Showing posts with label arrested. Show all posts
Showing posts with label arrested. Show all posts

Saturday, June 30, 2018

Memphis BEC Scammers Arrested and At Large

The FBI announced another round of Business Email Compromise arrests this past week.  This time, a focus was in Memphis, Tennessee.  According to the Western District of Tennessee Press Release, "Eight Arrested in Africa-Based Cybercrime and Business Email Compromise Conspiracy", the individuals involved stole more than $15 Million!

The main indictment, originally filed in August 2017, charges 11 individuals with a variety of offenses related to their Business Email Compromise [BEC] crimes.


Count 1: 18 USC §1349.F - Attempt and Conspiracy to Commit Mail Fraud - penalties of up 20 years in prison and fines of up to $250,000, plus supervised release for up to 3 years.

Counts 2-8: 18 USC §1343.F - Fraud by Wire, Radio, or Television - penalties of up to 20 years in prison and fines of up to $250,000, plus supervised release for up to 3 years.

Count 9: 18 USC §§1956-4390.F - Money Laundering - Embezzlement, Other - penalties of up to 20 years in prison and fines of up to $500,000, plus supervised release for up to 3 years.

Count 10: 18 USC §371.F - Conspiracy to Defraud the United States - penalties of up to 5 years in prison and fines of up to $250,000, plus supervised release for up to 1 year.

Count 11-14: 18 USC §10288.A.F - Fraud with Identification Documents + Aggravated Identity Theft - 2 years incarceration consecutive to any other sentence imposed, plus fines of not more than $250,000.

1. Babatunde Martins (Counts 1,9,10,11)
2. Victor Daniel Fortune Okorhi (Counts 1,9,10)
3. Benard Emurhowhoariogho Okorkhi (Counts 1, 2, 3, 9, 10)
4. Maxwell Peter (Counts 1, 4, 6, 7, 8, 9, 10, 11, 14)
5. Dennis Miah - (Counts 1,9,10,11,13)
6. Sumaila Hardi Wumpini - (Counts 1,9,10)
7. Olufolajimi Abegunde (USM # 71343-019), (Counts 1,9,12)
8. Ayodeji Olumide Ojo (Counts 1,9,12)
9. Dana Brady (Counts 1,9)
10. James Dean (USM # 52637-076)  (Counts 1,9)
11. Javier Luis Ramos Alonso, 28,  (USM #24513-111) (Counts 1, 5, 9, 12)

In a separate indictment, Rashid Abdulai, was charged for much of the same, but with his key role being controlling five TD Bank accounts that were used to launder funds.

The primary victim in this case seems to be "Company A", a real estate company in Memphis, who is foolishly identified in the indictment through the carelessness of the author.  I've chosen to redact myself on that, but DAMN!  When you describe the company in such a way that there is exactly one such company on planet earth, you are failing to keep the faith of your victim companies.  Shame!

Fortunately, the indictment also shares a lot of details on the defendants:

RASHID ABDULAI, age 24
a citizen of Ghana, residing in Bronx, New York
controlled at least five TD Bank accounts

BABATUNDE MARTINS, age 62
email: papamart2000@yahoo.com
Company: Afriocean LTD
Nigerian citizen living in Ghana

VICTOR DANIEL FORTUNE OKORHI, age 35 -  *** STILL AT LARGE AND WANTED***
emails:  vicfoko@yahoo.com, VicdarycorriLTD@gmail.com, vicdarycomltd@icloud.com
Company: Vicdary Company LTD
Nigerian citizen living in Ghana

BENARD EMURHOWWHOARIOGHO OKORHI, age 39
emails: Marc.Richards@aol.com, benardokorhi@yahoo.com
Company: Coolben Royal Links LTD
Nigerian citizen living in Ghana

MAXWELL ATUGBA ABAYETA (AKA Peter Maxwell, AKA Maxwell Peter ), age 26
emails: petermaxwell200@gmail.com, sandarlin200@yahoo.com
social accounts: Facebook.com/maxwell.peter.5688
citizen of Ghana

DENNIS MIAH (aka Dennis Brown, AKA Dr. Den Brown), age 34 -  *** STILL AT LARGE AND WANTED***
 emails: JimRoyAirSeal1@yahoo.com, drdenbrown@yahoo.com
social accounts: Facebook.com/Oga.Bossson, Twitter.com/Oga.Bossson
citizen of Ghana

SUMAILA HARDI WUMPINI, age 29 - *** STILL AT LARGE AND WANTED***
email: hardi765_new@hotmail.com
social accounts: Facebook.com/Wumpini.Hardy
resident of Ghana

OLUFOLAJIMI ABEGUNDE, age 31
Nigerian citizen residing in Atlanta, Georgia

AYODEJI OLUMIDE OJO, age 35 -  *** STILL AT LARGE AND WANTED***
Nigerian citizen, lives with ABEGUNDE in Atlanta when in United States

DANA BRADY, aged 61
emails: bradydana50@gmail.com
US Citizen residing in Auburn, Washington

JAMES DEAN, aged 65
US Citizen, residing in Plainfield, Indiana

JAVIER LUIS RAMOS ALONSO, aged 28
Mexican citizen, residing in Seaside, California

D. G. -
emails: d2t2green696@gmail.com, d2t2green696@yahoo.com
US Citizen residing in Mississippi

J.R.
emails: LRIGNWM@yahoo.com
US Citizen residing in New Jersey

M.Z.
emails: CMIMIGO@aol.com
US Citizen residing in Utah

T.W. - US Citizen residing in Tennessee
J.B. - US Citizen residing in Alabama
C.M. - US Citizen residing in Tennessee (Western District)
C.W. - US Citizen residing in Tennessee
A.K. - US Citizen residing in Tennessee (Western District)
V.M. - US Citizen residing in Georgia

How It Worked

Martins, Maxwell, Bernard Okorhi, Victor Okorhi, and/or Miah would get the IP addresses of potentially vulnerable email servers and target them for intrusion.  Using US based IP addresses offered through VPN services, they would access a variety of websites, including credit card transaction processors and dating websites.  Their role in the conspiracy also included originating the spoofed emails that will be explained later.

Martins, both Okorhis, Maxwell, Miah, Wumpini, Brady, Dean, Ojo, and others would open bank accounts for receiving fraudulently-obtained funds and sending them to other accounts controlled by their co-conspirators.  

Because they had control of email accounts at Crye-Leike, they could tell when fund transfers related to real estate sales were scheduled to take place.  They would then spoof the email addresses of those involved in the transactions and send instructions causing the financial transfers to be redirected to accounts controlled by members of the conspiracy.

The funds were then laundered in a variety of ways, including using the funds to purchase goods, including construction materials, cell phones, and other electronics, and having those goods shipped to Ghana for use or resale to benefit the members of the conspiracy.

