RaidForums gets raided, alleged admin arrested
krebsonsecurity.com
krebsonsecurity.com
Not really the sharpest knife in the drawer, to do things like this and then to go holidaying in the USA with incriminating stuff on your person...
Story time:
A guy I met who did stuff that may have come to the attention of US authorities was on a plane that got diverted to the USA for a medical emergency. The guy obviously got very upset and needed to go to the bathroom, urgently, on the way there he spotted a mate of his. They didn't like each other much but got to talk for a while and they both agreed that this was the end of the line. They both expected to be arrested upon landing because the passenger manifest was shared with the US authorities because of the overflight. The one remarked to the other: 'spending the rest of my life in jail is bad enough, but now I'm going to have to spend it with you and that is so much worse'.
The person who had the medical emergency was taken off the plane to go to hospital, the flight continued on its way, no disembarkation, no checks, nothing.
>“In an attempt to retrieve his items, Coelho called the lead FBI case agent on or around August 2, 2018, and used the email address unrivalled@pm.me to email the agent,” the government’s affidavit states. Investigators found this same address was used to register rf.ws and raid.lol, which Omnipotent announced on the forum would serve as alternative domain names for RaidForums in case the site’s primary domain was seized.
I'm not surprised at all, though. These people tend not to be the brightest. If they were, they'd generally find legitimate employment, where they can still make very good money while also not constantly fearing arrest and imprisonment. Most of the people who operate and use these sites often don't have the ability to get even an entry-level infosec job.
It was the blind leading the blind but a lot of fun to watch.
yeah, in places like that you get banned for offering alternate perspectives like telling them it doesn't have the significance they think it has
better to just sell them infowars branded coffee mugs and move on.
With Cloudflare registrar I would not be surprised if they were a cooperating party in this case.
https://www.cloudflare.com/media/pdf/transparency-report.pdf - and https://developers.cloudflare.com/registrar/why-choose-cloud... indicates Cloudflare retains "the registrant email on file for that domain."
WHOIS redaction is extremely useful for shielding personal information from non-governmental entities! But US government entities have full access to any data the registrar has on file, regardless of whether they provide redaction services.
Last time I bought a domain, I did "1,lol,NYC, Dubai,90210" and other nonsense in the four fields.
Is it a compulsion to use real data and then rely on registrars promise to not disclose it?
Easy way to get a domain seized is to have it not be responding to legal notices.
>Easy way to get a domain seized is to have it not be responding to legal notices.
for such a website, seizure is ultimately going to happen regardless of response so why put themselves at more risk?
I'm sure he wouldn't let Coinbase get away with SMS 2nd factor authentication, something I can never forgive a company to do when there's big money on the line.
I did. Excellent, captivating interview, but he repeatedly acknowledged he didn't know much about the tech stuff, and he said several incorrect technical things towards the end. I stand by my statement: I think it would've been difficult for him to get a (technical) infosec job at the time of his arrest, or now (assuming a world where he didn't have a criminal record). While listening to it, I actually thought he perfectly fit the archetype of cybercrime forum operators I'm used to coming across.
He's certainly a great social engineer, and many other technically unskilled people in the cybercrime space also are. I'm definitely not discounting that ability. A lot of it comes down to brazenness; e.g. being confident and shameless enough to impersonate a law enforcement officer over the phone. There's still a lot of skill involved in being a con artist even then - you need affability and the gift of gab and all that - but it's not necessarily the kind of skill that's transferrable to technical expertise. There are many people with expertise in both areas, but also many who are exclusive to one.
Be very careful about taking infosec celebrities at face value.
Social engineering is and always has been a core feature of black hat activities. When these people graduate from criminal activities to being keynote speakers and consultants, they take their social engineering skills and use them to build a personal brand.
In other words: You were getting socially engineered through that podcast. Building an aura around himself is his business now ( https://www.anglerphish.com/speaking-consulting ).
His story is interesting and you can't deny that he's become a great storyteller. But even he admitted that he wasn't the strongest on the technical side of things.
