Pack93z
  • Pack93z
  • Select Member Topic Starter
14 years ago
It isn't often that you see those at the root of cyber crime tracked down... good ridden.

http://www.usatoday.com/tech/news/computersecurity/2010-03-02-botnet-arrest_N.htm?cspYahooModule_Tech 

SAN FRANCISCO Authorities have smashed one of the world's biggest networks of virus-infected computers, a data vacuum that stole credit cards and online banking credentials from as many as 12.7 million poisoned PCs.

The "botnet" of infected computers included PCs inside more than half of the Fortune 1,000 companies and more than 40 major banks, according to investigators.

Spanish investigators, working with private computer-security firms, have arrested the three alleged ringleaders of the so-called Mariposa botnet, which appeared in December 2008 and grew into one of the biggest weapons of cybercrime. More arrests are expected soon in other countries.

Spanish authorities have planned a news conference for Wednesday in Madrid.

The arrests are significant because the masterminds behind the biggest botnets aren't often taken down. And the story of investigators' hunt for them offers a rare glimpse at the tactics used to trace the origin of computer crimes.

Also, the suspects go against the stereotype of genius programmers often associated with cyber crime. The suspects weren't brilliant hackers but had underworld contacts who helped them build and operate the botnet, Cesar Lorenza, a captain with Spain's Guardia Civil, which is investigating the case, told The Associated Press.

Investigators were examining bank records and seized computers to determine how much money the criminals made.

"They're not like these people from the Russian mafia or Eastern European mafia who like to have sports cars and good watches and good suits the most frightening thing is they are normal people who are earning a lot of money with cybercrime," Lorenza said.

The three suspects were described as Spanish citizens with no criminal records. They weren't named and their mug shots weren't released, which Lorenza said is standard in Spain to protect the privacy of defendants. They face up to six years in prison if convicted of hacking charges.

Authorities identified them by their Internet handles and their ages: "netkairo," 31; "jonyloleante," 30; and "ostiator," 25.

Botnets are networks of infected PCs that have been hijacked from their owners, often without their knowledge, and put into the control of criminals. Linked together, the machines supply an enormous amount of computing power to spammers, identity thieves, and Internet attackers.

The Mariposa botnet, which has been dismantled, was easily one of the world's biggest. It spread to more than 190 countries, according to researchers. It also appears to be far more sophisticated than the botnet that was used to hack into Google Inc. and other companies in the attack that led Google to threaten to pull out of China.

The researchers that helped take down Mariposa first started looking at it in the spring of 2009.

Chris Davis, CEO of Ottawa-based Defence Intelligence, said he noticed the infections when they appeared on networks of some of his firm's clients, including pharmaceutical companies and banks.

It wasn't until several months later that he realized the infections were part of something much bigger.

After seeing that some of the servers used to control computers in the botnet were located in Spain, Davis and researchers from the Georgia Tech Information Security Center joined with software firm Panda Security, which is headquartered in Bilbao, Spain.

The investigators caught a few lucky breaks. For one, the suspects used Internet services that wound up cooperating with investigators. That isn't always the case.

Critically, one suspect also made direct connections from his own computer to try and reclaim control of his botnet after authorities took it down around Christmas. Investigators were able to identify him based on that traffic. They were able to back up their claims with records from domains he registered where he would eventually host malicious content.

It turned out that the botnet runners had infected computers by instant-messaging malicious links to contacts on infected computers. They also got viruses onto removable thumb drives and through peer-to-peer networks. The program used to create the botnet was known as Mariposa, from the Spanish word for "butterfly."

"I don't think there's anything about this guy that makes him smarter than any of the other botnet guys, but the (Mariposa) software, it's very professional, it's very effective," said Pedro Bustamante, senior research adviser with Panda Security. "It came alive and started spreading and it got bigger than him."

While arrests of people accused of running smaller botnets are fairly common, the biggest botnet leaders are rarely nabbed. That's partly because it's easy for criminals to hide their identities by disguising the source of their Internet traffic. Often, every computing resource they use is stolen.

For instance, there have been no busts yet in the spread of the Conficker worm, which infected 3 million to 12 million PCs running Microsoft Corp.'s Windows operating system and caused widespread fear that it could be used as a kind of Internet super weapon. The Conficker botnet is still active, but is closely watched by security researchers. The infected computers have so far been used to make money in ordinary ways, pumping out spam and spreading fake antivirus software.


