Internet Domain Registry

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Thursday, 4 November 2010

Sextortion Hacker: Victims sought by FBI

Posted on 03:12 by Unknown
On September 9, 2007, I received a forwarded email that had been sent to several high school parents in the Birmingham, Alabama area. It described a chilling scenario:

We have received SEVERAL reports of an unknown subject infiltrating students' Facebook and MySpace accounts. The unknown subject has taken over several students accounts and the student no longer has access to their account. The subject has made threats for the student to do what he demands or he/she will keep their accounts locked. ... The unknown subject has been using a screen name of 'metascape'.


In April of 2009, the public learned that Metascape was actually a 24 year old from Auburn, Alabama, who had taken over more than 200 accounts from young women from ages 14 to 26, with victims in at least Alabama, Pennsylvania, and Missouri. The Birmingham News headline was Facebook Helps Fight Cybercrime and detailed more of the situation. Metascape, whose real name was Jonathan Vance, had blackmail power over the girls through sexual statements of photos he had obtained from them. In at least 50 cases, he leveraged this information to force the girls to perform more and more graphic sexual acts for him on their webcams, which he then used for greater leverage.

Birmingham FBI Cybercrime Supervisor, Dale Miskell, put it this way to the Birmingham News:

"The embarrassment factor was big in this case," said Dale Miskell, supervisory spe­cial agent for the FBI's cyber­crimes squad in Birmingham. "How can a girl go to her pa­rents and tell them what hap­pened? Even the adult victim didn't come forward until we contacted her."


Jonathan Vance was sentenced to eighteen years in his case, mostly because of the severe emotional trauma that the girls described when interviewed by prosecutors and law enforcement.

My friend Graham Cluley of Sophos mentions that there have also been similar cases in Spain, Great Britain, and Canada in his Cyber-Sextortionist blog story.

When the FBI and US Attorney's Office shared the details of the case with my Investigating Online Crime class in the summer of 2009, I hoped I would never hear of another case like it. Unfortunately, this week there has been another such case revealed.

On November 2nd, the FBI put out a press release called Web of Victims that described a nearly identical scenario involving a 31 year old Santa Ana man. Luis Mijangos was arrested in June, according to the Los Angeles Times and charged with taking over the webcams of 44 girls and 186 women. A June 22nd KABC News story reveals that the investigation was begun by the Glenndale Police Department. A UPI Story from the same day describes Mijangos as a Mexican citizen, wheelchair bound after being shot in "a gangland shooting." After that first court visit he was restricted to home and forbidden to use a computer while out on $10,000 bond. He was indicted on July 8th and charged with:

18 U.S.C. § 371 - Conspiracy
18 U.S.C. § 1341 - Mail Fraud
18 U.S.C. § 1028A - Aggravated Identity Theft
18 U.S.C. §§ 1030(a)(2)(C) and (c)(2)(B)(ii) - Accessing Protected Computers to Obtain Information
18 U.S.C. § 875(d) - Extortion
18 U.S.C. §§ 2511(1)(a), (4)(a) - Wiretapping
18 U.S.C. §§ 1029(a)(3), (c)(1)(A)(i) - Possession of more than 15 Unauthorized Access Devices
18 U.S.C. § 2(a), (b) - Aiding and Abetting and Causing an Act to Be Done

The indictment calls Mijangos a "self-employed website developer and computer consultant" and says that he used the following screen names:

gui_blt, Woods05, CiFfEjUd914m EKEvatrGZrD03, Pimpcess03666, Your3name3here03, Bri23nice, Dmagecntr137, H2IOW14, ELEvATrhRZd03, Playrgrl37, Your3name3here3, goldlion14, and Hotchit13w

and the following email accounts:

yousoylammer@hotmail.com, christ@yahoo.com, gui_blt@live.com, mistahxxxrightme@aim.com, zapotin@hotmail.com, guich_x@aim.com, guicho_1.1@roadrunner.com, and mijangos3@msn.com

PARENTS - PLEASE TALK TO YOUR DAUGHTERS ABOUT THESE TYPES OF CASES

Let them know that if they, or any of their friends, has been subjected to something like this, they need to talk with you, and YOU need to talk with the FBI. Especially if you have information regarding one of the screen names or email addresses above. The 18 year sentence for Metascape was because victims came forward and talked freely (albeit painfully) about their victimization. Don't let these creeps get away with this, and don't let YOUR daughter live in shame because she is worried you will flip out.

The indictment names criminal acts from as far back as November 26, 2008, Mijangos and co-schemers throughout the world developed malware that would give him complete control of a computer, including keylogging for identity theft, and webcam and microphone control.

With the keylogged data, they would engage in credit card fraud. Mijangos was a better hacker than metascape. He would use computers belonging to teenage boys, and FROM THEIR COMPUTERS, trick their female friends into sharing intimate videos or images. He would then contact the women and girls directly, disclosing that he had these videos and images, and threatening to post them online if they did not share additional images and videos.

Some of the co-conspirators named (by screen name) include "Manhattan" and "Demonio666vip". One co-conspirator ordered stolen goods using the name "mauricio garza arcos" and the email "statikgto@gmail.com". This is probably "St4t1k" of the "Money Buster Team".