Legitimite employment might not give them the needed liberty to do what they see fit.
That's true; that's why I tried to qualify it with "generally". There certainly are some very intelligent, skilled people who are capable of finding legitimate employment and instead choose to immerse themselves in the criminal underworld, for various personal reasons. In practice, though, I've found them to be pretty rare.
Even among the ones who do have a desire for ultimate liberty and who see themselves as above the law, most feel like the risks greatly outweigh the rewards. Some temporary liberty in exchange for likely many years of zero liberty in a prison cell isn't a great deal. Especially when it's so easy for them to get a comfortable, high-paying legitimate job. (Admittedly, this trade-off may differ in places outside the US, where good jobs may be scarce and criminal activity may pay very well and almost always go unpunished. Assuming one has no ethical compunction, at least. Or feels certain illegal actions are ethically justifiable, like how many hacktivists feel.)
I always feel like the people who are involved in these illegal forums would have better OpsSec. The fact the feds got all of his electronic devices and within a few hours had plenty of damning information is always kind of shocking to me.
I guess that's the difference between the real criminals who never get caught and others who get greedy or too lazy in covering their tracks.
If I got a magic gift of $10 million in crypto but I had to start doing proper OpSec to hide everything on my devices and digital life, that would be a huge downgrade in my quality of life; it's not worth it.
Anyway, yes, I know there is more to it- considering who your adversary is, the limitations of your tools, and what configurations of tools are required to raise the cost of retroactive deanonymization above the capacity of your adversary. Every adversary that exists can be outwitted with some effort, if we're talking in terms of the internet and not physical security. Then there's the can of worm that is security. . .
The actor never needs to interface with anything related to their activity ever again in any way, and can only screw themselves if they deliberately tell people what they did. And even if a nameless actor does 1000 things and gets caught for only 1, because they had no name/common set of characteristics, those 1000 things cannot be tied together. They're just caught for the one thing.
So opsec is hard... if you have a big huge ego or want to maintain some kind of central infrastructure.
Well, for those that are bright, you don't hear anything at all. So it's hard to characterize all of them.
I hear something similar on shows like Dateline about how not-bright the murderers are. Yet only about half of homicides are solved in the US every year.
I was looking over Wikipedia articles on software piracy groups of the 1980s/90s the other day and it was really interesting how many of them died to either a blatantly stupid move on the part of one of their members/leadership resulting in the whole group dropping like dominoes, or a political split when the leadership could not agree on policy (especially during a leadership changeover)
It was particularly interesting to see at least one major group collapse due to leadership getting nailed on phreaking charges, which spilled over to the entire group getting nabbed on the piracy.
A few of the brightest in the scene got out when they found an opportune time, then disappeared. At least one or two of them are CEOs in big business, if the articles are to be believed. I bet one or more are reading this now, even!
People might like him better if he didn't keep making 180-degree changes to his stance on major constitutional questions.
Whichever side of that issue you find yourself on, it's disturbing how easily he could his tune.
And the only thing that's worse for them than changing their mind is when they admit they haven't come to a decision on that yet, which is just admitting up front that they don't know as much as they should and are fallible.
It's not just that we don't expect politicians to by truthful, we disincentivize and sometimes outright punish any natural and truthful behavior that we would expect in a normal person, and force them into the mold we so like to criticize.
There are so many ways in which you could be tracked that the safe assumption is that you won't be able to avoid it.
How do I get anonymous internet access, from inside my cave?
More serious, the "best" way to do crime, is probably doing crime no one (in your jurisdiction) bothers enough to demand police action.
Which is why most(?) cyber gangs are operating from russia, kasachstan, etc. against the west.
Also your list misses IP logging from ISPs.
There is a caveat to this. As the perpetrator of a crime (what and how stuff is defined as a "crime" is a different discussion), no matter how smart you (think) you are, you have to get it right every single time, in perpetuity
For law "enforcement", they only need to get it right once.
