Thursday, September 15, 2011

The Nigerian ScamerAtor™!

The Nigerian ScamerAtor™!

Over the past ten years or so I have been sporadically reporting "Nigerian Scam" spam messages to the email vendors these criminals abuse.

I'm going to assume that you know what a Nigerian Scam is. They've been in existence since the mid-90's, and they re-use a lot of the same ruses to entice their victims to part with some - and in some cases nearly all - of their money. Many of you may remember my experiment over the past two years to tabulate how much I would have "won" from these alleged inheritances, lotteries, funds and other ridiculous scams. I also kept tabs on how much I would have "inherited" or "won" from November 2009 to the end of 2010. The final total was $100,319,915,673.22 USD (100.3 Billion dollars.)

In November 2008 I wrote a detailed posting describing how anyone could report these scam messages, and about the reliability and timeliness of the responses and cancellations of these offending accounts. At that time, Hotmail and Yahoo were two of the worst at getting accounts removed which were actively being used in this patently criminal activity. Fast forward to today - and especially the past six months - and that situation has greatly changed for the better.

Hotmail is now cancelling these offending account in as little as ten minutes of receiving my report. This is a huge, huge difference and I applaud this drastic change in their responses to these reports. I would report a new scammer's Hotmail / MSN Live Mail account within a few seconds of receiving one of them, and 10 - 15 minutes later it would be shut down.

It's important to note that they won't shut down just any account. You have to explain to them why the account is being used fraudulently, and explain where in the message the offending account appears. If your reporting to them is consistent, they shut the account down, simple as that.

Per day, I was receiving from 60 - 80 of these scam messages every single day. Once I started cc'ing the criminal's account on my reports, that account saw a precipitous drop in the volume of Nigerian Scam spam messages received every day. Now it's one or two a day. For that account, Nigerian scam messages are the only spam it receives. All the pharmacy spammers gave up on that account two years ago.

I also received a small handful of replies from the criminals on the other side of these accounts. Some of them demanded that I stop reporting them. I replied that they shouldn't have me in their lists in the first place. Some boasted that this would do nothing, that they would just create thousands of other new accounts. But then after a few weeks I received another message pleading for me to stop. All of this indicates that these reports work, even if it's just one person doing them.

So I decided to create a tool that automates the creation of these detailed reports so that a lot more people could join me in trying to put a major dent in this malicious activity, and I called it the Nigerian ScamerAtor™.

You can download it here:

http://www.spamtrackers.eu/downloads/files.php?fid=90
[Link last updated Jun. 24th, 2012 - v.1.6]

Instructions:
  • Download the file
  • Unzip the file
  • Open the html file in a browser of your choice (as always, I recommend FireFox.)
  • Choose the email vendor this criminal is abusing from the drop-down list.
  • Enter the offending email address
  • (Optional) Choose which fake scenario this criminal is claiming to present. (Lottery, fund, FBI, UN, etc.)
  • Choose where this email address appears (headers, body, both.)
  • Enter the message headers
  • Enter the message body
  • Click on the "Go!" button
  • A message will be generated for you including the "to", "subject" and a detailed message for the abuse team you wish to send it to.
  • Copy that into an actual email and send.
I'm discovering that some of the lesser-known of these email vendors - Blumail.org, Superposta, Globomail, etc. - are far less responsive, so it's unclear whether this will ultimately have any effect at all on these messages, but I figure with more volume of these complains coming in, somebody would have to take notice.

Both Gmail and Yahoo now only process these abuse reports via online forms. No emails, period. They also do not respond to any reports but I did some randomized testing and it appears that within 24 hours the reported accounts are indeed terminated. I wish that they would be more communicative of this but at least they do shut the accounts down.

I welcome responses as to further features you think this tool could use, and especially any reports of major successes.

As always, thanks for reading.

SiL / IKS / concerned citizen

Monday, August 8, 2011

On The Changing Landscape For Non-Compliant Career Spammers

Hello, faithful readers of this blog.

As you all have no doubt been aware, updates here have been very few and far between for a while now. I wanted to post a quick update to let you know that yes, I'm still alive, and yes, many things are still underway in the fight against online criminals and the spamming they engage in, among other things.

When I started this blog, email spam was definitely a major scourge, and a vast amount of criminality stemmed from spam itself, which eventually led me further and further up the food chain. That meant that over time, email spam itself (or spam of any sort really) became less of a focus of investigation for me than more meaty subjects like the hosting infrastructure of one or another criminally-operated pharmacy affiliate program, or investigations into one or another botnet's infrastructure and command and control.

Over the past several years, my role in these investigations has been one of a disseminator of collected research and intelligence, handing over as much of the indepth analysis and research as I could supply to a larger and larger number of researchers and investigators.

As the last two years have shown, that's lead to a much greater set of eyes becoming focused on all manner of online crime, and the results have been pretty fascinating to see. I am not saying that my research specifically has directly led to legal action - I have no way of knowing - but it's part of a collected mass of research which may have assisted several organizations in deciding which action (or actions) to take against the operators of these large-scale spam operations.

I'll just itemize a few of these investigations here to get the idea across. Much of this has been covered in greater detail and with more background research by many other more established journalists, security researchers and bloggers than I would have been able to do here.

Microsoft managed to shut down the infamous Rustock botnet - responsible for the majority of spam sent on behalf of Spamit - via some extremely strategic legal and subsequently technical means. That led to a massive drop in spam of any sort (but especially fake pharma) being greatly, greatly reduced. It's also more recently led to a very public notification to the public, especially in Russia, where most recently they've offered a new $250,000 reward for the "identification, arrest and criminal conviction of whoever is responsible" for the Rustock botnet. (If you know who it is, you can file your own report at avreward[at]microsoft[ot]com.)

This is a big deal to anyone who has been researching spamming via botnets, since Rustock was the botnet responsible for the vast majority of this spam.

Since Rustock was shut down, the statistics for spam overall have seen a dramatic drop. I mean a seriously dramatic drop. It's still there (there are other botnets of course) but it's nowhere near the high volume enterprise that it once was. This is a monumental shift from how things were even a year or so ago, but especially when compared with spam volumes from 2006 through 2010.

As previously mentioned, Spamit themselves pulled the plug on their fake pharmacy affiliate program in October of 2010. Very shortly after this, the alleged owner and operator of Spamit (and, one might logically assume, Glavmed) - Igor Gusev - fled Russia where he began a blog outlining the criminal activities of Russian payment processor Chronopay. Renowned security blogger Brian Krebs has written about all of this at great length, and continues to cover more recent legal activity against Chronopay and its (now former) CEO, Pavel Vrublevsky.

