<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Krebs on Security &#187; mariposa botnet</title>
	<atom:link href="http://krebsonsecurity.com/tag/mariposa-botnet/feed/" rel="self" type="application/rss+xml" />
	<link>http://krebsonsecurity.com</link>
	<description>In-depth security news and investigation</description>
	<lastBuildDate>Thu, 09 Feb 2012 22:39:50 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Alleged Mariposa Botnet Author Nabbed</title>
		<link>http://krebsonsecurity.com/2010/07/alleged-mariposa-botnet-author-nabbed/</link>
		<comments>http://krebsonsecurity.com/2010/07/alleged-mariposa-botnet-author-nabbed/#comments</comments>
		<pubDate>Thu, 29 Jul 2010 01:14:02 +0000</pubDate>
		<dc:creator>BrianKrebs</dc:creator>
				<category><![CDATA[Other]]></category>
		<category><![CDATA[christopher davis]]></category>
		<category><![CDATA[defence intelligence]]></category>
		<category><![CDATA[Dejan Janzekovic]]></category>
		<category><![CDATA[Iserdo]]></category>
		<category><![CDATA[mariposa botnet]]></category>
		<category><![CDATA[Nuša Čoh]]></category>

		<guid isPermaLink="false">http://krebsonsecurity.com/?p=4236</guid>
		<description><![CDATA[Police in Slovenia have arrested a 23-year-old man in Maribor believed to be responsible for creating the Mariposa botnet, a collection of hacked PCs that spanned an estimated 12 million computers across the globe, according to reports. The Associated Press cites FBI officials in Washington, D.C. stating that authorities had arrested &#8220;Iserdo,&#8221; the nickname used [...]]]></description>
			<content:encoded><![CDATA[
<div class="topsy_widget_data topsy_theme_silver" style="float: left;margin-right: 0.75em; background: url(data:,%7B%20%22url%22%3A%20%22http%253A%252F%252Fkrebsonsecurity.com%252F2010%252F07%252Falleged-mariposa-botnet-author-nabbed%252F%22%2C%20%22style%22%3A%20%22big%22%2C%20%22title%22%3A%20%22Alleged%20Mariposa%20Botnet%20Author%20Nabbed%22%20%7D);"></div>
<p>Police in Slovenia have arrested a 23-year-old man in Maribor believed to be responsible for creating the Mariposa botnet, a collection of hacked PCs that spanned an estimated 12 million computers across the globe, according to reports.</p>
<p><strong>The Associated Press</strong> cites <strong>FBI</strong> officials in Washington, D.C. <a href="http://www.msnbc.msn.com/id/38439213" target="_blank">stating</a> that authorities had arrested &#8220;Iserdo,&#8221; the nickname used by the hacker alleged to have created Mariposa, a botnet that first surfaced in December 2008 and grew to infect more than half of the Fortune 1,000 companies, as well as at least 40 major banks.</p>
<p>Earlier this year, police in Spain <a href="http://krebsonsecurity.com/2010/03/mariposa-botnet-authors-may-avoid-jail-time/" target="_blank">arrested three of Iserdo&#8217;s associates</a>, who allegedly used the Mariposa botnet to steal credit card accounts and online banking credentials.</p>
<p>The AP story doesn&#8217;t identify Iserdo, saying officials declined to release his name and the exact charges filed against him, but says that the arrest took place <a href="http://translate.google.com/translate?js=y&amp;prev=_t&amp;hl=en&amp;ie=UTF-8&amp;layout=1&amp;eotf=1&amp;u=http%3A%2F%2Fwww.slovenskenovice.si%2Fclanek%2F114359&amp;sl=sl&amp;tl=en" target="_blank">about 10 days ago</a>, and that the man has been released on bond.</p>
<p>According to information obtained by KrebsOnSecurity.com, Iserdo&#8217;s real name is <a href="http://translate.google.com/translate?js=y&amp;prev=_t&amp;hl=en&amp;ie=UTF-8&amp;layout=1&amp;eotf=1&amp;u=http%3A%2F%2Fwww.druga.org%2F~raz01c%2Fcejeki%2Fopis.html%3FDejanJanzekovic&amp;sl=sl&amp;tl=en" target="_blank"><strong>Dejan Janžekovic</strong></a>. Local Slovenian <a href="http://translate.google.com/translate?js=y&amp;prev=_t&amp;hl=en&amp;ie=UTF-8&amp;layout=1&amp;eotf=1&amp;u=http%3A%2F%2Fwww.slovenskenovice.si%2Fclanek%2F114359&amp;sl=sl&amp;tl=en" target="_blank">press reports</a> at the time of his arrest said Iserdo was a former student at the <strong>Maribor Faculty of Computer and Information Science</strong>, but that information could not be independently confirmed.</p>
