Tech News : Global Call-Spoofing Operation Shut Down

The UK’s National Crime Agency (NCA) has shut down a global call-spoofing operation called ‘Russian Coms’ which is believed to have been used to swindle more than 170,000 victims.

Russian Coms 

Russian Coms is the name of the major caller ID spoofing platform used by criminals to make over 1.8 million fraudulent calls to victims in 107 countries, including the UK, US, New Zealand, Norway, and France. Started in 2021, the platform is believed to have been responsible for financial losses amounting to tens of millions of pounds. It was the Russian Coms platform itself that was shut down by the NCA.

What Is Call Spoofing / ID Spoofing? 

Call spoofing, also known as ID spoofing, is a technique used to falsify the information displayed on the caller ID screen of the recipient’s phone. In other words, it allows the caller to appear as though they are calling from a different number. Criminals can, therefore, display the actual number of the victim’s bank or a government agency, thereby deceiving the recipient into answering the call or divulging sensitive information.

Criminals Paid For Months of Call Spoofing Features 

In the case of the Russian Coms platform, criminals were paying to use the Russian Coms platform to enable them to conduct ID spoofing activities, e.g. they were paying the Russian Coms administrators between £1,200 and £1,400 in cryptocurrency (for anonymity) for a six-month contract use the platform. This provided the criminals with services such as a smartphone (or, more recently, a web app) encrypted calls, web phone capabilities, instant handset wipes, voice-changing features, international calls, and 24/7 support. These features allowed them to spoof the phone numbers of banks or financial institutions, to gain the trust of their victims before stealing money and personal details.

Example 

An example of the kind of ID Spoofing crime committed using the platform was the criminal using the platform’s services would spoof the phone number of a bank (e.g. call a victim pretending to be from their bank) and deceive them into transferring their money to a new account by claiming that fraudulent activity had been noticed in their current account.

London, Not Russia 

In fact, despite the name of the platform, the two men suspected of being the platform’s developers and administrators (aged 26 and 28), were arrested in Newham, London, back in March. A third man, also 28 years old, suspected of being the handset courier, was arrested in April, and last week, one of the many hundreds of scammers thought to have used the platforms services was arrested in Potters Bar.

Handsets pre-loaded 

The smartphone-style handsets provided to scammers as part of the Russia Coms service are reported to have been preloaded with fake apps to fool law enforcement, a VPN to hide the scammer’s IP address, and a ‘burn app / burner app’ that could be used to wipe the handset instantly if needed.

How Much? 

The NCA has reported that between 2021 and 2024, the criminal users of Russian Coms made 1.3 million+ calls to 500,000 unique UK phone numbers, and the average reported loss of victims was more than £9,400.

Bailed 

Although the 3 men arrested in the UK suspected of being associated with the operation of Russian Coms have been bailed, it’s understood that a global operation is now under way to track down the many hundreds of criminals who used the platforms services.

What Does This Mean For Your Business? 

The shutting-down of the Russian Coms operation by the UK’s National Crime Agency (NCA) is a reminder of the evolving sophistication of cyber threats that individuals and businesses face today. For businesses, it’s a reminder of the pressing need to remain vigilant and proactive in their cybersecurity measures and of the importance of implementing robust security protocols to safeguard sensitive information.

It’s also a reminder to businesses to ensure that their employees are trained to recognise phishing and spoofing attempts, as these are common methods used by cybercriminals to gain unauthorised access to company and customer data. Regular training sessions and updated cybersecurity policies can help mitigate these risks.

Businesses should also consider investing in advanced security technologies such as multi-factor authentication, end-to-end encryption, and anti-spoofing measures. These tools can provide an extra layer of security, making it more difficult for cybercriminals to impersonate trusted entities and deceive employees or customers.

The case of Russian Coms also highlights the significance of monitoring and reporting suspicious activities. Prompt reporting to authorities can aid in the swift takedown of fraudulent operations and protect other potential victims. Establishing a clear protocol for employees to report suspicious communications can enhance the overall security posture of the organisation.

