Internet Domain Registry

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Friday, 5 November 2010

Minipost: NY Zeus "At Large" Codreanu and Adam captured

Posted on 12:38 by Unknown
We've previously posted about the FBI's Operation ACHing Mule (that's A-C-H as in Automated-Clearing-House, the way American banks send money between themselves) and the 17 Wanted Zeus Criminals who were still at large for their roles in moving massive amounts of money to Eastern Europe.

While we previously shared some fun Facebook photos of the "at large" criminals, we were encouraged to wait until they were arrested to share more of our findings.

Today @nigroeneveld let us know that two more of the missing baddies had been located, and were actually arrested arraigned yesterday in Madison, Wisconsin.

Graham Cluley had the first story I saw on the arrests on his Naked Security Blog, but I haven't really seen any details on how they were caught.


What do we know about how Dorin got into the country? All we have to go by is hearsay, but let's just say its interesting that convicted Zeus Money Mule Alina Turatura, at large Zeus Money Mule Catalina Cortac, and Dorin were all Facebook Friends with "Acord Travel" or Chisinau, Moldova, whose Facebook page calls them the "Lider in Programe Work and Travel" which would be consistent with the J1 Visa Travel theory.



Is Zeus connected with the Mafia? Let's just say that Dorin, whose profile picture featured himself holding a sign that reads "HELP! I Need Money for WEED!", was a level 68 criminal:




As a reminder, on April 21, 2010, Dorin Codreanu, carrying a Greek passport with his photo and the name "Savvas Paian", walked into a J.P. Morgan Chase Bank in New York and opened a new account with an initial $25 deposit. On May 4th, someone deposited $10 into the account. Then on May 11, 2010, someone wire transfered $10,246 from Illinois to the account. Within two days, $10,236 of that amount had been withdrawn, including a $800 ATM withdrawal, a $140 ATM withdrawal, and counter checks in the amounts of $2,000 and $4,800 from two different branches in the Bronx.

On May 18, 2010, Savvas Paian opened a business account at TD Bank North America in Cherry Hill, New Jersey using the same Greek Passport, in the name of "Savvas Import Group LLC". As we mentioned earlier, that's a "fruit and vegetable importer" at "1612 Kings Highway, Apartment 48, Brooklyn New York, 11229-1210 -- which used the same phone number as "Brooklyn Fruit Vegetable Growers Shippers" and "Neptune Fruit Vegetable Growers Shippers", which makes one wonder if there may be other bank accounts as well.

I think that rates as probably much lower than level 68, but I may be wrong. Dorin actually was recruiting other Moldovan students, named in the indictment as "CC-1", "CC-2", "CC-3", and "CC-4" to assist his efforts. Codreanu helped CC-1 get into the business, and CC-1 brought CC-2, who was also recruited to work under Codreanu. CC-2 received payments and made withdraws of approximately $34,000 from July 6 to July 9. CC-1 and CC-2 were arrested on August 4th, but have not been named.



Lillian Adam


Also arrested with Codreanu was Lillian Adam, also known as Roman Kobilev.

Lillian is one of four individuals named in the same indictment - the others being:

his at least sometime girlfiend, Catalina Cortac, pictured here kissing Adam on top of the Empire State Building:



Catalina Cortac, who is still friends with Acord Travel, and who claims to have successfully returned to Chisinau, Moldova.




Marina Oprea, who shares with us her "New York" photo album on Facebook, featuring bathing beauties Marina and Catalina:



I have no idea why Marina preferred to be photographed with Banks . . .





According to the Indictment, Marina opened accounts at both Chase Bank and M&T Bank, and used them to receive tens of thousands of dollars.

Ion Volosciuc --
Email ThisBlogThis!Share to XShare to Facebook
Posted in | No comments
Newer Post Older Post Home

0 comments:

Post a Comment

Subscribe to: Post Comments (Atom)

