funsec mailing list archives

U.S. Charges 37 Alleged Mules and Others in Online Bank Fraud Scheme


From: Paul Ferguson <fergdawgster () gmail com>
Date: Thu, 30 Sep 2010 13:51:43 -0700

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Some good news.

Via Threat Level.

[snip]

Thirty-seven people are being charged in the U.S. for their alleged role in
an international fraud ring based in East Europe that stole more than $3
million from bank accounts belonging primarily to small businesses and
municipalities, according to indictments released Thursday.

The sophisticated ring included a multitude of East Europeans who entered
the U.S. on student visas and fake passports to operate as so-called
“money mules,” laundering funds stolen from U.S. accounts and sending
the money overseas.

Hackers believed to be in East Europe ran a botnet that used variants of
the Zeus malware delivered to victims via e-mail. Zeus infected the
victims’ computers to steal bank login credentials. The hackers then took
over the accounts to initiate illegal bank transfers to other accounts
controlled by the mules.

 Last January, for example, about $130,000 was siphoned from the California
bank account of a hospital.

The charges, filed in the Southern District of New York, are the
culmination of a year-long investigation, dubbed Operation ACHing mules.
“ACH” refers to Automated Clearing House, the system under which funds
can be electronically transferred from one financial account to another.

[snip]

More:
http://www.wired.com/threatlevel/2010/09/zeus-botnet-ring/

Enjoy,

- - ferg

-----BEGIN PGP SIGNATURE-----
Version: PGP Desktop 9.5.3 (Build 5003)

wj8DBQFMpPhWq1pz9mNUZTMRAtR7AKCFQ027hLtvA+VE5lwM17tARRoaowCg33n9
IHjPe6iKukdpGD1qo+CcVlw=
=g5Tb
-----END PGP SIGNATURE-----


-- 
"Fergie", a.k.a. Paul Ferguson
 Engineering Architecture for the Internet
 fergdawgster(at)gmail.com
 ferg's tech blog: http://fergdawg.blogspot.com/

_______________________________________________
Fun and Misc security discussion for OT posts.
https://linuxbox.org/cgi-bin/mailman/listinfo/funsec
Note: funsec is a public and open mailing list.


Current thread: