{"id":24370,"date":"2024-04-22T13:17:04","date_gmt":"2024-04-22T21:17:04","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2024\/04\/22\/news-18100\/"},"modified":"2024-04-22T13:17:04","modified_gmt":"2024-04-22T21:17:04","slug":"news-18100","status":"publish","type":"post","link":"https:\/\/www.palada.net\/index.php\/2024\/04\/22\/news-18100\/","title":{"rendered":"Russian FSB Counterintelligence Chief Gets 9 Years in Cybercrime Bribery Scheme"},"content":{"rendered":"<p><strong>Credit to Author: BrianKrebs| Date: Mon, 22 Apr 2024 20:07:56 +0000<\/strong><\/p>\n<p>The head of counterintelligence for a division of the Russian <strong>Federal Security Service<\/strong> (FSB) was sentenced last week to nine years in a penal colony for accepting a USD $1.7 million bribe to ignore the activities of a prolific Russian cybercrime group that hacked thousands of e-commerce websites. The protection scheme was exposed in 2022 when Russian authorities arrested six members of the group, which sold millions of stolen payment cards at flashy online shops like <strong>Trump&#8217;s Dumps<\/strong>.<\/p>\n<div id=\"attachment_39492\" style=\"width: 760px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" aria-describedby=\"caption-attachment-39492\" decoding=\"async\" class=\" wp-image-39492\" src=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2017\/05\/trumpsdumps-580x395.png\" alt=\"\" width=\"750\" height=\"511\" srcset=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2017\/05\/trumpsdumps-580x395.png 580w, https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2017\/05\/trumpsdumps-768x524.png 768w, https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2017\/05\/trumpsdumps-940x641.png 940w, https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2017\/05\/trumpsdumps.png 1295w\" sizes=\"auto, (max-width: 750px) 100vw, 750px\" \/><\/p>\n<p id=\"caption-attachment-39492\" class=\"wp-caption-text\">A now-defunct carding shop that sold stolen credit cards and invoked 45&#8217;s likeness and name.<\/p>\n<\/div>\n<p>As <a href=\"https:\/\/therecord.media\/former-fsb-officer-sentenced-russia-helping-hackers\" target=\"_blank\" rel=\"noopener\">reported<\/a> by <em>The Record<\/em>, a Russian court last week sentenced former FSB officer <strong>Grigory Tsaregorodtsev<\/strong> for taking a $1.7 million bribe from a cybercriminal group that was seeking a &#8220;roof,&#8221; a well-placed, corrupt law enforcement official who could be counted on to both disregard their illegal hacking activities and run interference with authorities in the event of their arrest.<\/p>\n<p>Tsaregorodtsev was head of the counterintelligence department for a division of the FSB based in Perm, Russia. In February 2022, Russian <a href=\"https:\/\/krebsonsecurity.com\/2022\/02\/russian-govt-continues-carding-shop-crackdown\/\" target=\"_blank\" rel=\"noopener\">authorities arrested six men in the Perm region<\/a> accused of selling stolen payment card data. They also seized multiple carding shops run by the gang, including <strong>Ferum Shop<\/strong>, <strong>Sky-Fraud<\/strong>, and <strong>Trump&#8217;s Dumps<\/strong>, a popular fraud store that invoked the 45th president\u2019s likeness and promised to &#8220;make credit card fraud great again.&#8221;<\/p>\n<p>All of the domains seized in that raid were registered by an IT consulting company in Perm called <strong>Get-net LLC<\/strong>, which was owned in part by <strong>Artem Zaitsev<\/strong> &#8212; one of the six men arrested. Zaitsev reportedly was a well-known programmer whose company supplied services and leasing to the local FSB field office.<span id=\"more-67255\"><\/span><\/p>\n<div id=\"attachment_58442\" style=\"width: 759px\" class=\"wp-caption aligncenter\"><img aria-describedby=\"caption-attachment-58442\" decoding=\"async\" loading=\"lazy\" class=\" wp-image-58442\" src=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2022\/02\/deptk-td.png\" alt=\"\" width=\"749\" height=\"483\" \/><\/p>\n<p id=\"caption-attachment-58442\" class=\"wp-caption-text\">The message for Trump&#8217;s Dumps users left behind by Russian authorities that seized the domain in 2022.