Sunday, July 18, 2010

The Future of Cyber Attack Attribution

On July 15th, the US House of Representatives' Committee on Science and Technology's Subcommittee on Technology & Innovation held a hearing called Planning for the Future of Cyber Attack Attribution.

I was drawn to the topic, having a great deal of experience with the puzzles of finding bad guys on the Internet who need badly to spend some time deprived of freedom as a consequence for their actions. Unfortunately, the hearings really stressed the problem that using technology to make attribution certain creates human rights issues around the globe. Conversely, the creation of privacy tools can grant bullet-proof privacy to child pornographers, terrorists, and cyber criminals.

Finding almost no mention of this hearing in any media source, I wanted to at least give a brief outline of what happened.

Chairman David Wu, an advocate for cybersecurity, and co-author of the excellent Cybersecurity Enhancement Act of 2010, made the Opening Statement to kick off the hearings, putting this hearing in context in the overall series of hearings on cyber threats that have been held over the past two years. Wu said that "Now more than ever, we need to be focused on the development of tools and technologies to prevent, detect, and respond to cyber attacks." Wu went on to say that one method of deterrence, the focus of the hearings on this day, was "the ability to attribute an attack to a particular person, party, or system" and that this could be "vital to defending against cyber attack." The desire for attribution though was tempered by a reminder that Chairman Wu was "personally very concerned about the potential implications to privacy and internet freedom posed by attribution technologies."

Mr. Wu had to apologize for the lack of attendance by his committee, but ensured the panelists that the full committee will have read their written testimony, although at least one attending member admitted he had "browsed through" their testimony and "read some of it." It seems that only seven Congressmen were able to attend.

Each of the four witnesses below had been given four questions to answer in their written testimony:

Q1: As has been stated by many experts, deterrence is a productive way to prevent physical attacks. How can attack attribution play a role in deterring cyber attacks?

Q2: What are the proper roles of both the government and private industry in developing and improving attack attribution capabilities? What R&D is needed to address capability gaps in attack attribution and who should be responsible for completing that R&D?

Q3: What are the distinguishing factors between anonymity and privacy? How should we account for both in the development and use of attribution technologies?

Q4: Is there a need for standards in the development and implementation of attack attribution technologies? Is there a specific need for privacy standards and if so, what should be the government’s role in the development of these standards?



The video of the spoken testimony and Q&A is available. I encourage interested parties to avail themselves of the video and the written testimony. The notes below are my personal "sketchy" notes as I tried to reduce an hour of video and 150 pages or so of testimony into a blog entry.

The witnesses for the hearing were each given five minutes to make an opening statement. I took a few notes below, but would again recommend interested parties to the originals:

Dr. David A. Wheeler

- the Institute for Defense Analyses: Information Technology and Systems Division - I have to say that Wheeler's written "testimony" was quite disappointing. Introduced into a Senate hearing in 2010 is Wheeler's 85 page DARPA paper for the "Defense-Wide Information Assurance Program" called "Techniques for Cyber Attack Attribution", which was an excellent, thorough, and timely report, when it was authored in October of 2003. While it does provide a nice framework for possible forms of attribution, the paper is about fifty years old in "Internet years", making the relevance of much of the paper questionable. It was the only one of the four responses that actually talked about what could be done technologically with attribution, but most of the papers cited as references are from the late 90s or early 2000s, including things like Staniford-Chen's work from 1995, Stefan Savage's work from 2000 on "IP Network Traceback", and Jelena Mirkovic and Dave Dittrich writing about DDOS attacks in 2001. Good stuff, but quite dated.

The paper in fact specifically excuses itself from addressing nearly every modern form of cyber attack when it declares (p. 20 of the testimony):

This paper does not cover identifying or locating people who are not DIRECTLY ATTACKING the defender.


So, if they are attacking via a botnet, via a proxy, via malware already installed in the attacking organization, this paper doesn't address any of that. It also excludes itself from social engineering, determining HOW an attacker attacked. Another useful feature of this particular "testimony" is that most of the URLs referenced in the paper don't work. Nice.

Dr. Wheeler began his spoken testimony by cautioning about 4th amendment protection from "unreasonable search". One point he made was that if we cannot make attribution, then there is no chance of making a successful counter-attack, either over the network or using a "kinetic attack."

Mr. Robert Knake

- International Affairs Fellow at the Council on Foreign Relations. Mr. Knake started his spoken testimony by saying that the problem of attribution is "largely overstated", and went on to say that no more than 100 groups, and possibly as few as FOUR possess the capability to cause "real world" harm through cyber attacks.

Knake suggests that labeling all packets with a so-called "Internet license plate" would be more useful for authoritative regimes to deny their citizens any anonymity or freedom of speech, while criminals would probably find a way to work around these identifying mechanisms. He also gives the current example from China that even when we positively identify the attacking system, the owner of the system, or in this case the Chinese government, can say that while the attack traffic originated on that system, it was probably a case of that system having poor security itself and being used as a proxy. Because of the lack of our ability to overcome these doubts, attribution will likely never reach a level where a kinetic counter-attack can be justified.

Mr. Knake's Written Testimony contained one fairly interesting graphic, which I share here:



Mr. Knake's written testimony asks three main questions:

- what degree of certainty in attribution is necessary to take action?
- what would that action look like?
- how will we make potential adversaries understand the answer to those questions - because if they don't understand, they will not be deterred!

He goes on to discuss espionage, crime, terrorism, and the fact that you can't actually LEGISLATE this successfully, mentioning that the CAN-SPAM act made it a law that email marketers are required to "attribute" emails to themselves, yet 9 of every 10 emails on the Internet do not do so!


Mr. Ed Giorgio

- President and Co-Founder of Ponte Technologies - Mr Giorgio's testimony spoke of the need for Internet users to be allowed to create as many identities as they like, with some certificates positively identifying the real user, while other certificates guaranteed their anonymity or privacy. Mr. Giorgio said that a "trusted third party" would have to take the role of assigning these certificates, as government had so far not demonstrated the capability to do so in a trustworthy manner.

Mr. Giorgio's Written Testimony specifically mentions a number of threats:
whether it is the Chinese stealing our American innovations to produce less expensive versions, the Russians engaging in financial crimes, the Israelis' stealing our political intentions, the French stealing our competition-sensitive materials, the Nigerians conning our elderly, and so on.

He then goes on to mention that reference to foreign threats has been used in the past to justify "gross violations of domestic civil liberties" and warns that we must be cautious in this area of "dangerous constitutional grounds."

After answering the four questions, stressing the fear of government control, in an Appendix, Mr. Giorgio describes a "New Privacy Standards Framework". Remember "Alice and Bob" from crypto talks? In the new Privacy Standard we have a buyer, Bob, and a search agent, Goliath. Could Goliath = Google, Mr. Giorgio? The Framework was an interesting read, although it actually answered the opposite of what the committee was asking. It answers "how can individuals have their privacy protected?" when the question at hand was "how can we attribute attack traffic to its origins?"

Mr. Marc Rotenberg

- President of the Electronic Privacy Information Center - spoke of the fact that China has the most rigorous attribution capabilities, including a requirement that Internet users provide their true names, email addresses, and a list of news sources from which they receive information. Chinese ISPs are required to keep logs of all their activities, and Cyber cafes are required to log activities for sixty days of all users within their cafe. ".cn" domain owners have to provide both their real name and a photograph to create a domain name. "There is a real risk that attribution techniques will be used not for purposes of cyber security but in ways that have a real impact on human rights and freedom of expression. What attribution also does is make people think twice before saying something controversial. In the United States we have a strong constitutional right to speak anonymously," which Rotenburg says came from the use of anonymity in the publication of the Federalist Papers by our founding fathers.

I have to say that Mr. Rotenberg's written testimony was extremely well researched and had a fantastic list of eighty very current references, especially with great insights into China's censorship and monitoring activities. I found myself reading quite a few great papers that I hadn't seen previously as I followed the excellent footnotes prepared by EPIC's legal staff.



Q&A


Mr. Wu began the Q&A by saying that "as is often the case, when there are two flies flying in the Grand Canyon, they collide," apologizing that he had to go vote on another committee and would have to leave his own hearing. He also greeted "Russia Today" who was covering the committee hearings despite the absence of interest from American media.

Question from Chairman Wu: The role of Deterrence and Attribution may be over-stated. Comments?

Mr. Rotenberg - for non-state actors, attribution outside the US would be very difficult, and response may be very difficult for reasons of national sovereignty.

Mr. Giorgio mentions that even if we can't identify the PERSON at the keyboard, it is often enough to be able to block the COMPUTER at the other end in order to disrupt an attack.

Dr. Wheeler mentions that there is value to attribution, but there are serious limitations to attribution including delayed and intermediary attacks. Attribution should only be part of a larger strategy.

Mr. Knake - our strategy for preventing terrorism in the USA focuses on prevention, protection, and resiliency rather than deterring particular cyber actors. In many cases we do not lack attribution, we lack response options. Even when we know who the attacker is, we are limited in our ability to act. Whether they are Chinese national actors, Russian cyber criminals, or Nigerian scammers, knowing the identity of the attacker does not actually assist in having a means of acting.

Question from Chairman Wu - specifically to Mr. Giorgio - if we built attribution into the backbone of the Internet, we would be limiting privacy options.

All panelists agreed that anonymity was important. One speaker talked about the current noise about Blizzard requiring true identities for World of Warcraft players. Mr. Knake talks about the need for the government to actually step in and require Internet companies to disclose how they use personally identifiable information in the form of cookies and other information to target the internet user with customized advertising.

Ranking Member Smith asked the question "What are our current methods of being able to trace attacks?"

Dr. Wheeler mentions that there are many ways of doing so (in his written testimony, he had 17 categories of methods of identifying an attacker, and he states that surely there are more since then.)

Congressman Chris Smith then asked "if attribution is futile, what are our other methods to defend ourselves?"

Congresswoman Donna Edwards asked about the balance between Privacy and Attribution, specifically asking about internet cookies.

Congressman Dana Rohrabacher asked about the capability for "automatic counter attack" to be developed, and was warned off of the subject by multiple replies, stating that actually some forms of attack may be generated specifically to cause MIS-attribution in the hopes that a counter attack may be launched against a wrongful target.

