Showing posts with label cybercrime. Show all posts
Showing posts with label cybercrime. Show all posts

Saturday, April 5, 2025

United States Secures The Extradition From Canada, Colombia, Germany, Honduras, Kosovo, Israel, Mexico, Spain And Thailand Of Fugitives Wanted For Murder, Drug Trafficking, Child Sexual Abuse And Cybercrime In California, Florida, Georgia And Michigan.

The U.S. Justice Department released the information below:

Extensive coordination and cooperation efforts between the United States Department of Justice and law enforcement authorities in Canada, Colombia, Germany, Honduras, Kosovo, Israel, Mexico, Spain, and Thailand resulted in the extraditions last week of individuals alleged to have committed murder child sexual abuse, drug trafficking, cybercrime, money laundering, and fraud.

The fugitives extradited to the United States include:

  • Roberto Avina-Casillas, 30, a Mexican citizen, was extradited from Mexico to stand trial in Franklin County, Ohio for murder, felonious assault and endangering children. Avina-Casillas evaded arrest for more than 11 years after he was accused of the Aug. 7, 2013 death of his former girlfriend’s 3-year-old son.
  • Justin David Lanoue, 44, a Canadian citizen, was extradited from Canada to stand trial in Washington County, Utah, on charges filed against him in 2015 related to child rape and felony sexual abuse of a minor. The Washington County Attorney’s Office is handling the prosecution.
  • Dominik Rydz, 24, a Polish national, was extradited from Germany to stand trial in the state of Michigan, where he faces two counts of criminal sexual conduct in the second degree and one count of unlawful imprisonment. On the night of Sept. 3, 2023, Rydz allegedly lured a woman away from her friends at a social gathering and proceeded to sexually assault the victim and would not let her leave. Rydz’s extradition was first sought from Poland, where he resided. While out on release from the Polish proceedings, Rydz travelled to Germany and was arrested there on an INTERPOL Red Notice.
  • Olof Kyros Gustafsson, also known as “El Silencio,” 31, a Swedish national, was extradited from Spain to face conspiracy, wire and mail fraud, and money laundering charges in a 115-count federal indictment filed in the Central District of California alleging that he licensed the rights to use the name and persona of the late Colombian narco-terrorist Pablo Escobar and defrauded investors around the world by marketing and selling products — including flamethrowers and cellphones — that did not exist and that he never delivered to paying customers.
  • Ardit Kutleshi, 26, and Jetmir Kutleshi, 28, both Kosovo nationals, were extradited from Kosovo to face identity theft, access device fraud, and money laundering charges in the Western District of Pennsylvania for their roles as the alleged administrators of the Rydox cybercrime marketplace, an illicit website dedicated to selling stolen personal information, access devices, and other tools for carrying out cybercrime and fraud. The Criminal Division’s Computer Crime and Intellectual Property Section and the U.S. Attorney’s Office for the Western District of Pennsylvania are handling the prosecution.
  • Rene Javier Santos Alfaro, 53, a Honduran citizen, was extradited from Honduras to stand trial in the Southern District of Florida for drug trafficking offenses. Santos Alfaro is an alleged leader of a drug trafficking organization based in Honduras that was allegedly responsible for importing large quantities of cocaine from Honduras directly into Miami via commercial aircraft.
  • Cristian Eduardo Garcia Jerez, 36, a Colombian national, was extradited from Colombia to face drug trafficking charges in the Northern District of Georgia. Garcia Jerez is alleged to have owned two cocaine processing laboratories and coordinated the manufacturing of cocaine in Colombia and the smuggling of cocaine from Colombia into the United States.
  • Jose Guillermo Granja Rojas, 36, a Mexican national, was extradited from Colombia to face a money laundering conspiracy charge in the Northern District of Georgia. Granja Rojas was allegedly a money launderer for a Mexico-based drug trafficking organization (DTO) who collected hundreds of thousands of dollars of proceeds from the sale of methamphetamine, cocaine, and heroin in the United States and transferred them to Mexico. DTO members directed the deposit of drug proceeds into accounts allegedly controlled by Granja Rojas, and Granja Rojas also allegedly traveled from Mexico to the United States to receive cash drug proceeds in person.
  • Tien Vy Tai Truong, 46, an alleged leader of a transnational drug trafficking organization, was extradited from Thailand to face conspiracy to export methamphetamine charges in a 2024 indictment filed in the Central District of California. Truong is alleged to have engaged in negotiations with a Drug Enforcement Administration (DEA) confidential human source to export about 200 pounds of methamphetamine from the United States to Australia for sale.

