US recovers a record $15m from the 3ve ad-fraud crew
- Reference: 1652992250
- News link: https://www.theregister.co.uk/2022/05/19/us_3ve_fraud/
- Source link:
"This forfeiture is the largest international cybercrime recovery in the history of the Eastern District of New York," US Attorney Breon Peace said in a [1]statement .
The action, Peace added, "sends a powerful message to those involved in cyber fraud that there are no boundaries to prosecuting these bad actors and locating their ill-gotten assets wherever they are in the world."
[2]
Between December 2015 and October 2018, two Kazakhstan citizens, Sergey Ovsyannikov and Yevgeniy Timchenko, and one Russian, Aleksandr Isaev, carried out the massive fraud botnet scam and accessed more than 1.7 million infected computers in the US and globally, according to the Justice Department.
[3]
[4]
Both Ovsyannikov and Timchenko were arrested in 2018, [5]pleaded guilty and have been sentenced to terms in US prisons. Isaev, along with five others, are [6]charged [PDF] with money laundering, wire fraud, computer intrusion and identity theft for their involvement in 3ve (pronounced "Eve"), but remain free.
Here's how the scheme worked:
[7]
The operators purported to run legitimate companies that delivered ads to real human netizens accessing real websites. In fact, they faked both the humans and the websites using spoofed domains and a massive network of infected devices.
They were able to pull this off (for a while, at least) by developing a global infrastructure of command-and-control servers that monitored the infected computers to see if they had been flagged for possible fraud.
The operators used a pair of malware packages – Windows-targeting Boaxxe and [8]Kovter – to infect victims' PCs. Once they had access to millions of devices they used hidden browsers on those computers to download fake websites and load ads onto the spoofed sites.
[9]3ve Offline: Countless Windows PCs using 1.7m IP addresses hacked to 'view' up to 12 billion adverts a day
[10]Ad-tech firms grab email addresses from forms before they're even submitted
[11]Ukrainian crook jailed in US for selling thousands of stolen login credentials
[12]State of internet crime in Q1 2022: Bot traffic on the rise, and more
The Feds, working with Google and a collection of security companies, [13]took down the ad-fraud operation in 2018. The FBI executed seizure warrants to sinkhole 23 internet domains and also executed search warrants at 11 different US server providers for 89 servers related to 3ve or Kovter.
During the course of the scam, the miscreants falsified billions of ad views and spoofed more than 86,000 domains, resulting in businesses paying more than $29 million, according to the Justice Department. A little more than half of the illicit proceeds, $15,111,453.84, has since been transferred from Swiss bank accounts to the US government. ®
Get our [14]Tech Resources
[1] https://www.justice.gov/usao-edny/pr/united-states-recovers-over-15-million-swiss-bank-accounts-proceeds-global-digital
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Yoa@A5-OEdnmrxiazVxT6wAAAFc&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Yoa@A5-OEdnmrxiazVxT6wAAAFc&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Yoa@A5-OEdnmrxiazVxT6wAAAFc&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[5] https://www.justice.gov/usao-edny/pr/two-kazakh-cybercriminals-plead-guilty-global-digital-advertising-fraud-involving-tens
[6] https://www.justice.gov/usao-edny/press-release/file/1114576/download
[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Yoa@A5-OEdnmrxiazVxT6wAAAFc&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[8] https://www.trendmicro.com/vinfo/us/security/news/cybercrime-and-digital-threats/kovter-an-evolving-malware-gone-fileless
[9] https://www.theregister.com/2018/11/28/3ve_ad_fraud_men_charged/
[10] https://www.theregister.com/2022/05/16/ad_companies_data/
[11] https://www.theregister.com/2022/05/13/ukrainian_credentials_botnet/
[12] https://www.theregister.com/2022/05/18/fraud_economy_booms/
[13] https://www.theregister.com/2018/11/28/3ve_ad_fraud_men_charged/
[14] https://whitepapers.theregister.com/
Re: Fraud is not fixed
I can fix your mail server for you.
They still kept
They still got to keep 14million.
re: "operation that cost businesses more than $29 million for ads that were never viewed"
Depending on how one defines "view", this can be true of google and other ad-/track-ware slingers: does "view" mean that the image was summoned (and may have been blocked)? that the advert image actually loaded into the viewer's browser as intended (and wasn't s/adimage.gif/smilyface.gif/ by a browser extension or other end-user magic)? that the viewer actually laid eyeballs on that corner of the page? that the viewer paid enough attention to recall the product or service? Not to let Threeve off the hook, they just seem to have been more creative about exploiting a flaw in the whole concept.
Fraud is not fixed
The Feds, working with Google and a collection of security companies, took down the ad-fraud operation in 2018 and they left the SPAM, fake faxes and fake phone call efforts running daily. Every couple of hours everyone gets a phone call announcing that their vehicles warranty has expired but can be renewed. If you have a fax then you get details of the new loans that are available and everyone gets a couple of dozen SPAM emails a day (our mail server is only rejecting 85% of all spams).