In response to another question from Mr. Rohrabacher, Mr. Knake went back to a point that was well-articulated in his written testimony. He gave the example of the Taliban in Afghanistan, and pointed out that the warning we gave the Taliban after 9/11 was that if terrorist activities occurred from their soil, we would hold them responsible for refusing to cooperate with identifying and bringing to justice the criminals and terrorists they were protecting. In a similar way, Mr. Knake suggests that we have to hold foreign countries responsible when they thwart our abilities to identify various forms of cyber attackers in their countries.

Congresswoman Edwards then asked about the creation and establishment of new standards that would assist with these attribution standards.

Mr. Wu returned to his committee, and immediately cautioned that there were only seven more minutes before they had to adjourn for a floor vote. I really felt sorry for the panelists to see that there was so little time afforded to this very important topic.

Mr. Wu mentioned several questions that he hoped could be addressed in writing in the future, especially what role International committees, treaties, and standards may play in defining what is an attack, and how attacks should be responded to.

Monday, July 12, 2010

PakBugs Hackers arrested

(Thanks to Twitter friends - @nartv, @cedricpernet, @HostExploit - for setting me onto this story mostly by pointing to this article by Lucian Constantin over at SoftPedia, who had the English Language Scoop, as he often does.)

For Pakistani Hackers, July 7, 2010 will be remembered as the beginning of a fearful period in their lives. On that day, Mr. Shahid Nadeem Baloch, the Director of Cyber Crime Investigations for the Federal Information Agency announced the arrest of five ring leaders of the popular hacker forum "PAKBugs" in this release from the Press Information Department. Among those praised by FIA's Director General, Mr. Zafar Ullah Khan, for their roles in the investigation are Mr. Muhammad Idress Mian, who directs the National Response Center for Cyber Crimes (NR3C), Mr. Muhammad Raza, Cyber Crime Circle sub-inspector for the Rawalpindi Police, and NR3C Technical Officers Mr. Aun Abbas, and Mr. Amjad Abbasi.

The hackers arrested or wanted include:

Jawad Ehsan, alias Humza, still at large in Riyadh, Saudi Arabia.
Jawad uses the hacker handle ZombiE_Ksa, and is the founder of PakBugs and probably the most famous of all the PakBugs hackers. He is charged with 169 website defacements.

Ahmad Hafeez, arrested in Lahore.
Ahmad uses the hacker handle vergil, and is a moderator on the boards Pakbugs and Pakhaxorz. He is charged with 480 website defacements.

Hassan Khan, arrested in Peshawar.
Hassan uses the hacker handle x00mx00m, and is a co-founder of Pakbugs. He is charged with 8,697 website defacements.

Farman Ullah Khan, arrested in Bannu.
Farman uses the hacker handle Farman, and was a VIP-member of Pakbugs. Charges against Farman are unknown.

Malik Hammad Khalid, arrested in Rawalpindi.
Malik uses the hacker handle inject0r, and was a "super moderator" at Pakbugs. He is charged with 134 website defacements.

Taimoor Zafar Bhatti, arrested in Rawalpindi.
Taimoor uses the hacker handle h4v0c-, and was a "super moderator" at Pakbugs. He is charged with 105 website defacements.

Also wanted by the FIA Cyber Crimes Department are:
BiG^Smoke
Cyber-Criminal
spo0feR
and [a]

According to the press release:
These individuals have expertise in following techniques:
1) Linux
2) SQL Injection
3) Trojan horses
4) Phishing
5) Rooting
6) Access to various servers
7) Botnets
8) PHP Scripts
9) Stealers
10) ASP scripts (self writing)
11) JSP scripts (self writing)
12) Key loggers
13) Credit Cards Jacking and usage of stolen Credit Cards


What the press release doesn't mention is that the NR3C's own website was hacked by these website defacers in January of this year.

zonehmirrors.org/defaced/2010/01/07/www.nr3c.gov.pk/ "Hacked by zombie_ksa"

In that defacement the Pakbugs hackers suggest that if Pakistani citizens want help with security issues they should turn to Pakbugs rather than the NR3C.

The NR3C defacement was signed:

We are L33t Pakistani H4x0rZ,
www.Pakbugs.com
We are PAKbugs, We keep it real:
Zombie_Ksa::Spo0feR::x00mx00m::Cyber-Criminal
Special Greetz: BiG^Smoke
Greetz: Agd_Scorp :aB0 M0h4mM3d : The Moorish

That is actually the last website defacement credited to ZombiE_Ksa in the Zone-H archives, although his activities in 2009 included hacking numerous ".gov.pk" websites, temporarily taking over nameservers on the ".ug" registrar to allow defacements of the Ugandan websites for Microsoft, Toshiba, CNN, Citibank, and Google, and hacking the websites of the Saudi "Bank Al Bilad".

Zombie_KSA (KSA = Kingdom of Saudi Arabia) uses the hotmail addresses "Zombie_KsA@hotmail.com" and "mr.lonely420@hotmail.com".

TrendMicro posted screenshots obtained from Zombie_KSA proving that he not only had defaced the website, but actually had control of the email systems of the NR3C.

Despite the ZombiE_KsA hack, the Pakistani government is to be highly praised for taking on Cybercrime in such a proactive way. Pakistanis are encouraged to report cybercrime by emailing helpdesk@nr3c.gov.pk. The 2007 "Prevention of Electronic Crimes Bill (english language PDF) offers penalties from six months imprisonment all the way up to Capital punishment for 17 types of cyber crimes, with the most significant being "Cyber terrorism".


Other articles show that Zombie_KsA and Cyber-Criminal hacked the Pakistani Air Force website.

Unfortunately for the PakBugs hackers, in addition to having the Pakistani government after them, they had a bigger problem. Greyhat vigilante hacker "catch.them@live.com" posted the entire user database of the PakBugs forums to the mailing list Full-Disclosure back on September 14, 2009. That report revealed the email addresses used by all 12,640 members of PakBugs, including many of the hackers on the FIA wanted list including:

ZombiE_KsA = mr.lonely420@hotmail.com
x00mx00m = x00mx00m@gmail.com
Farman = farmanullahkhan@gmail.com
vergil = hotpoint-001@hotmail.com
Injector = lovedontcostapenny_1@live.com
h4v0c- = amilliondollarsmile@hotmail.com

The FIA may want to check out the history of website "loverzpoint.net", which has been "Greeted" several times by ZombiE_KsA, and where two of their "still at large" hackers have email accounts:

Cyb3r-Criminal = cyber-criminal420@loverzpoint.net
BiG Smoke = bigsmoke@loverzpoint.net
spo0fer = outlaw41@live.com
[a] = ahmed.kamal29@gmail.com

loverzpoint.net was originally registered to "big_smoke_boom@yahoo.com" with a fraudulent US-based address. In October 2008 that changed to "loverzpoint@gmail.com" with a Riyadh address and the name "Syed Jawad Shah".

(According to the Hack, userids 1, 12, 99, 1628 and 3844 all had "Admin" privileges at PakBugs. That would be users = ZombiE_KsA, spo0fer, Maximus, Test User, and Big Smoke, the last of those being the original owner of LoverzPoint.net)


The website "Propakistani.pk" has run a message regarding these arrests which is said to be from the "Pakistan Cyber Army". The PCA was active in a clash between Pakistani and Indian hackers in November of 2008. The message reads:
“Message from Pakistan Cyber Army on arrest of Pakbugs Members

If anyone has doubt that we are not the one who defaced ONGC then get a life first. If people have forgotten, then we are the same guys who Defaced ONGC in response to the attack on OGRA. After which we did a peace deal with the groups involved on both sides of borders including “Pakbugs” and “ICW” but kids didn’t keep their promise and got arrested.

We told PakBugs many (many, many, many) times to not to deface/destroy Pakistani websites and infrastructure. We told them to take FIA and NR3C seriously – as these agencies are not bunch of NOOBS, we had warned Pakbugs that you people don’t know about the power and the resources that NR3C has got but they gave a damn to our words and ended up in their custody.

I feel sad about the kids but… it happened due to their carelessness and childish attitude, which eventually landed them in the jail.

If you people are upcoming hackers and don’t know about Prevention of Electronic Crimes Ordinance then go and read it on NR3C website. I fear that Pakbugs would have a jail of 7 years if they got trialed and if FIA bail them out with some punishment they should thank Allah and concentrate on their studies.

We always told Jawad (HUMZA) and other kids about the consequences that they may face if arrested. [Jawad correct me if I am wrong.

Request to FIA/NR3C

“It is our humble request to FIA (NR3C) authorities to consider the case realistically and don’t give the kids the capital punishment as they are kids and can improve if given a chance. If they got the capital punishment as mentioned in Prevention of Electronic Crimes Ordinance then their future will be ruined. Sir these are our kids and our force if given a direction“

Message for upcoming Hackers

Our message to upcoming hackers or people who are interested in this field is that there is nothing bad to have the knowledge of hacking or hacking techniques, what’s bad is the usage of such knowledge and skill against our own country, National and international organizations or departments – that may cause damage to our country and its repute in the world. Don’t push your efforts to get famous. The fame will come by the time.

Some of your kids out there think that organizations in the west give opportunity to the hackers, if that’s the case then you are living in a heaven of fools.

Don’t believe in such stories that hackers will have a good future. The person who has a criminal record cannot fly from the country or he can’t enter into a country legally – go and ask your elders about it.

Message for Indian Hackers

If Indian hackers think that the game is over then read our message once again “Don’t mess with Pakistan else you will lose both your Name and this Game”. If you think that “Pakbugs” got arrested and you have a chance to play then give it a second thought.