Maxwell, Miah, and both Okorhis created false identities and created dating profiles with false emails to correspond to their false dating profiles.  Through these, they lured victims into online romance scams, gold-buying scams, and a variety of advanced fee fraud scams.  These romance scam victims would carry out acts on behalf of the conspiracy, including forwarding counterfeit checks, receiving and shipping merchandice, and transferring proceeds via wire, US Mail, ocean freight, and express package delivery services.

Martins, Maxwell, Miah, and both Okorhis also purchased stolen PII, including credit card information, banking information, and IP addresses from underground forums specializing in the sale of such information.

By purchasing cell phones in the United State and activating Voice-over-IP (VOIP) accounts, the US telephone numbers could then be used by the conspirators in Africa, allowing them to appear to be making their calls in the United States.

Some of the activity in this case dates back to 2012, when MIAH was already using fraudulently purchased credit cards and remote desktop protocol (RDP) to make online purchases that appeared to be in the United States.  (Hackers compromise US computers and set them up to use RDP so that foreign criminals can use them to originate credit card purchases in places where the credit card was issued.  By having, say, a Memphis Tennessee IP address, purchases made by a Memphis Tennessee credit card do not seem as suspicious.)

Specific Acts

Some of their crimes were extremely bold.  For example:

"On or about December 13, 2016, MIAH caused construction materials to be purchased with fraudulently obtained funds, and caused a freight container of construction supplies to be sent to him in Ghana."  WHAT?!?!  That's bold!

The compromise of the email accounts at Company A was in play by June 30, 2016, when $33,495 was wired to the wrong location after a tip received from stolen emails.

In August 2016, OJO opened a new Wells Fargo bank account, after his previous account at Bank of America was shut down due to fraud.  He used ABEGUNDE's new address (presumably in Atlanta, Georgia) as the address for the new account.

He also opened a Wells Fargo account in the same address in October of 2016.

Benard Okorhi sent emails as "Marc.Richards@aol.com" directing C.M. to obtain cash advances from credit cards and send the proceeds to recipients in Ghana.  He also ordered C.M. to purchase five iPhones and ship them to Ghana.

Miah used the "DrDenBrown@yahoo.com" email to tell Okorhi (as Marc.Richards) to smooth things out on the phone with a romance scam victim, because Okorhi had a better American accent.

Some of the other interesting "acts" in the conspiracy included:

25JUL2016 - Javier Luis Ramos Alonso accepts a $154,371 wire from Company A into his Wells Fargo account ending in 7688 and then sends the funds to accounts controlled by OJO in Atlanta.

26MAY2017 - Maxwell Peters sends a WhatsApp message directing an undercover Memphis FBI agent to receive a $15,000 check on his behalf.  Ooops!

30MAY2017 - Maxwell Peters directs the FBI agent to send $5,000 of the proceeds to himself in Ghana.

02JUN2017 - Maxwell Peters directs the FBI agent to send a $15,000 check to himself in Ghana.

Although the indictment doesn't lay out more of the particular acts, the Press Release says that this group stole more than $15 Million altogether!

Some interesting images

"M.Z." has an interesting Amazon Wish List for a romance scammer involved in shipping electronics:

On December 8, 2017, Abdulai says is asked in one of his WhatsApp chats:  "Hope Maxwell case didn't put you into any problem."  He responded "FBI came to my house asking me stuff about those transactions that was coming into my account so I'm tryna stay out f this whatapp n stuff for a while cuz I feel like they tracking me."

You got that right, Abdulai!



Monday, June 11, 2018

74 (Mostly Nigerians) Arrested in Business Email Compromise Action

Operation Wire Wire Cases 

Operation Wire Wire was announced June 11, 2018 by the Department of Justice.  This Operation led to the arrest of 42 people in the United States and 29 others in Nigeria, Poland, Canada, Mauritius, Indonesia, and Malaysia.  Not all of the case details have been made public yet, so this will be the first of several Operation Wire Wire blog posts.  What they all have in common is that they are all based on Business Email Compromise scams.


Case One: Okolie and Aisosa

Gloria Okolie ( 1:2018cr00029 ) - indicted in Georgia, arrested in Northern District of Texas on June 7, 2018.  She and Paul Aisosa, both Nigerian nationals residing in Dallas, are accused of laundering $665,000 in illicit funds.

Gloria opened a BBVA Compass Bank account in Addison, Texas in the name G.C. Investments and Logistics, with a $100 deposit.

Paul Wilson Aisosa opened an account at First National Bank of Texas in his own name at a branch in Killeen, Texas.  Someone using the email account 1234trot5@gmail.com sent emails to an attorney in Augusta, Georgia, who wired money from a sale of property to Okolie's BBVA Compass Bank account.  Some of these funds were wired to Paul's account from Gloria's account.

(A Facebook account in the name of Paul Aisosa checked into Dallas in April 2016)


Case Two: Odofuye, Nwoke, and Adejumo 

Adeyemi Odofuye (3:2016cr00232) (AKA Micky, AKA Micky Bricks, AKA Yemi, AKA GMB, AKA Bawz, AKA Jefe), is charged with a seven-count indictment in Connecticut for causing losses of $2.6 million, including $440,000 from a single victim in Connecticut.  (We'll call him Micky.)  According to his Facebook page, and the indictment, he recently graduated with a Masters of Science in Information Systems Security from Sheffield Hallam University.  One of Micky's email accounts was angelmicky_g41@yahoo.com.





















He is indicted in Connecticut along with Stanley Hugochukwu Nwoke (AKA Stanley Banks, AKA Hugo Banks, AKA Banks, AKA Banky, AKA Jose Calderon), who was a student at ApTech Computer Education in Lagos, Nigeria.

The two used a variety of custom domains to conduct fraud against an Austrian company with offices in Connecticut, including: veteranboats.org, messidepot.com, secondtow.info.  With these emails, they requested wire transfers to Technix Trade SP and Weequahic Group Inc.  Some of the funds were transferred to an HSBC account in Hong Kong.

The third party in this case, Olumuyiwa Yahtrip Adejumo (AKA Slimwaco, ACO Waco Jamon, AKA Hade, AKA Hadey) resided at 506 Hampton Avenue in Toledo Ohio.  (We'll call him Slimwaco.)  Slimwaco used his slimwaco@yahoo.com email addresses to communicate with praxes123@gmail.com both by email and Google chat.  He also sent numerous fraudulent emails to a company in Connecticut posing as the CEO of that company and causing five wire transfers to be sent "by his authorization" totalling more than $500,000.  Other emails he controlled included slimwaco@yahoo.com, kkssus@gmail.com, waco4real82@yahoo.com, slimhade@yahoo.com.  According to his Facebook page (in the name Adeola Crown Adejumo), he was originally from Ibadan, Nigeria.

