UPDATE

AS OF JANUARY 1, 2013 - POSTING ON THIS BLOG WILL NO LONGER BE 'DAILY'. SWITCHING TO 'OCCASIONAL' POSTING.

Showing posts with label credit cards. Show all posts
Showing posts with label credit cards. Show all posts

Tuesday, November 30, 2010

Hacker Jailed After Spying on Computer Users Using Their Own Cameras


A hacker spied on countless computer users by manipulating their home webcams.

Matthew Anderson, 33, is understood to have sent out 50million ‘spam’ emails containing an attachment for recipients to click on. All of those who did so – believed to be 200,000 – had their computer infected with a virus that left it effectively ‘enslaved’.

Anderson was then able to rifle through private files and saved photographs – and even switch on web cameras attached to the computers. At his leisure he then sat spying into the living rooms or bedrooms of strangers. The victims will have been completely unaware of his watching eyes.

When he was caught in a four-year police operation, officers found he had stored pictures and film of dozens of people in their own homes. Among clips was that of a 16-year-old girl bursting into tears when Anderson began changing words on her computer screen. He then gloated to a fellow hacker about tormenting her, revealing he had been using her webcam for hours, viewing her sisters, and lamenting the fact they were not naked.

Anderson was working in an international hacking gang called ‘m00p’ with at least three others. Only one other, from Finland, has been caught. He was jailed for 18 months today after pleading guilty to ‘unauthorised modification of computer systems’ at Southwark Crown Court in London. However, he is likely to serve just nine months. The court heard the father-of-five, who was born in Rochdale, carried out his crimes in the home of his mother Ruth, 54, in Banffshire, Scotland.

He claimed through his barrister that he joined online chatrooms after being left house-bound by panic attacks in his early 20s. Publicly he ran a computer security firm – offering to protect clients, ironically, from people like himself.

Simon Ward, defending, said Anderson was motivated by ‘the feeling of power that comes from the knowledge that you have control over something that others don’t know you have the control of’.
As well as private home computers, Anderson targeted the John Radcliffe Hospital in Oxford, Oxford University and government computers. But he avoided military sources for fear of detection.

The ‘cutting edge’ software behind his virus has been ranked as among the best in the world.
Anderson was caught after the m00p gang was investigated jointly by Scotland Yard and Finnish authorities when a computer expert at John Radcliffe hospital raised concerns. Anderson was found to have profited by £12,000 by selling on to legitimate marketing firms email addresses harvested from computer address books.

But it was the webcams he used and the personal data, including nude photos and bank account details, which he had access to and copied that is particularly chilling. Investigating officer Detective Constable Bob Burls said Anderson’s initial spam emails typically told recipients they had a computer problem, and offered to fix it. When they clicked on the file, the hacker’s virus was let loose to hijack the computer, although it seemed to continue working normally. From his remote location he could record every word typed, or copy the computer screen at any time.

Anderson and his fellow gang members operated unhindered for years – with around one in 250 spam recipients being taken in.

During police monitoring, Anderson – who used online nicknames including warpig and, warpiglet – successfully enslaved 1,743 computers in just 90 minutes. His fellow gang members were known online as Kdoe, CraDle and Okasvi - with the last, real name Artturi Alm, being the only other hacker brought to justice when jailed in his native Finland two years ago.

Mr Burls said the hacker copied one victim’s will, website passwords, banking passwords.

original article here

Monday, January 25, 2010

Dark Market


To the casual observer, there was little to distinguish the Java Bean internet cafe in Wembley from the hundreds of others dotted around the capital. But to surveillance officers staking it out month after month, this unremarkable venue was the key to busting a remarkable and sophisticated network of cyber criminals.

From the bank of computers inside, a former pizza bar worker ran an international cyber "supermarket" selling stolen credit card and account details costing the banking industry tens of millions.

Renukanth Subramaniam, 33, was revealed today as the founder and a major "orchestrator" of the secret ­DarkMarket website, where elite fraudsters bought and sold personal data, after it was infiltrated by the FBI and the US Secret Service.

Membership was strictly by invitation. But once vetted, its 2,000 vendors and buyers traded everything from card details, obtained through hacking, phishing and ATM skimming devices, to viruses with which buyers could extort money by threatening company websites.

The top English language cybercrime site in the world, it offered online tutorials in account takeovers, credit card deception and money laundering. Equipment – including false ATM and pin machines and everything needed to set up a credit card factory – was available.