Regards,

Pakistan Zindabad,
We are still awake for our country.
Haroon aka D45H & Hamza aka r4yd3n
Pakistan Cyber Army



(someone named R4yd3n was a member at PAKBugs as well, using the email sana2005@fastmail.fm)

Saturday, July 03, 2010

Stealing $10 Million, 20 cents at a time

On June 28, 2010, the Federal Trade Commission unveiled a law suit againt unknown credit card fraudsters, seizing the assets of 16 companies run by at least fourteen "money mules". The companies named were: API Trade, LLC; ARA Auto Parts Trading LLC; Bend Transfer Services, LLC; B-Texas European, LLC; CBTC, LLC; CMG Global, LLC; Confident Incorporation; HDPL Trade LLC; Hometown Homebuyers, LLC; IAS Group LLC; IHC Trade LLC; MZ Services, LLC; New World Enterprizes, LLC; Parts Imports LLC; SMI Imports, LLC; SVT Services, LLC. Each of these companies was run by a money mule recruited for the job via a spam email message. Each of them was instructed to establish their LLC to receive payments from small transactions, which they would then aggregate and wire to bank accounts in Lithuania, Estonia, Latvia, Bulgaria, Cyprus and Kyrgyzstan. Before the law suit hit, a Preliminary Injunction had already been issued back in March to freeze the assets of the company in question.

This is the sort of case that raises strongly a point that I continually preach at UAB: Modern cybercrime law enforcement is not possible without strong computer science and data mining skills. At UAB, I work as the "Director of Research in Computer Forensics". My normal pitch about the program is that Computer Scientists solve problems by applying technology and algorithms. Criminal Justice professionals are facing more and more crimes that can only be solved by the application of Computer Science. In our program, we introduce the two to each other. Some of our graduates will be tool users -- law enforcement and corporate investigators who now know the range of technology solutions that might be possible to make them better cybercrime investigators. Other graduates will be tool makers -- computer scientists who now understand the range of problems being faced by modern law enforcement and who are now equipped to design solutions to those problems.

In this case, the criminals, who have been active since at least 2006, are documented to have placed at least 1.3 million credit and debit card charges without the authorization of the card holder. Can you imagine working a case with 1.3 million fraudulent charges without the benefit of data mining technology? The defendants "somehow obtain the consumers' account numbers and proceed to sneak the charges onto the accounts. Defendants purposely make their unauthorized charges less than $10 in the hopes that consumers will not notice them or will choose not to contest the charges." (Quoted from the FTC Memorandum of Support.

Unknown defendants, referred to as "the Doe Defendants", manage the creators of the sixteen fake LLCs, referred to as the "Money Cashing Defendants" from somewhere in Eastern Europe. The Doe Defendants create hundreds of fake companies and corresponding websites which are named in ways that come close to the names of real organizations, making them difficult to search. Often the listed addresses and phone numbers are also similar to a real organization.

The consumers are charged as little as 20 cents in a single fraudulent transaction, and as much as $10. 90% of the charges were never disputed. Those that were received instructions to call non-existent telephone numbers, or answering services from which calls were never returned. More than 1000 consumers have filed complaints with the FTC about these illegal practices.

How much effort would YOU go to to right the wrong of an illegal $3 charge on your credit card?

The Memorandum of Support filed by the FTC describes three roles of various criminal groups in this action:

A. The Money Mules

This group is described as "an expansive network of money mules in the United States to cash out the unauthorized charges." The Doe Defendants sent out emails to recruit their money mules "announcing that an international financial services company is seeking a US finance manager to process transactions and cash checks, money orders, and international wire transfers." The claim is that there is a tax benefit to the company to have many tiny charges aggregated in the United States. In order to realize this tax savings, the Does will send the payments from their US customers to the Money Mules, who receive the payments and send them on to the "international financial services company."

B. The Money Cashing Defendants

The "international financial services company" required that the money mules form corporate entitites and establish bank accounts in the names of these corporate entities. Between the sixteen corporations established, more than three hundred merchant bank accounts were opened. While this sounds like the same group of people as Group A, Group A is the people themselves, while defendant Group B is actually the group of corporations formed by the people in Group A.

These companies then established merchant accounts at numerous "credit card clearing companies" in order to have charges processed by a clearing company and have the cash placed into their bank accounts. The companies used "virtual offices" through a company that sells "non-PO box" addresses to give the company a sense of legitimacy. Rather than establish their own Employer Identification Numbers (tax numbers required to be on file for merchant banking accounts), the companies "borrowed" the EINs of existing organizations with similar sounding names.

In order to pass the "due diligence" checks used when establishing merchant accounts, fake websites were created for each of the companies, claiming they sold various types of office supplies, and providing business and "home" telephone numbers for each of the organizations. All of the numbers forwarded to a cell phone number in Belarus. The "Owners" of these companies were real people, who included their name, social security number, and date of birth on the merchant account applications. The Defendant Does ran credit checks on each of the "borrowed" identities to make sure their credit scores were good before using their identities.

FTC: All Your Base Are Belong To Us



After reviewing the data, the FTC ruled against the defendants in the form of a Preliminary Injunction which freezes assets of all defendants as well as prevents them from sharing or selling the identity data they may have acquired about their victims. Here's the Asset Freeze language.

IT IS FURTHER ORDERED that Defendants, and their officers, agents, servants,
employees, and attorneys, and all other persons in acti ve concert or participation with any of them, who receive actual notice of this Order by personal service or otherwise, whether acting directly or through any trust, corporation, subsidiary, division, or other device, or any of them, except as provided herein, as stipulated by the parties, or as directed by further order of the Court, are hereby restrained and enjoined from:

A. Transferring, liquidating, converting, encumbering, pledging, loaning, selling, concealing, dissipating, disbursing, assigning, spending, withdrawing, granting a lien or security interest or other interest in, or otherwise disposing of any funds, credit instruments, real or personal property, accounts, contracts, shares of stock, lists of consumer names, or other assets,
or any interest therein, wherever located, including outside the territorial United States, that are:

1. Owned, controlled, or held by, in whole or in part, for the benefit of, or subject to access by, or belonging to, any Defendant;
2. In the actual or constructive possession of any Defendant; or
3. In the actual or constructive possession of, or owned, controlled, or held by, or subject to access by, or belonging to, any other corporation, partnership, trust, or any other entity directly or indirectly owned, managed, or controlled by, or under
common control with, any Defendant, including, but not limited to, any assets held by or for any Defendant in any account at any bank or savings and loan institution, or with any credit card processing agent, automated clearing house processor, network transaction processor, bank debit processing agent, customer service agent, commercial mail receiving agency, or mail holding or forwarding company, or any credit union, retirement fund custodian, money market or mutual fund, storage company, trustee, or with any broker-dealer, escrow agent, title company, commodity trading company, precious metal dealer, or other financial institution or depository of any kind, either within or outside the territorial United States;

B.Opening or causing to be opened any safe deposit boxes, commercial mail boxes, or storage facilities titled in the name of any Defendant, or subject to access by any Defendant or under any Defendant's control, without providing the Commission prior notice and an opportunity to inspect the contents in order to determine that they contain no assets covered by
this Section;

C. Cashing any checks or depositing any payments from customers of Defendants;

D. Incurring charges or cash advances on any credit card issued in the name, singly or jointly, of any Defendant;

E. Incurring liens or encumbrances on real property, personal property, or other assets in the name, singly or jointly, of any Defendant or of any corporation, partnership, or other entity directly or indirectly owned, managed, or controlled by any Defendant; or

F. Transferring any funds or other assets subject to this Order for attorney's fees or living expenses, except from accounts or other assets identified by prior written agreement with the Commission; provided that no attorney's fees or living expenses shall be paid from funds or other assets subject to this Order until the financial statements required by Section V are provided to counsel for the Commission.


I love it when the bad guys lose their toys!

Long Boring Lists


OK, I know this is the boring part, but here are all the companies listed in the order, followed by a list of the vendor names that may have showed up on your fake credit card charges if you are a victim. Both lists are drawn from the FTC documents already mentioned:

• API Trade, LLC, a Pennsylvania limited liability company incorporated in 2006, which has at least four bank accounts in its name; API's registered office address is 9926 Haldeman Avenue, #45 B, Philadelphia, Pennsylvania 19115

• ARA Auto Parts Trading LLC, a limited liability company, which has at least two bank accounts in its name; ARA's principal address is 14202 Barcalow Avenue, Philadelphia, Pennsylvania 19116

• Bend Transfer Services, LLC, a Nevada limited liability company incorporated in 2007, which has at least thirty bank accounts in its name; Bend's registered office address is 21285 East Highway 20, #169, Bend, Oregon 97701.

• B-Texas European, LLC, a Texas limited liability company incorporated in 2006, which has at least sixteen bank accounts in its name; B-Texas' registered office address is 701 Brazos Street, Suite 1050, Austin, Texas 78701. B-Texas also conducts business at 8070 County Road, 603, Brownwood, Texas 76801.

• CBTC, LLC, a Delaware limited liability company incorporated in 2007, which has at least four bank accounts in its name; CBTC's registered office address is 151 Evergreen Drive, Dover, Delaware 19901. It also conducts business at 9926 Haldeman Avenue, #45 B, Philadelphia, Pennsylvania 19115.

• CMG Global, LLC, a Pennsylvania limited liability company incorporated in 2006, which has at least eleven bank accounts in its name; CMG's registered office address is 7400 Roosevelt Boulevard, #52602, Philadelphia, Pennsylvania 19115. It also conducts business at 7400 Roosevelt Boulevard, Apartment A303, Philadelphia, Pennsylvania 19152 and P.O. Box 52602, Philadelphia, Pennsylvania 19115.

• Confident Incorporation, a California company incorporated in 2002, which has at least three bank accounts in its name; Confident's registered office address is 17800 Castleton Street, Suite 386, City of Industry, California 91748. Confident also conducts business at 30616 Sand Trap Drive, Agoura Hills, California 91301.

• HDPL Trade LLC, a Pennsylvania limited liability company incorporated in 2008, which has at least nine bank accounts in its name; HDPL's registered office address is 1143 Northern Boulevard, #263, Clarks Summit, Pennsylvania 18411.

• Hometown Homebuyers, LLC, a Texas limited liability company incorporated in 2002, which has at least thirty-seven bank accounts in its name; Hometown's registered office address is 413 East Highway 121, Lewisville, Texas 75057. It also conducts business at 8070 County Road 603, Brownwood, Texas 7680l.