<\/p>\n<\/div>\n<p>Russian news sites report that Internal Affairs officials with the FSB grew suspicious when Tsaregorodtsev became a little too interested in the case following the hacking group&#8217;s arrests. The former FSB agent had reportedly assured the hackers he could have their case transferred and that they would soon be free.<\/p>\n<p>But when that promised freedom didn&#8217;t materialize, four the of the defendants pulled the walls down on the scheme and brought down their own roof. The FSB arrested Tsaregorodtsev, and seized $154,000 in cash, 100 gold bars, real estate and expensive cars.<\/p>\n<p>At Tsaregorodtsev&#8217;s trial, his lawyers argued that their client wasn&#8217;t guilty of bribery per se, but that he did admit to fraud because he was ultimately unable to fully perform the services for which he&#8217;d been hired.<\/p>\n<p>The Russian news outlet <em>Kommersant<\/em> reports that all four of those who cooperated were released with probation or correctional labor. Zaitsev received a sentence of 3.5 years in prison, and defendant <strong>Alexander Kovalev<\/strong> got four years.<\/p>\n<p>In 2017, KrebsOnSecurity <a href=\"https:\/\/krebsonsecurity.com\/2017\/05\/trumps-dumps-making-dumps-great-again\/\" target=\"_blank\" rel=\"noopener\">profiled Trump&#8217;s Dumps<\/a>, and found the contact address listed on the site was tied to an email address used to register more than a dozen domains that were made to look like legitimate Javascript calls many e-commerce sites routinely make to process transactions &#8212; such as &#8220;js-link[dot]su,&#8221; &#8220;js-stat[dot]su,&#8221; and &#8220;js-mod[dot]su.&#8221;<\/p>\n<p>Searching on those malicious domains revealed <a href=\"https:\/\/web.archive.org\/web\/20161114152809\/https:\/\/www.riskiq.com\/blog\/labs\/magecart-keylogger-injection\/\" target=\"_blank\" rel=\"noopener\">a 2016 report from RiskIQ<\/a>, which shows the domains featured prominently in a series of hacking campaigns against e-commerce websites. According to RiskIQ, the attacks targeted online stores running outdated and unpatched versions of shopping cart software from <strong>Magento<\/strong>, <strong>Powerfront<\/strong> and <strong>OpenCart<\/strong>.<\/p>\n<p>Those shopping cart flaws allowed the crooks to install &#8220;web skimmers,&#8221; malicious Javascript used to steal credit card details and other information from payment forms on the checkout pages of vulnerable e-commerce sites. The stolen customer payment card details were then sold on sites like Trump&#8217;s Dumps and Sky-Fraud.<\/p>\n<p><a href=\"https:\/\/krebsonsecurity.com\/2024\/04\/russian-fsb-counterintelligence-chief-gets-9-years-in-cybercrime-bribery-scheme\/\" target=\"bwo\" >https:\/\/krebsonsecurity.com\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2017\/05\/trumpsdumps-580x395.png\"\/><\/p>\n<p><strong>Credit to Author: BrianKrebs| Date: Mon, 22 Apr 2024 20:07:56 +0000<\/strong><\/p>\n<p>The head of counterintelligence for a division of the Russian Federal Security Service (FSB) was sentenced last week to nine years in a penal colony for accepting a USD $1.7 million bribe to ignore the activities of a prolific Russian cybercrime group that hacked thousands of e-commerce websites. The protection scheme was exposed in 2022 when Russian authorities arrested six members of the group, which sold millions of stolen payment cards at flashy online shops like Trump&#8217;s Dumps.<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10643,10642],"tags":[16740,24911,31301,31302,24915,24916,31303,16696,24918,12377,17006],"class_list":["post-24370","post","type-post","status-publish","format-standard","hentry","category-independent","category-krebs","tag-a-little-sunshine","tag-alexander-kovalev","tag-artem-zaitsev","tag-federal-security-service-fsb","tag-ferum-shop","tag-get-net-llc","tag-grigory-tsaregorodtsev","tag-neer-do-well-news","tag-sky-fraud","tag-trumps-dumps","tag-web-fraud-2-0"],"_links":{"self":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/24370","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=24370"}],"version-history":[{"count":0,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/24370\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=24370"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=24370"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=24370"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}