[HN Gopher] Russian Reshipping Service 'Swat USA Drop' Exposed
___________________________________________________________________
Russian Reshipping Service 'Swat USA Drop' Exposed
Author : todsacerdoti
Score : 75 points
Date : 2023-11-02 20:00 UTC (3 hours ago)
(HTM) web link (krebsonsecurity.com)
(TXT) w3m dump (krebsonsecurity.com)
| throwawaaarrgh wrote:
| Do they not buy gift cards anymore? Back in the day you used
| carding to buy gift cards and then use the gift cards to buy the
| merch to resell. Gives you more time since the card could be
| cancelled quickly after first use and gift card is hard to trace.
| filoleg wrote:
| The OP says that the issue is that the scammers live in
| countries to which most western merchants refuse to ship
| anymore due to high prevalence of scams originating there
| (eastern europe, russia, etc.) and near zero ability to enforce
| the law against them by the US authorities.
|
| For all we know, those items sent to US-located "drops" (aka
| unaware victims and accessories to the crime) for shipping
| overseas were indeed bought with gift cards. That's beside the
| point, the problems that those SWAT services are supposed
| address are explicitly related to shipping items (which were
| purchased with stolen credit cards, either directly or by using
| gift cards) to countries where most western merchants refuse to
| ship in the first place.
|
| Gift cards won't even be needed here, since the only person who
| can get pinned for this is the US-based "drop" who was
| unknowingly helping out the criminals.
| wutwutwat wrote:
| It's physical onion routing/proxying to obscure the true
| origin of the scams and spread it over such a wide area (the
| world), or such a powerful and wealthy area (U.S.) that
| cutting off business in those regions is impossible because
| you'd put yourself out of business in doing so. The exit
| nodes, or true origins are the pockets of the folks running
| the whole scheme. Good luck finding them, and even if they
| are found, they are insanely wealthy, so nothing will come of
| it, because that's how the world works.
| filoleg wrote:
| > they are insanely wealthy
|
| The OP mentions that the main guy running the SWAT service
| makes roughly $100k/mo at most.
|
| While it is certainly a lot of money, it isn't even close
| to being "above the law."
|
| The OP says that the service has been operating under a
| bunch of different names for somewhere close to a decade.
| Even though they certainly were not making $100k/mo from
| the beginning, let's make the most generous assumptions
| possible and do some napkin math of the upper bound. 10
| years = 120 months, so 120*100k = $12mil. And that's the
| upper bound.
|
| That's only a single order of magnitude more than what
| someone who bought a house in the US for about $600k a
| decade ago has in net worth (with the fairly realistic
| assumption that the value of it rose to at least $1mil),
| and there are tons and tons of those people.
| wutwutwat wrote:
| > the main guy running the SWAT service makes roughly
| $100k/mo at most
|
| I can almost guarantee you that he wasn't the big
| fish/the end of the trail. His entire operation is just a
| proxy hop, one of many.
|
| $100k a month is an insane amount of money to me, and is
| more than enough to have power to buy people, lawyers,
| houses in countries that don't extradite or recognize the
| charges as crimes, and have people murdered. If you're
| not able to buy everyone around you with $100k every
| single month you're not even trying. I would assume
| anyway, who knows though lol
|
| buy == bribe/put in your pocket (just so it's not
| confused with literally buying people, which you could
| also do with that kind of money I'm assuming)
| ThePowerOfFuet wrote:
| >The information leaked from SWAT also has exposed the real-life
| identity and financial dealings of its principal owner --
| Fearlless, a.k.a. "SwatVerified." We'll hear more about Fearlless
| in Part II of this story. Stay tuned.
|
| What a fun ending.
| meepmorp wrote:
| > SWAT apparently kept its books in a publicly accessible Google
| Sheets document, and that document reveals Fearlless and his
| business partner each routinely made more than $100,000 every
| month operating their various reshipping businesses.
|
| Yeah, OpSec is hard, but come on.
| wutwutwat wrote:
| This shouldn't have required OpSec at all because any smart
| person would not have kept books online, and maybe not even on
| a computer at all. It's always boggled my mind that such
| intricate inditement records are kept, it's not going to end
| well.
|
| Tangent: if I were to open my house free for all to come and go
| as they please, but a bunch of criminals kept coming over and
| sitting at the kitchen table keeping their illegal record of
| their crimes, and I let them use my mailbox to contact their
| people to coordinate the executions of fruad and likely some
| murders sprinkled in there, and they would sometimes bring over
| suitecases filled with illegal materials or even filing
| cabinets, and store them in the living room for a bit and then
| some other criminal would come and take them out....
