Remember how yesterday I closed the program by suggesting that this year we will see increased governmental and corporate activity aimed against pirates, hackers and even common online hooligans with aims of making the internet more orderly so to say? Well, turns out that Russian law enforcements have just made a huge bust. The Ministry of Interior in a joint operation with the Federal Security Service have neutralized a major criminal group that has been stealing money through credit cards for over two years. According to preliminary estimates, in just last six months these criminals have stolen around 130 million rubles. The team had 8 members, most of them from Moscow. Everyone was apprehended and are charged with creation and spreading of malicious software as well as unlawful access to digital information. With all the details of the investigation currently being classified, media outlets cite sources from the law enforcements who admit this is a first time when an operation of this magnitude has been completely neutralized with the scheme and modus operandi traced by the investigators. The group has started gaining attention around two years. So what did the cybercriminals do? Well, they hacked popular websites that were frequented by accountants of large companies who use them for their work. The investigation also states that two popular online newspapers a website of a large retail chain and even of a state corporation were hacked. Basically perpetrators were targeting websites with large user base who preferably had access to numerous accounts, as the presence of specialized websites in the list suggests. These websites were infected with viruses called Carberp and Rdpdor that spread through the legitimate websites to visitors’ computers at a rate of up to 30,000 of machines per day. After the infestation process was complete, hackers connected to the compromised end user computers and scanned for those that had special software and necessary data to operate on bank accounts. The team had a special puppet master whose task was to create a money transfer order to the criminal’s account. The stolen money was then cashed in, usually through plastic cards issued to dummy companies or random people. They’ve even had a real office and according to the official paperwork the team was a company working on restoring lost data. Preliminary findings suggest clients of a total of over 100 banks all across the world were hit by these hackers. The investigation process involved independent experts such as the Group-IB. It’s the only company in Russia specializing in IT security investigations and offering consulting services starting from initial response to a leak or breach and up until the dust settles to help draw correct conclusions. Well, this company was commissioned to work the aforementioned case – its experts were the ones who eventually tracked down the digital trail to the fake company and its director, one Ilya Sachkov. While the company was registered and cashed in the stolen money here in Russia, according to Group-IB the mastermind was constantly moving around the country and even beyond the national borders, making it harder to identify the culprit through his digital wrongdoings.
Meanwhile, the first Russian criminal investigation on the subject of “phishing”, spelled with ‘ph’ has been closed, this time in St. Petersburg. Phishing is a new term, that was first introduced around in 1995. The term is a form of fishing, that is most likely influenced by the term phreaking. The latter is basically an old-school slang that was used before hacking even existed – or personal computers, for that matter. A portmanteau of “phone” and “freak”, the Esquire Magazine popularized the activity and term when it published a story called “Secrets of the Little Blue Box in 1971. Hackers, while not yet called as such, built these little blue boxes that could crack phone networks. Funny thing is, two especially notable people were inspired by this article – Steve Wozniak and Steve Jobs, who started their careers in IT by building these little blue boxes before founding Apple. Yep, one of the largest computer and gadget manufacturer of these days started off by a couple of glorified phone hooligans. But that a story for another time – for now, back to phishing. With the “ph” part explained, fishing alludes to using “baits” and lures in hopes that the potential victim will “bite” – pretty self-explanatory, really.
The baiting is usually done with something that the potential victim expects or wants and biting is them clicking a malicious link or opening a malicious attachment. Usually in this case, should anti-virus software fail to block the malware at this point, the victims’ financial information and passwords are then sent to addresses programmed by the criminals. Sometimes software isn’t even involved, at least not one that’s supposed to run on the victim’s computer. Phishers, cyber conmen, basically, can pretend to be someone they’re not to try to get information they don’t have. Do you know how various online services, especially ones with paid subscription warn users not to give private information, such as passwords, to anyone from staff? Well, there’s a reason for that. One of earliest documented instances of mass phishing involved the popular US internet service provider and internet services and media company AOL, also known as America Online. What phishers did is the posed as an AOL staff members and sent instant messages to potential victims, asking them to reveal their password. In order to provide successful “bait”, the messages included imperatives like “verify your account” or “confirm billing information”. If they gave the password, the account was then hijacked for fraudulent purposes or spamming. So yeah, this technique is over 15 years old but still quite popular – after all, gullibility does not age. Modern versions of phishing include making doubles of popular websites in order to steal account information – a while ago the popular Russian network VK was the main target. Phishers created several mirrors copying design and hosting them on servers with domain names looking very similar to vkontakte.ru. The social network was then spammed with links to these sites, promising things like finding out who visited your page, who removed you as a friend or other nonsense. Upon clicking the link the unobservant victims thought they were logged out of the social network and entered their logins and passwords, which, of course, were immediately sent to the mirror website’s creators. Another popular phishing website mirrors the design of a bank – that way not just the account is stolen, but also access to the victim’s finances, which is much more rewarding for the criminals, of course. And, much more interesting for the law enforcements to investigate. This brings us back to the here and now.
Apparently two brothers from St. Petersburg had been scouring specialized online forums for information on the operation of banking systems. They’ve also acquainted themselves with the principals of remote banking. Armed with this information and their keyboards, their criminal minds came up with a grand idea of stealing money from the accounts of one of major Russian banks. They’ve hired a web-designer-slash-student from Kaliningrad to make a semi-working copy of the web-page of the bank’s remote banking system. The fake page had different technical support phone numbers, however, that belonged to the brothers. After that they’ve purchased, yes, purchased Trojan viruses that hijacked the victim computer’s connection to the remote banking website. When the bank’s client tried accessing remote banking, it appeared that he did – while in fact they visited the fake website, the pages were identical and the address looked the same courtesy of the virus program. The functionality was partially preserved. Such systems require personal data not only to login, but often another code required to be entered at the time of each monetary transaction. So if login and password were stolen, criminals would be able only to observe, read financial statements and whatnot, but unable to actually steal money. Not in this case. The clients used the fake remote banking system, received a code for the operation and thought everything went as planned – but then the phishers sent text messages or called the clients, explaining the system malfunctioned and asked to give them new numbers by phone. The things is, scammers used the clients’ operation as cover to steal from their accounts. While the client thinks he has authorized an operation, he has not really done anything through the real bank. The criminals then are notified of the fake transaction, log in to the real remote banking system and submit a money order to the system, transferring the victim’s funds to one of their accounts used later for cashing in. The real bank then sends an authorization number to the victim’s phone, who is probably confused – after all, they did already receive a number for the transaction they thought they conducted. It is at that time that they are contacted by the criminals calling from the fake support number, explaining that need the new authorization code. Pretty ingenious – if only such creativity was used for good, right? Turns out that more often than not these people suspected no foul play and willing gave the real authorization number. According to the investigation, 140 people from 46 Russian administrative regions became victims of this operation in a little less than a year. So that’s right, folks – never give out personal data to anyone, even to staff – if they are who they say they are, they should already have everything they ask you.
