Saturday, November 20, 2010

Lin Mun Poo: Hacker of the Federal Reserve and ...?

** UPDATE: Poo arraigned and in custody **

On October 21, 2010, Malaysian citizen Lin Mun Poo landed at the JFK airport in New York and and hit the streets to make a business deal. He was taken into custody a few hours later, after meeting with a "carder" who had offered to give him $1,000 cash for 30 active credit and debit card numbers. When the meet went down, in Queens, New York, it turns out the carder was an undercover Secret Service agent. His laptop computer was searched and found to contain thousands of stolen credit and/or debit card numbers, as well as log files indicating multiple servers belonging to various financial institutions had been infiltrated. (From Case 1:10-mj-01240-VVP, PACER)

He was arrested and arraigned on a probable cause affidavit from the US Secret Service stating that "in or about and between September 2010 and October 21, 2010, both dates being approximate and inclusive, within the Eastern District of New York and elsewhere, the defendant LIN MUN POO did knowingly and with intent to defraud produce, use and traffic in one or more unauthorized access devices, and by such conduct did obtain $1,000 or more during that period."

As the affidavit makes clear, that wasn't all that was going to be charged, but this violation of Title 18 USC § 1029(a)(2) - "Fraud and related activity in connection with access devices" - was enough to get POO picked up and held.

Poo was taken into custody, and Justice argued he would be a flight risk, so he should be held. *UPDATE 22NOV2010 @ 1300* - Poo was arraigned today, pleading not guilty. He was remanded into custody and will be held without bail until at least his next hearing on December 20th! A copy of his Detention Letter is available courtesy of the Eastern District of New York.

A Press Release from the Eastern District of New York Department of Justice has the headline Malaysian National Indicted for Hacking into Federal Reserve Bank and continues "Defendant's Criminal Activities Extended to the National Security Sector."

Poo was in possession of 400,000 stolen credit and debit card numbers at the time of his arrest. According to the Press Release, "the defendant made a career of compromising computer servers belonging to financial institutions, defense contractors, and major corporations, among others, and selling or trading the information contained therein for exploitation by others."

While the headline is all about the Federal Reserve Bank of Cleveland, Ohio, an SC Magazine article by Dan Kaplan downplays that aspect of the story. In a statement Dan received for his story, Malaysian Man Charged with Hacking into Bank Systems, Fed spokeswoman June Gates said "There's been some confusion based on the wording in the Department of Justice news release. The incident here involved a test computer that is used to test software and applications. No Federal Reserve data or information was accessed or compromised."

The confusion comes from a misunderstanding of the Detention Request filed by justice, which states:
the defendant admitted that he compromised a computer network of the Federal Reserve Bank (“FRB”) by exploiting a vulnerability he found within their secure system. The FRB in Cleveland, Ohio has confirmed that an
FRB computer network was hacked in approximately June 2010, resulting in thousands of dollars in damages, affecting ten or more FRB computers, and forming the basis for Counts Three and Four.


It is not necessary to steal data to cause thousands of dollars in damages.

What should be of bigger concern are the other victims of Poo's hacking. One of these was FedComp, described as a data processor for federal credit unions. As a result of the FedComp breach, the New York Press Release says Poo "was able to gain unauthorized access to the data of various federal credit unions, such as the Firemen's Association of the State of New York and the Mercer County New Jersey Teachers." Another was a system belonging to a DoD contractor "that provides systems management for military transport and other military operations, potentially compromising highly sensitive military logistics information," according to the Press Release.

The four-count indictment against Poo, filed Nov 18, 2010 in Brooklyn, charges the following:

COUNT ONE - Access Device Fraud
"knowingly and with intent to defraud possess fifteen or more unauthorized access devices, to wit: credit and debit card account numbers, in a manner affecting interstate and foreign commerce."

(See: Title 18 USC §§ 1029(a)(3), 1029(c)(1)(A)(i),
Fraud and related activity in connection with access devices )

COUNT TWO - Aggravated Identity Theft
"knowingly and intentionally possess, without lawful authority, means of identification of one or more persons, to wit: credit and debit card account numbers of individuals, knowing that the means of identification belonged to said persons."
(See: Title 18 USC §§ 1028A(a)(1), 1028A(b), 1028A(c)(4)
Aggrevated Identity Theft )

COUNT THREE - Unlawful Transmission of Computer Code and Commands - Federal Reserve Bank
"knowingly and intentionally cause and attempt to cause the transmission of one or more programs, infomration, codes and commands, to wit: malicious codes and commands, and as a result of such conduct, did intentionally cause damage without authorization to one or more protected computer, to wit: computer of the Federal Reserve Bank, which offense caused, and if completed would have caused, loss to one or more persons during a one-year period aggregating at least $5,000 in value, and damage affecting ten or more protected computers during a one-year period."
(See: Title 18 USC §§ 1030(a)(5)(A), 1030(b), 1030(c)(4)(B), 2 and 3551 et seq)

COUNT FOUR - Unauthorized Computer Access Involving Government Information
"knowingly and intentionally access and attempt to access one or more computers without authorization, to wit: computers of the Federal Reserve Bank, and thereby obtained and attempted to obtain information from a department and agency of the United States, to wit: the Federal Reserve Bank, which offense was committed for the purpose of commercial advantage and private financial gain.

(See: Title 18 USC §§ 1030(a)(2)(B), 1030(b), 1030(c)(2)(B)(i), 2 and 3551 et seq.)
Fraud and related activity in connection with computers

Monday, November 08, 2010

WIRED: November Jargon Watch & Forensics?

One of my NASA buddies (hi, Lisa!) dropped by last week for coffee and to catch up on the world of information management. When I introduced her to one of the PhD candidates in our lab, Brad Wardman, she dropped a stray comment "Oh, have you been following the MIT Probability Chip? It seems relevant to what you are doing..."

I haven't asked, but she may have heard about the chip in this month's WIRED magazine. Although I browse lots of magazines, I have to confess the only ones I read cover to cover every month are WIRED and Analog.

This month, three of the four Jargon Watch terms had potential Forensic Applications, so I'm doing a bit of an odd column here and talking about them in more detail. (since they aren't actually online yet, I'm not going to "quote" them. Here's a link to the last available (October) Jargon Watch which has nothing to do with this article other than to give a shout out to Jonathan Keats!) Its one of my favorite columns in WIRED each month.

For those who don't read WIRED, Jargon Watch looks for new science and technology words or phrases that are beginning to be used more broadly in the media. The three from the November WIRED that I want to dig a bit deeper on were Bacterial Fingerprints, Probability Chip, and Cybercase. I first looked at the Probability Chip because of the hint Lisa dropped, but had so much fun doing it, I decided to dig deeper on the other two as well.

Bacterial Fingerprinting


Bacterial Fingerprinting is the idea that your fingertips may have a unique bacterial colony that could be retrieved from items you touch, such as your keyboard or mouse, and used to identify you. It started inching into the public consciousness with a CBS News story back in March that covered research at the University of Colorado by Dr. Christian Lauber. According to the story, the researchers gathered swabs from the keyboards and mice of three people and compared the bacteria found there to that found on the hands of 270 random people. 87 percent of the bacteria is unlike anyone else's, according to the story. Science Daily had more facts. The researchers, who are actually at University of Colorado at Boulder had their study published March 15th in the Proceedings of the National Academy of Sciences. Noah Fierer was the lead author, with Christian Lauber and Nick Zhou. They linked together chemistry and biochemistry departments for the study. In a second phase of the study, they sampled nine computer mouses that had not been used for more than 12 hours, and were able to find their owners when mixed with the same group of 270 random people.
Fierer's Lab seems to be a publishing MONSTER on this and related topics. Here is the story "Forensic identification using skin bacterial communities", which is the BEST source for all of the above.

According to Science Daily, in an earlier study in 2008, 4,700 different bacteria species were found on 102 human hands, with only five species being shared by all participants in the study. That study was actually The influence of sex, handedness, and washing on the diversity of hand surface bacteria, which planted the seeds that your personal bacterial colony may be of forensic interest.

The Probability Chip


The Probability Chip is a new type of microprocessor that claims to not use the traditional 0 and 1 that has been computing's mainstay since the days of the vacuum tube, but rather a new type of logic gate that calculates the probability that a value is 0 or 1. The story was covered by ZDNet in this recent story "Start-up sets sights on probability chip". For Jargon Watch to be interested, things have to have moved out of the academic community and into "the public eye." The story feature Lyris Semiconductor, an MIT startup.

On the company's website, they claim that with this new approach "many applications that today require a thousand conventional processors will soon run in just one Lyric processor, providing 1,000x efficiencies in cost, power, and size."

They go into more details, showing a demo that uses their new programming language that will take advantage of this new form of chip, called "PSBL" or "Probability Synthesis for Bayesian Logic".

So where is the Forensics link? They also have a demo about clustering where they have various typists type on a keyboard and log the timing and sequence of their keystrokes to create a forensic signature of their typing style. They claim "probability processing" would be especially strong at this type of calculation, and then they go on to imagine spam filtering as well:

"...It can tell which text was entered by which person. In the real world, this could help identify unauthorized access to a computer merely by observing the rhythms and typing habits of the designated user, and determining when someone else is accessing their computer.

This same class of computations can be used to cluster data for applications ranging from network security, to spam filtering, to enterprise search."



Cybercasing


Cybercasing is the idea that when one shares pictures or information online, it could be used by a potential thief to determine the geographic location of the item they would like to steal. Additional information about that location could help them "case the joint" and determine ideal times and methods of gaining access. This was described in The Atlantic's story "How Tech Savvy Thieves Could Cybercase Your House" which quoted a paper published in August at the Fifth USENIX Workshop on Hot Topics in Security (HotSec 10) by Friedland and Sommer of Berkeley's International Computer Science Institute (ICSI): "Cybercasing the Joint: On the Privacy Implications of Geotagging". You can read their full paper from the author's website, or see an Abstract or the Slides from the HotSec conference.