• IAS Group LLC, a California limited liability company incorporated in 2008, which has at least five bank accounts in its name; Highway 121, Lewisville, Texas 75057. It also conducts business at 8070 County Road 603, Brownwood, Texas 7680l.

• IHC Trade LLC, a New York limited liability company incorporated in 2007, which has at least seventy-one bank accounts in its name; IHC's registered office address is 5823 North Burdick Street, East Syracuse, New York 13057.

• MZ Services, LLC, an Arizona limited liability company incorporated in 2004, which has at least fifty-three bank accounts in its name; MZ Services's registered office address is located at 2910 North Casa Tomas Court, Phoenix, Arizona 85016.

• New World Enterprizes, LLC, a New Jersey limited liability company incorporated in 2005, which has at least fourteen bank accounts in its name; New World's registered office address is 115 Magnolia Avenue, Suite 10, Jersey City, New Jersey 07306. New World also conducts business using the following addresses: (1) 441 Tomlinson Road, Apartment G 12, Philadelphia, Pennsylvania 19116, (2) P.O. Box 2645, Newark, New Jersey 07114, (3) 2400 East 3rd Street, Apartment 705, Brooklyn, New York 11223, and (4) 504 Florida Grove Road, Keasby, New Jersey 08832.

• Parts Imports LLC, a Louisiana limited liability company incorporated in 2006, which has at least forty-two bank accounts in its name; Parts Imports' registered office address is 617 Elm Drive, Bogalusa, Louisiana 70427.

• SMI Imports, LLC, a Florida limited liability company incorporated in 2006, which has at least fourteen bank accounts in its name; SMI's registered office address is 2329 North Tamiami Trail, Apartment #10, Sarasota, Florida 34234. SMI also conducts business at 8122 45th Court East, Apartment 7, Sarasota, Florida 34243.

• SVT Services, LLC, a New York limited liability company incorporated in 2008, which has at least eight bank accounts in its name. SVT's registered office address is 800 East 13th Street, Apartment K, Brooklyn, New York 11230.

The fraudulent charges seen by the consumers actually The mark of the scam is to see fraudulent credit card charges from one of the following companies:

ACM
Adele Services
Advanced Global Tech
AEI
Albion Group
Alpha Cell
ALS
ALS LLC
BEI
BIT
BusinessWorks
Center Company
Centrum Group
CFM
CFR
COS
Data Services
Den Enterprises
Dgen
Digest Limited
Don Partners
DwellTech
Edge
ESTA
Eureka
Extra Path
Form Limited
Foto Fast
Gamma
GFDL
GLOBO
Green Stone
Harry Dean
HBS
Home Port
Homebase
ICH Services
IHS
Image Company
Image Services
IPS
ISSO
IVA
Lang Group
Light Flow
Link Group
Link Services
List Services
Mark Silver
MARX
Mera
MFG
Name Services
NETT
New Eight
Office Development
Office Services
OM Extra
ONE
Online Group
Prc Services
Presi
Rasna
RSIPartners
RSS Inc.
Safeworks
Search Company
Search Management
Search Services
SFR
Sigma
Site Group
Site Management
Site Services
Source Limited
Standard Six
SYS INC
System Development
Terra
THQ
TIMO
TLC Inc.
Union Green
United Services
VIVOS
WELLE
Will Services
World Trade
World Wide Services
YES

Thursday, July 01, 2010

ICE Operation "In Our Sites"

When you think of a Federal agency that should be enforcing criminal copyright violations, you might not think of the US Immigration and Customs Enforcement (ICE), but once again, they are serious members of the cybercrime-fighting pack with their recently announced "Operation In Our Sites".

ICE Assistant Secretary John Morton was backstage in Los Angeles for a meeting with movie studios, entertainment unions, and the Motion Picture Association of America (MPAA) where he announced the first arrests in this operation.



In their first action, nine web sites had their domains seized by agents operating from the Southern District of New York. In addition, ICE agents seized the criminals' assets from 15 bank, Paypal, investment, and advertising accounts and executed four residential search warrants.

The domain names targeted in the first round included:

TVShack.net
Movies-Links.tv
FilesPump.com
Now-Movies.com
PlanetMoviez.com
ThePirateCity.org
ZML.com

Visitors to these websites will see this sign instead of their regular content:



Some of these sites were quite creatively hosted. For example, TVShack.net was hosted on the IP address 84.22.98.3, owned by "CyberBunker Customer Delegations," which claims to be located in Antartica (although they have a sales office in Berlin Germany). One of its close neighbors, "the-movie-downloads.com" is still on live at 84.22.98.19, which claims to have 3 million members and a catalog of 80 million titles available for "instant free download."

FilesPump.com was hosted prior to its seizure on the subnet 213.174.143.0/24, which currently hosts more than 500 hardcore pornography websites at "Advanced Hosters", but still has free movie sites mixed in, such as "freemoviesplace.com" owned by Hungarian "Alen Miscak" according to the WHOIS information. That site claims to have been offering streams of Twilight Saga: Eclipse since June 30th and Toy Story 3 since June 18th, but its possible that they are just making money on their related "allposters.com" affiliate advertising.

Some of the sites are quite confusing for the novice to use . . . for instance ABCFilm.org is a Russian language site, offering streams of all the most recent movies - Eclipse, Grown-Ups, A-Team, Killers, Karate Kid, Jonah Hex - but to watch them you have understand their special "Codex" and use their "DownloadMaster" program. The movies are clearly labeled as to what kind of stolen IPR you will receive, for example Grown-Ups (Russian is Одноклассники) is labeled as a "CamRip" (meaning someone videotaped it in the theater) of 1938 kb/s 688x384 resolution. Although this one is a Russian site, its hosted at "HostForWeb"

PlanetMoviez was hosted in Chicago Illinois by Cogswell Enterprises on IP address 96.30.9.104, while ThePirateCity was hosted on 89.185.228.192 = "Fast Internet Web & Server Hosting" in the Czech Republic (exmasters.com = "best low-cost adult web-hosting")

ZML.com was hosted on a long-time favorite host of cybercriminals everywhere, Noc4Hosts in Tampa, Florida. Noc4Hosts IP 96.31.66.11 was ZML's previous home, on a subnet that also contains all your offshore banking domain names, from places like "caymanfinancialreview.com", and which also hosted DVD and Movie piracy websites such as Basecinema.com, BuyDVDFilm2.com, CinemaINet.com, DVDOnlineService.com, FilmoKingdom.com, MovieShop77.com, MoviesforaPenny.com, and many others. Strangely, quite a few of these sites are currently not online. I'm sure this means Noc4Hosts has decided to purge themselves of criminals. Haha!

The National Intellectual Property Rights Coordination Center (IPR Center), which is operated by ICE in Virginia, also seized the domain names and all web site content for the sites:

NinjaVideo.net
and
NinjaThis.net


The IPR Center has launched its own web presence to help identify and fight copyright and trademark violation on the Internet. Here's their new logo:


(click for full-sized image)

The IPR Center urges consumers to report additional websites where copyright violation is rampant by using the National IPR Coordination Center Complaint Referral Form or by contacting their IPR Hotline at 1-866-IPR-2060 (1.866.477.2060).

During Fiscal Year 2009, ICE launched 1,479 Intellectual Property Rights Investigations that resulted in 414 arrests, 164 indictments, 203 convictions, and the seizure of $62 Million in counterfeit merchandise, according to their IPR Fact Sheet.

If you think you'd be interested in a career with ICE as a Special Agent, read about The Hiring Process and use their "Contact Us>" page to call and discuss the recruitment process with one of their 26 offices around the country. In addition to Special Agent jobs, they also have positions as Auditor, Criminal Research Specialist, Investigative Assistant, Mission Support Specialist, and Technical Enforcement Officer.



Here are a couple screen shots from the ICE Press Release of sites that they took offline:




Wednesday, June 30, 2010

Russian Spies - Tradecraft and Follow the Money

There are two documents that have been made public which consist of most of the "official" information about this week's Russian Spy cases. We reviewed the first of these documents, a deposition by FBI Special Agent Amit Kachhia-Patel, in our article Tuesday, on Anna Chapman and Mikhail Semenko. Wednesday morning we took an "Unofficial" look at the Four Russian Spy Couples (& Two Solo Acts) constructing bits of information about them from Internet-based records and the media.

In this post we'll be focusing on the longer deposition of FBI Special Agent Maria L. Ricci, who lays out the case against eight defendants before the Honorable James L. Cott, US Magistrate Judge, Southern District of New York.

Christopher R. Metsos
Richard Murphy
Cynthia Murphy
Donald Howard Heathfield
Tracey Lee Ann Foley
Michael Zottoli
Patricia Mills
Juan Lazaro
Vicky Pelaez

The charges are still primarily "Conspiracy to Act as Unregistered Agents of a Foreign Government", which is a violation of Title 18 USC Section 951.

The thirty-seven pages of the deposition got a bit confusing, so I found it helpful to draw some pictures, and try to figure out how many conspiracies were documented within.

The Group of Five Spies





This diagram focuses on the "Seattle Conspirators", Michael Zottoli and Patricia Mills, and the "Hoboken Conspirators", Richard Murphy and Cynthia Murphy.

Bags of Money and Exchanged Packages



Christopher R. Metsos seems to be the only one who is actually being called an SVR agent in these documents. Metsos works directly for the Russian government, and likely has a salary and a pension. The "Illegals", as the other eight co-conspirators are named, are citizens who work "unofficially" to gather intelligence and perform tasks at the direction of their handler. Metsos met Richard Murphy at least four times between February 2001 and April 2005. On March 31, 2002, Metsos brought a bag of money, likely $40,000 to the meeting, and Murphy left with the bag. By April 17, 2005 he chose to give him an ATM card with matching identification and a PIN number rather than large sacks of cash.