I haven't written about any of that here, again because it's been covered in extremely deep detail by both Russian and North American bloggers and journalists. The litany of public leaks of internal Chronopay emails, documents and other items between 2010 and 2011 has been breathtaking and it most recently led to a large scale raid of the Chronopay offices, and the arrest of Mr. Vrublevsky. That is pretty huge news and I encourage any of my readers to dig into the stories covering that raid and the previous links because it's a pretty big eye openener into one of the largest online criminal operations I've seen in my time covering this subject. The leaked documents have revealed that Chronopay was the operator of one of the first taregted Mac-only fake antivirus scams, MacDefender, and further shows that Chronopay's direct statement insisting that they had no relationship with MacDefender whatsoever was an outright lie. The leaked documents further outline Chronopay as a company creating several new companies specifically to sell other types of fake antivirus "products" over many months. Vrublevsky is the co-founder of one of the larger fake pharmacy operations known as RX-Promotion. Rx-Promotion was formerly in third place after Spamit and what is now known as Eva Pharmacy (formerly Bulker.biz and Bulkerbiz.com.) Since the raids, rx-promotion.com no longer resolves, and other criminal online programs which used Chronopay as their payment processor (notably, other fake-antivirus affiliate groups) have had to recently announce that they were no longer able to pay affiliates in a timely manner.

In the midst of all of this, Pavel Vrublevsky is arrested for having ordered or engaged in a DDOS attack against his competitors.

An additional interesting occurrence was the publishing of a couple of very well-researched reports and the subsequent widespread publicity of the same. Two very gifted researchers at the University of California at San Diego published two reports - "Click Trajectories: End-to-End Analysis of the Spam Value Chain" and "Show Me the Money: Characterizing Spam-advertised Revenue" - which I cannot recommend more strongly as a must-read for anyone interested in discovering how an online criminal spam operation works and who profits from them. These two scholarly reports, each of which have been linked to, Slashdotted, quoted, reported on by the New York Times and many other large-scale media organizations, investigate in very great detail and organize the research into every facet of how a typical criminally-run spam operation works.

So what does this mean for the spam landscape? Generally it appears that spamming, as a scummy way of making money, is way down the list of things a burgeoning online criminal or otherwise unscrupulous "marketing" affiliate would choose to engage in. In fact, forum spamming - euphemistically referred to as "SEO marketing" - has very quickly come in to take its place. There are numerous existing researchers and monitoring operations which report on this activity, and many companies such as Google (especially Google!) have already begun to put processes in place to make this type of search engine gaming less and less effective.

Based on feedback from many individuals out there, the majority of email spam that now routinely appears in anyone's mailbox (if indeed it appears there at all, given how good some spam filters have become, again most notably Gmail's) are for Nigerian scams. This has to mean that whoever is still sending any volume of spam today has definitely run short on options of what to send their stolen or harvested lists of recipients. That's mostly a good sign, since there's a lot of very public stories about how to avoid Nigerian scams, and most of the content of the messages promoting these scams haven't changed significantly since 2003.

Today, for the first time in several years, I received a stock spam message. I can only see this as a further indication of outright desperation on the part of whoever's lists I'm on. Stock spam, when it was sent regularly at all (2006 through 2008) only rose in volume once some facet of a fake pharmacy operation experienced major issues either in terms of their ability to keep sites up or to process transactions. Receiving a single stock spam message in the current climate, when most people are seeing very small numbers of pharma or replica watch spam, is something I personally see as a cry for help.

So: taken together we see several fairly big breakthroughs in only the past 10 months or so:

  • Spamit closes their doors
  • Spamit operator (Igor Gusev) flees
  • Gusev starts an anti-Chronopay blog
  • Numerous sources leak internal emails and lots of internal documentation from Chronopay
  • Many researchers and bloggers, Russian and otherwise, examine and report on findings from the leaked Chronopay documents and emails
  • Chronopay is linked to RX-Promotion directly
  • Chronopay is linked directly to one or more fake antivirus scams
  • Chronopay is identified as the payment processor of choice for numerous other fake antivirus scams
  • The Rustock botnet is shut down via legal and technical efforts from Microsoft
  • The creator of the Rustock botnet is currently a wanted man, and has a new bounty on his head
  • Chronopay offices are raided and its CEO, Pavel Brublevsky, is arrested for DDOS attacks against his competitors
  • Several fake-antivirus affiliate programs indicate that they can no longer process payments for their affiliates
  • RX-Promotion's website and affiliate portal shut down with no public explanation (but we can all take a wild guess.)

That's a lot of activity in such a short amount of time. In all the years I've been researching the multitude of online criminal activities, this is the first year where it looks like the options for online criminals are finally dwindling. It hasn't disappeared completely, and I don't think I should ever expect that to happen. But the fight against the people who thrive on this illicit activity is turning a corner.

I'd like to add a separate item which is mostly speculation on my part. Since the recent devastating earthquake in New Zealand, spamming for a variety of fake pharmacy, "herbal" penis enlargement, diet and fake replica products have seen a massive decrease as well. These were all products which were virtually identical to ones previously promoted via the former "AffKing" affiliate program, operated by Shane and Lance Atkinson, who both still have restraining orders and very heavy fines against them for promoting those products via spam (well: and for the products being, you know, fake.) The spam hasn't stopped 100% but it's clear that the earthquake affected the ability for this particular type of spam to be sent.

My involvement in the exposition of these operations has been reduced mostly due to my desire to get the proper research into the hands of people who can accelerate the fight against this activity. That's proven to be the best use of my time over the past couple of years. I still research it. I still document what I find. I still participate in the many online communities which engage in this research, sharing ideas, discovering how things work in the online criminal world. But my use of this research is better served by being shared with broader groups of researchers, and it's encouraging to see so many more researchers (or even better: large groups of researchers) who are making a difference with the data they uncover.

I think it will be interesting to see if certain parts of the spam landscape resuscitate themselves or not, or if they morph into some newer or unexpected form of scammy operation. I also think it is heartening to know that a large number of career spammers are now left with far less of their regular illicit income, and most importantly that law enforcement agencies, internationally, are working together to get this activity shut down on a very large scale.

If I do have more to report I definitely will do so, even if that means I ultimately link to someone else's report. The battle continues, and from where I sit I hope that you would agree that the developments in that battle have been very interesting indeed.

SiL / IKS / concerned citizen

Thursday, February 17, 2011

Flying Croc Promotes Its Webcam Sites with Even More Lies and Messenger Spamming

Several readers (and others who found my blog via numerous searches) have complained to me for several months about a site known as "MyWebCamCrush.com."

This domain, among several others (camsecret.com, camsecretcrush.com, camsecretcrush2.com, yourprivateshow.com, many, many more), is being spammed via MSN Messenger and Yahoo Instant Messenger in much the same way that the renowned "SlickCams" webcam dating sites were spammed since 2007. (SlickCams is part of a very large number of companies and properties owned and operated by Flying Croc, who have a history that dates back several years of malicious adult-content spamming of one sort or another, but predominantly via MSN Messenger.)

It turns out that FlyingCroc.net has never stopped this practice, and appears to now control a large variety of similar adult webcam dating sites and affiliate programs, with no intention of stopping the ongoing practice of spamming total strangers (and probably minors) with automated MSN chat sessions promoting webcam porn dating sites. The most prominent of their spammed properties since 2008 has been StreaMate.com. I'll outline that setup here, but there are others.