The New Haven-based FBI agent who wrote the criminal complaint describes in detail the types of communications between the accounts, as Slimwaco sent a list of the CFOs of 100 Ohio-based companies to one of his colleagues, and another with more than 100 Illinois-based CFOs.  In other exchange, Micky and Slimwaco chat and help each other build lists of officers from public webpages and corporate directories.

Odfuye (Micky) was extradicted from the UK.  Nwoke was extradicted from Mauritius, the first extradiction from there in 15 years!

Case 3:  Idris, Shitu, Nyamekye, Ibrahim, and Bolorunduro 

The Western District of Pennsylvania announced their own case as part of Operation Wire Wire, namely the arrest of Taiwo Musiliudeen Idris and four co-conspirators.  Idris was one of 29 scammers arrested in Nigeria as part of this operation.  Idris worked with Ismail Shitu, Nathanael Nyamekye, Adnan Ibrahim, and Akintayo Bolorunduro to launder over $411,000 in real estate settlements via BEC.  Their scam primarily targeted residential real estate sellers in Maryland. 

The indictment against these four, (Case 2:17-cr-00192-AJS) was filed October 5, 2017 in Pittsburgh and covers three distinct BEC Scams.

BEC Scam #1 - Rockville, Maryland.  A married couple who were selling a home were anticipating the receipt of a wire for $411,548.06 in proceeds.  However a fraudulent fax caused the funds to be redirected to an account at Citizens Bank in New York, controlled by Ismail Shitu, who resides in the Western District of Pennsylvania.

BEC Scam #2 - Hopkinton, Massachusetts.  A married couple waiting to receive $212,961.75 for the sale of a home had the same experience.  The attorney who was to handle the funds transfer received fraudulent correspondence directing him to send the funds to a Suntrust Bank account in Clinton, Maryland, also controlled by the criminals.

BEC Scam #3 - Charlotte, North Carolina.  A real estate developer sold four parcels of land for $235,058.53.  Once again, the lawyer handling the case received a fax, from the same number as the two cases above, (760) 297-5626, instructing him to send the money to a SunTrust Bank account in McDonough, Georgia.

These funds were then laundered by transfers of funds from $30,000 to $104,000 to various shell companies controlled by members of the conspiracy.   Companies such as "Remy Tire Mart" and "Salem's Market and Grill" and "Sea Gull Freight LLC" and "Stability Capital Group" all received transfers of the funds from BEC Scam #1.

Remy Tire Mart also received funds from BEC Scam #2.  BEC Scam #3 also sent funds to Miken Auto LLC, Labor of Love, and OOPS!  Nathanael Nyamekye, who took $5,000 in an account in his true name.

Case 4: South Florida

We'll continue the Operation Wire Wire reporting as more cases are made public.  In South Florida, 23 individuals have been charged with laundering at least $10 Million from BEC scam proceeds, including 8 from a new indictment unsealed in Miami last week.   Reviewing the three related federal cases will be our next blog topic.

Sunday, May 13, 2018

How to Steal a Million: The Memoirs of a Russian Hacker

As a University researcher specializing in cybercrime, I've had the opportunity to watch the Russian carding market closely and write about it frequently on my blog "Cybercrime & Doing Time."  Sometimes this leads to interactions with the various criminals that I have written about, which was the case with Sergey.  I was surprised last January to be contacted and to learn that he had completed a ten year prison sentence and had written a book.   I have to say, I wasn't expecting much.  This was actually the third time a cybercriminal had tried to get my interest in a book they had written, and the first two were both horrible and self-promotional.  I agreed to read his first English draft, which he sent me in January 2017.

I was absolutely hooked from page 1.  As I have told dozens of friends since then, his story-telling vehicle is quite good.  The book starts with him already in prison, and in order to teach the reader about carding and cybercrime, a lawyer visits him periodically in prison, providing the perfect foil  needed to explain key concepts to the uninitiated, such as interrupting one of Sergey's stories to ask "Wait.  What is a white card?"
My copy of the book!

As someone who has studied cybercrime for more than 20 years, I was probably more excited than the average reader will be to see so many names and criminal forums and card shops that I recognized -- CarderPlanet, and card shop runners such as Vladislav Khorokhorin AKA BadB, Roman Vega AKA Boa, and data breach and hacking specialists like Albert Gonzalez and Vladimir Drinkman who served as the source of the cards that they were all selling.  These and many of the other characters in this book appeared regularly in this blog.  (A list is at the bottom of this article)

Whether these names are familiar to the reader or not, one can't help but be drawn into this story of intrigue, friendship, and deception as Pavlovich and his friends detect and respond to the various security techniques that shopkeepers, card issuers, and the law enforcement world are using to try to stop them.  Sergey shows how a criminal can rise quickly in the Russian cybercrime world by the face-to-face networking that a $100,000 per month income can provide, jet-setting the world with his fellow criminals and using business air travel, penthouse hotel suites, cocaine and women to loosen the lips of his peers so he can learn their secrets., but he also shows how quickly these business relationships can shatter in the face of law enforcement pressure.

The alternating chapters of the book serve as a stark reminder of where such life choices lead, as Sergey reveals the harsh realities of life in a Russian prison.  Even these are fascinating, as the smooth-talking criminal does his best to learn the social structure of Russian prison and find a safe place for himself on the inside.  The bone-crushing beatings, deprivation of food and privacy, and the fear of never knowing which inmate or prison guard will snap next in a way that could seriously harm or kill him is a constant reminder that eventually everyone gets caught and when they do, the consequences are extreme.

Sergey's original English manuscript has been greatly improved with the help of feedback from pre-readers and some great editors. After my original read, I told Sergey "I LOVE the story delivery mechanism, and there are fascinating stories here, but there are a few areas that really need some work."  It's clear that he took feedback like this seriously.  The new book, released in May 2018, is markedly improved without taking anything away from the brilliant story-telling of a fascinating criminal career ending with a harsh encounter with criminal justice.

A purchase link to get the book from Amazon: How to Steal a Million: The Memoirs of a Russian Hacker

The book was extremely revealing to me, helping me to understand just how closely linked the various Russian criminals are to each other, as well as revealing that some brilliant minds, trained in Computer Science and Engineering, and left morally adrift in a land where corruption is a way of life and with little chance of gainful employment, will apply those brilliant minds to stealing our money.

I seriously debated whether I should support this book.  Many so-called "reformed" criminals have reached out to me in the past, asking me to help them with a new career by meeting with them, recommending their services, or helping them find a job.  It is a moral dilemma.  Do I lend assistance to a many who stole millions of dollars from thousands of Americans?  Read the book.  To me, the value of this book is that it is the story of a criminal at the top of his game, betrayed by his colleagues and getting to face the reality of ten years in a Russian prison.  I think the book has value as a warning -- "a few months or even a couple years of the high life is not worth the price you will pay when it all comes crashing down."

Links to selected blog articles that feature Pavlovich's cast of characters:

May 12, 2008 TJX and Dave and Busters - Maksym Yastremskiy (Maksik) Aleksandr Suvorov (JonnyHell) and Albert Gonzales (Segvec) and their role in the TJX Data Breach.

August 5, 2008 TJX Reminder: We Will Arrest You and We Will Send You To Jail - some of the legal aftermath of the case above.

August 8, 2008 TJX: the San Diego Indictments where the US government indicts:
  • SERGEY ALEXANDROVICH PAVLOVICH, aka Panther, aka Diplomaticos, aka PoL1Ce Dog, aka Fallen Angel, aka Panther757
  • DZMITRY VALERYEVICH BURAK, aka Leon, aka Graph, aka Wolf
  • SERGEY VALERYEVICH STORCHAK, aka Fidel
and charges them with violation of "18 USC Section 1029(b)(2) Conspiracy to Traffic Unauthorized Access Devices"

May 9, 2013 ATM Cashers in 26 Countries Steal $40M talks about BadB's role in "Unlimited" ATM cash-out schemes, and his arrest in 2010 and sentencing to 88 months in 2013.

Jan 14, 2014 Target Breach Considered in Light of Drinkman/Gonzalez Data Breach Gang talked about Albert Gonzales, Vladimir Drinkman, and how there seemed to be such a strong pattern of behavior - a script if you will - to how criminals were conducting the major data breaches of that time.

Jan 27, 2014 Roman Vega (CarderPlanet's BOA) Finally Gets His Sentence addressed the plight of Roman Vega, who had been drifting around in the American criminal justice system, unsentenced, from 2003 until 2013! Dmitry Golubov AKA Script, the "godfather of CarderPlanet" is also discussed in this post.



Wednesday, November 02, 2016

NullCrew's Orbit, AKA Timothy French gets 45 months

This week, NullCrew hacker "Orbit" who is known to his jailers as Timothy French, was sentenced to 45 months for his role in several high profile hacking cases, including the University of Hawaii, the University of Virginia, the State Department, and Bell Canada.  The Criminal Complaint released by the Department of Justice has many more details.


For some reason, despite the criminal prosecution, one of the two official Twitter accounts of NullCrew is still live as of this writing.  The founders of NullCrew loved to depict themselves as ASCII Art aliens in their old-school-style ezine, FTS (Fuck The System), which made it to issue #5 before they began being arrested. (FTS Issue #5 is available at exploit-db.com
https://www.exploit-db.com/papers/32984/ )


Time Warner - March 6, 2013





FTS2014 will give you a sense of the way these guys think.  By the way, all of the Twitter accounts they claimed to be using in this magazine are still live today. ( @NullCrew_FTS, @siph0n_NC, and @zer0pwn)

pastebin.com/S0FfCpa2
A few days later they tweeted this post:

15 Jan 2014
Just had a talk with , this is going to be fun.



The 40,000+ userids and passwords, dumped from a database server, are still available online. 


Catching Orbit

Orbit was primarily caught because there was a snitch within NullCrew.  The snitch, described as a "CW" in the criminal complaint, or "Collaborating Witness", wanted to be able to tweet "officially" for NullCrew, and was granted permission to the shared Twitter account.  Once the CW had access, they checked the login history and found an IP address in Morristown, TN.   Charter Communications was able to provide a subscriber street address for the IP 24.151.251.118.  This IP came up repeatedly in the course of the investigation, being used to plant a hacked .php page on a University server, regular accessing a shared hacking platform in Chicago and more in hacked business accesses.

My favorite story, however, was of the auto accident.

(Updated: the admins of siph0n.net contacted me to make clear that their site has no association with siph0n the NullCrew member.  We've removed that portion of this article at their request.)


Getting to the Sentence

Part of the defendant's problem as sentencing approached was that Mr. French, who goes by the name "TJ" for "Timothy Justen", boasted over much about his association with many truly evil hackers over the years.  TJ claimed, according to his pre-sentencing memo, did claim to be a member of Team Poison, but denied emphatically that he had been involved with the TeamPoison April 2012 hacks against NATO and the United Nations, and the August 2011 hacks against NASA.  TeamPoison was run by Trick, aka Junaid Hussain, who was recently killed by a Hellfire Missile strike after becoming the leader of ISIS's hacking forces, and repeatedly hacking the Department of Defense.

Zer0pwn, one of the other arrested members of NullCrew, updated his Twitter profile to give as his description  "victim of sabu's wrath" implying that perhaps Sabu was involved with their arrests.

Facing a possible seven year sentence, one of the things the defendant appealed to was the relatively lenient sentences for people who had performed similar crimes.  TJ's attorney appeals to cases such as Nicholas Knight (from Team Digi7al) who confessed to hacking DHS, the National Geospatial Intelligence Agency, and assorted universities and businesses but was only sentenced to 24 months.  He lists several other cases, but comes back to a 17-year old hacker who also received only 24 months, concluding:

"This 24-month sentence alone compels a sentence for TJ far below the government's asserted guideline range in order to avoid unwarranted disparities."  (We wrote previously about how these "slap on the wrist" sentences were leading to others charging "unwarranted disparities" on behalf of their clients.   See: "Hacking, Carding, SWATting and OCD: The Case of Mir Islam

Several of my professional colleagues have commented that this sentence seems to hefty, but they were unaware of the extent of the damages to Bell Canada.  While Null (the Quebec citizen) identified the breach potential, it was Mr. French that took that information and used it to rampage through the files of Bell.ca.  "According to prosecutors, million of files were exfiltrated and 300,000 of them contained client information. At the time of the hack, Bell Canada said 22,421 login and password combinations along with five credit card numbers were exposed, but court documents indicate the number was smaller. Orbit later allegedly posted approximately 12,700 logins and passwords online and Tweeted a link to the data."

Sunday, October 09, 2016

Backpage.com, Human Trafficking, and Free Speech

Charges Against Backpage

Earlier this week the states of Texas and California worked together to have the CEO of Backpage.com arrested. The charges were brought in California, who issued the arrest warrant for CEO Carl Ferrer, who was then arrested in Texas. The cause of the arrest was that by running a website that profited heavily from the sale of sexual services, through the "escort" section of his website, Backpage was profiting from prostitution and human trafficking. 

The Dallas AG's press conference regarding the arrest is here:

Dallas was a good venue, because the company's headquarters are actually in Dallas, Texas.  The CEO was arrested at the airport as he returned from an international trip.