<p>Individuals close to the case say Janžekovic charged a few hundred dollars for each copy of the bot kit, and that sales frequently were handled by a former classmate who accepted Western Union transfers on his behalf. According to two sources,  one of those who helped with the transactions was a 24-year-old woman named <strong>Nuša Čoh</strong>, pictured <a href="http://www.druga.org/~raz01c/cejeki/opis.html?NusaCoh" target="_blank">here</a> in her high school photo.</p>
<p>Neither Janžekovic nor Čoh could be immediately reached for comment.</p>
<p><strong>Update, July 29, 4:45 p.m:</strong> Janzekovic appears only to have been a person of interest in this investigation, according to a law enforcement official I spoke with today. Also, I heard back from Janzekovic himself, who acknowledged having been investigated by the FBI and Slovenian police in connection with Mariposa, and taken in to the police station for questioning. But he said he is not Iserdo, and that the authorities somehow had him mixed up with someone else. From his e-mail to me:</p>
<p>&#8220;I am 23 years old (the picture you found is very outdated). I am single, I work as a senior systems administrator for a telco in Slovenia. Fact is that I love technology, I love life (even though the past two weeks it was hell on earth for me), but most of all &#8211; I am innocent. Yes, you read right, innocent. I am smarter than this and such things do interest me only from the technological point, as in how to protect against them.</p>
<p>Oh, not to forget, my net nick was and will never be Iserdo.</p>
<p>It is true, that I had the FBI and Slovenian police investigating me but it is also true, that I had nothing to hide. During the investigation I was very cooperative with authorities &#8211; I even gave them password for my encrypted partitions. What was the lead to me? It had to be some kind of mix-up and/or identity theft – the only person known to me in this whole story is the girl who I went to school with (as you have already found out).</p>
<p>Neither of authorities did explain to me how they came to conclusion that I was iserdo. I strongly believe the case was identity theft (obviously someone who knew enough about me, to know that I would easily fit in the case) and/or connection through Nusa. And believe me, it was also to my great surprise, when they woke me up at 6 a.m. to search my home on basis of me selling some &#8216;nasty code&#8217;.</p>
<p>But know this – I do not know any technical details about the botnet, program or anything about the criminal backgrounds as I have never seen it or worked with it.&#8221;</p>
<p><span id="more-4236"></span></p>
<p><em>Original story:</em></p>
<div id="attachment_4249" class="wp-caption alignleft" style="width: 175px"><a class="lightbox" href="http://krebsonsecurity.com/wp-content/uploads/2010/07/dejan-coh1.jpg"><img class="size-medium wp-image-4249" title="dejan-coh2" src="http://krebsonsecurity.com/wp-content/uploads/2010/07/dejan-coh1-165x300.jpg" alt="" width="165" height="300" /></a><p class="wp-caption-text">Janžekovic and Čoh, circled, from a class photo.</p></div>
<p>Authorities in Spain and Slovenia were aided in their sleuthing by the &#8220;Mariposa Working Group,&#8221; a collection of security companies and experts that infiltrated the botnet late last year and ultimately wrested control of it away from criminals who had purchased access to the network.</p>
<p><strong>Christopher Davis</strong>,  chief executive of working group member Defence Intelligence, said his team tracked just under 700 Web site domains being used to control portions of the Mariposa botnet, suggesting that Iserdo sold hundreds of copies of the bot kit, at <a href="http://de.pastebin.ca/959934" target="_blank">hundreds of dollars per kit</a>.</p>
<p>Davis said Iserdo&#8217;s creation used an advanced, custom-made communications protocol designed to slip in and out of firewalls unnoticed, and that communication between systems infected with the butterfly bot and its corresponding control Web site was obfuscated by using a homegrown encryption technology.</p>
<p>&#8220;It&#8217;s a complicated kit he built,&#8221; Davis said. &#8220;We&#8217;re pretty good at breaking crypto, and it took us at least three days to break the cryptography around this bot, when it normally takes us an hour or so.&#8221;</p>