It even featured breaking-news-style updates on the latest compromised material available, while criminals could buy banner adverts to promote their wares.

So vast was its reach, with members in the UK, Canada, US, Russia, Turkey, Germany and France, the UK's Serious Organised Crime Agency (Soca), which helped bust it, said it was "impossible" to put a figure on how much it cost banks worldwide.

Subramaniam, who used the online soubriquet JiLsi, was remanded in custody at his own request at Blackfriars crown court today after pleading guilty to conspiracy to defraud and five counts of furnishing false information. Judge John Hillen warned it was "inevitable" he faced a "substantial custodial sentence".

A Sri Lankan-born British citizen, Subramaniam was a former member of ShadowCrew, DarkMarket's forerunner, which was uncovered by the US Secret Service in 2004. "JiLsi was one of the highest in cybercrime in this country with what he managed to achieve setting up a forum globally. No JiLsi, no DarkMarket," said one Soca investigator.

Its 2,000 members never met in real life. Quality, not quantity, was the key. DarkMarket was fastidious in banning "rippers" who would cheat other criminals. Honour among thieves was paramount.

It operated an "escrow" service, with payments and goods exchanged through a third party – "like a PayPal for criminals", the judge observed, and an arbitration service resolved disputes. To keep off the radar, the rules were strict: no firearms, drugs or counterfeit currency.

Built on a pyramid structure, administrators decided who joined, moderators ran specific site sections, and reviewers vetted wannabes – each demanding 5% or £250 per transaction as a fixer's fee.

To get on, criminals had to present details of 100 compromised cards free of charge - 50 to one reviewer, 50 to another. Reviewers would test the cards and write an online review of customer satisfaction – just like eBay customers. "If the cards did what they were supposed to … they would be recommended. If not they weren't allowed in," said the investigator.

Payment was via accounts on WebMoney, or E-Gold. "It was the QuickTime method of sending money anywhere."

Subramaniam was one of the top administrators. He kept his operating system on memory sticks. But when one was stolen, costing him £100,000 in losses and compromising the site's security, he was downgraded to reviewer. Surveillance officers caught him logging on to the website as JiLsi unaware the fellow criminal MasterSplyntr he was talking to was, in fact, an FBI agent called Keith Mularski.

Considerable money was exchanged, though actual transactions took place away from the site for security reasons. One buyer spent £250,000 on stolen personal information in just six weeks.

Described as "a very quiet man", Subramaniam worked at Pizza Hut and as a dispatch courier. "He owned three houses but was largely itinerant," said Sharon Lemon, Soca deputy director. "The key to investigations of this sort is finding the evidence to connect the online persona with a living, breathing person."

Harendra de Silva QC, defending Subramaniam, said the "evidence was unchallenged" but said the "question of interpretation does arise in certain areas" and there would be submissions on "nuance" of the fraud in so far as it applied to his client. He is charged alongside John McHugh, 66, known as Devilman, also a site reviewer who has pleaded guilty to conspiracy to defraud and at whose Doncaster home officers found a credit card-making factory. The two will be sentenced later.

But the battle against cybercrime continues. "This was one of the top 10 sites in the world, but there are more than 100 we know of globally, and another 100 we don't yet know of," said the investigators.
In the DarkMarket

DarkMarket price list

Trusted vendors on DarkMarket offered a smorgasbord of personal data, viruses, and card-cloning kits at knockdown prices. Going rates were:

Dumps Data from magnetic stripes on batches of 10 cards. Standard cards: $50. Gold/platinum: $80. Corporate: $180.

Card verification values Information needed for online transactions. $3-$10 depending on quality.

Full information/change of billing Information needed for opening or taking over account details. $150 for account with $10,000 balance. $300 for one with $20,000 balance.

Skimmer Device to read card data. Up to $7,000.

Bank logins 2% of available balance.

Hire of botnet Software robots used in spam attacks. $50 a day.

Credit card images Both sides of card. $30 each.

Embossed card blanks $50 each.

Holograms $5 per 100.

Tuesday, March 04, 2008

Credit Card Trails Follow Online Predators!!



Where the Credit Card Trail Leads

By KURT EICHENWALD -- THE NEW YORK TIMES

For almost six years, a little-known Internet company called Neova.net has been quietly processing credit card information for online businesses - among them, Justin Berry and other minors who operate for-pay Webcam sites.