When you're doing low-level crime barely on anyone's radar, this matters little. But if you ever scale up, any mistake you may have made in the past could be used against you in the future.
Also, I'm referring to a certain subset of cybercrime. The kind associated with forums like RaidForums and HackForums and LeakForums.
> Today we were unlucky, but remember we only have to be lucky once. You will have to be lucky always
They just need to be unlucky once to go to jail.
A bit of survivorship bias at work here.
Criminal activity is more so a function of risk tolerance than intelligence. However getting caught is certainly a function of intelligence.
So your impression is that most criminals you read about being apprehended are people that seem to make many stupid mistakes. But this stupidity is heavily correlated with being caught, not necessarily with being a criminal.
That said there's probably also a (negative) correlation between extreme tolerance for risk and intelligence.
Most 21 year old kids will not know enough about opsec to understand that they don't know shit about opsec. If you know a little bit you might think "if I just do X, Y, and Z I'll be safe". I suspect once you learn a bit more about the area you will quite quickly decide that it's not actually possible to get away with this kind of thing once the cops are onto you.
Applying that to this scenario: evading/postponing arrest after the cops started to look into you is luck, never giving them reason to look for/into you is what could be considered skill.
Or even more specific: it became luck as soon as it became clear that there was an admin. A lot of criminals that get caught want to be notorious however and build their "street creds".
The book “The Mastermind” was about a guy who operated a nearly legal business that broke open the telemedicine industry, only to use the proceeds to fund wet works, piracy (not digital, like actually killing people and taking over vessels) and general shady stuff.
I think if you get a person who is motivated by money and power to a certain degree, they may actually prefer illegal business because there won’t be as much competition.
>Legitimite employment might not give them the needed liberty to do what they see fit.
That's true; that's why I tried to qualify it with "generally". There certainly are some very intelligent, skilled people who are capable of finding legitimate employment and instead choose to immerse themselves in the criminal underworld, for various personal reasons. In practice, though, I've found them to be pretty rare.
Even among the ones who do have a desire for ultimate liberty and who see themselves as above the law, most feel like the risks greatly outweigh the rewards. Some temporary liberty in exchange for likely many years of zero liberty in a prison cell isn't a great deal. Especially when it's so easy for them to get a comfortable, high-paying legitimate job. (Admittedly, this trade-off may differ in places outside the US, where good jobs may be scarce and criminal activity may pay very well and almost always go unpunished. Assuming one has no ethical compunction, at least. Or feels certain illegal actions are ethically justifiable, like how many hacktivists feel.)
I'll also add as a note that another potential explanation could be a criminal record. Someone may have all the necessary skills and experience, but may not be able to get one due to past criminal convictions.
Read Crime and Punishment by Dostoevskji.
Not if you have a world view that all risk is to be avoided and anyone who takes risk is a fool.
(and just to be clear, I think people with that world view are a major impediment to societal progress)
Most deceptions, even comically absurd ones like “dude who has two families in different cities” do not require perfect vigilance, whereas running a cybercrime forum does. I bet success at this stuff comes from having an unusually fastidious personality more than anything else.
While you’d think bright people would be smart enough to recognize these risks and the comparatively safe, lucrative alternatives available to them, I know plenty of genuinely bright people who’ve made systematically poor decisions about how to run their lives or who have personality defects that otherwise impair their ability to succeed. And that’s even despite my social circles being heavily weighted toward people who went to good universities and hold down good jobs.
I’m sure that the ability to make sound, rational, forward-thinking life choices is correlated with intelligence, but I’m not sure how strongly.
I think many constitutional protections do apply in case the USA is prosecuting an individual, eg even as a non American you could take the 5th if an American court was trying to convict you.
However, when you're asking to enter the country as a non US citizen your options are essentially to do whatever the border services agents ask you to do or turn around and go home.
IANAL but the fact that he is being charged with access device fraud might suggest that DOJ had to engage in some mental gymnastics in order to charge this. E: I’ll take that back since I actually read the indictment now, besides the usual raidforums fare he was also selling credit card data which would very much tend to attract access device fraud charges.
