Showing posts with label cybercrime. Show all posts
Showing posts with label cybercrime. Show all posts

Monday, August 20, 2018

DEFANGO: Cyberstalking the Russia Narrative - DEFNEWS 08/20/2018

DEFNEWS reports on #cyberwars, directly from the battlefield of the internet.

Keep up to date on the latest propaganda attacks as legal defense strategies in the ongoing investigations up on Capitol Hill, all over the nation, the world.


Multistreaming with https://restream.io/ 

Back to the Danger Zone, Let's get some frags and clip any of our stalker to send over to pubg. Man I love FPS Shooters Donate if you wanna https://streamlabs.com/defango 

Support VIA PATREON Patreon.com/defango 



 LTC - MRoQpUx1fZxXMBRLa9uZfuzeUKY8YsY9nL 

BTC - 325BQU2qBxuxBvWnUPHonzNzpRFTaYdf3s 

ETH - 0xfD651b1FCD273cE68F8BD87FEB896f92F44595D5 

Multi Streaming with https://restream.io 

 My Setup: S9+ Hp Omen 2017 i7 3770k + 16gb Ram + 500gig SDD + RX 580 4gig Razer Ripsaw Capture Card Razer Blackwidow Chroma Headset Mouse keyboad Skills Contact us at defango@gmail.com 

 Check out My Live Stream Channels 

Voting is beautiful, be beautiful ~ vote.©

Thursday, August 2, 2018

DOJ: Three Members of Notorious International Cybercrime Group “Fin7” In Custody for Role in Attacking Over 100 U.S. companies

You know, I have always wondered if they set up automatic, reoccurring deductions to political campaigns.

Just a thought, I thought I would share, for others to think about.

Victim Companies in 47 U.S. States; Used Front Company ‘Combi Security’ to Recruit Hackers to Criminal Enterprise