The Justice Department’s Office of International Affairs (OIA) provided significant assistance in securing the defendants’ arrests and extraditions along with the U.S. Marshals Service. OIA and the Criminal Division’s Narcotic and Dangerous Drug Section’s Office of Judicial Attaché in Bogotá, Colombia provided significant assistance in securing the arrests and extraditions from Colombia. The Criminal Division’s Office of Overseas Prosecutorial Development, Assistance and Training (OPDAT) also provided assistance with the extraditions from Kosovo. The Justice Department thanks and acknowledges the instrumental role of its law enforcement partners in Canada, Colombia, Germany, Honduras, Kosovo, Israel, Mexico, Spain, and Thailand for making these extraditions possible.

An indictment and criminal complaint are merely allegations. All defendants are presumed innocent until proven guilty beyond a reasonable doubt in a court of law.

Tuesday, November 9, 2021

Ukrainian Arrested And Charged With Ransomware Attack On Kaseya: Justice Department Seizes $6.1 Million Related To Alleged Ransomware Extortionists

 The U.S. Justice Department released the below information: 

The Justice Department announced recent actions taken against two foreign nationals charged with deploying Sodinokibi/REvil ransomware to attack businesses and government entities in the United States. 

An indictment unsealed today charges Yaroslav Vasinskyi, 22, a Ukrainian national, with conducting ransomware attacks against multiple victims, including the July 2021 attack against Kaseya, a multi-national information technology software company. 

The department also announced today the seizure of $6.1 million in funds traceable to alleged ransom payments received by Yevgeniy Polyanin, 28, a Russian national, who is also charged with conducting Sodinokibi/REvil ransomware attacks against multiple victims, including businesses and government entities in Texas on or about Aug. 16, 2019. 

According to the indictments, Vasinskyi and Polyanin accessed the internal computer networks of several victim companies and deployed Sodinokibi/REvil ransomware to encrypt the data on the computers of victim companies. 

“Cybercrime is a serious threat to our country: to our personal safety, to the health of our economy, and to our national security,” said Attorney General Garland. “Our message today is clear. The United States, together with our allies, will do everything in our power to identify the perpetrators of ransomware attacks, to bring them to justice, and to recover the funds they have stolen from their victims.” 

“Our message to ransomware criminals is clear: If you target victims here, we will target you,” said Deputy Attorney General Monaco. “The Sodinokibi/REvil ransomware group attacks companies and critical infrastructures around the world, and today’s announcements showed how we will fight back.  In another success for the department’s recently launched Ransomware and Digital Extortion Task Force, criminals now know we will take away your profits, your ability to travel, and – ultimately – your freedom. Together with our partners at home and abroad, the Department will continue to dismantle ransomware groups and disrupt the cybercriminal ecosystem that allows ransomware to exist and to threaten all of us.” 

“The arrest of Yaroslav Vasinskyi, the charges against Yevgeniy Polyanin and seizure of $6.1 million of his assets, and the arrests of two other Sodinokibi/REvil actors in Romania are the culmination of close collaboration with our international, U.S. government and especially our private sector partners,” said FBI Director Christopher Wray. “The FBI has worked creatively and relentlessly to counter the criminal hackers behind Sodinokibi/REvil. Ransomware groups like them pose a serious, unacceptable threat to our safety and our economic well-being. We will continue to broadly target their actors and facilitators, their infrastructure, and their money, wherever in the world those might be.” 