But yeah, definitely not the sharpest knife in the drawer.
I suspect that you are wrong about this.
https://en.wikipedia.org/wiki/Accessory_(legal_term)
"Count 1: Conspiracy to Commit Access Device Fraud (18 U.S.C. §§ 1029(b)(2)and 3559(g)(1))
Count 2: Access Device Fraud — Using or Trafficking in an Unauthorized Access Device (18 U.S.C. §§ 1029(a)(2)and 2)
Count 3: Access Device Fraud — Possession of Fifteen or More Unauthorized Access Devices (18 U.S.C. §§ 1029(a)(3)and 2)
Counts 4-5: Access Device Fraud — Unauthorized Solicitation (18 U.S.C. §§ 1029(a)(6)and 2)
Count 6: Aggravated Identity Theft (18 U.S.C. §§ 1028A(a)(l)and 2)"
If this sticks he will be gone for a long, long time, and, crucially, he handed over the the evidence himself so no amount of 'it wasn't me' is going to help here.
> Whoever, knowing that an offense against the United States has been committed, receives, relieves, comforts or assists the offender in order to hinder or prevent his apprehension, trial or punishment, is an accessory after the fact.
It’s not obvious at all that selling e.g. the leaked Linkedin database would be illegal in any way. You wouldn’t retroactively become an accessory to the original crime.
Of course, that stopped mattering the moment he started trafficking in stolen payment card information…
Trading in hacked data might not be illegal unless it’s credit card information, but your average hosting provider probably isn’t going to care about such nuances.
Dangerous nonsense. Trafficking in stolen data is illegal, please read the full indictment.
And besides, indictments are not law.
As far as I can tell, lawmakers simply have not criminalized this.
Many things that obviously should be illegal are not illegal.
As someone else mentioned, an 'access device' actually refers to many things, including emails. You have an extremely poor understanding of the law if you even remotely think that trading hacked emails would somehow be legal.
But there are in fact big infosec businesses trading them. They just brand it as “data leak monitoring” or “darknet intelligence” or whatever. Equifax does this, NortonLifeLock does this as do many others. There are also products aimed specifically for pentesters.
> As someone else mentioned, an 'access device' actually refers to many things, including emails
>”Access device" is defined at 18 U.S.C. § 1029(e)(1). Instead of using the term "credit card," or "debit/credit instrument," the term "access device" is used in the statute and is defined broadly as any "card, plate, code, account number, electronic serial number, mobile identification number, personal identification number, or other telecommunications service, equipment, or instrument identifier, or other means of account access that can be used, alone or in conjunction with another access device, to obtain money, goods, services, or any other thing of value, or that can be used to initiate a transfer of funds...." The only limitation, i.e., "other than a transfer originated solely by paper instrument," excludes activities such as passing forged checks.
How you are going to legally come up with money is the question and there are no real shortcuts there other than to get lucky. But with his skills properly applied he would have a much better chance at a nice life than he has today. Money doesn't really matter much if you're in a jail cell.
I mean, what are the odds?
I only had it happen once, but it was nuts. A guy from my previous company I ran into randomly in Frankfurt while I was on my way to India. He lives in California, I live in Chicago. We were on the same flight to Bangalore. Our trips had nothing to do with each other, other than we both work in tech and were visiting tech companies. Neither of us traveled internationally all that often.
I knew a half dozen folks with crazy "what are the odds" stories like that.
> how often people who know each other randomly run into each other in an airport.
> I mean, what are the odds?
This is explicitly stating "any two people" (and it's at an airport not a plane, so more people). But then follows up with changing the framing of question they're asking:
> I only had it happen once, but it was nuts.
The birthday paradox is only a paradox because we tend to think of birthdays in a very personal manner. So when we think of "any two people sharing a birthday" we immediately change this to "someone having my birthday", without realizing we've fundamentally changes the question we're asking.
I was in two classes where the birthday paradox was discussed, at different universities. Both times it was my birthday that was shared with someone else. What are the odds?
