Показаны сообщения с ярлыком Sergey Medvedev. Показать все сообщения
Показаны сообщения с ярлыком Sergey Medvedev. Показать все сообщения

воскресенье, 12 июня 2022 г.

“100 thousand BTC or $6 billion were found on his wallet”

How The Infraud Organization was organized and who is its "roof"




In light of the development of the story about the hacker group The Infraud Organization, a source of the telegram channel of the Cheka-OGPU and Rucriminal.info, who is a relative of one of the direct participants in the criminal organization, shared interesting details about the scale of their activities in Russia.

In January of this year, we published information about a special operation carried out by the FSB against members of Infraud. At the same time, under articles 272 (Illegal access to computer information) and 187 (Illegal circulation of means of payment) of the Criminal Code of the Russian Federation, criminal cases were initiated against the persons who led the group: Andrey Novak, Estonian citizen Kirill Samokutyaev, Mark Bergman and Konstantin Bergman, who are still in custody. under investigation.

In order to understand what exactly is happening now in this case, let's go back a little to the history of this organization. As we wrote earlier, The Infraud Organization, founded by Ukrainian hacker Svyatoslav Bondarenko, has been successfully operating since at least 2010. The turnover of the organization was estimated at billions of US dollars. However, the internal life of the group was accompanied by regular showdowns, banal theft from themselves and the redistribution of power throughout their existence.

So, in 2015, after a financial dispute with one of the members of the group, Bondarenko suddenly “disappears” under mysterious circumstances. His place is taken by Sergey Medvedev, who himself was arrested in Bangkok in 2018 at the request of the US FBI, and in March 2021 was sentenced to 10 years in prison. By the way, we recall that at the time of detention, 100 thousand BTC or $6 billion at the current rate were found on his wallet, but after a short time they disappeared without a trace (where they are is still unknown).

After the elimination of Medvedev, the company of Novak, Samokutyaev and Bergmanov comes to the fore (as Rucriminal.info learned from a source, Mark and Konstantin Bergman are not actually relatives - before the change of surnames they were Rizaev and Sinichkin). All this time they worked on the territory of the Russian Federation and managed to build a very strong and extensive internal structure under them. The unconditional leadership in the group was defended by Mark Bergman, who, to ensure internal and external security, attracted existing special employees. services, taking them as a share (we will return to their positions and names a little later).

In the period from 2019 to 2022, having acquired influential patrons who guaranteed complete impunity, the activities of the organizing group for pumping crypto assets into the real world acquired an industrial scale. The structure of the organization became more complex and began to represent not a group of 4 amateur programmers, as law enforcement agencies believed, but a whole criminal community operating not only on the Internet, but also in the real world.

More than 4 structural divisions appeared in the organization (the security service from the current employees of the special services of the regional and federal levels, the cybercrime division, the division for legalization, fraud and raider seizures, theft of bank card data and other payment systems, as well as cashing out), run by Mark Bergman.

We already wrote earlier that when the group members were under surveillance in Moscow, the first thing that caught my eye was how openly the suspects behaved without observing even the minimum security measures. It was obvious that they had acted for a long time and arrived in full confidence that in the Russian Federation they were not in danger of being prosecuted.

The thing is that the current criminal activity in exchange for monthly payments and periodic bribes for high-ranking officials was covered by the all-powerful intelligence officers, providing complete external security. The same persons monitored the internal security of the organization, instantly sending the Infraud members themselves (who could shake the group’s activities in the event of internal financial disputes) to places not so remote, while guaranteeing that information about the criminal community from former accomplices would not be disclosed and would not entail landing of gang leaders.

One of the clearest examples of such a well-established scheme for eliminating elements dangerous to beneficiaries is a direct relative of Mark Bergman, who has long been a member of TIO and a partner of these individuals, but is currently serving a sentence, like a number of other members of the gang (we will also return to this topic separately) . Such a reliable cover, combined with high technological protection, guaranteed complete impunity for the activities of The Infraud Organization in the Russian Federation.

None of the organizers expected that after the emergence of direct agreements between the Presidents of Russia and the United States on cooperation in the field of combating cybercrime, events would develop according to the scenario already known to all: the leadership of the FSB receives from American materials, on the basis of which cases are immediately initiated against the members of the hacker group and the entire criminal scheme begins to crumble.

How and who exactly is now trying to break up the criminal case against hackers in order to save their source of income (and we are talking here, we recall, about billions of US dollars) will be described further.

Timofey Grishin

To be continued

Source: www.rucriminal.info

суббота, 22 января 2022 г.

FSB conducted a secret operation against The Infraud Organization

The hacker organized crime group, called by the FBI "the largest group known in the United States," was defeated




As it became known to the telegram channel of the Cheka-OGPU and Rucriminal.info, the FSB of the Russian Federation, without publicity, conducted a new large-scale operation against an international group of hackers. This time, counterintelligence took for members of The Infraud Organization, which the FBI had hunted for many years, calling it "the largest fraudulent group ever investigated in the United States." The damage from the grouping is estimated by the United States at $586 million. The Investigative Department of the Ministry of Internal Affairs of the Russian Federation initiated a case under Articles 272 (Illegal access to computer information) and 187 (Illegal circulation of means of payment) of the Criminal Code of the Russian Federation. Investigators filed petitions with the court for the arrest of a whole group of people, which were granted on Friday evening. Among those arrested is one of the founders of The Infraud Organization Andrey Novak (Unicc, aka Faaxxx). A decision was also made to detain Kirill Samokutyaev, a member of The Infraud, an Estonian citizen. He was already tried in Russia in 2018. Then he was detained in Shcheremetyevo while trying to illegally smuggle 56,000 euros across the border. Then he was sentenced to a fine. Also, a decision was made to arrest the founders of the Dutch company BERGMAN MEYER CAPITAL GROUP B.V. and owners of a number of Russian firms, Mark Bergman and Konstantin Bergman.