Gerald Friedland went on to create the website PleaseRobMe.com talking about some of the geotagging things we do (and possibly shouldn't) including taking GPS-labelled photos (Geotagged) with our iPhones, and playing "Foursquare", a game where people "check in" to let the world know their exact geographic location at all times.

WIRED Plug


So, go subscribe to WIRED magazine!

Friday, November 05, 2010

Minipost: NY Zeus "At Large" Codreanu and Adam captured

We've previously posted about the FBI's Operation ACHing Mule (that's A-C-H as in Automated-Clearing-House, the way American banks send money between themselves) and the 17 Wanted Zeus Criminals who were still at large for their roles in moving massive amounts of money to Eastern Europe.

While we previously shared some fun Facebook photos of the "at large" criminals, we were encouraged to wait until they were arrested to share more of our findings.

Today @nigroeneveld let us know that two more of the missing baddies had been located, and were actually arrested arraigned yesterday in Madison, Wisconsin.

Graham Cluley had the first story I saw on the arrests on his Naked Security Blog, but I haven't really seen any details on how they were caught.


What do we know about how Dorin got into the country? All we have to go by is hearsay, but let's just say its interesting that convicted Zeus Money Mule Alina Turatura, at large Zeus Money Mule Catalina Cortac, and Dorin were all Facebook Friends with "Acord Travel" or Chisinau, Moldova, whose Facebook page calls them the "Lider in Programe Work and Travel" which would be consistent with the J1 Visa Travel theory.



Is Zeus connected with the Mafia? Let's just say that Dorin, whose profile picture featured himself holding a sign that reads "HELP! I Need Money for WEED!", was a level 68 criminal:




As a reminder, on April 21, 2010, Dorin Codreanu, carrying a Greek passport with his photo and the name "Savvas Paian", walked into a J.P. Morgan Chase Bank in New York and opened a new account with an initial $25 deposit. On May 4th, someone deposited $10 into the account. Then on May 11, 2010, someone wire transfered $10,246 from Illinois to the account. Within two days, $10,236 of that amount had been withdrawn, including a $800 ATM withdrawal, a $140 ATM withdrawal, and counter checks in the amounts of $2,000 and $4,800 from two different branches in the Bronx.

On May 18, 2010, Savvas Paian opened a business account at TD Bank North America in Cherry Hill, New Jersey using the same Greek Passport, in the name of "Savvas Import Group LLC". As we mentioned earlier, that's a "fruit and vegetable importer" at "1612 Kings Highway, Apartment 48, Brooklyn New York, 11229-1210 -- which used the same phone number as "Brooklyn Fruit Vegetable Growers Shippers" and "Neptune Fruit Vegetable Growers Shippers", which makes one wonder if there may be other bank accounts as well.

I think that rates as probably much lower than level 68, but I may be wrong. Dorin actually was recruiting other Moldovan students, named in the indictment as "CC-1", "CC-2", "CC-3", and "CC-4" to assist his efforts. Codreanu helped CC-1 get into the business, and CC-1 brought CC-2, who was also recruited to work under Codreanu. CC-2 received payments and made withdraws of approximately $34,000 from July 6 to July 9. CC-1 and CC-2 were arrested on August 4th, but have not been named.



Lillian Adam


Also arrested with Codreanu was Lillian Adam, also known as Roman Kobilev.

Lillian is one of four individuals named in the same indictment - the others being:

his at least sometime girlfiend, Catalina Cortac, pictured here kissing Adam on top of the Empire State Building:



Catalina Cortac, who is still friends with Acord Travel, and who claims to have successfully returned to Chisinau, Moldova.




Marina Oprea, who shares with us her "New York" photo album on Facebook, featuring bathing beauties Marina and Catalina:



I have no idea why Marina preferred to be photographed with Banks . . .





According to the Indictment, Marina opened accounts at both Chase Bank and M&T Bank, and used them to receive tens of thousands of dollars.

Ion Volosciuc --

Thursday, November 04, 2010

Sextortion Hacker: Victims sought by FBI

On September 9, 2007, I received a forwarded email that had been sent to several high school parents in the Birmingham, Alabama area. It described a chilling scenario:

We have received SEVERAL reports of an unknown subject infiltrating students' Facebook and MySpace accounts. The unknown subject has taken over several students accounts and the student no longer has access to their account. The subject has made threats for the student to do what he demands or he/she will keep their accounts locked. ... The unknown subject has been using a screen name of 'metascape'.


In April of 2009, the public learned that Metascape was actually a 24 year old from Auburn, Alabama, who had taken over more than 200 accounts from young women from ages 14 to 26, with victims in at least Alabama, Pennsylvania, and Missouri. The Birmingham News headline was Facebook Helps Fight Cybercrime and detailed more of the situation. Metascape, whose real name was Jonathan Vance, had blackmail power over the girls through sexual statements of photos he had obtained from them. In at least 50 cases, he leveraged this information to force the girls to perform more and more graphic sexual acts for him on their webcams, which he then used for greater leverage.

Birmingham FBI Cybercrime Supervisor, Dale Miskell, put it this way to the Birmingham News:

"The embarrassment factor was big in this case," said Dale Miskell, supervisory spe­cial agent for the FBI's cyber­crimes squad in Birmingham. "How can a girl go to her pa­rents and tell them what hap­pened? Even the adult victim didn't come forward until we contacted her."


Jonathan Vance was sentenced to eighteen years in his case, mostly because of the severe emotional trauma that the girls described when interviewed by prosecutors and law enforcement.

My friend Graham Cluley of Sophos mentions that there have also been similar cases in Spain, Great Britain, and Canada in his Cyber-Sextortionist blog story.

When the FBI and US Attorney's Office shared the details of the case with my Investigating Online Crime class in the summer of 2009, I hoped I would never hear of another case like it. Unfortunately, this week there has been another such case revealed.

On November 2nd, the FBI put out a press release called Web of Victims that described a nearly identical scenario involving a 31 year old Santa Ana man. Luis Mijangos was arrested in June, according to the Los Angeles Times and charged with taking over the webcams of 44 girls and 186 women. A June 22nd KABC News story reveals that the investigation was begun by the Glenndale Police Department. A UPI Story from the same day describes Mijangos as a Mexican citizen, wheelchair bound after being shot in "a gangland shooting." After that first court visit he was restricted to home and forbidden to use a computer while out on $10,000 bond. He was indicted on July 8th and charged with:

18 U.S.C. § 371 - Conspiracy
18 U.S.C. § 1341 - Mail Fraud
18 U.S.C. § 1028A - Aggravated Identity Theft
18 U.S.C. §§ 1030(a)(2)(C) and (c)(2)(B)(ii) - Accessing Protected Computers to Obtain Information
18 U.S.C. § 875(d) - Extortion
18 U.S.C. §§ 2511(1)(a), (4)(a) - Wiretapping
18 U.S.C. §§ 1029(a)(3), (c)(1)(A)(i) - Possession of more than 15 Unauthorized Access Devices
18 U.S.C. § 2(a), (b) - Aiding and Abetting and Causing an Act to Be Done

The indictment calls Mijangos a "self-employed website developer and computer consultant" and says that he used the following screen names:

gui_blt, Woods05, CiFfEjUd914m EKEvatrGZrD03, Pimpcess03666, Your3name3here03, Bri23nice, Dmagecntr137, H2IOW14, ELEvATrhRZd03, Playrgrl37, Your3name3here3, goldlion14, and Hotchit13w

and the following email accounts:

yousoylammer@hotmail.com, christ@yahoo.com, gui_blt@live.com, mistahxxxrightme@aim.com, zapotin@hotmail.com, guich_x@aim.com, guicho_1.1@roadrunner.com, and mijangos3@msn.com

PARENTS - PLEASE TALK TO YOUR DAUGHTERS ABOUT THESE TYPES OF CASES

Let them know that if they, or any of their friends, has been subjected to something like this, they need to talk with you, and YOU need to talk with the FBI. Especially if you have information regarding one of the screen names or email addresses above. The 18 year sentence for Metascape was because victims came forward and talked freely (albeit painfully) about their victimization. Don't let these creeps get away with this, and don't let YOUR daughter live in shame because she is worried you will flip out.

The indictment names criminal acts from as far back as November 26, 2008, Mijangos and co-schemers throughout the world developed malware that would give him complete control of a computer, including keylogging for identity theft, and webcam and microphone control.

With the keylogged data, they would engage in credit card fraud. Mijangos was a better hacker than metascape. He would use computers belonging to teenage boys, and FROM THEIR COMPUTERS, trick their female friends into sharing intimate videos or images. He would then contact the women and girls directly, disclosing that he had these videos and images, and threatening to post them online if they did not share additional images and videos.

Some of the co-conspirators named (by screen name) include "Manhattan" and "Demonio666vip". One co-conspirator ordered stolen goods using the name "mauricio garza arcos" and the email "statikgto@gmail.com". This is probably "St4t1k" of the "Money Buster Team".

UAB Computer Forensics Research Laboratory has determined that demonio666vip and st4t1k were both members of the hacker website "indetectables.net" and were involved in the trade of "undetectable" BiFrost servers. BiFrost is a "RAT" or "Remote Administration Trojan" which was likely involved in the case above.



Indetectables.net, so named for their distribution of undetectable malware, has 30,242 users who have posted 133,942 messages about hacking and malware.

Monday, November 01, 2010

USAA Phish: Avalanche uses many "redirectors"

A hard-hitting phishing campaign is trying to steal login credentials from the customers of USAA bank. Reports from all over are indicating the emails slide right through spam filters.

The emails look like this:



Dear USAA Customer,
We would like to inform you that we have released a new version of USAA Confirmation Form. This form is required to be completed by all USAA customers. Please use the button below in order to access the form.


