1Ce Dog, aka Fallen Angel, aka Panther757

DZMITRY VALERYEVICH BURAK, aka Leon, aka Graph, aka Wolf

SERGEY VALERYEVICH STORCHAK, aka Fidel

The only charge against these three is:

18 USC Section 1029(b)(2) Conspiracy to Traffic Unauthorized Access Devices

This is such a disappointment after the charges against the Boston crowd and the first two here! What are they charged with?

On May 11, 2007 - Sergey Pavlovich negotiated the sale of 90 stolen credit cards to a purchaser in the Southern District of California.

On September 11, 2006 - Dzmitry Valeryevich Burak negotiated the sale of 30 stolen credit cards to a purchaser in the Southern District of California.

On October 10, 2007 - Sergey Valeryevich Storchak agreed to sell 64 stolen credit cards to a purchaser in the Southern District of California.

Ummmm... Big whoop.




In the fourth indictment, the UNITED STATES OF AMERICA also charges three defendants:

HUNG-MING CHIU, aka Slimbady, aka Tomaliki, aka B&Q, aka Betrmb

ZHI ZHI WANG, aka Akihikotobe, aka Attorney

FNU LNU (for those of you who don't speak Chinese OR Indictmentese, that's First Name Unknown Last Name Unknown), aka Delpiero

The charges brought are:

18 USC Section 1029(b)(2) - Conspiracy to Possess Unauthorized Access Devices, to Traffic Counterfeit Access Devices, and to Traffic Unauthorized Access Devices
18 USC Section 1029(a)(2) and (c)(1)(A)(i) - Trafficking in Unauthorized Access Devices
18 USC Section 1029(a)(1) and (c)(1)(A)(i) - Trafficking in Counterfeit Access Devices
18 USC Section 1028A(a)(1) - Aggravated Identity Theft
18 USC Section 2 - Aiding and Abetting

The three defendants are charged with entering into conspiracy with Maksik (Maksym Yastremskiy) and JonnyHell (that's the third way I've seen that spelled in official documents this week!) (Aleksandr Suvorov).

The Overt Acts in their conspiracy include:

On July 30, 2005 - Zhi Zhi Wang sold 100 counterfeit credit card blanks to a purchaser located in the Southern District of California. The order was later filled by Hung-Ming Chiu.

On July 30, 2005 - Zhi Zhi Wang sold 100 counterfeit credit card blanks to a purchaser located in the Southern District of California. The order was subsequently filled by Hung-Ming Chiu.

On September 17, 2005 - Hung-Ming Chiu discussed with Maksym "Maksik" Yastremskiy the creation of a website that could be used to distribute stolen credit card accounts. Maksik agreed that he would be the website's provider of stolen credit card account information.

On September 28, 2007 - FNU LNU, aka Delpiero, sold 100 unauthorized access devices to a purchaser in the Southern District of California.

From September 17, 2004 until September 16, 2005, Hung-Ming sold approximately 162 credit card account numbers that had been stolen or obtained with intent to defraud, for approximately $4,500 in cash.

From September 17, 2005 until September 16, 2006, he did it again, with 172 cards for which he received $5,000.

From April 18, 2007 until April 17, 2008, Delpiero sold about 350 credit card account numbers for about $4,500.

They also sold "real looking" (or counterfeit) blank plastic.



OK, we'll pause here for a moment to reflect on how ludicrous it sounds to have a single press release naming people with $20 Million in forfeiture in the same case with people who only made $4,500. This is the part where we interject that these are real bad guys doing world-wide crime! The problem is that we have to have jurisdiction, in this case in the Southern District of California, for whatever we charge them with. Before you get terribly disillusioned about the nature of these "small fish" based on the indictments, let's investigate the Affidavit of Special Agent Ryan Knisley of the United State Secret Service.



SA Knisley has been a Secret Service Agent since August 7, 2006. What we don't see in the indictments themselves is that "Pavlovich" runs a HUGE Credit card trading service known as "Dumps Market" (www.dumpsmarket.net, at the time of the indictment.)

