The Russia-based SWAT USA Drop reshipping service, a major operation laundering stolen merchandise, was hacked, exposing its internal operations, finances, and organizational structure. The leak details how “drops” and “stuffers” use stolen credit cards to buy high-value goods and reship them for profit, with Fearlless identified as a central figure and a sprawling login infrastructure across many domains.
#SWATUSADrop #Fearlless #CTSI #Drops #Stuffer #FedEx #USPS
#SWATUSADrop #Fearlless #CTSI #Drops #Stuffer #FedEx #USPS
Keypoints
- The SWAT USA Drop service was hacked, revealing its operations, finances, and structure, including more than 1,200 drops listed in the United States.
- Drops are recruited via work-from-home reshipping jobs advertised on craigslist.com and other job sites, with promises of salaries and bonuses but often no payment on payday.
- Stuffers use stolen credit card numbers to purchase high-value goods, attach prepaid shipping labels, and reship them through drops for a cut of the proceeds (up to ~50%).
- The operation relies on a large, distributed login infrastructure across many domains, with portals like portal-ctsi.com and numerous /stuffer/login.php pages.
- The breach exposed financial records showing monthly earnings >$100,000 for Fearlless and his partner, stored in a publicly accessible Google Sheets document.
- Recurring costs include advertising on crime forums, personnel to re-route packages, hacked USPS/FedEx labels, drops tests, and front companies; cryptocurrency wallets linked to the operation show associations with cybercrime and ransomware.
- Fearlless, aka SwatVerified, is identified as the principal owner, with Part II promised for further details.
MITRE Techniques
- [T1583] Acquire Infrastructure – SWAT used a network of fake companies and a shared login panel across more than four dozen websites, with many domains ending in /stuffer/login.php, to manage drops and stuffers. “more than four dozen other websites running the same login panel” and “geared toward either stuffers or drops.”
- [T1566.003] Phishing – The recruitment of drops via work-at-home reshipping jobs advertised on craigslist.com and job search sites indicates social-engineering-style recruitment to obtain access and participation. “advertised on craigslist.com and job search sites.”
- [T1567.002] Exfiltration to Cloud Storage – The operation’s finances were exposed in a publicly accessible Google Sheets document, revealing earnings and payouts. “publicly accessible Google Sheets document… reveals Fearlless and his business partner each routinely made more than $100,000 every month.”
Indicators of Compromise
- [Domain] Portal and login infrastructure – portal-ctsi[.]com, lvlup-store[.]com/stuffer/login.php, 33cow[.]com/stuffer/login.php, swatship[.]club/stuffer/login.php
- [Domain] Additional domains hosting stuffer/login panels – personalsp[.]com, destaf[.]com, jaderaplus[.]com, panelka[.]net
- [Cloud Service] Public Google Sheets document exposing earnings – Google Sheets (public)
- [Actor] Fearlless – alias of principal owner, SwatVerified
- [Credential/Data] Stolen credit card numbers used to purchase goods – stolen payment credentials
- [Crypto] Bitcoin addresses linked to SWAT finances and related cybercrime activity – associated with ransomware and darknet transactions
Read more: https://krebsonsecurity.com/2023/11/russian-reshipping-service-swat-usa-drop-exposed/