Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Attacks/Breaches

2/7/2018
04:45 PM
Connect Directly
Twitter
LinkedIn
RSS
E-Mail
50%
50%

US, International Law Enforcement Shut Down Massive Cybercrime Marketplace

The Infraud Organization was responsible for over $500 million in losses to institutions and individuals worldwide, the US Department of Justice says.

US law enforcement authorities in collaboration with their counterparts in over a dozen nations have taken down a major cybercrime organization that was responsible for some $530 million in losses over the past seven years.

Thirty-six individuals from 17 countries have been charged in connection with their alleged roles in the so-called Infraud Organization, including five from the US. Thirteen of the 36 individuals have been arrested so far. Eight of them are awaiting extradition to the United States. More arrests are expected to follow.

In a media call announcing the arrests Wednesday morning, Deputy Assistant Attorney General David Rybicki described the Infraud Organization as a global forum for buying and selling stolen payment card data, financial information, Social Security numbers, personal identity data, malware, and other products.

"Infraud was truly the premier one-stop shop for cybercriminals worldwide," Rybicki said. "Over the course of the Infraud Organization's seven-year history, its members targeted more than 4.3 million credit cards, debit cards, and bank accounts held by individuals around the world and in all 50 states."

The 50-page indictment unsealed today does not allege that Infraud members committed any actual data breaches. But those operating on the forum offered tools and services that certainly would have facilitated those activities, Rybicki said.

According to the indictment, Svyatoslav Bondarenko, 34, of Ukraine, founded Infraud in 2010. Over the years, it became the premier destination on the Internet for crooks looking to transact business with stolen credit card, financial, banking, and identity information. In addition to providing a platform that cybercriminals could safely use to sell stolen data, Infraud also provided an escrow service that members could use to transact business using digital currencies.

As of last March, Infraud had over 10,900 members, making it one of the largest such operations on the Internet prior to its takedown this week. The group's members included individuals from the US, Ukraine, Russia, Australia, United Kingdom, Pakistan, Kosovo, and Bangladesh. The five individuals who have been arrested in the US are from New York, San Diego, Los Angeles, and Alabama.

As has become common with other cybercrime operations these days, Infraud had a formal hierarchy in place with defined roles for members, according to the indictment papers. "Administrators" were responsible for strategic planning operations as well as for managing day-to-day operations. They were also responsible for approving and monitoring membership, and for meting out rewards and punishments to members. Individuals with subject-matter expertise in different areas were assigned "Super Moderator" roles, while "Moderators" were responsible for one or two subforums within their specific areas of expertise, the DOJ indictment noted. The forum also had "vendors" who sold stolen goods, and malware and "members" and "VIP members" worked to facilitate various criminal activities.

"Today's indictment and arrests mark one of the largest cyber fraud enterprise prosecutions ever undertaken by the Department of Justice,” said John Cronin, acting assistant attorney general of the DOJ's criminal division.

"Infraud operated like a business to facilitate cyber fraud on a global scale," Cronin said, noting that the losses the group attempted to cause totaled more than $2.2 billion.

The charges in the case are the result of a joint investigation spearheaded by the US Immigration and Customs Enforcement's Homeland Security Investigations unit and the Henderson Police Department in Nevada.

The case itself is being prosecuted by the prosecutor's office in Nevada because of its familiarity with the details and the fact than 9,000 of Infraud's victims are from the state, said US Attorney Dayle Elieson of the District of Nevada during the media call.

The indictment charges the 36 individuals with racketeering, fraud, and seven other charges. They face a maximum of 20 years in federal prison on the racketeering charges and 10 years for each of the additional counts, Elieson said.

The Infraud takedown continues a string of major law-enforcement successes against cybercrime in recent years. Last year, the FBI and other US law enforcement agencies led an international operation that resulted in the takedown of the AlphaBay and Hansa criminal marketplaces. In December, the FBI, Europol, and others took down Avalanche, a massive malware operation involving 460 attack botnets.

Related content:

  

Jai Vijayan is a seasoned technology reporter with over 20 years of experience in IT trade journalism. He was most recently a Senior Editor at Computerworld, where he covered information security and data privacy issues for the publication. Over the course of his 20-year ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Mobile Banking Malware Up 50% in First Half of 2019
Kelly Sheridan, Staff Editor, Dark Reading,  1/17/2020
Exploits Released for As-Yet Unpatched Critical Citrix Flaw
Jai Vijayan, Contributing Writer,  1/13/2020
Microsoft to Officially End Support for Windows 7, Server 2008
Kelly Sheridan, Staff Editor, Dark Reading,  1/13/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: This comment is waiting for review by our moderators.
Current Issue
The Year in Security: 2019
This Tech Digest provides a wrap up and overview of the year's top cybersecurity news stories. It was a year of new twists on old threats, with fears of another WannaCry-type worm and of a possible botnet army of Wi-Fi routers. But 2019 also underscored the risk of firmware and trusted security tools harboring dangerous holes that cybercriminals and nation-state hackers could readily abuse. Read more.
Flash Poll
[Just Released] How Enterprises are Attacking the Cybersecurity Problem
[Just Released] How Enterprises are Attacking the Cybersecurity Problem
Organizations have invested in a sweeping array of security technologies to address challenges associated with the growing number of cybersecurity attacks. However, the complexity involved in managing these technologies is emerging as a major problem. Read this report to find out what your peers biggest security challenges are and the technologies they are using to address them.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-7227
PUBLISHED: 2020-01-18
Westermo MRD-315 1.7.3 and 1.7.4 devices have an information disclosure vulnerability that allows an authenticated remote attacker to retrieve the source code of different functions of the web application via requests that lack certain mandatory parameters. This affects ifaces-diag.asp, system.asp, ...
CVE-2019-15625
PUBLISHED: 2020-01-18
A memory usage vulnerability exists in Trend Micro Password Manager 3.8 that could allow an attacker with access and permissions to the victim's memory processes to extract sensitive information.
CVE-2019-19696
PUBLISHED: 2020-01-18
A RootCA vulnerability found in Trend Micro Password Manager for Windows and macOS exists where the localhost.key of RootCA.crt might be improperly accessed by an unauthorized party and could be used to create malicious self-signed SSL certificates, allowing an attacker to misdirect a user to phishi...
CVE-2019-19697
PUBLISHED: 2020-01-18
An arbitrary code execution vulnerability exists in the Trend Micro Security 2019 (v15) consumer family of products which could allow an attacker to gain elevated privileges and tamper with protected services by disabling or otherwise preventing them to start. An attacker must already have administr...
CVE-2019-20357
PUBLISHED: 2020-01-18
A Persistent Arbitrary Code Execution vulnerability exists in the Trend Micro Security 2020 (v160 and 2019 (v15) consumer familiy of products which could potentially allow an attacker the ability to create a malicious program to escalate privileges and attain persistence on a vulnerable system.