“And the Ministry of Internal Affairs has its own hackers”
The rapid development of computer technology in recent years has caused an equally rapid increase in crimes using them. The problem of investigating such specific cases automatically arose - after all, in them, unlike traditional criminology, the crime cannot be seen with the eyes, most of the evidence and traces of criminals cannot be collected by hand, touched or photographed. The leading specialist of the Investigative Committee (IC) under the Ministry of Internal Affairs in this area, senior investigator for particularly important cases of the crime investigation department in in the field of computer information and high technologies, Lieutenant Colonel of Justice Igor YAKOVLEV.
- As the practice of investigating such criminal cases shows, hackers are a rather conservative people, and they rarely develop new methods for taking money, preferring proven methods. As a rule, so-called carders - those who specialize in credit card fraud - operate according to one basic principle, which is based on gaining access to the passwords of credit and debit card holders. It should be noted here that our hackers obtain confidential information of this nature not only in Russia, but quite often in other countries of the world. In general, such scams are multi-stage, involving entire groups of “narrow-profile” specialists, each of whom is engaged in their own “business”. Most often, information about passwords is stolen in peculiar “packages”, and then put up by thieves in bulk for auction on specialized well-secret Internet portals, to which only “insiders” have access and which are extremely difficult for outsiders to detect, much less take part in. Usually on such portals “lots” are posted with lists of cardholders indicating the amounts on the accounts. This information is sold out very quickly, and, as a rule, for only 5-10% of the total amount. For example, if the total amount on the accounts of all cards in a “lot” is 100 thousand dollars, then the seller receives 5-10 thousand dollars. Then, one by one, information about the “stolen” passwords passes through the hands of different specialists. Buyers of passwords pass it on to manufacturers of counterfeit cards - roughly speaking, duplicates of “opened” cards, they are also called white plastic, malware developers are also involved, who launch a virus into a computer network to transfer money, well, and those who directly complete the scam cashes out money. For the sake of which, in fact, everything is started. As a rule, all “specialists” involved in such fraud receive their percentages for their work. There are already quite a lot of such cases in Russia; in our Investigative Committee, only the most significant ones are investigated, with great damage. We are currently working on a criminal case related to a similar theft of funds from clients of Alfa Bank OJSC. When this fact was revealed, the bank immediately reimbursed the clients’ money. That is why Alfa Bank is recognized as the injured party in the case. We quickly managed to get on the trail of three hackers, one of whom was put on the wanted list. They are accused under four articles of the Criminal Code of the Russian Federation - 159-4 (fraud committed by an organized group on an especially large scale), 272 (illegal access to computer information), 273 (creation, use and distribution of malicious computer programs) and 183 (illegal acquisition of information constituting commercial and banking secrets). We found that in 2007, over the course of several months, attackers, using a malicious program they created with the task of collecting confidential information, read the data of bank clients through one of the Internet services - account names, bank card passwords, etc. They then cashed out through the most common online payment system, WebMoney. At the time the case was initiated, it was about the theft of more than 12 million rubles by hackers, but already in the process of the investigation, more and more new episodes began to emerge, and by the time the final charges are brought, I think the amount will be much higher. As we established, the criminals spent this money on paying for mobile phones, gifts, and entertainment. We are now finding out whether the accused were involved in other similar frauds. Recently, by the way, a new way of cashing out money using fake credit cards has appeared. There have been cases when waiters, when paying in restaurants with cards, withdrew additional amounts, allegedly as tips.
-- How do criminals most often gain access to information about bank card owners?
— In principle, many ways to obtain such information have been invented, but the most common are the so-called skimming and phishing. Skimming is obtaining information about the cardholder and his account using a skimmer - a special scanner or, if you prefer, a mini-computer. This is a device with a magnetic reading head, an amplifier, a converter, memory and an adapter for connecting to a computer, which scammers secretly install on an ATM. It reads information from the magnetic stripe of the card when the owner inserts it into the ATM. Then the skimmer is removed and the scammers read information from it. As a rule, criminals equip remote ATMs with such devices that are not closely guarded. Recently, by the way, criminals have often begun to use when skimming not working ATMs, but their dummies, which they install themselves. Outwardly, they are no different from real ATMs, they have logos and data of real banks, but they are just an empty case with a skimmer built inside. When a bank client inserts a card into it, information is displayed on the display indicating that the ATM is either temporarily not working or has run out of money. An unsuspecting person takes the card back, but the information on it, including the PIN code, has already been recorded by the scammers. Phishing is a method of obtaining the same information about the cardholder using mass emails on behalf of popular brands or banks. These letters contain links to fake sites - exact copies of real ones. Once on such a site, the user can provide criminals with valuable information that allows them to manage their account from the Internet - username, access password, credit card number. By the way, the success of phishing scams is facilitated by the low level of user awareness about the operating rules of companies and banks. You need to know that real banks and companies will never offer clients, much less require them, to confirm their credit card number and PIN code online, as hackers do under the pretext of allegedly changing the website design or technical failures. If someone did this, he will certainly lose his money. True, quite often bank card owners themselves do not notice that they have become victims of carders. Hackers try to act very carefully, “pinching” clients en masse, but little by little, so that the theft is not immediately obvious. After all, many people do not carefully monitor the state of their account; they only replenish it, but do not check exactly how much money remains on the card. That is why sometimes the facts of such thefts are revealed during the investigation of a criminal case or even after several years.