Also, the financial implications of cyber fraud cannot be overstated. With reported average losses exceeding £9,400 per victim, the cumulative impact on affected businesses and individuals can be devastating. Therefore, it is crucial for businesses to have comprehensive insurance policies that cover cyber-related incidents and potential financial losses.

The dismantling of Russian Coms appears to be a victory for law enforcement but also a wake-up call for businesses worldwide. By adopting stringent cybersecurity measures, educating employees, and staying vigilant, businesses can better protect themselves against the ever-present threat of cybercrime. The proactive steps taken today can prevent costly breaches and preserve the trust and integrity that are vital to a company’s success.

Tech Insight : Police : Don’t Try Hiding Money in Crypto

The Home Office has announced that in an attempt to tackle the issue of drug dealers, fraudsters and terrorists using crypto to hide and raise money, it’s giving new powers to the police.

Over £1 Billion In Illegal Crypto Transactions 

With over £1 billion in illegal crypto transactions taking place in the UK each year, the Home Office has announced that the government has now updated its proceeds of crime and terror legislation so that the National Crime Agency and police now have the powers to seize, freeze and destroy the crypto assets used by criminals.

Stopping Criminals, And Supporting Economic Growth 

The government says the changes to the legislation, which have already come into force, will provide the dual benefits of stopping criminals from undermining the legitimate use of crypto, and supporting the development of crypto as a potential driver of economic growth.

Why Are Criminals Turning To Crypto? 

Criminals are increasingly using crypto-assets for several reasons, including:

– The level of anonymity that cryptoassets provide – transactions don’t require personal information like traditional banking does. This makes it harder for authorities to trace activities back to specific individuals.

– The decentralisation of cryptocurrencies. Crypto transactions don’t rely on centralised financial institutions and this reduces the oversight and interference from authorities and enables cross-border transactions with fewer restrictions.

– Cryptocurrencies allow for fast transactions that can be conducted at any time, from anywhere, without needing to go through traditional banking processes. This is advantageous for illicit activities that require fast and flexible operations.

– Global reach. Cryptoassets can be used internationally without the need for currency exchange or the complications of international banking regulations, facilitating global criminal operations.

– The irreversibility, i.e. once a crypto transaction is confirmed, it can’t be reversed. This protects criminals from chargebacks or other forms of financial reversal typically available in traditional banking systems.

Using Cryptoassets For Laundering and Raising Money 

As highlighted by the Home Office, crypto-assets are also increasingly used for laundering the proceeds of crime and for raising money for illicit activities. For example, this can involve using:

– Layering and integration. Cryptocurrencies can be used to obscure the origins of illegally obtained money through complex layers of transactions across multiple wallets and exchanges. This process, known as “layering,” helps criminals disguise the source of funds. The final step, “integration,” sees the now-disguised funds reintroduced into the legitimate economy, appearing as legal assets.

– Services known as “mixers” or “tumblers” obscure the source of funds by mixing potentially identifiable or “tainted” cryptocurrency funds with others, making it harder to trace the origins of the funds.

– Criminals can raise money by creating new cryptocurrencies or tokens and selling them to investors through ICOs (Initial Coin Offerings and Token Sales). These can sometimes be scams, with the organisers disappearing with the investors’ money, a process known as an “exit scam.”

– Many cryptocurrency exchanges and wallets operate with little to no regulatory oversight, providing a less scrutinised environment for moving and storing illicit funds.

– Cryptocurrencies are the primary mode of transaction in darknet markets, where illegal goods and services (like drugs, weapons, and illicit materials) are traded. These markets provide a ready avenue for criminals to earn and launder money through crypto transactions.

The Changes 

The new changes to UK legislation to tackle the issue of criminals using crypto assets mean that:

– Police are no longer required to make an arrest before seizing crypto from a suspect. The hope is that this will make it easier to take assets which are known to have been criminally obtained, even if sophisticated criminals are able to protect their anonymity or are based overseas.

