Jason Michael Milmont, of Cheyenne, Wyoming, may be only 19 years old, but he's already a very successful cybercriminal. In this Los Angeles FBI Press Release, Milmont confessed to controlling between 5,000 and 15,000 remote victims' computers, which he infected through modified versions of Limewire, and through Instant Message spam messages which lead users to infected websites. Links he placed on MySpace and PhotoBucket were also used to spread his malware.
In January, sources such as ComputerWorld were calling Nugache a challenger to the Storm Worm for its virility, and implied that hackers "tied to the Russian Business Network" may be responible for an upgraded version. Nugache was one of the first botnets to be controlled via a Peer to Peer or distributed interface. Lacking a central Command & Control made it more difficult to identify the real controller of the network.
Milmont confessed to being the programmer -- so, it was a 19 year old in Wyoming, rather than a Russian boogie man in this case. Using a graphical user interface Milmont created, he could easily harvest the stolen credentials which the Nugache worm was gathering from his victims as they logged in to their banking and credit card sites. Infected machines could be remotely upgraded to receive new versions of the malware. The third version added the key-logging software to the malware kit.
Although Milmont harvested many credentials, he is only being asked to pay $73,866.36 in restitution, for purchases made using the stolen credit cards. Milmont shipped packages to vacant addresses where he then picked the packages up himself.
Jason studied computers at Laramie County Community College in Cheyenne. One of his instructors there, Roger Findley, described him as extremely intelligent but socially awkward.
By pleading guilty, Milmont will only be charged with a single count of a violation of 1030 (a)(4), accessing a computer without authorization with intention to defraud and obtain a thing of value. The maximum sentence to that plea would be 5 years and a $250,000 fine.
View the 22 page plea agreement here.
Links:
http://www.theregister.co.uk/2008/06/28/nugache_creator_plea_agreement/
Monday, 30 June 2008
Saturday, 14 June 2008
Chinese Hackers hit Congress?
The early news from US Representative Frank Wolf (R-VA) came out on June 11th, when Wolf submitted House Resolution 1263, calling for the Sergeant at Arms of the House of Representatives to "ensure that all Members, committees, and offices of the House are alerted to the dangers of electronic attacks on the computers and information systems used in carrying out their official duties and are fully briefed on how to protect themselves, their official records, and their communications from electronic security breaches". This is what the news story should have been -- that Representative Wolf calls for tighter security. A news-worthy and noble action, which is long overdue and would receive wide support from the Security Community.
The single line from his Resolution which has captured all of the attention came from this "Whereas" . . .
More than 1100 news stories on Google mention the story, with some of the international mud-slinging using headlines like "US Accuses Chinese of Hacking Government Computers" which gained replies of "China says it's incapable of hacking Reps' computers".
Wolf didn't use such headlines -- the news story on his own website is headlined with Wolf Reveals House Computers Compromised by Outside Source. His office works with human rights activists and political dissidents around the world, and his emails and correspondence with some of these individuals was apparently compromised. He does say "My suspicion is that I was targeted by Chinese sources because of my long history of speaking out about China's abysmal human rights record." He also says that the Foreign Affairs Committee computers and that of other members who work "to help people who are suffering around the world" were similarly targeted.
That record is perhaps put most plainly in this impassioned speech by Representative Wolf from July 2007 -- Made in China, accuses China of poisoning toothpaste and toys, dumping products at below the cost of production on the international markets, arresting hundreds for religious beliefs and interring them in "slave labor camps", and compares their bid for the Olympics to that of the Nazis.
Wolf's words of warning on the Hill quote from several other sources as he issued his call for arms -- including a Congressional Research Service report indicating that 140 different foreign intelligence organizations regularly attempt to hack into the computer systems of US government agencies and US companies.
Joel Brenner, National Counterintelligence Executive of the Officer of the Director of National Intelligence used that figure in his speech here, and told CNN in October, it isn't just China, "there are about 140 foreign intelligence organizations trying to hack into the US government and US companies".
(Brenner also discussed the threat by the Chinese in this speech before the American Bar Association, where he says "From a purely fiscal point of view, it also means
the Chinese are leveraging the American R&D budget — your tax dollars and mine — in support of their own war-fighting capability.")
Wolf also made reference to the April 10, 2008 BusinessWeek story: The New E-Espionage Threat, which is a must read for anyone dealing with these threats both in corporate America and the government.
His reference to Shane Harris' alarming cover story of the National Journal magazine, China's Cyber Militia brings up other issues though. Is this fact? or fiction? I've had a copy of the "Northeast Blackout Report" on my hard drive for years, and am very familiar with the incident from both open and classified conversations. This is the first time that I've seen the blackout blamed on the People's Liberation Army, and frankly, I'm skeptical. Harris says:
Rising to speak after Mr. Wolf, in support of his resolution, was US Representative Chris Smith (R-NJ), who used the opportunity to smear Google and Cisco, and call for support for his "Global Online Freedom" bill:
Like Wolf, Smith has reason to believe the attacks are sponsored by Beijing. He says:
My conclusion is that it is clear that China is developing Cyber espionage capabilities, and it is clear that there are many attacks using Chinese IP addresses, but I have not yet seen any hard evidence that Wolf's computer was definitely attacked by "the Chinese". Even Mr. Smith's accusation indicates that the HIR staff told him "it came through or from a Chinese IP address".
That's why I refused to jump on the Evil China Bandwagon when I was interviewed by IDG News's Robert McMillan for the story he called: Weak Evidence Links Congressmen's Cyber Attacks to China. The truth is that there are many active criminal enterprises hosting "bullet proof servers" in China, which are used by a wide range of cyber criminals for all sorts of attacks. It would simplify things if we could return to a Reaganesque view of the world where all evil comes from a single location, but it takes more evidence than I have seen so far to jump on this particular bandwagon. Certainly there is a great deal of state-sponsored hacking from China, but until the details of each particular investigation are known, we can't make statements with the degree of certainty that Congressman Smith would like.
The single line from his Resolution which has captured all of the attention came from this "Whereas" . . .
Whereas in subsequent meetings with HIR [The House Information Resources office] and officials from the Federal Bureau of Investigation, the outside source responsible for these incides was revealed to be located in the People's Republic of China;
More than 1100 news stories on Google mention the story, with some of the international mud-slinging using headlines like "US Accuses Chinese of Hacking Government Computers" which gained replies of "China says it's incapable of hacking Reps' computers".
Wolf didn't use such headlines -- the news story on his own website is headlined with Wolf Reveals House Computers Compromised by Outside Source. His office works with human rights activists and political dissidents around the world, and his emails and correspondence with some of these individuals was apparently compromised. He does say "My suspicion is that I was targeted by Chinese sources because of my long history of speaking out about China's abysmal human rights record." He also says that the Foreign Affairs Committee computers and that of other members who work "to help people who are suffering around the world" were similarly targeted.