Kamala Harris, the California Attorney General, shares her announcement here:


California brought the charges primarily because Backpage.com made more money on their escort services from selling women and children in California than in other states.  In addition to charging CEO Carl Ferrer, California brings charges against controlling stock-holders, Michael Lacey and James Larkin.  Ferrer, Lacey, and Larkin are charged with operating a "Pimping Conspiracy" from 2010 through 2016.   Among the specific charges brought in the 9 page Criminal Complaint against Backpage.com are that although most sections of Backpage.com are free -- there is no charge to post an advertisement there -- the Escort service DOES charge to place ads, and in California, these ads generate more than $2 Million PER MONTH in profits just in the state of California.  Yes, ALMOST ALL of the revenue for Backpage.com is generated by its ads for escort services!

Furthering the conspiracy, however, is the fact that the same trio also operate other prostitution-oriented websites, EvilEmpire.com, an "escort directory service" and BigCity.com, an app for android and iPhone that provides profiles of those listed on EvilEmpire. (EvilEmpire currently has 1300 profiles claiming to be in Birmingham, Alabama!)   

The California charges then go on to include several violations of California Penal Code section 266h(b)(2), Pimping a Minor Under 16 Years of Age, and several additional violations of 266h(b)(2)/664, "Attempted" Pimping of a Minor Under 16.

Backpage and Law Enforcement

I've met the Backpage lawyer featured in this Anderson Cooper video. She used to defend CraigsLists adult services. She was at a law enforcement conference I attended in Singapore, and she said she was there to try to build law enforcement contacts because they wanted to be "the best ally possible" for law enforcement:



In 2011, Backpage received a letter signed by 46 Attorneys General asking Backpage to clarify 20 points of contention with regards to its advertising, monitoring of, and profiting from, the advertisement of prostitution.


The letter also mentions that CEO Carl Ferrer told Washington's Attorney General that at that time they were removing around 400 advertisements per month on suspicion that they involved underage minors.

Backpage and Freedom of Speech

The website has already been hit with a federal lawsuit -- but then the lawsuit was dismissed, and on appeal, it is clear that the "Freedom of Speech" crowd is pro-Human Trafficking.

Here is how the judge who heard the appeal opened her 37 page judgement:

"This is a hard case — hard not in the sense that the legal issues defy resolution, but hard in the sense that the law requires that we, like the court below, deny relief to plaintiffs whose circumstances evoke outrage. The result we must reach is rooted in positive law. Congress addressed the right to publish the speech of others in the Information Age when it enacted the Communications Decency Act of 1996 (CDA). See 47 U.S.C. § 230. Congress later addressed the need to guard against the evils of sex trafficking when it enacted the Trafficking Victims Protection Reauthorization Act of 2008 (TVPRA), codified as relevant here at 18 U.S.C. §§ 1591, 1595. These laudablelegislative efforts do not fit together seamlessly, and this case reflects the tension between them. Striking the balance in a way that we believe is consistent with both congressional intent and the teachings of precedent, we affirm the district court's order of dismissal. The tale follows. . . "

The law that makes this all legal, from the Federal side, is "47 U.S.C. § 230" which is the law that protects websites from being responsible for the things that third parties post on their servers. The full judgment in that lawsuit is here:


The EFF (Electronic Frontier Foundation) and the CDT (Center for Democracy and Technology) both argued in favor of Backpage in amicus briefs, and Forbes magazine foolishly went along with their headline "Big Win For Free Speech Online In Backpage Lawsuit" -- (click image for story)


http://www.forbes.com/sites/ericgoldman/2016/03/17/big-win-for-free-speech-online-in-backpage-lawsuit/

So "Free Speech" wins and our young woman get trafficked. I'm shocked that Forbes finds this a thing to celebrate!

Federal Responses to BackPage CEO Arrest

One of the champions against Human Trafficking on Capital Hill is Congresswoman Ann Wagner from the 2nd District of Missouri.  She is the sponsor of the Stop Advertising Victims of Exploitation Act (SAVE Act).  In many ways you could say the SAVE Act was written in response to Backpage.com.
https://www.youtube.com/watch?v=5vZAaOClo0M
 Wagner's SAVE Act became law with the passage of Senate Bill 178 - Justice for Victims of Trafficking Act of 2015, when it was signed by President Obama on May 29, 2015.  What her section of the law does is just adds the word "Advertising" to an existing law, 18 U.S. Code § 1591 - Sex trafficking of children or by force, fraud, or coercion.



We'll have to wait to see whether this new language gets used in Federal court sometime soon.  In this case, the big question with regards to 18 USC Section 1591 would be "who did the advertising?"  We already know that BackPages will say they are a neutral third part who allows OTHERS to advertise.

Senator Porter is also leading the charge from the Senate side.  In November 2015 he held hearings about Backpage and subpoenaed CEO Carl Ferrer to appear before the commitee.  When Ferrer refused, Contempts charges were filed against him (with a 96-0 vote in the Senate to sustain the charges.)  In his Senate Report about BackPage.com, he points out that in 2013, 80% of all revenue from advertising escort services in the United States was believed to have been generated by Backpage.com, and that according to the National Center for Missing and Exploited Children (NCMEC), 71% of the alerts they receive from members of the public about possible sex trafficking of underage persons has a Backpage.com nexus.  The report also points out that American Express, Visa, and MasterCard refuse to allow their cards to do business with Backpage.com, due to their illegal or "brand damaging" activities.  Although Backpage claims that 120 of its 180 employees do nothing but edit and filter ads on the site, NCMEC has documented 400 cases in 47 states of children being trafficked via Backpage.com.


(196 report from Portman/McCaskill)
Although the main body of the report is only 33 pages, the 196 page report from Senators Porter and McCaskill contains a great deal of additional interesting reading, if this is a topic of interest.  One document that is cited second-hand is a report by researcher Danah Boyd called "Combating Sexual Exploitation Online: Focus on the Networks of People, not the Technology."  I agree, focusing on the people is a key, but does that mean we continue to allow our children to be advertised in the meantime?

 Statements issued after the Arrest of Backpage.com's CEO:

 One Example Sex Trafficking Case 

https://www.ice.gov/news/releases/ice-investigation-results-17-sex-trafficking-indictments-minnesota

In this case, announced 05OCT2016, a group smuggled sex workers in from Thailand to the United States and kept each woman confined in a house of prostitution until they were able to pay off their "bondage debt" of between $40,000 and $60,000.  Hundreds of women were held in this way.  Each "house manager" would choose the best way to advertise the women, but many chose the websites backpage.com and eros.com.

Sunday, January 24, 2016

Vovnenko / Fly / MUXACC1 pleads guilty

Sergey Vovnenko pleads guilty

This week a Ukrainian hacker made famous for attempting to frame security journalist Brian Krebs by sending him heroin purchased on the Silk Road, had his day in court and chose to plead guilty.  Krebs blogged about his arrest in Italy in 2014 with the title The Fly Has Been Swatted, but now that a guilty plea has been entered, we can see the details of the case.