Although the spam is coming from all over the world, of 309 computers which have sent a copy of this spam to the UAB Spam Data Mine so far, 77 of them are in Russia, 40 in Ukraine, 29 in India, 18 in Brazil, and 12 in Belarus. The single largest sending ISP is URKTelecom in Ukraine.



There are several reasons for thesuccess. First, the phisher is using an unusually wide variety of spam subject lines, such as:


account notification: security alert Mon, 1 Nov 2010 22:29:32 +0300
Automatic notification
Automatic reminder
Automatic reminder
Enhanced online security measures
Enhanced online security measures [message ref: 3986632685]
Important alert [message ref: 8656525645]
Important alert Mon, 1 Nov 2010 22:10:09 +0200
important announce
important banking mail from USAA - Ref No. 911592
important instructions
Important security alert from USAA Mon, 1 Nov 2010 22:27:09 +0530
Important security update - Ref No. 867527
information from USAA customer service
information from USAA customer service team Mon, 1 Nov 2010 22:08:41 +0200
instructions for customer
instructions for our customers
Instructions for USAA customer
instructions from customer service team
Message from customer service Mon, 1 Nov 2010 09:45:22 -0800
message from customer service team (message ref: 5833415494)
new online security measures
new online security measures
new online security measures
New security measures Mon, 1 Nov 2010 20:15:10 +0100
new USAA form
new USAA form released
Notification
Official update
official update (message ref: 1785474186)
safeguarding customer information
scheduled security maintenance
Security alert
security alert
Security maintenance - Ref No. 390744
Service message from USAA
Service message Mon, 1 Nov 2010 22:47:50 +0500
Service notification from USAA
Software updating [message ref: 3352139151]
urgent message for USAA customer
urgent message from USAA Mon, 1 Nov 2010 11:38:23 -0800
urgent notification from customer service
urgent notification from customer service (message ref: 4130612339)
Urgent notification from customer service Mon, 1 Nov 2010 20:03:03 +0200
USAA customer service informs you
USAA customer service: account notification (message ref: 1265140610)
USAA customer service: account notification Mon, 1 Nov 2010 15:55:27 -0300
USAA customer service: important notification
USAA customer service: important security update
USAA customer service: instructions for customer
USAA customer service: instructions for customer
USAA customer service: instructions for customer Tue, 2 Nov 2010 01:34:18 +0530
USAA customer service: new online form released
USAA customer service: official information
USAA customer service: official update
USAA customer service: security alert
USAA customer service: security issues
USAA notification (message ref: 6543359729)
USAA online form (message ref: 8649844530)
USAA reminder: notification
USAA: customer alert
USAA: customer alert Mon, 1 Nov 2010 19:30:31 +0300
USAA: customer alert Mon, 1 Nov 2010 19:31:52 +0300
USAA: important announce (message id: 5905706704)
USAA: important announce
USAA: important information
USAA: important message
USAA: important message (message id: 8210883971)
USAA: important notification
USAA: important security update
USAA: notification Mon, 1 Nov 2010 22:39:46 +0300
USAA: security alert (message ref: 7918345647)
USAA: service message
USAA: service message
USAA: service message
USAA: service message Mon, 1 Nov 2010 20:18:41 +0300
USAA: urgent message Mon, 1 Nov 2010 20:58:50 +0300
USAA: urgent notification Mon, 1 Nov 2010 19:52:51 +0100
USAA: urgent security notification (message ref: 8157388415)


But the phisher is also not placing a direct link to his criminal website in any of the emails. Instead we have seen more than 200 URLs which used the "bit.ly" URL shortening service. Other URL shortening services deployed by this phisher include migre.me, thesurl.com, tinyurl.com, and j.mp. In addition to these traditional shorteners, the criminal has also created at least 290 "free" .tk domains using the service to create realistic looking domain names to redirect to their phishing site.

The actual phishing site looks like this:



The "CARDHOLDER FORM" is actually hosted on randomly generated hostnames on the domain name "vsdfile.ru". Some examples of the random domains would be:

session1007435456.usaa.com.vsdfile.ru

the path "inet/ent_chform/" is used on that server, regardless of the random numbers in the "session" portion of the URL.

The webserver seems to be fastflux hosted. We've seen the domain resolve to:

24.115.37.183 = PenTeleData - (Pennsylvania)

24.177.87.49 = Charter Communications - this IP has also hosted pill spam domains, such as xxpillsx.com, xxmedx.com, and approved-cvs-drugs.com

24.178.114.105 = Charter Communications (Georgia) (also hosting fastflux domains mtr5.com, mjp9.com, and qettt.com)

24.224.34.92 = CMA Cablevision (Dallas, TX)
67.161.113.88 = Comcast Cable (Washington)
67.244.129.9 = Rochester NY rr.com
75.49.17.139 = AT&T
94.178.170.12 = Ukraine UKR Telecom
95.79.67.201 = Russian Federation
98.67.62.187 = Bellsouth.net Macon, Georgia
98.198.202.128 = Comcast Cable (Texas)
170.51.59.219 = Paraguay
173.22.138.58 = MediaComBB.net
173.35.254.72 = Rogers Cable (Canada)
173.93.133.191 = Columbia, SC RR.com
174.57.49.182 = Comcast Cable
190.64.185.19 = Uruguay
190.209.140.81 = Chile
200.150.42.146 = Brazil

While almost none of the spam is coming from the US, almost all of the website addresses are in the US. That's because the spammers need fast sites that can resolve the webpages quickly for their US based victims, but the speed of their spam is irrelevant.

Sunday, October 31, 2010

With GlavMed gone, who is the King of Pharm Spam?

Last week the anti-spam community was abuzz with the news that Igor Gusev, the CEO of DespMedia, and the man behind GlavMed and SpamItDotBiz had been charged in absentia for running an unregulated internet company. The New York Times had an excellent story on the potential impact on spam.

At the end of this Russia Today article the author suggests "Glavmed partners are preparing to join a new pharmaceutical partnership program if the current one is shut down. Then it will be business as usual."

Where might they be going? Based on what we are seeing in the spam there are a few obvious choices. Most of the spam we have been receiving at the end of last week and through the weekend - more than 20% of our total spam volume - points us to domains that look like this:



Although "US Drugs" has had many look and feels, the thing that ties together this affiliate program is the phone number (800) 998-7978

This phone number is on many different pharma websites, some of which have harder narcotics, such as Vicodin, Percocet, and Hydrocodone such as "buy--viagra.net". These websites are often hosted on a Russian ASN belonging to Galant Ltd, but one of the spam campaigns is currently on Moldovan site AS49544, Complife, which we have seen hosting 1,783 distinct spammed pharmaceutical domains since October 19th on the IP 194.0.221.4 (click for list).

Another of the pharm sites that also uses the telephone (800) 998-7978 looks like this:



This group is currently hosted in Romania, on the IP address 86.55.211.152 (click for list) which has hosted 641 pharma domains since October 26th! prior to that, 2,271 times these domain names were hosted on 86.55.243.102 (click for list).

That leading group is followed by a close second, also almost 20% of our spam volume - for Pharmacy Express:



One of the main locations of this spam campaign's websites has been 188.95.159.61 (click for list) which has hosted 1,060 pharma domains since September 21st! Going back further, there were OEM Software sites and Casino spam sites hosted on the same IP.

Those two prominent spam affiliate programs are followed by a host of also-rans, including:

MediTrust



Acai News

Wednesday, October 27, 2010

Work From Home Scams: IC3 Advisory

This past week the Internet Crime & Complaint Center (IC3.gov) in conjunction with the FBI, the US Secret Service, and the Financial Services ISAC (FS-ISAC)released a Fraud Advisory regarding Work From Home scams. In particular, they are trying to raise awareness of many schemes which lead to individuals serving as Money Mules for organized crime.

We've shared several examples of Money Mule recruitment scams in the past, including:

- Sep 4, 2008: Work At Home...for a Criminal? - several scams, including money mule scams, were described

- Sep 19, 2008: CareerBuilder Scams - scroll down for a "Walker & Sons" position as a "Financial Coordinator"

- Dec 8, 2008: Fake UMB Bank - scroll down for a "Regional Financial Representative" position at "BMS" to be described

- July 24, 2009: From Russia With Love - scroll to the bottom of the article to see a Mule Recruitment site called "Angle Protective" hiring "Customer Service Specialists"

- Nov 19, 2009: Running out of Money Mules? - ABC Web Design claims to be hiring "Financial Managers" who are actually laundering money.

- July 3, 2010: Stealing $10 Million 20 cents at a Time - where US citizens were recruited to open businesses to receive fraudulent credit card payments - another form of money muling.


On October 1, 2010 the FBI Announced "Operation Trident BreACH" which described money mules used to steal more than $70 Million! In this case the Money Mules were Russian and Moldovan students working in the New York area on J1 Student Visas. The point of the new advisory is that most Money Mules working in the US are actually American citizens who have been recruited through these Work From Home emails to use their checking accounts to move money out of the country.

Here are a few of the scams we are seeing in the UAB Spam Data Mine recently.

CareerBuilder reply

This email arrives with a graphical layout that tries to invoke CareerBuilder.com:



The body of the email is a classic mule recruitment ad - promising huge earnings for tiny amounts of work - and mentioning email and finances:

Hello,

Hope this email will find you at your best.

I came across your resume on CareerBuilder and I am contacting you in regards to an excellent job opportunity. Your skill sets and experiences appear to align well with the position I am looking to fill.

I've attached the job description details below. Please take a look and let me know if you would be interested in pursuing this further.

Job Description & Requirements

Check e-mail three times per day.

Preparing brief summary reports, and weekly financial reports.

Proficiency in using Microsoft Office.

Good communication skills in English (both verbal and written)

Possess good interpersonal skills.

Self-motivated and capable of working independently.

US Citizen, GC Holder

We offer
Salary plus commissions: $85,000-$95,000 per year
401(k) plan
Employment type: full-time/part-time

If you interested, planning to make a change, or know of a friend who might have the required qualifications and interest, please email me. In considering candidates, time is of the essence, so please reply to this email ASAP.

