Capítulo 4
Meet the Buyers: Why People Purchase from Spam
Though Krebs' ultimate goal was unmasking the botmasters behind most of the world's spam, he decided to first investigate the people directly affected: customers who purchased pills from spam advertisements. Using leaked data containing contact information for over a million customers, he interviewed dozens of buyers about their motivations, avoiding those who purchased only erectile dysfunction drugs after an early uncomfortable call where a wife learned about her husband's secret Cialis purchase.
The primary motivation for spam pharmacy customers was affordability, especially for those treating chronic conditions. Americans, who face the world's highest prescription drug prices, were particularly susceptible. While other countries implemented price controls, U.S. medication costs continued rising-generic drugs increased 5.3% in 2012, while brand-name drugs jumped 25%. This price disparity, combined with high research and development costs and the expensive FDA approval process (around $350 million per new drug), created perfect conditions for spam pharmacies to thrive.
Many buyers sought discretion, either from embarrassment or to hide purchases from spouses. These customers typically fell into two groups: those self-treating venereal diseases and those ordering impotence drugs to perform for partners. Order histories revealed some customers repeatedly fit into both categories.
The ease of ordering prescription drugs online without a doctor visit appealed to many customers. Many buyers were simply purchasing medications they had previously been prescribed, essentially self-prescribing to avoid doctor visits and higher pharmacy prices.
Some buyers with medical knowledge attempt to bypass doctor visits by self-diagnosing and ordering medications directly. Kimberly, a nurse struggling with fertility while her military husband faced deployment, ordered Clomid online rather than consulting a fertility specialist. "Instead of having to pay a doctor tons of cash to explain something I already knew how to do, I opted to do it myself," she explained. When the pills arrived from India with an expired date, she demanded and received a refund.
Perhaps most concerning were customers purchasing controlled substances like painkillers and stimulants, primarily through Rx-Promotion rather than GlavMed. Goran, a 41-year-old former Eastern European POW living in the US with severe back injuries, spends $250-500 monthly on hydrocodone and tramadol after doctors stopped prescribing pain medication. Without pain medication, he claims he couldn't manage his transportation business: "If you don't work, you're homeless."
Analysis of the GlavMed database revealed concerning patterns-customers making more than five orders had an 80-85% chance of purchasing tramadol or Soma. These pills have approximately $5 street value, potentially yielding $1,300 profit per bottle if resold individually. UCSD researchers found painkillers and restricted drugs generated 48% of Rx-Promotion's revenue, suggesting abuse drove substantial demand.
Capítulo 5
Russian Roulette: The Dangers of Black Market Medications
Ordering drugs from online pharmacies can be deadly, as demonstrated by Marcia Bergeron's tragic death in 2006. After ordering medications from a supposedly Canadian pharmacy, the 57-year-old died from poisoning by heavy metals like uranium and lead found in her pills. Her symptoms included hair loss, blurred vision, nausea, and extreme fatigue before succumbing just after Christmas.
While GlavMed markets drugs as Canadian, most ship from unregulated facilities in India, China, and Pakistan. India's $10 billion pharmaceutical industry produces vast quantities of generic medications, often circumventing Western patents to create affordable alternatives. Though this makes life-saving drugs accessible in poorer countries, it raises serious safety concerns. According to various studies, 8-10% of drugs imported to the US are counterfeit or substandard, with global counterfeit medicine sales exceeding $75 billion.
Customers ordering from spam-advertised pharmacies play "Russian roulette" with their health. SpamIt used over forty different suppliers, with most medications coming from a half-dozen drop shippers in India and Hong Kong. The fulfillment system automatically selected suppliers based on lowest bid rather than safety considerations.
One concerning case was UK resident Deborah G., who ordered weight-loss drugs from a GlavMed-affiliated site. After taking the medications, she required emergency hospitalization for depression and stomach illness. Laboratory testing revealed her pills contained "poisons, cement, and talcum powder." Though she received a full refund after threatening legal action, her case highlights the dangers of counterfeit pharmaceuticals.