Three high-ranking members of a sophisticated international cybercrime group operating out of Eastern Europe have been arrested and are currently in custody facing charges filed in U.S. District Court in Seattle, announced Assistant Attorney General Brian A. Benczkowski of the Justice Department’s Criminal Division, U.S. Attorney Annette L. Hayes for the Western District of Washington and Special Agent in Charge Jay S. Tabb Jr. of the FBI Seattle Field Office.
According to three federal indictments unsealed today, Ukrainian nationals Dmytro Fedorov, 44, Fedir Hladyr, 33, and Andrii Kolpakov, 30, are members of a prolific hacking group widely known as FIN7 (also referred to as the Carbanak Group and the Navigator Group, among other names).  Since at least 2015, FIN7 members engaged in a highly sophisticated malware campaign targeting more than 100 U.S. companies, predominantly in the restaurant, gaming, and hospitality industries.  As set forth in indictments, FIN7 hacked into thousands of computer systems and stole millions of customer credit and debit card numbers, which the group used or sold for profit. 
In the United States alone, FIN7 successfully breached the computer networks of companies in 47 states and the District of Columbia, stealing more than 15 million customer card records from over 6,500 individual point-of-sale terminals at more than 3,600 separate business locations.  Additional intrusions occurred abroad, including in the United Kingdom, Australia, and France.  Companies that have publicly disclosed hacks attributable to FIN7 include such familiar chains as Chipotle Mexican Grill, Chili’s, Arby’s, Red Robin and Jason’s Deli.  Additionally in Western Washington, FIN7 targeted other local businesses. 
“The three Ukrainian nationals indicted today allegedly were part of a prolific hacking group that targeted American companies and citizens by stealing valuable consumer data, including personal credit card information, that they then sold on the Darknet,” said Assistant Attorney General Benczkowski.  “Because hackers are committed to finding new ways to harm the American public and our economy, the Department of Justice remains steadfast in its commitment to working with our law enforcement partners to identify, interdict, and prosecute those responsible for these threats.”
“Protecting consumers and companies who use the internet to conduct business – both large chains and small ‘mom and pop’ stores -- is a top priority for all of us in the Department of Justice,” said U.S. Attorney Hayes.  “Cyber criminals who believe that they can hide in faraway countries and operate from behind keyboards without getting caught are just plain wrong.  We will continue our longstanding work with partners around the world to ensure cyber criminals are identified and held to account for the harm that they do – both to our pocketbooks and our ability to rely on the cyber networks we use.”
“The naming of these FIN7 leaders marks a major step towards dismantling this sophisticated criminal enterprise,” said Special Agent in Charge Tabb.  “As the lead federal agency for cyber-attack investigations, the FBI will continue to work with its law enforcement partners worldwide to pursue the members of this devious group, and hold them accountable for stealing from American businesses and individuals.”
Each of the three FIN7 conspirators is charged with 26 felony counts alleging conspiracy, wire fraud, computer hacking, access device fraud, and aggravated identity theft. 
In January 2018, at the request of U.S. officials, foreign authorities separately arrested Ukrainian Fedir Hladyr and a second FIN7 member, Dmytro Fedorov.  Hladyr was arrested in Dresden, Germany, and is currently detained in Seattle pending trial.  Hladyr allegedly served as FIN7’s systems administrator who, among other things, maintained servers and communication channels used by the organization and held a managerial role by delegating tasks and by providing instruction to other members of the scheme.  Hladyr’s trial is currently scheduled for Oct. 22.
Fedorov, a high-level hacker and manager who allegedly supervised other hackers tasked with breaching the security of victims’ computer systems, was arrested in Bielsko-Biala, Poland.  Fedorov remains detained in Poland pending his extradition to the United States.
In late June 2018, foreign authorities arrested a third FIN7 member, Ukrainian Andrii Kolpakov in Lepe, Spain.  Kolpakov, also alleged to be a supervisor of a group of hackers, remains detained in Spain pending the United States’ request for extradition.
According to the indictments, FIN7, through its dozens of members, launched numerous waves of malicious cyberattacks on numerous businesses operating in the United States and abroad.  FIN7 carefully crafted email messages that would appear legitimate to a business’ employee, and accompanied emails with telephone calls intended to further legitimize the email. Once an attached file was opened and activated, FIN7 would use an adapted version of the notorious Carbanak malware in addition to an arsenal of other tools to ultimately access and steal payment card data for the business’ customers. Since 2015, FIN7 sold the data in online underground marketplaces. (Supplemental document “How FIN7 Attacked and Stole Data” explains the scheme in greater detail.)
FIN7 used a front company, Combi Security, purportedly headquartered in Russia and Israel, to provide a guise of legitimacy and to recruit hackers to join the criminal enterprise.  Combi Security’s website indicated that it provided a number of security services such as penetration testing.  Ironically, the sham company’s website listed multiple U.S. victims among its purported clients. 
The charges in the indictments are merely allegations, and the defendants are presumed innocent until proven guilty beyond a reasonable doubt in a court of law.
The indictments are the result of an investigation conducted by the Seattle Cyber Task Force of the FBI and the U.S. Attorney’s Office for the Western District of Washington, with the assistance of the Justice Department’s Computer Crime and Intellectual Property Section and Office of International Affairs, the National Cyber-Forensics and Training Alliance, numerous computer security firms and financial institutions, FBI offices across the nation and globe, as well as numerous international agencies. Arrests overseas were executed in Poland by the “Shadow Hunters” from CBŚP (Polish Central Bureau of Investigation); in Germany by the LKA Sachsen - Dezernat 33, (German State Criminal Police Office) and the Polizeidirektion Dresden (Dresden Police); and in Spain the Grupo de Seguridad Logica within the Unidad de Investigación Technologica of the Cuerpo Nacional de Policía (Spanish National Police)..
This case is being prosecuted by Assistant U.S. Attorneys Francis Franze-Nakamura and Steven Masada of the Western District of Washington with assistance from Trial Attorney Anthony Teelucksingh of the Justice Department’s Computer Crime and Intellectual Property Section.

Voting is beautiful, be beautiful ~ vote.©

Wednesday, September 28, 2016

Statement of the Honorable John Conyers, Jr. “Oversight of the Federal Bureau of Investigation”


Dean of the U.S. House
of Representatives
John Conyers, Jr.
Thank you, Mr. Chairman. And thank you, Director Comey, for your appearance here today.

The FBI’s mission is a complex undertaking: to protect the United States from terrorism, to enforce our criminal laws, and to lead the nation’s law enforcement community.

That mission ought to mirror our own priorities in this Committee. 

In the past few days, for example, we have witnessed near-fatal terrorist attacks in Minnesota, New York, and New Jersey.

These attacks underscore the growing fear that individuals can be moved to violence at home by the propaganda of ISIS and other terrorist groups abroad—even though they have no direct connection to those organizations.

To me, this threat is dire.  We should be doing all we can within our communities—and within our constitutional framework—to mitigate the danger.

But will our Majority use their time today to discuss these attacks?  I suspect it will not be their focus in this campaign season.

