[HN Gopher] Russian Reshipping Service 'Swat USA Drop' Exposed
       ___________________________________________________________________
        
       Russian Reshipping Service 'Swat USA Drop' Exposed
        
       Author : todsacerdoti
       Score  : 75 points
       Date   : 2023-11-02 20:00 UTC (3 hours ago)
        
 (HTM) web link (krebsonsecurity.com)
 (TXT) w3m dump (krebsonsecurity.com)
        
       | throwawaaarrgh wrote:
       | Do they not buy gift cards anymore? Back in the day you used
       | carding to buy gift cards and then use the gift cards to buy the
       | merch to resell. Gives you more time since the card could be
       | cancelled quickly after first use and gift card is hard to trace.
        
         | filoleg wrote:
         | The OP says that the issue is that the scammers live in
         | countries to which most western merchants refuse to ship
         | anymore due to high prevalence of scams originating there
         | (eastern europe, russia, etc.) and near zero ability to enforce
         | the law against them by the US authorities.
         | 
         | For all we know, those items sent to US-located "drops" (aka
         | unaware victims and accessories to the crime) for shipping
         | overseas were indeed bought with gift cards. That's beside the
         | point, the problems that those SWAT services are supposed
         | address are explicitly related to shipping items (which were
         | purchased with stolen credit cards, either directly or by using
         | gift cards) to countries where most western merchants refuse to
         | ship in the first place.
         | 
         | Gift cards won't even be needed here, since the only person who
         | can get pinned for this is the US-based "drop" who was
         | unknowingly helping out the criminals.
        
           | wutwutwat wrote:
           | It's physical onion routing/proxying to obscure the true
           | origin of the scams and spread it over such a wide area (the
           | world), or such a powerful and wealthy area (U.S.) that
           | cutting off business in those regions is impossible because
           | you'd put yourself out of business in doing so. The exit
           | nodes, or true origins are the pockets of the folks running
           | the whole scheme. Good luck finding them, and even if they
           | are found, they are insanely wealthy, so nothing will come of
           | it, because that's how the world works.
        
             | filoleg wrote:
             | > they are insanely wealthy
             | 
             | The OP mentions that the main guy running the SWAT service
             | makes roughly $100k/mo at most.
             | 
             | While it is certainly a lot of money, it isn't even close
             | to being "above the law."
             | 
             | The OP says that the service has been operating under a
             | bunch of different names for somewhere close to a decade.
             | Even though they certainly were not making $100k/mo from
             | the beginning, let's make the most generous assumptions
             | possible and do some napkin math of the upper bound. 10
             | years = 120 months, so 120*100k = $12mil. And that's the
             | upper bound.
             | 
             | That's only a single order of magnitude more than what
             | someone who bought a house in the US for about $600k a
             | decade ago has in net worth (with the fairly realistic
             | assumption that the value of it rose to at least $1mil),
             | and there are tons and tons of those people.
        
               | wutwutwat wrote:
               | > the main guy running the SWAT service makes roughly
               | $100k/mo at most
               | 
               | I can almost guarantee you that he wasn't the big
               | fish/the end of the trail. His entire operation is just a
               | proxy hop, one of many.
               | 
               | $100k a month is an insane amount of money to me, and is
               | more than enough to have power to buy people, lawyers,
               | houses in countries that don't extradite or recognize the
               | charges as crimes, and have people murdered. If you're
               | not able to buy everyone around you with $100k every
               | single month you're not even trying. I would assume
               | anyway, who knows though lol
               | 
               | buy == bribe/put in your pocket (just so it's not
               | confused with literally buying people, which you could
               | also do with that kind of money I'm assuming)
        
       | ThePowerOfFuet wrote:
       | >The information leaked from SWAT also has exposed the real-life
       | identity and financial dealings of its principal owner --
       | Fearlless, a.k.a. "SwatVerified." We'll hear more about Fearlless
       | in Part II of this story. Stay tuned.
       | 
       | What a fun ending.
        
       | meepmorp wrote:
       | > SWAT apparently kept its books in a publicly accessible Google
       | Sheets document, and that document reveals Fearlless and his
       | business partner each routinely made more than $100,000 every
       | month operating their various reshipping businesses.
       | 
       | Yeah, OpSec is hard, but come on.
        