Thank you.

Note: I chose to contact you because your resume had been posted to one of the Internet job sites to which we subscribe. If you are not currently seeking employment, or if you would prefer I contact you at some later date, please indicate your date of availability so that I may honor your request. If you are not interested in receiving our e-mails then please reply with a "REMOVE" in the subject line. We truly apologize for the inconvenience caused.

Hiring Department

You are receiving this employment opportunity email because you uploaded your resume on CareerBuilder. If your employment status has changed or you no longer wish to receive these emails, you can update your privacy and communication preferences from your resume by logging onto CareerBuilder.com or you can block this employer from viewing your resume and sending you candidate emails.
This email was sent from Account ID F893KIO989343KOA2 and by this logged in User OKDYW93499
You are currently subscribed to receive "CareerBuilder.com Customer Messages".
© CareerBuilder.com 5550-A Peachtree Parkway, Suite 200 | Norcross GA 30092

Monday, October 04, 2010

Is Russia Joining the Zeus Hunt?

Although its too early to know if this is Zeus related, Department "K", the Interior Ministry's Computer Crimes unit in Russia, released a press statement today about arrests which occurred over the weekend that sound suspiciously like the rest of the world-wide Zeus hunt. While there are really not enough details to proclaim this to be Zeus, its still praise-worthy action by the Russian government against criminals who are harming American interests over the Internet.



The headline on the official MVD website read Управлением «К» МВД России пресечена деятельность международной преступной группы, in English, Department K of the MVD suppresses the activity of an international criminal group.

The story details that a cybercrime group, lead by a Ukrainian national living in Russia, had stolen more than 20 million rubles from 17 different Russian banks between January and June 2010.

The criminal group, which consisted of at least 50 suspects, consisted of Russians, Ukrainians, and Armenians. They would use false passports to fool bank employees and establish bank accounts in assumed names. They used information stolen online to create fake credit cards which were used to steal further funds from online businesses based in the United States and the United Kingdom.

The story does not make clear how many were actually arrested, where the arrests took place, or whether all fifty suspects have been apprehended.

Those apprehended are being punished with "detention". The specific violations listed are дела по ч.2 ст.187 и ч.4 ст.159 УК РФ, parts 2 and 4 of section 187 of article 159 of the criminal code(?). According to the CyberPol.ru website, 159 is their "Fraud" statute, and 187 is the statute regarding "the manufacture or sale of counterfeit credit or payment cards and other payment documents."

The story has thus far only been seen in Russian speaking press, including stories in Kuban.kp.ru, Rian.ru, BFM.ru, and Rusnovosti.ru.


(image from BRM.RU)

While most of the stories do little more than echo the official story, BFM.ru adds the fact that the ring leader was a Ukrainian, and that SBERBANK had previously Issued a warning to their customers about a new form of fraud. In that warning, they quoted UniCreditBank director Alexander Vishnyakov warning them to never provide their PIN to anyone. Sberbank had seen an outbreak of SMS messages being sent to mobile phone numbers telling them their card was going to be blocked unless they replied with their PIN number, Expiration date, and Security Code. They also quoted HCFB's Vlad Guzhelev who said that "The amount of losses from illegal activity is very high." (Сумма потерь от противоправной деятельности очень высока. - ХКФБ Влад Гужелев.)

Congratulations to Department K! I hope they will continue to press against Cybercrime. We must all work together so that there are NO safe havens for cybercriminals.

Sunday, October 03, 2010

Sir Paul Speaks the Truth: Cyber Law Enforcement is a Good Investment

In this morning's BBC News, Metropolitan Police chief Sir Paul Stephenson is the focus of their story, Met police chief warns on internet crime. We would do well in the United States to listen to the points he is making.

Sir Paul told the BBC "If British crime gangs take up e-crime as enthusiastically as we fear, we must match the skills at their disposal." He says that for too long the attitude of the public, and presumably the funding agencies, has been "Leave cyber-crime to the banks and retailers to sort out." Sir Paul calls this a "fundamentally misguided argument."

In England and Wales there are 385 law enforcement officers dedicated exclusively to cybercrime, but 85% of those are dealing with human trafficking and child pornography issues, leaving only 60 officers to fight bank fraud. Last year the Metropolitan Police had an e-crime unit budget of only £2.75 million pounds. Yet Sir Paul says "It has been estimated that for every £1 spent on the virtual task force, it has prevented £21 in theft."

We have a very similar situation in the United States. Sir Paul says that losses in online fraud and theft reached £52 billion globally in 2007 ($82 billion USD). (Note, this is a far more reasonable number than the $1 Trillion recently fed to the Senate Commerce Science and Transportation commmitee by the AT&T CSO Edward Amoroso (6 page PDF). For more on the mythical $1 Trillion figure, please see John Leyden's Cybercrime Mythbusters story at The Reg.)

I'm totally ok with the $82 Billion figure, because I can get there with real data from scientifically based studies. For instance, the FTC's Identity Theft Survey in 2006 found that we had more than 8.3 million victims (3.3%) in the United States. Javelin Strategy's 2010 Identity Theft Survey put the number at 11.1 million US citizens, losing an average of $4,841 per person for $54 Billion in US losses. (For comparison, Javelin found 8.4 million US victims in 2006 while FTC found 8.3 million. I believe that shows their methodology is sound, and that we can accept their current numbers as well.) The losses per person average seems high when compared with actual losses reported in the FTC's annual Consumer Sentinel Report (101 page PDF) where losses were $2,721 per person for 630,604 actual reported losses, but I'm willing to accept the difference for now. Either way, lets agree that US losses for 11 million victims would be in the range of $30 to $50 Billion.

Think about those numbers another way. In 2006 we had 8.3 (or 8.4) million victims of identity theft, mostly via cyber crime means. In 2009 we had 11.1 million victims of identity theft. So the crime has increased by nearly 33% in three years. One would think this would mean we have dramatic increases in our budget to FIGHT cyber crime as well. But that is sadly not true.

Despite both the broadly held public perspection and the facts that cyber crime is increasing through the roof, the FBI's budget is only increasing by 4%. The budget states that the number of FBI Agents being requested in the FY 2011 budget is 14,169, an increase of 347 agents from the FY2010 budget. An increase of 408 Intelligence Analysts (across FBI, DEA, and ATF) is also requested raising the number of Intelligence Analysts across those three agencies to 4,558.

Similarly, despite overwhelming evidence that our court systems are overworked and underfunded, especially in their ability to prosecute cyber crime, we are only seeing a 5.5% budget increase request for FY11 for the US Attorney's offices.

What is being done to fix this? Clearly we need a dramatic increase in the number of agents and tools available to fight cyber crime. But a review of the FBI's FY 2011 budget request to congress shows that they are planning to add "Computer Intrusion" responsibilities to 163 personnel, resulting in an increase of 81 "Full-Time Equivalent" additional people to fight Computer Intrusion. (See: FY11 FBI Budget Summary (Excel spreadsheet).

These numbers are further broken down in the "Program Increases by Decision Unit" tab of the spreadsheet Exhibits: Salaries & Expenses which shows that within those 163 personnel, only 63 are agents, of which 32 are tasked to Counter Terrorism Counter Intelligence and 31 are tasked to Criminal Enterprises and Federal Crimes.

Despite the fact that the FBI is the primary law enforcement body for responding to many of the crimes passed by the Congress, the FBI does not consider crime fighting their primary responsibility. When we review their entire FY11 budget, we see that they have their mission broken down into two broad goals, and their budget divided between those goals:

GOALDescription2011 Request (000s)
GRAND TOTAL OF FBI BUDGET:$8,083,475
1Prevent Terrorism/Promote the Nation's Security$4,871,077
1.1Prevent, disrupt, and defeat terrorist operations before they occur$3,721,749
1.2Strengthen partnerships to prevent, deter, and respond to terrorist incidents$417,973
1.3Prosecure those who have committed, or intend to commit, terrorist acts in the United States$0
1.4Combat Espionage against the United States$731,355
2Prevent Crime, Enforce Federal Laws...$3,212,398
2.1Strengthen partnerships for safe communities and enhance the Nation's capacity to prevent, solve, and control crime$681,488
2.2Reduce the threat, incidence, and prevalence of violent crime$1,202,812
2.3Prevent, suppress, and intervene in crimes against children$26,035
2.4Reduce the threat, trafficking, use, and related violence of illegal drugs$91,733
2.5Combat public and corporate corruption, fraud, economic crime, and cybercrime$1,140,531
2.6Uphold the civil and Constitutional rights of all Americans$69,799
2.7Vigorously enforce and represent the interests of the United States in all matters over which the Department has jurisdition$0
2.8Protect the integrity and ensure the effective operation of the Nation’s bankruptcy system$0


This makes it difficult to tell how much money is actually being spent on Cyber crime, since it has now been lumped in with Public Corruption, Fraud, and Economic Crime, but it would be nice to think that a large part of that line item was cyber.

Does that line up with the FBI's stated priorities? At a risk of mixing church and state, a pastor I know is fond of saying "Show me a man's checkbook and I'll show you his priorities."

According to the FBI's National Security Priorities page, their top priorities, in order, are:

1. Counterterrorism (51.2% of budget)
2. Counterintelligence (9% of budget)
3. Cyber Crime (14.1% of budget - true number masked by combining #3,4,7)
4. Public Corruption (combined with #3,4,7)
5. Civil Rights (1% of budget)
6. Organized Crime
7. White Collar Crime
8. Major Thefts / Violent Crime (14.8%)

Its easy to see from the budget above that Counter Terrorism has swallowed the FBI. Yes, its their #1 priority, and that shows. But is Cyber really their #3, when, combining Cyber, Organized and White Collar Crimes together still gives them only 14.1% of the budget, while Major Thefts/Violent Crime gets 14.8%?

