Welcome | Sign In
ECommerceTimes.com
Malware

New Zealand Teen Nabbed in Big Botnet Bust

Print Version
E-Mail Article
Reprints
New Zealand Teen Nabbed in Big Botnet Bust

New Zealand police say they are questioning a man who goes by the handle "AKILL" and who may have helped lead a botnet of over 1 million PCs. Botnets are groups of computers infected with malware programs that work to carry out cyber mischief without the owner's consent. However, even as one big botnet has apparently been cracked, many smaller ones continue to flourish under the radar.


How Much is 'Free' Costing You?
Learn how DaveRamsey.com saw a 567% uplift in ROI with Omniture. This complimentary guide and webinar cover the most important factors in selecting an analytics solution. Download Now.

A New Zealand cybercrime police force nabbed an 18-year-old this week who goes by the cyber ID "AKILL," officials said. While the New Zealand officials haven't arrested the man, he is being interviewed in conjunction with a wider botnet crackdown involving the FBI and Dutch authorities.

The FBI said AKILL is believed to be the ringleader of an elite international botnet coding group that is responsible for infecting more than 1 million computers.

Botnets are networks of remotely controlled PCs that have been infected with malware viruses, adware and spyware that are installed remotely. The computers are then covertly used over the Internet for nefarious hacking activities like conducting distributed denial of service attacks (DDoS), collecting bank account information, and aiding in identity theft. The person controlling the botnets is a called a "botherder."

New Zealand's Waikato Crime Services Manager, Detective Inspector Peter Devoy, said AKILL is believed to be a co-conspirator in botnet-related activity that caused a DDoS attack at a Philadelphia university in February 2006.

The Philadelphia office of the FBI launched an investigation into the DDoS attack, which led the FBI to Ryan Brett Goldstein, 21, of Ambler, Pennsylvania. Goldstein was indicted on Nov. 1 by a federal grand jury in the Eastern District of Pennsylvania for botnet-related activity that caused the DDoS attack, the FBI reported.

A Tangled Web We Weave

In the midst of the university DDoS investigation, the FBI was able to neutralize a vast portion of the criminal botnet by disrupting the botnet's ability to communicate with other botnets, the bureau said. This particular investigation is still ongoing.

Police suspect New Zealand's AKILL, in cahoots with his partner in the U.S., may have used malware files to infect and control about 50,000 computers, which caused the server to crash and deny access to the university's 4,000 students, staff and faculty members.

Back on the Island

While in New Zealand, police said, AKILL designed a unique virus that utilized encryption and was undetectable by anti-virus software. "This program was viewed by the FBI as being very sophisticated malware," Devoy noted.

New Zealand police also said AKILL is the head of a botnet group call the "A-Team" that has members in the U.S. and in other countries. In a separate investigation with the Dutch Independent Post and Telecommunications Authority, New Zealand police say AKILL was involved with an adware scheme that may have infected 1.3 million computers.

The FBI, for its part, has also been working on what it calls "Operation Bot Roast," which the bureau announced last June. Since then, the FBI says eight individuals have been indicted, pleaded guilty or have been sentenced for crimes related to botnet activity. Additionally, 13 search warrants were served in the U.S. and by overseas law enforcement partners in connection with this operation, the FBI reports, noting that Operation Bot Roast has uncovered more than US$20 million in economic losses and more than one million victim computers.

"The public is reminded once again that they can play a part in thwarting botnet activity," noted FBI's Cyber Division Assistant Director James E. Finch.

"Practicing strong computer security habits such as updating anti-virus software, installing a firewall, using strong passwords and employing good e-mail Increase Customer Sales with Email Marketing -- Free Trial from VerticalResponse and Web security practices are as basic as putting locks on your doors and windows. Without employing these safeguards, botnets, along with criminal and possibly terrorist activities, will continue to flourish," he added.

Major Problem

"The scope of the problem is clearly something that's endemic, primarily because it's so easy for hackers and gangs of hackers to infect and control, theoretically, millions of different PCs," Mike Haro, a senior security analyst for Sophos, told TechNewsWorld.

The sheer number of PCs associated with the FBI and New Zealand bust is somewhat unusual for recent botnets, Haro said.

"It's drawing an enormous amount of attention to one botnet, and it puts a lot of [hacker] resources at risk that could theoretically be eliminated through just one investigation or crackdown," Haro explained.

"What we're seeing is that botnets are usually between 1 and 10,000 PCs, because they fly under the radar and are better distributed. So if any law enforcement agencies take down any botnets of that size, the operations of a botnet organization are not as drastically affected," he added.

"There are no geographical boundaries on the Internet, and these cyber criminals are often in each corner of the world," Haro said. "It becomes very difficult to find [law enforcement] jurisdictions to track down these gangs."


Print Version E-Mail Article Reprints More by Chris Maxcer


Related News Alerts

Sophos Activate Alert | Search Archives

More by Chris Maxcer

Clicker Cuts Through Web Video Chaos
November 23, 2009
Clicker is a new Web site that makes it easier to find the full-length, broadcast-quality TV shows and movies available around the Web via streaming. The interface is clean and easy to use, and if you sign up for a free account, you'll be able to make playlists of shows you'd like to follow. Most of Clicker's shortcomings are really due to the byzantine rights arrangements surrounding online show distribution.
The Gphone That Could Catch My Eye
November 20, 2009
Rumors are cropping up that Google is preparing to sell its own Gphone -- an Android handset using Google-branded hardware. There are some reasons to doubt it will happen, of course, but the possibility is intriguing. What would Google have to build to make something worthy of an iPhone fan's attention?
Apple's House Rules Won't Be the Death of App Development
November 13, 2009
Facebook's iPhone app is one of the most popular wares the App Store has ever carried. But its developer, Joe Hewitt, says he's through with it, stating that Apple's review policies are starting a bad precedent for other platforms. However, good apps from talented developers will always find platforms, and Apple's policies won't prevent that from happening. They may even help.
Don't miss a story -- sign up for our FREE e-mail newsletters and view the latest headlines at a glance.
Tech News Flash [ View Sample ]
E-Commerce Minute [ View Sample ]
ECT News Network Weekly Newsletter [ View Sample ]
Shortcuts
ECT News Network Information
Reader Services
Corporate
ECT News Network