<p>Davis praised the arrests, saying it was unusual because normally it is the individuals who are using and buying the bots that are apprehended, not the bot authors themselves. Still, he said, he hopes authorities can use the information to round up the various Mariposa botnet operators.</p>
<p>“We need to go after all of them &#8211; the people who write the code, the people who sell it, the people who distribute it, even the money mules they use to convert stolen credit cards and banking credentials into cash,” Davis said.</p>

]]></content:encoded>
			<wfw:commentRss>http://krebsonsecurity.com/2010/07/alleged-mariposa-botnet-author-nabbed/feed/</wfw:commentRss>
		<slash:comments>28</slash:comments>
		</item>
		<item>
		<title>Accused Mariposa Botnet Operators Sought Jobs at Spanish Security Firm</title>
		<link>http://krebsonsecurity.com/2010/05/accused-mariposa-botnet-operators-sought-jobs-at-spanish-security-firm/</link>
		<comments>http://krebsonsecurity.com/2010/05/accused-mariposa-botnet-operators-sought-jobs-at-spanish-security-firm/#comments</comments>
		<pubDate>Mon, 03 May 2010 14:53:48 +0000</pubDate>
		<dc:creator>BrianKrebs</dc:creator>
				<category><![CDATA[A Little Sunshine]]></category>
		<category><![CDATA[Web Fraud 2.0]]></category>
		<category><![CDATA[Luis Corrons]]></category>
		<category><![CDATA[mariposa botnet]]></category>
		<category><![CDATA[netkairo]]></category>
		<category><![CDATA[ostiator]]></category>
		<category><![CDATA[panda security]]></category>

		<guid isPermaLink="false">http://krebsonsecurity.com/?p=2757</guid>
		<description><![CDATA[Luis Coronns spent much of the last year helping Spanish police with an investigation that led to the arrest of three local men suspected of operating and renting access to a massive and global network of hacked computers. Then, roughly 60 days after their arrest, something strange happened:  Two of them unexpectedly turned up at Coronns' office and asked to be hired as security researchers.]]></description>
			<content:encoded><![CDATA[
<div class="topsy_widget_data topsy_theme_silver" style="float: left;margin-right: 0.75em; background: url(data:,%7B%20%22url%22%3A%20%22http%253A%252F%252Fkrebsonsecurity.com%252F2010%252F05%252Faccused-mariposa-botnet-operators-sought-jobs-at-spanish-security-firm%252F%22%2C%20%22style%22%3A%20%22big%22%2C%20%22title%22%3A%20%22Accused%20Mariposa%20Botnet%20Operators%20Sought%20Jobs%20at%20Spanish%20Security%20Firm%22%20%7D);"></div>
<p><strong><a href="http://krebsonsecurity.com/wp-content/uploads/2010/05/mariposa.jpg"><img class="alignright size-medium wp-image-2763" title="mariposa" src="http://krebsonsecurity.com/wp-content/uploads/2010/05/mariposa-300x219.jpg" alt="" width="300" height="219" /></a>Luis Corrons</strong> spent much of the last year helping <strong>Spanish</strong> police with an investigation that led to the arrest of three local men suspected of operating and renting access to a <a href="http://krebsonsecurity.com/2010/03/mariposa-botnet-authors-may-avoid-jail-time/" target="_blank">massive and global network of hacked computers</a>. Then, roughly 60 days after their arrest, something strange happened:  Two of them unexpectedly turned up at Corrons&#8217; office and asked to be hired as security researchers.</p>
<p>Corrons, a technical director and blogger for Spanish security firm <strong>Panda Security</strong>, said he received a visit from the hackers on the morning of March 22. The two men, known by the online nicknames &#8220;Netkairo&#8221; and &#8220;Ostiator,&#8221; were arrested in February by Spanish police for their alleged role in running the &#8220;Mariposa&#8221; botnet, a malware distribution platform that spread malicious software  to more than 12 million Internet addresses from 190 countries (mariposa is Spanish for &#8220;butterfly&#8221;).</p>
<p>Now, here the two Mariposa curators were at Panda&#8217;s headquarters in Bilbao, their resumes in hand, practically begging for a job, Corrons said.</p>
<p>“At first, I couldn’t believe it, and I thought someone in the office was playing a practical joke on me,” Corrons said. “But these guys were the real guys, and they were serious.</p>