Despite the dangers posed by rogue pharmacies, neither the FDA nor pharmaceutical companies have taken substantial steps to combat them through comprehensive drug testing. John Horton of LegitScript explains this reluctance stems from testing costs, constantly changing suppliers, and perhaps most significantly, fear that tests might reveal many "rogue" pharmacy drugs are chemically similar to approved medications. With over 41,000 active online pharmacies and only about 200 legitimate ones, consumers have a 99% chance of using an unapproved website when ordering medications online.
The task of testing rogue pharmacy drugs has fallen largely to academics like Stefan Savage at UCSD, whose team made over 800 test purchases from spam-advertised pharmacies. Surprisingly, they found the drugs contained correct active ingredients in appropriate amounts, though they couldn't test for contaminants. Gary Warner at UAB attempted similar research but encountered bureaucratic obstacles-despite having permission to test illegal substances like cocaine, they couldn't get FDA approval to test spam-purchased pills.
Even pharmaceutical giant Pfizer showed interest in collaborating only if they could suppress findings showing the drugs were genuine, revealing their conflicted priorities. Despite losing billions to counterfeiters, Pfizer declined to help the FBI investigation-likely because they had just settled a $2.3 billion fraud case with the Justice Department over misleading marketing practices, matching their annual Viagra revenue.
The pharmaceutical industry's reluctance to test spam-ordered drugs leaves consumers without objective data about their safety, potentially exposing them to dangerous contaminants while pharmaceutical companies avoid findings that might show these cheaper alternatives are equally effective.
Capítulo 6
Partner(ka)s in (Dis)Organized Crime
The spam ecosystem operates through "partnerkas"-affiliate marketing networks where spammers can easily switch between programs offering better terms. These partnerships benefit both sides: spammers (called "adverts") focus solely on driving traffic while earning 30-35% commissions, and program sponsors avoid legal risks associated with botnet operations. Most successful spammers work with multiple partnerkas simultaneously, creating a frustrating "balloon effect" for anti-spam efforts-shutting down one operation simply shifts traffic elsewhere.
To address the vulnerability of relying on a small number of top affiliates (who generated 75-90% of revenue), partnerka bosses attempted to establish a virtual cartel for online pharmacy operations. In September 2007, Dmitry Stupin and Igor Gusev initiated discussions with competitors like Rx-Partners to prevent disputes, price wars, and affiliate migration. Their goal was to cap affiliate commissions at 40% and standardize drug prices. Chat logs reveal negotiations with EvaPharmacy (Bulker.biz) about creating uniform conditions, including two-week payment holds and reduced commissions of 30-35%.
Running a successful spam operation requires substantial resources. Top-earning affiliates typically own large botnets, while smaller players must rent "installs" from botmasters, often surrendering up to 50% of their commissions. Effective spam operations need sophisticated software to distribute workload across infected machines, track delivery statistics, and "scrub" inactive email addresses. Despite causing worldwide anti-spam expenditures many times their profits, these operations typically earn only about 20% net profit on gross revenue.
Remarkably, these spam operators view themselves as legitimate entrepreneurs rather than criminals. Savage observed in leaked chats between Gusev and Stupin that they constantly sought to add value to their offerings, even debating whether to add penis-extending devices to their shops. "The pharma and spam guys don't fundamentally think of themselves as criminals at all," Savage explains. "Their mental model is that they're selling a quality product to an audience demanding it," with laws merely representing "Western power structure" obstacles to their marketplace.
Cybercrime forums provide structure to this "disorganized crime" ecosystem. These online communities serve multiple purposes: allowing novices to establish trustworthy reputations, enabling criminals to purchase missing components for their operations, providing self-help resources, and creating marketplaces where crooks with different skills can buy and sell illicit goods and services.
