
In July 2014, a few days after the 30-year-old Russian Roman Seleznev was detained in the Maldives and on a private plane, he was transported to the United States, the New Gazeta published a forecast for a well-informed expert in the field of cybercrime about the key areas in which the attacks of the special services will be delivered. Our interlocutor even then drew attention to the fact that for ten years, as in the United States, all arrests in criminal cases related to cybercrime are presented in the media and official prosecutors, and even in court decisions as the exposure of one giant cyber resident group, something like a cyber-heart. All suspects and already convicted people were positioned as members of a single criminal organization.
The warning of my interlocutor has been preserved on the dictaphone record:
- Sooner or later, all these people will be accused of entering the same group managed from Moscow. Already today, the American media write that over ten years of the Titanic struggle with cybercrime, many members of the Global Cyberbanda have been arrested, but some of the criminals are allegedly in Russia, almost under the auspices of the FSB .
In the summer of 2016, this forecast was confirmed. It was from June 2016, when the Washington Post reported that the “Russian hackers who enjoy the support of state structures” penetrated the servers of the US National Committee of the US Democratic Party, Russia began to position as the cybersla empire.
On June 10, 2017, the FBI ex-director James Komi at a hearing in the Senate stated that he first learned about Russian cyberats at the end of the summer of 2015 , and during this time “hundreds of, perhaps thousands of computer invasion attempts, the goals of which were non-governmental and near-government organizations.” Komi suggested that these attacks were “part of a large strategic plan”, that Russian hackers tried to influence the results of the US president. True, the ex-director of the FBI did not give any specifics.
Meanwhile, the analysis of crimes related to the Internet by which arrests have been made or even sentenced (first of all, the Seleznev case) suggests that cybercrime is much more multifaceted than in the description of the ex-director of the FBI, and that James Komi, perhaps, was lucid. For example, when he stated that he first heard about the “Russian cyber attacks” at the end of the summer of 2015. He seems to have “forgot” about the most grandiose cybercrime, committed in the United States, when at the end of December 2013, Target Corp., managing one of the largest chains of the country's retail stores, announced theft for 19 days (starting on November 27) 70 million credit cards.
A little later, Brian Krebs, an American journalist specializing in cybercrime, on the Krebs On Security blog, said the attackers abducted the information using software, which allowed to penetrate payment terminals reading information from the magnetic tapes of plastic cards. At the same time, these credit cards were downloaded from almost all terminals in all 1797 Target stores in the United States. Soon, information leaked to the American media: the FBI established that the largest abduction of these credit cards was carried out using a virus, which has “Russian roots”.
The experts I interviewed have assumptions that the theft of the data of 70 million credit cards has become a catalyst for activating the actions of American special services against Roman Seleznev. The fact is that it was on the stolen trading of credit cards created for automated trading that were created by Seleznev, that information from the terminals of Target Corp was laid out for sale. And it was after the “start of trading” the Americans went to an unprecedented special operation, actually abducting Seleznev with the Maldives.
By the way, back in May 2009, the FBI shared information with the FSB that Seleznev is one of the leaders of cybercrime, and from that time, and, possibly earlier, Seleznev was constantly in the field of view of the USS (United States Secret Service).
When two months ago the verdict against Seleznev was announced and I began to collect information for publication, I unexpectedly faced the fact that all my interlocutors-IT sphere specialists, computer security, retired and current FSB officers agreed to speak exclusively on anonymity conditions. What can I say, even if the father of the novel, the deputy of the State Duma Valery Seleznev, refused to meet, learning that I am interested in the details of the last years of the novel at the freedom. And one of my interlocutors said that this topic is fraught with serious consequences.

On April 21, the Court of Seattle (USA) sentenced Seleznev to 27 years in prison, pleading proven the Russian guilt in the commission of cybercrime. A very long time, because Seleznev pleaded guilty, repented and went to cooperate with the investigation. True, repentance occurred after the end of the judicial investigation, when the jury (in August last year) unanimously issued a verdict of Seleznev’s guilt in 38 criminal episodes, including cybersecurity, intentional damage to secure computers, obtaining information from these computers, the theft of personal data under aggravating circumstances.
