I wish the DOJ had a better designer for their domain seizure graphics.
Somebody should seize the DOJ website and replace it with a cDc logo or something... Or a redirect to phrack.org.
RaidForums gets raided, alleged admin arrested
21–30 of 197 posts
Re: RaidForums gets raided, alleged admin arrested
#22"Coelho landed on the radar of U.S. authorities in June 2018, when he tried to enter the United States at the Hartsfield-Jackson International Airport in Atlanta. The government obtained a warrant to search the electronic devices Coelho had in his luggage and found text messages, files and emails showing he was the RaidForums administrator Omnipotent." Not really the sharpest knife in the drawer, to do things like th…
This guy was under the impression that what he was doing wasn’t illegal. IANAL but the fact that he is being charged with access device fraud might suggest that DOJ had to engage in some mental gymnastics in order to charge this. E: I’ll take that back since I actually read the indictment now, besides the usual raidforums fare he was also selling credit card data which would very much tend to attract access device fr…
Re: RaidForums gets raided, alleged admin arrested
#23Earlier quoted context omitted.
Not to mention the following paragraph: >“In an attempt to retrieve his items, Coelho called the lead FBI case agent on or around August 2, 2018, and used the email address unrivalled@pm.me to email the agent,” the government’s affidavit states. Investigators found this same address was used to register rf.ws and raid.lol, which Omnipotent announced on the forum would serve as alternative domain names for RaidForums…
I'm not so sure about it. Did you listen to the interview of Lex Fridman with Brett Johnson? He seems like an intelligent person who could easily get an infosec job and be extremely good at it from UX/social engineering point of view, but he was socialized from being a kid to disregard authority and steal from other people in every possible way. I'm sure he wouldn't let Coinbase get away with SMS 2nd factor authentic…
I did. Excellent, captivating interview, but he repeatedly acknowledged he didn't know much about the tech stuff, and he said several incorrect technical things towards the end. I stand by my statement: I think it would've been difficult for him to get a (technical) infosec job at the time of his arrest, or now (assuming a world where he didn't have a criminal record). While listening to it, I actually thought he perfectly fit the archetype of cybercrime forum operators I'm used to coming across.
He's certainly a great social engineer, and many other technically unskilled people in the cybercrime space also are. I'm definitely not discounting that ability. A lot of it comes down to brazenness; e.g. being confident and shameless enough to impersonate a law enforcement officer over the phone. There's still a lot of skill involved in being a con artist even then - you need affability and the gift of gab and all that - but it's not necessarily the kind of skill that's transferrable to technical expertise. There are many people with expertise in both areas, but also many who are exclusive to one.
Re: RaidForums gets raided, alleged admin arrested
#24"Coelho landed on the radar of U.S. authorities in June 2018, when he tried to enter the United States at the Hartsfield-Jackson International Airport in Atlanta. The government obtained a warrant to search the electronic devices Coelho had in his luggage and found text messages, files and emails showing he was the RaidForums administrator Omnipotent." Not really the sharpest knife in the drawer, to do things like th…
Not to mention the following paragraph: >“In an attempt to retrieve his items, Coelho called the lead FBI case agent on or around August 2, 2018, and used the email address unrivalled@pm.me to email the agent,” the government’s affidavit states. Investigators found this same address was used to register rf.ws and raid.lol, which Omnipotent announced on the forum would serve as alternative domain names for RaidForums…
Legitimite employment might not give them the needed liberty to do what they see fit.
Re: RaidForums gets raided, alleged admin arrested
#25Interesting comment on Krebs' article... Probably a joke, but doesn't imply great intelligence among the people involved with RaidForums if not.
Re: RaidForums gets raided, alleged admin arrested
#26Earlier quoted context omitted.
This guy was under the impression that what he was doing wasn’t illegal. IANAL but the fact that he is being charged with access device fraud might suggest that DOJ had to engage in some mental gymnastics in order to charge this. E: I’ll take that back since I actually read the indictment now, besides the usual raidforums fare he was also selling credit card data which would very much tend to attract access device fr…
I already said he wasn't the sharpest knife in the drawer.
But yeah, definitely not the sharpest knife in the drawer.