Metsos is observed on video doing a "Brush-pass", where two travelers with identical bags exchange bags while bumping into each other, crossing each other, or sitting beside one another without speaking. One of these brush passes is the only link to Zottoli and Mills, but there is a long time between. On May 16, 2004, Metsos trades identical orange bags with "Russian Government Official #2" in a brush-pass on a stariwell at the Forest Hills Train Station on the Long Island Railroad. Metsos then proceeds to meet with Richard Murphy at the Sunnyside Restaurant. He passes Murphy the package, instructing him to take his cut and tell the guy he meets "Uncle Paul loves him". Two weeks later Zottoli and Mills fly from Seattle-Tacoma airport to Newark Airport, check in to the Manhattan Hotel, and on June 19, 2004 enter Central Park. Intercepted communications reveal they couldn't find one another, but the next day they do meet at a subway entrance near Columbus Circle. Zottoli leaves the meeting with a red museum gift shop bag he had not possessed before the meeting.

Two years later, Zottoli and Mills fly to JFK from SeaTac. This time they proceed to a location near the Forest Hills Train station, and dig up a package buried in 2004 on the day of the Brush-pass. They are observed filling several wallets and a money belt with money back at their hotel, where they are under video surveillance.

In 2009 a similar brush-pass is arranged at the North White Plains train station on Harlem Line. Intercepted electronic messages gave the plan, where to meet in a "dead zone" on a certain stairwell, where Barnes and Noble bags will be exchanged. It is believed Murphy received $300K from Russian Government Official #3, and passed half of the money to Zottoli, along with a flash memory card.

Murphy and Zottoli were given a script for positive identification:
"Excuse me, did we meet in Bangkok in April last year?"
"I don't know about April, but I was in Thailand in May of that year."

The second half of the pass happened on a park bench in Fort Greene Park in Brooklyn. Electronic comms intercepted after the meeting reported "Meeting with M was successful. A passed to M the card and $150k."

Murphy met with other SVR agents to receive an Irish passport in the name of Doherty Eunan Gerard and money and tickets for travel. In January 2010 Murphy received instructions to purchase computer equipment and take it to the Moscow Center. He traveled to Europe with the laptop, and after returning met once more with Michael Zottoli at a coffee shop in Brooklyn and passed him the laptop, two memory sticks, and $9,000 cash, according to intercepted electronic records.

Electronic Tradecraft & Taskings


In addition to the typical "package exchange" tradecraft, there is significant evidence of sophisticated electronic tradecraft as well.

On July 27, 2005, the FBI conducted a search of the Hoboken, New Jersey residence of Richard & Cynthia Murphy. During the search, they uncovered a 27-character long password written on a piece of paper near the computer, beginning with "ctrl alt e".

The password turned out to be the key to unlocking a secret steganography program located among their disks. Also on the computer in their apartment, an address book was found indicating "hundreds of websites" where photos could be uploaded. According to court documents, these websites were reviewed and more than 100 images were discovered which actually contained text files hidden within the images.

Although I am well familiar with the concept of steganography - hiding a text message inside the "noisy bits" of a graphic file - I was only aware of one "in the wild" story of steganography before this case. In fact, I frequently ask the question when various professionals mention steg if they have ever seen it "in the wild". Only one person so far has answered me in the affirmative with a credible story - Dorothy Denning of the Naval Post-Graduate School, speaking at a cybercrime meeting at UNC Charlotte - with a case involving stolen credit cards hidden in graphical bullets on a website. This would be the second case of which I am aware. All of the other "scary stories" about steganography I have heard have proven to be unfounded.

Another case of electronics was the shortwave radio found in the Seattle search of Zottoli and Mills apartment February 17, 2006. In that case, a spiral-bound notebook of "radiograms", short coded groups of letters was found written beside the shortwave. Several of the couples, including Boston and New Jersey, were observed to reserve electronic messages referring to "RGs" or RadioGrams. In January 2009, a message to New Jersey read "Pls, make sure your radioequipment for RG rcptn is in order. We plan to send a couple of test Rgs." Pelaez and Lazaro were also overheard in surveillance discussing "receiving radio from over there."

Some of the decoded messages to the New Jersey conspirators gave specific taskings, or "infotasks". For example, in the spring of 2009 - SVR requested information prior to Obama's visit to Russia, any information on the US position with respect to a new Strategic Arms Limitation Treaty, Afghanistan, or Iran's nuclear program. Specific sub-cabinet officials were named from which information should be tried to be gained. It wasn't necessarily classified information that was being sought - in one message of October 18, Moscow instructs "to send more info on current international affairs vital for R, highlighting US approach and providing us w. comments made by local expert (political, economic) scientist's community. Try to single out tidbits unknown publicly but revealed in private by sources close to State department, Government, major think tanks."

As I revealed in yesterday's blog story, Four Russian Spy Couples and Two Solo Acts, those arrested had many important contacts through well-chosen schools and carefully selected career options to put them near these types of people. As Richard Murphy was contemplating how to improve his collection, he was warned by Moscow Center to avoid directly seeking government jobs, because his legend was not strong enough to pass a full government level background check.


One "job well done" message was sent back to Cynthia Murphy after she shared some closely held information regarding the global gold market. SVR responded "Info on gold v. usefull, it was sent directly to Min of Finance, Min of Ec Devel."

Intercepts to and from Murphy provide further insights. She was urged to strengthen relationships with classmates and professors who may be able to help with introductions or who may work with secret data. If she became aware of a potential information source, she was to pass the data to SVR, who would instruct her to proceed ("the target is clean") or hold back ("the target is dirty"). She was given a "clean target" report about one of her financial firm's clients, who has been since revealed in the media to be Alan Patrickof, a Hillary Clinton financier. Even "White House kitchen" gossip would make for interesting reports, and she was encouraged to try to get invitations from Patrickof to events such as Democratic Party conventions.

Murphy was also tasked to seek out particular classmates who may apply for jobs with the CIA. (Murphy has an International Business Degree from NYU's Stern School of Business, and an MBA from Columbia.) After many years with the same firm, in 2010 Moscow Center began pushing for Murphy to consider a job with a lobbying firm that would increase her access to US government sources.


The Other Couples



Juan Lazaro and Vicky Pelaez don't seem to have a clear link that I could see in the court record with the other couples or with Metsos. The primary activities documented regarding these two are money movement. At least two South American money transfers occurred involving the receipt of funds from Russian government representatives. On January 14, 2000, Pelaez received funds while under video surveillance at a park in a South American country. A telephone intercept confirms that Pelaez told Lazaro that same day that "all went well." Lazaro would later meet "Russian Government Official #1" at the same park on August 25, 2007, with the exchange again being videotaped. Lazaro waited at a park bench with an open shopping bag at his feet. RG#1 placed a smaller plastic bag into Lazaro's shopping bag, and the two parted ways. When Lazaro returned home he paid $8,000 in taxes almost immediately.

On January 8, 2003 the couple reports that Lazaro is writing a report "in invisible" in a notebook, and that while Pelaez is in South America she will pass the book to contacts there. This is believed to be a reference to invisible ink. After one of Pelaez's trips she returns with "eight bags of ten" and the two are heard counting money on surveillance, determining they actually had $76,000. Other conversations recorded at their residence made it clear they were being paid to provide information. One exchange is shared in the deposition where their handlers are complaining that some facts do not indicate their source, and that this makes them worthless. Pelaez replies to her husband "Then why do they have you? If they don't care about the country, what do we have Intelligence Services for?" Most of the intercepts from this couple are from 2002 and 2003.


One of the only things that ties the Boston conspirators, Donald Howard Heathfield and Ann Foley, to the others is their common technology. As mentioned above, the New Jersey search warrant found secret steganography software, developed by the SVR, that was only accessible if a particular 27 character password was entered. The same software, also only accessible by entering a 27 character password, was also found on their Boston computer after a search of their home on July 29, 2006. In that same search, a number of deleted files were recovered from their computer, including files that were obviously the draft messages which had been included in image files and posted online for retrieval by SVR. Aural communication intercepts of the couple at home also reveal that they were using the steganography, included one intercept shared in the deposition from March 7, 2010, where Foley and Heathfield are discussing whether they were allowed to place two messages in the same image.

In several of the intercepts, it is revealed that Donald (who is referred to as "Dv" by Moscow Center) has established contact with a former high-ranking US Government national security official whose name is provided. He also relays conversations about the capabilities and strategic planning for "small yield high penetration nuclear warheads" called bunker-busters. His infosources were given codenames such as "Farmer", "Parrot", and "Cat". Sometimes he was encouraged to proceed. Other times he was asked for more details about work position, background, habits, contacts, etc in order to determine whether the target was worthwhile to pursue.

Foley is elsewhere provided with a fraudulent British passport, a flight itinerary, and an invitation from the Russian Chamber of Commerce to visit Moscow.

At this point, it is not obvious from the published documents how Pelaez and Lazaro can be linked to the others in the public documents. One may speculate that the link is from common handlers on the official Russian side which cannot be disclosed publicly at this time.

Tuesday, June 29, 2010

Four Russian Spy couples (& two Solo Acts)

In yesterday's blog post, Anna Chapman and Mikhail Semenko vs. FBI we looked at the Wireless Ad Hoc networks that are now part of SVR tradecraft. We'll look at the tradecraft in the rest of the case tomorrow, but for today we ask "Who are these people?"


Donald Heathfield & Ann Foley - Boston



Donald Howard Heathfield and Tracey Lee Ann Foley were a couple in Boston, Massachusetts. They lived at 111 Trowbridge St., apartment number 9, in Cambridge, according to this piece from WBZ Boston. The FBI became suspicious of Donald, who was believed to be French Canadian, and spent much of his time in France and Europe, when they learned in 2005 that he was dead. The real Donald Howard Heathfield, who was Canadian, had died in 2000.

His "wife", who went by the name "Ann Foley" dabbled in real estate, according to this Boston.com profile. Boston.com interviewed her boss at a Boston real estate company, Redfin Corporation. Ann had her own web address, "foleyann.com", which was part of the RedFin website.

Don's LinkedIn page says he was the CEO of a company called FutureMap. (He's a "3rd level" link of mine, through 9 different connections). His LinkedIn also lists his MBA in Paris and his Masters in Public Administration from the Kennedy School of Government at Harvard University. He worked after graduating there at Global Partners in Boston for six years before starting Future Map.

