Attacks/Breaches
12/12/2012
09:53 AM
Dark Reading
Dark Reading
Products and Releases
50%
50%

FBI, International Law Enforcement Disrupt International Organized Cybercrime Ring Related To Butterfly Botnet

Botnet linked to more than 11 million compromised computer systems and more than $850 million in losses

The Department of Justice and the FBI, along with international law enforcement partners, announced the arrests of 10 individuals from Bosnia and Herzegovina, Croatia, Macedonia, New Zealand, Peru, the United Kingdom, and the United States and the execution of numerous search warrants and interviews.

The operation identified international cyber crime rings that are linked to multiple variants of the Yahos malicious software, or malware, which is linked to more than 11 million compromised computer systems and over $850 million in losses via the Butterfly Botnet, which steals computer users’ credit card, bank account, and other personal identifiable information.

“Botnet” is short for robot network; botnets are made up of compromised computer systems and can be utilized by cyber criminals to execute distributed denial of service attacks, send spam e-mails, and conduct underground organized criminal activity, to include malware distribution.

Facebook’s security team provided assistance to law enforcement throughout the investigation by helping to identify the root cause, the perpetrators, and those affected by the malware. Yahos targeted Facebook users from 2010 to October 2012, and security systems were able to detect affected accounts and provide tools to remove these threats.

The investigation was conducted by the FBI’s Cyber Division, International Operations Division, and the following field offices: Albany, Baltimore, Boston, Charlotte, Cincinnati, Cleveland, Dallas, El Paso, Honolulu, Jacksonville, Los Angeles, Milwaukee, New Haven, New Orleans, Norfolk, Philadelphia, Pittsburgh, Sacramento, San Diego, San Juan, St. Louis, Tampa, and Washington Field; the Department of Justice’s Computer Crime and Intellectual Property Section; the U.S. Attorney’s Office for the District of Hawaii; the U.S. Attorney’s Office for the Western District of Pennsylvania; and the U.S. Attorney’s Office for the District of Columbia.

The FBI received invaluable international cooperation, assistance, and response from the following partner organizations: Bosnia and Herzegovina’s Republika Srpska Ministry of Interior; Republic of Croatia, Ministry of Interior General Police Directorate, National Police Office for Suppression of Corruption and Organized Crime; New Zealand Police; Peruvian National Police; and the United Kingdom’s Serious Organised Crime Agency.

It is recommended that computer users update their applications and operating system on a regular basis to reduce the risk of compromise and perform regular anti-virus scanning of their computer system. It is also helpful to disconnect personal computers from the Internet when the machines are not in use. Computer users who believe they have been victimized should file a complaint with the FBI’s Internet Crime Complaint Center at www.ic3.gov.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading December Tech Digest
Experts weigh in on the pros and cons of end-user security training.
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-7178
Published: 2014-11-28
Enalean Tuleap before 7.5.99.6 allows remote attackers to execute arbitrary commands via the User-Agent header, which is provided to the passthru PHP function.

CVE-2014-7850
Published: 2014-11-28
Cross-site scripting (XSS) vulnerability in the Web UI in FreeIPA 4.x before 4.1.2 allows remote attackers to inject arbitrary web script or HTML via vectors related to breadcrumb navigation.

CVE-2014-8423
Published: 2014-11-28
Unspecified vulnerability in the management portal in ARRIS VAP2500 before FW08.41 allows remote attackers to execute arbitrary commands via unknown vectors.

CVE-2014-8424
Published: 2014-11-28
ARRIS VAP2500 before FW08.41 does not properly validate passwords, which allows remote attackers to bypass authentication.

CVE-2014-8425
Published: 2014-11-28
The management portal in ARRIS VAP2500 before FW08.41 allows remote attackers to obtain credentials by reading the configuration files.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Now that the holiday season is about to begin both online and in stores, will this be yet another season of nonstop gifting to cybercriminals?