 

The Infraud platform, which provides services for fraudulent Internet crimes, was created in 2010 by Ukrainian Svyatoslav Bondarenko, who worked under the nicknames Obnon, Rector and Helkern. Infraud members and partners have worked throughout the world and in the US. The group planned to steal about $2.2 billion from private individuals, merchants and financial institutions, the actual damage exceeded $568 million.

Members of the organization have sold and purchased over 4 million hacked credit card numbers.

Infraud called itself the "Ministry of Fraud" and adopted "In Fraud We Trust" as its motto, parodying the official US slogan "In God We Trust" printed on every dollar bill.

The group was an Internet criminal enterprise that bought, sold and distributed stolen personal data, hacked debit and credit cards, personal information, financial and banking information, malware and other illegal goods on a large scale.

The organization included criminals from all over the world who acted through the forum. The participants performed the usual functions of “moderators” for online communities, but in many ways the structure of Infraud resembled traditional organized criminal groups.

“The members of Infraud had specific roles in the hierarchy. “Administrators” oversaw day-to-day activities and strategic planning, approved and supervised user registrations, assigned rewards and punishments to members of the group,” the US Department of Justice said in a 2018 statement when the group first came to light.

"The 'super moderators' managed specific sections, and the 'moderators' monitored one or two sub-forums within their area of​​responsibility."

Despite positions like "administrator" or "moderator", the structure of the organization is very similar to the Cosa Nostra families and other organized crime groups in the United States, where there are bosses, their henchmen and "foremen".

The internal life of the "Ministry of Fraudulent Affairs", however, was not cloudless and was accompanied by "showdowns" and the redistribution of power. So, on March 26, 2015, hacker John Telasma announced via the internal mail of a criminal group that Svyatoslav Bondarenko banned one of the members because he “ripped him off on a deal”. Who was this defendant removed from cases, is not named in the documents of the prosecutor's office. However, less than a month later, on April 16, 2015, Sergey Medvedev announced that Mr. Bondarenko had “disappeared” and now he himself is the “administrator and owner” of Infraud.

In 2018, Russian hacker Sergei Medvedev was arrested in Bangkok at the request of the US FBI. During a search of the residence, documents and a computer were seized, and 100,000 bitcoins were found in his accounts.

The US Attorney's Office issued a 50-page indictment against 36 Infraud defendants. The text of the nine-point accusation is at the disposal of Rucriminal.info. The suspects are charged with a series of crimes - from identity theft and conspiracy to involve in a criminal group to organized racketeering.

“We are proud to provide the best dumps service on the market!” - read an advertisement on the Infraud platform, posted in May 2014, it offered the data of 124,000 bank cards of US users. The stolen credit card data was presented as "high quality, fresh, 90% valid."

The geography of the crime covers a dozen countries, there are Slavic names in the list of the accused: in addition to the Russian Sergey Medvedev and the Ukrainian Svyatoslav Bondarenko, this is Alexei Klimenko Grfandhost, an unknown figurant under the nickname Malov, which may be his last name, and unlike everyone else, named by name - patronymic Andrey Sergeevich Novak. He owns also the Unicc.ru platform.

Sergei Medvedev, also known as Stells, segmed and serjbear, has been extradited to the US. In a Nevada County trial, he pleaded guilty to one count of racketeering conspiracy in March 2021 and was sentenced to 10 years in prison.

Recall that on January 14, 2022, the FSB announced the final defeat of the REvil hacker group.

As the Cheka-OGPU said, the FSB of the Russian Federation began to carry out active operational measures against members of the REvil hacker group in August 2021. And in September, the Investigative Department (SD) of the Ministry of Internal Affairs of the Russian Federation filed petitions with the court to seize items and documents containing state or other secrets protected by federal law, as well as to seize information about deposits and bank accounts of persons who were participants in REvil. In January 2022, as part of a case already initiated by the SD, the FSB carried out detentions. Active work, including investigative work, began shortly after Joe Biden, during a telephone conversation with Vladimir Putin in July 2021, called on Russia to take measures to stop the activities of hackers operating on its territory, “and emphasized that he was determined to continue combat the broader threat posed by ransomware.”

The Kremlin then reported that Putin had declared Russia's readiness "to jointly suppress criminal manifestations in the information space," but in the last month there were no such appeals from US departments.

The conversation was about REvil.

In 2021, there were several major cyber attacks against US businesses and companies that brought them to a halt. One of the loudest is the attack on the Colonial Pipeline, the largest pipeline network on the US East Coast for the supply of gasoline, diesel fuel and other petroleum products. The pumping of oil products was stopped for several days. In June 2021, all the factories of the largest meat producer JBS S.A. got up in the United States due to a cyber attack. As a result, the management of Colonial Pipeline paid the cybercriminals a ransom of 75 bitcoins ($4.5 million at the time of the transaction).

And so the July conversation between the two presidents led to the fact that in Moscow, St. Petersburg, Moscow, Leningrad and Lipetsk regions, an operation was carried out, first against the participants of REvil, and now against the participants of The Infraud Organization.







Timofey Grishin

To be continued