Pack93z
  • Pack93z
  • Select Member Topic Starter
14 years ago
It isn't often that you see those at the root of cyber crime tracked down... good ridden.

http://www.usatoday.com/tech/news/computersecurity/2010-03-02-botnet-arrest_N.htm?cspYahooModule_Tech 

SAN FRANCISCO Authorities have smashed one of the world's biggest networks of virus-infected computers, a data vacuum that stole credit cards and online banking credentials from as many as 12.7 million poisoned PCs.

The "botnet" of infected computers included PCs inside more than half of the Fortune 1,000 companies and more than 40 major banks, according to investigators.

Spanish investigators, working with private computer-security firms, have arrested the three alleged ringleaders of the so-called Mariposa botnet, which appeared in December 2008 and grew into one of the biggest weapons of cybercrime. More arrests are expected soon in other countries.

Spanish authorities have planned a news conference for Wednesday in Madrid.

The arrests are significant because the masterminds behind the biggest botnets aren't often taken down. And the story of investigators' hunt for them offers a rare glimpse at the tactics used to trace the origin of computer crimes.

Also, the suspects go against the stereotype of genius programmers often associated with cyber crime. The suspects weren't brilliant hackers but had underworld contacts who helped them build and operate the botnet, Cesar Lorenza, a captain with Spain's Guardia Civil, which is investigating the case, told The Associated Press.

Investigators were examining bank records and seized computers to determine how much money the criminals made.

"They're not like these people from the Russian mafia or Eastern European mafia who like to have sports cars and good watches and good suits the most frightening thing is they are normal people who are earning a lot of money with cybercrime," Lorenza said.

The three suspects were described as Spanish citizens with no criminal records. They weren't named and their mug shots weren't released, which Lorenza said is standard in Spain to protect the privacy of defendants. They face up to six years in prison if convicted of hacking charges.

Authorities identified them by their Internet handles and their ages: "netkairo," 31; "jonyloleante," 30; and "ostiator," 25.

Botnets are networks of infected PCs that have been hijacked from their owners, often without their knowledge, and put into the control of criminals. Linked together, the machines supply an enormous amount of computing power to spammers, identity thieves, and Internet attackers.

The Mariposa botnet, which has been dismantled, was easily one of the world's biggest. It spread to more than 190 countries, according to researchers. It also appears to be far more sophisticated than the botnet that was used to hack into Google Inc. and other companies in the attack that led Google to threaten to pull out of China.

The researchers that helped take down Mariposa first started looking at it in the spring of 2009.

Chris Davis, CEO of Ottawa-based Defence Intelligence, said he noticed the infections when they appeared on networks of some of his firm's clients, including pharmaceutical companies and banks.

It wasn't until several months later that he realized the infections were part of something much bigger.

After seeing that some of the servers used to control computers in the botnet were located in Spain, Davis and researchers from the Georgia Tech Information Security Center joined with software firm Panda Security, which is headquartered in Bilbao, Spain.

The investigators caught a few lucky breaks. For one, the suspects used Internet services that wound up cooperating with investigators. That isn't always the case.

Critically, one suspect also made direct connections from his own computer to try and reclaim control of his botnet after authorities took it down around Christmas. Investigators were able to identify him based on that traffic. They were able to back up their claims with records from domains he registered where he would eventually host malicious content.

It turned out that the botnet runners had infected computers by instant-messaging malicious links to contacts on infected computers. They also got viruses onto removable thumb drives and through peer-to-peer networks. The program used to create the botnet was known as Mariposa, from the Spanish word for "butterfly."

"I don't think there's anything about this guy that makes him smarter than any of the other botnet guys, but the (Mariposa) software, it's very professional, it's very effective," said Pedro Bustamante, senior research adviser with Panda Security. "It came alive and started spreading and it got bigger than him."

While arrests of people accused of running smaller botnets are fairly common, the biggest botnet leaders are rarely nabbed. That's partly because it's easy for criminals to hide their identities by disguising the source of their Internet traffic. Often, every computing resource they use is stolen.

For instance, there have been no busts yet in the spread of the Conficker worm, which infected 3 million to 12 million PCs running Microsoft Corp.'s Windows operating system and caused widespread fear that it could be used as a kind of Internet super weapon. The Conficker botnet is still active, but is closely watched by security researchers. The infected computers have so far been used to make money in ordinary ways, pumping out spam and spreading fake antivirus software.