That record is perhaps put most plainly in this impassioned speech by Representative Wolf from July 2007 -- Made in China, accuses China of poisoning toothpaste and toys, dumping products at below the cost of production on the international markets, arresting hundreds for religious beliefs and interring them in "slave labor camps", and compares their bid for the Olympics to that of the Nazis.
Wolf's words of warning on the Hill quote from several other sources as he issued his call for arms -- including a Congressional Research Service report indicating that 140 different foreign intelligence organizations regularly attempt to hack into the computer systems of US government agencies and US companies.
Joel Brenner, National Counterintelligence Executive of the Officer of the Director of National Intelligence used that figure in his speech here, and told CNN in October, it isn't just China, "there are about 140 foreign intelligence organizations trying to hack into the US government and US companies".
(Brenner also discussed the threat by the Chinese in this speech before the American Bar Association, where he says "From a purely fiscal point of view, it also means
the Chinese are leveraging the American R&D budget — your tax dollars and mine — in support of their own war-fighting capability.")
Wolf also made reference to the April 10, 2008 BusinessWeek story: The New E-Espionage Threat, which is a must read for anyone dealing with these threats both in corporate America and the government.
His reference to Shane Harris' alarming cover story of the National Journal magazine, China's Cyber Militia brings up other issues though. Is this fact? or fiction? I've had a copy of the "Northeast Blackout Report" on my hard drive for years, and am very familiar with the incident from both open and classified conversations. This is the first time that I've seen the blackout blamed on the People's Liberation Army, and frankly, I'm skeptical. Harris says:
One prominent expert told National Journal he believes that China’s People’s Liberation Army played a role in the power outages. Tim Bennett, the former president of the Cyber Security Industry Alliance, a leading trade group, said that U.S. intelligence officials have told him that the PLA in 2003 gained access to a network that controlled electric power systems serving the northeastern United States. The intelligence officials said that forensic analysis had confirmed the source, Bennett said. “They said that, with confidence, it had been traced back to the PLA.” These officials believe that the intrusion may have precipitated the largest blackout in North American history, which occurred in August of that year. A 9,300-square-mile area, touching Michigan, Ohio, New York, and parts of Canada, lost power; an estimated 50 million people were affected.
Rising to speak after Mr. Wolf, in support of his resolution, was US Representative Chris Smith (R-NJ), who used the opportunity to smear Google and Cisco, and call for support for his "Global Online Freedom" bill:
Google, for its part, has become the de facto center for China's ubiquitous anti-American, anti-Tibetan, anti-religious propaganda machine, while Cisco has made the dreaded Chinese secret police among the most effective in the world.
Like Wolf, Smith has reason to believe the attacks are sponsored by Beijing. He says:
The attackers hacked into files related to China. These contained legislative proposals directly related to Beijing, including the Global Online Freedom Act, e-mails with human rights groups regarding strategy, information on hearings on China--I chaired more than 25 hearings on human rights abuses in China--and the names of Chinese dissidents. While this absolutely doesn't prove that Beijing was behind the attack, it raises very serious concern that it was.
My conclusion is that it is clear that China is developing Cyber espionage capabilities, and it is clear that there are many attacks using Chinese IP addresses, but I have not yet seen any hard evidence that Wolf's computer was definitely attacked by "the Chinese". Even Mr. Smith's accusation indicates that the HIR staff told him "it came through or from a Chinese IP address".
That's why I refused to jump on the Evil China Bandwagon when I was interviewed by IDG News's Robert McMillan for the story he called: Weak Evidence Links Congressmen's Cyber Attacks to China. The truth is that there are many active criminal enterprises hosting "bullet proof servers" in China, which are used by a wide range of cyber criminals for all sorts of attacks. It would simplify things if we could return to a Reaganesque view of the world where all evil comes from a single location, but it takes more evidence than I have seen so far to jump on this particular bandwagon. Certainly there is a great deal of state-sponsored hacking from China, but until the details of each particular investigation are known, we can't make statements with the degree of certainty that Congressman Smith would like.
Friday, 6 June 2008
A Romantic June Storm
On June 2nd, starting at 5:53 PM, the UAB Spam Data Mine started receiving spam messages for the new version of the storm worm. The messages lead to a website titled "Who is loving you?" The "Love Riddles" web page invites you to "Just click here" to find out.

Its been four days since the new round of storm started up. How is the detection rate?
According to VirusTotal, only 6 of 32 AV engines are currently detecting this version of Storm:

What should you be looking for?
So far we've seen these email subjects:
I belong to you
I Wanna Be With You
Just you and me
Missing you
Missing you with every breath
My heart beats just for you
My heart was stolen
Nothing's Gonna Change My Love For You
Stand by my side
Together forever
We belong together
You are my world
You are the ONE
You make my world beautiful
You make my world special
Which contained a single phrase of text, followed by an IP address. Here are the Text lines in the body of the message:
Always on my mind
Can't stay away from you
Crazy in love with you
Dreaming 'bout you
Here in my heart
I want to be with you
I'll Still Love You More
In your arms
Just you and me
Lonely without you
Lost In Your Eyes
Lucky to have you
Missing you
Not the same without you
Somebody loves you
Stand by my side
Together forever
Wanna kiss you
We belong together
You are always on my mind
You are my world
You feel up my senses
You have touched my heart
You make my world special
And here are a list of some of the IP addresses we've seen advertised in the messages:
24.232.184.4
59.54.57.99
60.43.108.150
61.93.161.182
62.117.121.10
67.149.110.236 (*)
68.74.124.34
69.137.21.212 (*)
77.87.88.101
78.185.150.204
83.4.43.26
85.121.85.185
86.126.123.109
86.126.169.39
116.111.209.201
116.72.162.240
121.152.86.118
123.201.37.59
124.107.138.98
151.49.127.7
190.172.212.240
190.18.188.183
190.53.11.211
190.55.159.93
200.115.109.46
200.125.111.190
200.74.9.216
200.8.248.229
201.209.64.220
201.250.43.228
203.223.246.131 (*)
222.105.121.8
At this time, only 3 of these IPs, marked with an (*) actually delivered the malware.
Its been four days since the new round of storm started up. How is the detection rate?
According to VirusTotal, only 6 of 32 AV engines are currently detecting this version of Storm:
What should you be looking for?
