By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Security Parrot - Cyber Security News, Insights and ReviewsSecurity Parrot - Cyber Security News, Insights and Reviews
Notification
Latest News
OpenAI may use Associated Press archive for AI training
July 14, 2023
EU users can hold conversations with Google Bard from training set
July 14, 2023
Aptos, the new default font for Microsoft Office
July 14, 2023
BlackLotus UEFI bootkit sources published on GitHub
July 14, 2023
Hackers from the XDSpy cyber-espionage group attacked Russian organizations on behalf of the Ministry of Emergency Situations
July 14, 2023
Aa
  • News
  • Tutorials
  • Security InsiderComing Soon
  • Expert InsightComing Soon
Reading: Ministry of Internal Affairs and FACCT eliminated the fraudulent group Jewelry Team
Share
Security Parrot - Cyber Security News, Insights and ReviewsSecurity Parrot - Cyber Security News, Insights and Reviews
Aa
Search
  • News
  • Tutorials
  • Security InsiderComing Soon
  • Expert InsightComing Soon
Follow US
Security Parrot - Cyber Security News, Insights and Reviews > News > Ministry of Internal Affairs and FACCT eliminated the fraudulent group Jewelry Team
News

Ministry of Internal Affairs and FACCT eliminated the fraudulent group Jewelry Team

Last updated: 2023/06/05 at 2:44 PM
Security Parrot Editorial Team Published June 5, 2023
Share
SHARE

Jewelry Team Scam Group Busted by Experts

Experts have identified and detained a group of scammers known as the Jewelry Team who have been stealing money from Russians who use the popular online ride-sharing service for a year and a half.

How the Scam Worked

Since September 2021, members of the group have been posting fake ads on behalf of drivers on the online ride-sharing service. Those who responded were offered to continue communication not on the site, but in the messenger. The victim was then given a link to a phishing resource (for example, blablacari[.]com) and asked to transfer an advance payment in order to reserve a seat in the car.
The scammers received not only a “deposit” in the amount of 500 to 1,500 rubles, but also the details of a person’s bank card, and could themselves write off the money from the victim’s account. It is reported that 30,000 rubles were stolen from the card of an unnamed resident of Saratov, and they tried to withdraw more than 3 million rubles from a deceived citizen of Kirov, but the transfer was blocked by the bank in time.

Investigation and Findings

In August 2022, at the request of the police, FACST experts analyzed the correspondence of one of the group’s workers with the Telegram bot and traced the history of the group’s development, examined its infrastructure, and identified its member.
The Jewelry Team was created in January 2021. Its founders most likely came from the old HAUNTED FAMILY scam team. According to another version, the Jewelry Team could be an independent division of this large team, as evidenced by the “partner” advertising in the group.
Although the Jewelry Team mentioned only four “beautiful working domains”, experts, using the Threat Intelligence network infrastructure graph, found three dozen domain names that at different times the attackers used as phishing sites to receive advance payments.
In total, according to researchers, in 2021 in Russia, competent organizations blocked 655 phishing domains masquerading as an online service for joint trips (the service was used by more than more popular in the regions, which is what the scammers decided to take advantage of).
It is noted that some of the brightest and most euphonious domain names were “reanimated” by scammers, that is, they were registered again after their blocking period had expired. Experts have identified the owner of two such “resurrected” domain names used by the Jewelry Team. It turned out that he was previously one of the administrators of the Diamond Team scammer group. This group was formed almost a year before the Jewelry Team, but at the time of the investigation, it no longer actually existed.

Arrest of the Scammers

In the fall of 2022, during a joint investigation, police officers and specialists from the High-Tech Crimes Research Department identified and detained an 18-year-old resident of Izhevsk, who admitted to creating a phishing site. Before the trial, he was given a preventive measure in the form of a written undertaking.
The Jewelry Team scam group has been operating for over a year and a half, stealing money from unsuspecting Russians who use the popular online ride-sharing service. The group posted fake ads on behalf of drivers on the online ride-sharing service and asked victims to transfer an advance payment in order to reserve a seat in the car.
The scammers received not only a “deposit” in the amount of 500 to 1,500 rubles, but also the details of a person’s bank card, and could themselves write off the money from the victim’s account. It is reported that 30,000 rubles were stolen from the card of an unnamed resident of Saratov, and they tried to withdraw more than 3 million rubles from a deceived citizen of Kirov, but the transfer was blocked by the bank in time.
In August 2022, at the request of the police, FACST experts analyzed the correspondence of one of the group’s workers with the Telegram bot and traced the history of the group’s development, examined its infrastructure, and identified its member.
The Jewelry Team was created in January 2021 and its founders most likely came from the old HAUNTED FAMILY scam team. According to another version, the Jewelry Team could be an independent division of this large team, as evidenced by the “partner” advertising in the group.
Using the Threat Intelligence network infrastructure graph, experts found three dozen domain names that at different times the attackers used as phishing sites to receive advance payments. In total, in 2021 in Russia, competent organizations blocked 655 phishing domains masquerading as an online service for joint trips.
Some of the brightest and most euphonious domain names were “reanimated” by scammers, that is, they were registered again after their blocking period had expired. Experts have identified the owner of two such “resurrected” domain names used by the Jewelry Team. It turned out that he was previously one of the administrators of the Diamond Team scammer group.
In the fall of 2022, during a joint investigation, police officers and specialists from the High-Tech Crimes Research Department identified and detained an 18-year-old resident of Izhevsk, who admitted to creating a phishing site. Before the trial, he was given a preventive measure in the form of a written undertaking.
The Jewelry Team scam has been a major issue for many Russians who use the popular online ride-sharing service. The group has been operating for over a year and a half, stealing money from unsuspecting victims. It is important to be aware of such scams and to take the necessary precautions to protect yourself from becoming a victim.

Weekly Updates For Our Loyal Readers!

Security Parrot Editorial Team June 5, 2023
Share this Article
Facebook Twitter Email Copy Link Print

Archives

  • July 2023
  • June 2023
  • May 2023
  • April 2023
  • February 2023
  • October 2022
  • September 2022
  • August 2022
  • July 2022
  • June 2022
  • May 2022
  • April 2022
  • March 2022
  • February 2022
  • January 2022
  • December 2021
  • November 2021
  • October 2021
  • September 2021
  • August 2021
  • July 2021
  • June 2021
  • May 2021
  • April 2021
  • March 2021
  • February 2021
  • January 2021
  • December 2020
  • November 2020
  • October 2020
  • September 2020
  • August 2020
  • July 2020

You Might Also Like

News

OpenAI may use Associated Press archive for AI training

July 14, 2023
News

EU users can hold conversations with Google Bard from training set

July 14, 2023
News

Aptos, the new default font for Microsoft Office

July 14, 2023
News

BlackLotus UEFI bootkit sources published on GitHub

July 14, 2023

© 2022 Parrot Media Network. All Rights Reserved.

  • Home
  • Parrot Media Group
  • Privacy Policy
  • Terms and Conditions
Join Us!

Subscribe to our newsletter and never miss our latest news, podcasts etc..

Zero spam, Unsubscribe at any time.

Removed from reading list

Undo
Go to mobile version
Welcome Back!

Sign in to your account

Lost your password?