Vue lecture

Ukraine says it busted a Kyiv crypto ring that drained EU citizens’ wallets

SBU and Prosecutor General’s Office personnel stand inside a crowded room with computers as several people with pixelated faces lie or sit on the floor. An armed tactical officer stands near the back.

Ukraine’s Security Service (SBU) and National Police shut down a Kyiv-based network of several dozen people who allegedly used fake cryptocurrency investment platforms and malicious code to steal digital assets from citizens of EU countries, the SBU said on 1 September.

Investigators identified the alleged organizer as a 25-year-old Kyiv IT specialist, according to the SBU. The case reaches beyond Ukraine because the agency says the alleged victims were EU citizens. The agency said the network’s monthly turnover from funds obtained illegally could reach $1 million during its most lucrative periods.

The SBU said investigators had documented alleged crimes by every member of the group. However, its statement did not specify how long the network had operated, how many EU citizens were affected, which countries they lived in, or the total amount allegedly stolen.

The agency did not name any foreign law enforcement partners involved.

How the crypto ring operated

The alleged organizer of the crypto ring recruited other tech workers in the capital, the SBU said. Posing as cryptocurrency-platform representatives, they offered targets seemingly profitable ways to invest in digital assets.

The network found victims by posting about supposedly lucrative crypto projects in popular Telegram channels, then showed them fabricated trading results and fake profits to make the operation look legitimate, investigators said.

Engaged targets were sent a link to a counterfeit site that mimicked a real crypto service and were persuaded to connect their wallets and approve a transaction, the SBU said. The site carried malicious code called a “drainer” that, the agency said, let the operators withdraw the victims’ assets to addresses they controlled—emptying the wallets.

During 23 searches of the suspects’ offices and homes, officers seized phones, computers, money believed to be criminal proceeds, and 16 high-end cars, including Porsche, BMW, and Mercedes-Benz models, the SBU said.

Authorities were still deciding whether to serve notices of suspicion, while the investigation continued under the Prosecutor General’s Office, the SBU said. Those involved could face up to 12 years in prison with confiscation of property.

Ukraine’s role in combating cross-border cybercrime

Ukraine has previously joined with foreign agencies to pursue cross-border cyber threats. In April, the SBU said it worked with the FBI, EU law enforcement, and Polish counterintelligence to disrupt Russian military-intelligence spying through hacked routers. The operation blocked more than 100 servers and removed hundreds of routers in Ukraine from Russian control.

  •  

How Cyber Sleuths Tracked a Nigerian Scammer to His Doorstep

How Cyber Sleuths Tracked a Nigerian Scammer to His Doorstep

This is an adaption of a podcast interview 404 Media recorded with Erin West and Paul Raffile. Check out the whole thing here on YouTube.

Erin West and Paul Raffile stepped out of their van about 45 minutes outside Lagos, Nigeria, and walked down a muddy hill. At the bottom, they entered a field with houses made of corrugated steel and cardboard. Raffile kept falling into the mud.

After walking about a quarter of a mile, the pair came to a hut, six feet high on stilts, and climbed up a ladder. Inside was the baba lao, a local spiritual leader. The baba lao was going to do a ritual designed to ensure a Nigerian scammer would make more money in his blackmailing or manipulation of an overseas victim, maybe back in the United States.

A scammer who accompanied West and Raffile had a photo of the victim he was trying to get money from, and the identity he had impersonated to do so. The baba lao then fused these two souls together to bring more fortune to the scammer, Raffile recalled. For two and a half hours, the baba lao jumped between grinding herbs, creating talismans, sacrificing an animal. Locals gathered outside the hut.

West and Raffile are scam experts: West is the founder of Operation Shamrock, an organization that aims to disrupt scam operations, and Raffile is a long time cybercrime researcher, who focuses especially on sextortion. This is where scammers, like those in Nigeria, will assume the identity of a young person, approach teenagers in the U.S. on apps like Instagram, have them record explicit videos, then pull the mask away and threaten to release the videos to the victim’s friends and family unless they pay up. Sextortion is common across U.S. social media platforms; at least dozens of young boys have taken their own lives after being targeted.

The pair hatched a plan to go to Nigeria to see if they could actually track down a scammer. The trip provided rare insight into how some scammers live and how brazenly many of them flaunt their scams.

Sextortion is “targeting youth. It's surging,” Raffile said. “I wonder, can we hatch a plan where we put ourselves out there as a target, create our own fake account, get scammed by these criminals, and then trace the criminal back to their home turf?”

💡
Do you know anything else about Nigerian scammers? I would love to hear from you. Using a non-work device, you can message me securely on Signal at joseph.404 or send me an email at joseph@404media.co.

They made an Instagram and Snapchat account pretending to be a young person. Within a couple of days, they started receiving suspicious direct messages. West said she was “flabagasted” at how quickly the messages came in.

The scammers were pretending to be young women, often using photos stolen from OnlyFans models. As the chat progressed and the scammers demanded money, the pair said they could only pay in Bitcoin, and sent a link to a website where the scammer could allegedly claim their payment. The site was actually grabbing the scammers’ IP addresses. It showed the scammers were in Lagos, Nigeria. With not much to go on just yet, the pair got on a flight to Nigeria.

Once they landed, they had around six days to find a scammer. It would not be financially viable to sit around in Lagos forever. The pair deployed the IP address grabbing website again, but this time one of the scammers granted the tool more permissions in his browser. The tool was also designed to, if possible, get their exact location, or turn on its camera and see their face. This time, it worked. They had a scammer’s face.

At one point, another scammer asked the pair to move from Instagram, where the conversation initially happened, over to WhatsApp, which revealed the scammer’s phone number. The pair’s fixer put that number into TrueCaller— an app that harvests peoples’ phone contact lists and makes them searchable, essentially — which revealed the name Big Dollar. West also provided the number to some contacts who investigated it. They worked with another expert too who was able to dig up more information and find the scammer’s real name. They then found other social media profiles belonging to Big Dollar, including a TikTok account that had posted blackmail messages. The pair were given GPS coordinates of where this scammer might be.

They drove to Big Dollar’s village, and ultimately he refused to meet the pair. West told Big Dollar on the phone, we know who you are, we know where you live, and the next step is we’re going to give this information to the FBI. Around this time, they saw Big Dollar’s social media accounts go dark. 

West said, “it was an interesting opportunity to really put some fear in a class of people who aren't really afraid of being arrested.”

  •  
❌