|
| at what point would I as the homeowner become an accomplice to
| all the crimes being ran out of my house? I'm going to say at
| some point in time I would no longer be a oblivious homeowner
| and I would start to be viewed as a criminal and I'd be getting
| charges of crimes hurled my way.
|
| Now tell yourself the same story but instead of a house it's
| the Google product suite, sheets for the books, gmail for the
| comms, drive for the distribution of criminal data, etc.
|
| Sure Google is just the oblivious homeowner for awhile, but if
| I could be charged with being an accomplice to crimes, or
| aiding and abetting, surely something should be pointed at
| Google, or any other company, who is providing services to
| probably a massive amount of people using those services to
| realize crimes, all around the world, day in and day out. You
| can't have shit like that happening in your house and not know
| that it's happening, and these products are free so they can
| mine the data from us using them, which makes the "I didn't
| know some mobsters were keeping book at my kitchen table"
| defense hard to say and expect people to believe you.
|
| Not saying anything should happen, or that anything doesn't
| happen, I'm just pointing out that we don't really think about
| how often tech is used to commit crimes and I've never
| personally seen any news about the Feds going after Google for
| facilitating the back office of the criminal enterprise (maybe
| those Gov contracts Google does causes any LE to look the other
| way idk)
| jfim wrote:
| > This shouldn't have required OpSec at all because any smart
| person would not have kept books online, and maybe not even
| on a computer at all. It's always boggled my mind that such
| intricate inditement records are kept, it's not going to end
| well.
|
| They're running a business, albeit an illicit one, and it's
| hard to run a business without spreadsheets. How else would
| they keep track of everything efficiently?
| wutwutwat wrote:
| Ask the loan shark from the chop shop down on the corner
| when he's breaking your legs with a bat how he kept such
| accurate books with only a cashier's ledger notebook and no
| cloud based spreadsheet formulas.
|
| How they would run their business without spreadsheets is
| the same way that every business ran before spreadsheets
| existed. Or maybe if they didn't try to emulate legal
| businesses, who keep books for tax audit reasons, they
| wouldn't get caught. They are keeping audit records but the
| last thing they want is anyone to see those records. You
| don't need them the way legal businesses need them, the
| less paper trail the better.
| xwolfi wrote:
| Google isnt reading our emails but offers backdoor to
| authorities. They re the opposite of your oblivious turned
| malicious homeowner.
| irrational wrote:
| > In reality, the crooks in charge almost always stop
| communicating with drops just before the first payday, usually
| about a month after the drop ships their first package.
|
| I feel like there needs to be a financial literacy class in
| school that includes a unit on scams with many examples of how
| you can be scammed.
| Terr_ wrote:
| Oh, absolutely. Recognizing common scam archetypes or features
| would be vastly more useful than some of the crap that gets
| into a US high-school curriculum, especially considering the
| time spent making kids (temporarily) memorize exact dates and
| place-names.
|
| I never tried planning out a curriculum, but I think in
| addition _recognizing_ scams, people should also be aware of
| options they can request /demand that would protect themselves,
| things a legitimate partner would agree to but scammers would
| refuse. For example, putting funds in escrow, or "Oh, you work
| at the Important Institution? Please tell me your office-
| extension and I'll call you back through their official phone
| number."
|
| Other gaps that I would want to address if I were the Czar of
| Education include:
|
| 1. Debts, compounding, how bankruptcy works.
|
| 2. How contracts work, and what they _don 't_ do even if you've
| seen it in fiction.
|
| 3. Some basic tax stuff. (I've met adults-with-children who
| still think things like "I can't accept that raise, it'll put
| me into a higher tax bracket.")
|
| 4. What people can or can't usually sue each other for.
| filoleg wrote:
| > I've met adults-with-children who still think things like
| "I can't accept that raise, it'll put me into a higher tax
| bracket."
|
| If talking purely about taxes and income without anything
| else in the context, you are correct. However, sometimes the
| logic you describe makes sense when it comes to government
| benefits.
|
| Totally made-up example: imagine the government gives some
| sort of a benefit/assistance to people in certain
| circumstances (e.g., heavily subsidized childcare), but only
| if they are below a specific tax bracket, and if you cross
| that threshold, the benefit eligibility is gone entirely. So
| even though you technically still made more post-tax income
| if you crossed into that bracket, you might have lost more
| overall than you gained due to not getting that
| benefit/assistance (the one that requires you to be below a
| certain tax bracket) anymore.
