Suspect worked for antivirus and software development firms in Russia.
Microsoft is continuing its legal tear against botnets: It has now named the alleged botnet operator of the Kelihos botnet that it helped take down last fall.
The alleged perpetrator, Andrey N. Sabelnikov, a Russian engineer, has been added to Microsoft's legal suit filed in U.S. District Court in September in relation to the botnet. The company, which worked with Kaspersky Lab and Kyrus to take down the spamming botnet, says the initial claim's named co-defendants in Microsoft's civil lawsuit, Dominique Alexander Piatti and dotFREE Group SRO, cooperated and provided information that led to the latest legal action against Sabelnikov as part of a settlement in October.
"In today's complaint, Microsoft presented evidence to the court that Mr. Sabelnikov wrote the code for and either created, or participated in creating, the Kelihos malware. Further, the complaint alleges that he used the malware to control, operate, maintain, and grow the Kelihos botnet. These allegations are based on evidence Microsoft investigators uncovered while analyzing the Kelihos malware," said Richard Domingues Boscovich, senior attorney for Microsoft's digital crimes unit. "Microsoft also alleges that Mr. Sabelnikov registered more than 3,700 'cz.cc' subdomains from Mr. Piatti and dotFREE Group SRO, and misused those subdomains to operate and control the Kelihos botnet."
Microsoft says Sabelnikov lives in St. Petersburg, Russia, and is a contractor for a software development and consulting firm who once worked as a software engineer and project manager at a firewall and antivirus firm. According to KrebsOnSecurity, that firm was Agnitum.
Dark Reading Tech Digest, Dec. 19, 2014Software-defined networking can be a net plus for security. The key: Work with the network team to implement gradually, test as you go, and take the opportunity to overhaul your security strategy.
Published: 2015-01-23 The Pie Register plugin before 2.0.14 for WordPress does not properly restrict access to certain functions in pie-register.php, which allows remote attackers to (1) add a user by uploading a crafted CSV file or (2) activate a user account via a verifyit action.
Published: 2015-01-23 OpenStack Glance 2014.2.x through 2014.2.1, 2014.1.3, and earlier allows remote authenticated users to bypass the storage quote and cause a denial of service (disk consumption) by deleting an image in the saving state.
Published: 2015-01-23 Integer overflow in oggenc in vorbis-tools 1.4.0 allows remote attackers to cause a denial of service (crash) via a crafted number of channels in a WAV file, which triggers an out-of-bounds memory access.
If you’re a security professional, you’ve probably been asked many questions about the December attack on Sony. On Jan. 21 at 1pm eastern, you can join a special, one-hour Dark Reading Radio discussion devoted to the Sony hack and the issues that may arise from it.