News

AT&T Phone-Unlocking Malware Ring Costs Carrier $200M

  • Tara Seals--threatpost.com
  • published date: 2021-09-17 08:57:00 UTC

With the help of malicious insiders, a fraudster was able to install malware and remotely divorce iPhones and other handsets from the carrier’s U.S. network — all the way from Pakistan.

<div class="c-article__content js-reading-content"> <p>The ringleader of a seven-year phone-unlocking and malware scheme will head to the clink for 12 years, according to the Department of Justice, after effectively compromising AT&amp;T’s internal networks to install credential-thieving malware.</p> <p>The perp, one Muhammad Fahd of Pakistan and Grenada, was convicted of grooming AT&amp;T employees at a Bothell, Wash. call center to take part in the scam. He and his <a href="https://www.nwnews.com/news/man-accused-of-bribing-employees-to-plant-malware-at-bothell-at-t/article_632a3084-5f2f-5709-aa20-9f9135303a36.html" target="_blank" rel="noopener">now-deceased co-conspirator</a> bribed employees to first use their AT&amp;T credentials to sever phones from the AT&amp;T network for customers who were still under contract — meaning those customers could take their newly independent phones to another service. And then later, Fahd asked his accomplices in the call center to install custom malware and “hacking tools that allowed him to unlock phones remotely from Pakistan,” according to <a href="https://www.justice.gov/opa/pr/fraudster-sentenced-prison-long-running-phone-unlocking-scheme-defrauded-att" target="_blank" rel="noopener">court documents</a>.</p> <p>In all, the 35-year-old Fahd effectively defrauded AT&amp;T out of more than $200 million in lost subscription fees after divorcing nearly 2 million mobile phones from the carrier, the DoJ explained.</p> <p><a href="https://threatpost.com/infosec-insider-subscription-page/?utm_source=ART&amp;utm_medium=ART&amp;utm_campaign=InfosecInsiders_Newsletter_Promo/" target="_blank" rel="noopener"><img loading="lazy" class="aligncenter wp-image-168544 size-full" src="https://media.threatpost.com/wp-content/uploads/sites/103/2021/07/10165815/infosec_insiders_in_article_promo.png" alt="Infosec Insiders Newsletter" width="700" height="50"></a></p> <p>“Unlocking a phone effectively removes it from AT&amp;T’s network, thereby allowing the account holder to avoid having to pay AT&amp;T for service or to make any payments for purchase of the phone,” it said.</p> <h2><strong>Recruiting Insider Threats</strong></h2> <p>It all started in the summer of 2012, when Fahd targeted an AT&amp;T employee through Facebook using the alias “Frank Zhang,” He offered the employee “significant sums of money” in return for taking part in his scheme, and asked the person to recruit other AT&amp;T employees to the ring as well.</p> <p>He also gave instructions on how to launder the bribery money: “Fahd instructed the recruited employees to set up fake businesses and bank accounts for those businesses, to receive payments and to create fictitious invoices for every deposit made into the fake businesses’ bank accounts to create the appearance that the money was payment for genuine services,” according to the DoJ.</p> <p>About a year later, in the spring of 2013, things got a little tougher for Fahd &amp; Co. after AT&amp;T implemented a new unlocking system. Undeterred, Fahd hired a software developer to design malware that would allow him to “unlock phones more efficiently and in larger numbers.” The malware was installed in stealth on AT&amp;T’s own networks, thanks again to the malicious insiders he had recruited.</p> <p>“At Fahd’s request, the employees provided confidential information to Fahd about AT&amp;T’s computer system and unlocking procedures to assist in this process,” according to the sentencing documents. “Fahd also had the employees install malware on AT&amp;T’s computers that captured information about AT&amp;T’s computer system and the network access credentials of other AT&amp;T employees. Fahd provided the information to his malware developer, so the developer could tailor the malware to work on AT&amp;T’s computers.”</p> <p>Of course, this kind of access could have been used for different kinds of cyberattacks, such as ransomware or wide-scale espionage efforts, but Fahd’s only goal seemed to be the mobile phone heist. AT&amp;T’s forensic analysis showed that in all, 1.9 million phones were unlocked, costing AT&amp;T $200 million in potential cellular telephone subscriptions. Accordingly, Fahd was ordered to pay that back as restitution, along with his prison sentence.</p> <p>A <a href="https://www.geekwire.com/2015/att-sues-former-employees-alleging-they-were-secretly-paid-to-unlock-hundreds-of-thousands-of-phones/" target="_blank" rel="noopener">2015 lawsuit</a> by AT&amp;T against the implicated call-center workers elaborated a bit on the gambit. The “customer-facing” aspect was run through a shady, now-defunct company called Swift Unlocks, which advertised phone-unlocking services for consumers. When someone requested an unlock, Swift Unlocks would oblige, obtaining the unlock codes using the malware-enabled remote access to AT&amp;T’s systems.