• Home
  • Cyber Crime
  • Cyber warfare
  • APT
  • Data Breach
  • Deep Web
  • Digital ID
  • Hacking
  • Hacktivism
  • Intelligence
  • Internet of Things
  • Laws and regulations
  • Malware
  • Mobile
  • Reports
  • Security
  • Social Networks
  • Terrorism
  • ICS-SCADA
  • POLICIES
  • Contact me
MUST READ

Athlete or Hacker? Russian basketball player accused in U.S. ransomware case

 | 

U.S. CISA adds Citrix NetScaler ADC and Gateway flaw to its Known Exploited Vulnerabilities catalog

 | 

UK NCA arrested four people over M&S, Co-op cyberattacks

 | 

PerfektBlue Bluetooth attack allows hacking infotainment systems of Mercedes, Volkswagen, and Skoda

 | 

Qantas data breach impacted 5.7 million individuals

 | 

DoNot APT is expanding scope targeting European foreign ministries

 | 

Nippon Steel Solutions suffered a data breach following a zero-day attack

 | 

Iranian group Pay2Key.I2P ramps Up ransomware attacks against Israel and US with incentives for affiliates

 | 

Hackers weaponize Shellter red teaming tool to spread infostealers

 | 

Microsoft Patch Tuesday security updates for July 2025 fixed a zero-day

 | 

Italian police arrested a Chinese national suspected of cyberespionage on a U.S. warrant

 | 

U.S. CISA adds MRLG, PHPMailer, Rails Ruby on Rails, and Synacor Zimbra Collaboration Suite flaws to its Known Exploited Vulnerabilities catalog

 | 

IT Worker arrested for selling access in $100M PIX cyber heist

 | 

New Batavia spyware targets Russian industrial enterprises

 | 

Taiwan flags security risks in popular Chinese apps after official probe

 | 

U.S. CISA adds Google Chromium V8 flaw to its Known Exploited Vulnerabilities catalog

 | 

Hunters International ransomware gang shuts down and offers free decryption keys to all victims

 | 

SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 52

 | 

Security Affairs newsletter Round 531 by Pierluigi Paganini – INTERNATIONAL EDITION

 | 

North Korea-linked threat actors spread macOS NimDoor malware via fake Zoom updates

 | 
  • Home
  • Cyber Crime
  • Cyber warfare
  • APT
  • Data Breach
  • Deep Web
  • Digital ID
  • Hacking
  • Hacktivism
  • Intelligence
  • Internet of Things
  • Laws and regulations
  • Malware
  • Mobile
  • Reports
  • Security
  • Social Networks
  • Terrorism
  • ICS-SCADA
  • POLICIES
  • Contact me
  • Home
  • Cyber Crime
  • Social Networks
  • IntelCrawler update- BlackPOS author forgot delete social network page

IntelCrawler update- BlackPOS author forgot delete social network page

Pierluigi Paganini January 20, 2014

Security experts at IntelCrawler provided a new interesting update on BlackPOS author, he forgot to delete his social network page.

Intelligence firm IntelCrawler announced a few days ago that the author of the BlackPOS/Kaptoxa malware used in the attack against Target and Neiman Marcus retailers a teenager known in the underground with the pseudonym of Ree[4].

The first sample of malware was created in March 2013, first documented use of BlackPOS were in Australia, Canada and the US. The first name assigned to the malicious code was “Kaptoxa” (“potato” – in Russian slang), which then was renamed to “DUMP MEMORY GRABBER by Ree[4]” for forum postings, but the title for Command & Control server maintained string “BlackPOS“. Ree[4] is not directly responsible for the attack, he sold the BlackPOS to other cyber gangs from Eastern Europe and other countries, it seems that the owners of underground credit cards shops “.rescator“, “Track2.name”, “Privateservices.biz” and many others were his clients.

The malware was already mentioned in the report done by iSIGHT Partners,  BlackPOS (aka “Memory Form Grabber”, “Dump Memory Grabber”) is a malicious code easily available due to a leaked version of the source code.
“The original source code was authored by actor “ree[4]” (for more information and attribution, see iSIGHTPartners. “Analysis of “Dump memory Grabber” Point-of-Sale Malware,” Malware Report #13-25113. April 8, 2013; and “Attribution for Russian Actor “Ree[4],” Seller of a Credit card RAM Memory Grabber”, Intel-792666. April 11, 2013″

 

BlackPos

IntelCrawler update also anticipated that several other breaches may be revealed soon, the technique to infect POS systems with memory grabber is consolidated in the cybercrime ecosystem, poorly configured POS and lack of security best practices (e.g. The use of weak passwords)  advantaged the cyber criminals.

Who is Ree[4]?

In the last I preferred to not reveal the name if the young guy, but now it is public, Intercrawler revealed that alleged Russian hacker and malware developer is Sergey Taraspov (ree4), this is the name of the author of BlackPOS.

