Accused email scammers busted in Nigeria for alleged fraud against 50,000 victims
Full article552 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
The TMT gang has compromised victims in more than 150 countries, according to Interpol and Group-IB.
An Interpol-helmed operation led to the arrest of three suspected cybercriminal gang members in Nigeria whose outfit has allegedly targeted victims in more than 150 countries, including schemes that involved offering COVID-19 aid.
The sting, announced Wednesday, was part of Operation Falcon, a year-long investigation that teamed with cybersecurity company Group-IB and the Nigeria Police Force.
“This group was running a well-established criminal business model,” said Craig Jones, Interpol’s cybercrime director. “From infiltration to cashing in, they used a multitude of tools and techniques to generate maximum profits.”
The gang, dubbed TMT, is divided into numerous subgroups, according to Vesta Matveeva, head of Group-IB’s APAC Cyber Investigations Team. The three suspects arrested in Lagos tallied 50,000 victims in government and industry, the company said. Matveeva said via email that TMT overall might have compromised more than 500,000 victims since 2017.
TMT’s speciality is business email compromise (BEC), where the attackers pose as someone known to an organization, most often to request authentic-looking money transfers. The FBI’s Internet Crime Complaint Center recorded $1.7 billion in losses from BEC scams last year alone, a figure that’s based only on complaints received.
The gang deploys mass phishing campaigns and relies on a range of publicly-available spyware and remote access trojans, among them AgentTesla, Loki, AzoRult, Pony, NetWire, Spartan and NanoCore, according to Group-IB and Interpol.
It sends purchasing orders and product inquiries, and has impersonated legitimate companies offering COVID-19 aid, Group-IB said. It counts victims in the U.S., U.K., Singapore, Japan and Nigeria, according to Group-IB data.
“While the monetization methods of this gang are still being investigated, it’s not uncommon for cybercriminals to sell account access as well as sensitive data extracted form emails could to the highest bidder in the underground markets,” Group-IB said.
Trend Micro, in fact, has identified TMT as a group that sells stolen credentials.
The operation only identified the arrested suspects by their initials, O.C., I.O. and O.I.
The Interpol-led investigation into TMT is ongoing.
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Technology
Threats
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/nigeria-email-scam-arrests-bec-group-ib/