At first it was assumed that this particular spammer was engaging in this malicious activity on behalf of only one webcam affiliate program. It turns out: he / they are doing this on behalf of at least two distinct affiliate programs, but probably more.

Here's how the StreaMate scam works:
  • An unsuspecting user of either Yahoo Messenger or MSN Messenger receives notice that an unknown user has added them to their list of Messenger friends / "Buddies"
  • They accept the invite
  • They initiate a messenger session with the anonymous "person"
  • The anonymous person goes through a predictable script
  • The messenger chat always mentions a specific link that the victim should click on to see this "person" on their webcam
  • The link is always to one of the above-mentioned domains
There are several examples of these fake chat sessions which make it clear that these are in fact MSN bots, not real people. (Examples: here and here.)

Here's a sample:

<[redacted] 4:19:15pm> hello
<princesstera200 4:19:38pm> hey :-)
<[redacted] 4:22:11pm> someone told me to IM you
<princesstera200 4:22:18pm> im good how are you?
<[redacted] 4:22:30pm> oh it's a bot
<princesstera200 4:22:40pm> looks like you got my message? whats up with you?
<[redacted] 4:22:50pm> you're a bot yo

...

<princesstera200 4:26:12pm> do you think i should wear a thong?
<[redacted] 4:26:17pm> no
<princesstera200 4:26:30pm> lol great choice well i want to give you a free courtesy pass to view me on my cam?
<[redacted] 4:26:40pm> chii would never wear a thong
<princesstera200 4:26:54pm> i want to give it to you k babe?
<[redacted] 4:27:06pm> k fine
<princesstera200 4:27:18pm> Ok go to http://www.camsecretcrush.com/kiss***** and create a free profile
<[redacted] 4:27:32pm> k thx
<[redacted] 4:27:44pm> bot

Very obviously an automated chat session.

So here's where we end up if we follow that link [click to enlarge]:


Visiting the site we see a page that presents a few things which appear to be real, but actually are not.

The first is a countdown, indicating that this invitation from our MSN bot has a time limit, and therefore some urgency is implied with your immediate registration.


The second is that there is what appears to be a live chat window, which it turns out is a pre-recorded 1 minute video of a girl pretending to engage in conversation with the victim.


If you attempt to type into the fake chat field, the page refreshed with a totally different video of a totally different girl.


Note the inclusion of the blinking words "Live Now" on the top right corner of the video window. Also utterly fake.

It turns out that video is provided in an iframe by the camsecretcrush.com website itself:

http://www.camsecret.com/exports/golive/iframe/?chat=0&input=0&AFNO=1-0-1&

But that iframe is in fact pulling all of its content from a site called camsecret.com

http://www.camsecret.com/exports/golive/iframe/?AFNO=1-0-1&chat=0&input=0&rlc=1&timer=5

Each of these pass the affiliate id of "1-0-1". This is probably irrelevant since the only time I or anyone else have seen these is via spammers, so one could assume that every single affiliate of this program is probably a spammer via MSN, and that this company fully condones MSN or Yahoo Messenger spamming. (Some have also complained that this is also occurring on Skype.)

If you load that camsecret.com iframe url on its own you see a completely random choice of fake videos depicting several women. It lies to you and says it's "Live Now", but in reality these are all pre-made videos which stream to it in real-time from the domain naiadsystems.com:

http://www.naiadsystems.com/flash/generic/20110112/avchatpure.swf

naiadsystems.com uses flyingcroc name servers:

Domain Name: NAIADSYSTEMS.COM
   Registrar: TLDS, LLC DBA SRSPLUS
   Whois Server: whois.srsplus.com
   Referral URL: http://www.srsplus.com
   Name Server: NS1.FLYINGCROC.NET
   Name Server: NS2.FLYINGCROC.NET
   Status: clientTransferProhibited
   Updated Date: 02-apr-2007
   Creation Date: 27-apr-2005
   Expiration Date: 27-apr-2012

Surprise surprise. Welcome back, former SlickCam.com spammers.

Its contact information in the WHOIS points to StreaMates, allegedly in Cyprus:

Registrant:
         Streamates Limited Streamates Limited  (hostmaster@streamates.com)
        Streamates Limited
        196 Arch Makarios Avenue, Ariel Corner 1st Floor, Office 102, PO Box 57528
        3316 Limassol,   3316
        CY
        00357-25820280

StreaMate has had affiliates spamming via MSN on their behalf for something like two full years as of this writing.

The chat itself (if it occurs) is also completely fake. We can see this by looking at the JavaScript within the page of these throwaway sites this spammer has registered. They make no attempt to hide the fact that this whole setup is fake.

<script type="text/javascript">
var spoof_cam = '';
var start_minutes = 5;
var start_seconds = 30;
var current_minutes = start_minutes;
var current_seconds = start_seconds;
var splashpage_name = 'Sam';
var random_message_start = 3;
var random_message_end = 6;
var random_message_interval = (random_message_start + Math.floor(Math.random() * (random_message_end - random_message_start))) * 1000;
var random_message_text = 'hurry im waiting for u..';
var ad_categories = '';
</script>

"spoof_cam". "random_message_text". This is so clearly a scam. Not a single real event is taking place here. The spammers know this.

When the 1 minute video is completed, a link appears in the flash video window only, an attempt to further obscure where this spammer wants you to click.

In the example I'm presenting here, the link goes to:

http://www.camsecret.com/signup/?smid=5844090&AFNO=1-0-1

[Notice: no secure "https://", just plain "http://"]

CamSecret is also operated by FlyingCroc:

Registrant:
         FCI, Inc. FCI, Inc.  (hostmaster@flyingcroc.net)
        FCI, Inc.
        2019 3rd Ave Ste 200
        Seattle, WA  98121
        US
        206.374.0374

Note that at the top of that page, it claims that you can "Sign-up safely at Camsecret"


This is of course also a lie. None of these domains offer any SSL or other security. CamSecret.com makes this statement boldly on a page which is very obviously not secure.

Just to be 100% sure: attempting to load:

https://www.camsecret.com/signup/?smid=5844090&AFNO=1-0-1

Results in a "not found" error.

Liars. So far numerous lies from beginning to end and we haven't even joined yet. Exactly how "real" do you these so called "webcam girls" are going to be?

As with all of these spamvertised domains, whois information for one of the numerous spammed domains, webcamcrush.com, was originally protected by Privacy Protection provided by GoDaddy.com. However one intrepid researcher decided to raise this case with the Arizona State Attorney General's office, who apparently managed to convince GoDaddy to identify who had registered this domain. It turns out to be one Yaniv Mindell, from the domain "DefiniteDollars.com":

Registrant:
YMIND, Ltd.