Burak had screwed up and found himself with a Yahoo! address which was searched by the US Secret Service. As a result of that search, he was found to be trading "BIN lists" (Bank Identification Numbers) and stolen credit card numbers with Storchak.

Storchak's accounts were also searched, and it was found that the credit card numbers traded between these two actually had been used for real dollar losses of $7,000,000!

Other evidence pointed to email accounts at a site called "safe-mail". Commonly held by the criminals to be beyond the stretch of US Law Enforcement. Through the Mutual Legal Assistance Treaty, email accounts at "SAFe-mail", which resides in Israel, were also searched, and the results shared with the USSS. In those mails
more details were revealed indicating that Pavlovich was the source of many of the stolen credit cards.

Pavlovich was running DumpsMarket in Belarus. Who also cooperates with US Law Enforcement. The Belarus law enforcment folks seized Pavlovich's hard drive, made a copy, and sent it to the US Secret Service. Pavlovich's hard drive contained more than 10,000 stolen credit cards, and photographs of himself spending time with Burak and Storchak in various social settings.

So, while the actual charges brought here seem small, we MUST make them stick. This is a $7 Million Bad Guy of the variety who needs to go to jail.

Three Cheers to Southern California for taking what data they could own and deciding to press forward with it!

While it is not specifically laid out in the documents to which I have access, it is my strong belief that the Chinese defendants are in a similar situation. The small numbers in Southern California should not be seen as a measure of their insignificance as criminals, but rather as a sign that when you spread multi-million dollar crime around the entire globe, its hard to find one small set of contiguous ZIP Codes that had many losses.

Again, Three Cheers to the US Secret Service, and the US Attorney of the Southern District of California!

(All Four Indictments, and the Affadavit are included in a single 34 page PDF)

TJX Update: The Boston Indictments

The Boston indictments are now public and have quite a few more facts for us, and I'm so excited that I've just received the first of the San Diego indictments from their most helpful press officer!

I'm going to run this in two parts. Boston first, and then San Diego.

An incomplete story was painted by the earliest press releases, which lead the media to quickly jump on the fact that Gonzalez was a wardriver, and TJX and the other victim companies had sloppy wireless security. True, but not a complete picture.

We'll start by looking at what else we can learn from the indictments that are now available in Boston.

What's in a name? We'll start with Albert Gonzalez's A/K/A's:

cumbajohny
cj
UIN 201679996
UIN 476747
k1ngchilli
stanozololz

Unfortunately, that genius of blackhat journalism, Kevin Poulson, has beat us to the punch with this one in his Wired Blog, but what a great story it is. You'll recall in our previous blog post on this subject, TJX Reminder: We Will Arrest You, and We Will Send You To Jail, we mentioned that Albert Gonzalez was a US Secret Service Informant. Now that we know his alias, CumbaJohny, we see that Albert was the snitch for Operation Firewall, the Secret Service case that lead to the arrests of 28 members of the ShadowCrew back in October of 2004. CumbaJohny, now re-handled as Segvec, now gets to feel what its like to be on the receiving end of one of these seizures.

The Violations that Segvec faces are:

18 USC section 371 Conspiracy
18 USC section 1030(a)(5)(A)(i)Damage to Computer Systems
18 USC section 1343 Wire Fraud
18 USC section 1029(a)(3) Access Device Fraud
18 USC section 1029(c)(1)(C), 982(a)(2)(B),981(a)(1)(C) Criminal Forfeiture
28 USC section 2461(c) Criminal Forfeiture

Here's the way the Conspiracy charges stack up. First we have to establish what they conspired to do. The indictments lists "the objects of the conspiracy" this way:


a. Exploit vulnerabilities in wireless computer networks used at retail store locations

b. Exploit vulnerabilities used to manage large business databases

c. Gain unauthorized access to computer networks processing and storing debit and credit card transactions and other valuable data for major corporate retailers.