<p>&#8220;Ostiator told me, &#8216;The thing is, with everything that&#8217;s been happening, we’re not earning any money at the moment,&#8221; Corrons recalled. &#8220;He said, &#8216;We thought we could look for some kind of agreement in which both sides would benefit. We think we have knowledge [that] could be useful to Panda and thought we could have some kind of agreement with Panda.&#8217;&#8221;</p>
<p>Spanish police do not typically release the names of individuals who  have been arrested, and Netkairo and Ostiator haven&#8217;t yet been charged  with any crime. But Corrons recognized that the names and addresses on  the resumes matched those that police had identified as residences  belonging to Netkairo and Ostiator.</p>
<p>Corrons said Panda&#8217;s lawyers were unwilling to release the full names  of the two men that visited Panda Labs, but said Ostiator&#8217;s first name is <strong>Juan Jose</strong>, and  that he is a 25-year-old male from Santiago de Compostela. Corrons said  Netkairo is a 31-year-old from Balmaseda named <strong>Florencio.</strong></p>
<p><strong></strong>Shortly after the arrests were announced, local Spanish media <a href="http://translate.google.com/translate?hl=en&amp;sl=es&amp;u=http://www.20minutos.es/noticia/642167/8/" target="_blank">said</a> the third individual arrested by Spanish  authorities in connection with Mariposa &#8212; a 30-year-old identified by  his initials &#8220;JPR&#8221; &#8212; used the hacker nickname &#8220;Johny Loleante&#8221; and  lived in Molina de Segura,  Murcia.</p>
<p>On Mar. 3, I had the opportunity to interview <strong>Captain Cesar  Lorenzana</strong>, deputy head technology crime  division of the Spanish  Civil Guard. Lorenzana told Krebsonsecurity.com that Netkairo and his associate were earning about 3,000  Euros each month renting out the Mariposa botnet to other hackers.</p>
<p>Interviewing the same hackers less than three weeks later, Corrons asked them how they got started creating Mariposa.</p>
<p>&#8220;Basically, they said they started it as kind of a hobby, and that they weren&#8217;t working at the time,&#8221; Corrons said. &#8220;Suddenly, they started to earn money, a few hundred Euros a week to start, and then discovered they couldn&#8217;t stop. And the whole time, their network kept growing.&#8221;</p>
<p><span id="more-2757"></span></p>
<p>Corrons said he told the pair there was really no way his company could hire them, but that he&#8217;d ask his boss all the same.</p>
<p>&#8220;I told them, &#8216;I’m not sure what you were thinking, but using Mariposa as your business card is not really a great help, quite the opposite in fact,&#8217;&#8221; Corrons said. &#8220;I said, &#8216;Well, I can&#8217;t promise anything [and] the fact you were behind Mariposa won&#8217;t work in your favor, although in any event, I don&#8217;t have the last word. I&#8217;ll speak about this with the management at Panda.&#8217;”</p>
<p><a href="http://krebsonsecurity.com/wp-content/uploads/2010/05/NETK2.jpg"><img class="alignleft size-medium wp-image-2776" title="NETK2" src="http://krebsonsecurity.com/wp-content/uploads/2010/05/NETK2-300x162.jpg" alt="" width="300" height="162" /></a>Corrons said the meeting ended shortly after that, and later that evening he noticed he had <a href="http://twitter.com/juanjillo25" target="_blank">two</a> <a href="http://twitter.com/FLOXTER_SEC" target="_blank">new</a> followers on <strong>Twitter</strong>. One of the new followers, a user named &#8220;FLOXTER_SEC,&#8221; a few days later sent him a message saying &#8220;please dont [sic] forget us, everyone deserves a second chance.&#8221; The name attached to that Twitter profile is one &#8220;Florencio Carro&#8221; (Spanish authorities said Netkairo&#8217;s real initials were FCR).</p>
<p>THE SECOND MEETING</p>
<p>Corrons said he had no direct contact with the two hackers again until Apr. 12, when someone calling himself Netkairo called him at work.</p>
<p>&#8220;He told me, &#8216;Listen, I&#8217;m calling because Juanjo [Ostiator] is insisting that   I come and see you,&#8221; Corrons said. &#8220;He was asking about working for us again, and said, &#8216;We just want to know &#8212; as you haven&#8217;t answered &#8212; whether you&#8217;re thinking of hiring us or not?&#8217;&#8221;</p>
<p>Corrons said he met with with Netkairo again at Panda&#8217;s offices, but said he repeated his previous statement that the company could not hire someone who had been accused of running a botnet.</p>
