Tracking the Russian Business Network

Last month, we talked about China's Wicked Rose and the NCPH Hacking Group. This month, we are going to mention the Russian Business Network (RBN) . Malware researchers have been tracking this group for some time and they claim they are responsible for a lot of pain on the Internet.

Brian Krebs has written a good overview of the RBN on his blog.

The Russian Business Network sells Web site hosting to people engaged in criminal activity, the security experts say. Groups operating through the company's computers are thought to be responsible for about half of last year's incidents of 'phishing' -- ID-theft scams in which cybercrooks use e-mail to lure people into entering personal and financial data at fake commerce and banking sites."

It is tough to find a serious cyber-crime attack over the past two to three years that did not involve RBN Internet addresses to some degree.

It seems the RBN is also listed in ROKSO (Register of Known Spam Organisation) of Spamhaus.

Here are some related articles:


Karim Vaes said...

Check out the "Hacker Economics" articles (by Scott Berinato), it contains a very interesting read on one of the malwares that actually used RBN.

Link here:

Security4all said...

And here it is with a link:

Thank you for the reference.