In Charlotte, in Tulsa, in Dallas—right here in Washington, DC—and in other cities across this country, our citizens demand answers to questions about race and policing, and the use of lethal force by law enforcement. 

Our police are under siege, often under resourced, and in some cases hard pressed to build trust with the communities they serve.

Director Comey, your continued work to foster lines of communication between police officers and the general public is commendable—and necessary if we are to keep our citizens safe from harm.

But will my colleagues discuss this pressing issue with the Director of the FBI, whose leadership in the law enforcement community is paramount?  Again, I fear their focus will be elsewhere.

The FBI is the lead agency in the investigation of cyber-based terrorism, computer intrusions, online sexual exploitation, and major cyber fraud.  We have known for some years about the persistent cyber threat to our critical infrastructure.

Now, we hear reports of a new cyber threat—to the very basis of our democratic process.

Twice this summer, Director Comey, I wrote to you with my fellow ranking members to ask you to look into reports that Russian state actors are working to undermine our election process.

Without objection, I ask that both of those letters be placed into the record.

It is now the clear consensus of the Intelligence Community that the Russian government was behind the hack of the Democratic National Committee—and not, as some have suggested, “somebody sitting on their bed that weighs 400 pounds.”

On Friday, we learned from one report that: “U.S. intelligence officials are seeking to determine whether an American businessman identified by Donald Trump as one of his foreign policy advisors has opened up private communications with senior Russian officials—including talks about the possible lifting of economic sanctions if the Republican nominee becomes president.”
           
The report cites to an unnamed “senior U.S. law enforcement official,” which I presume means someone in your orbit, Director Comey.

Without objection, I ask that this article be placed into the record as well.

Let me be clear: if true, this allegation represents a danger to our national security and a clear violation of federal law—which expressly prohibits this type of back-channel negotiation.

I am not alone in describing the nature of this threat.  Speaker Ryan himself has said that “Russia is a global menace led by a devious thug.  Putin should say out of this election.”

But will our Majority press you on this problem today, Director Comey?  I suspect not.

Instead, I believe that the focus of this hearing will be more of the same: an attack on you, and your team at the Department of Justice, for declining to recommend criminal charges against Secretary Hillary Clinton.

In recent weeks, this line of attack has been remarkable only for its lack of substance.

Your critics dwell in character assassination and procedural minutia—like the proper scope of immunity agreements, and your decision to protect the identities of individuals wholly unrelated to the investigation.

They want to investigate the investigation, Director Comey.  What an unfortunate waste of this Committee’s time.

With so many actual problems confronting this nation, and so many of those challenges within your jurisdiction and ours, you would think my colleagues would set their priorities differently.

I hope that they do, as they listen to our conversation today.  I thank the Chairman, and I yield back.

Voting is beautiful, be beautiful ~ vote.©

Saturday, September 24, 2016

Assistant Attorney General Leslie R. Caldwell Delivers Remarks at New York University Center for Cybersecurity