The argument could be made that not all Computer crime falls into the category of Computer Intrusion, but we seem similar tiny increases elsewhere. The FBI is requesting only $15 Million to improve its "Combat International Organized Crime" effort, which will only add 18 positions, including 3 agents and 7 attorneys. (See: Combatting International Organized Crime.

The President's FY 11 Budget request directs that the Law Enforcement Components of the entire US Department of Justice be increased from $12.6 Billion to $13.2 Billion. An additional cyber-related increase is not for crime fighting per se, but to increase the security of the DOJ's own computer systems and upgrade their technology.

Here is a graph from the President's budget for the Department of Justice outlining new hires:

click for larger version. Extracted from DOJ Budget Presentation.

$300.6 million to strengthen national security and fight terrorism

$234.6 million to restore confidence in our markets - with a $100 million for economic fraud enforcement and $100 million for infrastructure improvements

$121.9 million to reduce the threat, incidence, and prevalence of violent crime and drug trafficking

Did you notice it too? The absence of the big increase in funding and personnel to fight cyber crime?

The FBI FY11 budget asks for 13,057 personnel in the category "Criminal Investigative Series (1811), which is an increase in 276 Special Agents.

The FBI FY11 budget asks for 3,165 personnel in the category "Intelligence Series" (0132), which is an increase in 187 Intelligence Analysts.

In keeping with Sir Paul's comments about Cyber Crime in the UK, I'd like to suggest that someone should study the above numbers, study our cyber crime laws in America and the size of the problem, and then make a determination about whether we should adding 1,000 new Cybercrime agents instead of a mere handful.

In the meantime, States need to serious study this problem as well. The message in this budget is clear. THE FBI IS TOO BUSY FIGHTING TERRORISM TO HELP YOU WITH YOU MINOR CYBER CRIMES. I am an ENORMOUS fan of the FBI, and believe that the investment to fight terrorism is necessary and beneficial. I also believe the FBI has incredible cybercrime agents, as evidenced by this week's Zeus Arrests. But its clear they don't have the manpower to scale to the size of the problem.

The FBI's Internet Crime & Complaint Center 2009 Annual Report received 336,655 complaints of victimization due to Cyber Crime and online fraud.

My question is who is supposed to be helping Ma & Pa with the identity theft that they have experienced? Who is supposed to help with the undelivered eBay goods? or the phisher who just drained your bank account? 336,655 times last year someone called the FBI and asked for help. You've seen the budget.

Something has to change.

Friday, October 01, 2010

The Big One: Zeus Operation Trident BreACH

The FBI's Cyber Division has just concluded a press conference where they announced the culmination of Operation Trident BreACH. Finally we can tell "the rest of the story" of the Zeus arrests that began in the UK earlier this week and were followed by Operation ACHing Mule in New York yesterday.

This operation began in Omaha Nebraska in May of 2009 when FBI agents were alerted that 46 separate bank accounts had received ACH payments that seemed to be tied to malware. Unveiled in this press release publicly for the first time is the fact that this particular Zeus group had attempted to ACH transfer $220 Million, and actually got away with $70 million!

On September 30th, the Ukrainian Security Service, the SBU, had fifty SBU officers as well as members of their elite tactical operations team hit eight locations looking for the leadership of this international financial cybercrime ring. They were able to arrest five of the ringleaders, who are now being questioned.

This operation included the FBI's Omaha Cyber Crime Task Force, New York Money Mule Working Group, and Newark Cyber Crime Task Force, the Netherlands Policy Agency, the Ukrainian SBU, the Netherlands Police Agency's National High-Tech Crime Unit, and the United Kingdom's Metropolitan Police Service.

Pim Takkenberg, team leader of the Netherlands National High-Tech Crime Unit was quoted as saying their "involvement in this international operation is representative of the commitment that the KLPD and the National Prosecutor's Office have made to the fight against cyber crime in addition to the need for worldwide cooperation among all partners."

Well said, Pim!

Hopefully even more details about these arrests will be revealed in the near future.

FBI's Operation ACHing Mule

While visiting a Russian news site working on getting proper Cyrillic spellings for the Zeus criminals, I saw the first time the name of the FBI Operation. "Operation ACHing Mule" -- Love it!

ACHing of course has the double meaning -- these mules are in pain (aching) -- but also that these mules are performing "Automated Clearing House" bank transfers between victim bank accounts and their "mule" bank accounts.

Here is how "webplanet.ru" spelled them in their story. I've inserted the English next to each name:

"Citizens of Russia"

Артём Цыганков (Artem Tsygankov *), Софья Дикова (Sofya Dikova *), Максим Панферов (Maxim Panferov *), Кристина Извекова (Kristina Izvekova *), Артём Семёнов (Artem Semenov *), Альмира Рахматулина (Almira Rakhmatulina *), Юлия Шпирко (Julia Shpirko *), Максим Мирошниченко (Maxim Miroshnichenko), Юлия Сидоренко (Julia Sidorenko), Кристина Свечинская (Kristina Svechinskaya), Станислав Расторгуев (Stanislav Rastorguev *), Маргарита Пахомова (Margarita Pakhomova), Илья Карасёв (Ilya Karasev *), Марина Мисюра (Marina Misyura), Николай Гарифулин (Nikolai Garifulin *), Дмитрий Сапрунов (Dmitry Saprunov *), Касум Адыгюзелов (Kasum Adigyuzelov), Сабина Рафикова (Sabina Rafikova), Адель Гатауллин (Adel Gataullin), Руслан Ковтанюк (Ruslan Kovtanyuk), Юлия Клепикова (Yulia Klepikova *) , Наталия Дёмина (Natalia Demina), Александр Сорокин (Alexandr Sorokin), Александр Фёдоров (Alexander Fedorov) and Антон Юферицын (Anton Yuferitsyn)

"Citizens of Moldova"
Марина Опря (Marina Oprea *), Каталина Кортак (Catilina Cortac *), Йон Волосчук (Ion Volosciuc *), Лильян Адам (Lilian Adam *), Дорин Кодряну (Dorin Codreanu *), Виктория Опинка (Victoria Opinca) and Алина Турута (Alina Turuta)

"Citizenship not specified"
Александра Киреева (Alexander Kireev) and Константина Акобирова (Konstantin Akobirov)

* - SEVENTEEN of the criminals listed are still "at large" are indicated above with an asterisk. If you are in the New York, New Jersey, or Las Vegas areas and party with Russian criminals, you might have more information about them. Please see yesterday's blog post, New York FBI: 17 Wanted Zeus Criminals if you think you can help.

The Operation ACHing Mule press release (34 page PDF) lists many separate but related law enforcement cases, and the charges for each case.

In each of the cases below, the charges are given and the fines. I'm going to list the charge categories here, and then we'll show the same number after each person's name:

1 - Conspiracy to Commit Bank Fraud (up to 30 years, $1 M)
2 - Conspiracy to Possess False Identification Documents (up to 15 years, $250k)
3 - False Use of Passport (up to 10 years, $250k)
4 - Money Laundering (up to 20 years, $500k)
5 - Transfer of False Identification Documents (up to 5 years, $250k)
6 - Bank Fraud (up to 30 years, $1 M)
7 - Production of False Identification Documents (up to 15 years, $250k)
8 - Posession of False Immigration Documents (up to 10 years, $250k)
9 - False Use of Passport (up to 10 years, $250k)
10 - Conspiracy to Produce False Identification Documents (up to 15 years, $250k)
11 - Conspiracy to Commit Wire Fraud (up to 20 years, $250k)
12 - Conspiracy to Commit Money Laundering (up to 20 years, $250k)

On each charge, the fine can be replaced with "twice the gross gain or loss" of their actual crime, so for example "$250k fine or up to twice the gross gain or loss."

In reality, no one ever gets NEARLY the sentence. So for example, Anton Yuferitsyn has already been sentenced. Instead of "20 years and $500k fine" he got ten months and $38k in restitution.

United States v. Artem Tsygankov, et al. (10 Mag. 2126)


Artem Tsygankov, age 22 (charged with: 1, 2)
Sofia Dikova, age 20 (1,2)
Maxim Panferov, age 23 (1,2,3)
Kristina Izvekova, age 22 (1,2,3)

United States v. Artem Semenov, et al (10 Mag. 2154)


Artem Semenov, age 23 (1,2,3)
Almira Rakhmatulina, age 20 (1,2,3)
Julia Shpirko, age 20 (1, 2)

United States v. Maxim Miroshnichenko, et al. (10 Mag. 2141)


Maxim Miroshnichenko, age 22 (1,2)
Julia Sidorenko, age 22 (1,2,3)

United States v. Marina Oprea (10 Mag. 2142)


Marina Oprea, age 20, (1,2)
Catalina Cortac, age 21 (1,2)
Ion Volosciuc, age 19 (1,2)
Lilian Adam, age 21 (1,2)

United States v. Kristina Svechinskaya, et al. (10 Mag. 2137)


Kristina Svechinskaya, age 21 (1,3)
Stanislav Rastorguev, age 22 (1,3)

United States v. Margarita Pakhomova (10 Mag. 2136)


Margarita Pakhomova, age 21 (1,3)

United States v. Ilya Karasev (10 Mag. 2127)


Ilya Karasev, age 22 (1,2,3)

United States v. Marina Misyura (10 Mag. 2125)


Marina Misyura, age 22 (1,3)

United States v. Nikolai Garifulin, et al. (10 Mag. 2138)


Nikolai Garifulin, age 21 (1)
Dmitry Saprunov, age 22 (1,3)


United States v. Dorin Codreanu (10 Mag. 2152)


Dorin Codreanu, age 21, (1)

United States v. Victoria Opinca, et al. (10 Mag. 2153)


Victoria Opinca, age 21, (1)
Alina Turuta, age 21, (1)


United States v. Alexander Kireev (10 Mag. 1356)


Alexander Kireev, age 22, (4)

United States v. Kasum Adigyuzelov (10 Mag. 1622)


Kasum Adigyuzelov, age 25, (1,5)

United States v. Sabina Rafikova (10 Mag. 1623)


Sabina Rafikova, age 23, (6,7,8)

United States v. Konstantin Akobirov (10 Mag. 1659)


Konstantin Akobirov, age 25, (6,9)

United States v. Adel Gataullin (10 Mag. 1680)


Adel Gataullin, age 22, (6, 7, 9)

United States v. Ruslan Kovtanyuk (10 Mag. 1827)


Ruslan Kovtanyuk, age 24, (6, 9)


United States v. Yulia Klepikova, et al. (10 Mag. 1753)


Yulia Klepikova, age 22 (1, 9, 10)
Natalia Demina, age 23 (1, 9)

United States v. Alexandr Sorokin (10 Cr. 437 (RWS))


Alexandr Sorokin, age 23 (4)

Plead guilty on June 16, 2010 (sentencing Oct 4, 2010)

United States v. Alexander Fedorov (10 Cr. 873 (KTD))


Alexander Fedorov, age 24 (4)

Plead guilty on September 27, 2010 (sentencing Jan 5, 2011)

United States v. Anton Yuferitsyn (10 Cr. 134 (JGK))


Anton Yuferitsyn, age 26 (4)

Plead guilty on Feb 19, 2010, sentenced on June 25, 2010 to ten months in prison and $38,413 in restitution.