Forums follow a consistent structure with sub-forums dedicated to specializations like spam, banking fraud, malware development, identity theft, and black SEO. These communities maintain order through reputation systems, escrow services, and strict codes of ethics. Members caught cheating others are ostracized or banned. Reputation points regulate behavior so effectively that even disputes involving tens of thousands of dollars are resolved amicably rather than risk negative forum feedback.
Despite law enforcement attempts to shut them down, mature cybercrime forums simply relocate to more bulletproof hosting with enhanced security measures. The most effective anti-spam efforts have targeted identifying and apprehending top individual spammers rather than shuttering their online gathering places.
Capítulo 7
Meet the Spammers: The World's Most Notorious Botmasters
By October 2011, leaked SpamIt and Rx-Promotion data provided crucial information for identifying the world's top spammers. A Microsoft Excel spreadsheet labeled "Registration data" found in ChronoPay documents became the Rosetta Stone for unmasking these individuals. The spreadsheet revealed that someone at ChronoPay had compiled detailed information about the most active spammers, including their real identities and contact information.
One of the most significant discoveries was linking a WebMoney account under the alias "Software Seller" to Dmitry Sergeyvich Nechvolod, the operator of Cutwail-the largest spam botnet at the time. This account had earned over $175,000 promoting pharmacy websites for SpamIt.
Nechvolod, an elite programmer specializing in UNIX systems and information security, ran a legitimate software firm called Digital Infinity Developers Group while maintaining and renting out the Cutwail botnet (marketed as "0bulk Psyche Evolution"). By 2008, his botnet controlled 125,000 infected computers capable of sending 16 billion spam messages daily. Like many cybercriminals, he spent lavishly on luxury cars and a fast lifestyle, while offering Moscow-based programmers competitive salaries with benefits packages to expand his operation.
Another major player was a hacker using the nicknames "Cosma," "Tarelka," "Bird," and "Adv1," who earned over $3 million in SpamIt commissions over three years. His spam operation was powered by the Rustock botnet, which initially focused on pump-and-dump stock scams before expanding to pharmacy spam in 2007. At its peak, Rustock infected over 150,000 PCs and could send 30 billion spam messages daily.
Cosma lived dangerously-he once told Stupin he'd been mugged and held hostage by thugs who targeted him for his $100,000+ Porsche Cayenne, which he replaced with a less conspicuous BMW 530xi. His real identity appears to be Dmitri A. Sergeev, a Belarusian-educated programmer who ironically expressed interest in working for Google.
Another major spammer was "Severa," indicted in the U.S. in 2007 as a partner of convicted American spammer Alan Ralsky but never arrested due to his residence in Russia. Severa operated the sophisticated Waledac botnet, believed to be an update to the earlier Storm worm. At its peak, Waledac sent 1.5 billion spam emails daily, with innovative peer-to-peer communication systems that made it resilient against takedown attempts.
SpamIt's second most successful affiliate was "GeRa," whose operations generated over 80,000 pharmaceutical sales, bringing SpamIt more than $6 million in revenue and earning GeRa and his associates over $2.7 million. Evidence suggests GeRa was the mastermind behind the Grum botnet, capable of sending 18 billion emails daily before its 2012 takedown.
Igor A. Artimovich (aka "Engel") and his brother Dmitry maintained the powerful Festi botnet, which at its peak delivered a third of all global spam. Initially working for both Rx-Promotion and SpamIt, Engel became increasingly hostile toward SpamIt in 2009 after suspecting commission theft. While SpamIt administrators denied "shaving" his commissions, leaked chats revealed that botmaster Gugle had indeed hijacked portions of Festi's traffic.
Capítulo 8
Old Friends, Bitter Enemies: The Downfall of Spam Empires
By summer 2008, SpamIt and GlavMed had become the world's largest rogue Internet pharmacy operation, attracting top spammers and generating nearly $6 million monthly. Yet despite this success, co-owner Igor "Desp" Gusev was contemplating leaving cybercrime behind for a legitimate government position at Russia's Ministry of Economic Development.
