AP/ March 2, 2010, 4:10 PM

Alleged Masterminds of Botnet Arrested

Authorities have smashed one of the world's biggest networks of virus-infected computers, a data vacuum that stole credit cards and online banking credentials from as many as 12.7 million poisoned PCs.

The "botnet" of infected computers included PCs inside more than half of the Fortune 1,000 companies and more than 40 major banks, according to investigators.

Spanish investigators, working with private computer-security firms, have arrested the three alleged ringleaders of the so-called Mariposa botnet, which appeared in December 2008 and grew into one of the biggest weapons of cybercrime. More arrests are expected soon in other countries.

Spanish authorities have planned a news conference for Wednesday in Madrid.

The arrests are significant because the masterminds behind the biggest botnets aren't often taken down. And the story of investigators' hunt for them offers a rare glimpse at the tactics used to trace the origin of computer crimes.

Also, the suspects go against the stereotype of genius programmers often associated with cyber crime. The suspects weren't brilliant hackers but had underworld contacts who helped them build and operate the botnet, Cesar Lorenza, a captain with Spain's Guardia Civil, which is investigating the case, told The Associated Press.

Investigators were examining bank records and seized computers to determine how much money the criminals made.

"They're not like these people from the Russian mafia or Eastern European mafia who like to have sports cars and good watches and good suits - the most frightening thing is they are normal people who are earning a lot of money with cybercrime," Lorenza said.

The three suspects were described as Spanish citizens with no criminal records. They weren't named and their mug shots weren't released, which Lorenza said is standard in Spain to protect the privacy of defendants. They face up to six years in prison if convicted of hacking charges.

Authorities identified them by their Internet handles and their ages: "netkairo," 31; "jonyloleante," 30; and "ostiator," 25.

Botnets are networks of infected PCs that have been hijacked from their owners, often without their knowledge, and put into the control of criminals. Linked together, the machines supply an enormous amount of computing power to spammers, identity thieves, and Internet attackers.

The Mariposa botnet, which has been dismantled, was easily one of the world's biggest. It spread to more than 190 countries, according to researchers. It also appears to be far more sophisticated than the botnet that was used to hack into Google Inc. and other companies in the attack that led Google to threaten to pull out of China.

The researchers that helped take down Mariposa first started looking at it in the spring of 2009.

Chris Davis, CEO of Ottawa-based Defence Intelligence, said he noticed the infections when they appeared on networks of some of his firm's clients, including pharmaceutical companies and banks.

It wasn't until several months later that he realized the infections were part of something much bigger.

After seeing that some of the servers used to control computers in the botnet were located in Spain, Davis and researchers from the Georgia Tech Information Security Center joined with software firm Panda Security, which is headquartered in Bilbao, Spain.

The investigators caught a few lucky breaks. For one, the suspects used Internet services that wound up cooperating with investigators. That isn't always the case.

Critically, one suspect also made direct connections from his own computer to try and reclaim control of his botnet after authorities took it down around Christmas. Investigators were able to identify him based on that traffic. They were able to back up their claims with records from domains he registered where he would eventually host malicious content.

It turned out that the botnet runners had infected computers by instant-messaging malicious links to contacts on infected computers. They also got viruses onto removable thumb drives and through peer-to-peer networks. The program used to create the botnet was known as Mariposa, from the Spanish word for "butterfly."

"I don't think there's anything about this guy that makes him smarter than any of the other botnet guys, but the (Mariposa) software, it's very professional, it's very effective," said Pedro Bustamante, senior research adviser with Panda Security. "It came alive and started spreading and it got bigger than him."

While arrests of people accused of running smaller botnets are fairly common, the biggest botnet leaders are rarely nabbed. That's partly because it's easy for criminals to hide their identities by disguising the source of their Internet traffic. Often, every computing resource they use is stolen.

For instance, there have been no busts yet in the spread of the Conficker worm, which infected 3 million to 12 million PCs running Microsoft Corp.'s Windows operating system and caused widespread fear that it could be used as a kind of Internet super weapon. The Conficker botnet is still active, but is closely watched by security researchers. The infected computers have so far been used to make money in ordinary ways, pumping out spam and spreading fake antivirus software.
By AP Technology Writer Jordan Robertson
© 2010 The Associated Press. All Rights Reserved. This material may not be published, broadcast, rewritten, or redistributed.
9 Comments Add a Comment
linkicon reporticon emailicon
Funky-President says:
What about these master minds?

PUBLISHED SEPT 4, 2001.


nytimes.com/2001/09/04/international/04GERM.html ?pagewanted=all

"The projects, which have not been previously disclosed, were begun under President Clinton and have been embraced by the Bush administration, which intends to expand them.

Earlier this year, administration officials said, the Pentagon drew up plans to engineer genetically a potentially more potent variant of the bacterium that causes anthrax, a deadly disease ideal for germ warfare."

"A published account of the experiment, which appeared in a scientific journal in late 1997, alarmed the Pentagon, which had just decided to require that American soldiers be vaccinated against anthrax. American officials tried to obtain a sample from Russia through a scientific exchange program to see whether the Russians had really created such a hybrid. The Americans also wanted to test whether the microbe could defeat the American vaccine, which is different from that used by Russia.

Despite repeated promises, the bacteria were never provided.

Eventually the C.I.A. drew up plans to replicate the strain, but intelligence officials said the agency hesitated because there was no specific report that an adversary was attempting to turn the superbug into a weapon.

This year, officials said, the project was taken over by the Pentagon's intelligence arm, the Defense Intelligence Agency. Pentagon lawyers reviewed the proposal and said it complied with the treaty. Officials said the research would be part of Project Jefferson, yet another government effort to track the dangers posed by germ weapons.

A spokesman for Defense Intelligence, Lt. Cmdr. James Brooks, declined comment. Asked about the precautions at Battelle, which is to create the enhanced anthrax, Commander Brooks said security was "entirely suitable for all work already conducted and planned for Project Jefferson."
reply
linkicon reporticon emailicon
Dgunner says:
The government needs to put them on a payroll. lessoning thier time by using thier skills to help catch others.If you want to catch a outlaw you hire a outlaw if you want to catch a run away priest hire a pregnant nun.
reply
linkicon reporticon emailicon
rock0223 says:
It is ridiculous how soft the 'authorities' on this type of crime. Six years? I never would have believed it.
reply
linkicon reporticon emailicon
RoboBlogger says:
Six years is a slap on the wrists. It's just a day and a wake up for them and they'll be back on their feet in no time.
reply
linkicon reporticon emailicon
scottyusa says:
Masterminds? Mastercreeps is more like it.
reply
linkicon reporticon emailicon
lilbear925 says:
These creeps need to spend just as much time in jail as Bernie Madoff. Considering the interruption of services and money lost, this is definitely not small potatoes.
reply
linkicon reporticon emailicon
IndiasWorstTechSupport says:
They'll probably end up working for their government or someone's political interests. Now, that's if someone else gets doesn't get to them first. hehe...
reply
linkicon reporticon emailicon
dkb218 says:
...Way to stick it to the man!!!
reply
linkicon reporticon emailicon
John_Merritt says:
They should get a minimum of 25 years all time to be served. No less. They should be fined $1,000 per infraction. This should send a message to EVERYONE you mess with US and you lose your right to be part of society.
reply
Scroll Left Scroll Right