His LinkedIn Group memberships include:

* Oxford Futures Forum
* Society of Competitive Intelligence Professionals
* World Future Society
* Predictors logo Predictors
* Selling in the New Global Economy logo
* Harvard University, John F. Kennedy School of Government (HKS)
* Harvard China Group
* US Policy on China & the Rest of the World Group
* Business Intelligence Group
* Private Sector Preparedness
* IVY GROUPS - The Professional Network for Ivy League Alumni
* Strategic Business and Competitive Intelligence Professionals
* IVY GROUPS: Management Consulting & Professional Services
* Public Sector Innovation
* Public Sector Consultants
* U.S. Government Relations & Public Affairs
* SOFT POWER NETWORK
* National Emergency Management Resource Center [NEMRC]
* Pharma Market Research
* World Future Society
* HFMA CFO Forum
* Business Intelligence Professionals
* Public Sector Forum
* Public Sector Risk Management
* Global Insurance Professionals
* IVY GROUPS: Government & International Affairs
* State & Federal Public Sector Professionals
* Professional Public Service: MPA-MPP Degrees
* Balanced Scorecard Practitioners Global Network
* Association for Strategic Planning
* China Business
* Web 2.0

The WHOIS information for Ann's domain confirms her address, and the email used, "dh@thefuturemap.com", is consistent with her husband's listed email address.


Registrant:
Tracey Ann Foley
111 Trowbridge St.
Unit 9
Cambridge, Massachusetts 02138
United States
dh@thefuturemap.com

Domain Name: FOLEYANN.COM
Created on: 27-Sep-07
Expires on: 27-Sep-10
Last Updated on: 26-Aug-08

His website uses different contact information, including a hotmail email account:

Donald Heathfield
111 Trowbridge St.
#9
Cambridge, Massachusetts 02138
United States
dheathfield@hotmail.com

Domain Name: THEFUTUREMAP.COM
Created on: 12-Jan-05
Expires on: 12-Jan-11
Last Updated on: 13-Jan-10


His website, thefuturemap.com, gives a mission statement:

Future Map enables governments and businesses to develop comprehensive preparedness systems and build a culture of strategic proactivity and anticipatory leadership.


According to his website, the company's feature project was currently a joint effort with the Beijing Academy of Soft Technologies and the Chinese Academy of Social Sciences, called "Green China". They maintained a "ning" site for the project at ChinaGreenFuture.ning.com


Her website provides this bio:

Ann Foley, a native of Montreal, lived and was educated in Switzerland, Canada and France. Prior to her career in real estate she worked as a Human Resources officer in Toronto and ran her own travel agency in Cambridge that specialized in organizing trips to French wine regions for small groups of enthusiasts. Ann’s cultural awareness and international experience make her sensitive to the needs of other people. She strives for excellence in everything she does. Ann succeeds through her ability to ensure quality service, honesty and integrity. You will appreciate Ann’s enthusiasm and commitment to make sure that your real estate goal becomes a reality.

Ann resides in Cambridge with her husband and two teenage sons. She and her family are fond of travel. They have enjoyed visiting much of Europe but are particularly in love with Asia. Ann also appreciates gourmet food, ballet and spending time with her children


Mikhail Semenko - Washington DC


According to Mikhail's LinkedIn Page, he currently works for "Travel All Russia, LLC", which is a company that "Sell customized tours to English, Spanish and Chinese speaking clients. Establish connections with business partners in China and Latin America. Design new tours and business expansion initiatives."

If one of the goals was to find spies who could influence policies, the rest of Mikhail's resume looks like he might have been a rising star!

Before his current travel position he was a "Council Coordinator" for the The Conference Board: Trusted Insights for Business Worldwide, where his responsibilities are given as:

Coordinated with researchers and program directors to develop, support and operate five councils of senior executives. Enhanced member engagement and promote networking, research and exchange of new ideas among senior corporate executives. Identified, developed and implemented membership recruitment initiatives.


While working as a graduate student at Seton Hall University, his responsibilities as an intern included "File purchase orders, invoices and related accounting paperwork. Track, file and report on faculty stipends." He was an Intern at the World Affairs Council in 2007, and taught English and Western culture to students at the "Harbin Nangang District Language Center" while studying Chinese language and culture himself as a student at the Harbin Institute of Technology from 2003 to 2005. Harbin is in the extreme NorthEast corner of China.

Mikhael uses his voice as a blogger to decry US Policy in China. His blog post from June 24th begins with ... "I’m amazed at the persistence, with which American policymakers keep blaming China for its economic vows. Meanwhile, we finally received a response to US’s continuing whining about undervalued Renminbi from the China’s Foreign Ministry: “We believe the appreciation of the renminbi cannot bring about balanced trade and cannot help the U.S. solve its own problems of unemployment, overconsumption and a low savings rate”.

According to his blog, Mikhail can be reached at msemenko@gmail.com or on his cell at 973-489-2297 begin_of_the_skype_highlighting              973-489-2297      end_of_the_skype_highlighting. http://chinaeconomytoday.wordpress.com/contact-me/

That's the same contact email he uses on "forums.amur.info", a Russian hang-out spot where he calls himself "mike_newyork". That's similar to his Twitter ID, http://twitter.com/mike_nuevayork.


While finishing his Masters at Seton Hall, his research projects included "China's Energy Policy in the Arab World" and "China-Taiwan Relations". As an undergrad in International relations at Amurskij Gosudarstvennyj Universitet, he was a leader in the "Model United Nations" focusing on Far East relations.

He networks well on LinkedIn. He's a "3rd level" connection to me through five different connections.

His LinkedIn Groups included:
* Carnegie Council for Ethics in International Policy, Asia Society
* Whitehead Alumni Association
* China Business Consultants Network
* Consultants Network Consultants Network
* Procurement Professionals (#1 supply chain & sourcing group) Business, network, jobs & candidates
* Seton Hall University Alumni Network
* Friends of China
* Overseas Chinese Network
* Hotel Industry Professionals Worldwide
* BRIC
* China HR Network (1000+)
* Friend of China
* Chinese-Speaking & China-Experienced Business Executives
* Public Policy Network - International
* Friends of Chinglish
* Non Profit & Philanthropic Job Board
* MENA Private Equity and Venture Capital Group
* US Policy on China & the Rest of the World Group
* The Green Leap Forward 绿跃进
* Doing Business & Expanding into China
* JOBS 2.0: Job Search Career Networking Staffing.
* Global Jobs Network
* España economía en crisis, Macroeconomía de otros países
* JOBS 2.0 Northeast (Northeastern US): New York City Philadelphia Boston Pittsburgh Hartford Buffalo
* JOBS 2.0 in Asia – Japan Hong Kong Taiwan South Korea China Russia India Pakistan Malaysia Thailand
* eyeforpharma Sales Force Effectiveness
* Innovation Works (China)
* Top SEO
* TRAVELALLRUSSIA

Anna Chapman - Manhattan


Anna Chapman is the celebrity of the group and has been much covered elsewhere. I did point out in Yesterday's Entry that she was interviewed about her "TIME Ventures" fund. TIME, the acronym stolen from a Canadian company of the same name, stands for "Technology, Internet, Media, Entertainment" had a bankroll of $2 Million to help other Russian entrepreneurs establish companies in New York.

Her Facebook Page says she has 168 friends, and is interested in "Alma De Agave Tequila, New York Entrepreneur Week, Do It In Person, AMBAR, MostProperties.com, School of Academic and Professional Blogging". Anya has her Facebook privacy settings set to make her "Wall" public, so there is some interesting things there.

(AMBAR = American Business Association of Russian-speaking Professionals ( AmBAR ) is a non-profit business association of entrepreneurs, venture capitalists, engineers, lawyers and other professionals with headquarters in Silicon Valley.

She really did seem to be in the Russian Entrepreneur scene, with recent links such as:

Anna Chapman Ребята, всем кому интересно узнать про венчурное инвестирование, в Москве будет отличное мероприятие - Московский венчурный форум, участие бесплатное, информация на http://arip.ru/
Инновации, инновационные проекты, субсидии, инвестиции, поддержка

(Translated:
Anna Chapman guys, all who are interested to learn about venture investing, in Moscow will be a great event - the Moscow Venture Forum, part free of charge, information on http://arip.ru/
Innovation, innovation projects, grants, investments, support


She also attended New York Entrepreneur Week cocktail reception back on April 15th.

A bit of her poetic musings: "Anna Chapman In the midst of winter, I finally learned that there was in me an invincible summer.
April 8 at 6:52am"

And a post about her Mac, the focus of her "spy" activities: "Anna Chapman My new Mac has been the buy of the year... Love it!
January 24 at 6:11pm"

OK - this is the part where my teenage daughter would accuse me of being a Facebook creeper...moving on.

Vicky Pelaez and Juan Lazaro - Yonkers



Vicky Pelaez, Spanish-language journalist, profiled in the New York Daily News. In 1984 she was kidnapped in Peru by the MRTA, but her cameraman at the time claimed she was a willing accomplice of the kidnappers. She lived with her Peruvian husband and fellow accused spy, Juan Lazaro, at a home in Yonkers, New York. In this photo from 1010WINS.com, FBI agents are entering their property: They have a 38 year old son, named Waldo Mariscal.

Vicky used her New York based "El Diario" email, Vicky.pelaez@eldiariony.com, in her byline for recent stories, including:

June 1, 2010 - El derrame de petróleo es la ‘Katrina’ de Obama - (the Oil Spill is Obama's Katrina)

May 25, 2010 - Obama campeón deportador de indocumentados - (Obama is the champion of the undocumented) - mocks our government as being racist, xenophobic, and intolerant and starts with the Thomas Aquinas quote: "Justice without mercy is cruelty"

May 4, 2010 - Arizona: un 'muerto de hambre' con ínfulas - compares the Arizona immigration law with Nazi Germany and Apartheid, and quotes FDR (in Spanish) "“Acuérdate, acuérdate siempre, que todos nosotros somos descendientes de inmigrantes y revolucionarios”." (Remember, always remember, that all of us are the descendants of immigrants and revolutionaries)

Juan Lazaro is mentioned in today's New York Times article, Curiosities Emerge in Suspected Russian Spy Ring by James Barron, because former students of his at Baruch College remember his anti-American views. He taught as an adjunct for a single semester only. Here's how the NYT relays student views:

His students said he was a professor like none other. The reason? His passionate denunciation of American foreign policy. He maintained that the wars in Iraq and Afghanistan were a money-making ploy for corporate America. He praised President Hugo Chávez of Venezuela and disparaged President Álvaro Uribe of Colombia as a pawn for paramilitary groups that have broad control over drug trafficking.

