Internet Domain Registry

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Wednesday, 15 October 2008

SanCash (Affking) taken down in New Zealand

Posted on 21:03 by Unknown
It was great of the Federal Trade Commission to up an arrest that can be announced at this years eCrime Researchers Summit that I'm attending this week in Atlanta. Right after the afternoon break, a spam researcher from McAfee shared the good news with me: the New Zealand government and the Federal Trade Commission had both taken action againt AffKing / SanCash.

SiL from I Kill SPammers did a column in his blog back on March 3, 2008 called On The Trail of SanCash and Infinity Secure. At the end, he mentions his evidence linking SanCash to GenBucks, Tulip Labs, and Elite Herbal. He mentions that besides SanCash in India, there were representatives located in Christchurch, New Zealand, and issues a warning:


SanCash: your days as a sponsor of illegal spammers are numbered. Spammers in the SanCash Program: we will find you and you will lose everything.


Apparently SiL was right. According the FTC and New Zealand documents, the ring was actually run from Australia and the United States, but had links to ChristChurch. Here's the FTC's intro to the topic from their "Memorandum Supporting Plaintiff's ex parte Motion for a Temporary Restraining Order with Asset Freeze, Other Equitable Relief, and Order to Show Cause Why a Preliminary Injunction Should not Issue":


The FTC asks the Court to take immediate action to shut down an international "spam" enterprise that deceptively markets and sells bogus "male enhancement" pills and "generic" prescription drugs that are falsely claimed to be FDA-approved. Defendants' ongoing deceptive product sales are defrauding consumers out of millions of dollars, and the network of "spammers" that they pay to promote their product is causing considerable harm. Despite taking great efforts to avoid detection, the evidence shows that Australia-based Lance Atkinson and U.S.-based Jody Smith control, and profit from, this operation.

This enterprise -- which operates on the Internet under the name "AffKing" -- is responsible for likely billions of illegal commercial e-mail messages and is one of the largest spam organizations in the world. The FTC has received over three million complaints regarding spam messages connected to this operation. The spam messages sent on behalf of the operation falsify information that would identify the true sender in violation of the federal CAN-SPAM law regulating e-mail marketing. The messages also illegally fail to offer a mechanism by which consumers can opt-out from receiving further email messages.


The FTC had previously placed a permanent injunction ordering Lance Atkinson to cease making false claims about "herbal" products and utilizing illegal spam messages. If the name Lance Thomas Atkinson was familiar, it should! He and his colleague Michael John Anthony Van Essen were charged in the Global Web Promotions Pty Ltd case in 2004, which was called, on April 29, 2004, in this FTC Press Release, "the first criminal action under CAN-SPAM". The FTC had, at that time, received 399,000 email messages that they linked back to Global Web Promotions. Global Web was at that time selling a diet patch and a "Natural Human Growth Hormone" product, which sold at $80 and $74.95 each. Files related to that case may be found Under FTC File No 042-3086, which ended on September 20, 2005 with an order for the pair to pay $2.2 Million dollars. ($490,280 for selling bogus products, and $1,709,982.74 for sending illegal spam).

The current FTC case, FTC File No 072 3085, is against Lance Thomas Atkinson, Inet Ventures Pty Ltd, an Australian proprietary company, Jody Michael Smith, Tango Pay Inc., a Delaware corporation, Click Fusion Inc., a Delaware corporation, and TwoBucks Trading Limited, a Cyprus limited liability company.

The players in the case and their roles, seem to break down like this:

Lance Atkinson, aka "SanCash", sold herbal products and hired spammers to promote them from October 2006 through December 2007. He controlled the website "sancash.com", where his "affiliates" could log in to check their earnings.

The New Zealand Police have many chat logs of Lance talking with his co-conspirators, including one where he recruits Roland Smits to help him run Global Web Promotions. In the chat, Atkinson says "well hopefully it doesn't end in the FTC again."

Other excerpts from the log include Shane telling Lance things like "I have a dude in India who employs 50 people to manually spam people from gmail / hotmail" and "The Russians want to do some serious spamming this weekend".

Just in his ePassporte account, Atkinson received over $1.7 million from the Genbucks account, and transferred over $1.8 Million to others to cover their commissions.

Despite living in Australia, Lance logged in regularly to his "sancash@gmail.com" email address from his home IP.

Things started heating up in December 2007, when an intercepted chat message reveals Shane telling Lance "I had bbc world call my home. i think you need to stop spamming asap."

The Archive.org Wayback machine has archives of sancash from June 29, 2007 to December 11, 2007.

After that time period, Lance partnered with his new US buddy, Jody Smith, to form "affking.com", which replaced the sancash site. Affiliates were paid for their spam services on behalf of "King Replica" and "VPXL" male enhancement pills, as well as "Target Pharmacy" and "Canadian Healthcare".

Revenues for the new operation exceeded $500,000 per month only in payments from Visa. MasterCard charges would presumably make the payment even higher.

Tango Pay received $3.3 Million between September 2007 and May 2008.

Jody Smith ran Tango Pay and Click Fusion operations, using the fake names "Gerald Causey" and "Nicholas Santos"

In addition to the FTC charges, Lance and Shane Atkinson and Roland Smits, are being fined $200,000 by the New Zealanders. More details from New Zealand can be found in this Scoop Politics article.

