Computer Network Used in ‘Massive’ Crime Scheme Targeted by U.S. Agencies
Linkedin

Computer Network Used in ‘Massive’ Crime Scheme Targeted by U.S. Agencies

Reston : VA : USA | Apr 14, 2011 at 4:47 AM PDT
XX XX
Views: Pending
 

The U.S. Justice Department said it disabled a “massive fraud scheme” that infected more than 2 million computers worldwide with malicious software.

The department filed a civil complaint, criminal seizure warrants and issued a temporary restraining order in coordinated action with Microsoft Corp. (MSFT), which issued a software patch April 12 to correct a vulnerability in its Windows operating system. The vulnerability allowed the software to spread from one computer to another creating a so-called botnet.

The action was aimed at software called Coreflood, which collects passwords and financial information that was used by criminals, the Justice Department said in a statement yesterday. The group of computers infected with Coreflood, known as the Coreflood botnet, is suspected by the U.S. of operating for almost a decade and infecting more than 1.8 million computers in the U.S. alone.

“The scale of the botnet is huge,” said Don Jackson, the director of intelligence at Dell Secureworks, a cyber security firm that said it first discovered Coreflood. “The scale of the operation itself, in terms of the core team, is very small and very close-knit.”

People in Russia

The company, based in Atlanta, concluded that the botnet is controlled by as few as three people in Russia, Jackson said. The hackers specifically targeted corporations, downloading private e-mails and confidential financial data, he said.

“Botnets and the cyber criminals who deploy them jeopardize the economic security of the United States and the dependability of the nation’s information infrastructure,” Shawn Henry, executive assistant director of the FBI’s Criminal, Cyber, Response and Services Branch, said in the statement

The U.S. attorney in Connecticut filed a civil complaint against 13 unidentified defendants known as John Does, alleging wire fraud, bank fraud and international interception of electronic communications, according to the statement. Authorities also obtained search warrants for computer servers and a seizure warrant for 29 domain names.

The complaint alleges that some of the John Does are the owners of Coreflood domains, the computer addresses that are used by the botnet to issue instructions and extract the data. Laura Sweeney, a Justice Department spokeswoman, said she couldn’t comment on 13 civil defendants’ country of origin.

Bank Transfers

The stolen information was used to make bank transfers in some cases of hundreds of thousands of dollars, the Justice Department said. Thieves attempted to transfer more than $934,000 from an unnamed defense contracting company in Tennessee in one case. They removed $78,421 from the bank account of an unidentified law firm in South Carolina and $115,771 from an unidentified real estate company in Michigan, according to court papers.

Americans are believed to have lost millions of dollars in the scheme, according to an FBI official who spoke on condition of anonymity because the criminal investigation remains open. Authorities were unable to tally how much money was stolen “due in part to the large number of infected computers and the quantity of stolen data,” according to court documents.

Botnet Control

The operation to shut down Coreflood is the first time U.S. law enforcement has seized control over a botnet and used that authority to send instructions to computers belonging to victims, according to court papers.

In this case, authorities seized the command-and-control apparatus and sent commands to computers to shut down the malware.

“There has been a real legal barrier to do this because essentially you are issuing instructions to someone else’s computer,” said Alex Cox, principal research analyst at NetWitness Corp., a cyber security firm based in Reston, Virginia.

“That is very, very significant,” Cox said.

imranulhaq is based in Mīrpur Khās, Sind, Pakistan, and is a Stringer for Allvoices.
Report Credibility
 
  • Clear
  • Share:
  • Share
  • Clear
  • Clear
  • Clear
  • Clear
 
 
Advertisement
 
Advertisement
 

News Stories

 
  • Govt targets ring infecting 2.3 million computers

    Kansas City Star
    The FBI and the Justice Department on Wednesday began dismantling a ring of international computer thieves who have stolen an undetermined amount of money by infecting over 2.3 million computers with malicious software, the biggest such enforcement...
  • U.S. Gov't Targets Ring Infecting 2.3M Computers

    Fox
    The FBI and the Justice Department on Wednesday began dismantling a ring of international computer thieves who stole hundreds of millions of dollars worldwide by infecting over 2.3 million computers with malicious software. It was the biggest such...
  • Govt targets ring infecting 2.3 million computers

    AP Online
    The FBI and the Justice Department on Wednesday began dismantling a ring of international computer thieves who stole hundreds of millions of dollars worldwide by infecting over 2.3 million computers with malicious software. It was the biggest such...
  • US shuts down massive cyber theft ring

    Arab News
    US authorities claimed one of their biggest victories against cyber crime as they shut down a ring they said used malicious software to steal what experts estimate could top $100 million. A computer virus, dubbed Coreflood, infected more than 2...
  • US disables 'Coreflood' botnet, seizes servers

    Sydney Morning Herald
    The "Coreflood" botnet is believed to have operated for nearly a decade and to have infected more than two million computers around the world, they said in a joint statement. The Justice Department and FBI said charges of wire fraud, bank fraud and...
  • U.S. agencies disable big ‘botnet’ cyberattack

    Bradenton Herald
    Justice Department and Federal Bureau of Investigation said Wednesday they have seized computers and filed a civil complaint in a bid to disable a software attack used to infect millions of computers and pilfer unsuspecting Internet users' personal...

Blogs

 >
  • Justice Department moves to disable malicious software ...

    onlysoftwareblog.com
    Coreflood installs itself by exploiting a vulnerability in the Windows operating system, according to the department. “Botnets and the cyber criminals who deploy them jeopardize the economic security of the United States and the ...
  • Department of Justice Takes Action to Disable International Botnet ...

    the390.com
    “Botnets and the cyber criminals who deploy them jeopardize the economic security of the United States and the dependability of the nation's information infrastructure,” said Shawn Henry, Executive Assistant Director of the FBI's ...
  • Criminal Justice Online: Department of Justice Takes Action to ...

    criminal-justice-online.blogspot.com
    “Botnets and the cyber criminals who deploy them jeopardize the economic security of the United States and the dependability of the nation's information infrastructure,” said Shawn Henry, Executive Assistant Director of the FBI's ...
  • Justice Department moves to disable malicious software « The Joe ...

    joeylakey.co.uk
    The U.S. moved to disable an international “botnet” that infected more than 2 million computers with malicious software as part of a “massive fraud scheme,” according to the Justice Department. ... “Botnets and the cyber criminals who deploy them
  • Computer Network Used in 'Massive' Fraud Targeted by US ...

    www.simplesitetutorials.org
    April 13 (Bloomberg) — More than 2 million computers worldwide were infected with malicious software in a “massive fraud scheme” that the U.S. disabled as part of a criminal investigation, the Justice Department said. ... “The scale of the botnet is
  • US Targets Computer Network Used in 'Massive' Hacker Fraud ...

    www.simplesitetutorials.org
    April 14 (Bloomberg) — The U.S. Justice Department said it disabled a “massive fraud scheme” that infected more than 2 million computers worldwide with malicious software. The department filed a civil complaint, criminal seizure warrants and ... “The

More From Allvoices

Related People

Report Your News Got a similar story?
Add it to the network!

Or add related content to this report

 
Tap_logo_330_110_event
 


Use of this site is governed by our Terms of Use Agreement and Privacy Policy.

© Allvoices, Inc 2008-2013. All rights reserved.