United States v. Jamal Beyrouti et al.(10 Mag. 2134)


Jamal Beyrouti, age 53 (11, 12)
Lorenzo Babbo, age 20 (11,12)
Vincenzo Vitello, age 29 (11,12)

Thursday, September 30, 2010

New York FBI: 17 Wanted Zeus Criminals

The New York FBI needs your help. Today they announced indictments against thirty-seven cybercriminals involved with Zeus. Ten of these were arrested previously in the recent past. Ten more were arrested today. The other seventeen are "At Large".

I'll let you read for yourself the charges against the many criminals by visiting the FBI's New York Field Office announcement:

FBI New York Press Release

A wanted poster, showing the seventeen "At Large" criminals is available here:

Seventeen Zeus Criminals Wanted by FBI

If you find clues about any of these people make sure to get them to your local FBI office! (Send us a copy too! gar at cis dot uab dot edu)

Wanted: Ilya Karasev



Known aliases: Goran Dobric, Alexis Herris, Fransoise Lewenstadd, Fortune Binot, Diman Karasev

Status: J-1 Visa issued May 2008. Converted to F-1 Visa in December 2008. Terminated January 11, 2010

Actions:

April 13, 2010 - presented a Belgium passport in the name of Fransoise Lewenstadd to a TD Bank branch to open an account.

April 19, 2010 - presented a Greek passport in the name of "Alexis Herris" to open a TD Bank account.

June 2, 2010 - received $4200 stolen funds into the TD Bank Herris Account. Withdrew $4,000 from a TD Bank branch in Ocean Township, NJ.

July 1, 2010 - presented a foreign passport in the name "Fortune Binot" to open a TD Bank account in Brooklyn, New York

May 3, 2010 - "Herris" opened a Bank of America account. Received $12,300 in unauthorized wire transfer to that account.

May 20, 2010 - "Herris" withdrew $9,000 from Neptune, NJ branch. Made two debit card purchases totaling $3581.40 at a convenience store in Jersey City, NJ. (That's a lot of Doritos!!!)

Several more items are known with BOA withdraws from Little Silver, Little Eatontown, and Red Bank, New Jersey from a Bank of America "Fortune Binot" account.

There was also JP Morgan Chase activity.

Open Source Intelligence:

Facebook Profile

An Ilya Karasev, with many friends in New Jersey, has a Facebook account. In this picture from the account, he looks to be the same person as pictured above.



Other photos on his site include Ilya riding a bus, standing in front of Applebee's Time Square in New York. Ilya attended Volgograd State Technical University, class of 2005, where he majored in "Motor Transport."



Wanted: Dmitry Saprunov




Known Aliases: Lean Marc Garrot, Bazil Kozloff, Milorad Petrovic

Status: Entered the United States on May 19, 2009 on a visa.

A cooperating subject says that Saprunov lives as roommates with fellow co-conspirator Nikolai "Robert" Garifulin in an apartment in Brooklyn, New York. Subject says they recently accessed a safety deposit box, probably at Wachovia Bank. Gariflun recently traveled to Russia to "pay the hackers" carrying $150,000 cash concealed in his luggage.

Actions:

June 4, 2010 - Saprunov opens a TD Bank account in Manhattan using a foreign passport in the name of "Bazil Kozloff".

June 7, 2010 - Saprunov uses the Kozloff identity to open a Bank of America account in Bronx, New York.

June 11, 2010 - Saprunov opens a TD Bank account in Brooklyn using a passport from Belgium in the name of "Lean Marc Garrot".

June 12, 2010 - Saprunov opens a BOA account in Long Island, New York using the Garrot identity.

June 29, 2010 - $14,000 is wired to the Kozloff BOA account.

July 6, 2010 - just under $14000 is wired to the Garrot BOA Account.

July 6, 2010 - "Garrot" withdraws $13,9450 in four transactions from a teller and three ATM machines in Bradley Beach, New Jersey

Open Source Intelligence:

Facebook Profile:


(from the Facebook album "AVE" (Possibly Avenue New York Club?) by Sergey Palychev.
Also pictured: Alejandro Martinez, Elizaveta Osadchikh, Anastasia Yudintseva, Natalya Vassilyeva



(Interesting note: Ildar Mukhamedov is a friend of both Saprunov and Karasev on facebook, and they are friends of each others.)

Watcha Got?



More will be added as time allows. If you have something you'd like to share, send it in!

Go Go, Maltego!!


Wanted: Lilian Adam



Known Aliases:

Wanted: Marina Oprea



Known Aliases:

Wanted: Kristina Izvekova



Known Aliases:

Wanted: Sofya Dikova



Known Aliases:


Wanted: Artem Tsygankov



Known Aliases:

Wanted: Catalina Cortac



Known Aliases:

Wanted: Ion Volosciuc



Known Aliases:




Testimony from State Department DSS Agent



Wanted: Artem Semenov



Known Aliases: Valentin Kulakov, Alexey Michinnik, Arvind Shah, Fred Teschemacher, Tokin Waaran, David Warren

Entered the country June 1, 2009 on a J1 Visa, stating that he was a full-time student at Kazan State University of Technology.

Arrested December 17, 2009 by NYPD at a Manhattan branch of Bank of America, trying to open an account in the name of Nicholas Congleton. Arraigned on December 18th. Failed to appear in court on February 22, 2010.

On January 15, 2010, Customs agents intercepted a package from the Republic of Moldova destined for Artem shipping new passports to him. The passports were from the Federal Republic of Yugoslavia and were issued in the names of Petar Stojanovic and Victor Rajkov.

A collaborating witness testified that Artem recruited Almira and Julia (below) to work for him. The CW says that the two were provided with tickets to fly from New York City to Las Vegas on August 25, 2010.


Wanted: Almira Rakhmatulina



Known Aliases: Natalia Davidova, Irina Sergeeva

On June 6, 2010 Almira entered the country traveling on a J1 Student Visa stating that she was a full-time student at Omsk State University.

On July 16, 2010, Almira opened a TD Bank account in the name of Natalia Davidova using a Greek passport in that name. On July 17th, the same passport was used to open a Wachovia Bank account in New York City.

On July 20, 2010, Almira opened a TD Bank account in the name of Irina Sergeeva, using the same Brooklyn street address that she used with the Natalia Davidova account. A Greek passport for the Sergeeva alias was used as proof of identity.

A balance check of that account was made using an ATM in Las Vegas, Nevada on September 17, 2010.


Wanted: Julia Shpirko



Known Aliases: Ekaterina Kaloeva, Ekaterina Smirnova


On June 6, 2010, Shpirko entered the country traveling on a J1 Student Visa stating that she was a full-time student at Omsk State University.

On or about July 20, 2010, Shpirko opened a TD Bank account was opened in Manhattan in the name of Ekaterina Smirnova.




Wanted: Yulia Klepikova



Known Aliases:

Wanted: Maxim Panferov



Known Aliases:

Wanted: Nikolai Garafulin



Known Aliases:

Wanted: Dorin Codreanu



Known Aliases: Savvas Paian

On April 21, 2010, Dorin opened a Chase account using a Greek passport in the name Savvas Paian.

On May 11, 2010, the Chase-Paian account received $10,246 from a victim in Illionois.

On May 18, 2010, Dorin opened a TD Bank account using the same identity, but making it a business account in the name "Savvas Import Group LLC".

Open Source Intelligence:

Savvas Import Group, LLC is a "fruit and vegetable" importer, using the address "1612 Kings Highway Apartment 48, Brooklyn, NY 11229-1210", according to Manta.com.
Manta puts their phone number as 347.530.9785 begin_of_the_skype_highlighting              347.530.9785      end_of_the_skype_highlighting

That phone number also belongs to "Brooklyn Fruit Vegetable Growers Shippers" and "Neptune Fruit Vegetable Growers Shippers" which both have the same street address as well.



On June 3, 2010, the

Wanted: Stanislav Rastorguev



Known Aliases:

Wednesday, September 29, 2010

MiniPost: UK Zeus Criminals Identified

Eleven of those arrested for committing financial cybercrimes using Zeus malware in the UK have now been formally charged and named, according to a story in this morning's Guardian from which I quote:

Eight people have been charged with conspiracy to defraud and money laundering. They are Ukrainian Yuriy Korovalenko, 28, from Chingford, Essex; Ukrainian Yevhen Kulibaba, 32, from Chingford; Latvian Karina Kostromina, 33, from Chingford; Estonian Aleksander Kusner, 27, from Romford, Essex; Ukrainian Roman Zenyk, 29, of Romford; Belorussian Eduard Babaryka, 26, from Romford; Latvian Ivars Poikans, 29, from Harlow, Essex; and Latvian Kaspars Cliematnieks, 24, from Harlow.