“Ransomware can cripple a business in a matter of minutes. These two defendants deployed some of the internet’s most virulent code, authored by REvil, to hijack victim computers,” said Acting U.S. Attorney Chad E. Meacham for the Northern District of Texas. “In a matter of months, the Justice Department identified the perpetrators, effected an arrest, and seized a significant sum of money. The Department will delve into the darkest corners of the internet and the furthest reaches of the globe to track down cyber criminals.” 

According to court documents, Vasinskyi was allegedly responsible for the July 2 ransomware attack against Kaseya. In the alleged attack against Kaseya, Vasinskyi caused the deployment of malicious Sodinokibi/REvil code throughout a Kaseya product that caused the Kaseya production functionality to deploy REvil ransomware to “endpoints” on Kaseya customer networks. After the remote access to Kaseya endpoints was established, the ransomware was executed on those computers, which resulted in the encryption of data on computers of organizations around the world that used Kaseya software. 

Through the deployment of Sodinokibi/REvil ransomware, the defendants allegedly left electronic notes in the form of a text file on the victims’ computers. The notes included a web address leading to an open-source privacy network known as Tor, as well as the link to a publicly accessible website address the victims could visit to recover their files. Upon visiting either website, victims were given a ransom demand and provided a virtual currency address to use to pay the ransom. If a victim paid the ransom amount, the defendants provided the decryption key, and the victims then were able to access their files. If a victim did not pay the ransom, the defendants typically posted the victims’ stolen data or claimed they sold the stolen data to third parties, and victims were unable to access their files.  

Vasinskyi and Polyanin are charged in separate indictments with conspiracy to commit fraud and related activity in connection with computers, substantive counts of damage to protected computers, and conspiracy to commit money laundering. If convicted of all counts, each faces a maximum penalty of 115 and 145 years in prison, respectively. 

The $6.1 million seized from Polyanin is alleged to be traceable to ransomware attacks and money laundering committed by Polyanin through his use of Sodinokibi/REvil ransomware. The seizure warrant was issued out of the Northern District of Texas. Polyanin is believed to be abroad. 

On Oct. 8, Vasinskyi was taken into custody in Poland where he remains held by authorities pending proceedings in connection with his requested extradition to the United States, pursuant to the extradition treaty between the United States and the Republic of Poland. In parallel with the arrest, interviews and searches were carried out in multiple countries, and would not have been possible without the rapid response of the National Police of Ukraine and the Prosecutor General’s Office of Ukraine. 

The FBI’s Dallas and Jackson Field Offices are leading the investigation. Substantial assistance was provided by the Justice Department’s Office of International Affairs and the National Security Division’s Counterintelligence and Export Control Section. 

Assistant U.S. Attorney Tiffany H. Eggers of the U.S. Attorney’s Office for the Northern District of Texas and Senior Counsel Byron M. Jones from the Justice Department’s Computer Crime and Intellectual Property Section are prosecuting the case. 

The U.S. Attorney’s Office for the Northern District of Texas, the FBI’s Dallas and Jackson Field Offices, and the Criminal Division’s Computer Crime and Intellectual Property Section conducted the operation in close cooperation with Europol and Eurojust, who were an integral part of coordination. Investigators and prosecutors from several jurisdictions, including: Romania's National Police and the Directorate for Investigating Organised Crime and Terrorism; Canada’s Royal Canadian Mounted Police; France’s Court of Paris and BL2C (anti-cybercrime unit police); Dutch National Police; Poland’s National Prosecutor’s Office, Border Guard, Internal Security Agency, and Ministry of Justice; and the governments of Norway and Australia provided valuable assistance. 

The U.S. Department of the Treasury Financial Crimes Enforcement Network (FinCEN), Department of Homeland Security's Cybersecurity and Infrastructure Security Agency (CISA), Germany’s Public Prosecutor’s Office Stuttgart and State Office of Criminal Investigation of Baden-Wuerttemberg; Switzerland’s Public Prosecutor’s Office II of the Canton of Zürich and Cantonal Police Zürich; United Kingdom’s National Crime Agency; U.S. Secret Service; Texas Department of Information Resources; BitDefender; McAfee; and Microsoft also provided significant assistance. 

