Subscribe free to our newsletters via your
. 24/7 Space News .




CYBER WARS
US disables 'Coreflood' botnet, seizes servers
by Staff Writers
Washington (AFP) April 13, 2011


US authorities on Wednesday announced the disabling of a vast network of virus-infected computers used by cyber criminals to steal millions of dollars.

The "Coreflood" botnet is believed to have operated for nearly a decade and to have infected more than two million computers around the world, the Justice Department and FBI said in a joint statement.

They said charges of wire fraud, bank fraud and illegal interception of electronic communications had been filed against 13 suspects identified in court papers only as John Doe 1, John Doe 2, etc.

The complaint said they were all "foreign nationals" but provided no further information about their identities or nationalities.

Five "command and control" computer servers and 29 Internet domain names were seized as part of the operation, described as the "most complete and comprehensive enforcement action ever taken by US authorities to disable an international botnet."

A botnet is a network of malware-infected computers that can be controlled remotely from other computers.

Coreflood, which exploited a vulnerability in computers running Microsoft's Windows operating systems, was used to steal usernames, passwords and other private personal and financial information, US officials said.

As of February 2010, some 2.33 million computers were part of the Coreflood botnet, including 1.85 million in the United States, according to the complaint filed with the US District Court for the District of Connecticut.

"Infected computers in the Coreflood botnet automatically recorded the keystrokes and Internet communications of unsuspecting users, including online banking credentials and passwords," the complaint said.

"The defendants and their co-conspirators used the stolen data, including online banking credentials and passwords, to direct fraudulent wire transfers from the bank accounts of their victims," it added.

The complaint said the full extent of the financial loss is not known but it provided details on a number of victims.

They included a real estate company in Michigan hit for $115,771 in fraudulent wire transfers, an investment company in North Carolina taken for $151,201 and a defense contractor in Tennessee which lost $241,866.

Dave Marcus, research and communications director at McAfee Labs, said the cyber criminals behind Coreflood were apparently able to "turn the botnet into a money making machine."

"It is hard to estimate the actual loot, but the criminals likely made tens of millions of dollars, based on the estimates in the complaint filed by the Department of Justice," Marcus said. "It is not outside of the realm of possibility that they netted more than $100 million."

US attorney David Fein said the seizure of the Coreflood servers and the Internet domain names "is expected to prevent criminals from using Coreflood or computers infected by Coreflood for their nefarious purposes."

"These actions to mitigate the threat posed by the Coreflood botnet are the first of their kind in the United States and reflect our commitment to being creative and proactive in making the Internet more secure," added Shawn Henry of the FBI's Criminal, Cyber, Response and Services Branch.

In July of last year, US, Spanish and Slovenian law enforcement authorities announced the arrest of the suspected creator of the "Mariposa Botnet," which may have infected as many as eight million to 12 million computers around the world.

.


Related Links
Cyberwar - Internet Security News - Systems and Policy Issues






Comment on this article via your Facebook, Yahoo, AOL, Hotmail login.

Share this article via these popular social media networks
del.icio.usdel.icio.us DiggDigg RedditReddit GoogleGoogle








CYBER WARS
Third Phase of FBI's Next Gen ID System Begins
Rockville MD (SPX) Apr 13, 2011
The Lockheed Martin-led Next Generation Identification (NGI) team is beginning to fully develop and deploy a capability that will enhance the FBI's latent fingerprint matching accuracy and introduce palm print matching to the system. Development efforts began after a successful Critical Design Review (CDR) for the system's Increment 3. The milestone came just weeks after the FBI declared I ... read more


CYBER WARS
BRP To Contribute To Canadian Moon And Mars Exploration Programs

Naveen Jain Co-Founder And Chairman Of Moon Express

Project Morpheus To Begin Testing At NASA's Johnson Space Center

NASA Announces Winners Of 18th Annual Great Moonbuggy Race

CYBER WARS
Several Drives This Week Put Opportunity Over 17-Mile Mark

Next Mars Rover Nears Completion

Mars In Spain

Study Of 'Ruiz Garcia' Rock Completed

CYBER WARS
"I See Earth! It Is So Beautiful!"

Report Provides NASA With Direction For Next 10 Years Of Space Research

Last legends of early space flight laud Gagarin

Spacelinq The First European Space Liner

CYBER WARS
Asia's star ever brighter in space

What Future for Chang'e-2

China setting up new rocket production base

China's Tiangong-1 To Be Launched By Modified Long March II-F Rocket

CYBER WARS
The MELFI Shuffle: Contingency Planning For Preserving Samples

Space Debris No Threat To ISS

Astronauts head to ISS on spaceship Gagarin

Station Fires Engines To Avoid Orbital Debris

CYBER WARS
Arianespace to launch ASTRA 2E Satellite

PSLV Launch On April 20

Russia Looks To Grab Half Of World Space Launch Market

Mitsubishi Electric's ST-2 Satellite Arrives In French Guiana

CYBER WARS
A New Way To Find Planets

Telescope Ferrets Out Planet-Hunting Targets

White Dwarfs Could Be Fertile Ground For Other Earths

NASA Announces 2011 Carl Sagan Fellows

CYBER WARS
WHO eyes 20 year nuclear health watch in Japan

Tissue Engineers Use New System To Measure Biomaterials, Structures

Finding May End A 30-Year Scientific Debate

Researchers Find Replacement For Rare Material Indium Tin Oxide




The content herein, unless otherwise known to be public domain, are Copyright 1995-2014 - Space Media Network. AFP, UPI and IANS news wire stories are copyright Agence France-Presse, United Press International and Indo-Asia News Service. ESA Portal Reports are copyright European Space Agency. All NASA sourced material is public domain. Additional copyrights may apply in whole or part to other bona fide parties. Advertising does not imply endorsement,agreement or approval of any opinions, statements or information provided by Space Media Network on any Web page published or hosted by Space Media Network. Privacy Statement