And what are the odds people meet in the first place? Those exact same factors are what make folks run into each other again later. It would actually be weird if you never ran into people you know.
>…Bangalore. Our trips had nothing to do with each other, other than we both work in tech and were visiting tech companies.
Bangalore is a tech city, and you both worked in tech. That's how you ran into each other.
I'll throw you another curve ball:
He was working in the same complex, and we'd run into each other at lunch.
The project he was there for was one I would have been assigned to, if I hadn't left our previous company. (I was the #1 SME for that bit of software)
Therefore, I would have been the one sent there anyways that week, and been in that area. I actually confirmed this with my old boss.
Like the birthday paradox: If there are just 23 people in a room, then there's a 50% probability that two people share the same birthday.
And is this for day-month or day-month-year?
This for day-month.
This is because the group of people who travel often is surprisingly small, and so overlap will happen much more likely than you think.
Have had a handful of similar scenarios, seeing someone I know when we are in a far-away random place. I think it had to do a lot with I was traveling frequently at the time (200K miles/year), to all kinds of random places.
I'm surprised at how few times I've run into people I know when out and about shopping or doing other normal daily activities.
I live and work in a town with a population of around 11k. Coworkers live in that town, or one about 9 miles away with a population of around 22k, or one with a population of about 41k that is about 20 miles away in the same direction as that second town so the second town is in the middle.
This area has one Best Buy, one Target, one Barnes and Noble, one Walmart Supercenter, one Office Max, one Staples, and one mall all located in the middle town except the Walmart Supercenter which is in the 11k town. There are a few movie theaters but the quality varies a lot and most people I know only go to 2 of them.
In ~20 years these are the only times I've run into people I know which out doing ordinary things:
1. Two times I ran into a coworkers or former coworker at Best Buy.
2. One time at a gas station I saw a coworker getting gas at the same time.
3. One time I ran into a coworker while grocery shopping.
4. One time I ran into my dental hygienist while grocery shopping.
5. One time my doctor was having lunch at the same sandwich shop as me.
I would have thought that in 20 years, with a pool of 2 or 3 dozen coworkers or former coworkers living in the area, I'd run into people I know a lot more often.
But I know 200 people, and I take ten flights a year, there are about 200 travellers on each flight, and such random bumpings don't happen more than once a decade. It's rather unlikely that I won't randomly bump into someone I know, on some flight, sooner or later.
But when it does happen, I'll still be surprised.
The US could have gone after him any time it wanted in nearly any country, including his home in Portugal. They actually arrested him in the UK.
This issue with the warrant when he entered was a procedural thing that appeared out of convenience. They could have cooperated with Portugal to get the equivalent done there. They just saw this low hanging fruit flagged on a flight manifest and was like "sure why not".
He was incredibly convinced of his own ability to hide his tracks because technically up to that point, his ability to hide his tracks was good. A self fulfilling prophecy of sorts.
The indictment documents a pretty lengthy sting operation.
https://en.wikipedia.org/wiki/Extradition#Own_citizens
Edit: Actually Portugal seems to make an exemption for terrorism or international organised crime. The second one might apply here.
https://fra.europa.eu/en/law-reference/constitution-portugue...
I called complete, total and utter bullshit. That's a parallel construction if I ever saw one. Very few people get their devices searched (I know maybe one in 100) and, oh-the-coincidence, this guy happens to be that "Omnipotent" admin of a cybercrime forum?
Yeah. I've got a bridge to sell you too.
That’s not what the text really suggests. It very clearly states:
> The government obtained a warrant
Which obviously means that he wasn’t randomly searched at the border, but the government knew who he was.
It’s not parallel construction, just poor wording by Krebs.
The middleman service used his personal, verified, Coinbase account. The raidforums domains were his customer service website and contact emails for Coinbase, Kraken, and PayPal. His personal gmail used recovery@raidforums.