UAB Computer Forensics Research Laboratory has determined that demonio666vip and st4t1k were both members of the hacker website "indetectables.net" and were involved in the trade of "undetectable" BiFrost servers. BiFrost is a "RAT" or "Remote Administration Trojan" which was likely involved in the case above.



Indetectables.net, so named for their distribution of undetectable malware, has 30,242 users who have posted 133,942 messages about hacking and malware.
Email ThisBlogThis!Share to XShare to Facebook
Posted in | No comments
Newer Post Older Post Home

0 comments:

Post a Comment

Subscribe to: Post Comments (Atom)

Popular Posts

  • 2009 Year in Review
    As 2009 comes to a close I wanted to take a minute to thank all of the people who have been helpful to this blog this year, and to share bac...
  • What about the Social Security Numbers? (The Utah Data Breach and your SSN)
    The Utah Data Breach This week the continuing saga of the Utah Medicaid Data Breach continued to unfold. If you haven't been following...
  • Top Brands Imitated by Malicious Spam
    WebSense recently released an InfoGraphic titled "Top Five Subject Lines in Phishing Emails." for January 1, 2013 through Septemb...
  • Carder Christopher Schroebel gets Seven Years
    21 years old and thinking about Cybercrime as a career choice?  Think again.  Seattle-based U.S. Attorney Jenny Durkan told a press conferen...
  • Stop the Rumors: Quit SMSing about WalMart Gang Initiations
    My daughter and her teenage friend were sitting on the couch watching TV today when they began getting text messages on their phone. Here...
  • New BBC spam mocks Georgia's President, Spreads New Virus
    This morning we've received more than 300 copies of a new "BBC" spam campaign which mocks Georgia's President and spreads ...
  • New Year's Waledac Card
    We haven't seen a new version of Waledac since Independence Day (July 4, 2009), but it looks like its back! I'm on vacation today, s...
  • Digital Certificates Update
    A quick update from the previous post. The Digital Certificates spam campaign against Merrill Lynch continues, but the good guys seem to be ...
  • ATM Cashers in 26 Countries steal $40M
    CBS News in New York has a video on their website this morning title Cyber-attacks behind possibly record-breaking bank heist . Former FBI ...
  • A New Year and Anti-Virus Products Are Still Losing
    One of our most popular blog posts in 2008 was back in August - Anti-Virus Products Still Fail on Fresh Viruses . I'm sad to report tha...

Categories

  • china
  • computer security careers
  • conficker
  • cyberwar
  • digital certificates
  • facebook
  • fake av
  • gumblar
  • koobface
  • law enforcement
  • malware
  • pharmaceuticals
  • phishing
  • public policy
  • spam
  • twitter
  • twitter malware
  • waledac
  • zbot

Blog Archive

  • ►  2013 (21)
    • ►  December (4)
    • ►  November (1)
    • ►  October (1)
    • ►  September (1)
    • ►  August (3)
    • ►  July (1)
    • ►  June (1)
    • ►  May (5)
    • ►  April (3)
    • ►  March (1)
  • ►  2012 (18)
    • ►  August (1)
    • ►  June (1)
    • ►  May (7)
    • ►  April (2)
    • ►  March (7)
  • ►  2011 (28)
    • ►  November (3)
    • ►  October (1)
    • ►  August (4)
    • ►  July (6)
    • ►  June (1)
    • ►  May (2)
    • ►  April (2)
    • ►  March (6)
    • ►  February (1)
    • ►  January (2)
  • ▼  2010 (80)
    • ►  December (6)
    • ▼  November (10)
      • Minipost: IPR Center celebrates Cyber Monday
      • Cyber Monday Warnings
      • Schoolboy Hackers steal $18 Million (£12 Million p...
      • Another M00P Group Member arrested
      • Lord Aughenbaugh of the Trailer Park
      • Lin Mun Poo: Hacker of the Federal Reserve and ...?
      • WIRED: November Jargon Watch & Forensics?
      • Minipost: NY Zeus "At Large" Codreanu and Adam cap...
      • Sextortion Hacker: Victims sought by FBI
      • USAA Phish: Avalanche uses many "redirectors"
    • ►  October (6)
    • ►  September (12)
    • ►  August (5)
    • ►  July (4)
    • ►  June (11)
    • ►  April (7)
    • ►  March (8)
    • ►  February (4)
    • ►  January (7)
  • ►  2009 (92)
    • ►  December (12)
    • ►  November (11)
    • ►  October (16)
    • ►  September (7)
    • ►  July (5)
    • ►  June (10)
    • ►  May (2)
    • ►  April (6)
    • ►  March (7)
    • ►  February (6)
    • ►  January (10)
  • ►  2008 (101)
    • ►  December (7)
    • ►  November (17)
    • ►  October (11)
    • ►  September (10)
    • ►  August (22)
    • ►  July (12)
    • ►  June (3)
    • ►  May (7)
    • ►  April (5)
    • ►  March (2)
    • ►  February (1)
    • ►  January (4)
  • ►  2007 (31)
    • ►  December (3)
    • ►  November (9)
    • ►  October (3)
    • ►  September (2)
    • ►  August (5)
    • ►  July (5)
    • ►  January (4)
  • ►  2006 (5)
    • ►  December (2)
    • ►  October (3)
Powered by Blogger.

About Me

Unknown
View my complete profile