This case is part of the Department of Justice’s Ransomware and Digital Extortion Task Force, which was created to combat the growing number of ransomware and digital extortion attacks. As part of the task force, the Criminal Division, working with the U.S. Attorneys’ Offices, prioritizes the disruption, investigation, and prosecution of ransomware and digital extortion activity by tracking and dismantling the development and deployment of malware, identifying the cybercriminals responsible, and holding those individuals accountable for their crimes. The department, through the task force, also strategically targets the ransomware criminal ecosystem as a whole and collaborates with domestic and foreign government agencies as well as private sector partners to combat this significant criminal threat. 

For more information about the Ransomware and Digital Extortion Task Force, read the Deputy Attorney General’s recent guidance memo on related investigations and cases. For more resources on ransomware prevention and response, visit StopRansomware.gov

Monday, October 5, 2020

FBI/CISA: Spoofed Internet Domains And Email Accounts Pose Cyber And Disinformation Risks To Voters

 The Federal Bureau of Investigation (FBI) and the Cybersecurity and Infrastructure Security Agency (CISA) are issuing this announcement to help the public recognize and avoid spoofed election-related internet domains and email accounts during the 2020 election year.

Spoofed domains and email accounts are leveraged by foreign actors and cybercriminals and can be easily mistaken for legitimate websites or emails. Adversaries can use spoofed domains and email accounts to disseminate false information; gather valid usernames, passwords, and email addresses; collect personally identifiable information; and spread malware, leading to further compromises and potential financial losses.

Cyber actors set up spoofed domains with slightly altered characteristics of legitimate domains. A spoofed domain may feature an alternate spelling of a word ("electon" instead of "election"), or use an alternative top-level domain, such as a "[.]com" version of a legitimate "[.] gov" website. Members of the public could unknowingly visit spoofed domains while seeking information regarding the 2020 election. Additionally, cyber actors may use a seemingly legitimate email account to entice the public into clicking on malicious files or links.

The FBI and CISA urge all members of the American public to critically evaluate the websites they visit and the emails sent to their personal and business email accounts, to seek out reliable and verified information on election information.

RECOMMENDATIONS
  • Verify the spelling of web addresses, websites, and email addresses that look trustworthy but may be close imitations of legitimate election websites.
  • Seek out information from trustworthy sources, verifying who produced the content and considering their intent. The Election Assistance Commission (https://www.eac.gov) provides a vast amount of verified information and resources.
  • Ensure operating systems and applications are updated to the most current versions.
  • Update anti-malware and anti-virus software and conduct regular network scans.
  • Do not enable macros on documents downloaded from an email unless absolutely necessary, and only then, after ensuring the file is not malicious.
  • Disable or remove unneeded software applications.
  • Use strong two-factor authentication if possible, via biometrics, hardware tokens, or authentication apps.
  • Do not open e-mails or attachments from unknown individuals. Do not communicate with unsolicited e-mail senders.
  • Never provide personal information of any sort via e-mail. Be aware that many e-mails requesting your personal information appear to be legitimate.

The FBI is responsible for investigating and prosecuting election crimes, malign foreign influence operations, and malicious cyber activity targeting election infrastructure and other U.S. democratic institutions. CISA helps critical infrastructure owners and operators, including those in the election community, remain resilient against physical and cyber threats. The FBI and CISA provide services and information to uphold the security, integrity, and resiliency of U.S. electoral processes.

VICTIM REPORTING AND ADDITIONAL INFORMATION

The FBI encourages the public to report information concerning suspicious or criminal activity to their local field office (www.fbi.gov/contact-us/field-offices) or to the FBI's Internet Crime Complaint Center (www.ic3.gov). For additional assistance, best practices, and common terms, please visit the following websites:


Thursday, February 27, 2020

FBI: Romanian Hackers Sentenced - Members Of Bayrob Criminal Enterprise Infected Thousands Of Computers With Malware, Stole Millions Of Dollars