This was a multi-country investigation. The USA were likely already aware of Coelho so when he entered the US, he was then arrested by US authorities upon landing. It doesn't say his devices were searched there and then. It said a warrant was obtained to search his device, so they would needed to have a valid reason to apply for that warrant.
You seem to be reading it as if they had no idea who he was and they randomly searched someone's electronic devices and just happened to be this guy. That's not what they're saying happened?
Edit: Breaking news is that the card is indeed believed to be from the attacker. Aside from photos on social media, the suspect also left behind a bag of other weapons and a key to a U-Haul van. I'm guessing the card may have been in said bag. I'm not really sure there is much to suspect parallel construction here.
Unless they meant he left it as a calling card, which I don't think they did, I don't see why that is suspicious, just another example of not having to make a single mistake.
Not uncommon with these types. Some former lulzsec dude got into EVE then very publicly threatened my corp with hacking/claimed he’d hacked us. Of course, he was on some kind of probation IRL that banned him even using computers/the internet. Our IT lead called the FBI and he got picked up again.
---
Not all of those undercover buys went as planned. One incident described in an affidavit by prosecutors (PDF) appears related to the sale of tens of millions of consumer records stolen last year from T-Mobile, although the government refers to the victim only as a major telecommunications company and wireless network operator in the United States.
[...]
The government says the victim firm hired a third-party to purchase the database and prevent it from being sold to cybercriminals. That third-party ultimately paid approximately $200,000 worth of bitcoin to the seller, with the agreement that the data would be destroyed after sale. “However, it appears the co-conspirators continued to attempt to sell the databases after the third-party’s purchase,” the affidavit alleges.
---
T-mobile paid 200k and got precisely nothing from it.
Also, who was hosting these guys? I remember in early 2000s (back when milw0rm was a thing) - a lot of sites like this struggled to stay online because nobody wanted to host them.
Anyways, that's a pretty stupid way to go out. And, not just because he is at fault or whatever, it sounds like they turned that site into a capitalist enterprise and that's going to hurt more than the fact that he engaged in illegal activity in the first place.
[0]: https://twitter.com/NatSecGeek/status/1513875386395987968
Epik?
Any mid-size hosting companies these days has an api, so you write scripts to deploy your (pretty simple) services on Host A with account A, and when the ban happens, move to Host B with account A, then back to Host A with account B, then host B with account B, then host A with account C, etc etc.
The insecure forum can simply be hacked and basically become honeypots.
One is not like the other two. To be honest I didn't know the Feds cared that much (comparatively speaking) about contraband. Is it because of some pressure coming from higher-up? (i.e. affected companies pressure the politicians they support => the politicians pressure the higher-ups in the FBI => those higher-ups pressure the regular agents).
Asking for a friend, of course...
Such lists can be queried by those that are properly connected, typically LE/three (and in some countries four) letter agencies if your name ever turns up in some other context and then it might be given some weight, but other than that I wouldn't expect anything to come of it assuming that you are telling the truth. Such inter-service requests for information on particular individuals are pretty regular but someone first has to ask for you by name, and in a country with proper privacy protections typically a judge would have to sign off on such a broad request, but these mechanisms are not always perfect.
Reading threads isn't a crime, but hanging out in places where lots of criminals hang out doesn't help you in the association department.
— and ‘swatting,’ the practice of making false reports to public safety agencies of situations that would necessitate a significant, and immediate armed law enforcement response.”
If he did swatting they need to lock him up for attempted murder. People die from that "prank".
Interesting comment on Krebs' article... Probably a joke, but doesn't imply great intelligence among the people involved with RaidForums if not.
[2] https://krebsonsecurity.com/2012/06/carderprofit-forum-sting...
Also, in this day of the internet, why would you need to travel with your laptop if you store the compromising data on a secure server, and then download it on a fresh computer when you get where you are going.
Some thing doesn’t add up
2. they've had a long time to build a solid case against him (and probably get info on others involved on the site)
3. he actually walked into their hands
...although I guess they did that last part for a while before they changed the graphic.
Or a redirect to phrack.org.
I like it though. A bit of punk spirit.