Justice Department Indicts Two Iranians Over SamSam Ransomware Attacks

  • 28 November 2018
  • 1 reply
  • 2 views

Userlevel 7
Badge +48
U.S. federal prosecutors have indicted two Iranian nationals for creating and deploying the notorious SamSam ransomware.
 
28th November 2018, By Zach Whittaker 
 


 
 
Faramarz Shahi Savandi, 34, and Mohammad Mehdi Shah Mansouri, 27, were indicted by a federal grand jury in New Jersey on Monday on several counts of computer hacking and fraud charges. The case was unsealed Wednesday, shortly before a press conference announcing the charges by U.S. deputy attorney general Rod Rosenstein.
 
“The Iranian defendants allegedly used hacking and malware to cause more than $30 million in losses to more than 200 victims,” said Rosenstein. “According to the indictment, the hackers infiltrated computer systems in ten states and Canada and then demanded payment. The criminal activity harmed state agencies, city governments, hospitals, and countless innocent victims.”
 
 
Full Article
 
 
 

1 reply

Userlevel 7
Badge +25
These guys are a bunch of dummies! I can't believe they made $6M
 
Looking at the official court docs linked in the article 
"On or about July 21, 2016, defendant MANSOURI sent a chat communication to Exchanger #1 instructing him to convert Bitcoin associated with ransom proceeds into Iranian rial and to deposit the rial into accounts controlled by defendant MANSOURI and defendant SAVANDI"
 
It appears the criminals didn’t convert their bitcoin to Monero or another private ledger crypto – they sent their bitcoin straight to the exchange. This seems like a silly error because you can track transactions from the ransom address all the way the exchange. All exchanges that deal in fiat (Rial, US dollars, Euro) have KYC (know your customer) which likely means this is how they are being charged with COUNT 2 "conspiracy to commit wire fraud." I expect criminals in the future to be even more careful about how they convert their bitcoin into cash. 

Reply