Re: RaidForums gets raided, alleged admin arrested
#27Earlier quoted context omitted.
Not to mention the following paragraph: >“In an attempt to retrieve his items, Coelho called the lead FBI case agent on or around August 2, 2018, and used the email address unrivalled@pm.me to email the agent,” the government’s affidavit states. Investigators found this same address was used to register rf.ws and raid.lol, which Omnipotent announced on the forum would serve as alternative domain names for RaidForums…
How is infosec job related to him? Legitimite employment might not give them the needed liberty to do what they see fit.
That's true; that's why I tried to qualify it with "generally". There certainly are some very intelligent, skilled people who are capable of finding legitimate employment and instead choose to immerse themselves in the criminal underworld, for various personal reasons. In practice, though, I've found them to be pretty rare.
Even among the ones who do have a desire for ultimate liberty and who see themselves as above the law, most feel like the risks greatly outweigh the rewards. Some temporary liberty in exchange for likely many years of zero liberty in a prison cell isn't a great deal. Especially when it's so easy for them to get a comfortable, high-paying legitimate job. (Admittedly, this trade-off may differ in places outside the US, where good jobs may be scarce and criminal activity may pay very well and almost always go unpunished. Assuming one has no ethical compunction, at least. Or feels certain illegal actions are ethically justifiable, like how many hacktivists feel.)
Re: RaidForums gets raided, alleged admin arrested
#28Earlier quoted context omitted.
I already said he wasn't the sharpest knife in the drawer.
What he was doing might very well have been legal had he just avoided payment information and stuck to stolen databases containing emails, phone numbers, passwords. That was the bulk of the trade on raidforums anyway. But yeah, definitely not the sharpest knife in the drawer.
I suspect that you are wrong about this.
https://en.wikipedia.org/wiki/Accessory_(legal_term)
"Count 1: Conspiracy to Commit Access Device Fraud (18 U.S.C. §§ 1029(b)(2)and 3559(g)(1))
Count 2: Access Device Fraud — Using or Trafficking in an Unauthorized Access Device (18 U.S.C. §§ 1029(a)(2)and 2)
Count 3: Access Device Fraud — Possession of Fifteen or More Unauthorized Access Devices (18 U.S.C. §§ 1029(a)(3)and 2)
Counts 4-5: Access Device Fraud — Unauthorized Solicitation (18 U.S.C. §§ 1029(a)(6)and 2)
Count 6: Aggravated Identity Theft (18 U.S.C. §§ 1028A(a)(l)and 2)"
If this sticks he will be gone for a long, long time, and, crucially, he handed over the the evidence himself so no amount of 'it wasn't me' is going to help here.
Re: RaidForums gets raided, alleged admin arrested
#29Earlier quoted context omitted.
What he was doing might very well have been legal had he just avoided payment information and stuck to stolen databases containing emails, phone numbers, passwords. That was the bulk of the trade on raidforums anyway. But yeah, definitely not the sharpest knife in the drawer.
> might very well have been legal had he just avoided payment information and stuck to stolen databases containing emails, phone numbers, passwords I suspect that you are wrong about this. https://en.wikipedia.org/wiki/Accessory_(legal_term) "Count 1: Conspiracy to Commit Access Device Fraud (18 U.S.C. §§ 1029(b)(2)and 3559(g)(1)) Count 2: Access Device Fraud — Using or Trafficking in an Unauthorized Access Device (1…
> Whoever, knowing that an offense against the United States has been committed, receives, relieves, comforts or assists the offender in order to hinder or prevent his apprehension, trial or punishment, is an accessory after the fact.
It’s not obvious at all that selling e.g. the leaked Linkedin database would be illegal in any way. You wouldn’t retroactively become an accessory to the original crime.
Of course, that stopped mattering the moment he started trafficking in stolen payment card information…
Re: RaidForums gets raided, alleged admin arrested
#30"Coelho landed on the radar of U.S. authorities in June 2018, when he tried to enter the United States at the Hartsfield-Jackson International Airport in Atlanta. The government obtained a warrant to search the electronic devices Coelho had in his luggage and found text messages, files and emails showing he was the RaidForums administrator Omnipotent." Not really the sharpest knife in the drawer, to do things like th…