So far we've seen these email subjects:
I belong to you
I Wanna Be With You
Just you and me
Missing you
Missing you with every breath
My heart beats just for you
My heart was stolen
Nothing's Gonna Change My Love For You
Stand by my side
Together forever
We belong together
You are my world
You are the ONE
You make my world beautiful
You make my world special
Which contained a single phrase of text, followed by an IP address. Here are the Text lines in the body of the message:
Always on my mind
Can't stay away from you
Crazy in love with you
Dreaming 'bout you
Here in my heart
I want to be with you
I'll Still Love You More
In your arms
Just you and me
Lonely without you
Lost In Your Eyes
Lucky to have you
Missing you
Not the same without you
Somebody loves you
Stand by my side
Together forever
Wanna kiss you
We belong together
You are always on my mind
You are my world
You feel up my senses
You have touched my heart
You make my world special
And here are a list of some of the IP addresses we've seen advertised in the messages:
24.232.184.4
59.54.57.99
60.43.108.150
61.93.161.182
62.117.121.10
67.149.110.236 (*)
68.74.124.34
69.137.21.212 (*)
77.87.88.101
78.185.150.204
83.4.43.26
85.121.85.185
86.126.123.109
86.126.169.39
116.111.209.201
116.72.162.240
121.152.86.118
123.201.37.59
124.107.138.98
151.49.127.7
190.172.212.240
190.18.188.183
190.53.11.211
190.55.159.93
200.115.109.46
200.125.111.190
200.74.9.216
200.8.248.229
201.209.64.220
201.250.43.228
203.223.246.131 (*)
222.105.121.8
At this time, only 3 of these IPs, marked with an (*) actually delivered the malware.
Monday, 19 May 2008
38 Indicted in Los Angeles and Connecticut Phishing Cases
On April 23rd, Attorney General Michael B. Mukasey gave a speech in Washington DC where he revealed his new stance on International Organized Crime. He said in the speech that in the days of Robert Kennedy it was said mobsters would be "prosecuted for spitting on the sidewalk", and promised that he had 120 prosecutors and 500 FBI agents today who were going to be just as tough. He released a strategy document called Overview of the Law Enforcement Strategy to Combat International Organized Crime. In this document, he stresses that they are going to "Marshal Information and Intelligence" to "Prioritize and Target the Most Significant IOC Threats", and "Attack From All Angles". today's phishing indictments have turned out to be. To make it clear that this includes cybercrime, Threat #5 and the accompanying example from that document are given here:
I've just reviewed the 77-page indictment unsealed today, and its clear the Attorney General is making good on his promise. To make sure the Romanians didn't miss it, Deputy Attorney General Mark Filip was in Bucharest Romania to do the press release alongside his Romanian counterparts. Here is a copy of the press release in Romanian.

At his Press Conference in Bucharest the DAG said:
Some of the schemes were quite interesting. In a "Smishing" scam described in the indictment, an SMS Text Message would be received that says "We're confirming that you've signed up for our service. You will be charged $2 per day unless you cancel your order on this URL: www.trustme.com -- this would result in malware being planted on the visitor's browser.
Chat logs were included in the indictment, such as Panait sending a message to Tran, telling him "bro this are from my spam . . . super fresh . . . I will spam more . . . spammed like hell . . . used 7 remote desktops and 13 smtp servers, 5 root, and sent over 1.3 million emails."
Logs from August 2006 all the way up to January 2008 were included, that make it clear the roles of each of the defendants. Discussions and logs include counterfeit cards made for:
Allegheny Federal Credit Union, American National Bank of Texas, Arizona Federal Credit Union, Artesian City Federal Credit Union, Bank of America, BB&T (Banker's Bank & Trust), Boeing Employee's Credit Union, Bowdoinham Federal Credit Union, Capital One Bank, Citibank, Credit Union One, Downey Savings & Loan, epassporte, E-Trade, First Merit Bank, Flagstar Bank, Franklin Mint Federal Credit Union, Iowa League Corporate Central Credit Union, Jeffco Schools Credit Union, Langley Federal Credit Union, Mountain America Credit Union, NASA Federal Credit Union, North Island Credit Union, PointBank, Premier Credit Union, Premier Credit Union, Southern Lakes Credit Union, Southwest Federal Credit Union, Teacher's Credit Union, Telco Credit Union & Affiliates, Valley National Bank, Washington State Employees Credit Union, and the Waterbury Teachers' Federal Credit Union.
Caroline Tath and Tran were making their cash cards with laptop computers, Tath had a Dell Inspiron and an HP laptop, Gigatech flash drives, an MSR-206 encoder, an Operah card reader, and a software system called "CC2Bank 1.3", which was used to make the cards. Tran used a Sony Vaio laptop, and also provided software to defendant Lee, including a program called "TheJermMSR206". Lee used a Sony Vaio laptop and an MSR505C encoder.
Some of the defendants used their counterfeit cards to buy goods at WalMart and CostCo. Others purchased stock on E-Trade accounts, or used E-Trade accounts to purchase Postal Money Orders. Many cards were used to withdraw cash from ATM's in Los Angeles and Orange County. Some of those funds were transferred via Western Union or MoneyGram to Romania, where the data to make the cards had been received from on a "50/50" cashier's deal.
At least one defendant also shipped "refurbished notebook computers" to co-defendants in Romania.
Some of the ATM withdrawals were made using hotel room keys with the PINs written on the back in sharpie.
Romanians (indicted in Los Angeles):
Ovidiu-Ionut Nicola-Roman
Petru Bogdan Belbita
Stefan Sorin Ilinca, AKA AzZ, AKA Kahn, AKA Kahnpath
Sorin Alin Panait, AKA scumpic4u
Costel Bulugea, AKA The.Vortex
Nicolae Dragos Draghici, AKA Marius Bogdan, AKA Nonick
Florin Georgel Spiru, AKA niggaplease
Marian Daniel Ciulean, AKA spuickeru
Irinel Nicusor Stancu, AKA sicaalex
Didi Gabriel Constantin, AKA StauLaSoare, AKA Estaulasoare, AKA snoop
Mihai Draghici
Marius Sorin Tomescu, AKA Andrei
Lucian Zamfirache, AKA Krobelus
Laurentiu Cristian Busca, AKA italianu
Dan Ionescu, AKA m1nja
Marius (Last Name Unknown), AKA 13081981
Alex Gabriel Paralescu, AKA paraiul
Andreea Nicoleta Stancuta, AKA godfather
Romanians indicted in Connecticut:
(See FBI New Haven's Press Release )
residents of Craiova:
Ciprian Dumitru Tudor
Ovidiu-Ionut Nicola-Roman
Mihai Cristian Dumitru
Petru Bogdan Belbita, AKA "CA is SK", AKA Robert Wilson
residents of Galati
Radu Mihai Dobrica
Cornel Ionut Tonita
Cristian Navodaru
Perhaps more interesting would be the international partners who were also indicted, including:
Hiep Thanh Tran, AKA John Tran, AKA Sam Lam -- a US resident from Vietnam
Hassan Parvez, AKA XID - from Pakistan
US Citizens:
Sonny Duc Vo, Alex Chung Luong, and
Leonard Gonzales, AKA Bonecrusher
Vietnam Citizens:
Nga Ngo, AKA Christina Ngo
Thai Hoang Nguyen, Loi Tan Dang, Dung Phan - Vietnam
Cambodian Citizen:
Caroline Tath
Rolando Soriano, AKA Loco, AKA Danny Villalopez - from Mexico
Four other hackers remain at large, known only by their aliases:
Cryptmaster, PaulXSS, euro_pin_atm, and SeleQtor
We can look forward to the next big bust, because there seems no indication these fools are slowing down. When we visit some of the chat rooms where "kahnpath", for example, used to advertise his wares, we are immediately greeted with ads for people looking for "Cashout partners", and trying to sell an MSR-206 card writer for $400.