<p>&#8220;So he says to me, &#8216;But we still haven&#8217;t been charged,&#8217; Corrons recalled. &#8220;I told him, &#8216;It doesn&#8217;t matter&#8230;just the fact that you are involved is a problem when it comes to  working for any serious security company.&#8217; And what he then came out  with says a lot about him. He said, &#8220;Yeah, but nobody else knows that.&#8221;</p>
<p><a href="http://krebsonsecurity.com/wp-content/uploads/2010/05/NETK3.jpg"><img class="alignright size-medium wp-image-2777" title="NETK3" src="http://krebsonsecurity.com/wp-content/uploads/2010/05/NETK3-300x236.jpg" alt="" width="300" height="236" /></a>When it became clear that Panda wasn&#8217;t interested in hiring him, Netkairo changed his tune, Corrons said, claiming he had found vulnerabilities in the company&#8217;s cloud anti-virus software and hinting that he planned to publish the information. Later that week, someone opened a blog at Google Blogspot using the account name &#8220;NeTK,&#8221; and posted a video labeled Panda Cloud Antivirus Detection Bypass POC.</p>
<p>For his part, Corrons dismisses the video, saying it merely shows the obvious result of disconnecting an anti-virus solution from the Internet.</p>
<p>NETKAIRO RESPONDS</p>
<p>Reached via e-mail and instant message, Netkairo said he was limited in what he could discuss about his case at the moment. He acknowledged visiting Panda and asking for a job there, saying he was flat broke now that their Mariposa money-making machine was gone.</p>
<p>But he said Panda&#8217;s estimate of 12 million PCs infected by the Mariposa botnet was hugely inflated.</p>
<p>&#8220;I can say that they [have] 100x the real numbers just to do nice marketing,&#8221; Netkairo wrote in an e-mail. &#8220;The real size of mariposa was like 100,000, [and] peak about 500,000 to 900,000 total machines.&#8221;</p>
<p>Netkairo said Panda failed to take into account the prevalence of so-called &#8220;dynamic&#8221; Internet addresses, where the same computer is assigned multiple Internet addresses over a period of time.</p>
<p>Corrons said the 12 million estimate was never meant to mean distinct, individual PCs, and that the company <a href="http://pandalabs.pandasecurity.com/mariposa-stats/" target="_blank">was careful to note</a> that it was only talking about the number of unique Internet addresses that it saw associated with Mariposa.</p>
<p>A LITTLE KNOWLEDGE IS A DANGEROUS THING</p>
<p>Whether the true number of PCs infected by Mariposa was one million or 12 million, the botnet culled massive amounts of personal data from infected systems. Spanish police said Mariposa helped crooks steal sensitive data from more than 800,000 victims, including home users, companies, government agencies and universities in at least 190 countries.</p>
<p>The botnet was rented out to criminals as a delivery platform for installing  malicious software such as the data-stealing ZeuS Trojan and  pay-per-install toolbars. Panda said the gang also stole directly from  victim bank accounts, using <a href="http://www.krebsonsecurity.com/2010/01/top-10-ways-to-get-fired-as-a-money-mule/" target="_blank">money mules</a> in the United States and Canada, and  laundered stolen money through online gambling Web sites.</p>
<p>Mariposa illustrates just how much damage malicious hackers can wreak these days with just a modicum of know-how. Corrons said both Netkairo and Ostiator told him that while they did indeed maintain the Mariposa botnet, they did not develop the botnet code and had relatively few technical skills. One hacker in the criminal underground who is familiar with Netkairo&#8217;s activities said the botnet owners generated many of the installations for their bot by seeding poisoned copies of pirated software on peer-to-peer file-sharing networks.</p>
<p>Spanish police say the break in the case came when one of the members of the Mariposa gang made an amateur mistake: Accessing the botnet&#8217;s control networks directly from his home Internet address instead of anonymizing his connection by relaying it through  a mesh of third-party systems.</p>