Amory Building, Victoria Road
Basseterre, 3979
Saint Kitts and Nevis

Administrative Contact:
Mindell, Yaniv yaniv@definitedollars.com
YMIND, Ltd.
Amory Building, Victoria Road
Basseterre, 3979
Saint Kitts and Nevis
+1.9544788981

Another shell company. First Cyprus, now Saint Kitts and Nevis.

webcamcrush.com is also suspended as a domain.

mywebcamcrush.com's whois information is still protected via GoDaddy. (Aside: When are registrars going to stop providing this for repeat offenders? This is year #4 of this activity. GoDaddy should know better by now.)


DefiniteDollars.com has all the markings of an underground affiliate program. No FAQ, a terms of service that states that they don't allow spamming, but of course no contact gets any response from this company.

I would like to cast an open invitation to anyone who has been affected by this group's ongoing MSN or Yahoo Messenger spamming, and I'd also like to put out an open invitation to both the Yahoo Messenger and Microsoft Live Messenger Team specifically, since I have been attempting to raise any attention whatsoever with that team since 2007, with absolutely no effect.

I'd also like to openly ask GoDaddy why it is that four years on they still allow this group to register dozens-to-hundreds of domains with their company, an continue to hide their contact information despite numerous abuses of their terms of service.

As with all previous spam activity on behalf of Flying Croc, the risk is very high that minors are being exposed to this content. Whoever harvested these MSN and Yahoo accounts had absolutely no concern for how old the unwitting recipient of these invitations might be. They just send out the invitation to however many thousands of these accounts they can unearth, and begin the automated chat to get them into what is clearly an adults-only website. I would assume that the Arizona State Attorney General's office would be aware of this detail, but if not they certainly should be.

Somebody has to start a class-action suit against the owners and operators of Flying Croc. They've been getting away with this crap for years and people are sick of hearing from them.

SiL / IKS / concerned citizen

Monday, January 31, 2011

Spammers Are Now Using Verified By Visa

It's been a while since I posted anything here. It's been a really busy two years, all in really good ways.

I've begun receiving tons (as usual) of spam promoting a new "Viagrow" site setup. This same spammer also sends me Ultimate Replica spam and spam messages promoting "Online Pharmacy" (I don't know the affiliate program for that one.)

Viagrow is of course yet another in a long line of utterly fake penis enlargement products. (I have to wonder why these spammers, all predominantly Russian, have such a fixation on penises, but that's probably a topic for another day.)

I decided to check out the new "Viagrow" site setup in terms of examining their order processing methods and was stunned to discover that they actually use the Verified by Visa process. This is a first, and is especially surprising given how frequently spam affiliate programs have been abusing the Verified by Visa brand over the past six years.

Spammed site:

http://[randomtext].change-your-life1.com/

Presents two forms to the user to capture personal details including full credit card details. It does so (of course) using no security whatsoever.

Posting the second form leads to this spam operation's custom payment processing domain:

http://cyber-pay.biz/paynet/payment.html

Which in turn passes the form's values to the actual Verified by Visa domain, using Visa's proprietary encryption.

Since I began researching criminal spam operations and the forms their sites use to snare personal details from victims (ahem) "customers", Visa - or more likely the third-party "high-risk" merchants who perform the processing - has never canceled any processing for these sites. This is going all the way back to 2002 or earlier. MasterCard and American Express have repeatedly denied service to pro-spam websites, but never Visa.

Now the Verified by Visa program, one which is directly operated by Visa itself, is allowing payments to be processed directly, essentially sending the message that Visa as a company is a-ok with criminals using their services.

cyber-pay.biz is registered with Directi and hosted on 67.228.177.168, provided by SoftLayer. Softlayer is now owned by ThePlanet. Softlayer has provided hosting, dns and domain registration to online criminals for many years now, so it's probably not going down anytime soon. Directi, in my experience, has been very helpful with spam complaints so we'll see what happens in that department.

change-your-life1.com is registered with bizcn, hosted on 93.114.40.213 by Voxility in Bucharest, Romania.

If anyone knows of any Verified by Visa contacts I'd be extremely interested to see if anyone over there would care to respond regarding their support of a criminal spamming operation.

SiL / IKS / concerned citizen

Friday, December 31, 2010

2010 Year End Wrap-up: Year Of The Botnet

While the previous two years saw several high-profile investigations, arrests, trials and convictions of several very well-known spammers and their supporters, 2010, even from the very start, was already appearing to be a year where international focus turned to botnets, cyber attacks, cyber crime, and theft via malicious Windows infections. For the first time we saw mainstream news organizations featuring stories about international criminal activity via computers and rogue networks, and for the first time some of these ended up on the front page of newspapers like the Wall Street Journal and the New York Times. This is a very distinct shift from previous years where this type of story would be relegated only to tech news outlets, and only discussed and understood by tech professionals. This is, I must say, a very good sign, because cybercriminal activity's real target is the rest of the public who really are not that tech-savvy.

However, this year we also saw several very highly publicized "takedowns" of some well known botnets, notably Lethic, Waledac, Bredolab, and Mega-D. Not all of these shutdowns were 100% successful, but the volume of activity related to getting specific control servers for one or another botnet is a welcome development, and hopefully will lead to more firm activity on behalf of law enforcement and security researchers around the world. In one particularly interesting case, a series of renowned criminal botnets known as Zeus were shut down and several of their operators were also arrested, pending sentencing as of this writing. This didn't always immediately result in a slowing of criminal activity related to these botnets, and in many cases it didn't appear to have any noticeable effect on the volume of spam received by ordinary email users, but it was still a very notable development in the fight against online criminal activity.

2010 was also the first year where we saw a major international incident caused by a malware infection, which in this case affected Iran's nuclear program. This was a major story and continues to be a genuine concern with regards to international diplomacy and overall relations in the Middle East. Later still, the now-infamous Wikileaks "Cablegate" releases to the media further compromised international diplomacy, as bit by bit thousands and thousands of classified US embassy cables from embassies around the world make their way into the mainstream media. This is an unprecedented event and should continue to be the source of further interesting developments in the years to come.

In more specifically spam-related areas we saw major media also casually refer to operations such as Spamit or Glavmed, identifying them (correctly) as one of the most egregious high-volume criminal spam operations in the world. Even better: a lot of media and law enforcement attention was paid specifically to Spamit and Glavmed, resulting in Spamit closing up shop due to receiving too much heat. That was a development I wasn't expecting to happen so quickly, and it's an indication that the days of criminally operated pharmacy affiliate programs may finally be about to come to an end.

So here we go. Start the popcorn maker...

Jan. | Feb. | Mar. | Apr. | May | Jun. | Jul. | Aug. | Sep. | Oct. | Nov. | Dec.