The FBI released the below information:
The hackers were like modern-day John Dillingers, brazenly committing their crimes and repeatedly escaping law enforcement’s grasp.
But like Dillinger and most other criminals, they eventually slipped up, and the FBI and its international partners were waiting for them after years of tracking their activities. 
In 2007, an Ohio woman wired thousands of dollars to an eBay seller thinking she was buying a used car. The car never arrived. When she went to her local police department, the listing did not appear on the officers’ computers.
That’s because the woman was on a fraudulent version of the online auction site that mimicked the real one—a result of having unknowingly downloaded malicious software, known as malware, to her computer.
And to thousands of other victims just like her, the website and transactions looked legitimate. But buyers who thought they were wiring money across town were, in fact, sending money to hackers halfway across the world.
The hackers, known as the Bayrob Group, laundered the money via money mules, making it difficult to track. (Money mules are criminal accomplices who, often unwittingly, move criminal money through their own bank accounts.) Additionally, if a user on an infected machine went to the “Help” section of the site, they were met with the hackers’—not eBay’s—customer service.
The Bayrob hackers also blocked websites like ic3.gov—the FBI’s Internet Crime Complaint Center—where a user might have gone for help. And before smartphones were so common, the infected computer may have been a victim’s only access to the Internet.
The would-be car buyer, along with many other victims, lost her money because wiring funds lacks the consumer protection of a credit card. Agents estimate each victim lost between $8,000 and $11,000.
“At the time, this was really cutting edge,” said Special Agent Ryan Macfarlane, who worked this case out of the FBI’s Cleveland Field Office. “These guys did a very good job of staying current with the technologies in the cyber criminal underground.”
The Bayrob hackers were frustratingly nimble and good at covering their tracks. They used multiple layers of proxy servers to hide their location. Those proxy servers communicated with the “command and control” servers that talked to the thousands of computers the malware had infected.
But as the hackers gained more victims, more partners joined the investigation. The FBI worked with numerous law enforcement agencies around the world on this case, as well as with companies such as AOL, eBay, and Symantec.
Beginning in 2012, the Bayrob Group began to diversify its criminal business as technology advanced. They continued to spread their malware via spam and social media, but they also got into cryptocurrency mining and selling credit card numbers on the Darknet.
“They had all of these infected systems, and they tried to use as many ways as possible to make money from them,” Macfarlane said.
A break finally came when a Bayrob participant accidentally logged into his personal email instead of his criminal one. AOL, who was investigating his abuse of their network, connected the two accounts. That personal account led to online profiles in Romania and on social media—essentially the first action tying one of the suspects to the crimes.
That small mistake helped set investigators, in partnership with the Romanian National Police, on a path toward discovering the identities of all three hackers. And after much further investigation, including undercover buys from the group on Darknet marketplace Alphabay, the FBI had enough evidence to work with Romanian authorities on the arrests.
By the time the hackers were arrested in 2016, the Bayrob Group had become one of the top senders of malicious email.
“We were essentially taking down this entire infrastructure and arresting the three individuals at one time,” Macfarlane said. “And the Romanian National Police were key partners in this effort. They stuck with us year after year. We couldn’t have done this without them.”
Bayrob Group members Bogdan Nicolescu and Radu Miclaus were both convicted on wire fraud, money laundering, and identity theft charges. In December 2019, Nicolescu was sentenced to 20 years and Miclaus to 18 years in prison.
A third member of the group, Tiberiu Danet, pleaded guilty to similar charges. He was sentenced in January to 10 years in prison.
While it was years in the making, putting a stop to these prolific thieves was worth the time and effort for the investigators—even when the hackers were as elusive as a gangster on the run.
“We stuck with it because these guys weren’t stopping,” Macfarlane said. “They continued to evolve, and they were becoming a bigger and bigger threat.”
Protecting Yourself Online
Although many of the victims had no way of knowing their computers were compromised, there are steps you can take to protect yourself and your devices, such as making sure your antivirus and operating systems are always up to date. Also be careful of what you click on, even if it’s coming from someone you know.
“A lot of people don’t think that someone they know will be compromised,” said FBI Special Agent Stacy Diaz, who also worked on the case. “These hackers know how social networks work, and they use those relationships to grow their network.”
Bayrob by the Numbers 
  • Infected computers: 400,000+
  • Money lost: $4 million+
  • Average loss per victim: $8,000-$11,000
  • Years in operation: 2007-2016
  • Malware variations: 160+
  • Malicious emails sent: 70+ million 

