Go Back   Two Wheel Fix > General > Off Topic

Reply
 
Thread Tools Display Modes
Old 01-27-2009, 02:21 PM   #1
pauldun170
Serious Business
 
pauldun170's Avatar
 
Join Date: Nov 2008
Location: New York
Moto: 1993 ZX-11 2008 CBR1000rr
Posts: 9,723
Default Three years undercover with the identity thieves

Three years undercover with the identity thieves
Salesmen and parents know the technique well. It's called the takeaway, and as far as Keith Mularski is concerned, it's the reason he kept his job as administrator of online fraud site DarkMarket.

By Robert McMillan, IDGNS
January 20, 2009

Salesmen and parents know the technique well. It's called the takeaway, and as far as Keith Mularski is concerned, it's the reason he kept his job as administrator of online fraud site DarkMarket.

DarkMarket was what's known as a "carder" site. Like an eBay for criminals, it was where identity thieves could buy and sell stolen credit card numbers, online identities and the tools to make fake credit cards. In late 2006, Mularski, who had risen through the ranks using the name Master Splynter, had just been made administrator of the site. Mularski not only had control over the technical data available there, but he had the power to make or break up-and-coming identity thieves by granting them access to the site. And not everybody was happy with the arrangement.

A hacker named Iceman -- authorities say he was actually San Francisco resident Max Butler -- who ran a competing Web site, was saying that Mularski wasn't the Polish spammer he claimed to be. According to Iceman, Master Splynter was really an agent for the U.S. Federal Bureau of Investigation.

Iceman had some evidence to back up his claim but couldn't prove anything conclusively. At the time, every other administrator on the site was being accused of being a federal agent, and Iceman had credibility problems of his own. He had just hacked DarkMarket and three other carder forums in an aggressive play at seizing control of the entire black market for stolen credit card information.

That's when Mularski went for the takeaway. Salesmen have long used this tactic to seal difficult deals: You simply take the deal off the table in the hope it will spur the customer to come to you. Badgered by questions about his credibility, he threatened to quit altogether. "I decided to risk it all and just said, 'Hey, if you think you can do a better job running the site and if you think I'm a fed, then by all means take the stuff. I don't want anything to do with it," he recalled recently in an interview. "What law enforcement agency would, after they were monitoring the site, want to give it back to the bad guys?"

Mularski's gambit paid off, and the other DarkMarket administrators let him stay on for another two years.

In the end they would regret that decision. Iceman was right: Supervisory Special Agent J. Keith Mularski had gone deeper into the world of online computer fraud than any FBI agent before. Working with police agencies in Germany, the U.K., Turkey and other countries, he spearheaded a remarkable investigation that netted 59 arrests and prevented an estimated US$70 million in bank fraud before the FBI pulled the plug on Operation DarkMarket on Oct. 4, 2008.

Mularski works for a little-known FBI division called the Cyber Initiative and Resource Fusion Unit, run out of the National Cyber-Forensics & Training Alliance in Pittsburgh, Pennsylvania. The unit is different from a typical FBI field office. It works hand in hand with industry and takes the time to do the deep research required to penetrate the world of online criminals.

"They have a direct personal relationship with industry people in all areas, but specifically a great relationship with the financial institutions," said Gary Warner, director of research in computer forensics at the University of shitville at Birmingham. The group also works closely with international law enforcement, laying the groundwork to prosecute Internet criminals who launch attacks across national borders. "Those relationships allow them to take on cases that nobody else would take on," Warner said.

Mularski's life as an undercover spammer began around July of 2005, when he created his handle Master Splynter in a tribute to the cartoon rat who plays sensei to the Teenage Mutant Ninja Turtles. His unit ran a project called Slam-Spam, and Mularski, a self-confessed computer nerd, said he had picked up a lot of spamming tricks before he started the operation. "I could talk shop," he said.

