‘Evil Corp,’ a $100M Cybercrime Menace
krebsonsecurity.com
krebsonsecurity.com
> So, each day for several years my morning routine went as follows: Make a pot of coffee; shuffle over to the computer and view the messages Aqua and his co-conspirators had sent to their money mules over the previous 12-24 hours; look up the victim company names in Google; pick up the phone to warn each that they were in the process of being robbed by the Russian Cyber Mob.
Just assigning an agent to that seems like a dead simple way to really quickly curtail that operation.
A lot of time, complete outsiders find very high "value" tasks that they can do, seem trivial, but the organisation seems unable to "task" to someone.
A classic example is "watchdog" regulators that are supposed to police an industry. Regardless of mandate, they nearly always operate entirely via well organized, documented complaints. They don't do "outbound" policing, even if it's deeming easy & productive. The
@patio11 recently did a great post on his dealings with CROs, and such regulators make an apoearance.
Add a little risk/reward to the mix and an overarching system that impractically punishes failure to convict or prosecute, leading to risk-averse approaches, and you get a nice system that is happy to prosecute the low-level weed peddlers instead of the real players. Those people land on your desk or you get them from a traffic stop. Try to go further and you might lose your job or your pension. And, of course as a prosecutor or AG, make sure you plea-bargain everyone to boost your incarceration stats.
Lots of easy wins to cook the books without really touching on the real problem. So you've got Too Big To Fail in the black markets and the criminal world too.
(I hasten to avoid saying 'criminal-underworld' because our righteous overworld tends to be just as bad, if not worse in some cases.)
That said, the FBI is not in the pre-crime business (with few exceptions), so they're not really set up to warn businesses like I did for so many years.
This seems like a bit of a systemic defect, if you can watch a financial (etc.) crime in progress but not have the jurisdiction (or allocation) to intercede.
p.s. Shouldn't some of this fall into USSS jurisdiction?
I guess those pre-crime exceptions are the ones were the agent convinces the malcontents they're embedded with to try a little terrorism?
That's the exception, you have to justify your job and budget somehow. And nothing loosens purse-strings like the 'T-word' post 9/11. Although to be fair, the first attempt to bomb the WTC was a failed FBI Sting:
https://www.nytimes.com/1993/10/28/nyregion/tapes-depict-pro...
[“Protecting our senior citizens from criminals who target them is one of the Trump Administration’s highest priorities”](https://www.justice.gov/opa/pr/justice-department-announces-...)
Sadly, the FBI is apparently not in the business of going after the king pin either. They are prosecuting the low level money mules, who are either unwilling or unable to comprehend the need to cease and desist after a letter from the FBI.
>In many instances, my call would come in just minutes or hours before an unauthorized payroll batch was processed by the victim company’s bank, and some of those notifications prevented what otherwise would have been enormous losses — often several times the amount of the organization’s normal weekly payroll. At some point I stopped counting how many tens of thousands of dollars those calls saved victims, but over several years it was probably in the millions.
Because Mr. Krebs was doing so with good effect and as a private individual he did not face the legal firewalls in place to prevent LEOs taking such actions for corrupt or ill intent or blow investigations.
Law enforcement already masquerades online as underage girls and boys, potential terrorists searching for bomb-making materials, etc.
What "legal firewalls" would prevent them from walking a URL to see what companies are about to get robbed?
And forget about law enforcement, why wouldn't banks and payroll services do the same thing to protect their customers?
It's beyond ridiculous that our only line of defense is Brian Krebs.
None there, but the moment they have a bank freeze a company's account…
Apparently, the companies themselves called their banks to prevent the transactions. Banks do engage in effort to protect their customers and already flag questionable actions.
* You do not want to create an environment where some enjoy the protection of the FBI and others do not.
* You do not want to jeopardize an ongoing investigation or later trial.
Consider that the attackers are in different countries that are beyond the reach of U.S. federal law enforcement. The machines they used to send the spam and remote into the victim systems are usually elsewhere. The money mules are and their corresponding banks are scattered across the U.S. and Europe. The victim's bank may or may not be located in the same place as the victim. And so on. Where did the crime take place? That's a monumental challenge for federal law enforcement, and frankly the local PD is just not up to it, especially when they're up to their eyeballs in fighting crimes (often violent ones) where their jurisdiction is quite clear.
Costs consist of writing and updating the malware itself, maintaining C&C servers and hiring mules to cash out the proceeds with an 8% commission.
Maybe there are kickbacks to government authorities, though I understand kickbacks are often payments in kind, by sharing exploits with intelligence agencies.
From what we've seen out of Russia, the militarization of hacking hasn't yet evolved to private armies - so either it's all being controlled by an existing (maybe the government) or early emergent (maybe a shiny new oligarch) player or the profit margins just aren't enough to justify violence. As soon as you can make 200k by robbing a criminal you'll see it happen though.
I would be interested in what legal firewalls in particular exist - anyone have references?
My own guess would be that "don't blow the investigation" would be the catch-all phrase used to explain this situation (even if there is not investigation at time X). It seems as if the institutional mandate of law enforcement is 99% catch criminals, 1% stop crimes without catching criminals. So no one wants to be tasked in efforts to merely stop a theft and not catch a thief.
This seems much in line with the push to "get tools to catch bad guys" by weakening encryption, even if said weakening would result in many more crimes.