| kibibu wrote:
| In Australia, government student loans (HECS/HELP) don't
| need to be repaid until you earn over a certain amount, but
| then it's a flat 4% of income. Also access to lower priced
| medicine has an income cap (your made up example is called
| a Health Care Card in Aus), so it's very possible for
| people at various thresholds to get a raise and have a dip
| in income or a bump on expenses.
| filoleg wrote:
| In the US, if you are qualified, you can get on an
| income-driven repayment plan. Under that plan, your
| federal student loan repayment is also capped at income
| percentage. If you keep making payments, the rest of the
| loan gets discharged after 20-25 years (depending on
| circumstances)[0].
|
| 0. https://www.consumerfinance.gov/paying-for-
| college/student-l...
| Terr_ wrote:
| I agree that the misconception may originate from practical
| factors (either directly-experienced or through garbled
| retelling), however I also believe it has spread and exists
| among a lot of people who _don 't_ have a good personal
| excuse for it.
|
| For example, a former-worker, a software engineer in the
| Seattle area making _way_ above welfare-levels. Perhaps he
| had always let his scientist-wife handle the finances
| before, I dunno.
| morkalork wrote:
| Fascinating the ecosystem is big enough that someone can
| specialize in a niche like this:
|
| >"drops test" services, contractors who will test the honesty of
| drops by sending them fake jewelry;
| kasey_junk wrote:
| This was the thing that jumped out at me. I now want an expose
| just on this! How do _they_ get paid and made sure they aren't
| also getting ripped off? Do they too run their own drops for
| shipping the fake jewelry? Do they advertise success rates?
| wutwutwat wrote:
| > On a suspicion that the login page for portal-ctsi[.]com might
| be a custom coding job, KrebsOnSecurity selected "view source"
| from the homepage to expose the site's HTML code
|
| Ahhh shit, it's time for some early 2000's "Antitrust" style
| quick pans to CRTs with HTML tags wizzing by while discount Bill
| Gates talks in the background about how you're either a 1 or a 0,
| alive or dead, before Teddy comes to the revolutionary
| realization that "The answer's not in the box, it's in the band."
|
| But in all seriousness, that screenshot shows a page clearly
| designed by a backend engineer so I find the suspicion of a
| "custom coding job" pretty funny. I've been out of the loop for a
| bit but I haven't seen anything make the rounds on HN about any
| criminal drop shipping saas graduating from a startup accelerator
| with a big ole seed round and a office in SF on the way. Of
| course all of their software is custom, in house stuff, or
| heavily adapted tooling, they can't really go and use salesforce
| now can they? And at the end of the day what does a "custom
| coding job" even mean, because trace any application that's ever
| existed and it was a custom coding job. And also I'm lol'ing
| because the article is trying to make viewing html on a "hunch"
| out like it's fucking Batman level detective work :)
|
| Why were they doing all of this on the clear net out in the open?
| They are smart enough to have a super intricate network of mules
| and delivery people, custom written software, and even have what
| appears to be management sending memo's about corporate policy,
| yet they weren't smart enough to put this all behind a private
| VPN or throw it on the TOR network AND also behind a private vpn?
| It almost seems like they were trying to get caught, and wtf kind
| of name is that? I'm not convinced this isn't a false flag for
| something else or a spark to act on something. It has the grab
| bag of things needed to breed more hatred at random countries
| that we've been told since grade school to hate.
| batch12 wrote:
| > And at the end of the day what does a "custom coding job
|
| By custom coding job, I think he just means that the file is
| unique enough to be used to fingerprint sites created by the
| same entity. Tracking unique assets on a page to find
| similarities is a solid way to hunt for malicious related
| sites.
|
| > yet they weren't smart enough to put this all behind a
| private VPN or throw it on the TOR network
|
| The use of Tor would limit the pool of mules either due to
| technical limitations or tripping BS sensors. Also, it's the
| dumb ones that get caught first.
| ahoka wrote:
| It seems like an easy way to get a free iphone.
| scrose wrote:
| As entertaining as it'd be to scam the scammers, it's probably
| not wise to keep a device that was purchased and shipped to you
| using a stolen CC after also giving up tons of PII..
|
| > Anyone can sign up at this website as a potential reshipping
| mule, although doing so requires applicants to share a great
| deal of personal and financial information, as well as copies
| of an ID or passport matching the supplied name.
| xwolfi wrote:
| But it wont be yours and you re the first node in the graph the
| bank and police will find after asking the merchant who bought
| it with the stolen card.
|
| We really really need scam literacy education if that's your
| first reaction.
___________________________________________________________________
(page generated 2023-11-02 23:01 UTC)