Attacks/Breaches
4/10/2013
08:37 AM
50%
50%

LulzSec Hackers Plead Guilty To CIA, Sony Attacks

Three men admit in London courtroom they launched distributed denial of service attacks and defacements that targeted a variety of websites.

Anonymous: 10 Things We Have Learned In 2013
Anonymous: 10 Things We Have Learned In 2013
(click image for larger view and for slideshow)
Three members of LulzSec pleaded guilty Tuesday in a London courtroom to waging a seven-month hacking campaign in 2011.

Defendant Ryan Ackroyd (aka Kayla), 26, pleaded guilty to one charge of carrying out an unauthorized act to impair the operation of a computer, relating to attacks launched between February and September 2011 against numerous websites, including the Arizona State Police and 20th Century Fox.

Separately, Jake Davis (aka topiary, atopiary), 20, and Mustafa al-Bassam (aka "Tflow"), 18, pleaded guilty Tuesday to launching attacks against the CIA, both Britain's Serious Organized Crime Agency (SOCA) and National Health Service (NHS), as well as News International, 20th Century Fox and Sony Pictures Entertainment.

[ Anonymous seems to still be active. Read Anonymous Claims 100,000 Israel Site Disruptions. ]

All had been arrested in the course of a trans-Atlantic investigation conducted by the FBI and Scotland Yard into the hacktivist groups LulzSec and Anonymous. A separate U.S. indictment had charged Ackroyd and Davis with having participated in attacks against the Atlanta chapter of Infragard, Nintendo, the Public Broadcasting Service (PBS) and Westboro Baptist church.

Prosecutors said Ackroyd was the brains and botnet aficionado behind the LulzSec operations. Notably, Ackroyd's botnet, which tapped infected -- or zombie -- PCs, was used to launch distributed denial-of-service (DDoS) attacks against many of the targets.

"He was the hacker, so to speak, they turned to him for his expertise as a hacker," prosecutor Sandip Patel told the court, reported the Guardian. She also said that Ackroyd had admitted to using the online persona known as "Kayla," claiming to be a 16-year-old girl.

Tuesday marked the first time that Mustafa al-Bassam, a student who turned 18 in January, was named in court. He's the youngest known LulzSec participant to have been charged.

All three men, together with Ryan Cleary (aka "ryan," "Herschel.mcdoogenstein," "anakin," "ni," "vial" and "x"), who previously pleaded guilty to related charges, are due to be sentenced on May 14.

LulzSec, or Lulz Security, which spun off from the Anonymous collective in 2011, espoused a lulz -- or "for the laughs" -- mentality. Backed by witty press pronouncements and putdowns authored by Davis, the hacktivist group engaged in a 50-day hacking, data breach and defacement spree before unexpectedly announcing its retirement.

The reason for the sudden stop to LulzSec operations came to light later, when court documents revealed that group leader "Sabu" had been busted by the FBI in June 2011 and immediately turned informant. Hector Xavier Monsegur, 29, aka Sabu, has been helping the bureau amass intelligence on LulzSec and Anonymous operators, as well as block planned and unfolding attacks.

Monsegur has yet to be sentenced by U.S. authorities, with his sentencing hearing having most recently having been delayed to August 2013 "in light of the defendant's ongoing co-operation with the government," according to court documents.

Cleary and Davis appeared in London court last year, at which time they were then scheduled to stand trial -- together with Ackroyd and Bassam, who hadn't yet been named -- this week.

Since Tuesday's court hearing, everyone who's been charged by British police with crimes related to LulzSec or the original incarnation of Anonymous has now pleaded guilty. But related prosecutions are still continuing in the United States, with authorities most recently having charged Reuters journalist Matthew Keys, 26, with helping Anonymous hack into the computers of Tribune Co. In addition, Cleary was indicted last year by a U.S. federal grand jury and could face extradition to the United States, although U.S. prosecutors haven't publicly stated that they plan to seek his extradition.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2013-2184
Published: 2015-03-27
Movable Type before 5.2.6 does not properly use the Storable::thaw function, which allows remote attackers to execute arbitrary code via the comment_state parameter.

CVE-2014-3619
Published: 2015-03-27
The __socket_proto_state_machine function in GlusterFS 3.5 allows remote attackers to cause a denial of service (infinite loop) via a "00000000" fragment header.

CVE-2014-8121
Published: 2015-03-27
DB_LOOKUP in nss_files/files-XXX.c in the Name Service Switch (NSS) in GNU C Library (aka glibc or libc6) 2.21 and earlier does not properly check if a file is open, which allows remote attackers to cause a denial of service (infinite loop) by performing a look-up while the database is iterated over...

CVE-2014-9712
Published: 2015-03-27
Websense TRITON V-Series appliances before 7.8.3 Hotfix 03 and 7.8.4 before Hotfix 01 allows remote administrators to read arbitrary files and obtain passwords via a crafted path.

CVE-2015-0658
Published: 2015-03-27
The DHCP implementation in the PowerOn Auto Provisioning (POAP) feature in Cisco NX-OS does not properly restrict the initialization process, which allows remote attackers to execute arbitrary commands as root by sending crafted response packets on the local network, aka Bug ID CSCur14589.

Dark Reading Radio
Archived Dark Reading Radio
Good hackers--aka security researchers--are worried about the possible legal and professional ramifications of President Obama's new proposed crackdown on cyber criminals.