-- Recently, hacker attacks, or, as they are also called, DDoS attacks, on the websites of large companies have become increasingly widespread. Who is usually behind them?
- As a rule, such attacks are organized at the request of competitors. Thus, Russian hackers managed to disable not only the websites of Russian companies, but also Western ones, such as yahoo, ebay, buy.com, amazon.com, cnn.com and a number of others, there are many of them. The scheme of these attacks is simple - at the right moment, a robot program with the help of a launched virus begins to activate and infects a number of IP addresses, which begin to “bombard” a particular site with false requests. As a result, the site that has come under attack begins to freeze and will not open. The purpose of such attacks, as a rule, is one - to cause losses to the company. After all, it’s good if the site goes down for a couple of hours, but if, say, for a week, then the resource will most likely have to be raised from scratch. You can fight hacker attacks only with the help of the latest security equipment and competent specialists. By the way, many hackers earn a comfortable living this way, by supporting the Internet resources of various companies and stopping DDoS attacks in a timely manner without breaking the law. In general, a service for such an attack costs on average from $100 to $10 thousand per week. It all depends on the complexity and duration of the attack and the characteristics of the victim’s website. Hackers openly post advertisements on their special websites: “We accept orders for DDoS attacks.” This work is paid in full immediately.
-- Is it possible to bring to justice the organizers of hacker attacks?
-- The very first criminal case on cybercrime concerned DDoS attacks. This was in 2003, when our hackers used such attacks to constantly block the websites of nine major English betting companies, extorting large sums of money from them. In 2004, the Russian Ministry of Internal Affairs received a request from the National Hi-Tech crime unit (NHTCU) of Great Britain, in which we were asked to provide assistance in catching criminals. As the English police established, the DDoS attacks took place from Russian territory, and the server was located in Houston, from where the hackers actually “bombed” the bookmakers. At that time, not only did we have no experience in investigating such cases, but there were no analogues in the whole world. Until then, hackers were simply elusive. And yet I opened a criminal case under Art. 163-3 of the Criminal Code (extortion committed by a group of persons on a large scale) and 273-1 (creation, use and distribution of malicious computer programs). Moreover, this was my first investigation in this area; before, I handled economics cases. It was incredibly difficult - because at that time there were no books or any manuals on how to investigate these cases, how to identify such criminals. We soon established that four hackers were located in different cities of the country - in the Saratov region, Astrakhan, St. Petersburg and Pyatigorsk. They met, as we established, on one of the hacker sites, but had never seen each other, communicated exclusively via the Internet, and agreed to “do the job quickly” in the hope of a big jackpot. To begin with, they sent email letters to bookmakers demanding that they pay them money, and if they refused, they promised to block the sites, and then the bookmakers would suffer colossal losses. Moreover, nine bookmaker companies were officially recognized as victims in the case; the damage from daily downtime of their Internet resources amounted, according to the materials of the criminal case, to tens of thousands of dollars. Some bookmakers paid money, but the attacks did not stop, and that’s when they decided to write a statement to the English police. After we opened the case, we asked our English colleagues to persuade one bookmaker company to pay the 40 thousand dollars that the hackers demanded. Thanks to this, the entire chain was tracked - first, the money went to one of the banks in Latvia, where it was cashed by accomplices of hackers (those who specialize in cashing money stolen over the Internet are called drops) and then sent it in several batches via Western Union, minus their interest to Pyatigorsk, where they were successfully withdrawn from the account and sent to Astrakhan, Saratov region and St. Petersburg. When I finished the case, the question arose in which court to hear it. The crime was committed in the UK, and the hackers themselves were here. As a result, it was decided to send the case to the court where we detained the first hacker - in the city of Balakovo, Saratov region. The judge read the indictment, did not understand anything, and at first tried to refuse to consider the case. But the Prosecutor General’s Office protested his decision, and the case was eventually heard in Balakovo. Already in court, additional examinations were ordered. Representatives of the English side took part in the process. Unfortunately, we were unable to prosecute the organizer of these hacker attacks, even though we knew that he was from Pyatigorsk. The court considered that we had not collected enough evidence against him. But