U.S., foreign agents disrupt Gamover Zeus botnet
Two U.S. courts unseal charges releated to the giant botnet and the Cryptolocker ransomware
IDG News Service - The U.S. Department of Justice, working with law enforcement agencies in other countries, revealed Monday a multinational effort to disrupt Gameover Zeus, a 2-year-old botnet employing an estimated 500,000 to 1 million compromised computers.
Two U.S. courts, meanwhile, have unsealed criminal charges against the alleged administrator of the giant Gameover Zeus botnet. The FBI estimates that Gameover Zeus, which targets banking credentials and other personal information, is responsible for more than $100 million in losses.
In a separate but related action, U.S. and foreign law enforcement officials worked together to seize computer servers central to the malware known as Cryptolocker, a form of ransomware that encrypts files on victims' computers until they pay a ransom, the DOJ said.
"This operation disrupted a global botnet that had stolen millions from businesses and consumers as well as a complex ransomware scheme that secretly encrypted hard drives and then demanded payments for giving users access to their own files and data," Deputy Attorney General James Cole said in a statement.
In the Gameover Zeus case, a grand jury in Pittsburgh has unsealed a 14-count indictment against Evgeniy Mikhailovich Bogachev, 30, of Anapa, Russia, the DOJ announced Monday. The grand jury charged him with conspiracy, computer hacking, wire fraud, bank fraud and money laundering in connection with his alleged role as an administrator of Gameover Zeus.
Bogachev was also charged by criminal complaint in Omaha, Nebraska, with conspiracy to commit bank fraud related to his alleged involvement in the operation of a prior variant of Zeus malware known as Jabber Zeus.
"Gameover Zeus is the most sophisticated botnet the FBI and our allies have ever attempted to disrupt," FBI Executive Assistant Director Robert Anderson Jr. said in a statement. "The efforts announced today are a direct result of the effective relationships we have with our partners in the private sector, international law enforcement, and within the U.S. government."
In a separate civil injunction application filed in Pittsburgh, Bogachev is identified as the alleged leader of a tightly knit gang of cybercriminals based in Russia and Ukraine responsible for the development and operation of both the Gameover Zeus and Cryptolocker schemes.
A law enforcement investigation identified the Gameover Zeus network as a common distribution mechanism for Cryptolocker, the DOJ said.
Unsolicited emails containing an infected file purporting to be a voicemail or shipping confirmation are also widely used to distribute Cryptolocker. When opened, those attachments infect victims' computers. Bogachev is alleged in the civil filing to be an administrator of both Gameover Zeus and Cryptolocker.
Law enforcement agencies from several countries also participated in efforts to disrupt Gameover Zeus and Cryptolocker.
- Comprehensive Advanced Threat Defense The hot topic in the information security industry these days is "Advanced Threat Defense" (ATD). This paper describes a comprehensive, network-based approach to...
- Advanced Threat Defense: A Comprehensive Approach In this interview, Peter George, president, General Dynamics Fidelis Cybersecurity Solutions, explains why we need more than anti-malware, and what constitutes a comprehensive...
- 2013 Cyber Risk Report The "Cyber risk report 2013 Executive summary" presents the major findings of HP Security Research's comprehensive dive into today's cyber vulnerability and threat...
- Cybersecurity for Dummies eBook This book provides an in-depth examination of real-world attacks and APTs, the shortcomings of legacy security solutions, the capabilities of next-generation firewalls, and...
- Live Webcast Security Vulnerabilities Associated With Having Local Administrator Privileges Viewfinity will demonstrate how removing admin rights and granularly managing privileges at the application level reduces the attack surface.
- Security Vulnerabilities Associated With Having Local Administrator Privileges Viewfinity will demonstrate how removing admin rights and granularly managing privileges at the application level reduces the attack surface.
- What should I look for in a Next Generation Firewall? SANS Provides Guidance With so many vendors claiming to have a Next Generation Firewall (NGFW), it can be difficult to tell what makes each one different.... All Cybercrime and Hacking White Papers | Webcasts