On the Internet, he was known as BadB, a disembodied criminal flitting from one server to another selling stolen credit card numbers despite being pursued by the US Secret Service.
In real life, he was nearly as untouchable — because he lived in Russia.
BadB’s real name is Vladislav Horohorin, a statement released last week by the US Justice Department said, and he was a resident of Moscow before his arrest by the police in France during a trip to that country earlier this month.
He is expected to appear soon before a French court that will decide on his potential extradition to the US, where Horohorin could face up to 12 years in prison and a fine of US$500,000 if he is convicted on charges of fraud and identity theft. For at least nine months, however, he lived openly in Moscow as one of the world’s most wanted computer criminals.
The capture of BadB provides a peek into the shadowy world of Russian hackers, the often well-educated and sometimes darkly ingenious programmers who pose a recognized security threat to online commerce — besides being global spam nuisances — and who often seem to operate with relative impunity.
Law enforcement groups in Russia have been reluctant to pursue these talented authors of Internet fraud, for reasons, security experts say, of incompetence, corruption or national pride.
In this environment, BadB’s network arose as “one of the most sophisticated organizations of online financial criminals in the world,” said a statement issued by Michael Merritt, the assistant director of investigations for the Secret Service, which pursues counterfeiting and some electronic financial fraud.
As long ago as in November last year, the US attorney’s office in Washington, in a sealed indictment, identified BadB as Horohorin, a 27-year-old residing in Moscow with dual Ukrainian and Israeli citizenship.
However, it was not until Aug. 7 this year that Horohorin, who was traveling from Russia to France, was detained on a warrant from the US as he boarded a plane to return to Russia at an airport in Nice, in southern France.
The Secret Service released a statement on Aug. 11, when the indictment was unsealed. Max Milien, a Secret Service spokesman in Washington, said the agency could not comment about the decision to arrest Horohorin in France.
Olga Shklyarova, spokeswoman for the Russian bureau of Interpol, said no US law enforcement agency had requested Horohorin’s arrest in her country.
“We never received such a request,” she said by telephone.
The Secret Service statement said that Horohorin managed Web sites for hackers who were able to steal large numbers of credit card numbers that were sold online anonymously around the globe. Those buyers would do the more dangerous work of running up fraudulent bills.
The numbers were exchanged on Web sites called CarderPlanet — carder.su and badb.biz — the Secret Service said, and payment was made indirectly through accounts at a Russian online settlement system known as Webmoney, an analogue to PayPal.
Underscoring the nationalistic tone of much of Russian computer crime, one site featured a cartoon of Russian Prime Minister Vladimir Putin awarding medals to Russian hackers.
“We awaiting you to fight the imperialism of the U.S.A.” the site said, in approximate English.
Horohorin lived openly in Moscow. As a foreign citizen, he registered with the police, said Dmitri Zakharov, a spokesman for the Russian Association of Electronic Communication, an industry lobby for legitimate Russian Internet businesses, who cited a database of such registries.
A phone number for Horohorin was out of service on Thursday.
Arrests in Russia for computer crimes are rare, even when hackers living in Russia have been publicly identified by outside groups, like Spamhaus, a nonprofit group in Geneva and in London that tracks sources of spam.
The FBI in 2002 resorted to luring a Russian suspect, Vasily Gorshkov, to the US with a fake offer of a job interview (with a fictitious Internet company called Invita), rather than ask the Russian police for help. To obtain evidence in the case, FBI computer experts had hacked into Gorshkov’s computer in Russia. When this was revealed, Russian authorities expressed anger that the FBI had resorted to a cross-border tactic.
Online fraud is not a high priority for the Russian police, Zakharov said, because most of it is aimed at computer users in Europe or the US.
“This is a main reason why spammers are not arrested,” he said.
Politics may also play a role. Vladimir Sokolov, deputy director of the Institute of Information Security, a Russian research organization, said the US and Russia were still at odds on basic issues of computer security, although the differences were narrowing.