In June 2013, a U.S. Secret Service agent swore out a criminal complaint against Vovnenko for crimes he committed against citizens in New Jersey.  Although we refer to "Federal Crimes" in most cyber crimes, charges can only be brought for damages local to the U.S. Attorney's office where the prosecution makes the charges.


From 2003 until 2013, the complaint states, SERGEY VOVNENKO, AKA Centurion, AKA Flycracker, AKA Flyck, AKA MUXACC1, AKA Stranier, ran various scams related to carding.  In a specific instance, cards were stolen "on or about" March 14, 2011 from a victim in Rutherford, NJ, violating Title 18 Section 371 of the Federal Code.  Many of the early attacks used SQL Injection to gain access to target computers that were accessible via the web and had access to databases of personally identifiable information and credit card data.  Vovnenko in particular advertised "dumps" services using both his Twitter account and an ICQ account.

Between 2009 and 2011, Vovnenko managed to plant malware on computers at "Victim 1" which is described as a "global financial institution with millions of customer accounts" that "maintaned signficant infrastrucutre in New Jersey, including computer servers housing banking information located in New Jersey."

Vovnenko was an old-school carder.  He originally sold his dumps on the Shadowcrew website, which was shut down in 2004 by the U.S. Secret Service.  (This site is where Vovnenko began chatting with now infamous Data Breach king Albert Gonzalez.)  In 2008, Vovnenko used ICQ to chat with Vladislav Horohorin, the hacker known as "BadB."  BadB was sentenced to 88 months for trafficking in stolen cards and for his role in the $9M theft from Atlanta-based RBS WorldPay.  By 2010, Vovnenko was actively selling as "Centurion" on CardingWorld, Mazafaka, and Verified.ru.

Our complaintant testifies that on or about March 16, 201, Vovnenko chatted with another criminal who asked him to review his logs from his botnet to see whether he had IP addresses indicating that some of his bots were in the NJ-based Financial Institution known as "Victim 1" in the court documents.  He did, and was asked to plant an executable on that computer to give his co-conspirator remote control to the computer.  (We've heard about this type of "log selling", where a "commodity botnet infection" leads to targeted attacks at specific institutions before.  See my blog post about the Fox-IT/Group-IB "Anunak" report, "Botnets, APTS, and Malicious Emails")

A "Zeus Logs" seller offers 240MB of logs for $300-$400 ...

A Criminal Complaint is only intended to show Probable Cause to open an investigation.  It does not require the same level of details as an Indictment, which charges the accused of committing specific criminal acts.

The Indictment came in April of 2014 ...

The Indictment adds additional aliases (Tomas Rimkis, Darklife) and specific charges.  We'll focus on Charge One and Three, which are the ones he pleaded guilty to this week.

Count One:  Wire Fraud Conspiracy (18 u.s.c.§1349)
From September 2010 to August 2012, VOVNENKO and his co-conspirators "operated an international criminal organization that hacked into the computers of individual users and of companies in the United States and elsewhere, and used that access to steal data, including, among other things, user names and passwords for bank accounts and other online services, as well as debit and credit card nubmers and related personal identifying information.   After stealing the Log-In Credentials and Payment Card Data, defendant VOVNENKO and his co-conspirators used that information to illegally access and withdraw money from bank accounts and to incur unauthorized charges using the payment card data."  They also sold the data using online forums to individuals and groups that in turn did other illegal things with the data.

The indictment states that VOVNENKO had a botnet of "over 13,000 computers infected with malware" and that several of the infected computers were in New Jersey.  At least part of the malware was the "Zeus" malware that specializes in stealing banking information and recording keystrokes of users.  At least one employee (known as "J. H." in the indictment) of the Victim 1 bank had his workstation infected and from that base, the botnet was able to contact and interact with computers located inside financial institutions.  Counts Three through Six of the indictment refer to the specific acts of logging in to J.H.'s computer "in related to felony violations
18 U.S.C.§1349 and 18 U.S.C.§1030(a)(2)(C) and (c)(2)(B)(i)



By December of 2015, Vovnenko and his lawyers knew he was going to be found guilty on all charges, no ifs, ands, or buts.  They agreed to a plea agreement where Vovnenko took the rap for Count One and Count Three, agreeing that he could face a sentence of 20 years imprisonment and $250,000 fine.  Because he also faced the charge of Aggravated Identity Theft, there is an additional two year mandatory minimum sentence that cannot run concurrently with any other sentence.  Further, VOVNENKO understood that he may be required to pay restitution, and will likely be deported after his sentence is served.

Sentencing in this case is set to May 2, 2016.  At that time, a Money Judgement will also be made regarding the amount of Restitution that may be required.

Many more details about "Flycracker" (as he was known on Silk Road) or "MUXACC1" (as he was known on Twitter) are available from Brian Krebs' story "Hacker Who Sent Me Heroin Faces Charges in U.S."








Monday, August 24, 2015

Darkode guilty pleas: Phastman, Loki, & Strife


So far there have been three guilty pleas related to the Darkode hacking forum.  Although the case, which used the name "Operation Shrouded Horizon" resulted in 70 arrests worldwide, only twelve individuals have been indicted so far by the Department of Justice, and several of those individuals are overseas.  When the site was taken over, it displayed this graphic, showing the many foreign law enforcement agencies that cooperated with the takedown and the arrests.


Johan Gudmunds / Mafi

Image from ArrestTracker

The main administrator of Darkode is Johan Anders Gudmunds.  Gudmunds used three hacker aliases: Mafi, Crim, and Synthet!c.  According to DOJ, he resides in Sweden.   According to the indictment "From around September 2008 until about January 23, 2015" Gudmuns "knowingly and willfully did aid and abet and conspire, combine, confederate and agree together with other persons" ... "to commit offenses against the United States" including:

  • intentionally accessing a computer without authorization and exceeding authorized access to a protected computer, committing the offense for purposes of commercial advantage and private financial gain in furtherance of a criminal and tortious act in violation of the Constituion and the laws of the United States to obtain a thing of value exceeding $5,000 -- 18 USC Sections 1030(a)(2)(C) and (c)(2)(B)(i)-(iii).
  • knowingly and with intent to defraud accessed a protected computer and by means of such conduct intended to commit fraud or obtain something of value -- 18 USC Section 1030(a)(4) and (c)(3)(A)
  • knowingly caused the transmission of a program, information, code, and commands that as a result of such conduct intentionally caused damage affecting 10 or more protected computers during a 1-year period -- 18 USC Sections 1030(a)(5)(A) and (c)(4)(B).
  • knowingly and with intent to defraud trafficked in passwords and similar information through which a computer may be accessed without authorization affecting interstate and foreign commerce -- 18 USC Sections 1030(a)(6)(A) and (c)(2)(A).
Gudmunds wrote a botnet called "Blazebot" that compromised computers that he later sold access to. His price for access was $80 per 1,000 compromised machines, or 8 cents per computer.  Yes, that is how much your PC is worth!  Gudmunds also sold root access on computers at universities in Europe for $50 per server, and to at least 200 other servers for between $10 and $50.  The Zeus malware that he controlled logged more than 200,000,000 credential thefts from 60,000 compromised computers that made up his botnet.  (This would include many repeated credentials, obviously.)  Gudmunds also wrote an Exploit Kit called "CrimePack" that he sold on his forum, as well as an MSN Messenger spreader.  He was still authoring and selling code much more recently, including his package called "Pandemiya 2014"

Some of Gudmunds online ids included the jabber account "mafioso@xmpp.jb" and the email account "mafi@thesecure.biz".  He began using the Synthet!c alias in January 2012.