Somebody attempted to cash some fraudulent checks for a company I worked for, luckily this was caught by our bank before we lost any money. The NYPD had no interest in doing any more than taking a report and were extremely happy when the perpetrator attempted to cash a third check, taking the total above $100k and into FBI justification. The FBI took the report and nothing happened even though our bank was able to provide details which should have led to an arrest.
It's also the case with more serious financial crimes, eg. Ponzi Schemes. The crazy thing is some of these things are completely illegal operations, yet publicized, with brick and mortar locations. This can go on for years. Sometimes there are complaints. Sometimes it's one determined victim or would-be victim that blows the lid on the whole thing. Even then it can take time; months to years. It's an area where people have been able to get away with it, often for a good chunk of their adult lives.
And then proceed to take the force to the court for "damages".
Probably they were using Scrum.
They also have a heavy focus on counterterrorism these days, which likely makes everything else lower priority by default.
https://arstechnica.com/information-technology/2019/12/membe...
The mastermind, Yakubets, is still on the fbi’s most wanted list, FWIW.
1. https://meduza.io/news/2019/12/13/minfin-ssha-isklyuchil-iz-...
Basically, it's founder married a daughter of a high-placed FSB official and enjoys full immunity for his actions.
it's way too dangerous, and it's going to be worse and worse
What I mean is that I don't risk getting involved in a business that can attract murderers and geopolitical interests. I would be happy to work for a computer security company if it was working towards making the world a safer place, meaning searching for vulnerabilities and fixing them.
But so far the computer security market tend to favor wrongdoing, because there are no standards or political forces that encourage people to do security work for good reasons. One reason is to let intelligence agencies have the upper hand.
That's why I'm not really willing to work in security. It's an unregulated market. I think that most people who do computer security work either for governments, for blackhats, or for pointless security consulting who have a very hard time to do a meaningful job.
That really rubs me the wrong way... someone doubts the random phone call telling them they are being robbed and he acts like it was their fault for doubting?
I often spent huge chunks of my workday on the phone doing these notifications, and some were harder to track down just by Googling a name than others. I never faulted companies for reacting angrily or suspiciously to my calls; it's too bad that's the conclusion you come to from reading what I wrote. If I was ever bitter about anything related to these calls, it was that I rarely ever received so much as a thank you from the victim or their bank.
I generally welcomed the calls from police departments and FBI agents because in many cases it was an opportunity to educate them about a prolific and often hugely damaging form of fraud that they simply weren't aware of at the time. Some of these companies actually went out of business as a result of these attacks, and I did everything I could to minimize that outcome.
Anyway, I almost always found that the law enforcement person on the other end of the line genuinely appreciated my explaining my methods and how these schemes work.
Thank you!
There's nothing wrong with skepticism on the part of the victims but we're not talking about an anonymous tip off from a phone booth. He goes out of the way to share his own personal information and means of reaching him. It's not his fault that some victims decide to lash out on him emotionally. The fact that he continued to play the good Samaritan is more to his credit.
Happens often. Someone brings bad news and the recipient wants to take out their emotions on the deliverer. And, sometimes emotion can overwhelm logic.
What rubs me the wrong way is that they'd doubt the call. It'd take seconds to process "how can the attacker benefit from this" and come up empty.
After all it's not like he was calling them and offering to fix the issue, he was literally giving them a heads up, the worst that could happen is a wasted call to the bank.
Well, no. The worst (and probably very likely) thing that would happen is they would call the bank, the bank would block withdrawals from their payroll processor, and they would miss payroll for that period. This could also have severe financial consequences for the company's employees, given how many people live paycheck to paycheck.
Small businesses are constantly inundated with all varieties of scam calls, so it's not at all unreasonable to be suspicious of someone who calls you out of the blue and says, "Your payroll accounts have been hacked, and you’re about to lose a great deal of money. You should contact your bank immediately." The odds of ever getting a call from a good samaritan like Brian Krebs are vanishingly small, while you're probably getting called by scammers every day.
He says right there, the fraudulent payroll payments were many times the normal amount and not part of the normal cycle.
In fact, from what he described, even the bank would have picked up on the fraudulent transactions upon human review.
Small businesses are not going to confuse out-of-cycle payroll payments with normal ones, cash flow is way too tight for mistakes like that. -
I'm also not saying it's unreasonable to be suspicious of the call, but after that initial suspicion, it's unreasonable not to hang up immediately on the scammer... then make a "sanity call" to bank/payroll processor/both
The other comment is arguing you could accidentally cancel payroll, which tells me they've never had to worry about payroll before.
This one is claiming I'm advocating making a "security decision based on...".
-
It's making a sanity check based on a few seconds of conversation.
If you didn't know, confirming a withdrawal for many times your normal payroll from your payroll account to an unknown account at the wrong time is fraudulent takes very little effort past a phone call.
That effort is easily worth it based on an off-the-cuff risk assessment.
When arguing from an armchair on the internet, somehow people forget what actual uncertainty under stress is like.
Amazing....
And the picture of the Russian tool in question, with his cat and his clothes. Could he be anymore more stereotypical Russian Goon looking?! He looks like the evil character in an Austin Power's movie...
Cannot run a simple PHP forum securely.
To the hackers, it's likely a cost of business.
Arrest Flyman.
I actually enjoy the hackers' questionable taste and extravagant lifestyle -- it's like Russian hackers are becoming self aware and having fun with it. They seem like they'd be cool to hang out with if you were interested in also defrauding millions from innocent people (which, alas, I am not).