The Hidden History of CyberCrime Forums

The notorious dark web marketplaces Alphabay and Hansa were shut down in July following "landmark" action by police forces in the US and Europe to unmask who was running them.

They join a long list of other forums, chat rooms and boards that appeared and were blazingly popular with the criminal underworld before they were compromised and closed. But those sites, including Dark Market, Carders Market, Shadow Crew, Carder.su, Darkode, GhostMarket and the Silk Road, have more in common than just the trajectory of their genesis and demise.

They all follow the modus operandi of a landmark forum set up in 2001 called Carder Planet. Designed for criminals who specialised in monetising lists or "dumps" of credit card numbers, it has had an influence far beyond that select group.

"Carder Planet created the framework for the current criminal underground," said Andrei Barysevich, now a director at security firm Recorded Future but who, at the time the site operated, was helping to monitor cyber-crime in Eastern Europe.

Expert View

The site was set up online shortly after a face-to-face meeting at a restaurant in Odessa attended by some of Ukraine and Russia's top credit card thieves, said Mr Barysevich.

"Odessa was, and still is, the ground zero for cyber-crime," he said. "It is a very criminalised city and a centre of white collar crime."

Before Carder Planet was set up, anyone who wanted to make money from stealing card numbers had to be a jack of all trades, said Liam O'Murchu, a researcher at Symantec who has spent years tracking online crime forums.

Not only did they have to find ways to steal the card numbers, often involving malware or hacking, they also had to work out how to turn those numbers into cash and not get caught.

"What they decided to do was pool everyone's resources, so they did not have to be perfectly skilled in everything in order to be able to do crime," he said.

"They set up the forum where people could come together and trade skills and nobody had to be an expert in the entire chain from beginning to end," said Mr O'Murchu.

The site proved an immediate success and soon had thousands of members all busily trading with each other.

"They got so blasé and so sure of themselves that they organised the first real life meet-up of Carder Planet members," said Mr Barysevich. "Forum members were invited to a resort outside Odessa where they hung out together.

"They had good food, drink and girls and had a pretty good time," he said.

It was not only the attendees who enjoyed themselves. The police did too because news about the conference, as well as pictures of attendees, were leaked to the authorities. It was the first time that many of the cyber-thieves had been photographed and the images were widely studied, he said.

Shopping Growth

Despite the attention, Carder Planet kept going and enjoyed significant success, said Dmitri Alperovitch, co-founder of CrowdStrike and a veteran cyber-crime researcher, who has helped to track down and expose some of its key members.

"It was the right place at the right time," he said. "You had a lot of smart folks in Russia and Ukraine at the time and you had the proliferation of the internet in those days in the former Soviet Union and the economy was doing very, very poorly."

Given that, he said, it was not surprising that those with technical skills and nothing legitimate to do with them turned to crime.

Coupled with this was the rise of online shopping in the US, much of which was powered by people using credit cards. Unfortunately, many of the firms setting up online were better at selling than security, meaning the thieves were regularly able to steal large amounts of card numbers.

Mr Alperovitch said the board explicitly modelled itself on more traditional organised crime groups - specifically the Italian mafia.

Occasional contributors were called "soldiers" and the more someone got involved the higher up the ranks they rose. At the top, he said, were the "dons" and "capos" who ran the biggest scams and collected financial tributes from the people they set working on them.

He said it was also a board on which reputation mattered a lot - a trait seen on many other criminal forums ever since.

Before any criminals worked together they looked for "vouches" - essentially personal recommendations from other thieves about whether someone was trustworthy or not. Without those endorsements a collaboration between say a spammer and a malware writer was unlikely to get started. Anyone with a persistently bad reputation would find that no-one would work with them.

Carder Planet was shut down voluntarily by its creators in 2004 - largely to avoid the fate of other boards, many of which were compromised by police and used to gather intelligence about members.

Many of its members did keep on stealing cards and some of them, notably Roman Vega (aka Boa) and Vladislav Horohorin (aka Badb), have been tracked down and arrested.

Those arrests were a consequence of the open atmosphere on Carder Planet, said Mr Alperovitch.

"They've realised they were quite naive about law enforcement engagement and they did not realise that law enforcement was paying very close attention," he said.

BBC

You Might Also Read:

What Is Selling On the Dark Net?:

International Police Start Crackdown On The Darknet:

« Banks Join Forces to Fight CyberCrime
Get Your Data Strategy On Board »

Infosecurity Europe
CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

Jooble

Jooble

Jooble is a job search aggregator operating in 71 countries worldwide. We simplify the job search process by displaying active job ads from major job boards and career sites across the internet.

North Infosec Testing (North IT)

North Infosec Testing (North IT)

North IT (North Infosec Testing) are an award-winning provider of web, software, and application penetration testing.

Syxsense

Syxsense

Syxsense brings together endpoint management and security for greater efficiency and collaboration between IT management and security teams.

IT Governance

IT Governance

IT Governance is a leading global provider of information security solutions. Download our free guide and find out how ISO 27001 can help protect your organisation's information.

XYPRO Technology

XYPRO Technology

XYPRO is the market leader in HPE Non-Stop Security, Risk Management and Compliance.

ACIS Professional Center

ACIS Professional Center

ACIS provides training and consulting services in the area of information technology, cybersecurity, IT Governance, IT Service management, information security and business continuity management.

ITpreneurs

ITpreneurs

ITpreneurs provides IT training content, Instructors, Learning Infrastructure and services to IT Training providers.

44CON

44CON

44CON is an Information Security Conference & Training event taking place in London. Designed to provide something for the business and technical Information Security professional.

ISACA

ISACA

ISACA is a global professional association and learning organization for members who work in information security, governance, assurance, rissk and privacy.

Rackspace Technology

Rackspace Technology

Rackspace Technology is a leading provider of managed services across all major public and private cloud technologies. Secure your IT environments with powerful cloud security solutions and support.

Gigasoft

Gigasoft

Gigasoft provide secure online data backup & cloud backup services for the education sector and businesses.

TÜV Informationstechnik (TÜViT)

TÜV Informationstechnik (TÜViT)

TÜViT is a leading service provider in the IT sector offering unbiased and independent tests and certifications of IT products, hardware, software, systems and processes.

SecuLution

SecuLution

SecuLution is an Antivirus product using Application Whitelisting which offers much more protection than Virus Scanners ever can.

Infortec

Infortec

Infortec provide consultancy and solutions for the protection of digital information and the management of computer resources.

TROOPERS

TROOPERS

TROOPERS InfoSec event consists of two days of high-end training, followed by a two-day, three-track conference, culminating in Roundtables on the final day.

Cyphra

Cyphra

Cyphra’s team provide cyber security consulting, technical and managed services expertise and experience to support your organisation.

Netlinkz

Netlinkz

Netlinkz has developed the Virtual Secure Network (VSN) overlay technology platform, a breakthrough in connectivity security, speed, and simplicity.

National Academy of Cyber Security (NACS) - India

National Academy of Cyber Security (NACS) - India

National Academy of Cyber Security provides Professional Training Courses and Programmes in Cyber Security.

Concourse Labs

Concourse Labs

Concourse Labs Security Guardrails continuously verify cloud infrastructure and workloads. Continuously assess clouds for security, resiliency, and regulatory compliance.

Cloudaeris

Cloudaeris

Cloudaeris is a trusted Microsoft Partner, and we've got what it takes to make your business more efficient and agile.

Sasken Technologies

Sasken Technologies

Sasken’s Cybersecurity Services enables enterprises to develop, maintain, and take digital products to the market with security postures that empower operational excellence.