         | wutwutwat wrote:
         | This shouldn't have required OpSec at all because any smart
         | person would not have kept books online, and maybe not even on
         | a computer at all. It's always boggled my mind that such
         | intricate inditement records are kept, it's not going to end
         | well.
         | 
         | Tangent: if I were to open my house free for all to come and go
         | as they please, but a bunch of criminals kept coming over and
         | sitting at the kitchen table keeping their illegal record of
         | their crimes, and I let them use my mailbox to contact their
         | people to coordinate the executions of fruad and likely some
         | murders sprinkled in there, and they would sometimes bring over
         | suitecases filled with illegal materials or even filing
         | cabinets, and store them in the living room for a bit and then
         | some other criminal would come and take them out....
         | 
         | at what point would I as the homeowner become an accomplice to
         | all the crimes being ran out of my house? I'm going to say at
         | some point in time I would no longer be a oblivious homeowner
         | and I would start to be viewed as a criminal and I'd be getting
         | charges of crimes hurled my way.
         | 
         | Now tell yourself the same story but instead of a house it's
         | the Google product suite, sheets for the books, gmail for the
         | comms, drive for the distribution of criminal data, etc.
         | 
         | Sure Google is just the oblivious homeowner for awhile, but if
         | I could be charged with being an accomplice to crimes, or
         | aiding and abetting, surely something should be pointed at
         | Google, or any other company, who is providing services to
         | probably a massive amount of people using those services to
         | realize crimes, all around the world, day in and day out. You
         | can't have shit like that happening in your house and not know
         | that it's happening, and these products are free so they can
         | mine the data from us using them, which makes the "I didn't
         | know some mobsters were keeping book at my kitchen table"
         | defense hard to say and expect people to believe you.
         | 
         | Not saying anything should happen, or that anything doesn't
         | happen, I'm just pointing out that we don't really think about
         | how often tech is used to commit crimes and I've never
         | personally seen any news about the Feds going after Google for
         | facilitating the back office of the criminal enterprise (maybe
         | those Gov contracts Google does causes any LE to look the other
         | way idk)
        
           | jfim wrote:
           | > This shouldn't have required OpSec at all because any smart
           | person would not have kept books online, and maybe not even
           | on a computer at all. It's always boggled my mind that such
           | intricate inditement records are kept, it's not going to end
           | well.
           | 
           | They're running a business, albeit an illicit one, and it's
           | hard to run a business without spreadsheets. How else would
           | they keep track of everything efficiently?
        
             | wutwutwat wrote:
             | Ask the loan shark from the chop shop down on the corner
             | when he's breaking your legs with a bat how he kept such
             | accurate books with only a cashier's ledger notebook and no
             | cloud based spreadsheet formulas.
             | 
             | How they would run their business without spreadsheets is
             | the same way that every business ran before spreadsheets
             | existed. Or maybe if they didn't try to emulate legal
             | businesses, who keep books for tax audit reasons, they
             | wouldn't get caught. They are keeping audit records but the
             | last thing they want is anyone to see those records. You
             | don't need them the way legal businesses need them, the
             | less paper trail the better.
        
           | xwolfi wrote:
           | Google isnt reading our emails but offers backdoor to
           | authorities. They re the opposite of your oblivious turned
           | malicious homeowner.
        
       | irrational wrote:
       | > In reality, the crooks in charge almost always stop
       | communicating with drops just before the first payday, usually
       | about a month after the drop ships their first package.
       | 
       | I feel like there needs to be a financial literacy class in
       | school that includes a unit on scams with many examples of how
       | you can be scammed.
        
         | Terr_ wrote:
         | Oh, absolutely. Recognizing common scam archetypes or features
         | would be vastly more useful than some of the crap that gets
         | into a US high-school curriculum, especially considering the
         | time spent making kids (temporarily) memorize exact dates and
         | place-names.
         | 
         | I never tried planning out a curriculum, but I think in
         | addition _recognizing_ scams, people should also be aware of
         | options they can request /demand that would protect themselves,
         | things a legitimate partner would agree to but scammers would
         | refuse. For example, putting funds in escrow, or "Oh, you work
         | at the Important Institution? Please tell me your office-
         | extension and I'll call you back through their official phone
         | number."
         | 
         | Other gaps that I would want to address if I were the Czar of
         | Education include:
         | 
         | 1. Debts, compounding, how bankruptcy works.
         | 
         | 2. How contracts work, and what they _don 't_ do even if you've
         | seen it in fiction.
         | 
         | 3. Some basic tax stuff. (I've met adults-with-children who
         | still think things like "I can't accept that raise, it'll put
         | me into a higher tax bracket.")
         | 
         | 4. What people can or can't usually sue each other for.
        
           | filoleg wrote:
           | > I've met adults-with-children who still think things like
           | "I can't accept that raise, it'll put me into a higher tax
           | bracket."
           | 
           | If talking purely about taxes and income without anything
           | else in the context, you are correct. However, sometimes the
           | logic you describe makes sense when it comes to government
           | benefits.
           | 
           | Totally made-up example: imagine the government gives some
           | sort of a benefit/assistance to people in certain
           | circumstances (e.g., heavily subsidized childcare), but only
           | if they are below a specific tax bracket, and if you cross
           | that threshold, the benefit eligibility is gone entirely. So
           | even though you technically still made more post-tax income
           | if you crossed into that bracket, you might have lost more
           | overall than you gained due to not getting that
           | benefit/assistance (the one that requires you to be below a
           | certain tax bracket) anymore.
        
