Welcome to DU! The truly grassroots left-of-center political community where regular people, not algorithms, drive the discussions and set the standards. Join the community: Create a free account Support DU (and get rid of ads!): Become a Star Member Latest Breaking News General Discussion The DU Lounge All Forums Issue Forums Culture Forums Alliance Forums Region Forums Support Forums Help & Search

mahatmakanejeeves

(57,319 posts)
Mon Jun 2, 2014, 02:20 PM Jun 2014

Federal agents knock down Zeus Botnet, CryptoLocker

Source: USA Today

Kevin Johnson and Donna Leinwand Leger 1:38 p.m. EDT June 2, 2014

WASHINGTON -- The U.S. has seized a global network of computer servers known as Gameover Zeus Botnet used by cyber criminals to spread malware viruses and steal millions of dollars from businesses and consumers, the Justice Department said Monday.

U.S. and foreign law enforcement agents in a separate action also seized the computers that distributed malware known as "CryptoLocker" that locks computers until the victims pay a ransom.

A 14-count indictment, unsealed Monday in Pittsburgh, charges Evgeniy Mikhailovich Bogachev, 30, of Anapa, Russia, with directing the Gameover Zeus Botnet. Charges include conspiracy, computer hacking, wire fraud, bank fraud and money laundering. Bagchev is also charged in Omaha with conspiracy to commit bank fraud for his alleged involvement with an earlier version of the Zeus malware called "Jabber Zeus."

Court documents identify Bogachev as "Slavik," a computer nickname for a notorious leader of a tightly knit gang of cyber criminals based in Russia and Ukraine allegedly responsible for both Gameover Zeus and CryptoLocker. The hackers allegedly used the gameover Zeus network of infected computers to distribute CryptoLocker. Federal investigators also say Bogachev used other online names, including "Pollingsoon" and "Lucky12345."


Read more: http://www.usatoday.com/story/news/nation/2014/06/02/global-cyber-fraud/9863977/



Deputy Attorney General James Cole Delivers Remarks at Press Conference for Gameover Zeus and Cryptolocker Operations

Washington, D.C. ~ Monday, June 2, 2014

Good afternoon and welcome, everyone.

Today, we are here to announce that, over the weekend, the Department disrupted two extremely damaging cyber threats – the financial botnet known as Gameover Zeus and the malicious software known as Cryptolocker. Gameover Zeus has secretly diverted millions of dollars to bank accounts of criminals across the globe while Cryptolocker – a ransomware scheme – has shutout hundreds of thousands of users from their own computers and data and demanded that victims pay to get access back to their own machines and information.

We also have identified and charged one of the leaders of the Eastern European cybercriminal gang that is responsible for these schemes. Evgeniy Bogachev, a Russian national, has been indicted in Pittsburgh, Pennsylvania for his role as an administrator of the Gameover Zeus botnet. Bogachev – a true 21st Century criminal who commits cybercrimes across the globe with the stroke of a key and the click of a mouse – is also charged in a newly unsealed criminal complaint in Omaha, Nebraska, for orchestrating a related botnet scheme. These crimes have earned Bogachev a place on its list of the world’s most-wanted cyber criminals.

As alleged in the unsealed indictment, Gameover Zeus is the most sophisticated and damaging botnet we have ever encountered. Frequently targeting the computers of small and mid-size businesses, the Gameover Zeus software intercepts passwords and other private information that can be used to conduct wire transfers, and then initiates or re-directs wire transfers from victims’ bank accounts to foreign bank accounts controlled by the criminals. Individual fraudulent wire transfers conducted through Gameover Zeus commonly exceed $1 million. At least one fraudulent wire transaction amounted to $6.9 million. Security researchers estimate that between 500,000 and 1 million computers worldwide are infected with Gameover Zeus, and that approximately 25 percent of the infected computers are located in the United States. The total losses worldwide are unknown, but we believe that losses exceed $100 million to U.S. victims alone. Because many of the victims are small- and mid-sized businesses, their accounts typically do not have the same legal protections afforded to consumer accounts, so such losses can be devastating.

Cryptolocker is a form of “ransomware,” a type of malicious software that prevents victims from accessing their computer files until they make a ransom payment to the criminals. It is the most sophisticated form of ransomware we have yet seen. Once it infects a victim’s computer, Cryptolocker encrypts its files and displays a ransom note on the screen, instructing victims to pay hundreds of dollars – typically in the cryptocurrency Bitcoin – to receive a password to decrypt their files. As of April 2014, Cryptolocker had attacked more than 200,000 computers, and more than half of those attacks occurred here in the United States. In its first two months of operation alone, it has been estimated that the criminals behind Cryptolocker collected over $27 million in ransom payments from victims seeking to get access to their files back.


