Hacker behind Mariposa botnet arrested: FBI
Last Updated: Wednesday, July 28, 2010 | 9:08 AM ET
The Associated Press
Related
Internal Links
International authorities have arrested a computer hacker believed responsible for creating the malicious computer code that infected as many as 12 million computers, invading major banks and corporations around the world, FBI officials told The Associated Press on Tuesday.
A 23-year-old Slovenian known as Iserdo was snagged in Maribor, Slovenia, after a lengthy investigation by Slovenian Criminal Police there along with FBI and Spanish authorities.
His arrest comes about five months after Spanish police broke up the massive cyber scam, arresting three of the alleged ringleaders who operated the so-called Mariposa botnet, stealing credit cards and online banking credentials.
The botnet — a network of infected computers — appeared in December 2008 and infected more than half of the Fortune 1,000 companies and at least 40 major banks.
Botnets are networks of infected PCs that have been hijacked from their owners, often without their knowledge, and put into the control of criminals.
Jeffrey Troy, the FBI's deputy assistant director for the cyber division, said Tuesday that Iserdo's arrest is a major break in the investigation. He said it will take the alleged cyber mastermind off the street and prevent him from updating the malicious software code or somehow regaining control of computers that are still infected.
Name, charges withheld
Officials declined to release Iserdo's real name and the exact charges filed against him, but said the arrest took place about 10 days ago and the man has been released on bond.
"To use an analogy here," said Troy, "as opposed to arresting the guy who broke into your home, we've arrested the guy that gave him the crowbar, the map and the best houses in the neighbourhood. And that is a huge break in the investigation of cyber crimes."
Troy said more arrests are expected and are likely to extend beyond Spain and Slovenia and include additional operators who allegedly bought the malware from Iserdo.
Authorities would not say how much Iserdo supposedly charged, but said hackers could buy the software package for a certain amount, or pay more to have it customized or get additional features. Internet reports suggest the fees ranged from as much as $500 for basic packages to more than $1,300 for more advanced versions.
Cyber masterminds behind the biggest botnets aren't often taken down largely because it is easy for experienced hackers to hide their identities by disguising the source of their internet traffic. Usually the computer resources they use are stolen. And the investigations are complex and technical, often spanning dozens of countries with conflicting or even non-existing cyber crime laws.
For instance, there have been no arrests yet in the spread of the Conficker worm, which infected three million to 12 million PCs running Microsoft Corp.'s Windows operating system and caused widespread fear that it could be used as a kind of internet super weapon.
The Conficker botnet is still active, but is closely watched by security researchers. The infected computers have so far been used to make money in ordinary ways, pumping out spam and spreading fake antivirus software.
190 countries affected
The Mariposa botnet, which has been dismantled, was easily one of the world's biggest botnets. It spread to more than 190 countries, according to researchers. It also appears to be far more sophisticated than the botnet that was used to hack into Google Inc. and other companies in the attack that led Google to threaten to pull out of China.
The researchers that helped take down Mariposa — which is from the Spanish word for "butterfly" — first started looking at it in the spring of 2009.
Hackers spread the botnet by using instant-messaging malicious links to contacts on infected computers. They also used removable thumb drives and peer-to-peer networks to spread the botnet.
The investigation has included federal and international law enforcement as well as a team of more than 100 people, including FBI, members of a specialized botnet investigative team and the so-called Mariposa working group, which includes researchers and private industry experts.
Share Tools
Top News Headlines
- Ottawa wins appeal to block RCMP union
- Ontario's Court of Appeal has overturned a 2009 ruling that said it was unconstitutional to prevent members of the RCMP from forming a labour association. more »
- 2,000 jobs cut as GM to close Oshawa plant
- The Canadian Auto Workers union says General Motors is going ahead with plans to close its consolidated plant in Oshawa, Ont. more »
- Diamond Jubilee: Your photos of royal encounters
- The CBC Community team asked you to submit your best photos of the Queen's visits to Canada, or visits by any member of the Royal Family. The result was tremendous! more »
- Helicopter crash reported near Terrace B.C. with 3 aboard
- Search and rescue crews have been dispatched to an area west of Terrace, B.C., after a helicopter crashed with three people aboard. more »
Latest World News Headlines
- Gaza border clash kills Palestinian militant, Israeli soldier
- A Palestinian militant infiltrated into Israel and set off a shootout that left the infiltrator and one Israeli soldier dead, the military says. more »
- Mistrial declared in John Edwards case
- The campaign fraud trial of disgraced former U.S. senator John Edwards ended on Thursday with an acquittal on one of six counts and a mistrial declared on the remaining charges. more »
- Diamond Jubilee: Your photos of royal encounters
- The CBC Community team asked you to submit your best photos of the Queen's visits to Canada, or visits by any member of the Royal Family. The result was tremendous! more »
- How manhunts work
- A nation-wide manhunt, like the one being undertaken to find suspected killer Luka Rocco Magnotta, is a highly co-ordinated exercise that isn't quite as gritty or dramatic as it may seem in TV police shows. more »
Dispatches »
- Child "bomberitos" on Peru's most dangerous highway May. 31, 2012 3:34 PM The bomberito children of the Andes hitch homemade carts to passing transport trucks -- to aid motorists and victims of disasters in mountains that were once the domain of Peru's Shining Path rebels. They risk their lives for tips that help feed their families.
Connect Newsroom Blog
The Hunt for Magnotta and #bullyPROOF May. 31, 2012 7:32 PM Tonight we'll take you deep inside the dark recesses of the internet for a closer look what's being posted and who watching it.
- Body-parts victim ID'd as Chinese student in Montreal
- Edmonton teacher suspended for giving 0s
- Owner defends 'gore' site connected to Luka Magnotta
- New duty-free limits will challenge Canadian retailers
- Flooding closes Toronto subway hub Union station
- Copyright board to charge for music at weddings, parades
- Quebec student talks collapse and more protests loom
- Tree faller plunges to death as bucket breaks
- Alberta boy hospitalized after fight involving dozens of students

