{"id":15336,"date":"2019-05-16T10:45:15","date_gmt":"2019-05-16T18:45:15","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2019\/05\/16\/news-9085\/"},"modified":"2019-05-16T10:45:15","modified_gmt":"2019-05-16T18:45:15","slug":"news-9085","status":"publish","type":"post","link":"https:\/\/www.palada.net\/index.php\/2019\/05\/16\/news-9085\/","title":{"rendered":"Goznym Takedown Shows the Anatomy of a Modern Cybercriminal Supply Chain"},"content":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/media.wired.com\/photos\/5cdcad8abaf0a36e85079bd5\/master\/pass\/Security-Cybersecurity-Europol%20HQ-184304110.jpg\"\/><\/p>\n<p><strong>Credit to Author: Andy Greenberg| Date: Thu, 16 May 2019 15:58:33 +0000<\/strong><\/p>\n<p><span class=\"lede\">For decades, the <\/span>security industry has warned that <a href=\"https:\/\/www.wired.com\/story\/fin7-wild-inner-workings-billion-dollar-hacking-group\/\">the cybercriminal economy<\/a> has been developing its own highly specialized, professional supply chain. But only when law enforcement tears the lid off a well-honed hacker operation\u2014as they did today with the global Goznym malware crew\u2014does the full picture of every interlinked step in that globalized crime network come into focus.<\/p>\n<p>On Thursday, police in six countries along with the US Justice Department and Europol announced the takedown of Goznym\u2014linked with another operation known as <a href=\"https:\/\/www.wired.com\/2016\/12\/took-4-years-take-avalanche-huge-online-crime-ring\/\">Avalanche, an associated cybercrime operation that was largely dismantled in 2016<\/a>\u2014including the arrest of five of its members across Bulgaria, Georgia, Moldova, and Ukraine. Five more alleged members remain at large in Russia. In total, the operation infected 41,000 computers with fraud-focused malware, and attempted to steal $100 million from victims in the US, though it&#x27;s not clear exactly how much of that theft they successfully pulled off.<\/p>\n<p class=\"paywall\">Speaking at a press conference at Europol&#x27;s headquarters in the Hague, global law enforcement hailed the arrests as an &quot;unprecedented&quot; example of international cooperation. But the indictment also details just how distributed and specialized the tasks of profit-focused hackers have become, composed largely of loosely associated freelancers, each responsible for a single step in the exploitation of victims. &quot;You look at what happened here. What was Goznym? What was Avalanche?&quot; asked Steven Wilson, the head of the European Cybercrime Centre. &quot;This was a supermarket of cybercrime services. You&#x27;re looking at coders, malware developers, bulletproof hosters, a whole range of cybercrime services.&quot;<\/p>\n<p class=\"paywall\">The indictment lays out that long chain of cybercrime specialists:<\/p>\n<p class=\"paywall\">Despite law enforcement&#x27;s description at times of the Goznym operation as a unified crew, most of those defendants seem to have worked as freelancers who offered their services on Russian-language cybercrime forums. &quot;The Goznym network was formed when these individuals were recruited from these online forums and came together to use their specialized skills in furtherance of the conspiracy,&quot; FBI special agent Robert Allan Jones said in the press conference. The group appears to have coordinated their activities over online chat.<\/p>\n<p class=\"paywall\">The globalized nature of that loose network required an equally global sort of cooperation among police and prosecutors across a half-dozen countries, sharing evidence and synchronizing arrests, according to Eurojust official Gabriele Launhardt. &quot;This kind of international cooperation is perhaps unprecedented. This is a sign that judiciary and police can and will always cope with however big a cybercrime organization can be, bringing down its infrastructure,&quot; Launhardt said. &quot;To sum up, criminals cooperate across borders, and we will do the same, so no one escapes justice.&quot;<\/p>\n<p class=\"paywall\">Left unspoken in those remarks about global coordination, of course, is that fully half of the defendants in the case <em>have<\/em> in fact escaped justice\u2014in Russia, one country that doesn&#x27;t seem to have cooperated at all in the investigation. As global as cybercrime crackdowns have become, the cybercriminals themselves remain more global still. And some hide behind borders where Western law enforcement still can&#x27;t reach.<\/p>\n<p><iframe loading=\"lazy\"  src=\"https:\/\/www.documentcloud.org\/documents\/600 width=\"100%\" height=\"420\" frameborder=\"0\" ><\/iframe> <\/p>\n<p class=\"related-cne-video-component__dek\">Jonna Mendez, former CIA Chief of Disguise, takes a look at spy scenes from a variety of television shows and movies and breaks down how accurate they really are.<\/p>\n<p><a href=\"https:\/\/www.wired.com\/story\/goznym-takedown-cybercrime-supply-chain\" target=\"bwo\" >https:\/\/www.wired.com\/category\/security\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/media.wired.com\/photos\/5cdcad8abaf0a36e85079bd5\/master\/pass\/Security-Cybersecurity-Europol%20HQ-184304110.jpg\"\/><\/p>\n<p><strong>Credit to Author: Andy Greenberg| Date: Thu, 16 May 2019 15:58:33 +0000<\/strong><\/p>\n<p>Charges against 10 men across Eastern Europe associated with the Goznym malware crew reveal global law enforcement&#8217;s reach\u2014and its limits.<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10378,10607],"tags":[714,21357],"class_list":["post-15336","post","type-post","status-publish","format-standard","hentry","category-security","category-wired","tag-security","tag-security-security-news"],"_links":{"self":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/15336","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=15336"}],"version-history":[{"count":0,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/15336\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=15336"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=15336"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=15336"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}