Anti Virus Softwares

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Friday, 5 November 2010

Minipost: NY Zeus "At Large" Codreanu and Adam captured

Posted on 12:38 by Unknown
We've previously posted about the FBI's Operation ACHing Mule (that's A-C-H as in Automated-Clearing-House, the way American banks send money between themselves) and the 17 Wanted Zeus Criminals who were still at large for their roles in moving massive amounts of money to Eastern Europe.

While we previously shared some fun Facebook photos of the "at large" criminals, we were encouraged to wait until they were arrested to share more of our findings.

Today @nigroeneveld let us know that two more of the missing baddies had been located, and were actually arrested arraigned yesterday in Madison, Wisconsin.

Graham Cluley had the first story I saw on the arrests on his Naked Security Blog, but I haven't really seen any details on how they were caught.


What do we know about how Dorin got into the country? All we have to go by is hearsay, but let's just say its interesting that convicted Zeus Money Mule Alina Turatura, at large Zeus Money Mule Catalina Cortac, and Dorin were all Facebook Friends with "Acord Travel" or Chisinau, Moldova, whose Facebook page calls them the "Lider in Programe Work and Travel" which would be consistent with the J1 Visa Travel theory.



Is Zeus connected with the Mafia? Let's just say that Dorin, whose profile picture featured himself holding a sign that reads "HELP! I Need Money for WEED!", was a level 68 criminal:




As a reminder, on April 21, 2010, Dorin Codreanu, carrying a Greek passport with his photo and the name "Savvas Paian", walked into a J.P. Morgan Chase Bank in New York and opened a new account with an initial $25 deposit. On May 4th, someone deposited $10 into the account. Then on May 11, 2010, someone wire transfered $10,246 from Illinois to the account. Within two days, $10,236 of that amount had been withdrawn, including a $800 ATM withdrawal, a $140 ATM withdrawal, and counter checks in the amounts of $2,000 and $4,800 from two different branches in the Bronx.

On May 18, 2010, Savvas Paian opened a business account at TD Bank North America in Cherry Hill, New Jersey using the same Greek Passport, in the name of "Savvas Import Group LLC". As we mentioned earlier, that's a "fruit and vegetable importer" at "1612 Kings Highway, Apartment 48, Brooklyn New York, 11229-1210 -- which used the same phone number as "Brooklyn Fruit Vegetable Growers Shippers" and "Neptune Fruit Vegetable Growers Shippers", which makes one wonder if there may be other bank accounts as well.

I think that rates as probably much lower than level 68, but I may be wrong. Dorin actually was recruiting other Moldovan students, named in the indictment as "CC-1", "CC-2", "CC-3", and "CC-4" to assist his efforts. Codreanu helped CC-1 get into the business, and CC-1 brought CC-2, who was also recruited to work under Codreanu. CC-2 received payments and made withdraws of approximately $34,000 from July 6 to July 9. CC-1 and CC-2 were arrested on August 4th, but have not been named.



Lillian Adam


Also arrested with Codreanu was Lillian Adam, also known as Roman Kobilev.

Lillian is one of four individuals named in the same indictment - the others being:

his at least sometime girlfiend, Catalina Cortac, pictured here kissing Adam on top of the Empire State Building:



Catalina Cortac, who is still friends with Acord Travel, and who claims to have successfully returned to Chisinau, Moldova.




Marina Oprea, who shares with us her "New York" photo album on Facebook, featuring bathing beauties Marina and Catalina:



I have no idea why Marina preferred to be photographed with Banks . . .





According to the Indictment, Marina opened accounts at both Chase Bank and M&T Bank, and used them to receive tens of thousands of dollars.

Ion Volosciuc --
Email ThisBlogThis!Share to XShare to FacebookShare to Pinterest
Posted in | No comments
Newer Post Older Post Home

0 comments:

Post a Comment

Subscribe to: Post Comments (Atom)