“He challenged us intellectually,” said one student who graduated in May. “He criticized a lot about what happens in the United States, and that’s what I think got some people upset.”


The course catalog entry reads:

CUNY Bernard M Baruch College
POL 3364 - Lat Am&carib Pol Sys

This course examines contemporary political systems in selected Latin American and Caribbean countries. It emphasizes the common problems of state-building, political-economic development, political party development, political instability, revolution, dictatorship, and democracy in these nations. Special attention is paid to the current and historical relations between these countries and the United States and other nations in the hemisphere.


Michael Zottoli and Patricia Mills - Arlington, Virginia



Michael Zottoli, 40, and Patricia Mills, 31, lived together in an Arlington, Virginia apartment. According to this profile by KATU, the couple lived in five different apartments in Seattle, Washington between 2002 and October, 2009. Zottolli claims to be born in Yonkers, New York, although he may have entered the country as late as 2001. Mills claims to be a Canadian citizen who has lived in the US since 2003. They have at least two children, according to a former landlord.

Zottoli and Mills were students at the University of Washington, according to this Seattle Times piece by Jonathan Martin and Christine Willmsen, which says they were married in King County in 2005 and graduated with degrees in business in 2006. Although both have social security cards, the number on Mills' card belongs to someone else. After working briefly as a car salesman, Zottolli was hired in July of 2007 by "Link Conference Services". (His LinkedIn page lists him as a "senior accountant" there from July 2007 to September 2009.) He left that job telling his boss he was going to take a "six month vacation" to visit Mills parents in South Africa. Patricia told their landlord they were going to Europe. The landlord recalls they were "all about Kenny", their toddler. Zottolli's former boss says she received a reference check from a nursing home in Arlington who was interviewing him to be an accountant.

Richard Murphy and Cynthia Murphy - New Jersey


Richard and Cynthia Murphy, pictured here in a
photo obtained by the New York Daily News had a long profile published in NorthJersey.com with long interviews by several neighbors, who described Richard as "anti-social" and said they told confusing stories about their origins. Cynthia claimed to be from Toronto, but didn't recognize the name of a prominent subdivision where one neighbor had family.

We don't know a lot about Richard yet. He traveled to Russia recently on a fake Irish passport under the name of "Eunan Doherty"

Cynthia worked at Morea Financial Services, at 120 Broadway in New York, and had recently completed an MBA from Columbia University in May, with her undergrad from the Stern School of Business in 2000. Various media sources say that one of the firm's clients was Alan Patrickof, a Hillary Clinton fund-raiser who may have been mentioned in dispatches back to Russia. Patrickof says although the two have talked, their conversation was strictly about taxes.

Cynthia is actually in my LinkedIn network at the 3rd level, although she calls herself "Cindy Murphy" there. Her profile says she has been at Morea Financial Services since 1997 and that she is a "Certified Financial Planner." Three of my connections (one in Boston, one in Toronto, one in New York) have "links" who are "linked" with Cynthia. Small world!


Cyrillic spellings


For those Googling by Russian/Cyrillic spellings, they are listed here under the Cyrillic spellings of their names, with the text from a story in Izvestia.ru:

Согласно изложенным Минюстом США сведениям, в городе Монтклэр (штат Нью-Джерси) были задержаны Ричард и Синтия Мерфи; в Йонкерсе (штат Нью-Йорк) - Вики Пелаэз и Хуан Лазаро; в Нью-Йорке на Манхэттене – Анна Чэпмен; Майкл Зоттоли и Патриша Миллз, а также Михаил Семенко – в Арлингтоне (штат Вирджиния); Дональд Говард Хитфилд и Трейси Ли-Энн Фоли - в Бостоне (штат Массачусетс). Речь идет во всех случаях, кроме Чэпмен и Семенко, о супружеских парах. В розыск по данному делу объявлен его одиннадцатый фигурант – некий Кристофер Метсос.

(Translated via Google Translate:

According to the U.S. Justice Department set out the information in the city Montkler (New Jersey) were arrested Richard and Cynthia Murphy, in Yonkers (NY) - Vicky Pelaez and Juan Lazaro, in New York in Manhattan - Anna Chapman, and Michael Zottoli Patricia Mills, and Michael Semenko - in Arlington (Virginia), Donald Howard Heatfield and Tracy Lee-Ann Foley - Boston (Massachusetts). Речь идет во всех случаях, кроме Чэпмен и Семенко, о супружеских парах. It is in all cases except Chapman and Semenko, about couples. A search in the case has been announced for an eleventh person involved - a Christopher Metsos.

Anna Chapman and Mikhail Semenko vs. the FBI: Wireless Ad Hoc Networks and the SVR

The warrant for the arrest of Anna Chapman and Mikhail Semenko has been said to read "like a John LeCarre novel". Much has been made of 28 year old Anna Chapman, who is variously headlined as "Anna Chapman: Hot Russian Spy", "Flame-haired beauty", and "Glamorous Anna Chapman" in today's news stories. You can search for those elsewhere, though I suppose my favorite picture of her so far is this one that MSNBC found on her Odnoklassniki page (the Russian version of Classmates.com?): (click image for MSNBC story)

Here is an interview, in Russian, with a young entrepreneur named "Анной Чапман" (Anna Chapman) who has started a venture fund called "TIME Ventures" for Russian entrepreneurs in New York. Interesting . . .

(Click for YouTube video)


Here the only thing we'll be peeking at are the facts laid out in the warrant. Tomorrow we'll look at the other nine "illegals".

From the Warrant:

Violation of 18 USC § 371

Anna Chapman
Mikhail Semenko

From the 1990s until the present the defendants "did combine, conspire, confederate, and agree with each other to commit an offense against the US to violate section 951 of Title 18.

They acted as agents of a foreign government, the Russian Federation, including:

- June 26, 2010 - Anna Chapman met with a Russian government official in Manhattan from which she received a fraudulent passport.

- June 26, 2010 - Mikhail Semenko met with a Russian government official in Washington DC.

The "Illegals" Program



The FBI has conducted a multi-year investigation of a network
of US-based agents of the foreign intelligence organ of the
Russian Federation (the "SVR").

There are two types of SVR agents, which the Bureau refers to as "Illegals". The first type are SVR agents who have assumed false
identities, and lived in the US under the direction and control of the SVR. They receive extensive training in various forms of "tradecraft", including:
agent-to-agent communications
invisible writing
use of a cover profession

The SVR also maintains a network of illegals who do similar work but operate under their true names. This network of illegals are trained in the same trade-craft of the others, but receive shorter training in tradecraft. While the "false identity" illegals are usually paired together as part of their cover, the "true identity" illegals usually work independently.

The goal of the "Illegals" is to have long-term agents who become sufficiently "Americanized" to gather information about the US for Russia, and to be able to recruit sources in, or possibly to infiltrate, US policy-making circles.

This was spelled out clearly in an intercepted and decrypted communication from Moscow to Anna and Mikhail, they were told:

You were sent to USA for long-term service trip. Your education, bank accounts, car, house etc. — all these serve one goal: fulfill your main mission, i. e. to search and develop ties in policymaking circles in US and send intels to C.




Means and Methods of the Conspiracy



The modern age has created new forms of "drops" not seen in the movies. One of these techniques is a private Wireless network. In this form of communication, the handler and the agent exchange MAC addresses for their laptop computers, and configure their machines so that they will create an encrypted network connection only if they see the MAC address of the Wireless network card of the other device.

Anna Chapman

Between January 2010 and June 2010, defendant Anna Chapman, on at least ten Wednesdays, entered the United Nations building in Manhattan and seated herself in order to exchange files with her Russian government handlers via this technique. Some other examples are given in the Affadavit that forms part of the complaint, including:

January 20, 2010 -- Anna Chapman enters a coffee shop on the corner of 47th street and 8th avenue in Manhattan. A minivan, being driven by unnamed Russian government official #1, pulled up to the curb outside the window, and created an "Ad Hoc" Wireless Network with Chapman's laptop, allowing them to communicate via an encrypted network.

March 17, 2010 -- Chapman enters a bookstore in the vicinity of Greenwich and Warren streets in Manhattan. While inside, Russian Government Official #1 was observed loitering outside the bookstore. Three minutes after Chapman powered on her laptop, the same MAC Address observed on January 20th created an Ad Hoc wireless network and data flowed between the devices for at least twenty minutes.

April 7, 2010 -- Russian Government Official #1 was observed leaving his office. Although the MAC Address for Chapman's laptop was observed in the vicinity, it is believed Russian Government Official #1 detected surveillance and aborted his attempts to contact Chapman.

Similar exchanges were observed on April 21, 2010, May 5, 2010, June 9, 2010, and June 16, 2010, on each time, the same pair of MAC addresses created an Ad Hoc private wireless network.

Mikhail Semenko

On June 5, 2010, Mikhail Semenko was seen entering a restaurant in DC, carrying a bag. Russian Government Official #2 arrived at the restaurant in a car with diplomatic license plates and sat in the car in the parking lot for twenty minutes before driving away. An Ad Hoc private wireless network was established shortly after the arrival of the car, and dismantled shortly after the departure of the car. It is believed that SEMENKO performed communications from a laptop in the bag he was carrying during this time.

(Russian Government Official #2 was involved with a "brush-pass", exchanging identical packages with a co-conspirator, back in 2004 at a train station in Forest Hills, New York.)

Anna Chapman gets an FBI Handler


On June 26, 2010, Anna Chapman met with an undercover FBI agent in Manhattan, who had arranged a meeting with her to discuss her "Wednesday" covert laptop sessions. Apparently Chapman had been having technical difficulties with her laptop, and the FBI took the opportunity to reach out to her, suggesting that she was ready "for the next step". Although the telephone calls with UnderCover-1 were in Russian, when they met in person, UC-1 suggested they speak in English "to not draw attention to themselves". A transcript of their conversation is part of the court documents.

