Endpoint

2/23/2018
03:45 PM
Dark Reading
Dark Reading
Products and Releases
50%
50%

Arkansas Man Sentenced to Prison for Developing and Distributing Prolific Malware

Department of Justice
Office of Public Affairs

FOR IMMEDIATE RELEASE
Friday, February 23, 2018

Arkansas Man Sentenced to Prison for Developing and Distributing Prolific Malware

An Arkansas man was sentenced today to 33 months in prison for aiding and abetting computer intrusions by selling malicious software, or “malware,” to individuals who used the malware to steal sensitive information, surreptitiously activate webcams, and conduct other illegal intrusions.

Acting Assistant Attorney General John P. Cronan of the Justice Department’s Criminal Division, Acting U.S. Attorney Tracy Doherty-McCormick for the Eastern District of Virginia and Assistant Director in Charge Andrew W. Vale of the FBI’s Washington Field Office, made the announcement.

Taylor Huddleston, 27, of Hot Springs, Arkansas was sentenced by U.S. District Judge Liam O’Grady.  Judge O’Grady also ordered the defendant to serve two years of supervised release following his prison sentence.  Huddleston pleaded guilty on July 25, 2017.

According to court documents, Huddleston developed, marketed, and distributed two products that were extremely popular with cybercriminals around the world. The first is the “NanoCore RAT,” a type of malware that is used to steal information from victim computers, including sensitive information such as passwords, emails, and instant messages. The NanoCore RAT even allowed users to surreptitiously activate the webcam on the victim computers in order to spy on the victims. Huddleston’s NanoCore RAT was used to infect and attempt to infect tens of thousands of computers. Huddleston’s other product, “Net Seal,” was licensing software that he used to distribute malware for co-conspirators for a fee. For instance, Huddleston used Net Seal to assist Zachary Shames in the distribution of malware to 3,000 people that was in turn used to infect 16,000 computers. In his guilty plea, Huddleston admitted that he intended his products to be used maliciously.

The case was prosecuted by Senior Counsel Ryan K. Dickey of the Criminal Division’s Computer Crime and Intellectual Property Section and Assistant U.S. Attorney Kellen S. Dwyer of the Eastern District of Virginia.

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
6 Security Trends for 2018/2019
Curtis Franklin Jr., Senior Editor at Dark Reading,  10/15/2018
Most IT Security Pros Want to Change Jobs
Dark Reading Staff 10/12/2018
4 Ways to Fight the Email Security Threat
Asaf Cidon, Vice President, Content Security Services, at Barracuda Networks,  10/15/2018
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
Flash Poll
The Risk Management Struggle
The Risk Management Struggle
The majority of organizations are struggling to implement a risk-based approach to security even though risk reduction has become the primary metric for measuring the effectiveness of enterprise security strategies. Read the report and get more details today!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-10839
PUBLISHED: 2018-10-16
Qemu emulator <= 3.0.0 built with the NE2000 NIC emulation support is vulnerable to an integer overflow, which could lead to buffer overflow issue. It could occur when receiving packets over the network. A user inside guest could use this flaw to crash the Qemu process resulting in DoS.
CVE-2018-13399
PUBLISHED: 2018-10-16
The Microsoft Windows Installer for Atlassian Fisheye and Crucible before version 4.6.1 allows local attackers to escalate privileges because of weak permissions on the installation directory.
CVE-2018-18381
PUBLISHED: 2018-10-16
Z-BlogPHP 1.5.2.1935 (Zero) has a stored XSS Vulnerability in zb_system/function/c_system_admin.php via the Content-Type header during the uploading of image attachments.
CVE-2018-18382
PUBLISHED: 2018-10-16
Advanced HRM 1.6 allows Remote Code Execution via PHP code in a .php file to the user/update-user-avatar URI, which can be accessed through an "Update Profile" "Change Picture" (aka user/edit-profile) action.
CVE-2018-18374
PUBLISHED: 2018-10-16
XSS exists in the MetInfo 6.1.2 admin/index.php page via the anyid parameter.