Money Laundering via the Free-to-Play Gaming Market: An Examination of MaxiTooliOS

open
This talk will dig into a complex scheme of using stolen credit cards to purchase online goods for free-to-play games such as Clash of Clans, Clash Royale, and Marvel Contest of Champions and sell them in third-party marketplaces for cash. Thanks to high levels of automation, tens of thousands of fake accounts were created to launder money using a tool called MaxiTooliOS. Thanks to a publically viewable MongoDB instance, investigators were able to uncover quite a bit of detail around this operation.