Two have been charged with conspiracy to defraud: Ukrainians Milka Valerij, 29, and Iryna Prakochyk, 23, from Chingford.

Georgian Zurab Revazishvili, 34, from Romford, is charged with offences under the Identity Cards Act 2005.

Major Zeus Bust in the UK: Nineteen Zbot Thieves Arrested

The Metropolitan Police are to be congratulated this morning on the largest Zeus arrest to date. News broke on September 28th that the Met's PCeU Police Central e-crime Unit had arrested nineteen criminals in relation to a large Zeus or Zbot trojan network.

The Daily Mail has a set of great pictures of the criminals being taken into custody from their homes in their story, Hi-tech crime police quiz 19 people over internet bank scam that netted hackers up to £20m from British accounts. Police raided the homes simultaneously in the pre-dawn hours on Tuesday. These two pictures are part of five you can find there:





In case you don't travel much, £20 million pounds is a lot of money. That's roughly $31 Million USD. The criminals were stealing "about two million pounds per month". For comparison, the FBI released second quarter bank theft numbers last week. From April 1 to June 31 there were 1135 bank robberies and eleven bank burglaries in the United States, which earned criminals only $8 million USD or £5 million pounds.

In otherwords, this one Zeus gang stole more money in three months than ALL TRADITIONAL BANK ROBBERIES in the United States during the same length of time.

Although many folks haven't heard of the PCeU, their Mission Statement is
To improve the police response to victims of e-crime by developing the capability of the Police Service across England, Wales and Northern Ireland, co-ordinating the law enforcement approach to all types of e-crime, and by providing a national investigative capability for the most serious e-crime incidents.


15 men and 4 women were arrested, ranging in age from 23 to 47 years old. Detective Chief Inspector Terry Wilson of the Metropolitan Police credits the arrest to a Virtual Task Force composed of law enforcement, computer experts, and bank security personnel who worked together to track the movements of the criminals. Sounds a lot like the InfraGard model to me -- a private public partnership anchored on the FBI where computer security experts and personnel working in Critical Infrastructures, such as the Financial Industry, share information to stop criminals and terrorists.

Despite their financial success, the Daily Mail reports that the ringleader, "in his 20s, and his wife, an accomplice in the scam, were arrested in an unremarkable third-floor flat in Chingford, Essex.

Despite this raid, there are still at least 162 "online" Zeus servers that continue to gather stolen credentials from compromised computers, according to the invaluable ZeusTracker service.

We've documented dozens of stories in this blog about Zeus over the past year, and are excited to see this most significant law enforcement action to date.

The clock is ticking . . . who is going to have the best arrest before we all meet up in three weeks?

Thursday, September 23, 2010

eBay Spear Phisher Liviu Mihail Concioiu Arrested in Romania

IMPORTANT UPDATE


Readers of my blog will know that I have several contacts that I discuss things with in Romania. I have had further conversations with sources closely placed to this investigation that tell me the Romanian DIICOT Press Release has one rather glaring error. Press Releases are written by a media relations person, not technical people. The best explanation I can see is that a technical person explains to the media person "the criminal did a phishing attack against 1784 people and then 1521 people and he used that data to break into eBay's computers." The media person interpreted this as "stole the userids and password from 3300 people" when in reality the technical person meant "sent a phishing email to 3300 people, and got some of their passwords."

How many is some? We now believe it is SIX. Of 3300 people sent a phishing email that imitated a VPN system at eBay used by employees, we don't know how many gave up their passwords, but the criminal only tried to use six of them. The VPN site he was imitating was protected with a two-factor authentication solution, so any passwords gathered had to be used immediately, due to the rotating "secureId" style token.

I apologize for spreading false information, but the source, the Romanian DIICOT website, seemed credible to me. It was not.

Word for word, the Romanian press release reads: "CONCIOIU LIVIU MIHAIL a lansat două atacuri tip phishing asupra unui număr de 1784 de angajaţi şi respectiv 1521 de angajaţi ai companiei eBay.Inc., cărora le-a sustras ID-ul şi parola." which I believe I correctly translated.

The other error in the press release is that Concioiu is being charged with stealing $3 Million, which includes many assorted phishing and cybercrime schemes, only a portion of which was from eBay customers.

Corrected story follows



Prosecutors in the Romanian DIICOT (Direcţiei de Investigare a Infracţiunilor de Criminalitate Organizată şi Terorism or Directorate of Investigations of Organized Crime and Terrorism) announced the arrest of Liviu Mihail Concioiu a cyber criminal who stole more than $3 million USD from eBay account holders, customers of Italian banks, and unknown others.

I wanted to use that example today to illustrate a point that I raised in my presentation earlier this week as a guest of the Maryland InfraGard chapter. My presentation, called "Cybercrime: Money, Espionage or Both?" was targeted to an audience of approximately 125 composed primarily of Defense Contractors, Law Enforcement, Critical Infrastructure security personnel and other government employees and suppliers. As an InfraGard member myself, in the Birmingham InfraGard chapter it was great to spend time with one of the nation's top InfraGard coordinators, FBI Special Agent Lauren Schuler, and the outstanding leadership of their chapter including Paul Joyal, Allan Berg, and the energetic M L Kingsley who had coordinated the event.

In my presentation, I stressed two primary points. The first is that EVERY malware attack has to be fully investigated. If you don't know the origin, purpose, and targeting of a malware attack, you have no way of understanding the full impact of the malware on your organization. The second point was that it is critical that your organization has policies that help you understand when your employees have been victims of identity theft or password- or document-stealing malware -- even if it happened at home on their home computers!

The case of Liviu Concioiu drives these points home.

In 2009, Concioiu launched two phishing attacks which were only sent to eBay employees. In the first round, he sent a phishing email to 1,784 employees and in the second round, he tried again, sending an email to 1,521 more employees.

Let's stop there for a moment.

Do you recall the "Here You Have" malware last week? In my blogpost about that event Here You Have Spam Spreads Email Worm) I stressed that it was clear that the malware had been targeted against certain organizations. Did you have an outbreak in your company? Are you aware that one of the actions of the malware was to plant a very low detection version of the BiFrost "Remote Adminstration Trojan" on the infected computers? If the only action your organization took was to remove the "Here You Have" malware, they aren't finished yet. Its important to understand whether you were a target or collateral damage for the attacker, and of course its important to understand during what infection window the BiFrost trojan was also being installed.

OK, now back to Liviu Mihail Concioiu.

After collecting some eBay credentials, Concioiu realized he was defeated by the two factor authentication and came back on June 8, 2009 and attempted to phish 417 different employee identities, to explore the eBay internal network and see what useful information he could find. This time he was prepared to immediately use the credentials he harvested, and tried at least six different accounts before finding some success. His biggest find was a tool that eBay employees use to query their internal databases and look up information about eBay clients and the transactions they perform.

By reviewing the details of eBay customer accounts, Concioiu was now able to begin his SECOND TARGETED ATTACK. One of the problems with phishing campaigns is that when criminals broadly spread spam messages advertising their fake login pages, the anti-spam services and ISPs observe these spam messages and place the advertised pages on blacklists. Concioiu was able to avoid this typical phishing trap by selectively targeting his phishing emails at high value eBay customers whose email addresses he had confirmed by harvesting them from eBay's internal systems!

The result was that 1,183 eBay users were victimized!

In addition to the eBay charges, Concioiu is also charged with creating fake ATM cards for Italian banks and withdrawing more than 300,000 Euros from these accounts, and other crimes which created a total loss of $3 Million USD.

Concioiu was one of three cyber criminals arrested today by DIICOT. The case was investigated with the cooperation of the US Secret Service agents in the US Embassy in Bucharest and Italian judicial authorities.

Hopefully this example will help push home the lessons I was trying to demonstrate in Maryland this week. I have to mention one other thing about the Maryland trip. Last year I had read an auto-biography of General Oleg Kalugin, the top counter-intelligence officer of the KGB. He was the first presenter at the Maryland event, and I got to have dinner with General Kalugin the evening before. He spoke about his experiences recruiting Americans and then I attempted to show how Cyber tools make those efforts even easier today in my follow-up presentation.

General Kalugin was kind enough to autograph one of his new books, Spymaster: My Thirty-two Years in Intelligence and Espionage Against the West, which is now one of my prized possessions! Kalugin was at one point Vladmir Putin's boss in the KGB, but later became one of the most out-spoken critics of the Soviet system and especially the KGB.

Kalugin read a part from a poem about "the new Russia" as his closing statement:

There are no departments in Russia, there are friends. There are no laws, there are personal relationships. Moreover, there is no KGB. … KGB was an organization. There are no organizations in Russia now. There are principalities and feudal lands handed out in exchange for loyal service and profitability. It was not Putin who set up the system, but he did nothing to change it. He is just handing out feudal lands to his friends in order to be able to control other feudal principalities.


Profound.

(I'm not sure of the origin, but I found the quote online here: http://www.cdi.org/russia/johnson/7102a.cfm )

Wednesday, September 22, 2010

NPR CyberWar Part One: I Beg to Differ

This morning on National Public Radio, we heard a story about "CyberWar" and some of the problems that the growing reality of CyberWar is going to present.

I'll have to review the transcript more carefully, but from the first pass listen as I drove to work this morning, I believe I disagreed with every single point in the entire story. I'll try to break that down a bit here, using the story from the NPR website, Extending the Law of War to Cyberspace as my guide.

(All of the "Declarations" that I am responding to are quoted from that guiding article.)

Most Important Development in Decades?


Declaration: "The emergence of electronic and cyberwar-fighting capabilities is the most important military development in decades"

Response: Actually, if we're counting "decades", my top nominations would be the Unmanned Aerial Vehicle and the GPS-guided munitions such as the JDAM: Joint Direct Attack Munition.