Tensions were mounting between Gusev and his business partner Dmitry Stupin. While vacationing in Spain with his family, Gusev revealed his potential career change to Stupin, who responded with frustration. Stupin argued they could triple profits by focusing on their existing business, but Gusev was more concerned about security than money: "The most important thing is to retain it, multiply it, to ensure that nobody is going to seize it."
Their feud was interrupted by urgent news from Gusev's hacker friend Alexey ("Leha"). Leha had encountered a drunk Yuri "Hellman" Kabayenkov, Pavel Vrublevsky's partner in Rx-Promotion, who boasted about bribing local police to open a criminal investigation into Gusev for money laundering. Hellman claimed he needed money to pay off police colonels and generals working for him.
The confrontation between Gusev and Vrublevsky escalated into the "Pharma Wars"-a costly grudge match between the world's largest pharmacy partnerka proprietors. Each spent fortunes bribing officials to ruin the other, and both succeeded.
Gusev and Vrublevsky were fundamentally incompatible partners. Gusev was thoughtful, erudite, deliberate, self-deprecating, and frugal-a "golden boy" from a wealthy family with classical education. Vrublevsky was vulgar, impulsive, loquacious, self-aggrandizing, and extravagant, looking a decade older than his mid-thirties. They met through their connections to extreme pornography businesses in 1998, with Gusev running Digital Internet Billing (DiBill) and Vrublevsky operating Red & Partners. In 2003, they formed ChronoPay in the Netherlands, but their partnership deteriorated within months due to constant disagreements.
Two years after splitting from ChronoPay, Gusev had built successful operations with GlavMed and SpamIt, generating millions monthly and employing top Moscow programmers. In 2007, Vrublevsky and Hellman launched Rx-Promotion to compete, specializing in highly restricted prescription medications like hydrocodone and Valium, selling to customers without prescriptions.
Despite Vrublevsky's early warnings, Gusev underestimated his former partner's resolve and political connections. By 2010, Gusev finally accepted he was under investigation by Russian FSB agents targeting him as "Spammer #1 in Russia." This investigation coincided with President Dmitry Medvedev's push to attract foreign investment for Skolkovo, Russia's attempt at creating its own Silicon Valley.
Gusev attempted to bribe officials by "sponsoring" the Volleyball Federation of Russia for approximately $500,000, hoping to leverage the influence of its head, former FSB director Nikolai Patrushev. Gusev explained that Russian sports leagues functioned as vehicles for funneling money to policymakers: "In Russia, sports is not really a business. It's a way of getting business settled."
By early 2010, Gusev and Stupin had spent over $400,000 on bribes to Russian officials to delay the case against them. Gusev found a "problem-solver" lawyer who promised to ensure Vrublevsky's incarceration and business destruction for $1.5 million. In summer 2010, thousands of ChronoPay emails and documents were leaked, exposing Vrublevsky's denied activities. When Gusev denied involvement, Vrublevsky retaliated by paying a hacker to leak the SpamIt and GlavMed customer database to American authorities.
After the database leak, Gusev fled Russia with his family, launching redeye-blog.com to publicly document Vrublevsky's past. The blog attracted hundreds of comments from Vrublevsky's enemies detailing grievances against him. Meanwhile, global spam volumes dropped significantly as both operations suffered from the ongoing war.
Capítulo 9
The Takedown: How Spam Empires Collapsed
The most significant impact on the spam economy came from academic researchers who mapped the money-laundering networks supporting pharmacy affiliate programs. By early 2010, researchers from George Mason University, the International Computer Science Institute, and UC San Diego were making hundreds of "test buys" from shady websites selling knockoff drugs, counterfeit software, and fake antivirus products.
Led by professor Stefan Savage, they aimed to identify the financial institutions profiting from these transactions, believing that public exposure would damage the industry. Despite bureaucratic obstacles and resistance from both government agencies and pharmaceutical companies, their research revealed the critical vulnerabilities in the payment processing systems that kept spam operations profitable.