UC-1 says that Chapman has done well with the laptop, but now it was time to the next step. The subject of her broken laptop came up in the course of conversation. UC-1 mentions that he would be happy to take it and have it repaired, or she can take it to the Consulate herself. Chapman told UC-1 "It would be more convenient if I gave you it." To avoid blowing cover, UC-1 continued with the task, which was providing a fake passport to Chapman which she was supposed to convey to another agent.

UC-1 tells her that she is to sit on a certain park bench, holding a magazine in a certain way. The other agent will approach and say "excuse me, but haven't we met in California last summer?" Chapman was to reply "No, I think it was the Hamptons," which would be the signal that everything was ok. The other person would then take the magazine, with the passport. If the pass was successful, Chapman was to return to a city map on an outside display and place a postage stamp on the map. That would be the way UC-1 would know everything went well.

An hour after this meeting, Chapman entered a CVS pharmacy, then a Verizon store, then went to a Rite Aid pharmacy, then back to the Verizon store. When she exited the Verizon store the second time, she discarded a bag. The receipts and packaging in the bag indicated she had bought a Motorola cell phone and a "TracFone" calling card. The customer agreement was for "Irine Kutsov" who lived at "99 Fake Street". She discarded the charger that came with the phone, indicating that she probably didn't intend to use it for more than that day.

Mikhail Semenko gets an FBI Handler



Using a very similar method, and on the same day, Semenko meets with an Undercover FBI Agent (UC-2). UC-2 also has a "next step" task for Semenko. He provides an envelope with $5,000 and a map indicating a drop spot beneath a bridge in a park in Arlington between 11 and 11:30 AM the following day. During the same conversation, UC-2 indicates that there were problems receiving the file from the Wireless network at the restaurant, and tries to elicit more information from Semenko about what the problem may have been. Semenko says that he did everything right - he made the file and zipped it - and the computer turned itself off after the file was sent, which is the sign that the transfer was successful.

Based on the information above, FBI Special Agent Amit Kachhia-Patel requests a warrant for the arrest of Chapman and Semenko, which was signed on June 27, 2010 by US Magistrate Judge, the Honorable Ronald L. Ellis, of the Southern District of New York.




For some interesting reading, flip up Google Translate and start following the Comments sections on some of the Russian coverage on this story:

http://www.ruformator.ru/news/article06934/default.asp

http://www.lenta.ru/lib/14206093/#4

Anna Chapman and Mikhail Semenko vs. the FBI: Wireless Ad Hoc Networks and the SVR

The warrant for the arrest of Anna Chapman and Mikhail Semenko has been said to read "like a John LeCarre novel". Much has been made of 28 year old Anna Chapman, who is variously headlined as "Anna Chapman: Hot Russian Spy", "Flame-haired beauty", and "Glamorous Anna Chapman" in today's news stories. You can search for those elsewhere, though I suppose my favorite picture of her so far is this one that MSNBC found on her Odnoklassniki page (the Russian version of Classmates.com?): (click image for MSNBC story)

Here is an interview, in Russian, with a young entrepreneur named "Анной Чапман" (Anna Chapman) who has started a venture fund called "TIME Ventures" for Russian entrepreneurs in New York. Interesting . . .

(Click for YouTube video)


Here the only thing we'll be peeking at are the facts laid out in the warrant. Tomorrow we'll look at the other nine "illegals".

From the Warrant:

Violation of 18 USC § 371

Anna Chapman
Mikhail Semenko

From the 1990s until the present the defendants "did combine, conspire, confederate, and agree with each other to commit an offense against the US to violate section 951 of Title 18.

They acted as agents of a foreign government, the Russian Federation, including:

- June 26, 2010 - Anna Chapman met with a Russian government official in Manhattan from which she received a fraudulent passport.

- June 26, 2010 - Mikhail Semenko met with a Russian government official in Washington DC.

The "Illegals" Program



The FBI has conducted a multi-year investigation of a network
of US-based agents of the foreign intelligence organ of the
Russian Federation (the "SVR").

There are two types of SVR agents, which the Bureau refers to as "Illegals". The first type are SVR agents who have assumed false
identities, and lived in the US under the direction and control of the SVR. They receive extensive training in various forms of "tradecraft", including:
agent-to-agent communications
invisible writing
use of a cover profession

The SVR also maintains a network of illegals who do similar work but operate under their true names. This network of illegals are trained in the same trade-craft of the others, but receive shorter training in tradecraft. While the "false identity" illegals are usually paired together as part of their cover, the "true identity" illegals usually work independently.

The goal of the "Illegals" is to have long-term agents who become sufficiently "Americanized" to gather information about the US for Russia, and to be able to recruit sources in, or possibly to infiltrate, US policy-making circles.

This was spelled out clearly in an intercepted and decrypted communication from Moscow to Anna and Mikhail, they were told:

You were sent to USA for long-term service trip. Your education, bank accounts, car, house etc. — all these serve one goal: fulfill your main mission, i. e. to search and develop ties in policymaking circles in US and send intels to C.




Means and Methods of the Conspiracy



The modern age has created new forms of "drops" not seen in the movies. One of these techniques is a private Wireless network. In this form of communication, the handler and the agent exchange MAC addresses for their laptop computers, and configure their machines so that they will create an encrypted network connection only if they see the MAC address of the Wireless network card of the other device.

Anna Chapman

Between January 2010 and June 2010, defendant Anna Chapman, on at least ten Wednesdays, entered the United Nations building in Manhattan and seated herself in order to exchange files with her Russian government handlers via this technique. Some other examples are given in the Affadavit that forms part of the complaint, including:

January 20, 2010 -- Anna Chapman enters a coffee shop on the corner of 47th street and 8th avenue in Manhattan. A minivan, being driven by unnamed Russian government official #1, pulled up to the curb outside the window, and created an "Ad Hoc" Wireless Network with Chapman's laptop, allowing them to communicate via an encrypted network.

March 17, 2010 -- Chapman enters a bookstore in the vicinity of Greenwich and Warren streets in Manhattan. While inside, Russian Government Official #1 was observed loitering outside the bookstore. Three minutes after Chapman powered on her laptop, the same MAC Address observed on January 20th created an Ad Hoc wireless network and data flowed between the devices for at least twenty minutes.

April 7, 2010 -- Russian Government Official #1 was observed leaving his office. Although the MAC Address for Chapman's laptop was observed in the vicinity, it is believed Russian Government Official #1 detected surveillance and aborted his attempts to contact Chapman.

Similar exchanges were observed on April 21, 2010, May 5, 2010, June 9, 2010, and June 16, 2010, on each time, the same pair of MAC addresses created an Ad Hoc private wireless network.

Mikhail Semenko

On June 5, 2010, Mikhail Semenko was seen entering a restaurant in DC, carrying a bag. Russian Government Official #2 arrived at the restaurant in a car with diplomatic license plates and sat in the car in the parking lot for twenty minutes before driving away. An Ad Hoc private wireless network was established shortly after the arrival of the car, and dismantled shortly after the departure of the car. It is believed that SEMENKO performed communications from a laptop in the bag he was carrying during this time.

(Russian Government Official #2 was involved with a "brush-pass", exchanging identical packages with a co-conspirator, back in 2004 at a train station in Forest Hills, New York.)

Anna Chapman gets an FBI Handler


On June 26, 2010, Anna Chapman met with an undercover FBI agent in Manhattan, who had arranged a meeting with her to discuss her "Wednesday" covert laptop sessions. Apparently Chapman had been having technical difficulties with her laptop, and the FBI took the opportunity to reach out to her, suggesting that she was ready "for the next step". Although the telephone calls with UnderCover-1 were in Russian, when they met in person, UC-1 suggested they speak in English "to not draw attention to themselves". A transcript of their conversation is part of the court documents.

UC-1 says that Chapman has done well with the laptop, but now it was time to the next step. The subject of her broken laptop came up in the course of conversation. UC-1 mentions that he would be happy to take it and have it repaired, or she can take it to the Consulate herself. Chapman told UC-1 "It would be more convenient if I gave you it." To avoid blowing cover, UC-1 continued with the task, which was providing a fake passport to Chapman which she was supposed to convey to another agent.

UC-1 tells her that she is to sit on a certain park bench, holding a magazine in a certain way. The other agent will approach and say "excuse me, but haven't we met in California last summer?" Chapman was to reply "No, I think it was the Hamptons," which would be the signal that everything was ok. The other person would then take the magazine, with the passport. If the pass was successful, Chapman was to return to a city map on an outside display and place a postage stamp on the map. That would be the way UC-1 would know everything went well.

An hour after this meeting, Chapman entered a CVS pharmacy, then a Verizon store, then went to a Rite Aid pharmacy, then back to the Verizon store. When she exited the Verizon store the second time, she discarded a bag. The receipts and packaging in the bag indicated she had bought a Motorola cell phone and a "TracFone" calling card. The customer agreement was for "Irine Kutsov" who lived at "99 Fake Street". She discarded the charger that came with the phone, indicating that she probably didn't intend to use it for more than that day.

Mikhail Semenko gets an FBI Handler



Using a very similar method, and on the same day, Semenko meets with an Undercover FBI Agent (UC-2). UC-2 also has a "next step" task for Semenko. He provides an envelope with $5,000 and a map indicating a drop spot beneath a bridge in a park in Arlington between 11 and 11:30 AM the following day. During the same conversation, UC-2 indicates that there were problems receiving the file from the Wireless network at the restaurant, and tries to elicit more information from Semenko about what the problem may have been. Semenko says that he did everything right - he made the file and zipped it - and the computer turned itself off after the file was sent, which is the sign that the transfer was successful.

Based on the information above, FBI Special Agent Amit Kachhia-Patel requests a warrant for the arrest of Chapman and Semenko, which was signed on June 27, 2010 by US Magistrate Judge, the Honorable Ronald L. Ellis, of the Southern District of New York.




For some interesting reading, flip up Google Translate and start following the Comments sections on some of the Russian coverage on this story:

http://www.ruformator.ru/news/article06934/default.asp

http://www.lenta.ru/lib/14206093/#4