Attacks/Breaches

2/2/2018
04:05 PM
50%
50%

Russian National Arrested for Kelihos Botnet Sent to US

Peter Levashov, among the world's most notorious email spammers, has been extradited to the US.

Peter Levashov, one of the world's most well-known email spammers and operator of the Kelihos botnet, has been extradited to the US from Spain. He awaits federal charges in Connecticut, where prosecutors say he used the botnet to harvest personal data.

Levashov, a Russian citizen, is accused of identity theft, wire fraud, and conspiracy. He was arrested in April 2017 while on holiday in Barcelona as part of a US Department of Justice effort to take down Kelihos. Officials said the operation was distributing hundreds of millions of fraudulent emails per year, intercepting credentials for online accounts belonging to thousands of Americans, and spreading ransomware. Indictment details were released later the same month.

The spammer initially claimed he was collecting data on opposition parties for the United Russia party, which later said he was unknown to them. Russia filed a competing extradition request; the Spanish National Court approved Levashov's extradition to the US in October.

In addition to driving spam and malware-rigged email campaigns, Levashov has been associated with click-fraud and DDoS operations. Many cyberattackers thought of him as a spam service provider. He was indicted, but not extradited, in 2009 for operating the Storm botnet.

Read more details here.

Dark Reading's Quick Hits delivers a brief synopsis and summary of the significance of breaking news events. For more information from the original source of the news item, please follow the link provided in this article. View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
BrianN060
50%
50%
BrianN060,
User Rank: Ninja
2/4/2018 | 10:46:55 AM
Russian National Arrested for Kelihos Botnet Sent to US
This is a high information-density Quick Hits article -- well worth a thorough exploration. While some aspects of the story are readily apparent, a number of more subtle and sophisticated implications are revealed when you learn more of the backstory. 
Election Websites, Back-End Systems Most at Risk of Cyberattack in Midterms
Kelly Jackson Higgins, Executive Editor at Dark Reading,  8/14/2018
Australian Teen Hacked Apple Network
Dark Reading Staff 8/17/2018
Data Privacy Careers Are Helping to Close the IT Gender Gap
Dana Simberkoff, Chief Risk, Privacy, and Information Security Officer, AvePoint, Inc.,  8/20/2018
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2017-17305
PUBLISHED: 2018-08-21
Some Huawei Firewall products USG2205BSR V300R001C10SPC600; USG2220BSR V300R001C00; USG5120BSR V300R001C00; USG5150BSR V300R001C00 have a Bleichenbacher Oracle vulnerability in the IPSEC IKEv1 implementations. Remote attackers can decrypt IPSEC tunnel ciphertext data by leveraging a Bleichenbacher R...
CVE-2017-17311
PUBLISHED: 2018-08-21
Some Huawei Firewall products USG2205BSR V300R001C10SPC600; USG2220BSR V300R001C00; USG5120BSR V300R001C00; USG5150BSR V300R001C00 have a DoS vulnerability in the IPSEC IKEv1 implementations of Huawei Firewall products. Due to improper handling of the malformed messages, an attacker may sent crafted...
CVE-2017-17312
PUBLISHED: 2018-08-21
Some Huawei Firewall products USG2205BSR V300R001C10SPC600; USG2220BSR V300R001C00; USG5120BSR V300R001C00; USG5150BSR V300R001C00 have a DoS vulnerability in the IPSEC IKEv1 implementations of Huawei Firewall products. Due to improper handling of the malformed messages, an attacker may sent crafted...
CVE-2018-12115
PUBLISHED: 2018-08-21
In all versions of Node.js prior to 6.14.4, 8.11.4 and 10.9.0 when used with UCS-2 encoding (recognized by Node.js under the names `'ucs2'`, `'ucs-2'`, `'utf16le'` and `'utf-16le'`), `Buffer#write()` can be abused to write outside of the bounds of a single `Buffer`. Writes that start from the second...
CVE-2018-7166
PUBLISHED: 2018-08-21
In all versions of Node.js 10 prior to 10.9.0, an argument processing flaw can cause `Buffer.alloc()` to return uninitialized memory. This method is intended to be safe and only return initialized, or cleared, memory. The third argument specifying `encoding` can be passed as a number, this is misint...