d. Download and steal from computer networks operated by major corporate retailers over 40 million pieces of card holders' track 2 data - the information found on the magnetic stripes of credit and debit cards, which is read by ATMs and credit card readers - as well as internal accounts and proprietary files

e. Sell stolen track 2 data in Eastern Europe, the United States and elsewhere to others for fraudulent use

f. "Cash out" stolen track 2 data by encoding the data on the magnetic stripes of blank payment cards and using these cards to obtain tens of thousands of dollars at a time from banks' ATMs

g. Conceal and launder the illegal proceeds through anonymous web currencies in the United States and Russia, and offshore bank accounts in Latvia

h. Repatriate portions of the illegal proceeds through web currency converters and ATM cards linked to Eastern European banks.


The Gonzalez indictment tells quite a bit more about how they moved from WarDriving to much greater exploits.

First, Gonzalez, Toey, and Scott went wardriving around Miami, in commercial areas such as the area around U.S. 1, identifying vulnerable wireless networks. They targeted large retailers, "including, but not limited to" BJ's Wholesale Club, DSW, OfficeMax, Boston Market, Barnes & Noble, Sports Authority, and TJX.

After infiltrating their networks, they began locating and stealing sensitive files and data, including credit card numbers.

At this point, they are just punks. This type of break-in is a dime a dozen. But then they took it further. It says they went on to install sniffer programs, monitoring and stealing password and account information as well as track 2 data.

The conspiracy broadened as they had to bring in new associates to help with decrypting the encrypted PIN numbers on their tens of millions of Track 2 reads.

The stolen data was stored on servers in Latvia, the Ukraine, and the United States, and encrypted to prevent access by others. From there, the data was sold in "dumps", cashed out, and the money was redistributed, using webmoney, ATMs, and in some cases even mailing express packages full of cash to drop boxes!

Regarding their technical skills, custom SQL injection attacks were developed to take on particularly desirable web sites. The attacks were mounted against a variety of database-driven web sites to find additional track 2 data, internal accounts, and files of large businesses.

Regarding the level of Gonzalez' conspiracy -- he used sensitive law enforcement information, which he obtained by his "cooperation" with the US Secret Service, to alert his conspirators and make sure they would not be identified and arrested.


Some particular examples illustrate the dates and players:

In 2003, Gonzalez and Scott use wireless access to steal track 2 data at BJ's Wholesale Club.

In 2004, Scott and "J.J." gain unauthorized access to the wireless network of the OfficeMax on 109th Street and US 1 in Miami, locating and downloading encrypted PINs.

Scott and J.J., unable to decrypt the PINs, passed the data to Gonzalez, who located and engaged another co-conspirator who had the necessary decryption abilities.

On July 12 and 18th, 2005, Scott accessed TJX's Marshalls department stores in Miami, using the wireless network there to compromise servers at TJX's server farm in Framingham, Massachusetts.

On September 15-16, Scott accessed the Framingham servers and retrieved the data which their sniffers had been collecting.

Beginning on May 14-15, 2006, Scott installed and configured a VPN connection between one of the TJX card transaction servers and a server obtained by Gonzalez.

On May 15, 2006, Gonzalez used ICQ to ask Yastremskiy for help in obtaining an undetectable sniffer program. Beginning on May 15 and lasting through May 20th, they established their new undetectable sniffer.

The new sniffer's data was retrieved on many dates, including October 27 and December 18, 2006.

Beginning in August of 2007, Gonzalez invited Toey to move to Miami. In exchange for cash payments and free rent, Toey began to develop an Internet-based attack on the servers at "Forever 21", with the goal of obtaining financial data.

Prior to moving to Miami, Toey worked as a broker for Gonzalez, finding customers, who would be given login credentials to retrieve the credit cards from one of the many encrypted dump sites around the Internet.

From February to May of 2006, Gonzalez collaborated with Yastremskiy to distribute OfficeMax track 2 data.