             | kibibu wrote:
             | In Australia, government student loans (HECS/HELP) don't
             | need to be repaid until you earn over a certain amount, but
             | then it's a flat 4% of income. Also access to lower priced
             | medicine has an income cap (your made up example is called
             | a Health Care Card in Aus), so it's very possible for
             | people at various thresholds to get a raise and have a dip
             | in income or a bump on expenses.
        
               | filoleg wrote:
               | In the US, if you are qualified, you can get on an
               | income-driven repayment plan. Under that plan, your
               | federal student loan repayment is also capped at income
               | percentage. If you keep making payments, the rest of the
               | loan gets discharged after 20-25 years (depending on
               | circumstances)[0].
               | 
               | 0. https://www.consumerfinance.gov/paying-for-
               | college/student-l...
        
             | Terr_ wrote:
             | I agree that the misconception may originate from practical
             | factors (either directly-experienced or through garbled
             | retelling), however I also believe it has spread and exists
             | among a lot of people who _don 't_ have a good personal
             | excuse for it.
             | 
             | For example, a former-worker, a software engineer in the
             | Seattle area making _way_ above welfare-levels. Perhaps he
             | had always let his scientist-wife handle the finances
             | before, I dunno.
        
       | morkalork wrote:
       | Fascinating the ecosystem is big enough that someone can
       | specialize in a niche like this:
       | 
       | >"drops test" services, contractors who will test the honesty of
       | drops by sending them fake jewelry;
        
         | kasey_junk wrote:
         | This was the thing that jumped out at me. I now want an expose
         | just on this! How do _they_ get paid and made sure they aren't
         | also getting ripped off? Do they too run their own drops for
         | shipping the fake jewelry? Do they advertise success rates?
        
       | wutwutwat wrote:
       | > On a suspicion that the login page for portal-ctsi[.]com might
       | be a custom coding job, KrebsOnSecurity selected "view source"
       | from the homepage to expose the site's HTML code
       | 
       | Ahhh shit, it's time for some early 2000's "Antitrust" style
       | quick pans to CRTs with HTML tags wizzing by while discount Bill
       | Gates talks in the background about how you're either a 1 or a 0,
       | alive or dead, before Teddy comes to the revolutionary
       | realization that "The answer's not in the box, it's in the band."
       | 
       | But in all seriousness, that screenshot shows a page clearly
       | designed by a backend engineer so I find the suspicion of a
       | "custom coding job" pretty funny. I've been out of the loop for a
       | bit but I haven't seen anything make the rounds on HN about any
       | criminal drop shipping saas graduating from a startup accelerator
       | with a big ole seed round and a office in SF on the way. Of
       | course all of their software is custom, in house stuff, or
       | heavily adapted tooling, they can't really go and use salesforce
       | now can they? And at the end of the day what does a "custom
       | coding job" even mean, because trace any application that's ever
       | existed and it was a custom coding job. And also I'm lol'ing
       | because the article is trying to make viewing html on a "hunch"
       | out like it's fucking Batman level detective work :)
       | 
       | Why were they doing all of this on the clear net out in the open?
       | They are smart enough to have a super intricate network of mules
       | and delivery people, custom written software, and even have what
       | appears to be management sending memo's about corporate policy,
       | yet they weren't smart enough to put this all behind a private
       | VPN or throw it on the TOR network AND also behind a private vpn?
       | It almost seems like they were trying to get caught, and wtf kind
       | of name is that? I'm not convinced this isn't a false flag for
       | something else or a spark to act on something. It has the grab
       | bag of things needed to breed more hatred at random countries
       | that we've been told since grade school to hate.
        
         | batch12 wrote:
         | > And at the end of the day what does a "custom coding job
         | 
         | By custom coding job, I think he just means that the file is
         | unique enough to be used to fingerprint sites created by the
         | same entity. Tracking unique assets on a page to find
         | similarities is a solid way to hunt for malicious related
         | sites.
         | 
         | > yet they weren't smart enough to put this all behind a
         | private VPN or throw it on the TOR network
         | 
         | The use of Tor would limit the pool of mules either due to
         | technical limitations or tripping BS sensors. Also, it's the
         | dumb ones that get caught first.
        
       | ahoka wrote:
       | It seems like an easy way to get a free iphone.
        
         | scrose wrote:
         | As entertaining as it'd be to scam the scammers, it's probably
         | not wise to keep a device that was purchased and shipped to you
         | using a stolen CC after also giving up tons of PII..
         | 
         | > Anyone can sign up at this website as a potential reshipping
         | mule, although doing so requires applicants to share a great
         | deal of personal and financial information, as well as copies
         | of an ID or passport matching the supplied name.
        
         | xwolfi wrote:
         | But it wont be yours and you re the first node in the graph the
         | bank and police will find after asking the merchant who bought
         | it with the stolen card.
         | 
         | We really really need scam literacy education if that's your
         | first reaction.
        
       ___________________________________________________________________
       (page generated 2023-11-02 23:01 UTC)