"The oranges are dry; the apples are mealy; and the papayas... I don't know what's going on with the papayas!"
Formo
14 years ago
Nice. Good riddance is right.
UserPostedImage
Thanks to TheViking88 for the sig!!
Fan Shout
dfosterf (3h) : Surprisingly low initially is my guess cap wise, but gonna pay the piper after that
dfosterf (3h) : The number on Love is going to be brutal.
Zero2Cool (3h) : May 3rd. Extension day for Jordan Love. (soonest)
Zero2Cool (22h) : USFL MVP QB Alex McGough moved to WR. So that's why no WR drafted!
earthquake (1-May) : Packers draft starters at safety ever few years. Collins, Clinton-Dix, Savage
beast (1-May) : Why can't the rookies be a day 1 starter? Especially when we grabbed 3 of them at the position
dfosterf (1-May) : Not going to be shocked if Gilmore goes to the Lions.
dfosterf (1-May) : I hear you dhazer, but my guess would be Gilmore Colts and Howard Vikings from what little has been reported.
Mucky Tundra (30-Apr) : S learn from McKinney who learns from Hafley who learns from the fans. Guaranteed Super Bowl
Zero2Cool (30-Apr) : could*
Zero2Cool (29-Apr) : Safeties should learn from Xavier.
dhazer (29-Apr) : And what about grabbing a Gilmore or Howard at CB ? Those are all Free Agents left
dhazer (29-Apr) : out of curiosity do they try and sign Simmons or Hyde to let these young safeties learn from, they can't be day 1 starters.
Zero2Cool (29-Apr) : I miss having Sam Shields.
Zero2Cool (29-Apr) : Not that he's making excuses, just pointing it out
Zero2Cool (29-Apr) : That's for dang sure. Make our erratic kicker have no excuse!
packerfanoutwest (28-Apr) : having a great long snapper is gold
Zero2Cool (28-Apr) : LaFleur looking like he had some weight. Coachin will do that lol
Zero2Cool (28-Apr) : Thanks Mucky and whomever created topcos for each pick!
Zero2Cool (28-Apr) : Insane about Kingsley
dfosterf (28-Apr) : Putring it here so Mucky sees it. He was our guy!
dfosterf (28-Apr) : Bowden long snapper Wisconsin. Consensus best LS in college.
dfosterf (28-Apr) : We got Peter Bowde
dfosterf (28-Apr) : I personally interpret that as a partial tear that can be recovered from with rehab
dfosterf (28-Apr) : MLF said Kingsley Enagbare did NOT tear his ACL and did NOT require surgery, and that he is "looking good" for the 2024 season!
beast (28-Apr) : T.O. son signs with the 49ers
Mucky Tundra (28-Apr) : damn those vikings
beast (27-Apr) : UDFA Vikings sign TE – Trey Knox, South Carolina
beast (27-Apr) : Kitchen was all high from Miami, he was more lucky than talented in 2022 and it showed in 2023
beast (27-Apr) : Reportedly Packers have UDFAs Jennings and Jones
beast (27-Apr) : OL – Donovan Jennings, USF OT – Trente Jones, Michigan
TheKanataThrilla (27-Apr) : Interesting draft. A bit shocked that we didn't select an early CB. Definitely have Safety help. Pretty happy overall.
dhazer (27-Apr) : wow the last 2 picks are really stupid and probably will be special teams players Top 10 draft pick next year book it
TheKanataThrilla (27-Apr) : I think he ended up with a terrible RAS score
dhazer (27-Apr) : Anyone know what went on with Kitchens from Florida? At 1 point he was to be the Packers 1st round and he is way down the board now
Martha Careful (27-Apr) : Z, could you please combine my thread with yours please. I obviously did not see it when I Created it
Martha Careful (26-Apr) : Re: 'Kool-Aid' McKinstry. Other than Icky Woods, has there ever been a good NFLer with a childish nickname?
Martha Careful (26-Apr) : Packers looking to trade up
Martha Careful (26-Apr) : Flag?
Martha Careful (26-Apr) : Sag?
Nonstopdrivel (26-Apr) : It rhymes with "bag."
beast (26-Apr) : Family? That's Deadpool's F word
Nonstopdrivel (26-Apr) : Not THAT f-word.
Zero2Cool (26-Apr) : fuck
beast (25-Apr) : 49ers are Cap Tight
beast (25-Apr) : Fuck
Mucky Tundra (25-Apr) : Kanata, I will be when I'm on my lunch later
TheKanataThrilla (25-Apr) : Love you NSD
Nonstopdrivel (25-Apr) : Huh. I guess the F-word is censored in this fan shout.
Nonstopdrivel (25-Apr) : Anyone who doesn't hang out in the chat probably smokes pole.
Please sign in to use Fan Shout
2023 Packers Schedule
Sunday, Sep 10 @ 3:25 PM
Bears
Sunday, Sep 17 @ 12:00 PM
Falcons
Sunday, Sep 24 @ 12:00 PM
SAINTS
Thursday, Sep 28 @ 7:15 PM
LIONS
Monday, Oct 9 @ 7:15 PM
Raiders
Sunday, Oct 22 @ 3:25 PM
Broncos
Sunday, Oct 29 @ 12:00 PM
VIKINGS
Sunday, Nov 5 @ 12:00 PM
RAMS
Sunday, Nov 12 @ 12:00 PM
Steelers
Sunday, Nov 19 @ 12:00 PM
CHARGERS
Thursday, Nov 23 @ 11:30 AM
Lions
Sunday, Dec 3 @ 7:20 PM
CHIEFS
Monday, Dec 11 @ 7:15 PM
Giants
Sunday, Dec 17 @ 12:00 PM
BUCCANEERS
Sunday, Dec 24 @ 12:00 PM
Panthers
Sunday, Dec 31 @ 7:20 PM
Vikings
Sunday, Jan 7 @ 3:25 PM
BEARS
Sunday, Jan 14 @ 3:30 PM
Cowboys
Saturday, Jan 20 @ 7:15 PM
49ers
Recent Topics
1h / Green Bay Packers Talk / beast

18h / Green Bay Packers Talk / dfosterf

18h / Green Bay Packers Talk / bboystyle

1-May / Green Bay Packers Talk / greengold

1-May / Green Bay Packers Talk / Zero2Cool

1-May / Packers Draft Threads / dfosterf

30-Apr / Green Bay Packers Talk / Zero2Cool

29-Apr / Green Bay Packers Talk / Martha Careful

29-Apr / Packers Draft Threads / Zero2Cool

29-Apr / Packers Draft Threads / Mucky Tundra

29-Apr / Packers Draft Threads / Mucky Tundra

29-Apr / Packers Draft Threads / Mucky Tundra

28-Apr / Feedback, Suggestions and Issues / Zero2Cool

28-Apr / Packers Draft Threads / Mucky Tundra

28-Apr / Packers Draft Threads / Martha Careful

Headlines
Copyright © 2006 - 2024 PackersHome.com™. All Rights Reserved.