He didn't send out spam himself, but he knew what questions to ask and -- more importantly -- what not to ask. He kept to his character as a spammer. If someone approached him with a new "zero day" attack, he wouldn't ask for details. And he avoided going after personal information, not asking forum members obvious cop-giveaways such as where did they live. "The thing is with these guys, you can't necessarily target them and just approach them out of the blue," he said. "So by being out there and not really caring about things -- I played a lot of things off nonchalant -- I was able to gain their trust."

The hours were long; scammers don't work 9 to 5. "Sometimes I spent as much as 18 hours in a day online," Mularski said. "I was online every day from August 2006 until the operation came down."

His most active discussion time was between 10 o'clock at night and one or two in the morning. "Every night I'd be watching TV with my wife next to me and I'd have the computer on, just in case somebody needed to get a hold of me," he recalled.

After 10 years of marriage to an FBI agent, Mularski's wife knew that operations could cut into personal time. It couldn't have been easy, though. "She was the real saint in this whole thing," he said.

Master Splynter didn't take vacations either, even if Mularski did. "Usually, if you're not going to be online, you've got to give notice because they wonder what you're doing, whether you got busted or not. So if I was travelling somewhere and I couldn't be online, I'd always give these guys advance notice."

By September 2006, Mularski had become a moderator on DarkMarket. Not as powerful as an administrator, he was still a trusted manager, one step above the reviewers who assessed the quality of products being sold on the site.

That's when he got his big break. And it came from an unlikely source: Iceman himself. According to authorities, Iceman was making a play to control the market for fake credit cards by hacking into four carder sites, including DarkMarket, knocking them offline and moving their membership to his own site, CardersMarket.

Even when the site was back up and running, Iceman continued to hit DarkMarket with distributed denial of service (DDoS) attacks, which would overwhelm it with wave after wave of useless Internet traffic.

Mularski wasn't sure how things would play out, but in September 2006 he saw his chance. He started talking with Iceman about joining CardersMarket as a moderator, but soon realized that he the had a better shot with another administrator at DarkMarket, Renu Subramaniam, aka JiLsi. "I basically told him, 'Hey, I can secure your servers for you,'" Mularski said. JiLsi made him a moderator, but held off granting him administrative access.

Then one Saturday night a month later, DarkMarket started getting hammered with another DDoS attack. "I was talking with JiLsi and I said, 'Hey I can secure the site? The servers are all set.'"

JiLsi's reply: "Let's move it."

Mularski was now a made man. As administrator to the site he could track people who logged in and, most importantly, read everything the cyberthieves were saying to each other. Working with his international law enforcement contacts, Mularski compiled evidence and, one by one, his team tracked down the crooks who ran DarkMarket.

The first big one to go was Markus Kellerer, a.k.a. Matrix001. German authorities picked him up with five other scammers in May 2007. A few months later Mularski's patron, JiLsi, was arrested in the U.K., one of the first targets of a newly created U.K. organization called the Serious Organized Crime Agency.

By September last year the operation had pretty much run its course. FBI approval for Operation DarkMarket was set to expire on Oct. 5, and Turkish authorities had finally rounded up Cha0, (real name Cagatay Evyapan), considered one of the FBI's top targets. An electrical engineer who manufactured ATM and point-of-sale skimming devices that could be hooked up to legitimate machines to steal information, Evyapan considered himself a "very traditional, organized criminal," not just a computer hacker, Mularski said.

He showed his nasty side when an associate named Kier (news reports have named him as Mert Ortac) spoke with Turkish media in early 2008, angering Evyapan. "He kidnapped him and tortured him and posted a picture of Kier in his underwear that's now famous," Mularski said.

The sign read, among other things, "I am rat. I am pig. I am reporter. I am ****ed by Cha0."

With Evyapan gone, "We had taken out all the administrators of DarkMarket, and that pretty much left me at the top," Mularski said.