three - Ivan Maksakov from the city of Balakovo, Saratov region, Alexander Petrov from Astrakhan and Denis Stepanov from St. Petersburg in 2006, the court sentenced to eight years in prison and payment of 100 thousand rubles. from everyone. I’ll immediately explain why they were punished so severely, although at the stage of the preliminary investigation the accused were under recognizance not to leave the place. The fact is that extortion is considered a particularly serious type of crime, and there can be many ways. In this particular case, the convicts used the Internet and their knowledge to commit the crime. But this does not change the essence of extortion, because according to the law, the crime is considered completed from the moment demands for payment of money are made. Moreover, in this case the hackers even received money. After investigating such a voluminous and complex case at the level of international cooperation, our law enforcement agencies became famous in the world, and we repeatedly made presentations to foreign colleagues at international conferences, where we shared our experience.
— How often are such cases initiated, what difficulties arise during their investigation?
-- Cases are initiated quite often, but the problem is different. There are few competent specialists in the country, including investigators, who could bring such cases not just to court, but also to a guilty verdict. Unfortunately, due to a lack of experience and competently collected evidence, many such cases are either abandoned at the initial stage of the investigation or fall apart in court. We still do not have advanced training courses in this area. After all, the most difficult thing is not just to identify the hacker and establish his location, but to catch him red-handed at his “workplace” and competently prove his guilt. After all, usually on the Internet, hackers communicate anonymously, under fictitious names - nicknames, and each of them can have more than a dozen. Just like email addresses, accounts, etc. In addition, they are constantly encrypted, use remote access, the computer itself may be located in Moscow, from where all the scams are carried out, and the server may even be in Jamaica. And our task is to establish who exactly is hiding behind them. It's not easy, but we're trying. And when seizing material evidence from a hacker, it is very important to describe it correctly - after all, most of the evidence here cannot be touched or photographed. A self-respecting hacker has a lot of special programs - from simple to complex ones, for encrypting all files and virtual disks, which, of course, are not visible on the desktop, and only the owner of the computer can always access them. And here the competent work of experts is extremely important. Our experts, by the way, are in no way inferior to foreign and hackers themselves and are able to find and open any encrypted directories. After all, traces from a disk cannot be erased irrevocably, they always remain, and it is based on these traces that we catch them and bring charges.
— According to your data, what is the rating of Russian hackers in the world? And what kind of people are these anyway?
-- Last year, at an international conference in London, where now not only representatives of law enforcement agencies around the world involved in the investigation of cybercrimes, but also large IT companies gather annually to exchange experiences, everyone unanimously came to the conclusion that at the moment Russian hackers are alone of the strongest. After them in this peculiar table of ranks come the Chinese hackers, but they do not yet reach the level of ours. By the way, as foreign experts admit, Russian hackers are also distinguished by amazing impudence. It happens that they launch attacks on the websites of not only private companies, but also government agencies without any benefit - simply out of a sense of revenge or ordinary hooliganism, to simply show their strength. As for the social composition of Russian hackers, it is very diverse. Among them are students, clerks, and even businessmen. For some, hacking is just a hobby, while others make money from it professionally. Their career growth begins, as a rule, at the age of 14, sometimes even at ten - as soon as they master a computer. By the age of 18, such hackers become top-class specialists. They rarely communicate with each other “live” - as a rule, they get to know each other and conduct joint business only through the Internet, on special hacker forums. They are deeply conspired and encrypted, it is extremely difficult to get to the uninitiated on them. And in order to take part in some hacker project, numerous recommendations and guides of multi-lover hackers will be required. On the sites and forums of hackers there are even black lists of those with whom you should not deal. The monitoring and monitoring of such sites is carried out by employees of the K of the Ministry of Internal Affairs of Russia, not a single thing is excited without their verification. And among the employees of the Ministry of Internal Affairs there are hackers.
“And the Ministry of Internal Affairs has its own hackers” • Vremya novostej • RIMA — Russian Independent Media Archive