Chat logs obtained by the New Zealand police reveal that Lance's brother Shane contorlled the company Genbucks.

This weekend, we'll examine our UAB Spam Data Mine to see what types of volumes we may have been dealing with, and some of the domains that were used in the scam.
Email ThisBlogThis!Share to XShare to Facebook
Posted in | No comments
Newer Post Older Post Home

0 comments:

Post a Comment

Subscribe to: Post Comments (Atom)

Popular Posts

  • Happy New Year! Here's a Virus! (New Year's Postcard malware)
    I've been busy this week looking at the various defacements (see ComputerWorld , and ABC News ) and other cyber attacks (see yesterday...
  • From Russia, With Love . . . new Postcard spam spies on your PC
    Isn't it nice to have friends who send you postcards? The UAB Spam Data Mine is especially fortunate in that way. Beginning the evenin...
  • Top Brands Imitated by Malicious Spam
    WebSense recently released an InfoGraphic titled "Top Five Subject Lines in Phishing Emails." for January 1, 2013 through Septemb...
  • New Year's Waledac Card
    We haven't seen a new version of Waledac since Independence Day (July 4, 2009), but it looks like its back! I'm on vacation today, s...
  • Tempting Photo Attachments Lead to Fake AV
    One of today's largest malicious spam campaigns continued an occasional theme we've been seeing for a few weeks. A subject line, fo...
  • What about the Social Security Numbers? (The Utah Data Breach and your SSN)
    The Utah Data Breach This week the continuing saga of the Utah Medicaid Data Breach continued to unfold. If you haven't been following...
  • Stop the Rumors: Quit SMSing about WalMart Gang Initiations
    My daughter and her teenage friend were sitting on the couch watching TV today when they began getting text messages on their phone. Here...
  • Minipost: IPR Center celebrates Cyber Monday
    The National Intellectual Property Rights Center (IPR Center) announced today that in celebration of Cyber Monday, they have Seized 82 Domai...
  • ACH Spammer switches to Shortened URLs
    For many weeks now the spammers behind one particular malware family have been fighting a running battle to keep their malware-hosting domai...
  • Work at Home . . . for a Criminal?
    How do you tell if a "Work at Home" invitation is a scam? Here's a clue: It comes in your email. In today's Blog, I tho...

Categories

  • china
  • computer security careers
  • conficker
  • cyberwar
  • digital certificates
  • facebook
  • fake av
  • gumblar
  • koobface
  • law enforcement
  • malware
  • pharmaceuticals
  • phishing
  • public policy
  • spam
  • twitter
  • twitter malware
  • waledac
  • zbot

Blog Archive

  • ►  2013 (21)
    • ►  December (4)
    • ►  November (1)
    • ►  October (1)
    • ►  September (1)
    • ►  August (3)
    • ►  July (1)
    • ►  June (1)
    • ►  May (5)
    • ►  April (3)
    • ►  March (1)
  • ►  2012 (18)
    • ►  August (1)
    • ►  June (1)
    • ►  May (7)
    • ►  April (2)
    • ►  March (7)
  • ►  2011 (28)
    • ►  November (3)
    • ►  October (1)
    • ►  August (4)
    • ►  July (6)
    • ►  June (1)
    • ►  May (2)
    • ►  April (2)
    • ►  March (6)
    • ►  February (1)
    • ►  January (2)
  • ►  2010 (80)
    • ►  December (6)
    • ►  November (10)
    • ►  October (6)
    • ►  September (12)
    • ►  August (5)
    • ►  July (4)
    • ►  June (11)
    • ►  April (7)
    • ►  March (8)
    • ►  February (4)
    • ►  January (7)
  • ►  2009 (92)
    • ►  December (12)
    • ►  November (11)
    • ►  October (16)
    • ►  September (7)
    • ►  July (5)
    • ►  June (10)
    • ►  May (2)
    • ►  April (6)
    • ►  March (7)
    • ►  February (6)
    • ►  January (10)
  • ▼  2008 (101)
    • ►  December (7)
    • ►  November (17)
    • ▼  October (11)
      • LaSalle acquisition by Bank of America spreads mal...
      • First Enom Phish, now Network Solutions Phish
      • Caution: Enom Phishing continues
      • Ding Dong The Witch Is Dead! ( ICANN Pulls the Pl...
      • Tip to Phishers: First Build Site, THEN Spam
      • Operación Carrusel sets an example for fighting Ch...
      • The demise of index1.php PornTube Video Malware
      • Ryan Goldstein: Digerati Faces ?Justice?
      • FTC stops AffKing and SanCash, so is Pill Spam Gone?
      • SanCash (Affking) taken down in New Zealand
      • Need help with your debt? Ask the Panamanian Russ...
    • ►  September (10)
    • ►  August (22)
    • ►  July (12)
    • ►  June (3)
    • ►  May (7)
    • ►  April (5)
    • ►  March (2)
    • ►  February (1)
    • ►  January (4)
  • ►  2007 (31)
    • ►  December (3)
    • ►  November (9)
    • ►  October (3)
    • ►  September (2)
    • ►  August (5)
    • ►  July (5)
    • ►  January (4)
  • ►  2006 (5)
    • ►  December (2)
    • ►  October (3)
Powered by Blogger.

About Me

Unknown
View my complete profile