<p>Perhaps Netkairo is being so bold because he doesn&#8217;t believe he will see the inside of a prison cell for his crimes. Indeed, Spanish authorities concede it may be extremely challenging to put the men in jail, even if they are convicted at trial.</p>
<p>&#8220;In Spain, it is not a crime to own and operate a botnet or distribute  malware,&#8221; Capt. Lorenzana told Krebsonsecurity in March. &#8220;So even if we manage to prove they are using a botnet, we will  need to prove they also were stealing identities and other things, and  that is where our lines of investigation are focusing right now.&#8221;</p>

]]></content:encoded>
			<wfw:commentRss>http://krebsonsecurity.com/2010/05/accused-mariposa-botnet-operators-sought-jobs-at-spanish-security-firm/feed/</wfw:commentRss>
		<slash:comments>20</slash:comments>
		</item>
		<item>
		<title>&#8216;Mariposa&#8217; Botnet Authors May Avoid Jail Time</title>
		<link>http://krebsonsecurity.com/2010/03/mariposa-botnet-authors-may-avoid-jail-time/</link>
		<comments>http://krebsonsecurity.com/2010/03/mariposa-botnet-authors-may-avoid-jail-time/#comments</comments>
		<pubDate>Thu, 04 Mar 2010 17:11:48 +0000</pubDate>
		<dc:creator>BrianKrebs</dc:creator>
				<category><![CDATA[Other]]></category>
		<category><![CDATA[christopher davis]]></category>
		<category><![CDATA[defence intelligence]]></category>
		<category><![CDATA[juan santana]]></category>
		<category><![CDATA[mariposa botnet]]></category>
		<category><![CDATA[panda security]]></category>

		<guid isPermaLink="false">http://www.krebsonsecurity.com/?p=1450</guid>
		<description><![CDATA[Three Spanish men were arrested last month for allegedly building an international network of more than 12 million hacked PCs that were used for everything from identity theft to spamming. But according to Spanish authorities and security experts who helped unravel the crime ring, the accused may very well never see the inside of a [...]]]></description>
			<content:encoded><![CDATA[
<div class="topsy_widget_data topsy_theme_silver" style="float: left;margin-right: 0.75em; background: url(data:,%7B%20%22url%22%3A%20%22http%253A%252F%252Fkrebsonsecurity.com%252F2010%252F03%252Fmariposa-botnet-authors-may-avoid-jail-time%252F%22%2C%20%22style%22%3A%20%22big%22%2C%20%22title%22%3A%20%22%27Mariposa%27%20Botnet%20Authors%20May%20Avoid%20Jail%20Time%22%20%7D);"></div>
<p><a rel="attachment wp-att-1451" href="http://www.krebsonsecurity.com/wp-content/uploads/2010/03/Screen-shot-2010-03-03-at-7.08.09-PM.png"><img class="alignright size-medium wp-image-1451" title="Screen shot 2010-03-03 at 7.08.09 PM" src="http://www.krebsonsecurity.com/wp-content/uploads/2010/03/Screen-shot-2010-03-03-at-7.08.09-PM-300x165.png" alt="" width="300" height="165" /></a>Three Spanish men were arrested last month for allegedly building an international network of more than 12 million hacked PCs that were used for everything from identity theft to spamming. But according to Spanish authorities and security experts who helped unravel the crime ring, the accused may very well never see the inside of a jail cell even if they are ultimately found guilty, due to insufficient cyber crime legislation in Spain.</p>
<p>According to Spanish security firm Panda Security, the massive botnet, dubbed &#8220;Marioposa&#8221; (Spanish for &#8220;butterfly&#8221;), was rented out to criminals as a delivery platform for installing malicious software such as the data-stealing ZeuS Trojan and pay-per-install toolbars. Panda said the gang also stole directly from victim bank accounts, using <a href="http://www.krebsonsecurity.com/2010/01/top-10-ways-to-get-fired-as-a-money-mule/" target="_blank">money mules</a> in the United States and Canada, and laundered stolen money through online gambling Web sites (pictured above is a screen shot of the Web site the men created where would-be Mariposa customers could visit for information on purchasing access to the botnet and other criminal services.)</p>
<p>Panda said Mariposa helped crooks steal sensitive data from more than 800,000 victims, including home users, companies, government agencies and universities in at least 190 countries. Spanish police estimate that at least 600,000 of the victimized PCs belong to Spanish citizens, and yet they concede it may be extremely challenging to put the men in jail if they are convicted at trial.</p>