January:

  • SiL begins 2010 having "won" or "inherited" $15 Billion USD from a 14-month flood of Nigerian scam messages. Within the month of January, SiL "wins" or "inherits" an additional $5 Billion USD, due to a sudden increase in this type of spam.
  • Jan. 4th, in a followup to a previous article he wrote in December 2009, Knujon's Garth Bruen writes about the large number of illicit hosting providers related to the online fake / illicit pharmacy trade. The article comes under fire from many US-based ISP's, but definitely makes some salient points, focusing on the violation of intellectual property rights by pill spammers.
  • On Jan. 11th, renowned security investigative firm M86 coordinate with several ISP's an registrars to take down the "Lethic" botnet, responsible for some 8 - 10% of all spam worldwide. From their research it seems very clear this spambot was dedicated to mailing on behalf of Spamit and Glavmed criminal online pharmacies ("Canadian Pharmacy", "Canadian Healthcare", etc.)
  • On Jan. 11th, the Dallas office of the FBI publishes a press release detailing a new indictment against 19 individuals for participating in a massive cybercrime conspiracy. [Original press release available here.] Four of the defendants - including the two primary individuals originally investigated back in April, 2009 (Michael and Chastity Faulkner) are alleged to have fled the United States to avoid prosecution. If convicted of conspiracy, the defendants face a maximum sentence of 30 years in prison and a $1 million fine. [Also see this coverage.]
  • On Jan. 12th, in what is considered to be a bold statement internationally, the Google Blog divulges that Google as a company has decided to no longer filter their search results from within China after coming under numerous strategic attacks, allegedly from Chinese locations.

    ...we have evidence to suggest that a primary goal of the attackers was accessing the Gmail accounts of Chinese human rights activists. Based on our investigation to date we believe their attack did not achieve that objective. Only two Gmail accounts appear to have been accessed, and that activity was limited to account information (such as the date the account was created) and subject line, rather than the content of emails themselves.

    and later:

    These attacks and the surveillance they have uncovered--combined with the attempts over the past year to further limit free speech on the web--have led us to conclude that we should review the feasibility of our business operations in China. We have decided we are no longer willing to continue censoring our results on Google.cn, and so over the next few weeks we will be discussing with the Chinese government the basis on which we could operate an unfiltered search engine within the law, if at all. We recognize that this may well mean having to shut down Google.cn, and potentially our offices in China.

    This announcement makes the front page of the New York Times among numerous other international newspapers, not merely tech news outlets.
  • On Jan. 15th, Cornel Ionut Tonita of Galati, Romania pleaded guilty to criminal phishing of bank credentials and faces up to five years in prison for his involvement in the criminal act. Also charged were two other Romanians: Petru Belbita and Ovidiu-Ionut Nicola-Roman, who was the first Romanian suspect convicted in the US for this activity. The phishing operation purported to represent Citibank, Wells Fargo and eBay. Sentencing for Tonita takes place on April 5th.
  • In a series of very public defacements, a group of rogue hackers referring to themselves as the "Iranian Cyber Army" modify the DNS settings of Twitter.com and Baidu.com to point to their own server, presenting a page stating that the site was taken over by them. [See coverage here and here.]
  • On Jan. 28th, Jody M. Smith is sentenced to a year plus one day in federal prison for his part in assisting the notorious AffKing / SanCash / Genbucks affiliate program, known for spamming all manner of fake "male enhancement" pills from 2004 til their court-ordered shutdown in 2008.
  • Brian Krebs, on his fantastic Krebs On Security blog, continues to hear from more and more victims of theft involving the use of the Zeus infection. This continues a very long-running series of stories (going back at least a full year) documenting the losses suffered by a litany of companies, schools, and other organizations.
  • Microsoft and Adobe, starting in January and continuing throughout 2010, issue a larger-than-average number of emergency patches for their products to specifically address a rash of newly-discovered exploits. In three months they issue as many emergency fixes as they did in all of 2008.

February:

  • On Feb. 8th, numerous news outlets report that the Chinese police have shut down a major hacker training site known as "Black Hawk Safety Net".

    The tally is: three people arrested; nine Web servers, five computers and one car confiscated; $249,000 in assets frozen.

    According to China Daily, the website was ran from the Hubei province in Central China, and offered attacking programs and malicious software to its subscribers.

    In theory this could represent some heavy damage to the Chinese hacker community.

    See also this coverage from the Wall Street Journal.
  • On Feb. 17th, CNN airs a multi-hour program which attempts to simulate the US government's reaction to a cyber attack. This results in a series of stories outlining the US's lack of preparedness for such an eventuality. [See one such story here.]
  • Also on Feb. 17th, security organization M86 report that despite a very highly-publicized shutdown last year, the Mega-D botnet is still sending very large amounts of spam.
  • On Feb. 22nd, in a Reuters story, representatives state that the US Government have pinpointed the Chinese developer of the malware used in the attack against Google.
    U.S. government analysts believe a Chinese man with government links wrote the key part of a spyware program used in hacker attacks on Google last year, the Financial Times reported on Monday.

    The man, a security consultant in his 30s, posted sections of the program to a hacking forum where he described it as something he was "working on," the paper said, quoting an unidentified researcher working for the U.S. government.
  • On Feb. 25th, Microsoft posts a story on their security blog detailing their shutdown of the command and control servers for the Waledac botnet. [See also this coverage and this story from the Wall Street Journal.] The project to get the botnet shut down is known internally as "Operation b49". On March 16th, it is independently confirmed that the Waledac botnet had ceased operation.
  • In late February, much of the massive flood of Zeus bot-related spam messages purporting to be from any number of financial or other institutions drops completely out of circulation. This had been slowing by Feb. 22nd, but by the 27th it drops to zero for the first time since June 2009.

March:

  • Further ratcheting up international criticism, on March 2nd the US government considers lodging a complaint with no less than the World Trade Organization (WTO) claiming that China's censorship requirements are an unfair barrier to trade. This is specifically in relation to the requirement that Google.cn must censor any potentially sensitive search terms in order to operate within China.
  • On Mar. 2nd, capping a multi-year investigation and year-long trial preparation, convicted and completely unrepentant stock spammer and all around fraud artist Alan Ralsky reports to the Morgantown Federal Correctional Institute to begin his four year sentence. You can see his prison listing here. His release date is scheduled for November 11th, 2013.
  • On Mar. 10th, with very little explanation to go on, it is reported that dozens of Zeus botnets are knocked offline.

    In an online chat conversation with Krebs on Security, [Zeus researcher Roman] Hüssy said the average ZeuS C&C he tracks has anywhere from 20,000 to 50,000 unique infected computers under its thumb. That means this takedown may have had a massive impact on a large number of criminal operations. For starters, even if we take a conservative estimate, and assume that each of the C&Cs knocked offline controlled just 25,000 PCs, that would mean more than 1.7 million infected systems were released from ZeuS captivity by this apparently coordinated takedown.
  • By March 10th, SiL's "winnings" pass the $32 Billion USD mark. That's past double what he started the year with. On average he receives from 40 to 60 of these messages every day, resulting in accumulated "winnings" of $1 Billion USD every two days or so. Who needs a stimulus package? Let's just rely on these Nigerians to pay for everything.
  • On March 10th, it is confirmed that two rogue ISP's were shuttered:
    Two ISPs, named Troyak and Group 3, were home to 90 of the 249 known Zeus command-and-control servers. Zeus Tracker, a Web site that tracks the botnet, noticed the steep drop in servers on Wednesday morning.