CNN's headline last year was one I agree with How robot drones revolutionized the face of warfare as was more fully explained in P.W. Sanger's Wired for War: The Robotics Revolution and Conflict in the 21st Century.

The biggest benefit of the UAV's is of course that they protect our soldiers from harm, while allowing missions that would never have been completed before or that could only have been completed with extreme risk to life and limb.

Likewise, Strategy Page's article How Precision Weapons Revolutionized Warfare gives a good outline on the revolution of extremely precise weapons, packed with the right size explosive to blow up exactly what you are shooting at.

When is CyberWar Equal to Armed Attack?


Declaration: "If nations don't know what the rules are, all sorts of accidental problems might arise," says Harvard law professor Jack Goldsmith. "One nation might do something that another nation takes to be an act of war, even when the first nation did not intend it to be an act of war."

Response: There is no agreed upon definition of "Use of Force" between nations even for non-cyber incidents. This came out in the answer to a question that was put to General Keith Alexander, now the commander of the US Cyber Command from his NSA post at Fort Meade, Maryland, during his confirmation hearings. The question he was asked was:

Does DOD have a definition for what constitutes use of force in cyberspace, and will that definition be the same for U.S. activities in cyberspace and those of other nations?

His answer:

Article 2(4) of the UN Charter provides that states shall refrain from the threat or use of force against the territorial integrity or political independence of any state. DOD operations are conducted consistent with international law principles in regard to what is a threat or use of force in terms of hostile intent and hostile act, as reflected in the Standing Rules of Engagement/Standing Rules for the Use of Force (SROE/SRUF).

There is no international consensus on a precise definition of a use of force, in or out of cyberspace. Consequently, individual nations may assert different definitions, and may apply different thresholds for what constitutes a use of force. Thus, whether in the cyber or any other domain, there is always a potential disagreement among nations considering what may amount to a threat or use of force.


My point is not so much to disagree with the NPR statement here, as to point out that it is EXACTLY the same problem we have in every other kind of warfare. Cyber isn't special in this regard. Was the downing of an Chinese plane in a collision with a US spy plane an act of war in 2001? Was the North Korean torpedo attack back in May an act of war? Was the Israeli bombing of buildings in Gaza an act of war? It has always been true that each attacked country gets to decide.

More answers along this line of reasoning from General Alexander are available in his published Q&A available from Washington Post.

Rogue Actions vs. State-Sponsored


Declaration: "One important consideration is whether the attack is the work of a lone hacker, a criminal group or a government. The law of war applies primarily to conflict between states, so truly rogue actions would not normally be covered."

Response: What defines "state" action? There have been Congressional hearings on this very subject, as I discussed in my July 2010 blog post, The Future of Cyber Attack Attribution. There have also already been multiple occasions where the victim accused a state of attacking and the state denied the accusation. In the case of Russian cyber-attacks against Georgia prior to the August 2008 invasion of South Ossetia, it was clear that there were some populist activities, as I wrote in the article Evidence that Georgia DDOS Attacks Are Populist in Nature, but the coupling of the Russian tanks driving through town would seem to support the theory that at least some of the cyber attacks were designed to take out C2 ability and especially the ability of the state to communicate with the governed. In the Estonian DDOS (pdf) of May 2007, it was clear that the attack was not "by" the government, but rather by the Russian "Nashi" youth movement, possibly incited to action by the government, and possibly even using some government computers as part of the attacking DDOS.

The concept that individuals could wage cyberwar was nicely stated in the January 1999 report by mi2g: "Cyber Warfare: The Threat to Government, Business, and Financial Markets"

Historically war has been classified as physical attacks with bombs & bullets between nation states. It was beyond the means of an individual to wage war.

Today, in the Information Age, the launch pad for war is no longer a runway but a computer. The attacker is no longer a pilot or soldier but a civilian Hacker. An individual with relatively simple computer capability can do things via the internet that can impact economic infrastructures, social utilities and national security. This is the problem we face in moving from the industrial world to the Information Age, which is the essence of Cyber War.


I suppose I mostly agree with this point, except to say that there are many ways, such as the Estonia example, where a country may be so clearly involved in inciting their citizenry to "cyber attack" that a nation-level response may be warranted.


Civilian Infrastructure Attacks


Declaration: "A direct attack on a civilian infrastructure that caused damage, even loss of life of civilians, would, I think, be a war crime." - Professor Daniel Ryan, National Defense University

Response: Didn't the United States blow up electrical plants, television and radio stations, bridges, roads, runways, and water treatment plants during the two Iraq Wars? Were those war crimes, too? Professor Ryan? We have to use a consistent definition. If its not a war crime to attack civilian infrastructure kinetically, why is it a war crime to do so electronically?

Electrical Grid Targeting?


Declaration: "Former CIA Director Hayden, a retired Air Force general, suggests using common sense. One example of an attack that should be illegal, he says, would be the insertion of damaging software into an electrical grid."

Response: Why would it be illegal to damage the electrical grid with software, when elsewhere THIS YEAR General Hayden said that the electrical grid was a fair target? Hayden talked about hacking power grids at Black Hat back in July. CNET's coverage of that talk "U.S. military cyberwar: What's off-limits?" includes this thinking:

Power grids are another example of where traditional military doctrine may need to shift, Hayden said. "A power grid is, according to traditional military thought, a legitimate target under some circumstances," he said. "Mark 82s are kind of definitive and it's a one-way switch--that thing's kind of gone." (An MK-82 is a general-purpose, 500-pound unguided bomb used by the U.S. military since the 1950s.)

But destroying, or at least thoroughly disabling, a power grid through an offensive cyberattack means penetrating it well in advance. And if there are dozens of different nations stealthily invading a grid's computers and controllers all the time, it's probably not going to be stable. "There are some networks that are so sensitive that maybe we should just hold hands and hum "Kumbaya" and agree they're off limits," he said. "One is power grids...You can't just have 23 different intelligence services hacking their way through the electrical grid."


So, its ok to use an MK-82 to blow up power plants, but it should be illegal to insert software into them because that might damage them. What kind of messed up logic is that?


Hostile Intent


Declaration: The purpose of the activity is also relevant. Michael Hayden, having directed both the National Security Agency and the CIA, would not include an effort by one country to break into another country's computer system to steal information or plans. "We don't call that an attack," Hayden said at a recent conference on hacking. "We don't call that cyberwar. That's exploitation. That's espionage. States do that all the time."

Response: Hayden's definition would, I suppose, be consistent with Richard Clark's definition in his new book CyberWar: The Next Threat to National Security and What to Do About It . He says CyberWar is "actions by a nation-state to penetrate another nation's computers or networks for the purposes of causing damage or disruption."

Several organizations have attempted to define "CyberWar" and the definition continues to evolve. "CyberWar" was probably first used by Eric Arnett in his paper "Welcome to Hyperwar" in the Bulletin of the Atomic Scientists, where it referred to war by robotic soldiers. The terms "NetWar" and "CyberWar" were both defined by RAND in their report CyberWar is Coming! part of the larger nineteen chapter monograph, "In Athena's Camp: Preparing for Conflict in the Information Age", published in 1992, where the term "NetWar" was used to describe PsyOps via the Internet, while "CyberWar" was closer to its current definition.

But should CyberWar NOT include Espionage?

Much more recently, David Wilson's excellent article for ISSA Journal in June 2010, When Does Electronic Espionage or a Cyber Attack become an "Act of War?" lays out an excellent set of definitions and conditions. In his article he quotes FBI Deputy Assistant Director for Cyber, Steve Chabinsky as telling the FOSE government IT Trade Show in March that:

A top FBI official warned today that many cyber-adversaries of the U.S. have the ability to access virtually any computer system, posing a risk that's so great it could "challenge our country's very existence."


Wilson's argument, supported by Chabinsky's quote, is that "electronic espionage" can be far more pervasive than traditional espionage, and that "a nation will have to decide how much pain it is willing to endure, and where it believes the international community’s tolerance lies, assuming they care, before retaliating
against electronic attacks or invasions to its networks."

I totally agree with Mr. Wilson. The placement of the line in the sand may be somewhat arbitrary, but its quite possible for cyber espionage to become so pervasive as to pose a risk to national security worthy of an armed response.

Ninety-Five Percent?


Declaration: "Computers don't always have signs over them that say, 'I'm a military target' [or] 'I'm a civilian target,' " says Harvard's Goldsmith. "Also, the two things are intermixed. Ninety to 95 percent of U.S. military and intelligence communications travel over private networks."

Response: The Department of Defense has more than 7 million computers. I don't know how Army works, but I know the Navy Marine Corps Internet was at one time the largest private Intranet on the entire planet. The US Army has maintained a stand-alone Intranet since at least 2001, and has repeatedly had headlines about it being the largest stand-alone network in the world. Soldiers don't call down an airstrike and then update their Facebook pages and do a little online banking as the implication seems to infer.

No One is Going to Get Caught



Declaration: If anything, it would be harder to enforce the law of war in the cyberworld than in other domains of warfighting. The amount of anonymity in cyberspace means that a devastating attack might leave no "signature" or trace of its origin.

"Since we know that that's going to happen all the time," Baker says, "and no one is going to get caught, to say that [a cyberattack] is a violation of the law of war, is simply to make the law of war irrelevant."

Response: The "untraceable" network attack, despite the movie by EJ Hilbert and friends, is a myth that we are working hard to dispel at the UAB Computer Forensics Research Laboratory. What we call "untraceable" today usually means "too much work for too little reward, so nobody bothers to trace it." I think many of my colleagues in security research would love to take on the challenge of some of these "untraceable" events. Let's buy one fewer B2 Bomber this year and put that extra $2.2 Billion towards making a concerted effort to prove this one wrong. Shoot. I'll do it for half that!



For more interesting reading on CyberWar, I strongly recommend:

Congressional Research Service Report: Information Operations and Cyberwar: Capabilities and Related Policy Issues