On March 13, 2008, Gonzalez used his VPN connection to TJX from a computer in Latvia to store 16 million unique credit and debit card numbers. That same day he stored more than 25 million credit and debit cards on a Ukranian server as well.

Gonzalez faces forfeiture of $1,650,000 cash, a condo in Miami, a 2006 BMW 330I, some computers, a Glock 27, a "350C Currency Counter" (wow!),

As for the further act of Gonzalez, and all that he did, are they not written in the Book of the Chronicles of the Criminals of Massachusetts?




Christopher Scott's Indictment is much less sexy from the beginning, mostly because he has no cool hacker aliases at the beginning.

He is charged with most of the same charges, with the exception of Wire Fraud.

His forfeiture included, $400,000 in cash, eleven computers, some nice iPods, some nice monitors, and they even took his XBOX and PSPs!

Let this be a warning to you, children. If you hack into TJX, you will lose your XBOX privileges! (Oh, and go to jail for a long time, hopefully!)

As for the further acts of Scott, and all that he did, are they not written in the Book of the Chronicles of the Criminals of Massachusetts?



Damon Patrick Toey faced the same charges as Chris Scott. He also does not get Cool Points for having many AKAs, but let's face it, Damon Toey is a cooler name than Chris Scott.

Toey's "Overt Acts" section focuses on his selling of "dumps" of cards on behalf of Gonzalez and splitting the proceeds, and his leading role in the SQL injection and other Internet-based attacks used to access corporate databases and systems, including the Forever 21 attack, where he had the leading role.

I love the actual wording of Count Two, the Access Device Fraud:


In or about October, 2004, in the Eastern District of Virginia and elsewhere, Damon Patrick Toey, knowingly and with intent to defraud, possessed at least 15 unauthorized access devices, to wit: stolen credit and debit card numbers.


Yes, 40,000,000 is "at least" 15.

Based on the forfeiture, it looks like Damon was the Talented but Unimaginative member of the team. He forfeited only $9,500 and a few computers. But they got his XBOX too!

As for the further acts of Toey, and all that he did, are they not written in the Book of the Chronicles of the Criminals of Massachusetts?

Tuesday, August 05, 2008

TJX Reminder: "We Will Arrest You, and We Will Send You To Jail"

As we've been watching the news since the TJX bust, there have been several times where I thought we would hear that charges for that break-in would finally come. Well, it seems today is the day! Albert Gonzalez of Miami, who is known by his hacker handle "Segvec", was charged along with two other Miami residents in Boston today, while eight others were charged in Los Angeles.

With several hundred million dollars in theft, Attorney General Michael Mukasey did a press release about the indictments. According to Mukasey's speech:

hey targeted at least nine major retail corporations, including the TJX Corporation, whose stores include Marshalls and TJ Maxx; BJ's Wholesale Club; Barnes and Noble; Sports Authority; Boston Market; Office Max; Dave and Busters restaurants; DSW shoe stores; and Forever 21.


Mukasey continued, describing today's actions as a key part in the strategy of the Identity Theft Task Force, co-chaired by Mukasey and the chairman of the Federal Trade Commission, William Kovacic:


And the cooperation among investigators and prosecutors throughout the United States and around the world that led to these indictments shows the promise of close coordination in tackling these problems. Cases like this send a clear message to those who might be tempted to abuse our computer networks to steal information and harm law-abiding people and businesses: If you do, we will track you down wherever you are in the world, we will arrest you, and we will send you to jail.


The Department of Justice Press Release goes into som emore details, naming the additional co-conspirators:

Three From Miami were charged in Boston today:

Albert Gonzalez, AKA Segvec
Christopher Scott
Damon Patrick Toey

In San Diego charges were unsealed against:

From the Ukraine:
Maksym Yastremskiy, AKA Maksik
Dzmitry Burak
Sergey Storchak (no, I don't believe this is the Deputy Minister of Finance in Russia, of the same name, who is already in prison for embezzlement...)