In the memorandum for the court prepared by prosecutors Seth Wilkinson and Norman Barbosa, the exact date is called and some details of the meetings of the FBI and the USS officers with the FSB officers are presented. It is indicated: the meeting took place on May 19, 2009 in Moscow. The prosecutors claim that the officers of the American intelligence services presented irrefutable evidence that the hacker operating under the nickname NCUX, suspected of performing dozens of cybercriminals, is Roman Seleznev.
But, according to the information set forth in the memorandum, the meeting of special services officers of the United States and Russia turned into the fact that the FSB warned Seleznev about exposure. The FBI recorded - on June 21, 2009, Seleznev informed his accomplices that he was leaving "Business", after which the hacker under the nickname of NCUX disappeared from the Internet. But a few months later, Seleznev returned to the cyberspace again by launching the Bulba and Track2 sites, appearing on the underground forums of carders - cybercriminals specializing in the embezzlement of data from credit cards, under the nicknames of 2pac, Bandysli64, SMAUS, ZAGREB, ShMAK, etc.
During the trial, the prosecutor Norman Barbos said: "His accomplices addressed him as Tony Soprano." The prosecutor showed the jury two reproductions. One depicted Seleznev in a luxurious robe with orders and ribbons. On the second - a fictional gangster soprano, depicted in the ceremonial uniform of the XVIII century. According to Norman Barbosa, these paintings, combined with other evidence obtained by the investigation, confirm that Seleznev is not an ordinary cybercriminal, but one of the leaders of the criminal community who has resold the data of more than two million credit cards and damaged the Americans, estimated at billions of dollars. The indictment indicates 3,700 financial organizations and 500 companies around the world, mainly in the USA, affected by organized crime groups.
Formally, Selezneva was detained in the Maldives as part of the operation of the liquidation of a gang of carders who hacked and stole the data of 160 million credit cards (this is more than half of the credit cards issued in the United States). The ideologist and leader of the international cyberbanda, before the start of the trial of Seleznev, was considered Alberto Gonzales, a US citizen of Cuban descent, who, during the trial, publicly admitted that he was an informant of the US intelligence services. In fairness, recognition did not help Gonzales: on September 11, 2009 he was sentenced to 20 years in prison.
There is a mention of Alberto Gonzales in the prosecutor’s memorandum against Roman Seleznev. But in this document, Gonzales is represented, albeit not an ordinary “fighter” of Cyberbanda, but not a leader. Yes, Gonzales and his team stole and sold the data of tens of millions of credit cards, but, as emphasized in the memorandum, “ Seleznev, although not so fruitful, was much more significant and long-term impact on the carding community than Gonzales.”
However, there are serious inconsistencies in the prosecutor's memorandum. For example, the prosecutors presented the court that in September 2009, Seleznev created the sites of Track2 and Bulba, designed for automated trade in stolen data from credit cards. These sites were rapidly gaining popularity, daily they began to use up to 25 thousand carders from around the world. For example, on one of the April days of 2011, TRACK2 was placed for the sale of about a million Dumps (that is, data from the kidnapped cards), and this happened a few weeks after the Washington’s western district against Roman Seleznev was incorrectly made in the hacker penetration of cash register terminals of stores, restaurants and bargains along the whole The territory of the United States from October 2009 to February 2011.
But here's what is interesting: in the American press, a man who exposed Seleznev is called special agent Robert Kirestead. Kirsted was transferred to the US Secret Service Electronic Crimes Crimes Task Force Cybercrime Cybercrift Service in May 2007 (before transferring Kirsteda worked in units engaged in security of the US President). Seleznev was already taken to the US territory, when in the American media the information leaked that back in March 2011, Kirstead presented the leadership of a report in which he cited irrefutable evidence that Roman Valerievich Seleznev was standing behind thefts of these credit cards. And on the basis of the information obtained by Kirstead, at the same time, in March 2011, in the Western district of Washington against Roman Seleznev, charges of hacker penetration into the cash register terminals were made in absentia.