The US tends to view computer security as a law enforcement matter. Russia has pushed for an international treaty that would regulate the use of online weapons by military or espionage agencies. Last year the US opened talks on a treaty, but it has continued to press for closer law enforcement cooperation, Sokolov said.
Computer security researchers have raised a more sinister prospect: that criminal spamming gangs have been co-opted by the intelligence agencies in Russia, which provide cover for their activities in exchange for the criminals’ expertise or for allowing their networks of virus-infected computers to be used for political purposes — to crash dissident Web sites, perhaps.
Sometimes, the collateral damage for online business is immediate. A year ago, for example, hackers used a network of infected computers to direct huge amounts of junk traffic at the social networking accounts of a 34-year-old political blogger in Georgia, a country that fought a war with Russia in 2008. The attack, though, spun out of control and briefly crashed the global service of Twitter and slowed Facebook and LiveJournal, affecting tens of millions of computer users worldwide.
The Russian authorities have repeatedly denied that the state has any connection to such attacks.
Spamhaus says seven of the top 10 spammers in the world are based in the former Soviet Union, in Ukraine, Russia and Estonia.
More ominously, Western law enforcement agencies have traced a code intended for breaking into banking sites to Russian programming.
In 2007, Swedish experts identified a Russian hacker known only by his colorful sobriquet — the Corpse — as the author of a virus that logged keystrokes on personal computers to capture passwords for Nordea, a Swedish bank, and the accounts were drained of about US$1 million.
For a time, these rogue programs were openly for sale on a Russian Web site. The home page displayed an illustration of Lenin making a rude gesture.
Since Horohorin’s arrest, the badb.biz Web site has gone dark. However, on Monday, at least, its CarderPlanet counterpart, the Russian site carder.su, was still open for business.
The US election result will significantly impact its foreign policy with global implications. As tensions escalate in the Taiwan Strait and conflicts elsewhere draw attention away from the western Pacific, Taiwan was closely monitoring the election, as many believe that whoever won would confront an increasingly assertive China, especially with speculation over a potential escalation in or around 2027. A second Donald Trump presidency naturally raises questions concerning the future of US policy toward China and Taiwan, with Trump displaying mixed signals as to his position on the cross-strait conflict. US foreign policy would also depend on Trump’s Cabinet and
The Taiwanese have proven to be resilient in the face of disasters and they have resisted continuing attempts to subordinate Taiwan to the People’s Republic of China (PRC). Nonetheless, the Taiwanese can and should do more to become even more resilient and to be better prepared for resistance should the Chinese Communist Party (CCP) try to annex Taiwan. President William Lai (賴清德) argues that the Taiwanese should determine their own fate. This position continues the Democratic Progressive Party’s (DPP) tradition of opposing the CCP’s annexation of Taiwan. Lai challenges the CCP’s narrative by stating that Taiwan is not subordinate to the
Republican candidate and former US president Donald Trump is to be the 47th president of the US after beating his Democratic rival, US Vice President Kamala Harris, in the election on Tuesday. Trump’s thumping victory — winning 295 Electoral College votes against Harris’ 226 as of press time last night, along with the Republicans winning control of the US Senate and possibly the House of Representatives — is a remarkable political comeback from his 2020 defeat to US President Joe Biden, and means Trump has a strong political mandate to implement his agenda. What does Trump’s victory mean for Taiwan, Asia, deterrence
The Taipei District Court on Nov. 1 agreed to extend the detention of Taiwan People’s Party (TPP) Chairman Ko Wen-je (柯文哲) for his suspected involvement in corruption involving a real-estate project during his time as Taipei mayor. Different voices are beginning to emerge from within the TPP about how to respond to their extended leaderless situation. Following a string of scandals coming to light since early August, including the TPP’s misreporting of election campaign finances and Ko’s alleged corruption related to the Core Pacific City redevelopment project, Ko on Aug. 29 announced he would take a three-month leave of absence from