Pittsburgh Post-Gazette

Hacker site busted here

Pittsburgh FBI office leads internatio­nal investigat­ion of illicit website used to traffic informatio­n and data for cybercrime­s

- By Rich Lord

Nobody got into Darkode.com without references.

It took even more credibilit­y to move through the online crime bazaar’s “tiers of membership based on knowledge, skill, illegal activity and reputation,” John Lynch, chief of the Department of Justice Criminal Division’s Computer Crime and Intellectu­al Property Section, said Wednesday.

Yet the FBI penetrated Darkode, which led to criminal charges that were unsealed Wednesday, the site’s shutdown and dozens of arrests across the globe, all coordinate­d from Pittsburgh.

The Darkode takedown was different from last year’s big cyber indictment­s, in which some of the victims were local, but the accused were (and probably still are) in Russia and China.

This time one of the accused, a Churchill man, is local, and some 28 others were under arrest Wednesday, charged in courts ranging

from Louisiana to Romania. And like most cyber busts, the Darkode bust involved technology — but it also took old-fashioned undercover work.

“The FBI has effectivel­y smashed the hornets’ nest, and we are in the process of rounding up and charging the hornets,” said U.S. Attorney David Hickton. He characteri­zed Darkode as “a crime bazaar for hackers” and the “best malware marketplac­e on the Web.”

Into the Darkode

Darkode was created around 2008 as a haven for the brightest hacking talent in the Western world.

Ads recently posted there showed that the bazaar’s fare included personal informatio­n and the tools for stealing it. One ad offered 23,000 Social Security numbers, with dates of birth, for a few hundred dollars. Another advertised “1 million email + [passwords] (quality).” Credit card numbers, counterfei­t passports, tools for infecting hardware — Darkode had it all, at prices ranging from $100 to $5,000, depending on the extent, quality and freshness of the material.

By 2010, an FBI undercover agent got far enough into Darkode to negotiate with site administra­tor Johan Anders Gudmunds, 27, of Sollebrunn, Sweden, according to the indictment against him. The Swede, in an online chat with the agent, offered to sell access to hacked computer servers.

In a case filed in federal court in Atlanta in 2011, men from Russia and Algeria were accused of using Darkode in a mail fraud scheme, distributi­ng malware called SpyEye, which stole victims’ financial informatio­n.

Officials said the Pittsburgh FBI’s probe into Darkode intensifie­d around 18 months ago, and took the name Operation Shrouded Horizon.

At that time, according to charges, Morgan C. Culbertson, 20, of Churchill, was on Darkode, using the code name Android. He marketed malware called Dendroid, which allowed criminals to remotely manipulate infected cell phones to spy on their owners, according to the charges.

Mr. Culbertson was not indicted, but rather charged through a document called an informatio­n, which usually indicates that the defendant has agreed to plead guilty. He could not be reached for comment.

FBI agents and analysts sorted through mounds of electronic data. Others gathered intelligen­ce on the players, participat­ing in undercover chats in which cyber criminals dropped hints of their identities and physical locations.

When an institutio­n’s credit cards went up for sale on Darkode, or when an actor marshaled forces for a denial-of-service attack against a company, the FBI warned the target.

Pittsburgh led a coalition that started domestical­ly with the bureau’s offices in Washington, D.C., San Diego, New Orleans and San Francisco, and extended to online enforcemen­t teams in 20 countries, including numerous European countries, Israel, Australia, Colombia, Brazil and Nigeria.

The goal, officials said, was not just to pick off a few Darkode merchants, but to pull the weed out, roots and all.

FBI Special Agent in Charge Scott S. Smith said agents “infiltrate­d the undergroun­d criminal forum Darkode at the highest level.”

Down goes Darkode

Starting Monday, a halfdozen Pittsburgh-based agents and analysts worked 24 hours to coordinate the multi-country bust.

Down went Darkode, replaced by a screen featuring the logos of involved law enforcemen­t agencies, and an announceme­nt that it had been “seized by the Federal Bureau of Investigat­ion, Pittsburgh Field Office,” plus Mr. Hickton’s office and Europol.

Mr. Culbertson, Mr. Gudmunds — who was searched and questioned Tuesday — and five others are being prosecuted in Pittsburgh.

Eric L. Crocker, of Binghamton, N.Y., is charged with spamming for using a “Facebook Spreader” program that infected computers via the social networking site, sending messages replete with infectious code to “friends” and creating a “botnet” of infected, remotely manipulabl­e machines.

Two Florida men, Naveed Ahmed, 27, of Tampa, and Dewayne Watts, 28, of Hernando, plus Phillip R. Fleitz, 31, of Indianapol­is, are charged with conspiring to use Darkode and Chinabased computer servers to send millions of spam text messages including links that, if clicked, compromise­d informatio­n stored on victims’ phones.

Indicted for identity theft, and not yet in custody, is Murtaza Saifuddin, 29, of Karachi, Pakistan.

Unlike last year’s Pittsburgh-led indictment­s of five members of the Chinese People’s Liberation Army cyber espionage unit, and of Russian superhacke­r Evgeniy Mikhailovi­ch Bogachev, Darkode will almost certainly lead to conviction­s. That process may enhance federal law enforcemen­t’s understand­ing of the cyber underworld.

The Darkode bust is also billed as the premier effort at internatio­nal cyber crime investigat­ion, building on the usual U.S. and European partnershi­p to add collaborat­ive agencies in Asia, South America, Africa and Australia.

Experts said that coalition couldn’t be emerging at a better time, as American cyber security reels from successful attacks, apparently engineered abroad.

“It’s almost like every day we are hearing about attacks, and every day it’s getting worse and worse,” said Bhavani Thuraising­ham, executive director of the Cyber Security Research Institute at the University of Texas at Dallas.

She hailed Pittsburgh’s ability to build a multi-country coalition to take on Darkode.

“If we can have more countries participat­e and we share informatio­n, I would say that would be a very positive thing.”

 ?? Nate Guidry/Post-Gazette ?? Scott Smith, Pittsburgh FBI Special Agent in Charge, looks on a U.S. Attorney David J. Hickton announced the takedown of the criminal online hacking forum known as Darkode.
Nate Guidry/Post-Gazette Scott Smith, Pittsburgh FBI Special Agent in Charge, looks on a U.S. Attorney David J. Hickton announced the takedown of the criminal online hacking forum known as Darkode.
 ?? Lake Fong/Post-Gazette ?? Agents with FBI Pittsburgh’s cyber squad monitor criminal activities at the National Cyber Forensic and Training Alliance Center in South Oakland.
Lake Fong/Post-Gazette Agents with FBI Pittsburgh’s cyber squad monitor criminal activities at the National Cyber Forensic and Training Alliance Center in South Oakland.

Newspapers in English

Newspapers from United States