The financial pressure from Visa's crackdown devastated pharmacy affiliate programs, with one manager lamenting that "Visa's audits, reputation risks, and other hassles" had caused many banks to refuse pharmacy business entirely. Another spammer put it bluntly: "fucking Visa is burning us with napalm."
Desperate pill-shop processors began "miscoding" pharmacy transactions to evade detection, using transaction codes for lower-risk activities. Researchers found they could disrupt these operations by simply calling U.S. banks to alert them about miscoded transactions, helping banks avoid Visa's hefty fines.
Some programs implemented extreme security measures like requiring photo IDs and credit card scans, but these backfired as legitimate customers abandoned their purchases. One affiliate complained their conversion rate "dropped to zero" after implementing these requirements.
In June 2011, Pavel Vrublevsky fled to the Maldives after learning Moscow prosecutors were preparing criminal charges against him for the July 2010 cyberattack on Aeroflot's ticketing systems. Russian authorities convinced him to return voluntarily, whereupon he was arrested and sent to Lefortovo, a notorious high-security prison.
Prosecutors alleged Vrublevsky had hired the Artimovich brothers, operators of the Festi botnet, to attack Assist (Aeroflot's payment processor) while ChronoPay was bidding for Aeroflot's contract. Though Vrublevsky initially confessed to ordering the attack, he later recanted.
Leaked chat logs revealed Gusev and Stupin had paid $1.5 million to bring criminal prosecution against Vrublevsky and $50,000 to start the case against the Artimovich brothers. The case against Vrublevsky likely stemmed from his rivalry with Gusev rather than pursuit of justice.
Despite questionable evidence, all four defendants were found guilty in July 2013. Vrublevsky and the Artimovich brothers received 2.5-year sentences, while Permyakov got 2 years for cooperating. Vrublevsky was unexpectedly released in June 2014, less than a year into his term, possibly connected to Russia's need to develop a national payment system after Visa and MasterCard stopped servicing Russian banks following sanctions over Ukraine.
Capítulo 10
Protecting Yourself in the Age of Cybercrime
Strong password management is essential since not every service offers two-factor authentication. Password managers like KeyPass, Password Safe, RoboForm and LastPass can generate and store complex passwords while requiring users to remember only one master password.
For those managing their own passwords, best practices include using combinations of words, numbers, symbols and mixed-case letters; avoiding usernames as passwords; steering clear of easily guessed information like birthdays or pet names; avoiding dictionary words unless modified with numbers and punctuation; rejecting simple keyboard combinations like "qwerty"; creating long passphrases rather than short passwords; and never reusing passwords across sensitive websites.
Length provides better security than mere complexity, as each additional character exponentially increases a password's resistance to brute-force attacks. Never use the same password at multiple sensitive websites, especially never reuse your email password elsewhere.
Antivirus software and firewalls aren't enough protection when today's malware is designed to evade detection, especially in the critical first 24 hours after release. The concept of "defense in depth" requires multiple security layers, with you as the most important layer.
Following "Krebs's Three Rules for Online Safety" dramatically reduces risk: First, "If you didn't go looking for it, don't install it"-avoid scareware, fake codecs, and unsolicited software by only installing programs you specifically sought out from official sources. Second, "If you installed it, update it!"-keep all applications current with security patches. Third, "If you no longer need it, remove it!"-uninstall unused programs to improve performance and reduce security vulnerabilities.
As the spam ecosystem evolves, new threats emerge. Ransomware rose as partnerka programs struggled to find banks willing to process cards for scareware payments. Cybercriminals also became more efficient, harvesting every valuable piece of data from infected systems-passwords, license keys, social media accounts-all sellable in underground markets.
The battle against spam and cybercrime continues, but understanding the ecosystem is the first step toward protecting yourself. As Krebs concludes, all internet users either contribute to or combat online fraud through their security practices, with no middle ground remaining in today's threat landscape.