Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Vulnerabilities / Threats

checkLoop 1checkLoop 2checkLoop 3
05:35 PM
Connect Directly

How A Pair Of Cybercriminals Scales Its Carder Business

'Vendetta Brothers' cybercrime duo runs site that offers cards stolen from over 600 banks in 41 countries, FireEye says.

A relatively small cybercrime operation specializing in the sale of stolen credit and debit cards is the latest example of the growing professionalism exhibited by many operators in the cyber underground.

Security vendor FireEye this week published a report describing the activities of two cybercriminals it has dubbed "Vendetta Brothers," who are operating a business modeled very much along the lines of legitimate organizations.

As of early this year, the duo had amassed and was selling payment cards from a total of 639 banks in 41 countries using a combination of legitimate business tactics like outsourcing and lead generation via phishing attacks.

Most of the payment card data available for sale from the Vendetta Bothers belong to users in the US and in Norway, Sweden, and Finland. FireEye’s analysis shows the two criminals are likely operating out of Spain and Eastern Europe.

What makes the Vendetta Brothers interesting is how they have managed to scale their criminal operation, says Will Glass, threat intelligence analyst at FireEye. Though just two people, the pair have shown an ability to grow and diversify their business using tactics like outsourcing and partnerships with other cybercriminals, Glass says.

“We wrote this report... because we collected enough information to raise awareness of how even small operations can adopt business-like practices to scale their operation while insulating themselves from the crimes,” he says.

The criminal duo currently operate an underground website for selling stolen credit and debit card data. It offers roughly 10,000 cards for sale, which according to FireEye, makes it relatively small compared to other carder operations.

The site offers drop-down menus for buyers of stolen card information to choose cards issued by specific banks or from specific geographic locations.

The two brothers use a couple of methods to diversify the sources for their stolen card data, FireEye says. One tactic involves partnering with cyber crooks that have already gained remote access to point-of-sale terminals at merchant locations. In these cases, the two cybercrooks supply malware for stealing card data from the already compromised POS systems.

"They place ads on underground forums looking for hackers who might already have access to point-of-sale systems but lack malware to harvest payment card data," Glass says. Another tactic they use is to look for people who might work in locations, which give them physical access to POS terminals.

Such outsourcing of the upfront legwork has offered the criminal pair an effective way to expand their reach, Glass notes. "Using recruits or cut-outs to do their dirty work for them allows them to focus on higher-level planning of their campaign while also placing distance between themselves and the actual POS compromises," he says.

On occasion, the Vendetta Brothers compromise systems on their own, sometimes using leads obtained from criminal partners. The typical strategy is to send malicious emails disguised as employment queries to targets. The emails contain attachments which when opened are designed to look for and infect POS systems.

In some cases, the duo also has used physical skimmers to capture card data and video devices to record PIN numbers.

"It is likely that other groups also use similar business-like models," Glass says. "The Vendetta Brothers have shown an enterprising nature in figuring out ways to scale their criminal schemes," in a manner that indicates thoughtful planning, he says.

Related stories:


Jai Vijayan is a seasoned technology reporter with over 20 years of experience in IT trade journalism. He was most recently a Senior Editor at Computerworld, where he covered information security and data privacy issues for the publication. Over the course of his 20-year ... View Full Bio

Comment  | 
Print  | 
More Insights
Newest First  |  Oldest First  |  Threaded View
Data Leak Week: Billions of Sensitive Files Exposed Online
Kelly Jackson Higgins, Executive Editor at Dark Reading,  12/10/2019
Register for Dark Reading Newsletters
White Papers
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: Our Endpoint Protection system is a little outdated... 
Current Issue
The Year in Security: 2019
This Tech Digest provides a wrap up and overview of the year's top cybersecurity news stories. It was a year of new twists on old threats, with fears of another WannaCry-type worm and of a possible botnet army of Wi-Fi routers. But 2019 also underscored the risk of firmware and trusted security tools harboring dangerous holes that cybercriminals and nation-state hackers could readily abuse. Read more.
Flash Poll
Rethinking Enterprise Data Defense
Rethinking Enterprise Data Defense
Frustrated with recurring intrusions and breaches, cybersecurity professionals are questioning some of the industrys conventional wisdom. Heres a look at what theyre thinking about.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
PUBLISHED: 2019-12-12
In Apache SpamAssassin before 3.4.3, a message can be crafted in a way to use excessive resources. Upgrading to SA 3.4.3 as soon as possible is the recommended fix but details will not be shared publicly.
PUBLISHED: 2019-12-12
In phpfastcache before 5.1.3, there is a possible object injection vulnerability in cookie driver.
PUBLISHED: 2019-12-12
In Apache SpamAssassin before 3.4.3, nefarious CF files can be configured to run system commands without any output or errors. With this, exploits can be injected in a number of scenarios. In addition to upgrading to SA 3.4.3, we recommend that users should only use update channels or 3rd party .cf ...
PUBLISHED: 2019-12-12
An exploitable denial-of-service vulnerability exists in the hostapd 2.6, where an attacker could trigger AP to send IAPP location updates for stations, before the required authentication process has completed. This could lead to different denial of service scenarios, either by causing CAM table att...
PUBLISHED: 2019-12-12
An exploitable denial-of-service vulnerability exists in the 802.11w security state handling for hostapd 2.6 connected clients with valid 802.11w sessions. By simulating an incomplete new association, an attacker can trigger a deauthentication against stations using 802.11w, resulting in a denial of...
checkLoop 4