Cyber crimes

cyber crimes, internet fraud, cyber security, information security – KeyboardCrime.com

August 27th, 2012

We`ve updated the Underground Activity Index and in its newer version all the statistics are now made on weekly basics. The information for the past 8 weeks will

b

e visible on the charts, all data older than 8 week will be shows in numeric format as archive. We are doing our best to include as many sources, offering data of stolen credit cards for sale, as possible and thus there was a rapid increase in the quantities offered, visible on the first chart, after 16.08.2012. The decline in the quantities a week earlier (09.08.2012) is due to one of the biggest automated shops, for stolen data of cards, being down for few days.

July 20th, 2012

We are happy to announce our Underground Activity Index, you can check the live charts here. The index is going to show the quantities, type, and prices of credit cards bein

g sold in the underground. We are also going to provide our analyses as to trends and changes in the stats, as well as update the stats as often as possible. Please have in mind the Underground Activity Index is still in beta state. Below you can see the charts :

As we can see in our initial report, the cards for sale from the USA are nearly six times more than those from the rest of the world, which indicates the USA appears to be the biggest victim of cyber crimes.


Visa cards are the major type of cards offered for sale in the underground communities, which most likely correlates to the number of cards issued.


There are many determining factors of the price of the cards in the underground.

The simple supply and demand model keeps Visa prices the lowest. Visa, for the past few years, has implemented their “Verified by Visa” security program, which seems to be more prevalent that MasterCard’s Secure Code. This may be a factor in keeping the price lower.

Platinum cards, sold from between $5-25 and as much of $100 if accompanied by a high scored credit report, are excluded from the index.

*The following data set is a sampling collected from various underground web sites. Since these web sites are volatile in nature, the sampling fluctuates.The data pool, in our opinion, is large enough to analyze and derive some empirical evidence to establish trends of cyber crime activity. In no way do we condone illegal activity.

 

July 15th, 2012

title=”AddThis utility frame” name=”_atssh823″ src=”//s7.addthis.com/static/r07/sh090.html#iit=1342374746555&tmr=load%3D1342374746444%26core%3D1342374746463%26main%3D1342374746553%26ifr%3D1342374746555&cb=0&cdn=0&chr=unicode&kw=&ab=-&dh=keyboardcrime.com&dr=&du=http%3A%2F%2Fkeyboardcrime.com%2Fwp-admin%2Fpost-new.php&dt=&md=0&cap=tc%3D0%26ab%3D0&inst=1&irt=0&jsl=12321&lng=en-us&ogt=&pc=men&pub=&ssl=0&sid=5003035a4fe24913&srd=0&srf=0.02&srp=0.2&srl=1&srx=1&ver=250&xck=0&xtr=0&og=&rev=114791&ct=1&xld=1&xd=1″ width=”1″ height=”1″>
Compton rapper Guerilla Black was on the rise in the mid-2000s with the release of his 2005 debut, Guerilla City. While he garnered nationwide recognition and a push from Jive Records, he was meant with resistance, simply because he sounded too much like the late Notorious B.I.G.

Although he’s remained active — releasing a handfull of mixtape, his last being 2009′s The Blacktapes — the rapper has remained under the radar. This week, however, he resurfaced when he made headlines after being arrested for identity theft.

According to the Seattle PD Blotter, the 33-year-old rapper (real name: Charles Tony Williamson) was arrested at his Los Angeles home on Thursday (July 12) on a 22-count indictment that alleges he purchased and used stolen credit/debit card numbers obtained through the computer hacks of two Seattle area businesses — a restaurant in Seattle’s Magnolia neighborhood and a restaurant supply company in Shoreline.

http://www.ballerstatus.com/2012/07/13/compton-rapper-guerilla-black-inducted-arrested-credit-card-scam/

 

 

July 15th, 2012

So who really were the 6,000 members of kurupt who frequented this site starting in Dec 2009 and ending around March 2012? Intrigued, I decided to see what our government had to say about kurupt. Below are the Freedom of Information Act responses

from a few agencies. You decide if it was possible for the US government to claim no knowledge of this site under the FOIA.

FOIA-USSS

FOIA-DOJ

FOIA-Interpol

FOIA-FBI

dansclements@gmail.com

 

 

June 11th, 2012

June 2012

David Schrooten arrives in Seattle on Saturday and makes a court appearance on Monday June 11th. Per the US Attorney, documents claim he ran a ring to distribute stolen credit cards.

In addition to talking to me, he

also had conversations with Brian Krebs.

http://krebsonsecurity.com/2012/06/feds-arrest-kurupt-carding-kingpin/

http://www.king5.com/news/cities/seattle/Dutch-man-indicted-in-Seattle-for-stealing-credit-card-numbers-158482905.html

http://www.ktvu.com/news/ap/crime/dutch-man-charged-with-stealing-wash-credit-cards/nPQ8T/

His next court appearance is Aug 20th.

