Group -IB , a leading provider of solutions for detecting and preventing cyberattacks, detecting online fraud, investigating high-tech crimes and protecting intellectual property, has supported Interpol in its operation codenamed “Lyrebird” which resulted in the identification and arrest of a suspect believed to be behind numerous attacks , including those targeting French telecommunications companies, major French banks and multinational corporations , following a two-year investigation . The alleged perpetrator, who turned out to be a Moroccan citizen , was arrested in May by Moroccan police following information provided by Group-IB about his cybercrimes.
According to Group-IB’s Threat Intelligence team, the suspect, named Dr HeX by Group-IB based on one of the aliases he used, had been active since at least 2009, being responsible for a range of cybercrimes, including phishing, defacing, malware, fraud and carding, with his victims numbering in the thousands. The starting point of Group-IB’s investigation to identify and investigate the cybercrime was the extraction of a phishing kit (a tool used to create phishing web pages) that misused the brand of a major French bank from Group-IB’s Threat Intelligence & Attribution system.
Read also: Interpol shuts down thousands of fake online pharmacies
The phishing kit that was detected used a common technique to install it, creating a spoofed website of a target company, sending mass emails that forged it and asked users to enter login details on the spoofed website. Then, with the credentials that the unsuspecting victims entered on the fake page, they were redirected to the perpetrator's email. Almost every script contained in the phishing kit had the pseudonym of its creator, Dr HeX, and a contact email address.

The email referring to the phishing kit allowed Group-IB Threat Intelligence analysts to find the YouTube channel registered under the same name – Dr HeX. In the description of one of the videos, the perpetrator left a link to an Arabic crowdfunding platform, which allowed Group-IB researchers to record another name associated with the cybercriminal. According to DNS data analysis, this name was used to register at least two domains, which were created using the email from the phishing kit.
Using network graph analysis technology, Group-IB researchers created a network graph, based on the phishing kit email address, that showed other elements of the cybercriminal’s malicious infrastructure used in various campaigns, along with their personal pages. A total of five email addresses associated with the defendants, along with six aliases and accounts on Skype, Facebook, Instagram, and YouTube.
Further analysis of Dr Hex’s digital footprint revealed his involvement in other malicious activities. Between 2009 and 2018, the malicious actor defaced over 130 websites. Group-IB analysts also found posts by the cybercriminal on several popular “underground” platforms dedicated to malware trading, which indicate his involvement in malware development. Group-IB also discovered evidence indicating Dr Hex’s involvement in attacks targeting numerous large French companies, with the aim of stealing customers’ bank card details.

See also: Interpol "prevented" the transfer of money to cybercriminal accounts
In Operation “Lyrebird,” Group-IB worked closely with Interpol’s Cybercrime Directorate, which, in turn, worked with the Moroccan Police through Interpol’s National Central Bureau in Rabat, to locate and arrest the individual who remains under investigation.
“This is a significant success against a suspect accused of targeting unsuspecting individuals and companies across multiple regions for years, and the case highlights the threat of cybercrime worldwide. The arrest of this suspect is the result of exceptional international investigative work and new ways of working with both the Moroccan police and key private sector partners, such as Group-IB,” said Stephen Kavanagh, Executive Director of Interpol’s Police Service.
Proposal: Interpol: Scammers approach their victims on dating apps!
“Having zero tolerance for cybercrime, Group-IB always emphasizes its focus not only on protecting our clients from cyberattacks, but also on identifying the perpetrators behind them, to ensure that they are duly punished. Operation “Lyrebird” is another example of strong coordinated cooperation between international law enforcement agencies, regional police forces and cybersecurity agencies. International cooperation, data exchange and long-term experience in cyber investigations help Group-IB lead its work to a good result – bringing cybercriminals to justice. With years of successful cooperation between Interpol and Group-IB, we are setting an example of synergy between the private sector and law enforcement forces, ensuring that cybercrime does not go unpunished,”said Dmitry Volkov, CTO of Group-IB and Head of Threat Hunting Intelligence.
Information source: securityaffairs.co