U.S. leads global effort to disrupt cyber crime ring


By Jim Finkle, Aruna Viswanatha and Julia Edwards

BOSTON/WASHINGTON Mon Jun 2, 2014 1:58pm EDT

BOSTON/WASHINGTON (Reuters) - A U.S.-led international operation disrupted a crime ring that had infected hundreds of thousands of PCs around the globe with malicious software used for stealing banking credentials and cyber extortion, the Justice Department said on Monday.

Authorities used technical and legal tactics to interrupt the so-called botnet's operations, shutting down the servers the cyber criminals used to control infected machines and causing those machines to "phone home" to servers controlled by law enforcement.
9 replies = new reply since forum marked as read
Highlight: NoneDon't highlight anything 5 newestHighlight 5 most recent replies
Federal agents knock down Zeus Botnet, CryptoLocker (Original Post) mahatmakanejeeves Jun 2014 OP
This is good news but.... mikeysnot Jun 2014 #1
Mikey, I think you are right, but... Nitram Jun 2014 #9
Much as I would like to believe this Demeter Jun 2014 #2
rt.com headline: US cracks down on internet entrepeneurs and activists nt geek tragedy Jun 2014 #3
You missed the most important paragraph, i.e. no one has actually been arrested. happyslug Jun 2014 #4
Not really. Chan790 Jun 2014 #6
Who is saying Putin is playing chicken, Putin may have decided he can NOT deal with Washington happyslug Jun 2014 #8
UK news differs - threat remains. Two Weeks' To Prepare For Cyber Attack. dipsydoodle Jun 2014 #5
"The Sky is falling, the sky is falling" The Green Manalishi Jun 2014 #7

mikeysnot

(4,756 posts)
1. This is good news but....
Mon Jun 2, 2014, 03:24 PM
Jun 2014

there are others that will have their version of this operation in place in no time...

Nitram

(22,768 posts)
9. Mikey, I think you are right, but...
Tue Jun 3, 2014, 08:34 AM
Jun 2014

...it is rare for a group to be this well-organized and disciplined. Nice to have them out of action.

 

Demeter

(85,373 posts)
2. Much as I would like to believe this
Mon Jun 2, 2014, 03:31 PM
Jun 2014

I've been burned too often before.

Too bad the US govt. spent all its credibility suppressing dissent on the Left (while running away from the Right). They'd have to bring about a Second Coming at this point to get any street cred from me or most anyone left of the Tea Party.

And we have only their word for it, too.

 

happyslug

(14,779 posts)
4. You missed the most important paragraph, i.e. no one has actually been arrested.
Mon Jun 2, 2014, 04:53 PM
Jun 2014
Cole said U.S. authorities were in contact with Russian officials in an attempt to secure Bogachev's arrest, though the suspect -- a boating enthusiast known to frequent ports along the Black Sea -- remains a fugitive.


Thus we are asking Russia to arrest this man, at the same time we are asking Russia to pull out of the Ukraine. All Putin has to do is to ask Bogachev to modify his bug, but simply removing the ability to undo the block. Right now, the blocks are being removed via the option in the program that if you pay up, the computer will be unblocked. If that system is removed, how do to unblock it?

The US may have to make a decision, accept computers being blocked or give Putin something.
 

Chan790

(20,176 posts)
6. Not really.
Mon Jun 2, 2014, 08:23 PM
Jun 2014

Putin doesn't want to play the chicken game with the US. The consequences are higher for Russia and Putin than the US.

 

happyslug

(14,779 posts)
8. Who is saying Putin is playing chicken, Putin may have decided he can NOT deal with Washington
Tue Jun 3, 2014, 12:22 AM
Jun 2014

Last edited Wed Jun 4, 2014, 04:22 PM - Edit history (1)

In simple terms, Putin is acting as if he is at war with the US, except no actual fighting. In such a situation, he sees nothing but good points in refusing to work with Washington.

1. Russia is the First or Second largest energy producer in the world. Russia and Saudi Arabia has jostle for position of #1 oil producer since 2000. In the 1990s the US was the #2 producer of oil, to Saudi Arabia, with Russia a solid, but distant third. These three countries, the US, Saudi Arabia and Russia (prior to 1989 the Soviet Union) had been the top three oil producers since at least the 1950s, when Saudi Arabia join the US and Russia was the top oil producers (The US and Russia being # 1 and #2 oil producer goes back to the 1860s).