Remarks as prepared for delivery

Thank you, Zach [Goldman], for that kind introduction.  It’s a pleasure to be here.  I was invited to speak today about the Justice Department’s approach to investigating and prosecuting organized cybercrime.  And what better place to do that than New York—once the stronghold of La Cosa Nostra and now a target of cyber criminals from across the world.
Today, I will focus on two challenges we face in this effort: first, how technology has enabled sophisticated and organized cyber criminals; and second, current limitations on the Justice Department’s ability to respond.
The department has had a long and successful track record in dismantling traditional organized crime, dating back to 1970, when Congress enacted the Organized Crime Control Act and its “Racketeer Influenced and Corrupt Organizations” provisions, commonly referred to as RICO.  For decades, groups like La Cosa Nostra or the Lucchese crime family were the focus of the department’s organized crime efforts.  Starting in the 1980s, for instance, we used the RICO statute in the Eastern District of New York—just across the water—to strike a blow to the five organized crime families of La Cosa Nostra in New York City. 
Today, that kind of organized crime seems almost quaint, and not because organized crime has vanished.  Rather, the same global networks and communications technologies that have transformed the world’s economy have also enabled a troubling evolution in criminal activity.  Criminal organizations use increased computing power, the widespread availability of high-speed internet, the growth of virtual currencies and the cover provided by technologies such as encryption and anonymizing software to launder money, traffic in narcotics and exploit children.  They also turn those advances into means of invading privacy, stealing intellectual property and emptying bank accounts of individuals and businesses around the world.  This is not your grandfather’s mafia.
The threat is increased with organized cybercrime because of its international reach.  Worldwide networks have turned local crimes into global crimes.  Hackers sitting in one country can now rob a bank—or many banks—from halfway around the world.  Cyber criminals steal personal information located in one country, sell the data to fraudsters in another country and count their profits in a third.  And just as sophisticated cyber criminals take advantage of weaknesses in computer security, technology can allow them to take advantage of international borders and differences in legal systems, hoping that investigators from the victim’s country will not be able to obtain evidence from abroad, if it is even available.
I am proud to say that we’ve been successful in infiltrating and dismantling some of these organizations.  For example, we are currently prosecuting an internet-based, international criminal enterprise known as Carder.su.  The over 5,500 members of this enterprise trafficked in compromised credit card account data and counterfeit identifications, and committed money laundering, narcotics trafficking and various computer crimes.  They used web forums largely hosted in former Soviet Union countries and communicated through secure and encrypted forums, proxy computers and virtual private networks.  Gaining membership in the group required the recommendation of two current members in good standing.  Disloyal members were stripped of membership and barred from the websites.
In July 2015, federal law enforcement seized a dedicated cybercrime forum known as Darkode.  Darkode was an online, password-protected cybercrime marketplace in which hackers and other cyber criminals convened to buy, sell, trade and share information, ideas and tools to facilitate unlawful cyber intrusions.  As with Carder.su, prospective members were vetted before they could join to determine whether they had marketable skills or products to bring to the group. 
Like most criminal organizations, the members of these two sites had different and defined roles.  But instead of Dons and Capos, “Administrators” handled day-to-day management.  In the place of Consiglieres, “Moderators” would monitor and police the websites.  “Vendors” advertised and sold illegal products, services and contraband and “Members” used the websites to purchase contraband and share criminal schemes.
Of the hundreds of criminal internet forums around the world, Darkode and Carder.su were two of the most pernicious.  Yet despite their sophisticated technologies, these groups remained vulnerable to a tried and true mob-busting technique: infiltration by undercover agents or confidential informants.  In Carder.su, 56 individuals were charged in four separate indictments.  To date, 33 individuals have been convicted and the rest are either fugitives or pending trial.  In Darkode, charges have been filed against 12 individuals in U.S. federal court; convictions have been obtained in seven U.S. cases and one foreign prosecution.
As organized crime digitizes its operations, law enforcement faces two significant challenges: first, the use by criminals of new encryption technologies to victimize innocent people while avoiding identification; and second, territorial limits on our ability to gather digital evidence of crimes.  Addressing these challenges is among the Justice Department’s top priorities.
First, let me say the Criminal Division is on the front lines of the fight against cybercrime.  We recognize that the development and adoption of strong encryption is essential to counteracting cyber threats and to promoting our overall safety and privacy.  But certain implementations of strong encryption pose an undeniable and growing threat to our ability to protect the American people.
In an attempt to market products and services as protective of personal privacy and data security, companies increasingly are offering products with built-in encryption technologies that preclude access to data without the consent of the user.  For law enforcement, this has resulted in something we often describe as “warrant-proof encryption.”  Warrant-proof is not a technical term, and it can encompass different types of technology, but we use it to describe a situation where a service provider has implemented encryption in a way that prevents them from producing usable, unencrypted information even if they are served with a valid court order.
This is no small problem.  Service providers with over a billion user accounts, that transmit tens of billions of messages per day around the world, now advertise themselves as unable to comply with warrants.  And device manufacturers that have placed hundreds of millions of products in the market have embraced the same principle. 
Where investigators used to rely on physical evidence, we now look to electronic evidence and digital communications.  In nearly every criminal investigation we undertake at the federal level—from homicides and kidnappings to drug trafficking, financial fraud and child exploitation—critical evidence comes from smart phones, computers and online communications.  These materials are increasingly unavailable to law enforcement as a result of some encryption technologies, even when we have a warrant to examine them.
