This is a read-only archive. No new posts or registrations. Privacy Page
Discussion

The Russian Business Network...

5 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

FYI…

- http://www.washingtonpost.com/wp-dyn/conte…1202461_pf.html
October 13, 2007 - "An Internet business based in St. Petersburg has become a world hub for Web sites devoted to child pornography, spamming and identity theft, according to computer security experts. They say Russian authorities have provided little help in efforts to shut down the company. The Russian Business Network sells Web site hosting to people engaged in criminal activity, the security experts say. Groups operating through the company's computers are thought to be responsible for about half of last year's incidents of "phishing" – ID-theft scams in which cybercrooks use e-mail to lure people into entering personal and financial data at fake commerce and banking sites. One group of phishers, known as the Rock Group, used the company's network to steal about $150 million from bank accounts last year, according to a report by VeriSign of Mountain View, Calif., one of the world's largest Internet security firms. In another recent report, the Cupertino, Calif.-based security firm Symantec said that the Russian Business Network is responsible for hosting Web sites that carry out a major portion of the world's cybercrime and profiteering. The company "is literally a shelter for all illegal activities, be it child pornography, online scams, piracy or other illicit operations," Symantec analysts wrote in a report. "It is alleged that this organized cyber crime syndicate has strong links with the Russian criminal underground as well as the government, probably accomplished by bribing officials." The Russian Business Network did not respond to requests for comment… Thomas V. Fuentes, the FBI's assistant director of international operations, declined to answer questions about the Russian Business Network…"

:ph34r:
More…

- http://blog.washingtonpost.com/securityfix…business_n.html
October 13, 2007 - "…It is tough to find a serious cyber-crime attack over the past two to three years that did not involve RBN Internet addresses to some degree. Going back as far as 2004 – when RBN was known variously as "TooCoin Software" and "ValueDot" – the network has offered an affiliate program called "iFramecash," wherein Web site administrators are paid a small sum for each visitor they silently refer to RBN's network. The visitor's machine is then peppered with Trojan horse programs that try to install password-stealing programs. In the past year-and-a-half or so, the main affiliates of that program simply started hacking into legitimate Web sites and placing the redirect code there…"

- http://blog.washingtonpost.com/securityfix…n_business.html
October 13, 2007 - "…Estimates of the number of computers running Microsoft Windows that are currently infected with Storm range from 1 million to 10 million globally, depending on which anti-virus company is doing the estimating. Most infected machines corralled by criminals into "botnets" are used to anonymously relay junk e-mail, or to serve as a conduit for routing stolen financial data back to organized criminals… Attackers typically stitch malicious programs created with Mpack into the fabric of legitimate Web sites that they have hacked. When a visitor arrives at such site with a Web browser that is not equipped with the latest software security updates, the site silently installs a password-stealing program on the visitors computer. The victim's stolen data is then regularly forwarded on to a "drop site" pre-arranged by the attackers – in the case of the Mpack authors, a set of Web servers residing on RBN…"

:thumbdown: :angry:
FYI…

http://preview.tinyurl.com/23bgxp
November 07, 2007 (Computerworld) - "The Russian Business Network (RBN), a notorious hacker and malware hosting organization that operates out of St. Petersburg, Russia, has gone off the air, security researchers said today. According to a pair of Trend Micro Inc. researchers, RBN went dark around 10 p.m. EST Tuesday… By relinquishing control of the IP blocks it had been allocated, RBN essentially cut ties to the Internet and made it impossible for its domains – which number in the thousands – to access the Web or for users to reach those domains. "Where once there might have been 22 feasible paths for data to take to their IP blocks, now there are none," Ferguson said. He speculated that RBN is simply shifting to new digs… The Spamhaus Project antispam group has posted information that indicates RBN may have already laid claim to IP blocks located in China, Shanghai in particular…"

- http://blog.trendmicro.com/rbn-goes-poof/
November 7th, 2007

.
More…

- http://blog.washingtonpost.com/securityfix…twork_down.html
November 7, 2007 - "…Not everyone is willing as yet to attribute the Chinese address registrations to RBN. Matthew Richard, director of the rapid response team for iDefense, a security company owned by Verisign, said it's too soon to draw that connection definitively… The apparent flight of RBN came on the eve of a lengthy cybercrime speech ( http://www.fbi.gov/pressrel/speeches/mueller110607.htm ) by FBI Director Robert Mueller. Speaking at Penn State on Tuesday, Mueller addressed the internationalization of cyber crime and its threat to the political and economic stability of the United States. "Increasingly, cyber threats originate outside of our borders. And as more people around the world gain access to computer technology, new dangers will surface," Mueller said. "The Internet has opened up thousands of new roads for each of us–new ideas and information, new sights and sounds, new people and places. But the invaders–those whose intent is not enlightenment, but exploitation and extremism–are marching right down those same roads to attack us in multiple ways."

.
FYI…

- http://www.theregister.co.uk/2007/11/13/rbn_quits_china/
13 November 2007 - "Infamous cybercrime hosting outfit Russian Business Network (RBN) has disappeared again, days after quitting Russia and setting up shop in China. RBN obtained seven net blocks of Chinese IP addresses. Last Wednesday (8 November), some of RBN's clients began popping up on some of the 5,120 IP addresses it had acquired. But a day later China cut the connection to six of the seven net blocks controlled by RBN, once again forcing it offline. Security researchers at VeriSign iDefense, who have kept a close eye on the cybercrime network's activities, reckon the organisation may break itself up into smaller parts in an effort to make its business less visible. The days of RBM as a monolithic organisation may be numbered. "[A break-up] may keep it under the radar, but it's also more expensive for them, and it's riskier, too, because the more ISPs that it has to deal with, the better the chance that one of those ISPs says 'no' to hosting RBN content and shuts them off," an iDefense analyst told Computerworld*…"
* http://www.computerworld.com.au/index.php/…;16;fpid;1;pf;1

.