Still, he remained in character for a few weeks longer. In September he posted a note saying he was closing the site, in part because of police infiltration. "It obvious [sic] that the Special Services and Security f***s are still here lurking in our ranks. They continue to gather evidence on us. They read our posts, they talk with our vendors, they look to see who are the active members of the forum," he wrote, according to a posting published on Wired.com.

But Mularski always knew that with all the international arrests being made there was a chance, through error or differences in judicial processes, that his name would be made public. And that's ultimately what happened. A German reporter, Kai Laufen, working on a story about cybercrime, discovered Mularski's name in court documents relating to the Kellerer case. On Oct. 13 Wired reported the story and everybody knew.

Still, some of Mularski's carder buddies refused to believe the reports. "These guys trusted me so much that even after the Wired article came out exposing me, for two days afterwards people were reaching out to me on ICQ thinking that it was a hoax and making sure I was alright."

Most were silent, however, after Mularski wrote them back saying that he was indeed an FBI agent.

One hacker who called himself Theunknown swore at Mularski, "You piece of crap fed... you're never going to catch me."

"Why don't you turn yourself in. It beats living the rest of your life on the run," Mularski wrote back. A week later, Theunknown followed his advice.
__________________


Quote:
Originally Posted by Dave View Post
feed your dogs root beer it will make them grow large and then you can ride them and pet the motorcycle while drinking root beer
pauldun170 is offline   Reply With Quote
Old 01-27-2009, 04:46 PM   #2
Kaneman
AMA Supersport
 
Kaneman's Avatar
 
Join Date: Nov 2008
Location: Odessa, TX
Moto: 2000 Honda CBR1100XX Blackbird
Posts: 4,931
Default

Good story. I'm a Fraud Investigator for an auto lender by day so I spend a lot of time dealing with ID Theft. The truth of it is for now that local law enforcement is far behind the game and consider it a low priority. Little by little though more agencies are starting to take notice on the prevention and the prosecution side.
________
New Mexico Medical Marijuana Dispensaries

Last edited by Kaneman; 05-09-2011 at 08:33 PM..
Kaneman is offline   Reply With Quote
Old 01-28-2009, 10:49 AM   #3
Katana-750_lady
Umm... hi
 
Katana-750_lady's Avatar
 
Join Date: Dec 2008
Location: Ft Lauderdale
Moto: Used to be F4i
Posts: 100
Default

Nice!! That was a long read but worth it.
__________________
Katana-750_lady is offline   Reply With Quote
Old 01-28-2009, 11:17 AM   #4
BobTheBiker
too much time on my hands
 
BobTheBiker's Avatar
 
Join Date: Jul 2008
Location: the northern district of god damn
Moto: 01 ZX6R, looking for more now.
Posts: 1,802
Default

Too bad they couldnt have strung it out longer and caught more of the dumbasses.
BobTheBiker is offline   Reply With Quote
Old 01-28-2009, 11:48 AM   #5
the chi
Forum Coach
 
the chi's Avatar
 
Join Date: Feb 2008
Location: GA
Moto: 2006 GSXR 600
Posts: 7,419
Default

Wow, that was pretty interesting stuff, altho the one guy kidnapping the other was a tad creepy!
__________________
Quote:
Originally Posted by Cutty72 View Post
The Chi hath spoken...
and let it be known that what The Chi hath spoketh, will henceforth be done.
the chi is offline   Reply With Quote
Old 01-28-2009, 12:16 PM   #6
Amorok
Issukangitok
 
Amorok's Avatar
 
Join Date: Nov 2008
Location: Biloxi, MS
Moto: '06 Suzuki Boulevard C50T
Posts: 2,225
Default

Fantastic, nerd cops making a difference.
__________________
What goes around comes around. Sometimes you get what's coming around, and sometimes you are what's coming around. You see what I mean?
Amorok is offline   Reply With Quote
Reply

Bookmarks


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -4. The time now is 03:11 AM.

Powered by vBulletin® Version 3.8.11
Copyright ©2000 - 2024, vBulletin Solutions Inc.