THREAT 5: International organized criminals use cyberspace to target U.S. victims and infrastructure. International organized criminals use an endless variety of cyberspace schemes to steal hundreds of millions of dollars at a cost to consumers and the U.S. economy. These schemes also jeopardize the security of personal information, the stability of business and government infrastructures, and the security and solvency of financial investment markets.
One example of the intersection between organized crime and cybercrime is found in Romania. There, traditional Romanian organized crime figures, previously arrested for crimes such as extortion, drug trafficking and human smuggling, are collaborating with other criminals to bring segments of the young hacker community under their control. They organize these new recruits into cells based on their cyber-crime specialty and they routinely target U.S. businesses and citizens in a variety of fraud schemes.
One of the most lucrative schemes involves online auction fraud, where U.S. citizens are tricked into buying or selling goods, and never receive the funds or merchandise. One particular online criminal, using the online nickname “Vladuz” engaged in multiple fraud schemes, including hacking into the computers of eBay, the largest online auction retailer. On April 17, 2008, Vlad Duiculescu, a/k/a “Vladuz” was arrested in Romania by Romanian police officials and charged with crimes related to these schemes. It is believed that Vladuz is a participant in a ring of Romanian hackers who work together to develop joint U.S. targets for online frauds, share hacking techniques and launder proceeds from multiple crimes committed in the United States. U.S. prosecutors and law enforcement agents worked in Romania with Romanian officials to ensure that a case could be successfully prosecuted in Romania.
I've just reviewed the 77-page indictment unsealed today, and its clear the Attorney General is making good on his promise. To make sure the Romanians didn't miss it, Deputy Attorney General Mark Filip was in Bucharest Romania to do the press release alongside his Romanian counterparts. Here is a copy of the press release in Romanian.
At his Press Conference in Bucharest the DAG said:
The anonymity of the Internet makes it an ideal tool for this kind of fraud, and law enforcement agencies in the United States have conducted several recent investigations in partnership with our Romanian colleagues. We are proud to do so, and we are learning from each other as we jointly help to protect our citizens and people in other countries from this sort of theft and crime.
For the people arrested today, the indictments charge that the defendants sent out mass quantities of e-mails, known as "spam," to lure victims to go to fraudulent Websites that appeared to be legitimate banking or financial businesses. At those sites, victims were tricked into entering personal information such as financial and identity information and personal passwords—a scheme known as "phishing." That information was then harvested by “suppliers” who, in turn, sent the information to “cashiers” via real-time Internet chat sessions.
The cashiers used hardware encoders and related software to record the fraudulently obtained information onto the magnetic strips on the back of credit and debit cards. They then directed “runners” to withdraw money from automated teller machines. A portion of the withdrawals was wired by money transfer services, such as Western Union, back to the supplier. We believe these criminals defrauded literally thousands of individual victims out of several million dollars.
These arrests and charges are the result of a joint operation by the FBI and the Romanian General Inspectorate of Police, and the cases demonstrate the close cooperation our two countries have developed to fight international organized crime.
Some of the schemes were quite interesting. In a "Smishing" scam described in the indictment, an SMS Text Message would be received that says "We're confirming that you've signed up for our service. You will be charged $2 per day unless you cancel your order on this URL: www.trustme.com -- this would result in malware being planted on the visitor's browser.
Chat logs were included in the indictment, such as Panait sending a message to Tran, telling him "bro this are from my spam . . . super fresh . . . I will spam more . . . spammed like hell . . . used 7 remote desktops and 13 smtp servers, 5 root, and sent over 1.3 million emails."
Logs from August 2006 all the way up to January 2008 were included, that make it clear the roles of each of the defendants. Discussions and logs include counterfeit cards made for:
Allegheny Federal Credit Union, American National Bank of Texas, Arizona Federal Credit Union, Artesian City Federal Credit Union, Bank of America, BB&T (Banker's Bank & Trust), Boeing Employee's Credit Union, Bowdoinham Federal Credit Union, Capital One Bank, Citibank, Credit Union One, Downey Savings & Loan, epassporte, E-Trade, First Merit Bank, Flagstar Bank, Franklin Mint Federal Credit Union, Iowa League Corporate Central Credit Union, Jeffco Schools Credit Union, Langley Federal Credit Union, Mountain America Credit Union, NASA Federal Credit Union, North Island Credit Union, PointBank, Premier Credit Union, Premier Credit Union, Southern Lakes Credit Union, Southwest Federal Credit Union, Teacher's Credit Union, Telco Credit Union & Affiliates, Valley National Bank, Washington State Employees Credit Union, and the Waterbury Teachers' Federal Credit Union.
Caroline Tath and Tran were making their cash cards with laptop computers, Tath had a Dell Inspiron and an HP laptop, Gigatech flash drives, an MSR-206 encoder, an Operah card reader, and a software system called "CC2Bank 1.3", which was used to make the cards. Tran used a Sony Vaio laptop, and also provided software to defendant Lee, including a program called "TheJermMSR206". Lee used a Sony Vaio laptop and an MSR505C encoder.
Some of the defendants used their counterfeit cards to buy goods at WalMart and CostCo. Others purchased stock on E-Trade accounts, or used E-Trade accounts to purchase Postal Money Orders. Many cards were used to withdraw cash from ATM's in Los Angeles and Orange County. Some of those funds were transferred via Western Union or MoneyGram to Romania, where the data to make the cards had been received from on a "50/50" cashier's deal.
At least one defendant also shipped "refurbished notebook computers" to co-defendants in Romania.
Some of the ATM withdrawals were made using hotel room keys with the PINs written on the back in sharpie.