– Items that could be used to give information to help an investigation, such as written passwords or memory sticks, can now be seized.

– UK Law enforcement officers can now transfer illicit cryptoassets into an electronic wallet which they control, meaning criminals can no longer access it.

– UK law enforcement now have the power to destroy a crypto asset if returning it to circulation is not conducive to the public good. Privacy coins, for example, are a type of cryptocurrency that offer an extremely high degree of anonymity and are often used for money laundering.

– Victims can now apply for money belonging to them in a cryptoassets account to be released to them.

Next Level 

Following the changes to the law, Security Minister Tom Tugendhat said: “Our agencies have already shown they have the expertise to target sophisticated criminals and deprive them of their ill-gotten gains. These new measures will help them take the fight to the next level.” 

Also, Adrian Searle, Director of the National Economic Crime Centre, said: “Criminals are increasingly using crypto assets to conceal and move the proceeds of crime at scale and pace, pay for other criminal services and as a means to defraud victims” and that “these new powers are very welcome and will enhance law enforcement’s ability to restrain, recover and destroy crypto assets if required.”

Examples 

Examples recently given by the Home Office of where they’ve been successful in thwarting criminals by seizing their crypto-assets include the NCA working with the United States Drug Enforcement Administration to investigate a multi-million drug enterprise which led to $150 million (in cash and crypto) being seized (January 2024). Also, the Home Office has highlighted how crypto-assets were seized in a case where three men sold counterfeit drugs on the dark web and accepted crypto as payment, amassing £750,000 in the process. They were jailed for more than 20 years between them.

What Does This Mean For Your Business? 

These changes to UK legislation could have significant implications for the landscape around cryptocurrency usagee, affecting everyone from cyber-criminals to legitimate users and UK businesses alike.

For cyber-criminals, this represents a tightening of the net. The new powers granted to police to seize, freeze, and even destroy crypto-assets (without prior arrest) shows tougher governmental response to the sophisticated ways criminals are exploiting digital currencies. This stance may deter some criminal activities, but it may also, in some cases, push others to find even more clandestine methods or technologies to evade detection.

For legitimate users of cryptocurrencies, these changes could enhance the security of the crypto ecosystem. While it may introduce some inconvenience, e.g. increased scrutiny of transactions and potentially stricter KYC (Know Your Customer) and AML (Anti-Money Laundering) procedures, these measures are intended to protect the economic environment from being undermined by illicit activities. For the broader crypto market, this could mean a more stable and trustworthy system that could encourage greater adoption and potentially increase the value of law-abiding crypto enterprises.

For UK businesses, especially those operating in the tech and financial sectors, this change in the law could be a catalyst for innovation and adaptation. Companies involved in blockchain and fintech may find new opportunities in developing solutions that align with legal requirements while enhancing transaction security and transparency. This could open up new markets and customer bases that were previously wary of the potential risks associated with crypto transactions.

It’s also worth noting that for victims of crime, the ability to apply for the release of funds from crypto accounts is a significant step forward. This not only provides a means of recourse and recovery but also means that the rights and protections of victims are now being taken more seriously.

Although the new legislation introduces challenges, it looks as though it could help with increased security, enhanced trust in digital transactions, and potential growth and innovation within the UK’s tech and financial sectors. Some would say that, not before time, this is a sign that legislation (which seems to move slowly) is starting to catch up with criminal activities around crypto, and police are finally being given more of the powers they need.

Security Stop Press : ConnectWise LockBit Alert

Just days after it was announced that the UK’s National Crime Agency (NCA), the FBI, and Europol had taken down the Russian LockBit ransomware gang’s website, it’s been reported that LockBit ransomware is still being deployed via flaws in a popular remote access tool.

Researchers at cybersecurity companies Huntress and Sophos have highlighted how two bugs in the ConnectWise ScreenConnect remote access IT support tool, usually used by IT technicians, are being exploited to launch LockBit attacks.

ConnectWise has issued an alert urging IT administrators to take quick action to patch the two critical vulnerabilities. Details are available here.