Sergey Taraspov is based in St.Petersburg and Nizhniy Novgorod (Russian Federation) and he is a very well-known programmer of malicious code in the underground.  I

“He is still visible for us, but the real bad actors responsible for the past attacks on retailers such as Target and Neiman Marcus were just his customers”, comments Dan Clements, IntelCrawler President.

Before both breaches IntelCrawler detected large-scale RDP brute-forcing attacks on Point-of-Sales terminals across the US, Australia and Canada started at the beginning of 2013 year in winter period with weak passwords such as:

 "pos":"pos";
 "micros":"micros" (MICROS Systems, Inc. - Point-of-Sale Hardware);
 "edc":"123456" (EDC - Electronic Draft Capture).

Today I propose you a new exclusive update from security researchers at IntelCrawler on the author of BlackPOS.  The author of BlackPOS is the bad actor with nickname “ree4” or “ree[4]”, he started to sell this malware on one of underground forums called “Exploit.in” under the same nick at the beginning of 2013 as visible in the following screenshot:

 

BlackPoS Dump_Memory_grabber1

 

Despite the author of blackPOS malware is a cyber expert, it seems that he has ignored the power of social networking platform, and the possibility to use them for OSINT purposes. One profile of the popular Russian social network VKontakte has the same nickname as BlackPOS author https://vk.com/ree4_ree4. Obviously this is not a body of evidence, but researcher at IntelCrawler noted that one of the interest of the owner of the page is “coding” and it was checked that one of his emails is linked to this page through password recovery option by email.

BlackPos SocialNework

BlackPos a
BlackPos b
BlackPos c

According to operative information from IntelCrawler, the person behind the nickname “ree[4]” is Rinat Shibaev, working closely with Sergey Taraspov, who was acting as his technical support, having roots in St.Petersburg (Russian Federation), very well-known coder of malicious code in the underground.

Let’s wait for new updates from Andrew Komarov, Dan Clements and the experts at IntelCrawler.

About IntelCrawler

IntelCrawler.com is a multi-tier intelligence aggregator, which gathers information and cyber prints from a starting big data pool of over 3, 000, 000, 000 IPv4 and over 200, 000, 000 domain names, which are scanned for analytics and dissemination to drill down to a desired result. This finite pool of cyber prints is then narrowed further by comparing it to various databases and forum intelligence gathered from the underground and networked security company contacts. The final result could be the location of a particular keyboard or a computer housing the threat.

Pierluigi Paganini

(Security Affairs –  BlackPOS, IntelCrawler)


facebook linkedin twitter

credit card credit cards shops Cybercrime data breach Database Breached fraud Hacking IntelCrawler Neiman Marcus Russian Underground shopping season Social Network Target underground VK

you might also like

Pierluigi Paganini July 10, 2025
UK NCA arrested four people over M&S, Co-op cyberattacks
Read more
Pierluigi Paganini July 10, 2025
Qantas data breach impacted 5.7 million individuals
Read more

leave a comment

newsletter

Subscribe to my email list and stay
up-to-date!

    recent articles

    Athlete or Hacker? Russian basketball player accused in U.S. ransomware case

    Uncategorized / July 11, 2025

    U.S. CISA adds Citrix NetScaler ADC and Gateway flaw to its Known Exploited Vulnerabilities catalog

    Hacking / July 11, 2025

    UK NCA arrested four people over M&S, Co-op cyberattacks

    Cyber Crime / July 10, 2025

    PerfektBlue Bluetooth attack allows hacking infotainment systems of Mercedes, Volkswagen, and Skoda

    Hacking / July 10, 2025

    Qantas data breach impacted 5.7 million individuals

    Data Breach / July 10, 2025

    To contact me write an email to:

    Pierluigi Paganini :
    pierluigi.paganini@securityaffairs.co

    LEARN MORE

    QUICK LINKS

    • Home
    • Cyber Crime
    • Cyber warfare
    • APT
    • Data Breach
    • Deep Web
    • Digital ID
    • Hacking
    • Hacktivism
    • Intelligence
    • Internet of Things
    • Laws and regulations
    • Malware
    • Mobile
    • Reports
    • Security
    • Social Networks
    • Terrorism
    • ICS-SCADA
    • POLICIES
    • Contact me

    Copyright@securityaffairs 2024

    We use cookies on our website to give you the most relevant experience by remembering your preferences and repeat visits. By clicking “Accept All”, you consent to the use of ALL the cookies. However, you may visit "Cookie Settings" to provide a controlled consent.
    Cookie SettingsAccept All
    Manage consent

    Privacy Overview

    This website uses cookies to improve your experience while you navigate through the website. Out of these cookies, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities...
    Necessary
    Always Enabled
    Necessary cookies are absolutely essential for the website to function properly. This category only includes cookies that ensures basic functionalities and security features of the website. These cookies do not store any personal information.
    Non-necessary
    Any cookies that may not be particularly necessary for the website to function and is used specifically to collect user personal data via analytics, ads, other embedded contents are termed as non-necessary cookies. It is mandatory to procure user consent prior to running these cookies on your website.
    SAVE & ACCEPT