Tracking down the company is challenging. Its Web site is just black-and-blue text on a white background, with little hint of the scope of its business. Its contact information shows it in London, but corporate records list its main offices in Boston, at an address for a private mailbox provider. And its server, the powerful computer that handles transactions and stores the business data electronically, is in California, Internet records show.

Just days after his decision to abandon his pornography business, Justin Berry accessed his operating account at Neova, downloaded the data of his for-pay Webcam site - including the names and credit card information of people who subscribed to his site - and provided it to The New York Times. Until then, Justin had never before known what kind of people paid to see an underage boy film himself in sexual situations.

"I really didn't want to know who they were," he said.

The names numbered more than 1,750; about 200, however, were customers who had signed up multiple times. The Times reduced the listing to a sampling of 300 people in eight cities and attempted to identify the adults who were paying to view child pornography.

In the analysis, The Times cross-referenced the names and locations of subscribers with publicly available records. Often, a name was traced to a company or organization through the subscriber's e-mail address. Subscribers whose identities were not clear, based on public information, were not counted in the sample.

Because of the possibility that some people whose information was on the list may have been victims of identity theft, and to guard the privacy of individuals, The Times is not publishing the names of adults whose credit card payments for Justin's sites were processed by Neova. The company and its principal, however, are targets of a federal investigation into online child pornography, according to court records and government officials; its customer records have been independently obtained by the government.

The detailed personal information accompanying the accounts indicates that virtually all of the customers subscribed using their real names. And the level of chargebacks - reversed payments that occur when customers dispute charges to their credit cards - was relatively low for the accounts, indicating that these subscriptions had in fact been ordered by the cardholders.

The analysis found that few of the subscribers fit the stereotype of online predators as people on the fringes of society. Instead, they included successful members of communities across the country, people whose education and language skills could help them win the trust of underage teenagers.

Of the 300 subscribers to Justin's site whose identities were checked, a large percentage were in professions that placed them in the proximity of children on almost a daily basis. There were pediatricians and elementary school teachers, as well as lawyers who represent children in court. But there were also subscribers whose careers seemed unrelated to children, including a public official in the West and the president of a privately held construction company who used his corporate credit card to sign up for the site.

Experts in the field of child sexual exploitation said such findings - particularly the prominence of adults having careers that placed them near children - were consistent with anecdotal evidence from law enforcement.

"These people go into these professions, like teacher and pediatrician, to get themselves close to kids," said Patrick A. Trueman, the former head of the Child Exploitation and Obscenity Section of the Justice Department, who is now senior research counsel for the Family Research Council, a Christian conservative organization that promotes policies on marriage and family. "Their desires drive their careers."

Neova.net is not the only online company whose computer records contain the names and identifying information of people paying for child pornography; other large payment processors have had such sites as their customers. In some instances, the processors are legitimate corporations that unwittingly play a role in its dissemination.

A pornographic Web site (now defunct) called bigfunhouse, for example, was dependent on a global Internet payment processing company for handling its credit card billings.

For years, bigfunhouse - which portrayed itself as the most popular site of its kind in America and Europe - offered to members a free link to a second site featuring Webcam videos of boys who were lured into one or two online sexual performances, according to Internet records and customers interviewed by The Times.

E-mail traffic reviewed by The Times showed that, in June, the company that processed credit card charges for bigfunhouse - Verotel, which is based in Amsterdam - received a message purportedly from a teenager whose image was on the site; the message stated that bigfunhouse was carrying child pornography. Verotel - one of the largest credit card processors for Web sites offering digital content, which says it is strongly committed to combating child pornography - replied that it had investigated the claim and had become convinced that it was not true, the e-mail messages showed.

In November, The Times asked Verotel about illegal images, and the company responded that there were none on the bigfunhouse site. The Times provided Verotel with specific information about illegal images, including the identities of people who had been arrested for possessing the material. Verotel severed its relationship with bigfunhouse. Within hours, the pornography site shut down.

The bigfunhouse Web site then changed its message to "Game over. We closed."

Be warned Cyberpaths! Already had TWO of our cyberpaths' credit card trails followed by law enforcement, which led to the closing of a $2Million a year brothel. Another showed this cyberpath on multiple dating sites, scamming women for sex while emptying their bank accounts. Police are now online on TER and similar sites as well as doing forensic searches for cached files - which you can NOT delete - and which remain online in archival files forever.

Be careful what you put online and you DENY doing online. The truth is out there. Encoded & encrypted forever!