Popular Posts

  • From Russia, With Love . . . new Postcard spam spies on your PC
    Isn't it nice to have friends who send you postcards? The UAB Spam Data Mine is especially fortunate in that way. Beginning the evenin...
  • Happy New Year! Here's a Virus! (New Year's Postcard malware)
    I've been busy this week looking at the various defacements (see ComputerWorld , and ABC News ) and other cyber attacks (see yesterday...
  • ACH Spammer switches to Shortened URLs
    For many weeks now the spammers behind one particular malware family have been fighting a running battle to keep their malware-hosting domai...
  • Tempting Photo Attachments Lead to Fake AV
    One of today's largest malicious spam campaigns continued an occasional theme we've been seeing for a few weeks. A subject line, fo...
  • Morocco based "Team Evil" reroutes prominent Israeli websites
    After more than 10,000 websites being defaced in protest of Israeli actions in Gaza, Morrocco-based defacement team "Team Evil" ha...
  • Indictments reveal $77 Million in Illegal Pill Sales
    Congratulations to the Daytona Beach FBI, US Attorney Robert O'Neill, and their colleagues at IRS and FDA. The Daytona Beach News report...
  • Most Dangerous Cities for Cyber Crime?
    Symantec Riskiest Cybercrime Cities Symantec released a study today in conjunction with Sperling's Best Places today. According to thei...
  • Minipost: Google v. Pacific WebWorks
    I blogged recently about the "Google Jobs" scammers who were abusing Twitter, Blogspot, Google Reader, and spaces.live.com by crea...
  • New Year's Waledac Card
    We haven't seen a new version of Waledac since Independence Day (July 4, 2009), but it looks like its back! I'm on vacation today, s...
  • WIRED: November Jargon Watch & Forensics?
    One of my NASA buddies (hi, Lisa!) dropped by last week for coffee and to catch up on the world of information management. When I introduce...

Categories

  • Blogs
  • Calendar
  • china
  • Communities
  • computer security careers
  • conficker
  • cyberwar
  • digital certificates
  • Drivers
  • email
  • Excel 2007
  • facebook
  • fake av
  • Features
  • Firewall
  • Gadgets
  • gumblar
  • Hardware
  • Hotmail
  • IE7
  • Internet Explorer 7
  • koobface
  • law enforcement
  • malware
  • Microsoft
  • Outlook
  • pharmaceuticals
  • phishing
  • PowerPoint 2007
  • public policy
  • Ready Boost
  • ReadyBoost
  • Security
  • Sidebar
  • Software
  • spam
  • Tutorials
  • twitter
  • twitter malware
  • USB
  • Virtual PC
  • Vista
  • waledac
  • Wallpaper
  • Websites
  • Windows
  • Windows Live
  • Windows Vista
  • Word 2007
  • zbot

Blog Archive

  • ►  2013 (17)
    • ►  November (1)
    • ►  October (1)
    • ►  September (1)
    • ►  August (3)
    • ►  July (1)
    • ►  June (1)
    • ►  May (5)
    • ►  April (3)
    • ►  March (1)
  • ►  2012 (18)
    • ►  August (1)
    • ►  June (1)
    • ►  May (7)
    • ►  April (2)
    • ►  March (7)
  • ►  2011 (28)
    • ►  November (3)
    • ►  October (1)
    • ►  August (4)
    • ►  July (6)
    • ►  June (1)
    • ►  May (2)
    • ►  April (2)
    • ►  March (6)
    • ►  February (1)
    • ►  January (2)
  • ▼  2010 (80)
    • ►  December (6)
    • ▼  November (10)
      • Minipost: IPR Center celebrates Cyber Monday
      • Cyber Monday Warnings
      • Schoolboy Hackers steal $18 Million (£12 Million p...
      • Another M00P Group Member arrested
      • Lord Aughenbaugh of the Trailer Park
      • Lin Mun Poo: Hacker of the Federal Reserve and ...?
      • WIRED: November Jargon Watch & Forensics?
      • Minipost: NY Zeus "At Large" Codreanu and Adam cap...
      • Sextortion Hacker: Victims sought by FBI
      • USAA Phish: Avalanche uses many "redirectors"
    • ►  October (6)
    • ►  September (12)
    • ►  August (5)
    • ►  July (4)
    • ►  June (11)
    • ►  April (7)
    • ►  March (8)
    • ►  February (4)
    • ►  January (7)
  • ►  2009 (93)
    • ►  December (12)
    • ►  November (11)
    • ►  October (16)
    • ►  September (7)
    • ►  July (5)
    • ►  June (10)
    • ►  May (2)
    • ►  April (7)
    • ►  March (7)
    • ►  February (6)
    • ►  January (10)
  • ►  2008 (109)
    • ►  December (7)
    • ►  November (17)
    • ►  October (12)
    • ►  September (10)
    • ►  August (23)
    • ►  July (14)
    • ►  June (3)
    • ►  May (8)
    • ►  April (6)
    • ►  March (2)
    • ►  February (3)
    • ►  January (4)
  • ►  2007 (37)
    • ►  December (3)
    • ►  November (9)
    • ►  October (3)
    • ►  September (2)
    • ►  August (5)
    • ►  July (5)
    • ►  April (2)
    • ►  March (2)
    • ►  February (2)
    • ►  January (4)
  • ►  2006 (5)
    • ►  December (2)
    • ►  October (3)
Powered by Blogger.

About Me

Unknown
View my complete profile