Friday, April 29, 2016

Ransomware: Latest Cyber Extortion Tool


The FBI released the below information:

Ransomware has become a significant threat to U.S. businesses and individuals. In 2014, over 1,800 complaints were filed regarding ransomware, resulting in a loss of more than $23 million. In 2015, that number grew to more than 2,400 complaints with a reported loss of more than $24 million.
Perpetrators use ransomware to encrypt a user’s important files and documents, making them unreadable, until a ransom is paid. Ransomware victims are not only at risk of losing their files but may also experience financial loss due to paying the ransom, loss of productivity, IT services, legal fees, network countermeasures, and/or the purchase of credit monitoring services for employees or customers if their information was referenced in the encrypted files. Everyone is at risk from this threat; there is no indication at this time that any particular sector or type of business or individual is specifically targeted.
Prevention is the most effective defense against ransomware, and it is critical to take precautionary measures for protection. These measures include, but are not limited to, the following:
  • Implement a robust data back-up and recovery plan. Maintain copies of your files, particularly sensitive or proprietary data, in a separate secure location. Back-up copies of sensitive data should not be readily accessible from local networks.
  • Never open attachments included in unsolicited e-mails. Be very vigilant about links contained in e-mails, even if the link appears to be from someone you know.
  • Keep your anti-virus software up to date.
  • Enable automated patches for your operating system and web browser.
  • Only download software, especially free software, from sites you know and trust.
If you believe you are a victim of an extortion attempt, we strongly encourage you to contact your local FBI field office, which may be able to provide guidance or assistance. Contacting your local FBI field office may also assist in identifying the perpetrator and the malware used, which could help prevent future victimizations. In addition, file a complaint with the Internet Crime Complaint Center (IC3), including as much information as possible in your complaint.
While the FBI recognizes that ransomware victims may feel they have few viable options if they do not have a data backup or if they cannot sustain a release of confidential or proprietary information, the FBI does not condone payment of ransoms. Payment of extortion monies may encourage continued criminal activity and lead to other victimizations, and the funds may be used by criminals to facilitate other serious crimes. In addition, in some cases, even if payment is made, the decryption key provided by the perpetrator to unlock files may not work due to the system configuration issues.
Any questions regarding this news release can be directed to SA Vicki D Anderson at the Cleveland Office of the FBI, 216-522-1400 or Vicki.Anderson@ic.fbi.gov.

Thursday, April 21, 2016

Critical Infrastructure Vulnerable To Attack, NSA Deputy Director Says


David Vergun at the Army News Service offers the below piece:

WEST POINT, N.Y., April 21, 2016 — Strong dependence on industrial control systems, or ICS, is a serious vulnerability for industry, the National Security Agency’s deputy director said here yesterday.
"There's no doubt that Chinese military planners understand the importance of industrial control systems and the critical infrastructure they control," Richard H. Ledgett Jr. (seen in the above DoD released photo) said in his keynote address during a dinner at the Joint Service Academy Cyber Security Summit at the U.S. Military Academy.
Security Threat Inadequately Addressed
Historically, ICS has been strong because of its obscurity, he explained, calling it "weird software with proprietary systems."
But over time, ICS has become less obscure, and providers, working on thin profit margins, haven't adequately addressed the security threat, he said. "Adversaries are seeing what they can get by compromising those industrial control systems," he added.
In 2007, Idaho National Laboratory ran the Aurora Generator experiment, which demonstrated that the electric grid could be compromised. There are other notable examples, he said.
"You don't need to cause physical harm to affect critical infrastructure assets," Ledgett pointed out. For instance, he said, remote hackers using stolen credentials caused a Ukrainian blackout about four months ago that took down the country’s entire power grid.
"These are all fairly significant events," he said. "We're seeing more and more of that by adversaries."
Internet of Things
More and more devices are being connected to the Internet, Ledgett noted. Some 6.4 billion things worldwide will be connected by the Internet this year, he said, and by 2020, that number will be about 20.8 billion. The challenge is identifying emerging risks and vulnerabilities that come about with the introduction of new hardware and software, he said.
"Any system is only as strong as its weakest link," Ledgett said. Most types of devices connected to the Internet are built with differing security profiles and updated on differing timescales, and every time it's updated, that's another opportunity for a security vulnerability, he added.
Cybercrime is one example, Ledgett said. A million pieces of malware come out every day, he said, and 1.5 million criminal cyber events take place every year.
"Today, anyone with a computer and a fairly decent level of knowledge and an Internet connection can pose a very serious threat to an individual, a business, a city and a foreign nation," he said.