Romanians (indicted in Los Angeles):
Ovidiu-Ionut Nicola-Roman
Petru Bogdan Belbita
Stefan Sorin Ilinca, AKA AzZ, AKA Kahn, AKA Kahnpath
Sorin Alin Panait, AKA scumpic4u
Costel Bulugea, AKA The.Vortex
Nicolae Dragos Draghici, AKA Marius Bogdan, AKA Nonick
Florin Georgel Spiru, AKA niggaplease
Marian Daniel Ciulean, AKA spuickeru
Irinel Nicusor Stancu, AKA sicaalex
Didi Gabriel Constantin, AKA StauLaSoare, AKA Estaulasoare, AKA snoop
Mihai Draghici
Marius Sorin Tomescu, AKA Andrei
Lucian Zamfirache, AKA Krobelus
Laurentiu Cristian Busca, AKA italianu
Dan Ionescu, AKA m1nja
Marius (Last Name Unknown), AKA 13081981
Alex Gabriel Paralescu, AKA paraiul
Andreea Nicoleta Stancuta, AKA godfather
Romanians indicted in Connecticut:
(See FBI New Haven's Press Release )
residents of Craiova:
Ciprian Dumitru Tudor
Ovidiu-Ionut Nicola-Roman
Mihai Cristian Dumitru
Petru Bogdan Belbita, AKA "CA is SK", AKA Robert Wilson
residents of Galati
Radu Mihai Dobrica
Cornel Ionut Tonita
Cristian Navodaru
Perhaps more interesting would be the international partners who were also indicted, including:
Hiep Thanh Tran, AKA John Tran, AKA Sam Lam -- a US resident from Vietnam
Hassan Parvez, AKA XID - from Pakistan
US Citizens:
Sonny Duc Vo, Alex Chung Luong, and
Leonard Gonzales, AKA Bonecrusher
Vietnam Citizens:
Nga Ngo, AKA Christina Ngo
Thai Hoang Nguyen, Loi Tan Dang, Dung Phan - Vietnam
Cambodian Citizen:
Caroline Tath
Rolando Soriano, AKA Loco, AKA Danny Villalopez - from Mexico
Four other hackers remain at large, known only by their aliases:
Cryptmaster, PaulXSS, euro_pin_atm, and SeleQtor
We can look forward to the next big bust, because there seems no indication these fools are slowing down. When we visit some of the chat rooms where "kahnpath", for example, used to advertise his wares, we are immediately greeted with ads for people looking for "Cashout partners", and trying to sell an MSR-206 card writer for $400.
Saturday, 17 May 2008
Spanish Arrest D.O.M. Team
Spanish police announced the arrest today of five members of a prolific hacking team known as "D.O.M.". The D.O.M. team has been a political activism team active for quite some time. Zone-H, the "scoreboard of the underground", lists D.O.M as being #5 in prevalence of "Special" defacements - those against governments or major corporations or organizations. For all types of attacks, D.O.M is listed as #26, with 21,191 attacks credited to their account.
Update: Press Release from Spanish Police shows that the arrest operation was coordinated by "el Grupo de Seguridad Lógica de la Brigada de Investigación Tecnológica de la Policía Nacional" with cooperation from " agentes de la Brigada Provincial de Policía Judicial de Burgos, Málaga, Valencia y Sabadell". Congratulations to them all on their police work!
Recent defacements by the group list their members as:
an0de, ka0x, Xarnuz, and Piker
while hacks from earlier in the year listed:
crane0x, ka0x, Xarnuz, and S0cratex
We're not sure yet which were actually arrested, as the Spanish are protecting the identities of the group who are mostly minors, with two of those arrested being only 16 years old, and the other three being 19 and 20. Those arrested resided in four Spanish cities - Barcelona, Malaga, Valencia, and Burgos.
A Spanish speaking group, the actual membership has varied over time to include members from Spain, Argentina, and Mexico. For a short time a Brazilian hacker, "nwx0x" was also a member of their group, and "vpn0" and "Nitronet" have also been seen to claim membership. Their recent defacements have been Environmental Activism, decrying the pollution of rivers and the building of paper mills. The Spanish investigation began after a member of the group hacked the "Izquierda Unida" website and left supposedly "obscene messages" and caricatures of politicians on the site on March 3rd, a week prior to the March 9th election.
The actually words were:
"Tenemos algo en común, le dijo un presidente a un embustero..."
(roughly, "we have something in common, said the President to the liar/cheater" - which doesn't sound nearly as nasty as "obscene messages").
and the caricature may still be found on ImageShack, where it was originally hosted:

A spanish blogger at the time provided some clues as to what happened, including giving links to ka0x's profile on "spanish-hackers.com" (now offline) and pointing them to the current "D.O.M" website -- domlabs.org
Some of the more high-profile attacks credited to the group, at least from an American perspective, would include having hit the US government's National Cancer Institute with an SQL injection attack back in July of 2007, ( archived from Zone-H). In February, an0de defaced an MIT server with an anti-American, anti-Bush message, archive from Zone-H .
Members of the group are said to have hit NASA back in March, but it is unclear whether "Spanish Hackers Team"'s March defacement of "climate.gsfc.nasa.gov" is the same reference. Certainly its the same server that the closely allied hacker "SSH-2" hit as recently as April 25th, but we do have a positive reference of D.O.M member "an0de" hitting the NASA server "issues.worldwind.arc.nasa.gov" back in August 2007.
In a typical environmentally-motivated hack of Groton South Dakota's government website by the group in April 2007, the hacker used a gmail address: 3sk0rbut0@gmail.com and posted the message:
The spanish police say they are responsible for more than 21,000 website defacements including many government sites. (A statistic they surely got from Zone-H!) That matches what we see in the Zone-H archives, where hacks against the governments of India, Thailand, Turkey, Columbia, China, Malaysia, and others are readily found in the archives.
For several years the team ran a website, called "DomTeam.info", although their hosting was sketchy at best as they were run off numerous webservers. The original registration, from back in September of 2005, shows the email address "arcax.ath@gmail.com" as the contact address. "ATH" was another hacker group called "Arrow Team Hispanic", where Arcax partnered with KingMetal to cause script-kiddie type trouble to websites.
From the whois data from October of 2005, we find the meaning of the "D.O.M" name, as the whois information was changed to being registered to "Dark Owned Mafia". The members actually listed themselves in the WHOIS information later in 2005, when the whois "Street Address" was given as: "XgdnX - Davidu - Rootbox - ArCaX-ATH", the then current members of the group. That would remain the team's street address until November of 2007 when the domain was shut down by the Registrar (Melbourne IT).
ArCaX-ATH posted his "retirement from the underground" message on April 4, 2007, claiming at that time that he had been personally responsible for 10,880 website defacements. Here's that farewell message:
Although he was withdrawing, he states that "anonyph" will carry the team forward in the right direction.
ka0x was the one, however, who took the reins to set up the new website on January 31, 2008, and we find his gmail account listed in the registration for "domlabs.org" -- "ka0x01@gmail.com", with a (probably fake) Peruvian street address.
Using the same email, ka0x posted several exploits that he had written to the milw0rm collection of attack tools, including Remote SQL injection programs written in Perl, and a program to insert your own user information into an LDAP directory, which was bannered with this:
Ten exploits and two papers are credited to ka0x on his milw0rm author page, including an 11 page paper on "Blind MySQL Injection" where he also lists the gmail address of one of his fellow team members, Piker, at piker0x90@gmail.com.
an0de also kept a blog at: http://buclenoapto.wordpress.com/
Update: Press Release from Spanish Police shows that the arrest operation was coordinated by "el Grupo de Seguridad Lógica de la Brigada de Investigación Tecnológica de la Policía Nacional" with cooperation from " agentes de la Brigada Provincial de Policía Judicial de Burgos, Málaga, Valencia y Sabadell". Congratulations to them all on their police work!
