❌

Reading view

There are new articles available, click to refresh the page.

Phone-hacking company that won U.S. security agency contracts hid Russian ownership, DOJ alleges

Law enforcement has arrested two leaders of a Russian-owned phone hacking company used by Kremlin agencies who allegedly masked its foreign ownership from the U.S. Defense Department, Department of Homeland Security and others to win millions of dollars worth of contracts, the Justice Department announced Wednesday.

Lee Reiber of Boise, Idaho, the CEO of Oxygen Forensics (Oxygen US), was arrested in his home state and Oleg Davydov, one of five Russian nationals whom DOJ said actually controlled the company, was arrested in London, from where the department plans to seek his extradition. They face charges of conspiracy to commit wire fraud.

Publicly, Oxygen went to great lengths to present Reiber as the true leader of a company based in Alexandria, Va., asserting that the company was not controlled by Russian-based executives, according to a criminal complaint., While the company told government agencies it was U.S.-owned, Russian officials with the company repeatedly overruled him, the complaint alleges. 

Oxygen’s business aims were complicated in 2022 after the United States expanded sanctions against Russia following its invasion of Ukraine. That’s when the company installed Reiber as CEO and removed the owners from public corporate filings. An unnamed co-conspirator in the complaint nonetheless said that “fateful decisions will be made by” five shareholders, including Davydov. 

Since March 2022, Oxygen has sold its forensics software to the U.S. Secret Service, Homeland Security Investigations, the DHS inspector general and DOD. After the 2022 sanctions, Oxygen won more than $2 million in contracts and purchases from the Secret Service and its National Computer Forensics Institute. Reiber asserted U.S. ownership as recently as February of this year to the NCFI, according to the complaint.

Reiber knew the company had to conceal its true ownership, the complaint states. Oxygen and its competitors have quarreled in the media and in courts. Oxygen in 2023 faced accusations that Oxygen US and Oxygen Russia were both using software code reverse-engineered from Elcomsoft’s products. Oxygen Russia’s customers included the Russian Federal Security Service (FSB). 

“The accusation mattered to Reiber because answering it truthfully would have required disclosing that Oxygen US and Oxygen Russia sold the same software, developed by the same team, and were owned by the same people,” the complaint reads, citing email correspondence.

Knowing Oxygen’s actual ownership configuration would’ve changed the equation for the government agencies, according to the complaint.

“Procurement officials at the U.S. government customers have represented that they would not have awarded or renewed contracts for the forensic software had they known that OxygenUS was a Russian-owned company,” the complaint reads.

Natalia Krapiva, senior tech-legal counsel at Access Now, celebrated what she nonetheless called an overdue move from DOJ.

“For years, civil society warned that Oxygen Forensics was owned and built from Russia. Now the Justice Department confirmed it,” Krapiva told CyberScoop. “We applaud the U.S. government for taking this crucial step, but the fact that it took so long is both a national security and a human rights scandal.”

“The same technology that extracted data for U.S. investigations has been used inside Russia to jail journalists, activists, and peaceful dissenters. And it doesn’t stop at the U.S. border,” she continued. “We call on the U.S. and over 100 governments using this technology to immediately sever all ties to the company, implement sanctions, and conduct full investigation(s) of how Russian tech designed for the FSB spent all these years inside their sensitive law enforcement operations.”

Court-listed attorneys for Reiber listed in court documents didn’t respond to requests for comment. No attorney for Davydov could be located.

The DOJ in its announcement specified that “The complaint does not allege that the software contained malicious code or that it was used to gain unauthorized access to any customer’s computer systems or data.”

The post Phone-hacking company that won U.S. security agency contracts hid Russian ownership, DOJ alleges appeared first on CyberScoop.

Arrested man allegedly impersonated NSA elite hacking unit, Supreme Court chief justice

Colorado police arrested a man last week over charges that he impersonated both Supreme Court Chief Justice John Roberts and head of the National Security Agency’s famed Tailored Access Operations hacking unit.