From the Ukraine:
Aleksander Suvorov, AKA Jonny Hell

From China:
Hung-Ming Chiu (邱黄明)
Zhi Zhi Wang (王治治)

From ????:
the unknown hacker named Delpiero (isn't that an Italian soccer player's name?)

From Belarus:
Sergey Pavolvich

The indictments in San Diego are the result of an on-going three year undercover operation run by the Secret Service.


We last discussed Albert Gonzalez in this blog posting from May 12th, under the title TJX and Dave & Busters. Gonzalez was actually working as a "Confidential Informant" for the US Secret Service when they became aware of his involvement in this case. He had come to the attention of the Service when they arrested him in 2003 for Access Device Fraud. He was re-arrested for Wire Fraud on May 8th, according to documents from the US District Court in Miami, Floriday.

Maksym Yastremskiy has been jailed longer than any of the others, having been arrested at a nightclub in Kemer, Turkey with his girlfriend, and found to be in possession of "at least 1 million" credit card credentials, many of which have been found to be TJX data. That story broke (if you speak Turkish), all the way back in August of 2007 with these two articles:

Milliyet.com.tr - August 2nd

and

Sabah.com.tr - August 3rd

We first talked about that in this blog with the story TJX: From Florida to the Ukraine?, where we discussed the Miami crew who were turning TJX cards into WalMart Gift Cards before laundering them via eBay sales of luxury items bought in Sam's Clubs.

The next to get arrested was probably Jonny Hell, whose arrest back on March 3, 2008 was recently depicted in this Der Spiegel story from June 30th.



Jonny Hell, in Der Spiegel . . .

If you'll forgive my bad translation, the story says something like:


The two American agents, dark suits and service-brands of the Secret service, stood motionless beside the snake of the flight-traveler at the Frankfurt airport. They waited until Aleksandr Suvorov and his friend Vika were next, arriving at terminal 1 Singapore Airlines for three weeks of recuperation in Bali for the love-pair. As Suvorov pushed his Estonian passport over the counter-bar, eyewitnesses remember, there the Special Agents Paul B. and Timothy G. stepped forward, pulled out their ID cards, and revealed it to him. "You are arrested". It was March 3rd, shortly before 22 o'clock . . .

Since then, he has waited for his delivery to the USA. He is regarded as a top international hacker, that steals sensitive data in a big style by means of Trojan horses, and then resells it. The young Estonian, who supposedly hides behind the hacker-pseudonym "Jonny Hell", belongs to "one of the biggest world-wide circles dealing in stolen credit card numbers".




If anyone has more information on these hackers and their other exploits, please send them in!

Gary Warner
gar@askgar.com

Monday, May 12, 2008

TJX and Dave & Busters

If you've visited a Dave & Busters, you know these are a great place for grown-ups to go out and play. I've been to several events at the Atlanta location, and enjoy the Virtual Reality games there. I never thought I would see a Dave & Busters story come up on the news-ticker that I have watching for new TJX stories, but that is what happened this morning.

You will probably recall the story of Maksym Yastremskiy (Maksik), a Ukrainian citizen arrested in Turkey for his role in trading enormous volumes of credit cards which could all be traced back to the TJX debacle. He was back in the news today with two other hackers, Aleksandr Suvorov (JonnyHell) from Estonia, and Albert Gonzales (Segvec). The charges are that the first two ran a scam involving the installation of packet sniffers into thte cash register systems at 11 Dave & Buster's restaurants. Just the Islandia, New York location was credited with 5,000 customer's credit card data leading to more than $600,000 in fraudulent purchases. Segvec is charged only with "wire fraud conspiracy", in that he purchased some of this data from Maksik.

The indictment was posted on the ABC News website.

The 27 counts against the first two are:

Count One: Conspiracy to Commit Wire Fraud
(knowingly and intentionally conspiring to devise a scheme and artifice to defraud D&B, its customers, and the financial institutions that issued the customers' credit and debit cards, and to obtain money and property...by means of materially false and fraudulent pretenses, representations and promises, and attempting to do so by means of wire communication in interstate and foreign commerce . . . )

Counts 2-5: Wire Fraud
(installing a packet sniffer, and reactivating it at D&B Store #2 in Islandia, New York, on 5/18/07, 6/9/07, 7/23/07, 8/14/07.)


