On the Internet, he was known as BadB, a disembodied criminal flitting from one server to another selling stolen credit card numbers despite being pursued by the US Secret Service.
In real life, he was nearly as untouchable — because he lived in Russia.
BadB’s real name is Vladislav Horohorin, a statement released last week by the US Justice Department said, and he was a resident of Moscow before his arrest by the police in France during a trip to that country earlier this month.
He is expected to appear soon before a French court that will decide on his potential extradition to the US, where Horohorin could face up to 12 years in prison and a fine of US$500,000 if he is convicted on charges of fraud and identity theft. For at least nine months, however, he lived openly in Moscow as one of the world’s most wanted computer criminals.
The capture of BadB provides a peek into the shadowy world of Russian hackers, the often well-educated and sometimes darkly ingenious programmers who pose a recognized security threat to online commerce — besides being global spam nuisances — and who often seem to operate with relative impunity.
Law enforcement groups in Russia have been reluctant to pursue these talented authors of Internet fraud, for reasons, security experts say, of incompetence, corruption or national pride.
In this environment, BadB’s network arose as “one of the most sophisticated organizations of online financial criminals in the world,” said a statement issued by Michael Merritt, the assistant director of investigations for the Secret Service, which pursues counterfeiting and some electronic financial fraud.
As long ago as in November last year, the US attorney’s office in Washington, in a sealed indictment, identified BadB as Horohorin, a 27-year-old residing in Moscow with dual Ukrainian and Israeli citizenship.
However, it was not until Aug. 7 this year that Horohorin, who was traveling from Russia to France, was detained on a warrant from the US as he boarded a plane to return to Russia at an airport in Nice, in southern France.
The Secret Service released a statement on Aug. 11, when the indictment was unsealed. Max Milien, a Secret Service spokesman in Washington, said the agency could not comment about the decision to arrest Horohorin in France.
Olga Shklyarova, spokeswoman for the Russian bureau of Interpol, said no US law enforcement agency had requested Horohorin’s arrest in her country.
“We never received such a request,” she said by telephone.
The Secret Service statement said that Horohorin managed Web sites for hackers who were able to steal large numbers of credit card numbers that were sold online anonymously around the globe. Those buyers would do the more dangerous work of running up fraudulent bills.
The numbers were exchanged on Web sites called CarderPlanet — carder.su and badb.biz — the Secret Service said, and payment was made indirectly through accounts at a Russian online settlement system known as Webmoney, an analogue to PayPal.
Underscoring the nationalistic tone of much of Russian computer crime, one site featured a cartoon of Russian Prime Minister Vladimir Putin awarding medals to Russian hackers.
“We awaiting you to fight the imperialism of the U.S.A.” the site said, in approximate English.
Horohorin lived openly in Moscow. As a foreign citizen, he registered with the police, said Dmitri Zakharov, a spokesman for the Russian Association of Electronic Communication, an industry lobby for legitimate Russian Internet businesses, who cited a database of such registries.
A phone number for Horohorin was out of service on Thursday.
Arrests in Russia for computer crimes are rare, even when hackers living in Russia have been publicly identified by outside groups, like Spamhaus, a nonprofit group in Geneva and in London that tracks sources of spam.
The FBI in 2002 resorted to luring a Russian suspect, Vasily Gorshkov, to the US with a fake offer of a job interview (with a fictitious Internet company called Invita), rather than ask the Russian police for help. To obtain evidence in the case, FBI computer experts had hacked into Gorshkov’s computer in Russia. When this was revealed, Russian authorities expressed anger that the FBI had resorted to a cross-border tactic.
Online fraud is not a high priority for the Russian police, Zakharov said, because most of it is aimed at computer users in Europe or the US.
“This is a main reason why spammers are not arrested,” he said.
Politics may also play a role. Vladimir Sokolov, deputy director of the Institute of Information Security, a Russian research organization, said the US and Russia were still at odds on basic issues of computer security, although the differences were narrowing.