Daniel Placek / Loki

According to the Gudmunds indictment, the original Darkode.com forum was created by "Iserdo" and "nocen / Loki".  We know from the charges against Daniel Placek of Glendale, Wisconsin, that he was the one who used the aliases Nocen, Loki, Juggernaut, and M1rro0r.

Loki's charges say that "in or about June 2008, Daniel Placek and Martjaz Skorjanc (AKA Iserdo)  created the Internet forum with the domain darkode.com with the intention of bringing together computer hackers and other criminals to facilitate the production and sharing of malicious software, and later led to forum discussion about the creation and dissemination of botnets and the sending of spam."   Placek was an administrator on the forum, and in January 5, 2010, agreed to sell malware that he designed for harvesting network traffic for email addresses and passwords to a user named Dethan.78 for $500.  Dehtan.78 was an FBI agent.  Oops!

When Placek's computer was raided, all the way back in 2010, it was found to contain 74,190 credit card numbers and 297 bank account numbers.  In his guilty plea on July 31, 2015, Placek agreed to plea to one charge in exchange for prosecutors agreeing to seek a sentence of "six to twelve months".  This agreement carefully considered the fact that Placek has provided full cooperation regarding law enforcement queries and access to Darkode FOR MORE THAN FIVE YEARS!

From all reports, Placek has left his black hat ways behind him and has not participated in crime since his 2010 activities.   He has been working as a network engineer for a company named Swick Technologies, and neither law enforcement nor his employer has had any reason to doubt that he is reformed.  (More from this article:  Placek to plead guilty for role in creating Darkode hacker marketplace  )

Eric Croker AKA Phastman

Eric L. Crocker, a 39-year old resident of New York, (some sources say 29) was the first to plea guilty from the charges that came out of the Darkode forum seizure.  His primary plea is that he violated the CAN-SPAM ACT.  Phastman's primary activity that he is charged with is the creation of a hacking tool called the Facebook Spreader.  Although he is only directly charged for breaking into "at least 77,000 computers" and his indictment indicates he sold access to computers his botnets controlled for $200 to $300 per 10,000 (2 to 3 cents per machine) some news sources are reporting that his hacking earned Crocker "upwards of $21 Million." 

Phillip Fleitz, AKA Strife

Phillip Fleitz photo from ArrestTracker
 Phillip Fleitz was the most recent person to plead guilty on the Darkode case.  Fleitz is named along with two others in an indictment from the Western District of Pennsylvania.  The three were:

  • Naveed Ahmed (AKA "Nav" AKA "Semaph0re")
  • Phillip R. Fleitz (AKA "Strife")
  • Dewayne Watts (AKA "m3t4lh34d" AKA "metal"
The conspiracy that these three are charged with involves leasing at least two "bullet-proof hosting" servers in China that were used to scan Internet-connected routers to identify places that would allow them to use those routers as Proxies to reroute commercial email messages to hide their true source.  The spam that was sent was primarily using "email-to-SMS gateways" so that the emails sent would show up as text messages on cell phones of the recipients.  The spam was primarily "gift card scams" with the indictment giving the particular example of Best Buy Gift Card spam.  A couple examples include:
  • "Congratulations, your 4th place code is H7G0 - BestBuyVouchers.com"
  • "Congratulations! You've finished Fifth!  Your code is: WM154 - FreeBestBuyCards.net"
  • "Your entry placed 8 out of 10!  Claim the prize with this Code: U0V2 - BBCodeTexts.net"

Still to Come

The people who are still named by the Department of Justice, but have not yet plead guilty are:

  •     Johan Anders Gudmunds - see above
  •     Morgan C Culbertson - the "FireEye Intern" / Carnegie Mellon student
  •     Naveed Ahmed -
  •     Dewayne Watts - M3t4lh34d / metal
  •     Murtaza Saifuddin
  •     Matjaz Skorjanc - rzor from Pakistan
  •     Florencio Carro Ruiz - NetK, Netkairo from Spain
  •     Mentor Leniqi - Iceman from Slovenia
  •     Rory Stephen Guidry - selling botnets, k@exploit.im
 Of those, the only individual who has received much US-based press was Morgan, who is the author of a Remote Administration Trojan known as Dendroid.            





If any more guilty pleas come through, we'll try to update this page!

By the way, much praise to a site I was not previously familiar with called "Arrest Tracker" from the people that run CyberWarNews.info.  His page "Mass Arrest #24"  here has a great summary of what's going on with Darkode, but I know many of my readers will be interested in regularly following the regular updates from his page!




Monday, June 02, 2014

Is the Game Over for GameOver Zeus?

Several weeks ago law enforcement friends in Pittsburgh started asking people not to publish anything too public about GameOver Zeus. When we asked why, we got a teasing "You'll see!" Now our ISP friends that were participating in the effort are grinning ear to ear as we may actually have a chance to disrupt Zeus in a meaningful way. Being a legal geek, I was excited to have the documents published on the main Justice website today at www.justice.gov/opa/gameover-zeus.html.

The Complaint against Evgeniy Mikhailovich Bogachev aka Slavik, aka Pollingsoon was unsealed in court where the Pittsburgh FBI led the investigation into CryptoLocker and GameOver Zeus. In addition to Bogachev, charges are filed against several aliases of as-yet-unidentified hackers, "Temp Special", "Ded", Chingiz (aka Chingiz 911), and Mr.KyKyPyKy. The Complaint charges that "Together, GOZ and Cryptolocker have infected hundreds of thousands of computers around the world and have generated losses that exceed $100 million."