    The Troyak network was itself an upstream provider to six networks, known to host a large number of cybercrime servers, including Web sites used in drive-by attacks and phishing sites, according to Kevin Stevens, a researcher with SecureWorks.
    Troyak and Group 3 join McColo and 3fn / Pricewert in the dustbin of rogue ISP's. Yet another blow to criminal botnet operators.

    (Note that there are multiple Zeus botnets, not just one. Any vetted criminal can buy the code to start their own. This was still a very heavy blow to a large number of criminal operators.) [More great coverage by Brian Krebs]
  • March 11th: another shoe drops and another of the co-conspirators in the infamous TJX hacking case is sentenced to 4 years.
    Humza Zaman, a co-conspirator in the hack of TJX and other companies, was sentenced Thursday in Boston to 46 months in prison and fined $75,000 for his role in the conspiracy. The sentence matches what prosecutors were seeking.

    Zaman, a 33-year-old former network security manager at Barclays Bank, was charged with laundering between $600,000 and $800,000 for hacker Albert Gonzalez, who is currently awaiting sentencing on charges that he and others hacked into TJX, Office Max, Heartland Payment Systems and numerous other companies to steal data on more than 100 million credit and debit card accounts.
    So far, March 2010 looks like one of the worst months in history for cyber criminal operatives. Good to see.
  • On March 11th, a securities attorney, ironically named David B. Stocker, pleaded guilty and was sentenced to two and three-quarter years for his participation in yet another stock spamming and market manipulation scheme. (His mailer was one Justin Medlin, previously unknown to me.) This makes the third straight year we've seen charges, arrests, trials, convictions and actual prison time for this type of crime. You would have to be an outright imbecile to engage in stock spamming.
  • On March 23rd, the FBI's Steven R. Chabinsky gave a Major Executive Speech entitled The Cyber Threat: Who's Doing What to Whom? In it he outlined the very real threat that online crime poses to ordinary citizens but also to governments and businesses.

April:

  • In the first major leak they have released to date, Wikileaks post a classified US military video to their website and numerous other locations [YouTube Link] which depicts a US apache helicopter firing on over a dozen people, most of them non-military personnel. This includes journalists, women and children. This is a very serious leak and sets the stage for far bigger leaks which begin to appear in late 2010. [Further coverage: Collateral Murder Website]
  • On April 17th, National Defense magazine publishes a report on the current status of the threat of online criminal activity. The author quotes liberally from well-known online crime researcher Gar Warner, but it has some interesting insights about the risks and dangers if this activity is allowed to continue.

May:

  • In what may have been a first, M86 actually names "Spamit" (as opposed to "Glavmed") as the subject of one of several spam messages they witness being sent by a new botnet which resembles the Storm botnet. [source]
  • On May 3rd Knujon's Garth Bruen writes a great article entitled When Registrars Look the Other Way, Drug-Dealers Get Paid. The article outlined the key process that supports non-compliant spamming: lazy and non-compliant registrars, and a slow, ineffective ICANN. As a bonus he specifies Bulker.biz / Eva Pharmacy as an especially bothersome spammer affiliate program. This is the first of what would become several blog postings and online magazine articles drawing attention to this rampant problem with so-called "bullet-proof" domain registrars.
  • In what would become a high-water mark for the exposition of the Russian online crime economy, on May 18th Brian Krebs publishes a landmark article regarding several Russian individuals and their involvement with spamming and illicit payment processor Chronopay, sourced from several Russian media articles.
    In an open letter to investigators at the Ministry of Internal Affairs (MVD) of the Russian Federation, Ilya V. Ponomarev, a deputy of the Russian State Duma's Hi-Tech Development Subcommittee, in March called for a criminal inquiry into the activities of one Pavel Vrublevsky, an individual I interviewed last year in an investigative report on rogue security software (a translated PDF version of Ponomarev's letter is here).

    This leads to a lot of open discussion spanning several months on both Russian and English forums related to online security and cybercrime research.
  • On May 19th, notorious rogue ISP 3FN (a.k.a.: Triple Fiber Network or "Pricewert") is shut down by the FTC for providing hosting and other infrastructure to several varieties of online criminal activity.
    The Federal Trade Commission today got a judge to effectively kill off the Internet Service Provider 3FN who the agency said specialized in spam, porn, botnets, phishing and all manner of malicious Web content.

    The ISP's computer servers and other assets have been seized and will be sold by a court and the operation has been ordered to give back $1.08 million to the FTC.

    This caused some sizable financial damage to several criminal elements who profited from these servers' continued availability and marked a small success for law enforcement against some really scummy spammers.

June:

  • On June 10th, Wired Magazine's Threat Level blog publishes an article [source] in which two of their journalists communicate with a hacker named Adrian Lamo who had communicated via a variety of chats with Private Bradley Manning. Manning allegedly downloaded thousands of classified cables and handed them over to WikiLeaks over a lengthy period of time.
  • On June 20th, Igor Gusev, the alleged owner and operator of the notorious Spamit.com affiliate program files a defamation lawsuit against representatives and editors of the Russian "Newsweek" magazine over an article they published in Dec. 2009 entitled "The Evil (Cyber) Empire: Inside the world of Russian hackers." The article, which has since been amended, referred directly to Igor Gusev by name, calling him "one of the world's leading spammers".
  • On June 21st, Knujon posts a report [full report pdf] which directly names Demand Media and their domain registration unit eNom "as a major facilitator of Internet drug crime."
  • On June 28th, the FTC busted a massive online fraud ring which used spam messages, money mules and stolen credit card data to swindle cardholders out of an alleged $10 million USD over many years using "micro transactions" which were then funneled through several shell companies without the cardholders ever noticing. [FTC press release here, Wired Threat Level article here.]

July:

  • On July 8th, an anonymous person using the name "Obivan" posts a comment on a story by Brian Krebs regarding a hack on the Pirate Bay website. The comment announces that the Russia-based payment processing company "Chronopay" has been under a sustained online attack, and that a great deal of data has been lost. At about the same time, numerous anonymous bloggers begin posting several large-scale leaks of insider information regarding the payment processing company "Chronopay", totaling several gigabytes in size.

August:

  • Aug. 3rd: LegitScript, a website which reports on criminal or rogue online pharmacies, publishes a story exposing a hack performed on a US government website which was used to promote yet another Spamit website via "blackhat SEO" (a.k.a.: search engine spamming). [source] These kinds of exploits against the public's servers are not new, but a hack against a US government website by these same Russian criminals highlights how rampant this actviity has become.
  • On August 9th, one of the previously-mentioned Chronopay leak sources, operating under the name "Chronoplay", publishes a comment on porn forum "gfy.com" which reveals that long-time spammer Leo Kuvayev (operator of the original BadCow and later Mailien spam affiliate programs) has been arrested in Russia on 50 counts of juvenile rape. The arrest apparently took place earlier in 2010. Unfortunately the comment and any of Chronoplay's blogs are all offline as of this writing, but the arrest has been confirmed from several sources including Russian law enforcement. [Brian Krebs coverage here.]
  • Russian credit card thief Vladislav Anatolievich Horohorin (a.k.a.: "BadB") was arrested by French authorities on August 12th and charged with the illegal sale of thousands of stolen credit card numbers, known as "dumps".
    Horohorin, in an April 2009 advertisement of his services, said he had been selling "dumps" — compromised credit and debit card numbers — through websites such as the now-closed Cardplanet.com for about eight years.

