<<<
NEWS FROM THE LAB - Wednesday, November 14, 2007
>>>
 

 
Raining Money Mules Posted by Patrik @ 06:15 GMT

The USA Web site of Korean pop singer "Rain" has been hacked to host a money mule fraud site.

The hacked site uses the company name of Rain Solutions. Clever…

http://rain-solutions.rain-usa.com/e/

Click image for animation.

Money mules are very often unsuspecting people getting tricked into helping out in money laundry schemes. They receive stolen money into their accounts, withdraw it in cash, and then transfer it to the bad guys by using some more anonymous service, such as Western Union. When authorities look into these cases the trail will always lead to the money mule, not the people behind the crime. We see these cases pretty frequently but it's not that often that a site gets hacked and used to host the mule site.

The same site design is also available on:

   http://www.calisto-trading.org
   http://www.simple-investments.org

An excellent catch by Bob over at Bobbear.co.uk.

Rain is quite popular in Asia and has even been spoofed by Steven Colbert in the USA:
http://en.wikipedia.org/wiki/Rain_(singer)

While we're on the topic, if you haven't seen it yet, check out the Weblog's challenge post:
https://www.f-secure.com/weblog/archives/00001314.html

Updated to Add: Rain Solutions is still online. That's the difficult nature of these fraud sties.

Here's how the front page of the legitimate site appears:

Rain-USA