The Joint Service Academy Cyber Security Summit was co-hosted by the Army Cyber Institute and Palo Alto Networks.

Monday, July 6, 2015

The OPM Cyberattack Was A Breech Too Far


The Washington Post offers an editorial on the cyberattack on the U.S. Office of Personnel Management (OPM).

The other shoe is expected to drop this week on the disastrous loss of confidential information from the databases of the Office of Personnel Management. The agency is expected to reveal the extent to which information from security investigations of current, former and prospective federal employees and contractors was compromised. The background checks often unearth sensitive and intimate matters, and the loss may put many at risk of blackmail. The agency is expected to reveal this week how many dossiers were taken, but reports suggest it was in the millions. The breach comes on top of a separate intrusion in which personally identifiable information on 4.2 million federal workers was filched from the OPM databases.

President Obama ought to be far more steamed about the break-ins than he appears. The OPM director, Katherine Archuleta, knew as well as anyone how sensitive the data was, yet the door to her agency was apparently left ajar. Thieves walked out with an intelligence goldmine, the most intimate details about U.S. public servants, including those who handle the most highly classified secrets of the United States. This was an unforgivable failure of stewardship that should lead to firings for incompetence. Ms. Archuleta, confronted with questions on Capitol Hill, refused to shoulder any blame. “I don’t believe anyone” at the agency “is personally responsible,” she said. “If there is anyone to blame, it is the perpetrators.”

The director of national intelligence, James R. Clapper, said China is the “leading suspect” in the breach. The FBI has issued a “flash” alert that did not specify China as the origin, but identified some malware — including a remote access tool called Sakula — that has previously been associated with Chinese cyberattacks.

You can read the rest of the editorial via the below link:

http://www.washingtonpost.com/opinions/the-opm-cyberattack-was-a-breach-too-far/2015/07/05/de2b98b2-20e9-11e5-aeb9-a411a84c9d55_story.html?wpisrc=nl_headlines&wpmm=1

Thursday, June 25, 2015

Swedish Co-Creator Of Blackshades Malware That Enabled Users Around The World To Secretly And Remotely Control Victims’ Computers Sentenced To 57 Months In Prison


The U.S. Attorney's Office for the Southern District of New York released the below information:

Preet Bharara, the United States Attorney for the Southern District of New York, announced that ALEX YÜCEL, the owner of an organization known as “Blackshades” that since 2010 sold and distributed to thousands of people in more than 100 countries a sophisticated and pernicious form of malicious software, or “malware,” known as the Blackshades Remote Access Tool, or “RAT,” was sentenced today in Manhattan federal court to 57 months. The sentence was imposed by U.S. District Judge P. Kevin Castel. YÜCEL pled guilty to computer hacking on February 18, 2015.

Manhattan U.S. Attorney Preet Bharara said: “Alex Yucel created, marketed, and sold software that was designed to accomplish just one thing—gain control of a computer, and with it, a victim’s identity and other important information. This malware victimized thousands of people across the globe and invaded their lives. But Yucel’s computer hacking days are now over.”

According to the allegations in documents filed in Manhattan federal court, and statements made at today’s sentencing and other court proceedings:

Beginning in 2010, the “Blackshades” organization, which YÜCEL owned and controlled, sold and distributed malware to thousands of cybercriminals throughout the world. Blackshades’ flagship product was the RAT—a sophisticated piece of malware that enabled cybercriminals secretly and remotely to gain control over a victim’s computer.