    Horohorin is charged with access device fraud and aggravated identity theft. He faces a maximum penalty of 10 years in prison and a US$250,000 fine on the count of access device fraud and two years in prison and a fine of up to $250,000 for aggravated identity theft.

    [Dept. of Justice press release here.]
  • On August 25th, ICANN begins an investigation into the operations of domain registrar eNom. [source] This follows a report by HostExploit entitled Demand Media / eNom Report - CyberCrime USA which concludes that 51.5% of all domains that eNom approved were detected in spam traps, and that eNom was considered the #1 rogue domain registrar on the Internet. eNom had been the subject of numerous complaints for many months by security researchers and many members of the team at InBoxRevenge, and was also mentioned in the aforementioned scathing report in June by Knujon.
  • On August 26th, Andrew J. Klein, the White House Senior Adviser for Intellectual Property Enforcement, invited representatives of several domain registrars to attend a three-hour meeting in September to talk about cracking down on criminally-operated rogue online pharmacies. [Brian Krebs coverage here.] This appears to be related to Knujon's previous coverage of domain registrar eNom and their lack of action against several million domain names registered for the purpose of spamming numerous criminal pharmacy websites.

September:

  • On Sep. 21st, following many months of reporting of illicit domain registrations by registrar eNom (see above), LegitScript joins forces with eNom to assist them in identifying the individuals behind the plethora of rogue, fake or otherwise non-compliant domain registrations by predominantly Russian online pharmacy affiliate programs.
  • On Sept. 23rd, numerous media outlets report that Iran's delayed Bushehr nuclear power plant was infected by the Stuxnet virus as far back as June 2010. This story brings to the forefront a scenario which was previously the stuff of movies: that a piece of malware could be used for nefarious purposes to affect real-world infrastructure. Stuxnet is said at the time to be a very complex piece of malware and was likely programmed by several very senior developers and other operatives. This is considered a very serious international incident and finger-pointing ensues, largely blaming the Israeli government for the infection. [More coverage: Switched.com, Wired Threat Level]
  • In a completely unsurprising turn of events, the majority of domains for spammed criminal online pharmacies are now registered via Russian domain registrars.
  • October comes one day early in the arrests and convictions department: on Sep. 30th, 19 individuals of Eastern-European origin are arrested in London on fraud charges related to their long-term Zeus botnet activities.
    He and his team targeted hundreds of victims who had weak security on their computers and accessed their user names and passwords despite tight security systems put in place by the banks on their internet sites.

    Police were alerted by high street banks who were alarmed by a sudden surge in fraud.

    Investigators from Scotland Yard's e-Crime Unit discovered that the gang were hitting vulnerable computers using software which is described in the industry as a 'Trojan horse' because it infiltrates the computer without the user realising.

    London was only the first of many countries which made arrests related to this action. Most notably in the US, more than 60 people were arrested for engaging in identical behavior and operating Zeus botnets.

    This story received very wide coverage, and not only via tech or security news sites or blogs:


October:
Last year I mentioned that November is usually a very high-volume month for announcements of indictments, arrests, convictions and other legal actions against spammers and those who help them. I want to amend that this year to say that it's actually more like October through November. However 2010 was especially fruitful during the month of October. This was another landmark year for legal action against numerous criminal entities related not only to spamming (of any sort, not merely email spamming) but any kind of online criminality, from botnet operation, to the operation of any large-scale criminal pharmacy affiliate program, to money mules, to you name it. As you can see from the story mentioned above, we got a head start this year as well.

  • On Oct. 8th the US Food and Drug Administration (FDA) posts a warning letter specifically naming RX-Promo as an affiliate program which violates numerous FDA regulations and several US laws by selling illicit, fake versions of numerous pharmaceutical products. RX-Promo are a very active spamming affiliate program known to sell fake or dangerous pills online, promoted solely via spamming of one sort or another.
  • On Oct. 21st, James Bragg, a former assistant in Al Ralsky's pump-and-dump spamming operation, who had already served six months in prison for his part in that organized fraud, pleaded guilty to charges of securities fraud and fraud related to new pump-and-dump activity since that arrest. He faces five years in prison and a $500,000 fine. Once a fraudster, always a fraudster...
  • On Oct. 25th, it is reported in the Dutch news media that the High Tech Crime unit had shut down 143 servers which were part of the Bredolab botnet. One day later, F-Secure reported that any affected servers were now redirecting users to a help page describing how to remove the infection. Later on the 26th, it was announced that a 27-year-old Armenian citizen had been arrested in connection with the operation of Bredolab, among other crimes.
  • On Oct. 27th, the New York Times run a story which delves into the workings of Russian email pharmacy spam, specifically naming Spamit and its alleged operator Igor Gusev.
  • Oct. 29th, Igor Gusev makes a statement to the press that he is not a spammer, and has never spammed. This is in response to charges made by the Russian Association of Electronic Commerce [RAEC] and other Russian law enforcement agencies that Gusev has been the operator of the most widely-renowned pharmacy spam affiliate program, Spamit, since at least 2006. Gusev claims this is a smear campaign on behalf of Chronopay's director, Pavel Vrublevsky. Chronopay is Russia's largest online payment processing company. The same day it is reported that Russian police raided Gusev's properties in relation to these charges.
  • On Oct. 30th, Igor Gusev begins writing a blog entitled RedEye Blog (in Russian and English) in which he exposes the inner workings of Chronopay, his business relationship with Pavel Vrublevsky and other interesting items.