"The oranges are dry; the apples are mealy; and the papayas... I don't know what's going on with the papayas!"
Formo
14 years ago
Nice. Good riddance is right.
UserPostedImage
Thanks to TheViking88 for the sig!!
Fan Shout
beast (18h) : Seems like he was just pissed because he was no longer the starter
beast (18h) : Campbell is right, he's rich and he doesn't have to explain sh!t... but that attitude gives teams reasons to never sign him again.
dfosterf (22-Feb) : I have some doubt about all that
dfosterf (22-Feb) : I read De'Vondre Campbell's tweet this morning (via the New York Post) Florio says that if he invested his earnings wisely, he will be good
beast (20-Feb) : I haven't followed, but I believe he's good when healthy, just hasn't been able to stay healthy.
dfosterf (20-Feb) : Hasn"t Bosa missed more games than he has played in the last 3 years?
Mucky Tundra (19-Feb) : He hasn't been too bad when healthy but I don't feel like I ever heard much about when he is
Zero2Cool (19-Feb) : Felt like he was more interested in his body, than football. He flashed more than I expected
Zero2Cool (19-Feb) : When he was coming out, I thought he'd be flash in pan.
Mucky Tundra (19-Feb) : Joey seems so forgettable compared to his brother for some reason
Zero2Cool (19-Feb) : NFL informed teams today that the 2025 salary cap will be roughly $277.5M-$281.5M
Zero2Cool (19-Feb) : Los Angeles Chargers are likely to release DE Joey Bosa this off-season as a cap casualty, per league source.
Zero2Cool (18-Feb) : If the exploit is not fixed, we'll see tons of "50 top free agents, 50 perfect NFL team fits: We picked where each should sign in March" lo
Zero2Cool (18-Feb) : Issue should be solved, database cleaned and held strong working / meeting. Boom!
Zero2Cool (18-Feb) : It should be halted now.
Mucky Tundra (18-Feb) : usually spambots are trying to get traffic to shady websites filled with spyware; the two links being spammed were to the Packers website
Mucky Tundra (18-Feb) : you know when you put it that way combined with the links it was spamming (to the official Packers website)
Zero2Cool (18-Feb) : Yep. You can do that with holding down ENTER on a command in Console of browser
Mucky Tundra (18-Feb) : even with the rapid fire posts?
Zero2Cool (18-Feb) : I'm not certain it's a bot.
Mucky Tundra (18-Feb) : I've got to go to work soon which is a pity because I'm enthralled by this battle between the bot and Zero
Zero2Cool (18-Feb) : Yeah, I see what that did. Kind of funny.
Mucky Tundra (18-Feb) : now it's a link to Wes Hodkiezwicz mailbag
Mucky Tundra (18-Feb) : Now they're back with another topic
Mucky Tundra (18-Feb) : oh lol
Zero2Cool (18-Feb) : I have a script that purges them now.
Zero2Cool (18-Feb) : 118 Topics with Message.
Mucky Tundra (18-Feb) : what's 118 (besides a number)?
Zero2Cool (18-Feb) : They got 118 slapped in there.
Mucky Tundra (18-Feb) : that's why it confused the hell out of me
Zero2Cool (18-Feb) : Yeah, but this is taking a headline and slapping it into the Packers Talk
Mucky Tundra (18-Feb) : Wasnt there a time guests could post in the help forum?
Zero2Cool (18-Feb) : lol good question, kind of impressed!
Mucky Tundra (18-Feb) : So how is a guest posting?
Mucky Tundra (18-Feb) : Tell them its an emergency
Zero2Cool (18-Feb) : Working. Meetings.
Mucky Tundra (18-Feb) : Lots of fun; the spam goes back 4 or 5 pages by this point
Mucky Tundra (18-Feb) : I thought you'd look for yourself and put 2 and 2 together lol. I overestimated ya ;)
Mucky Tundra (18-Feb) : I thought Guests couldnt post?
Zero2Cool (18-Feb) : And gosh that's gonna be fun to clean up! hahaa
Zero2Cool (18-Feb) : Oh. Why not just say that then? Geez.
Mucky Tundra (18-Feb) : check the main forum, seems a spam bot is running amok
Zero2Cool (18-Feb) : What?
Mucky Tundra (18-Feb) : Is the Packers online game "Packers Predict" now available for 2024? I can't tell
Zero2Cool (17-Feb) : Bengals planning to Franchise Tag Tamaurice Higgins
Zero2Cool (14-Feb) : Packers are hiring Luke Getsy as senior offensive assistant.
Martha Careful (12-Feb) : I would love to have them both, esp. Crosby, but either might be too expensive.
Zero2Cool (12-Feb) : Keisean Nixon is trying to get Maxx Crosby and Davante Adams lol
Mucky Tundra (11-Feb) : Yeah where did it go?
packerfanoutwest (11-Feb) : or did you resctrict access to that topic?
Please sign in to use Fan Shout
2024 Packers Schedule
Friday, Sep 6 @ 7:15 PM
Eagles
Sunday, Sep 15 @ 12:00 PM
COLTS
Sunday, Sep 22 @ 12:00 PM
Titans
Sunday, Sep 29 @ 12:00 PM
VIKINGS
Sunday, Oct 6 @ 3:25 PM
Rams
Sunday, Oct 13 @ 12:00 PM
CARDINALS
Sunday, Oct 20 @ 12:00 PM
TEXANS
Sunday, Oct 27 @ 12:00 PM
Jaguars
Sunday, Nov 3 @ 3:25 PM
LIONS
Sunday, Nov 17 @ 12:00 PM
Bears
Sunday, Nov 24 @ 3:25 PM
49ERS
Thursday, Nov 28 @ 7:20 PM
DOLPHINS
Thursday, Dec 5 @ 7:15 PM
Lions
Sunday, Dec 15 @ 7:20 PM
Seahawks
Monday, Dec 23 @ 7:15 PM
SAINTS
Sunday, Dec 29 @ 3:25 PM
Vikings
Sunday, Jan 5 @ 12:00 PM
BEARS
Sunday, Jan 12 @ 3:30 PM
Eagles
Recent Topics
7h / Green Bay Packers Talk / Zero2Cool

23-Feb / Green Bay Packers Talk / beast

23-Feb / Green Bay Packers Talk / beast

22-Feb / Green Bay Packers Talk / TheKanataThrilla

19-Feb / Green Bay Packers Talk / Zero2Cool

19-Feb / Green Bay Packers Talk / MintBaconDrivel

18-Feb / Green Bay Packers Talk / Zero2Cool

18-Feb / Green Bay Packers Talk / Zero2Cool

18-Feb / Green Bay Packers Talk / Zero2Cool

18-Feb / Green Bay Packers Talk / Zero2Cool

16-Feb / Around The NFL / beast

16-Feb / Green Bay Packers Talk / beast

16-Feb / Green Bay Packers Talk / Zero2Cool

15-Feb / Around The NFL / beast

15-Feb / Green Bay Packers Talk / Zero2Cool

Headlines
Copyright © 2006 - 2025 PackersHome.com™. All Rights Reserved.