Our inability to access such data can stop our investigations and prosecutions in their tracks.  Securing and keeping private our electronically-stored information is critically important, but so too is the time-honored legal process that protects our values and our safety.  These are complementary, not competing priorities, and they are considered every time a warrant is issued.  If an independent judge has evaluated the facts of a case, and, after balancing the constitutional privacy interests and the needs of justice, issues a warrant or order, a company served with that order must comply.
To be sure, solutions to the challenge of widespread, warrant-proof encryption will not be easy.  But the decision about whether law enforcement can access data must be made in the policy arena, not by the private sector.  We should not allow changing technologies or the economic interests of the private sector to overwhelm larger policy issues relating to the needs of public safety and national security. 
The challenge we face with warrant-proof encryption is part of a broader trend requiring harmonization of law and technology.  In July, in the so-called “Microsoft Ireland” case, the Court of Appeals for the Second Circuit held that a judge could not authorize the use of a Stored Communications Act (SCA) warrant to compel disclosure by Microsoft of email communications stored in Microsoft’s Ireland data center, or any server outside U.S. borders.  This holding means that, in the Second Circuit, the contents of communications held by any service provider outside the United States—even when they belong to a U.S. person, are maintained by a U.S.-based company and are controlled by a person sitting at a computer terminal in the United States—is off limits under an SCA warrant. 
Data stored by communications providers, such as emails, IP records or even subscriber information, can be crucial to the department’s work.  It is not unusual for this type of information to be stored in the United States, whether the information relates to an American, or to a foreign citizen who happens to use an American service. 
Increasingly, however, American providers and other providers subject to the jurisdiction of U.S. courts are storing information outside the United States, and not always at rest and in the same location.  For example, one major American provider has said that it has begun to store the contents of many accounts in data centers located abroad.  That provider indicated that it chooses whether to maintain data in the United States or abroad based solely on the user’s selection of her country of residence at the time the account is created.  Accordingly, even Americans who live in the United States can effectively choose to have their account data stored abroad by doing no more than choosing a desired country from the drop-down menu on the sign-up form.  In fact, many of the largest American providers now operate data storage centers abroad and it is unusual for a major provider to store all of its data within the United States.
In today’s world of global cloud computing, it makes little sense to determine the legality of search warrants based on where companies choose to store their data.  U.S. providers control billions of user accounts for customers across the globe, and nothing in U.S. law requires their data to be stored in this country.  Today’s technology means that data can be moved across jurisdictions or stored in multiple locations for any number of business reasons.  The location of the data could change day-by-day or hour-by-hour.  Meanwhile, U.S. providers increasingly face tax or other business incentives to operate data storage centers outside the United States. 
Already, U.S. providers have declared in response to multiple federal warrants, on the basis of the Microsoft Ireland ruling, that they will only produce responsive information known to be located in the United States.  That number will certainly grow. 
Alternative methods, such as the Mutual Legal Assistance Treaty—or MLAT—process, are not sufficient.  The United States has MLATs with less than half the countries in the world, and many of those treaties exclude certain categories of evidence altogether.  Even when a request for evidence is covered, the MLAT process generally lacks the requisite efficiency for time-sensitive investigations and other emergencies.  Ireland, for example, reports that requests take 15 to 18 months in routine cases.  In less experienced or less cooperative countries, the process can take even longer.  Sometimes we never receive a response at all.  What all of this means is that an enormous amount of electronic evidence—information necessary for investigations ranging from national security cases to human and drug trafficking, to cyber intrusions and child exploitation—may now be out of reach entirely.
That is why the administration has made clear that it intends to promptly submit legislation to address the significant public safety implications of the Microsoft decision.  But in doing so, we must be mindful of the responsibility Congress and the American people have entrusted to us: to protect Americans from threats to their safety and security.  Legislative proposals that base law enforcement access to electronic evidence solely on MLAT requests to other countries will inevitably slow, and in some cases end, the investigation of serious offenses against Americans. 
That cannot be the path forward.  In a world where business decisions and cumbersome bureaucratic processes, rather than time-tested constitutional standards, determine when criminal investigations can advance, both privacy and the safety of Americans surely lose.  As with the encryption debate, we should not leave the commercial market to resolve what must be balanced policy decisions.
In each of these areas, we must proceed thoughtfully and balance multiple different legitimate interests.  Yet several basic principles should be obvious.  First, sitting back and doing nothing is not an acceptable option.  The world is changing around us, and those seeking to do harm are evolving with it.  If those responsible for ensuring public safety do not have the same ability to adapt, public safety will suffer. 
Second, these changes pose policy challenges and we need to develop policy responses.  Rather than let events or evolutions in technology dictate our responses, we must think ahead as a society and develop appropriate frameworks to address new and upcoming challenges before they become crises. 
And finally, when there are multiple interests at stake—public safety, cybersecurity, international comity and civil rights and civil liberties—we cannot allow the most consequential decisions to be made by a single stakeholder, or leave them to the whim of the commercial marketplace.  We would never countenance that approach in other areas of importance to society, and we should not do so here. 
Thank you.

Voting is beautiful, be beautiful ~ vote.©