Category Archives: Web Fraud 2.0

Reintroducing Scanlab (a.k.a Scamlab)

December 7, 2010

Many sites and services require customers to present “proof” of their identity online by presenting scanned copies of important documents, such as passports, utility bills, or diplomas. But these requests don’t really prove anything, as there are a number of online services that will happily forge these documents quite convincingly for a small fee.

FBI Identifies Russian ‘Mega-D’ Spam Kingpin

December 1, 2010

FBI investigators have identified a 23-year-old Russian man as the mastermind behind the notorious “Mega-D” botnet, a network of spam-spewing PCs that once accounted for roughly a third of all spam sent worldwide.

According to public court documents related to an ongoing investigation, a grand jury probe has fingered Moscow resident Oleg Nikolaenko as the author and operator of the Mega-D botnet.

Shopping Online? Know Thy Seller

November 29, 2010

This time of year, it seems like everyone has a guide on how to shop safely online. Most of these tip sheets focus on ways to spot insecure Web sites and harden your computer against data-stealing malware, but it’s equally important to research the reputation of the merchant before it’s too late.

Spear Phishing Attacks Snag E-mail Marketers

November 24, 2010

Criminals have been conducting complex, targeted e-mail attacks against employees at more than 100 e-mail service providers (ESPs) over the past several months in a bid to hijack computers at companies that market directly to customers of some of the world’s largest corporations, anti-spam experts warn.

The attacks are a textbook example of how organized thieves can abuse trust relationships between companies to access important resources that are then recycled in future attacks.

Captchabot: Blurring Human and Machine

November 16, 2010

Last week, I wrote about a “bulletproof hosting” provider that offers dodgy Web hosting that is insulated from takedown by abuse complaints or requests from Western law enforcement agencies. Today, I’ll look at one of that bulletproof provider’s biggest clients: Captchabot.com, a service that automates the solving of “CAPTCHAs,” those annoying agglomerations of squiggly numbers and letters that many online services require users to solve to help ensure that new accounts are not being auto-created by a computer.

Body Armor for Bad Web Sites

November 9, 2010

Hacked and malicious sites designed to steal data from unsuspecting users via malware and phishing are a dime a dozen, often located in the United States, and are a key target for takedown by ISPs and security researchers. But when online miscreants seek stability in their Web projects, they often turn to so-called “bulletproof hosting” providers, mini-ISPs that specialize in offering services that are largely immune from takedown requests and pressure from Western law enforcement agencies.