Popular Posts

  • From Russia, With Love . . . new Postcard spam spies on your PC
    Isn't it nice to have friends who send you postcards? The UAB Spam Data Mine is especially fortunate in that way. Beginning the evenin...
  • Happy New Year! Here's a Virus! (New Year's Postcard malware)
    I've been busy this week looking at the various defacements (see ComputerWorld , and ABC News ) and other cyber attacks (see yesterday...
  • Top Brands Imitated by Malicious Spam
    WebSense recently released an InfoGraphic titled "Top Five Subject Lines in Phishing Emails." for January 1, 2013 through Septemb...
  • A Dark and STORMy Night
    Just in time for the spookiest night of the year, the Storm botnet recruitment spam switched to a Halloween flavor. On the evening of Octobe...
  • TJX Update: The San Diego Indictments
    As promised, here is the update regarding the eight individuals charged in San Diego in connection with "the TJX bust". There wer...
  • Help stop the Osama bin Laden Videos on Facebook
    If you have teenage friends, or friends with poor security practices, you will probably notice that your wall has recently filled up with in...
  • New Year's Waledac Card
    We haven't seen a new version of Waledac since Independence Day (July 4, 2009), but it looks like its back! I'm on vacation today, s...
  • Facebook Safety & Million Member Facebook Groups
    Two of my friends today invited me to join "Million User" facebook groups. Not that it matters really, but the two groups were: P...
  • First 2008 Presidential Spam Campaign?
    Does Ron Paul suddenly have a strong support base among foreign computer owners with strange names and multiple personalities? or is it poss...
  • 70 Romanian Phishers & Fraudsters Arrested
    On March 4th, FBI Director Robert Mueller was given a speech on Cybercrime to the RSA conference where he mentioned that: And we have worke...

Categories

  • china
  • computer security careers
  • conficker
  • cyberwar
  • digital certificates
  • facebook
  • fake av
  • gumblar
  • koobface
  • law enforcement
  • malware
  • pharmaceuticals
  • phishing
  • public policy
  • spam
  • twitter
  • twitter malware
  • waledac
  • zbot

Blog Archive

  • ►  2013 (21)
    • ►  December (4)
    • ►  November (1)
    • ►  October (1)
    • ►  September (1)
    • ►  August (3)
    • ►  July (1)
    • ►  June (1)
    • ►  May (5)
    • ►  April (3)
    • ►  March (1)
  • ►  2012 (18)
    • ►  August (1)
    • ►  June (1)
    • ►  May (7)
    • ►  April (2)
    • ►  March (7)
  • ►  2011 (28)
    • ►  November (3)
    • ►  October (1)
    • ►  August (4)
    • ►  July (6)
    • ►  June (1)
    • ►  May (2)
    • ►  April (2)
    • ►  March (6)
    • ►  February (1)
    • ►  January (2)
  • ▼  2010 (80)
    • ►  December (6)
    • ▼  November (10)
      • Minipost: IPR Center celebrates Cyber Monday
      • Cyber Monday Warnings
      • Schoolboy Hackers steal $18 Million (£12 Million p...
      • Another M00P Group Member arrested
      • Lord Aughenbaugh of the Trailer Park
      • Lin Mun Poo: Hacker of the Federal Reserve and ...?
      • WIRED: November Jargon Watch & Forensics?
      • Minipost: NY Zeus "At Large" Codreanu and Adam cap...
      • Sextortion Hacker: Victims sought by FBI
      • USAA Phish: Avalanche uses many "redirectors"
    • ►  October (6)
    • ►  September (12)
    • ►  August (5)
    • ►  July (4)
    • ►  June (11)
    • ►  April (7)
    • ►  March (8)
    • ►  February (4)
    • ►  January (7)
  • ►  2009 (92)
    • ►  December (12)
    • ►  November (11)
    • ►  October (16)
    • ►  September (7)
    • ►  July (5)
    • ►  June (10)
    • ►  May (2)
    • ►  April (6)
    • ►  March (7)
    • ►  February (6)
    • ►  January (10)
  • ►  2008 (101)
    • ►  December (7)
    • ►  November (17)
    • ►  October (11)
    • ►  September (10)
    • ►  August (22)
    • ►  July (12)
    • ►  June (3)
    • ►  May (7)
    • ►  April (5)
    • ►  March (2)
    • ►  February (1)
    • ►  January (4)
  • ►  2007 (31)
    • ►  December (3)
    • ►  November (9)
    • ►  October (3)
    • ►  September (2)
    • ►  August (5)
    • ►  July (5)
    • ►  January (4)
  • ►  2006 (5)
    • ►  December (2)
    • ►  October (3)
Powered by Blogger.

About Me

Unknown
View my complete profile