<p>&#8220;It is almost impossible to be sent to prison for these kinds of crimes in Spain, where prison is mainly for serious crime cases,&#8221; said <strong>Captain Cesar Lorenzana</strong>, deputy head technology crime division of the Spanish Civil Guard. &#8220;In Spain, it is not a crime to own and operate a botnet or distribute malware. So even if we manage to prove they are using a botnet, we will need to prove they also were stealing identities and other things, and that is where our lines of investigation are focusing right now.&#8221;</p>
<p><span id="more-1450"></span></p>
<p>Spain is one of nearly three dozen countries that is a signatory to the Council of Europe&#8217;s cybercrime treaty, but  Spanish legislators have not yet ratified the treaty by passing anti-cybercrime laws that would bring its judicial system in line with the treaty&#8217;s goals.</p>
<p>The Mariposa botnet takedown was orchestrated by a working group comprising Panda, the Georgia Tech Information Security Center, and Canadian security firm Defence Intelligence, which first detailed the workings of the botnet in a white paper released in May 2009.</p>
<p>On Dec. 23, 2009, the working group was able to &#8220;sinkhole&#8217; the botnet by hijacking the command and control networks that were being used to orchestrate the botnet&#8217;s activities. But according to Defence Intelligence CEO <strong>Christopher Davis</strong>, a few days later, the alleged ringleader of the Mariposa botnet gang who goes by the hacker alias &#8220;Netkairo,&#8221; bribed an employee at a Spanish domain name registrar that the gang had been using to register Web site names that helped them control the botnet. Armed with those domains, Netkairo was able to rebuild the botnet, as the individual PCs previously enslaved by the Mariposa botnet were still programmed to regularly connect to those sites and download new marching orders.</p>
<p>Davis said that on Jan. 22, the hacker launched a distributed denial of service attack against Defense Intelligence&#8217;s Web site, using more than a million PCs the gang had managed to corral back into the Mariposa botnet. That assault, which forced the infected PCs to flood the company&#8217;s site with junk Web traffic, not only knocked Defence Intelligence offline, but took out networks of several other organizations that were using the same Internet service provider, including a local university and a few government agencies in Ottawa.</p>
<p>Lorenzana said the three men haven&#8217;t been named publicly because they haven&#8217;t yet been charged with a crime. Until that happens, which will probably be in a couple of weeks, the men are all free on their own recognizance. In the meantime, they are free to hoover up as much stolen data as they please, as the Mariposa working group has not yet been able to shutter the Web sites that served as the repository for personal and financial data stolen from people whose systems were ensnared by the bot.</p>
<p>&#8220;The main problem is that even though the botnet itself has been taken down, these bots are all still infected, and these guys who operated the botnet can still go and download all the details of the data they have stolen,&#8221; Lorenzana said.</p>
<p><strong>Juan Santana</strong>, CEO of Panda Security, said he hopes this case will spur Spanish lawmakers to amend the penal code to more specifically punish cyber crime activities.</p>
<p>&#8220;I don&#8217;t think these guys will go to jail, especially if it is the first time they have committed a crime,&#8221; Santana said. &#8220;The government needs to pass laws that are enforceable and enforced afterward. In the vast majority of countries, malicious hackers do not fear that if they do get caught that they will go to jail, because the benefit for them is far higher than the risk right now.&#8221;</p>

]]></content:encoded>
			<wfw:commentRss>http://krebsonsecurity.com/2010/03/mariposa-botnet-authors-may-avoid-jail-time/feed/</wfw:commentRss>
		<slash:comments>29</slash:comments>
		</item>
	</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Page Caching using memcached (User agent is rejected)
Database Caching 2/21 queries in 0.009 seconds using memcached
Object Caching 580/621 objects using memcached

Served from: krebsonsecurity.com @ 2012-02-11 13:43:10 -->