Joshua Culver, also known as “Maverick Young,” appeared in a Colorado court Tuesday after his arrest stemming from an indictment in Indiana in July on four counts of falsely impersonating an officer of the court and one count of using a forged signature of a judge.

Culver allegedly pretended to be an officer of the NSA in September of last year and said in that capacity he “could take adverse action” against the Tippecanoe County sheriff’s office in Lafayette, Ind. if it didn’t provide him information he sought, including the location of his biological daughter.

He also allegedly pretended to be an NSA officer again that month, then produced a document purportedly from the head of the Tailored Access Operations (TAO) elite hacking unit in February to the Clerk of the Lake County, Ind. Superior Court.

“The document, which purported to bear official letterhead, falsely stated that it was a directive issued by the ‘Director of TAO’ and that Culver was a ‘federal asset’ active in multiple investigations,” the indictment reads. “The document commanded that certain actions be taken as required by ‘federal directive,’ including that the case pending against Culver be dismissed with prejudice, that warrants be quashed, and that Lake County officials cooperate with a ‘federal audit’ of individuals identified in the document.”

TAO has gone by the name of Office of Computer Network Operations since 2017, although in July it indicated that it was resuming its old name. TAO garnered unflattering attention in 2017 after the global WannaCry ransomware outbreak used an exploit that the NSA developed.

The indictment also alleges that Culver used a forged signature of Roberts in September for an “Order of Dismissal With Prejudice” in a case against Culver in Grant County, Indiana.

A defender appointed to Culver did not immediately respond to a request for comment Tuesday.

You can read the indictment below.

The post Arrested man allegedly impersonated NSA elite hacking unit, Supreme Court chief justice appeared first on CyberScoop.

Eight years later, federal authorities re-up charges against alleged Iranian hackers at Mabna Institute

Federal authorities on Tuesday unsealed an indictment against 17 Iranians affiliated with the tech firm Mabna Institute, alleging a campaign of vast cybertheft on behalf of the Iranian government against universities, governments and companies.

It’s a second wave of indictments against the Tehran-based firm, expanding on and replacing a 2018 indictment of nine of the defendants from then and adding others. 

“Today’s charges, which include eight additional defendants, reveal the broader network allegedly behind a sweeping, state-sponsored campaign to steal research and intellectual property from American universities, businesses, and government institutions,” said Jamie McDonald, U.S. Attorney for the Southern District of New York. “More than eight years after making the original indictment public, these charges make clear that the passage of time will not deter us from identifying and pursuing those who target the United States from abroad.”

Unlike in 2018, the United States is currently waging a war against Iran that recently saw a 60-day negotiation deadline pass with no progress.

“Cyber operations have become a central instrument of national power, and attacks on American and allied institutions carry direct consequences for our security and economic strength,” McDonald continued.

According to the Justice Department, Gholamreza Rafatnejad and Ehsan Mohammadi founded the Mabna Institute around 2013 with the goal of helping Iranian universities and scientific and research organizations to steal from foreign scientific efforts. In doing so, it paid hackers-for-hire listed in the indictment.

The institute has compromised more than 100,000 professors’ email accounts globally, the indictment alleges, and successfully compromised 8,000 accounts at 144 U.S. universities and 178 universities in other parts of the world.

Its hackers used stolen credentials to take academic journals, dissertations and e-books across all fields of research, at least 31.5 terabytes worth in total. The institute sometimes sold stolen data, according to the indictment. 

“Through the course of the conspiracy, U.S.-based universities spent more than approximately $3.4 billion to procure and access such data and intellectual property,” a press release on the indictment states.

The defendants also have compromised and stolen from email accounts for at least five U.S. federal and state government agencies, 42 U.S. companies and 11 foreign companies, among them HBO. 

In all, the indictment brings 14 separate, sometimes overlapping charges against the 17 defendants, with sentences for each offense ranging from two to 20 years.

In conjunction with the indictment, the State Department’s Rewards for Justice program is offering up to $10 million for information leading to the location of four of the defendants.

The post Eight years later, federal authorities re-up charges against alleged Iranian hackers at Mabna Institute appeared first on CyberScoop.

❌