The Russian Business Network
(commonly abbreviated as RBN
) is a multi-faceted cybercrime
organization, specializing in and in some cases monopolizing personal identity theft for resale. It is the originator of MPack (software)
and an alleged operator of the Storm botnet
. The RBN, which is notorious for its hosting of illegal and dubious businesses, originated as an Internet Service Provider
for child pornography
, and malware
distribution physically based in St. Petersburg Russia
. More recently it has developed partner and affiliate marketing techniques in many countries to provide a method for organized crime
to target victims internationally.
The RBN has been described as "the baddest of the bad". It offers web hosting services and internet access to all kinds of criminal and objectionable activities, with individual activities earning up to $150,000,000 in one year. Businesses that take active stands against such attacks are sometimes targeted by denial of service
attacks originating in the RBN network. RBN has been known to sell its services to these operations for $600 per month.
The business is difficult to trace. It is not a registered company, and its domains are registered to anonymous addresses. Its owners are known only by nicknames. It does not advertise, and trades only in untraceable electronic transactions.
There is one increasingly known activity of the RBN which is an exploit delivery method by applying fake anti-spyware and anti-malware for the purpose of PC hijacking and personal identity (ID) theft. According to McAfee’s SiteAdvisor, MalwareAlarm is a dangerous fake anti-spyware software and is an updated version of Malware Wiper. They tested 279 “bad” downloads from this one site. The methodology is to entice the user to use a “free download” to test for spyware or malware on their PC, MalwareAlarm then displays a warning message of problems on the PC to persuade the unwary web site visitor to purchase the paid version. Along with MalwareAlarm, numerous other rogue software are linked to and hosted by the RBN.
In the 2007 cyber threat matrix developed by Spy-Ops, RBN was ranked number 4 in the development and sale of cyber attack weapons.
According to Spamhaus RBN is “Among the world's worst spammer, child-pornography, malware, phishing and cybercrime hosting networks. Provides "bulletproof hosting", but is probably involved in the crime too”. RBN was the subject of an article in the Washington Post on October 13, 2007, where Symantec and other security firms claim RBN provides hosting for many illegal activities, including identity theft and phishing. The article quotes a spokesman for Kaspersky Labs that the owners of RBN might not have directly violated the law as they primarily provide hosting services; their customers are apparently the ones violating laws.
The RBN also operates under the guise of several other different names or what even could conventionally be regarded as international business or operating divisions. These core operations apparently have no geographical base with a few showing a physical location, however again the validity of these is doubtful.
- iFrame Cash,
- SBT Telecom Network (Seychelles),
- Aki Mon Telecom,
- Rusouvenirs Ltd.,
- TcS Network (Panama),
- Nevcon Ltd. (Panama),
- Micronnet Ltd. (St. Petersburg Russia),
- Too coin Software (UK)
It has recently been alleged that the founder and leader of the organization, known as 'Flyman', is related to a "powerful and well-connected" Russian politician. In light of this, it is entirely possible that recent cyber-terrorism
activities, such as the denial of service attacks on Estonia
in May 2007 and on Georgia
in August 2008, may have been co-ordinated by or out-sourced to such an organization. Although this is currently unproven, intelligence estimates suggest this may be the case.
- RBNexploit - The RBN watch-blog that provides detailed information on the RBN
- Spamhaus – Rokso listing and description of RBN activities
- StopBadWare - RBN User's Guide
- Verisign / iDefense - Uncovering Online Fraud Rings: The Russian Business Network
- Emerging Threats - Blocking Rules and Snort Signatures for RBN Networks
- RBN Study - bizeul org - PDF
- Shadowserver - RBN as RBusiness Network AS40898 - Clarifying the guesswork of Criminal Activity - PDF