Three indicted for making, spreading Gozi Trojan
Malware was used to steal millions of dollars from U.S., offshore bank accounts, since 2006
Computerworld - Three individuals were indicted in New York Wednesday for allegedly creating and distributing the Gozi malware that's said to have caused tens of million of dollars in losses at several major U.S. banks.
U.S. Attorney Preet Bharara said indictments were filed today against Nikita Kuzmin, Mihai Paunescu and Deniss Calovskis today.
The trio is alleged to have conspired to steal at least $50 million from online bank accounts of people whose computers were hit with the Gozi virus.
The indictments alleged that the three individuals, described as software experts, used Gozi to infect at least 100,000 computers around the world, including 25,000 in the United States.
The U.S. Attorney's office says Kuzmin, a Russian citizen, was the chief architect of the virus. The indictment alleges that Kuzmin created a list of master specifications for the Gozi malware in 2005. The malware was created by a partner based on the specs.
Kuzmin is alleged to have started renting the Gozi code by the week to cybercrimnals starting in 2006. The lease operation was called "76 Service", according to the complaint.
The initial Gozi attacks mostly targeted customers of European banks.
In 2009, according to the indictment, Kuzmin was approached by unnamed co-conspirators seeking to use the Gozi malware to attack customers of American banks.
Kuzmin sold the Gozi source code to the co-conspirators for approximately $50,000 plus a share of the profits.
Kuzmin faces seven criminal charges related to wire fraud, access device fraud and computer intrusion.
The court papers say Paunescu provided the infrastructure for the operation.
Paunescu, a Romanian national based in Bucharest, operated a so-called "bullet-proof" hosting service using computers housed in Romania, the United States and other countries.
The complaint says Paunescu provided Kuzmin and others with servers and IP addresses that allowed them to use and distribute Gozi and other banking Trojans such, as Zeus and SpyEye, with relative anonymity.
The court papers also allege Paunescu's rented servers hosted the tools used to launch distributed denial of service attacks, including several that took advantage of the infamous Black Energy botnet. The server were often used as command and control servers for botnets and as proxy systems that let attackers to hide their identities, the complaint said.
Calovskis, a Latvian national, was indicted on charges of developing a web injection code that was used to alter how banking websites appeared on infected computers. The software fooled victims into providing key security information such as their mother's social security number and mother's maiden name when they attempted to log into their bank's website.
The information was later used to steal funds from victim accounts, the complaint alleged.
Jaikumar Vijayan covers data security and privacy issues, financial services security and e-voting for Computerworld. Follow Jaikumar on Twitter at
@jaivijayan, send e-mail to jvijayan@computerworld.com or subscribe to Jaikumar's RSS feed
.
Cybercrime watch
- Police arrest Anonymous suspects in Italy
- Four former LulzSec members sentenced to prison in the UK
- Bank security weaknesses led to cyber looting of $45M from ATMs
- Payment card processors hacked in $45 million fraud
- Spamhaus DDoS suspect extradited to the Netherlands
- Accused SpyEye virus creator extradited to the U.S.
- Dutch bill would give police hacking powers
- DDoS suspect used a van as a mobile office, Spanish police say
- Dutch man arrested in connection with major DDoS attack on Spamhaus
- Australia charges man claiming to be LulzSec leader
Read more about Cybercrime and Hacking in Computerworld's Cybercrime and Hacking Topic Center.
- 12 iPhones Apps That Will Make You a Networking Star
- 10 Careers Robots Are Taking From You
- Big Data Gold Isn't Always Where You Would Expect It
- 6 Tips to Build Your Social Media Strategy
- A walking tour: 33 questions to ask about your company's security
- 15 social media scams
- The 7 elements of a successful security awareness program
- IT Certification Study Tips
- Register for this Computerworld Insider Study Tip guide and gain access to hundreds of premium content articles, cheat sheets, product reviews and more.
- Streamlining Information Workflows In order to streamline your workflows effectively, you will need to properly align your file transfer solution with your business requirements.
- Streamlining Information Workflows In order to streamline your workflows effectively, you will need to properly align your file transfer solution with your business requirements.
- Streamlining Information Workflows In order to streamline your workflows effectively, you will need to properly align your file transfer solution with your business requirements.
- Securing Internet File Transfers This solution brief describes the four essential elements of secure Internet transfers.
- Bridging HTTP and FTP with FileXpress Internet Server What if you could take an FTP server on your internal network, and allow external users (partners or customers) to securely access it...
- MFT and FileXpress - An Overview Business users and applications exchange files on a regular basis. File transfer is a core part of the flow of business activity. All Cybercrime and Hacking White Papers | Webcasts