Count 6: Conspiracy to Possess Unauthorized Access Devices

Count 7-9: Possession of Unauthorized Access Devices
(the "access device" in question being log files containing "15 or more credit and debit card account numbers".)
(Title 18, Section 1029(a)(3))
(Title 18, Section 1029(c)(1)(A)(i))


Count 10-12: Aggravated Identity Theft
(Title 18 Section 1028A(a)(1), (b), (c)(5))

Count 13: Conspiracy to Commit Computer Fraud
(Title 18 Section 371 and 3551)

Count 14-16: Unauthorized Computer Access Involving an Interstate Communication
(Title 18 Section 1030(a)(2)(C))
(Title 18 Section 1030(c)(2)(B)(i))

Count 17-19: Unauthorized Computer Access to Obtain Things of Value
(Title 18 Section 1030(a)(4))
(Title 18 Section 1030(c)(3)(A))

Count 20-23: Unlawful Transmission of Computer Codes
(Title 18 Section 1030(a)(5)(A)(i))
(Title 18 Section 1030(a)(5)(B)(i))
(Title 18 Section 1030(c)(4)(A))

Count 24-27: Interception of Electronic Communications
(Title 18 Section 2511(1)(a))
(Title 18 Section 2511(4)(a))

Oh yeah, and they are going to go for Criminal Forfeiture of all losses.

All the way back in June 2007, Maksik and Segvec are on the way towards losing their e-gold accounts, according to this testimony from US Secret Service agent Roy Dotson, who names e-gold account number 1751848 as belonging to Maksik, and 3584940 as belonging to Segvec.

From that affadavit:


“Segvec”: “Segvec” is a vendor of stolen financial information on the carding
website Makafaka and accepts payment for his contraband in e-gold. A search and review of the e-gold database revealed number 2464856 – which has as its contact name “segvec.” According to information related to me from agents of New Scotland Yard’s National Terrorist Financial Investigation Unit regarding email communications they had with Douglas Jackson in April 2007, Douglas Jackson was aware that “segvec” was a Ukrainian carder.

An analysis of “segvec”’s account number 2464856 yielded the following results:
The account was created in October 2005. There were 93 transfers into the account with a value of 1524.80951 grams ($845,545.60).

20 of the 90 transactions, which total 726.623113 grams ($410,750.00) and occur between February and May 2006, are transfer of funds from account 1751848, “Maksik’s Job”



“Maksik”: “Maksik” is a known vendor of stolen credit card information, stolen
financial accounts, and fraudulent Ukranian passports on the Shadowcrew, Mazafaka, and Carderplanet carding websites and accepts payment for this contraband in e-gold. A search and review of the e-gold database revealed account number 1751848, with the account name “Maksik’s Job,” and contact email addresses of info@maksikjob.com and maksik@maksik.biz. Several memo fields in the transaction record for e-gold account number 1751848 indicate carding activity, including, for example, “1-27 order amex” (i.e., an order for a stolen American Express credit card number), “Happy H4xOr Dumps” (i.e., stolen credit card information), “For 20 classics” (i.e., a type of credit card). A search and review of the e-gold database also revealed e-gold account number 3399565, with the account name “Maksik’s account,” and containing a contact email address of Maksik@maksik.cc. A review of this account also shows many transactions with other e-gold accounts controlled by known carders, including e-gold account number 2567183 (controlled by “Lord kaisersose” – a known vendor of stolen credit card information), and e-gold account number 2874688 (controlled by “u26" – a provider of credit card pre-authorization services to vendors)


Yastremskiy was arrested in Turkey in July 2007, where he remains in jail.

Suvorov was arrested in Germany in March 2008.

Gonzalez was arrested in Miami in May 2008 by the US Secret Service.