Some of the specific cases mentioned in the complaint include:

  • A composite materials company in the Western District of Pennsylvania which lost more than $198,000 from its bank account using credentials stolen by the Defendants through the use of GOZ; (The Pittsburgh Indictment shares more details, telling us this was Haysite Reinforced Plastics, whose PNC Bank account was fraudulently accessed and used to send their money to a Mule account in the name of Lynch Enterprises, LLC, at SunTrust Bank in Atlanta, Georgia, after they clicked on a NACHA email informing them their ACH payment had failed, in October 2011. They also transfered $175,756.91 to an account belonging to R&R Jewelers, and ATTEMPTED six additional transfers, all on October 20, 2011. The money in the SunTrust account was quickly moved on ($99,822 of it, anyway) to an HSBC account in London.)
  • An Indian tribe in Washington - $277,000
  • A corporation managing assisted living facilities in Pennsylvania - $190,800
  • A regional bank in Northern Florida - $7 Million
CryptoLocker is described separately as having "first emerged in mid-to-late 2013" and infected "more than 230,000 computers, including more than $120,000 in the United States.

Just between October 15, 2013 and December 18, 2013, we know that $27 million in ransom payments were made, just by tracking the ransom payments made using Bitcoin!

The charges in the criminal complaint are:

Count I: Wire fraud: 18 USC Section 1343 "Having devised a scheme or artifice to defraud and for obtaining money by means of false or fraudulent pretenses and transmitting and causing to be transmitted by means of wire communications in interstate and foreign commerce, writings, signs, and signals for the purpose of executing such scheme or artifice.

Count II: Bank Fraud: 18 USC Section 1344 "knowingly executing a scheme or artifice to defraud financial institutions insured by the FDIC and to obtain moneys under the custody and control of these institutions by means of false and fraudulent pretenses and representations.

Count III: Unauthorized interception of electronic communications: 18 USC Section 2511 "intentionally intercepting electronic communications, and intentionally using and endeavoring to use the contents of the electronic communications knowing that the information is obtained through the unauthorized interception of electronic communications."

all of which, according to 18 USC Section 1345(a) and (b) allows Injunctive Relief to prevent a continuing and substantial injury to the owners and legitimate users of the infected computers.

An FBI Pittsburgh cyber agent was the affiant in the 28 page Application for Temporary Restraining Order recounts that while the largest known single wire transfer was a $6.9 million wire, fraudulent wires in the amount of $1 million dollars were "very common." A single bank experienced 11 fraudulent wires, with six being for more than $950,000 and the largest being 2 million dollars!

The GOZ affidavit mentions a few email addresses, Bogachev uses as one email address, bollinger.evgeniy@yandex.ru, while Chingiz 911 uses charajiang16@gmail.com. Seeing the nickname "Ded" as one of the members of the gang, I can't help but recall "Ded Pixto" the nickname for Stanislav Avdeiko the Koobface malware author.

So how will this "takedown" actually work? First, some hard work by a couple genius malware reverse engineers at Dell Secure Works and CrowdStrike helped the Pittsburgh FBI agent to understand the current Command & Control infrastructure so it could be rendered harmless. The problem though, is that both GOZ and Cryptolocker have a built-in backup plan in the form of a Domain Generation Algorithm. The job of a DGA is to allow the botmaster to IN THE FUTURE reconnect to his bots using infrastructure that neither the bots nor the botmaster have even created yet. A formula is used to calculate a domain name based on a timestamp. So, if NONE of the hard-coded IP addresses are able to be reached, the bot will look up the current date and begin "guessing" domains that the criminal may have registered for use to update the bot with new hard-coded addresses. As a few examples, on July 1, 2014, CryptoLocker will try to connect to 1,000 domains, including:

wncbbejfurrw.net
kbdnkmpgxlxh.biz
aevmpupnouqy.ru
nrwyydvorowj.org
bvgurlkgcwya.co.uk
ojhhbtqhfqfk.info
eqcoayuicfrp.com
fsdnbhyofoiv.net
fimwcppbphaq.biz
gknvdxthsqqw.ru
iygiqgvjjkys.org
jbhhroapmtpy.co.uk
jqqqswqcwmht.info
ksrptfuiavxa.com
klrmfgyihrch.net
xysyolodvgen.biz
mgcjywthscyu.ru
atdvicjchqbb.org
otvgvnajowjk.co.uk
The Temporary Restraining Order (TRO) seeks an Order that:

1) directs four U.S. based internet domain Registries to block access to around 900 PAGES of domain names seemingly the "future" list of DGA-generated domain names for CryptoLocker and GOZ. The GameOver Zeus domains are listed in Appendix A while the CryptoLocker domains are listed in Appendix B. Because ICANN only has jurisdiction over the Generic TLDs, this approach doesn't work for the ".ru" domains. CryptoLocker also uses ".co.uk" domains, so one would hope that the British government has asked for a similar favor from their counterpart registries. The four Registries in the US were, VeriSign, Inc., representing .com and .net, Neustar, Inc., representing .biz, Affilias USA, Inc., representing .info, and Public Interest Registry, representing .org.

Appendix A actually contains 25,937 domains for Game Over Zeus, arranged in ten columns, with three columns of domains listed on pages 1-69, 70-138, 139-207, and then a single column on pages 208 to 276. Its actually seven columns of 2594 domains and three columns of 2593 domains or 25,937 domains for Game Over Zeus.

Appendix B has six columns on pp. 1-176, pp.177-352, and then six columns of various length from 353 to the end of the 704 page document, for a total of 130,421 domains for CryptoLocker.

Affilias, Neustar, Verisign, and Public Interest Registry are ordered to redirect all of those 156,000 or so domains to use the nameservers ns1.kratosdns.net and ns2.kratosdns.net, preventing the criminals from using those domains to re-establish control of their botnet.

2) directs the twenty largest ISPs in America to not allow access from their networks to the .RU domains that the DGA can make, as the .RU domains are not under ICANN control. The ISPs named here are:

Cablevision, AT&T, Cox, Comcast, Mediacom, AOL, Frontier, Sprint, Time Warner Cable, Verizon, Charter, CenturyLink, Suddenlink, Wide Open West, Windstream, Level 3, Armstrong Group of Companies, Bright House, Earthlink, and NTT America.

Those ISPs are forbidden to allow traffic to the .ru domains listed in Appendix C.

3) To redirect all traffic intended for one of those domains to .gov controlled servers

and

4) to seek a Pen Register/Trap and Trace Order that would gather information about the nodes directed to those replacement boxes, and to share that information back to the ISPs and victims to help protect themselves. This "Dialing, Routing, Addressing, and Signaling" data (called DRAS in telephone-legalese) is to be turned over to the government so that attempts can be made to clean up these victims computers.

In cooperation with these efforts, McAfee is providing their "Stinger" program to be used by any victims to clean and remove GameOver Zeus or CryptoLocker infections.

All of that is now in play ... it is too early to tell if the game is really over, but best of luck and congratulations to the fine agents and CCIPS lawyers who made this possible!