Recent defacements by the group list their members as:
an0de, ka0x, Xarnuz, and Piker
while hacks from earlier in the year listed:
crane0x, ka0x, Xarnuz, and S0cratex
We're not sure yet which were actually arrested, as the Spanish are protecting the identities of the group who are mostly minors, with two of those arrested being only 16 years old, and the other three being 19 and 20. Those arrested resided in four Spanish cities - Barcelona, Malaga, Valencia, and Burgos.
A Spanish speaking group, the actual membership has varied over time to include members from Spain, Argentina, and Mexico. For a short time a Brazilian hacker, "nwx0x" was also a member of their group, and "vpn0" and "Nitronet" have also been seen to claim membership. Their recent defacements have been Environmental Activism, decrying the pollution of rivers and the building of paper mills. The Spanish investigation began after a member of the group hacked the "Izquierda Unida" website and left supposedly "obscene messages" and caricatures of politicians on the site on March 3rd, a week prior to the March 9th election.
The actually words were:
"Tenemos algo en común, le dijo un presidente a un embustero..."
(roughly, "we have something in common, said the President to the liar/cheater" - which doesn't sound nearly as nasty as "obscene messages").
and the caricature may still be found on ImageShack, where it was originally hosted:
A spanish blogger at the time provided some clues as to what happened, including giving links to ka0x's profile on "spanish-hackers.com" (now offline) and pointing them to the current "D.O.M" website -- domlabs.org
Some of the more high-profile attacks credited to the group, at least from an American perspective, would include having hit the US government's National Cancer Institute with an SQL injection attack back in July of 2007, ( archived from Zone-H). In February, an0de defaced an MIT server with an anti-American, anti-Bush message, archive from Zone-H .
Members of the group are said to have hit NASA back in March, but it is unclear whether "Spanish Hackers Team"'s March defacement of "climate.gsfc.nasa.gov" is the same reference. Certainly its the same server that the closely allied hacker "SSH-2" hit as recently as April 25th, but we do have a positive reference of D.O.M member "an0de" hitting the NASA server "issues.worldwind.arc.nasa.gov" back in August 2007.
In a typical environmentally-motivated hack of Groton South Dakota's government website by the group in April 2007, the hacker used a gmail address: 3sk0rbut0@gmail.com and posted the message:
Defaced by ka0x
This is a cyber-protest against climatic change!!
Stop contamination!
(censored) to all governs that allow the contamination of the world!
we are: [ Arp; ka0x; an0nyph; xarnuz; Tequila ]
(SPain - Mexico - Argentina}
The spanish police say they are responsible for more than 21,000 website defacements including many government sites. (A statistic they surely got from Zone-H!) That matches what we see in the Zone-H archives, where hacks against the governments of India, Thailand, Turkey, Columbia, China, Malaysia, and others are readily found in the archives.
For several years the team ran a website, called "DomTeam.info", although their hosting was sketchy at best as they were run off numerous webservers. The original registration, from back in September of 2005, shows the email address "arcax.ath@gmail.com" as the contact address. "ATH" was another hacker group called "Arrow Team Hispanic", where Arcax partnered with KingMetal to cause script-kiddie type trouble to websites.
From the whois data from October of 2005, we find the meaning of the "D.O.M" name, as the whois information was changed to being registered to "Dark Owned Mafia". The members actually listed themselves in the WHOIS information later in 2005, when the whois "Street Address" was given as: "XgdnX - Davidu - Rootbox - ArCaX-ATH", the then current members of the group. That would remain the team's street address until November of 2007 when the domain was shut down by the Registrar (Melbourne IT).
ArCaX-ATH posted his "retirement from the underground" message on April 4, 2007, claiming at that time that he had been personally responsible for 10,880 website defacements. Here's that farewell message:
Bueno esto es algo que notaba desde hace algunos meses, mi poco tiempo para hacer las cosas del grupo D.O.M... y que muchos estaban anciosos de poder leer, así que hay les otorgo el siguiente regalo, baj la una reunión de costumbre. el domingo pasado he decidido delante de todos los miembros del grupo y con aprobación de los mimos, he decidido retirarme completamente de la scene Underground sin aviso por nuevo reintegro ni nada por el estilo, tenia pensado en hacerlo en octubre de este año cuando el team cumpliera los 2 años ... pero ya no podía tener en espera a los demás compañeros del grupo, aunque el echo de mi retirada no quiere decir que el grupo también se pare, se que anonyph los demás lo llevaran por el buen camino; agradezco en especial a her0 y ka0x que me llevaron a tomar la decisión correcta para el team. también se ha decido que la web de DOM no seguiría con portal ya que un portal requiere un cuidado exhaustivo con los foros y demás, se ha decido que me quedase con los 2 dominios (INFO y BIZ) para utilizarlo en mi blog personal, y otros proyectos personales... de ArCaX-ATH tendrán para rato eso sí, solo que con menos frecuencia que antes....
Although he was withdrawing, he states that "anonyph" will carry the team forward in the right direction.
ka0x was the one, however, who took the reins to set up the new website on January 31, 2008, and we find his gmail account listed in the registration for "domlabs.org" -- "ka0x01@gmail.com", with a (probably fake) Peruvian street address.
Using the same email, ka0x posted several exploits that he had written to the milw0rm collection of attack tools, including Remote SQL injection programs written in Perl, and a program to insert your own user information into an LDAP directory, which was bannered with this:
Title: LDAP injections
Author: ka0x
contact: ka0x01[!]gmail.com
D.O.M TEAM 2007
we: ka0x, an0de, xarnuz, s0cratex
from spain
Ten exploits and two papers are credited to ka0x on his milw0rm author page, including an 11 page paper on "Blind MySQL Injection" where he also lists the gmail address of one of his fellow team members, Piker, at piker0x90@gmail.com.
an0de also kept a blog at: http://buclenoapto.wordpress.com/
Thursday, 15 May 2008
Certificate Dangers?
The German Import House has a catalog where you can by a Dirndl dress or an Oktoberfest Party Hat.
https://germanimporthouse.sslpowered.com/germanimporthouse/nfoscomm/catalog/
The catalog gives its visitors the added sense of security by turning the address bar in my Firefox browser yellow, and adding a padlock to the address bar. When I float my mouse over the padlock, I get the "Authenticated by Equifax" popup.
When I click on it, it says:
Unfortunately, someone put a Meadows Credit Union phish in a subdirectory of the catalog.

Visitors to that phishing site will see the same "warm fuzzy" yellow bar, and the same "Authenticated by Equifax" message.
Which brings me to the point of this article. We are all talking about Extended Validation Certificates, which will turn your address bar green, "proving" that the site is legitimate. What proof do we have that someone hasn't hacked the legitimate site and used it for an illegitimate purpose. That's what we see here with a "pre-" EV Certificate. German Import House is a legitimate site, and paid for an Equifax Certificate to prove so. However, the visitor to the Meadows Credit Union phishing site is ALSO going to see the Certificate behavior. But what does that prove?