We compare this information with the approval of Set Wilkinson and Norman Barbosa, stated in the memorandum that by May 2009 the FBI had sufficient reasons to consider Seleznev one of the collapses of cybercrime. And these grounds were so serious that the FBI and Secret Service officers fleeed urgently to Moscow.
And what happens? Already in May 2009, the FBI knew that Seleznev was the leader of the cybercriminal world, but at the same time take some serious measures to detain Seleznev FBI only in the spring of 2011. In April 2011, for example, the court received a request to send the search documents for Seleznev to South Korea, in January 2012 petitions were received to send similar documents to Indonesia and Thailand. That is, the FBI was known that Seleznev regularly performs air travel to certain countries under his own name, and the US intelligence services had the opportunity to get a hacker much earlier and in a much more legal way than de facto abducting him at Male Airport?
In fact, the FBI began to throw courts with petitions for arrest orders in different parts of the planet after the name of Roman Seleznev fell into the pages of the world media-as a victim of the terrorist attack in the Moroccan city of Marrakesh.
On April 28, 2011 Seleznev and his wife rested in the popular Argan cafe in the very center of Marrakesh at the very moment when the explosion thundered there. 16 people died, but the novel survived, having received very serious injuries. The Seleznev, who was in the Comes, was delivered to Russia with a special sample.
Initially, the version was put forward that the explosion occurred as a result of gas leakage. But later information appeared: two bombs were laid in the cafe with the help of a mobile phone. The Moroccan authorities had to admit that it was a terrorist attack. Soon the customer was also named-Al-Qaeda. Surprisingly, al-Qaeda, willingly taking responsibility for terrorist attacks around the world, has disowned this explosion.
The investigation promptly established the performers, and exactly six months later, on October 28, 2011, the Moroccan court sentenced Adil al-Atmani to the death penalty, which, according to the investigation, laid bombs in the cafe and put them into effect. The accomplice of Al-Atmani-someone Hakim yes-received a life imprisonment, even seven were sentenced to minor terms.
While sentences were sentenced to Morocco, in Russia doctors fought for the life of Roman Seleznev, who underwent several complex operations. The treatment and restoration of the novel lasted a long time. Only a year later he was able to start talking again and move independently. But all this time, while he was chained to bed, the FBI threw the US courts with petitions for the arrest of the novel.
Well, when Seleznev was still delivered to the United States, he was kept in a single chamber for a long time. And when he was transferred to the general, he had killers and rapists in his neighbors, who constantly provoked fights, and Roman was returned to a “loner”.
Today, when it is already known that in March 2011, the Western District Court of Washington issued a Seleznev arrest warrant, and literally a few weeks later, in April, at the site controlled by him, more than a million Damps, explosions in the Marrakesh cafe, thundered on April 28, 2011, look like a purposeful attempt, and not a terrorist attack. As one of my interlocutors suggested, it is possible that the goal was Roman Seleznev, whom the FBI “Velo” since 2009 and who, perhaps, somehow gained access to too explosive information.
Today it is no secret that the special services of countries that are seriously related to cyberspace are actively recruiting talented hackers to work in the “interests of the state”, and the civilian affiliation of a specialist in this case does not matter.
For example, a massive cyber attack on American computer networks, which occurred in 1999 after the US Air Force Air Force, was well known, when the Chinese Embassy was destroyed as a result of a “fatal mistake”. The same powerful cyberataka in the United States was produced by Chinese hackers in 2001 after a collision of the US intelligence aircraft with a Chinese fighter. In 2003, Hackers from China conducted the Titan Rain operation, attacking the computer resources of the US Department of Defense.
In the computer world, the Chinese hacker group of NCPH is well known, which created dozens of programs using spaces in Microsoft Office, to introduce viral subprograms into the system that allow you to remotely control infected computers, copy the necessary documents and transmit them to the desired address.
And NCPH is not the only hacker group acting in the interests of China. Similar groups in the Middle Kingdom are dozens.
The hacker groups leading local cyberwains are well known in the computer world. Hackers from Greece traditionally exchange strikes with hackers from Turkey. Pakistani hackers strike at the computer systems of India, and Indian, on the contrary, in the Pakistani ...