After installing the RAT on a victim’s computer, a user of the RAT had free rein to, among other things, access and view documents, photographs, and other files on the victim’s computer, record all of the keystrokes entered on the victim’s keyboard, steal the passwords to the victim’s online accounts, and even activate the victim’s web camera to spy on the victim—all of which could be done without the victim’s knowledge. A Blackshades user could also exploit victims’ computers for Distributed Denial of Service (“DDoS”) attacks by commanding Blackshades-infected computers to repeatedly send requests to targeted websites in an effort to disable those websites and deny service from those websites to legitimate visitors.

The RAT was typically advertised on forums for computer hackers and marketed as a product that conveniently combined the features of several different types of hacking tools. Copies of the Blackshades RAT were available for sale, typically for $40 each, on a website maintained by Blackshades. After purchasing a copy of the RAT, a user had to install the RAT on a victim’s computer—i.e., “infect” a victim’s computer. The infection of a victim’s computer could be accomplished in several ways, including by tricking victims into clicking on malicious links or by hiring others to install the RAT on victims’ computers.

The RAT contained tools known as “spreaders” that helped users of the RAT maximize the number of infections. The spreader tools generally worked by using computers that had already been infected to help spread the RAT further to other computers. For instance, to lure additional victims to click on malicious links that would install the RAT on their computers, the RAT allowed cybercriminals to send those malicious links to others via the initial victim’s social media service, making it appear as if the message had come from the initial victim. For example, a RAT user could send an instant message, or IM, to potential victims that appeared to come from the initial victim, inviting them to click on a link that appeared to lead to a legitimate website, but would instead install the RAT on the potential victim’s computer.

YÜCEL co-created the Blackshades RAT with Michael Hogue and operated the Blackshades organization with the help of several employees whom YÜCEL paid to advertise the RAT on various Internet forums and to provide customer support. The RAT was purchased by several thousand users in more than 100 countries and used to infect more than half a million computers worldwide. Blackshades generated sales of more than $350,000 between September 2010 and April 2014.

* * *

YÜCEL, 24, a Swedish national, was arrested in Moldova in November 2013. He was the first defendant ever to be extradited from Moldova to the United States. In addition to the prison term, YÜCEL was sentenced to three years’ supervised release, and forfeiture of $200,000 and the computer equipment used.

Brendan Johnston, an administrator for the Blackshades organization, pled guilty in November 2014, before U.S. District Judge Jesse M. Furman to conspiracy to commit computer hacking. On June 19, 2015, Johnston was sentenced to one year and one day in prison.

Marlen Rappa, a customer of Blackshades who purchased the RAT and used it to infect victims’ computers, spy on those victims using their web cameras, and steal personal files from their computers, pled guilty in October 2014, before U.S. District Judge Valerie E. Caproni. On April 22, 2015, Rappa was sentenced to one year and one day in prison.

Kyle Fedorek, a customer of Blackshades who purchased the RAT and used it to steal financial and other account information from more than 400 victims, pled guilty in August 2014 before U.S. Magistrate Judge Gabriel W. Gorenstein. On February 19, 2015, Fedorek was sentenced to two years in prison.

Michael Hogue, the co-creator of the RAT, pled guilty before Judge Castel in January 2013, and is awaiting sentencing.

Mr. Bharara praised the outstanding investigative work of the Federal Bureau of Investigation.

The case is being prosecuted by the Office’s Complex Frauds and Cybercrime Unit. Assistant U.S. Attorneys Sarah Lai and Daniel Noble are in charge of the prosecution.

Tuesday, October 12, 2010

My On Crime & Security Column: Stop. Think. Connect, October is National Cybersecurity Awareness Month

The online small business magazine Businessknowhow.com published my On Crime & Security column today.

My column covered National Cybersecurity Awareness Month and a major FBI roll up of an international cybercrime operation.

You can read my column via the below link:

http://www.businessknowhow.com/security/cybersecurity.htm