Dan Clements

*As I’m still developing the Fortezza profile, I’d be appreciative of any information that may help this project. I can be reached confidentially and or anonymously at dansclements@gmail.com

 

May 26th, 2012

rc=”http://keyboardcrime.com/wp-content/uploads/2012/05/1618_0000226148_W75-H100-HA1-VA42.jpg” alt=”" width=”75″ height=”100″ />
 

 

 

 

 

David B. Schrooten aka Fortezza? Xakep? Empirion? Echelon?

May 2012

Another suicide attempt by David was unsuccessful. He says his conditions are deplorable and doesn’t object to being extradited to the the United States. No one is Cluj has any idea why the process to move him to the United States has taken so long.

http://www.citynews.ro/cluj/cautare-taguri/schrooten+david+benjamin/

David did travel to Bucharest in an attempt to get a release in Romania while he awaits extradition. His appeal was denied.

 

Dan Clements

*As I’m still developing the Fortezza profile, I’d be appreciative of any information that may help this project. I can be reached confidentially and or anonymously at dansclements@gmail.com

 

May 26th, 2012

Apr 2012

Apr 27 Update Court

David claims to have co-operated with authorities by giving them his computer and passwords. The judge gives him a conditional release pending extradition because of medical cond

itions. Prosecutors have a short time to appeal.

http://oradecluj.oradestiri.ro/document-hackerul-olandez-a-fost-eliberat-pentru-ca-incercase-sa-se-sinucida-si-din-cauza-conditiilor-din-arestul-politiei-clujene/actualitate/2012/04/27/

 

Apr 25 Court

David questions the EU legal system, claiming he does not have any evidence or charges to respond to. He attempts to take his life because of the deplorable jail conditions.

http://oradecluj.oradestiri.ro/un-hacker-olandez-momit-in-romania-pentru-a-fi-arestat-si-extradat-in-sua-si-a-taiat-venele-in-arestul-politiei-cluj/exclusiv/2012/04/25/

 

Apr 25

You tube video outside court in Cluj Romania

http://www.youtube.com/watch?v=3M7tFDaFIiI

 

Dan Clements

*As I’m still developing the Fortezza profile, I’d be appreciative of any information that may help this project. I can be reached confidentially and or anonymously at dansclements@gmail.com

May 26th, 2012

March 2012

March 29

Schroebel and Schrooten cases related for one trial

It appears many of the indictment charges against Christoph

er and David are similar. These are always intriguing cases since the evidence appears mostly circumstantial. This case may have some common ground with a hacker trial a few years ago in a Seattle. Here”s an exert from an analysis done by Philip Attfield after the USA vs. Gorshkov trial in which the government got a conviction.

5.1 Establishing the link between “digital” and “human” domains

Digital data is not human and bears no relation to the entity or human that might have

caused their creation – there are no human fingerprints in cyberspace. The primary strategy

underlying the presentation of computer data and its forensic analysis is to demonstrate a

connection between material from the “digital domain” and the real world where flesh-andbone

humans exist.

The F.B.I. did not witness Mr. Gorshkov typing at the keyboard of “tech.net.ru” in

Chelyabinsk when intrusions took place at computers belonging to the victims associated with

the case. They did however learn first-hand of “tech.net.ru” hacking exploits during the Invita

undercover. They also learned of incidents for which Mr. Gorshkov claimed responsibility.

The trial needed to demonstrate the connection between Mr. Gorshkov’s interview at the

Invita undercover, the data downloaded from “tech.net.ru” and the testimony and data

obtained from victims.

The forensic analysis of the reconstructed “tech.net.ru” and “freebsd.tech.net.ru” systems

showed that somebody (“kvakin”) had knowledge and significant control of those computers.

The keystroke log captured the login of “kvakin” on “tech.net.ru” and “freebsd.tech.net.ru”

during the undercover. Statements made during the Invita undercover in relation to victims

and incidents demonstrated Mr. Gorshkov’s knowledge and involvement. The undercover

keystroke log demonstrated Mr. Gorshkov’s knowledge and control of the digital domain (he

logged into “tech.net.ru” and retrieved novoline online spielen a hacking tool). Forensic analysis of the downloaded

data as well as data obtained from victims strengthened the link between Mr. Gorshkov and

the “tech.net.ru” criminal activities – it placed him within the context of the greater body of

evidence.

 

March 28

Schrooten court docket out

 

March 28

Schrooten indictment out

 

March 21

David B. Schrooten, alledged to be Fortezza, Xakep, Empirion, and Echelon arrested in Cluj Romania.

http://www.adevarul.ro/locale/cluj-napoca/Un_olandez_care_a_pagubit_americanii-arestat_la_Cluj_0_667733660.html

 

March 13 IM

David is feeling pressure and says he”s heading to Romania.