November:

  • On Nov. 1st, SiL posts his final update to the running tally of his Nigerian scam "winnings", having hit the $100 Billion USD mark several months ahead of schedule. At the time of that final update, SiL was averaging nearly $1 Billion USD of winnings or inheritances every day of the year. The sheer volume of Nigerian scam spam messages is at its highest point since SiL began tracking, often resulting in several hundreds of messages every day to just one of the accounts he monitors.
  • On Nov. 11th, as the Igor Gusev story continues to unfold, the RAEC hold a press conference in which they claimed they would expose Igor Gusev as "the largest spammer in the world". [Blog posting here, English translation here.] As previously mentioned, Gusev is alleged to be the operator of renowned criminal spamming affiliate program Spamit, and sister site Glavmed.
    Gusev, in this case is called a man who stands for the well-known pharmaceutical affiliate program "GlavMed". A year ago, RAEC, declaring war on pharmaceutical spammers, used as an example of this particular resource, associating it with a brand Canadian Pharmacy, which Spamhaus list, ranked by volume of the world's spam.
  • On Nov. 26th, The UK's Metropolitan Police Central eCrime Unit (PCeU) arrest two 18 year olds (Nicholas Webber and Ryan Thomas) for engaging in widespread credit card theft totalling some £12 million (~$18.6 million USD). [Gar Warner coverage here.] Sentencing, which is expected to be very severe, has been adjourned until Feb. 28th, 2011.
  • In what would become one of the most notorious international incidents, WikiLeaks begin leaking what they claim is a portion of over 200,000 classified US embassy cables in an event which would come to be known as CableGate. Over the following weeks and months, several news outlets report on the vast amount of information contained in the leaked documents, including the Guardian, the New York Times, Der Spiegel and Wired. As of this writing, the cables are still being released in what seems to be batches of just over 1,000 at a time. Weeks later, an international arrest warrant is released for Wikileaks director Julian Assange by Swedish police. [WikiPedia Link] The cables were apparently illegally downloaded by Private Bradley Manning, who allegedly downloaded them from the US's "SIPRNET" system, a network system which allows US embassies to communicate securely. [Cryptome timeline re: Adrian Lamo]

December:

  • On Dec. 5th, an FBI indictment against one Oleg Nikolaenko is leaked to the Smoking Gun. Nikolaenko is alleged to be the main operator of the once-rampant spamming botnet known as Mega-D, a fundamental botnet for the former AffKing affiliate group. The FBI arrested Nikolaenko on Dec. 3rd. [PDF available here.]
  • Dec. 13th, the Chinese government announces a new crackdown on piracy of any copyrighted property, from DVD's to MP3's to (presumably) fake Rolex watches. This is allegedly to smooth trade relations iwth the US who have been attempting to get China on board with this strategy for many years.
  • On Dec. 18th, it is announced that the US government is setting up an initiative that would attempt to shut down fake pharmacy websites. They will certainly have their work cut out for them. This is an addendum to an existing strategy to go after any site which violates patents or copyrights, which was started mid-2010.
  • On Dec. 14th, Bloomberg publishes a story confirming that, among many other major online companies, Google and Microsoft are creating a non-profit organization targeting illegal internet pharmacies, in support of the US government initiative.
    Google Inc. and Microsoft Corp. are helping to establish a nonprofit organization targeting illegal Internet pharmacies in support of Obama administration efforts, according to the White House Office of Management and Budget.

    The group is comprised of companies that serve as Internet choke points and was in response to a call from the administration for private efforts to police illegal pharmacies, said Victoria Espinel, the White House intellectual property enforcement coordinator.
  • On Dec. 16th, several news outlets report that the Stuxnet infection which hit Iran's Bushehr reactor in June was apparently better than a bomb in terms of affecting Iran's nuclear program, possibly setting it back by as much as two years:
    According to a top German computer consultan, the Stuxnet virus, which has attacked Iran's nuclear facilities and which Israel is suspected of creating, has set back the Islamic Republic's nuclear programme by two years.

    The consultant, who was one of the first experts to analyse the program's code and was only identified as "Langer", told The Jerusalem Post that it will take two years for Iran to get back on track.

    "This was nearly as effective as a military strike, but even better since there are no fatalities and no full-blown war. From a military perspective, this was a huge success."

    There have been claims that the virus is still infecting Iran's computer systems at its main uranium enrichment facility at Natanz and its reactor at Bushehr.
  • On Dec. 23rd an independent research blogger named Nart Villeneuve posts a detailed breakdown of how a site is created and configured for the widely-spammed RX-Promotion pharma affiliate program.
  • On Dec. 27th, the website for Chronopay displays a notice that their entire database had been compromised, and all credit card and other payment information, has been downloaded by criminal entities. The notice turns out to have been placed by hackers who have actually redirected the DNS for chronopay.com to the domain "anotherbeast.com". Links are placed to what they claim is a database of all the stolen credit card data, but which is in fact only the credit card information for 800 users, captured between Dec. 25th and 26th.

Phew! That is quite a year.

Here's hoping that online criminal activity remains a high-focus item for world governments and the mainstream media. This is a first for both of those entities paying any kind of attention to these issues and it's been extremely refreshing to see.

Happy New Year, everybody. Stay safe!

SiL / IKS / concerned citizen

Wednesday, September 22, 2010

Spamit.com: Closing down?

After a tip from a few different sources, I was informed that the Spamit.com domain is now showing the following message:

Уважаемые партнеры и коллеги,

В связи с длинной чередой негативных событий последнего года и обострившимся вниманием к деятельности нашей партнерской программы, мы приняли решение свернуть свою деятельность и прекратить прием трафика с 1 октября 2010 года.

Мы считаем, что в создавшейся ситуации такое решение является наиболее правильным, т.к. оно позволяет полностью избежать рисков внезапной, незапланированной остановки, которая обязательно повлекла бы за собой коллапс всей деятельности нашей программы и, скорее всего, привела бы к невыплате заработанных вами средств. В нашем же случае, все заработанные средства будут выплачены в обычном режиме. Кидков не будет.

Пожалуйста, используйте оставшееся время для своевременного перевода трафика на другие партнерские программы.

Спасибо что работали с нами, мы очень ценим ваше доверие!


Dear partners and colleagues!

Because of the numerous negative events happened last year and the risen attention to our affiliate program we’ve decided to stop accepting the traffic from 1.10.2010. We find the decision the most appropriate in this situation. It provides avoiding the sudden work stop which leads to the program collapse and not paying your profit.

In our case the whole profit will be paid normally. All possible frauds are excluded. Please transfer your traffic to other affiliate programs till 1.10.2010.

Thank you for your cooperation! We appreciate your trust very much!
login

Here's a screenshot of Spamit.com from around an hour ago:


This was the output on Spamit.biz and Spamit.com. Now I and many others notice that spamit.com no longer resolves as a domain. Spamit.ru is also down but I don't know if that had been the case prior to today.

Note that no such notice appears anywhere on Glavmed.com (long alleged to be their sister company.)

The #1 criminally-operated spam operation in the world is suddenly shutting down? (Albeit, possibly temporarily. I'll check back on Oct. 1st of course.)

The "numerous negative events" possibly refers to the loss of Mastercard processing which happened several months ago, and "the risen attention to our affiliate program" possibly means coverage from this blog but also several other media outlets, most notably a large amount of coverage in the Russian press.

If Spamit as an affiliate operation were in any way operating legally or legitimately, this media coverage would not be a cause to shut down. This only goes to show you what a scumbag, criminal operation Spamit and Glavmed have always been.

The fact that spamit domains specifically are shutting down the same day a few sources told me to check this page out indicates some Very Bad Things could be underway for the operators of Spamit.

This could be a very interesting few weeks.

SiL

Sunday, July 25, 2010

Blog-Spamming an Anti-Spam Blog = Utter Genius

To all you moron spammers out there who keep submitting spammy comments to this blog:

Are you high?

You keep saying I need a life. Look at yourselves.

SiL