How much danger are we in when we train our users that a colored address bar means they are safe - and then phishers hack those sites to host phishing content? The user sees a colored bar and a padlock -- one that really has a corresponding certificate on file -- and decides that its a safe site. Are EV Certs the answer? or just another way to train users that they don't have to think?
--
https://germanimporthouse.sslpowered.com/germanimporthouse/nfoscomm/catalog/
The catalog gives its visitors the added sense of security by turning the address bar in my Firefox browser yellow, and adding a padlock to the address bar. When I float my mouse over the padlock, I get the "Authenticated by Equifax" popup.
When I click on it, it says:
SSL Server Certificate
Issued to
Common Name *.sslpowered.com
Serial Number: 08:90:D2
Issued By
Equifax Secure Certificate Authority
Issued On: 1/11/1008
Expires On: 2/10/2010
Unfortunately, someone put a Meadows Credit Union phish in a subdirectory of the catalog.
Visitors to that phishing site will see the same "warm fuzzy" yellow bar, and the same "Authenticated by Equifax" message.
Which brings me to the point of this article. We are all talking about Extended Validation Certificates, which will turn your address bar green, "proving" that the site is legitimate. What proof do we have that someone hasn't hacked the legitimate site and used it for an illegitimate purpose. That's what we see here with a "pre-" EV Certificate. German Import House is a legitimate site, and paid for an Equifax Certificate to prove so. However, the visitor to the Meadows Credit Union phishing site is ALSO going to see the Certificate behavior. But what does that prove?
How much danger are we in when we train our users that a colored address bar means they are safe - and then phishers hack those sites to host phishing content? The user sees a colored bar and a padlock -- one that really has a corresponding certificate on file -- and decides that its a safe site. Are EV Certs the answer? or just another way to train users that they don't have to think?
--
Wednesday, 14 May 2008
Indictments reveal $77 Million in Illegal Pill Sales
Congratulations to the Daytona Beach FBI, US Attorney Robert O'Neill, and their colleagues at IRS and FDA.
The Daytona Beach News reported the arrest of three Volusia county ringleaders with the headline Locals accused in $77 million Internet drug ring.
According to the indictment, Jive Network distributed approximately 4.8 million dosage units of Schedule III controlled substances and approximately 39.2 million dosage units of Schedule IV controlled substnaces to Internet customers who had no valid prescriptions. They serviced over 500,000 customer orders and generated more than $77 Million in revenues over a three year period.
Charged in the indictment were:
Jude LaCour, 35, Daytona Beach, Florida (Jive Network Owner)
Jeffrey LaCour, 60, South Daytona, Florida (Jive Network Director of Operations)
whose charges included money laundering and drug trafficking offenses involving the sale of controlled substances over the Internet. (The elder LaCour was profiled May 11th in this story: Rx Suspect has Mixed Local History
Hudsen Smith, 36, Deland, Florida (Jive Network Director of Pharmacy/Physician Operations)
and the following physicians, who were paid to do the "medical reviews" for patients who had no prescriptions.
Christopher Tobin, 41, Wilmington, North Carolina (Physician)
Akhil Baranwal*, 34, Pennsylvania (Physician)
Alexis Roman Torres, 54, Puerto Rico (Physician)
Andrew DeSonia, 47, Indiana (Physician)
Marget Fulmore (McIntosh), 52, Charlotte, North Carolina (Physician)
Abel Lau, 36, Tulsa, Oklahoma (Physician)
James Pickens, 72, Midvale, Utah (Physician)
The prescriptions were filled by several pharmacists, but the only one charged in this indictment is:
Geunnet Chebssi, 56, Spencerville, Maryland (Pharmacist)
Customers, who had no prescriptions, accessed the websites and purchased the controlled substances after completing a short health history questionnaire. Identities were not verified and medical records were not submitted.
The announcement of this indictment has been a long time coming. Online drug stores have known that The Jive Network, also known as "Celestial Group Inc", has been in trouble since at least April of 2005. A note from one such online drugstore dated April 24, 2005, read:
An update on May 12, 2005 added this:
At that time, Jive sent a letter to their affiliates explaining the situation. (Quoted from the "rx-affiliate" forum at "ABestWeb.com", posted April 29, 2005):
(The same letter can also be found here)
In February 2006 the note was updated again that "XL Pharmacy" had acquired the chain of online drugstores, and was standing by to fill your needs. "XLPharmacy prescriptions drugs are made by world renowned International pharmaceutical companies such as Novartis, Cipla Abbot, Aventis, Bayer, Cipla, Dr. Reddy's, Merck, Eli Lily, GlaxoSmithKline, and Ranbaxy. All prescription drugs are shipped in the manufacturers' original package and have the manufacturers' original seal for your safety.
The link provided is still live:http://www.xlpharmacy.com/index.php?img=4&kbid=1325. The helpful FAQ on that site, which claims to have been online since 2004, says:
And yes, this replacement pharmacy is still recruiting . . .according to their website:
I can't swear that to be accurate. There were several competing affiliate programs who apparently were believed to have purchased Jive Networks customer list. LaCour and Jive Network were also the feature of an issue of The Ripoff Report claiming they had gone back into business operating "rxwebdrugstore.com, realprescriptions.com, rxwebmeds.com" and others. The owner of "Secure Medical" posted a rebuttal to this though claiming they were not related, and that their database had been compromised.
In a letter written by Haden Smith back on Aug 20, 2004, he claims there are more than 100 online prescription websites using their fulfillment services, and that their pharmacies earn between $3,000 and $10,000 per day profit.
The chat boards used by the online pharmacies and their customers are lighting up with news stories about the arrests:
Rx Affiliate Forum posters want to know "are affiliates next"? In reply, the poster was reminded "What about the 8 affpower affiliates" who were arrested? Several posters say that advertising is not illegal as long as the affiliates don't take the payments or touch or ship the drugs they are "just like Google or Yahoo" - only advertisers.
epharmacywatch.com, which provides this list of online pharmacies and their associated "Consultation Fees" and user ratings. Their conversation forum for talking about US-based online pharmacies has over 100,000 posts! The site has 117,791 registered users as of this morning. It will be interesting to see if their reaction to the news goes beyond mere reporting of the indictments.
* - curious coincidence in names here . . . this name, and city, came from court documents, but there is an Akhil Baranwai in Georgia accused of the same sort of behavior (i vs L at the end of the last name)
The Daytona Beach News reported the arrest of three Volusia county ringleaders with the headline Locals accused in $77 million Internet drug ring.
According to the indictment, Jive Network distributed approximately 4.8 million dosage units of Schedule III controlled substances and approximately 39.2 million dosage units of Schedule IV controlled substnaces to Internet customers who had no valid prescriptions. They serviced over 500,000 customer orders and generated more than $77 Million in revenues over a three year period.