Xakep: my american friend will probably become hot news
Xakep: sooner or later in your country
Xakep: he already was last year
anondis5: if”s he”s targeted, yes.
Xakep: but yes
Xakep: i admit
Xakep: i”m lost
Xakep: :)
anondis5: is it Interpol or USSS?
Xakep: united states secret service
Xakep: and fbi
Xakep: he told me fbi sucked
Xakep: but secret service was good
anondis5: well..those agencies compete a bit.
anondis5: both have specific agenda”s to cuff u
Xakep: i know
Xakep: i talked with tinkode
Xakep: before he got arrested
Xakep: literally 24 hours
Xakep: before his arrest lol
Xakep: i talked with so many people that are being extradited to usa
Xakep: my nickname is probably all over them
anondis5: which nik?
Xakep: Fortezza
anondis5: why did u pick that name? and echelon?
Xakep: :)
Xakep: Why do you think
anondis5: I”m asking u :)
Xakep: :)
Xakep: You know
Xakep: the meaning of those names
anondis5: more or less

This was the first time the name Fortezza was ever mentioned. It”s still not a 100% confirmation as many of the admin posts signed by Fortezza at kurupt.su were written by multiple people.

 

Dan Clements

*As I”m still developing the Fortezza profile, I”d be appreciative of any information that may help this project. I can be reached confidentially and or anonymously at dansclements@gmail.com

 

 

May 26th, 2012

Dec 2011

Dec 7

Christopher Schroebel Indictment

Buy Cialis Online Without Prescription-sn

No prescription cialisapshot2.jpg”>

 

 

 

 

 

 

 

Late Dec

Fortezza resigns as admin at kurupt.su.

Dec 17 IM with Fortezza

On being outted:

Xakep: besides i am not active
Xakep: valvontaa should XXX his brothers donmagic XXXX
Xakep: idiots
Xakep: i am not active anymore
On his enemies:

Xakep: i dont fuck normal people
Xakep: i eat hackers
Xakep: and carders :)

On talking to the press:

Xakep: i can give you one hell of a story
Xakep: i have backups
Xakep: of every major carder forum

On carding:

Xakep: I am not carder
Xakep: note that please
Xakep: i am interested in the internet underground
Xakep: too interested :)

On legit work:

Xakep: but i have to be honest with you
Xakep: this is taking a lot of interest
Xakep: would be interesting to make a legit living
Xakep: of investigating fraud
Xakep: and new methods, and solving problems

 

Dec 11

Fortezza is outed as “David Schrooten” with posts at kurupt.su and kurupt.ru. A lot of infighting is going on between these sites. If these were real hackers, would they really be taking risks of outing each other? Or are they just amateurs whose ego’s have run amok?

These name changes are interesting. Could they be different federal agents taking over a new nik? Or does the hacker remove some risk by starting a new nik and giving others access to it’s use?

Fortezza changes nik to Xakep.

Echelon changes nik to Fortezza.

Others think Fortezza is LE.

Dan Clements

*As I’m still developing the Fortezza profile, I’d be appreciative of any information that may help this project. I can be reached confidentially and or anonymously at dansclements@gmail.com

 

 

May 26th, 2012

Nov 2011

After two attempts to reach Fortezza via PM in kurupt.su, in which he banned my login twice, I decided to try and approach him thru his ISP promtheus.org.ua A few days after sending an email, I get a response from Venc

elj Krnjovąek, telling me they have control of about ten sites frequented by the underground and seemingly have access to lots of intelligence and possibly data. After an email exchange, I give him my IM address.

On Nov 7th, I get an IM from Xakep. He’s checking me out and vice versa. My situation has been an open book for 14 years and he can see my bio at my website. I on the other hand have no idea who is behind this nik. My agenda, as clearly stated in the email, is to try and retrieve lost data or IP for clients. We both probably believe each other is law enforcement. But as we feel each other out, a slow trust seems to form. Here are a few exerts from our chat:

On helping us find LOST items:

“I am not talking about the low level stuff, I am talking about 50.000 dumps per week, and 30.000 cc’s per week”

On RSA:

“I am having problems with RSA, they wrote articles about me already before”

On Interpol:

“i got several reports of interpol hacked Clearance Level TSecret and Confidential”

On Wikileaks:

“I don’t like wikileaks or lulzsec or anonymous or anything in that area”

On notoriety:

” i have been on bbc before as well always my nicknames french television german television lol”

 

He did state he likes to hack other cybercrime sites and would like to help American companies get their property back. No way to tell how sincere he really is at this point.

 

Nov 21, 2011 Christopher Schroebel aka “Pookie” arrested

http://www.seattlepi.com/local/article/Prosecutors-Hacker-traded-Seattleites-stolen-2403725.php

As I will come to find out at a later date, Christopher Schroebel and David Scrhooten were friends.

Dan Clements

*As I’m still developing the Fortezza profile, I’d be appreciative of any information that may help this project. I can be reached confidentially and or anonymously at dansclements@gmail.com