Now, the US is a net oil IMPORTER since 1969, Russia has been a net oil exporter since the 1860s. The #1 traded commodity in the world is Fuel, followed by Agricultural products:

http://www.wto.org/english/res_e/statis_e/its2013_e/its13_merch_trade_product_e.htm

In world Trade the Russia is #10 in exports, #16 in imports. The US is #1 in imports and #2 in exports, thus while the US economy is larger and in many ways stronger, Russia is the most independent of any of the major nations from US domination do to its low level of imports and exports.

http://www.censtatd.gov.hk/hkstat/sub/sp230.jsp?tableID=081&ID=0&productType=8

In total Trade the US is #1, Russia is #13 of the top trading nations:

Total trade
The mainland of China.......1
USA....................................2
Germany............................3
Japan.................................4
France................................5
Netherlands.......................6
United Kingdom..................7
Hong Kong..........................8
Korea..................................9
Italy...................................10
Canada..............................11
Belgium..............................12
Russia................................13
Singapore..........................14
India..................................15
Mexico................................16

http://www.censtatd.gov.hk/hkstat/sub/sp230.jsp?tableID=081&ID=0&productType=8

1/2 of all INTERNATIONAL trade in North America is the Nations of North America.

3/4 of all INTERNATIONAL trade within Europe is with other Nations of Europe:

http://foreigntrade.polpred.com/upload/pdf/wto2.pdf

While 50% of all international trade is from Europe and North America, the # 1 source of imports into Europe is Asia (including China and Japan). North America is a close #2.

1/2 of Russia's trade is with Europe, Another 1/4 of Russia's trade is with former members of the Soviet Union. 20% of Russia's trade is with Asia, the remaining 5% is divided between the US, then the Middle East, then Africa and South America.

US trade with Russia AND all of the former nations of the Soviet Union is less then 1.1%.

7.7% of European Trade is with the US and only 1.7% with the Russia Federation.

I bring this all up, for Russia is the least tied in with the rest of the world when it comes to trade. Thus US ability to harm Russia economically is limited. The world no longer looks at Russia Planes as an alternative to US planes, but many Russian Flights are still made by Russia planes and are used by Russia Airlines including Aerofloat. Today, Aerofloat has 153 planes and another 165 planes on order. 121 Airbus (with another 22 or order). 16 Boeings (various makes and models) with another 30 on order, but it still has 16 Russian made jets, with 67 on order. Aerofloat has since 2000 concentrated on Airbus and Russian built planes, through it still buy some America made Boeings.


My point is Russia is relatively independent economically from the US. Russia is more dependent on Europe (or more accurately Europe is dependent in Russian Oil and Natural Gas). Thus of all of the countries of the world, Russia and Putin have the least to fear from any ECONOMIC war with the US. Yes, Russia will suffer, but Europe will suffer more and will Europe permit the US to hurt Europe so the US can hurt Putin? In many ways that is the real question, and a question I think Europe will answer in the Negative.

dipsydoodle

(42,239 posts)
5. UK news differs - threat remains. Two Weeks' To Prepare For Cyber Attack.
Mon Jun 2, 2014, 05:08 PM
Jun 2014

The National Crime Agency is warning computer users they have two weeks to protect against a "powerful computer attack".

It comes as US officials held a press conference accusing a Russian hacker of masterminding the scam and raking in £60m.

>

People are being warned to make sure their security software and operating system are both up to date, and to run scans to check for any problems.

Important files should also be backed up, said the UK's National Crime Agency (NCA).

http://news.sky.com/story/1273922/two-weeks-to-prepare-for-cyber-attack



Gameover Warning: People Given Two Weeks to Protect Against 'Powerful Computer Attack'

>

The stealth attack on the Gameover Zeus botnet (also known as P2P Zeus or GO Zeus) began late last week and as well as involving law enforcement agencies saw the collaboration of internet service providers and the security experts from companies like Dell, Trend Micro, Crowdstrike and McAfee.

While the operation has severed the links between the command and control servers maintaining the malicious software, and the victim's machines, this is only a temporary solution, and people have been warned they need to update their systems within two weeks.

https://uk.news.yahoo.com/gameover-warning-people-given-two-weeks-protect-against-160746898.html#1bsELu5

Latest Discussions»Latest Breaking News»Federal agents knock down...