Charged in the indictment were:
Jude LaCour, 35, Daytona Beach, Florida (Jive Network Owner)
Jeffrey LaCour, 60, South Daytona, Florida (Jive Network Director of Operations)
whose charges included money laundering and drug trafficking offenses involving the sale of controlled substances over the Internet. (The elder LaCour was profiled May 11th in this story: Rx Suspect has Mixed Local History
Hudsen Smith, 36, Deland, Florida (Jive Network Director of Pharmacy/Physician Operations)
and the following physicians, who were paid to do the "medical reviews" for patients who had no prescriptions.
Christopher Tobin, 41, Wilmington, North Carolina (Physician)
Akhil Baranwal*, 34, Pennsylvania (Physician)
Alexis Roman Torres, 54, Puerto Rico (Physician)
Andrew DeSonia, 47, Indiana (Physician)
Marget Fulmore (McIntosh), 52, Charlotte, North Carolina (Physician)
Abel Lau, 36, Tulsa, Oklahoma (Physician)
James Pickens, 72, Midvale, Utah (Physician)
The prescriptions were filled by several pharmacists, but the only one charged in this indictment is:
Geunnet Chebssi, 56, Spencerville, Maryland (Pharmacist)
Customers, who had no prescriptions, accessed the websites and purchased the controlled substances after completing a short health history questionnaire. Identities were not verified and medical records were not submitted.
The announcement of this indictment has been a long time coming. Online drug stores have known that The Jive Network, also known as "Celestial Group Inc", has been in trouble since at least April of 2005. A note from one such online drugstore dated April 24, 2005, read:
The Jive Network, also trading as Celestial Group Inc, were closed on the morning of April 19, 2005 as part of an investigation by DEA and FBI. To date no charges have been laid and the owner of the online pharmacy group, Jude LaCour is not in custody and has not been charged with any offences. (...) The pharmacy sites that are affected are: ePharmacist, Pillvalue, Pillstore, InstantPills, and Cyberpills.
An update on May 12, 2005 added this:
We believe Jive Network are trying to get back online and are clearing ePharmacist, PillStore, PillValue, and CyberPill orders that were held up around April 19th. Over the past 2 weeks, they seem to be either refunding customers or sending product.
At that time, Jive sent a letter to their affiliates explaining the situation. (Quoted from the "rx-affiliate" forum at "ABestWeb.com", posted April 29, 2005):
Dear Affiliate,
You may have heard the news that our offices were served with a search warrant last Tuesday, April 19th, 2005.
However, NO ARRESTS were made. No Charges were filed.
This is an obvious attempt by the DEA and FBI to try and lump us in with a group of 20 other companies/individuals that had been under
investigation, and who WERE arrested around the same time.
We want to share with you that we are NOT related to nor connected with these 20 in any way.
Jive Network has ALWAYS done everything by the book and beyond.
We have broken no laws.
We know that some of your checks have bounced. This is because the search warrant also allowed them to seize all bank accounts. When we say all,
we do mean ALL! We realize that apologizing for the difficulty this has caused you does very little, but we want to assure you of this: As soon as we are able to correct it, we will.
As to the current status, late last week, we put the websites back online. We have our internet connections and the equipment we need to start
processing orders again. However, until our accounts and other matters are operational, we are not taking orders at this time.
Additionally, something is going on with our phone lines. This is likely part of this defamatory attempt on us, so we are working to uncover and
resolve that problem as well.
When we are fully operational, we will immediately begin processing orders.
Lastly, to those of you that have emailed us telling us that you are with us, we want to express how sincerely all of us appreciate that support.
We have read comments such as, "You guys are the best ever in the industry, just let me know when I can switch my links back".
This kind of response is more than encouraging to us, and the truth is that we want to be here for as much as you are here for us. We do understand
what you are experiencing.
Please understand that the delay in sending you some kind of direct communication has been due to the circumstances of this situation, NOT
BECAUSE WE DIDN'T WANT TO TALK TO YOU.
You can be sure that this situation will not stop us. We might "look" much different in the future, we will still be us, the same "Jive Network
Team" working hard for you.
While we are uncertain as to when we will come back online, you can be certain that when we do, our entire business will be stronger and even better
than before. A team that has been through an event like this and stands firm, is a team that can accomplish anything.
Stand firm with us. We will accomplish great things, together.
Sincerely,
Jive Network
(The same letter can also be found here)
In February 2006 the note was updated again that "XL Pharmacy" had acquired the chain of online drugstores, and was standing by to fill your needs. "XLPharmacy prescriptions drugs are made by world renowned International pharmaceutical companies such as Novartis, Cipla Abbot, Aventis, Bayer, Cipla, Dr. Reddy's, Merck, Eli Lily, GlaxoSmithKline, and Ranbaxy. All prescription drugs are shipped in the manufacturers' original package and have the manufacturers' original seal for your safety.
The link provided is still live:http://www.xlpharmacy.com/index.php?img=4&kbid=1325. The helpful FAQ on that site, which claims to have been online since 2004, says:
In all cases orders require a prescription prior to shipment. If you do not have a prior prescription you will be asked to complete a online medical consultation and it will them be reviewed by a licensed physician who may or may not issue a medical prescription based upon your medical consultation. If your online medical consultation was not approved by the physician you will then need to provide a medical prescription from your local physician by fax to us prior to the shipment of your order.
And yes, this replacement pharmacy is still recruiting . . .according to their website:
Experience the highest payout commission and the best Affiliate Support by telephone, live chat and email. XLPharmacy.com pays the highest direct commission and the highest second tier commissions in the industry. Payments are made by bank transfer or epassporte weekly. Please contact the program manager to arrange for your preferred payment options and commissions structure. Commissions are paid up to 45%.
I can't swear that to be accurate. There were several competing affiliate programs who apparently were believed to have purchased Jive Networks customer list. LaCour and Jive Network were also the feature of an issue of The Ripoff Report claiming they had gone back into business operating "rxwebdrugstore.com, realprescriptions.com, rxwebmeds.com" and others. The owner of "Secure Medical" posted a rebuttal to this though claiming they were not related, and that their database had been compromised.
In a letter written by Haden Smith back on Aug 20, 2004, he claims there are more than 100 online prescription websites using their fulfillment services, and that their pharmacies earn between $3,000 and $10,000 per day profit.
The chat boards used by the online pharmacies and their customers are lighting up with news stories about the arrests:
Rx Affiliate Forum posters want to know "are affiliates next"? In reply, the poster was reminded "What about the 8 affpower affiliates" who were arrested? Several posters say that advertising is not illegal as long as the affiliates don't take the payments or touch or ship the drugs they are "just like Google or Yahoo" - only advertisers.
epharmacywatch.com, which provides this list of online pharmacies and their associated "Consultation Fees" and user ratings. Their conversation forum for talking about US-based online pharmacies has over 100,000 posts! The site has 117,791 registered users as of this morning. It will be interesting to see if their reaction to the news goes beyond mere reporting of the indictments.
* - curious coincidence in names here . . . this name, and city, came from court documents, but there is an Akhil Baranwai in Georgia accused of the same sort of behavior (i vs L at the end of the last name)
Subscribe to:
Posts (Atom)