</p> <p>AT&amp;T employees were paid $2,000 every two weeks for facilitating the effort, according to the lawsuit, with two of the top participants “earning” $10,500 and $20,000 respectively. AT&amp;T discovered the malware around October 2013, firing the employees involved. Eventually, the entire operation was traced back to Fahd and</p> <p>At the sentencing hearing U.S. District Judge Robert S. Lasnik for the Western District of Washington noted that Fahd had committed a “terrible cybercrime over an extended period.”</p> <p>Fahd was indicted in 2017 and arrested in Hong Kong in 2018. He was extradited and appeared in U.S. District Court in Seattle in August 2019. He pleaded guilty to conspiracy to commit wire fraud last September.</p> <p>Call-center and in-store employees continue to provide a conduit for fraud – whether knowingly, as in this case, or unknowingly, <a href="https://threatpost.com/mobile-customer-service-sim-swap-fraud/151993/" target="_blank" rel="noopener">as seen in some SIM-jacking efforts</a>. AT&amp;T has had its share of trouble, including facing a <a href="https://threatpost.com/att-faces-224m-legal-challenge-over-sim-jacking-rings/136645/" target="_blank" rel="noopener">$224 million legal challenge</a> after store employees were caught in a SIM-swapping ring.</p> <p><em><strong>Rule #1 of Linux Security: </strong>No cybersecurity solution is viable if you don’t have the basics down. <strong><a href="https://threatpost.com/webinars/4-golden-rules-linux-security/?utm_source=ART&amp;utm_medium=ART&amp;utm_campaign=September_Uptycs_Webinar" target="_blank" rel="noopener" data-saferedirecturl="https://www.google.com/url?q=https://threatpost.com/webinars/4-golden-rules-linux-security/?utm_source%3DART%26utm_medium%3DART%26utm_campaign%3DSeptember_Uptycs_Webinar&amp;source=gmail&amp;ust=1631845224654000&amp;usg=AFQjCNFe_DSLS_kj2I7aadlM3eEu2UBy4w">JOIN</a></strong> Threatpost and Linux security pros at Uptycs for a LIVE roundtable on the <strong><a href="https://threatpost.com/webinars/4-golden-rules-linux-security/?utm_source=ART&amp;utm_medium=ART&amp;utm_campaign=September_Uptycs_Webinar" target="_blank" rel="noopener" data-saferedirecturl="https://www.google.com/url?q=https://threatpost.com/webinars/4-golden-rules-linux-security/?utm_source%3DART%26utm_medium%3DART%26utm_campaign%3DSeptember_Uptycs_Webinar&amp;source=gmail&amp;ust=1631845224654000&amp;usg=AFQjCNFe_DSLS_kj2I7aadlM3eEu2UBy4w">4 Golden Rules of Linux Security</a></strong>. Your top takeaway will be a Linux roadmap to getting the basics right! <strong><a href="https://threatpost.com/webinars/4-golden-rules-linux-security/?utm_source=ART&amp;utm_medium=ART&amp;utm_campaign=September_Uptycs_Webinar" target="_blank" rel="noopener" data-saferedirecturl="https://www.google.com/url?q=https://threatpost.com/webinars/4-golden-rules-linux-security/?utm_source%3DART%26utm_medium%3DART%26utm_campaign%3DSeptember_Uptycs_Webinar&amp;source=gmail&amp;ust=1631845224654000&amp;usg=AFQjCNFe_DSLS_kj2I7aadlM3eEu2UBy4w">REGISTER NOW</a> </strong>and join the <strong>LIVE event on Sept. 29 at Noon EST</strong>. Joining Threatpost is Uptycs’ Ben Montour and Rishi Kant who will spell out Linux security best practices and take your most pressing questions in real time.</em></p> <p> </p> <footer class="c-article__footer"> <div class="c-article__footer__container"> <div class="c-article__footer__col"> <a href="#discussion" class="c-button c-button--secondary">Write a comment</a> </div> <div class="c-article__footer__col"> <div class="c-article__sharing"> <p><strong>Share this article:</strong></p> <nav class="c-nav-sharing"> <div class="social-likes social-likes_notext" data-title="AT&amp;T Phone-Unlocking Malware Ring Costs Carrier $200M" data-url="https://threatpost.com/att-phone-unlocking-malware/174787/" data-counters="no" data-zeroes="yes"><div class="facebook" title="Share via Facebook"></div> <div class="twitter" title="Share via Twitter"></div><div class="linkedin" title="Share via LinkedIn"></div> <div class="reddit" title="Share via Reddit"></div> <div class="flipboard" title="Share via Flipboard"></div> </div> </nav> </div> </div> </div> <div class="c-article__footer__container"> <div class="c-article__footer__col"></div> <div class="c-article__footer__col"> <ul class="c-list-categories"> <li><a class="c-label c-label--secondary-transparent" href="https://threatpost.com/category/malware-2/">Malware</a></li> <li><a class="c-label c-label--secondary-transparent" href="https://threatpost.com/category/mobile-security/">Mobile Security</a></li> </ul> </div> </div> </footer> </div>