"Бдительный подписчик подогнал книгу "Tracers in the dark" о том, как ФБР ловила кардеров, хакеров, криптанов и держателей наркомаркетплейсов. С ней ознакомимся чуть позже, а пока он просил обратить внимание на этот отрезок в тексте:
"When we looked at the platforms that cybercriminals were using to launder their money, it was BTC-e, BTC-e, BTC-e. Gambaryan wondered if BTC-e might even secretly be a CIA honeypot, then dismissed that theory as too absurd"
То есть BTC-e использовалась не только как прокладка для работы RAMP / Hydra, но в первую очередь как своя моечная поляна для хакерских группировок. Из-за чего Тигран Гамбарян (спецагент IRS, и скорее всего, ФБР) даже подумал, что это может быть ханипот, сделанный руками ЦРУ (или общак, сделанный ЦРУ для себя, да?).
"Gambaryan explained what he’d found: The IP address of the person trading stolen Mt. Gox coins on BTC-e matched the IP address of a BTC-e administrator—one with the username WME. So did one of the IP addresses that Gronager had just confirmed. It all supported Gambaryan’s conclusion: Whoever was cashing out Mt. Gox’s 650,000 stolen coins had been running BTC-e. The person profiting from the proceeds of the biggest Bitcoin heist in history and the administrator of the shadiest exchange in operation appeared to be one and the same. And that single enterprising criminal seemed to go by the handle WME. By the next morning, he’d finally made sense of the story in his mind: This person they knew as WME must have been part of a group of hackers who had found a security vulnerability in Mt. Gox in its earliest months online (though Gronager never found out what that entry point might have been). The group had used its access to steal a pile of coins from the exchange. One of them, WME, had cashed those coins in on Trade Hill. But as the group had grown more daring, siphoning out more and more money in the years that followed, they’d become worried about getting caught—especially as WME began to use Mt. Gox itself to exchange stolen funds for dollars after Trade Hill went down. Eventually, the sum of stolen coins had grown so large that WME had made a very bold business decision: He would build his own exchange to cash it out."
Обратите внимание, Гамбарян объявил Винника членом хакерской группировки, ломанувшей Mt.Gox, который потом сливал стыренные биткоины не только на TradeHill, но и на самой Mt.Gox. Ну а раз Винник - член хакгруппы, то оформят его основательно и надолго. Однако возникает вопрос: членом какой группы он являлся? И как тогда та самая группа имела отношение к RAMP и Hydra?
"A Secret Service agent on Gambaryan’s virtual currency-focused team with a particularly good memory recalled that a suspect that went by WME had years earlier been an active “carder,” a cybercriminal focused on stealing and selling credit card information. The agent had looked up the handle in the Secret Service’s broad database of cybercriminal profiles and found a name: Alexander Vinnik."
Сюприз! В базе Secret Service (отвечает в том числе за финансовую безопасность США) Винник числился как активный кардер. То есть не мойщик, не технический член хакгруппы, а непосредственный участник отжатия карт и финсредств у населения.
"WME’s posts had included an email address for further customer support questions at the domain wm-exchanger.com, an abbreviation for WebMoney Exchanger, another business WME had apparently created years earlier.""
* * *
Ссылка для доступа к полной версии Криптокритики: https://t.me/+_TGzke34EfgzZmEy
Post #193
956
- ❤ 1