Attacks/Breaches
12/12/2012
09:53 AM
Dark Reading
Dark Reading
Products and Releases
50%
50%

FBI, International Law Enforcement Disrupt International Organized Cybercrime Ring Related To Butterfly Botnet

Botnet linked to more than 11 million compromised computer systems and more than $850 million in losses

The Department of Justice and the FBI, along with international law enforcement partners, announced the arrests of 10 individuals from Bosnia and Herzegovina, Croatia, Macedonia, New Zealand, Peru, the United Kingdom, and the United States and the execution of numerous search warrants and interviews.

The operation identified international cyber crime rings that are linked to multiple variants of the Yahos malicious software, or malware, which is linked to more than 11 million compromised computer systems and over $850 million in losses via the Butterfly Botnet, which steals computer users’ credit card, bank account, and other personal identifiable information.

“Botnet” is short for robot network; botnets are made up of compromised computer systems and can be utilized by cyber criminals to execute distributed denial of service attacks, send spam e-mails, and conduct underground organized criminal activity, to include malware distribution.

Facebook’s security team provided assistance to law enforcement throughout the investigation by helping to identify the root cause, the perpetrators, and those affected by the malware. Yahos targeted Facebook users from 2010 to October 2012, and security systems were able to detect affected accounts and provide tools to remove these threats.

The investigation was conducted by the FBI’s Cyber Division, International Operations Division, and the following field offices: Albany, Baltimore, Boston, Charlotte, Cincinnati, Cleveland, Dallas, El Paso, Honolulu, Jacksonville, Los Angeles, Milwaukee, New Haven, New Orleans, Norfolk, Philadelphia, Pittsburgh, Sacramento, San Diego, San Juan, St. Louis, Tampa, and Washington Field; the Department of Justice’s Computer Crime and Intellectual Property Section; the U.S. Attorney’s Office for the District of Hawaii; the U.S. Attorney’s Office for the Western District of Pennsylvania; and the U.S. Attorney’s Office for the District of Columbia.

The FBI received invaluable international cooperation, assistance, and response from the following partner organizations: Bosnia and Herzegovina’s Republika Srpska Ministry of Interior; Republic of Croatia, Ministry of Interior General Police Directorate, National Police Office for Suppression of Corruption and Organized Crime; New Zealand Police; Peruvian National Police; and the United Kingdom’s Serious Organised Crime Agency.

It is recommended that computer users update their applications and operating system on a regular basis to reduce the risk of compromise and perform regular anti-virus scanning of their computer system. It is also helpful to disconnect personal computers from the Internet when the machines are not in use. Computer users who believe they have been victimized should file a complaint with the FBI’s Internet Crime Complaint Center at www.ic3.gov.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading Tech Digest, Dec. 19, 2014
Software-defined networking can be a net plus for security. The key: Work with the network team to implement gradually, test as you go, and take the opportunity to overhaul your security strategy.
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-8802
Published: 2015-01-23
The Pie Register plugin before 2.0.14 for WordPress does not properly restrict access to certain functions in pie-register.php, which allows remote attackers to (1) add a user by uploading a crafted CSV file or (2) activate a user account via a verifyit action.

CVE-2014-9623
Published: 2015-01-23
OpenStack Glance 2014.2.x through 2014.2.1, 2014.1.3, and earlier allows remote authenticated users to bypass the storage quote and cause a denial of service (disk consumption) by deleting an image in the saving state.

CVE-2014-9638
Published: 2015-01-23
oggenc in vorbis-tools 1.4.0 allows remote attackers to cause a denial of service (divide-by-zero error and crash) via a WAV file with the number of channels set to zero.

CVE-2014-9639
Published: 2015-01-23
Integer overflow in oggenc in vorbis-tools 1.4.0 allows remote attackers to cause a denial of service (crash) via a crafted number of channels in a WAV file, which triggers an out-of-bounds memory access.

CVE-2014-9640
Published: 2015-01-23
oggenc/oggenc.c in vorbis-tools 1.4.0 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted raw file.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
If you’re a security professional, you’ve probably been asked many questions about the December attack on Sony. On Jan. 21 at 1pm eastern, you can join a special, one-hour Dark Reading Radio discussion devoted to the Sony hack and the issues that may arise from it.