The US tends to view computer security as a law enforcement matter. Russia has pushed for an international treaty that would regulate the use of online weapons by military or espionage agencies. Last year the US opened talks on a treaty, but it has continued to press for closer law enforcement cooperation, Sokolov said.
Computer security researchers have raised a more sinister prospect: that criminal spamming gangs have been co-opted by the intelligence agencies in Russia, which provide cover for their activities in exchange for the criminals’ expertise or for allowing their networks of virus-infected computers to be used for political purposes — to crash dissident Web sites, perhaps.
Sometimes, the collateral damage for online business is immediate. A year ago, for example, hackers used a network of infected computers to direct huge amounts of junk traffic at the social networking accounts of a 34-year-old political blogger in Georgia, a country that fought a war with Russia in 2008. The attack, though, spun out of control and briefly crashed the global service of Twitter and slowed Facebook and LiveJournal, affecting tens of millions of computer users worldwide.
The Russian authorities have repeatedly denied that the state has any connection to such attacks.
Spamhaus says seven of the top 10 spammers in the world are based in the former Soviet Union, in Ukraine, Russia and Estonia.
More ominously, Western law enforcement agencies have traced a code intended for breaking into banking sites to Russian programming.
In 2007, Swedish experts identified a Russian hacker known only by his colorful sobriquet — the Corpse — as the author of a virus that logged keystrokes on personal computers to capture passwords for Nordea, a Swedish bank, and the accounts were drained of about US$1 million.
For a time, these rogue programs were openly for sale on a Russian Web site. The home page displayed an illustration of Lenin making a rude gesture.
Since Horohorin’s arrest, the badb.biz Web site has gone dark. However, on Monday, at least, its CarderPlanet counterpart, the Russian site carder.su, was still open for business.
Jaw Shaw-kong (趙少康), former chairman of Broadcasting Corp of China and leader of the “blue fighters,” recently announced that he had canned his trip to east Africa, and he would stay in Taiwan for the recall vote on Saturday. He added that he hoped “his friends in the blue camp would follow his lead.” His statement is quite interesting for a few reasons. Jaw had been criticized following media reports that he would be traveling in east Africa during the recall vote. While he decided to stay in Taiwan after drawing a lot of flak, his hesitation says it all: If
When Democratic Progressive Party (DPP) caucus whip Ker Chien-ming (柯建銘) first suggested a mass recall of Chinese Nationalist Party (KMT) legislators, the Taipei Times called the idea “not only absurd, but also deeply undemocratic” (“Lai’s speech and legislative chaos,” Jan. 6, page 8). In a subsequent editorial (“Recall chaos plays into KMT hands,” Jan. 9, page 8), the paper wrote that his suggestion was not a solution, and that if it failed, it would exacerbate the enmity between the parties and lead to a cascade of revenge recalls. The danger came from having the DPP orchestrate a mass recall. As it transpired,
Elbridge Colby, America’s Under Secretary of Defense for Policy, is the most influential voice on defense strategy in the Second Trump Administration. For insight into his thinking, one could do no better than read his thoughts on the defense of Taiwan which he gathered in a book he wrote in 2021. The Strategy of Denial, is his contemplation of China’s rising hegemony in Asia and on how to deter China from invading Taiwan. Allowing China to absorb Taiwan, he wrote, would open the entire Indo-Pacific region to Chinese preeminence and result in a power transition that would place America’s prosperity
All 24 Chinese Nationalist Party (KMT) lawmakers and suspended Hsinchu Mayor Ann Kao (高虹安), formerly of the Taiwan People’s Party (TPP), survived recall elections against them on Saturday, in a massive loss to the unprecedented mass recall movement, as well as to the ruling Democratic Progressive Party (DPP) that backed it. The outcome has surprised many, as most analysts expected that at least a few legislators would be ousted. Over the past few months, dedicated and passionate civic groups gathered more than 1 million signatures to recall KMT lawmakers, an extraordinary achievement that many believed would be enough to remove at