Often, cooperation turns into the fact that hackers and employees of the Sveslub “lose their shores” and begin to act together in their personal interests. A striking example of such a criminal “cooperation” is the Chatei Case, when cybercriminals specializing in hacking electronic mailboxes, finding themselves under the patronage of the officers of the FSB information security center, began to put the contents of the correspondence of the correspondence of Russian political and economic bomonds for sale.
The “roofing” of cybercriminals officers of specials are not a unique phenomenon inherent only in Russia. Similar stories are periodically opened in the United States. For example, several years ago, the SECRET SERVICE agent Sean Bridges, who investigated the activities of the underground bitcoin market, Silk Road, received worldwide fame. Going on the trail of Cyberbanda, Bridges took the criminals under his patronage and, as a result of only two cyber attacks, received his share of bitcoins worth about 800 thousand dollars, which he cleverly cashed ....
It is quite obvious that Seleznev was not a cybercriminal acting alone. He had accomplices around the world. And in contact with “partners”, for example, in the USA, he could accidentally find out about who “roofs” them. And this is, apparently, not about the “infantry” of the cybercrime world, but about characters who can turn the largest “operations”. And that is why the FBI was seriously alarmed. And even made contact with the FSB.
One of my interlocutors put forward this version:
- I drew attention for a long time: no matter how many carders, spammers, hounds, mailboxes and other cyber -wisdoms are arrested, have never seen information about the arrest of software developers, software, those who carry out the maintenance of hacking or abduction products. Nobody knows developers, they do not appear on the forums of carders or spamers. But 90% of all hacks are based on the vulnerability of programs. Cybercriminals find “holes” in software, and through them they drag everything that lies badly. При этом если внимательно прочитать, например, публикации Брайана Кребса, считающегося ведущим экспертом, выстраивается примечательная картина. Львиная доля жертв кардеров — это граждане США. В России и Европе данные кредитных карточек воруют на порядок меньше. А в США ущерб от этих преступлений исчисляется миллиардами долларов. Но что интересно, ни одно из раскрытых преступлений кардеров не было до конца расследовано. В тюрьмы попадали лишь исполнители, а вот те, кто сливал информацию о «дырах» или вовсе предоставлял софт, всегда оставался в тени.
— Роман Селезнев — очень умный парень, — продолжил мой собеседник. — Он мог как-то напрямую работать с кем-то из разработчиков софта. И «догадаться» о покровителях или, как говорят у нас, «крыше» своего партнера.
Это версия вполне рабочая, и с учетом того, что, судя по материалам суда над Селезневым, он сканировал по определенному алгоритму сервера платежных терминалов магазинов, кафешек, пиццерий, а когда находил открытые, вставлял туда троян и скачивал данные.
— Вообще-то это полнейший бред, — убежден мой собеседник. — Тем более что Селезнев якобы умудрялся опустошать одни и те же платежные терминалы по несколько раз за полтора года. Это просто нереально, потому что специалисты MasterCard или Visa автоматически увидели бы, что по одним и тем же терминалам идет хищение данных. Ну это все равно что охрана знает про дыру, через которую воры проникают на склад, но дыру не заколачивают, а, возможно, даже на шухере стоят. И можно предположить, что Селезневу стало что-то известно.
В эту версию вписывается и ограбление Селезнева, произошедшее вскоре после визита в Москву сотрудников американских спецслужб и их общения с коллегами из ФСБ. Незадолго до оглашения приговора Селезнев написал несколько писем, адресованных суду. В одном из них был рассказ о том, что в дом Селезнева ворвались грабители, пытали его, а уходя, забрали не только деньги и ценности, но и всю компьютерную технику, в которой были все пароли, коды доступа к софтам и программам. Кто мог ограбить Селезнева? Конечно, это могли бы быть и банальные бандиты. Но с учетом того, что преступников куда больше интересовали компьютеры и ноутбуки, нельзя исключить, что под камуфляжем грабителей к Селезневу наведались сотрудники какой-то из спецслужб.
PS
«Новая» продолжает расследование, пытаясь разобраться в истинной подоплеке и «дела Селезнева», и череде громких арестов последних лет. Мы обратились к нашим зарубежным коллегам, прежде всего в США, с предложением подключится к этой работе.