Endpoint

2/23/2018
03:45 PM
Dark Reading
Dark Reading
Products and Releases
50%
50%

Arkansas Man Sentenced to Prison for Developing and Distributing Prolific Malware

Department of Justice
Office of Public Affairs

FOR IMMEDIATE RELEASE
Friday, February 23, 2018

Arkansas Man Sentenced to Prison for Developing and Distributing Prolific Malware

An Arkansas man was sentenced today to 33 months in prison for aiding and abetting computer intrusions by selling malicious software, or “malware,” to individuals who used the malware to steal sensitive information, surreptitiously activate webcams, and conduct other illegal intrusions.

Acting Assistant Attorney General John P. Cronan of the Justice Department’s Criminal Division, Acting U.S. Attorney Tracy Doherty-McCormick for the Eastern District of Virginia and Assistant Director in Charge Andrew W. Vale of the FBI’s Washington Field Office, made the announcement.

Taylor Huddleston, 27, of Hot Springs, Arkansas was sentenced by U.S. District Judge Liam O’Grady.  Judge O’Grady also ordered the defendant to serve two years of supervised release following his prison sentence.  Huddleston pleaded guilty on July 25, 2017.

According to court documents, Huddleston developed, marketed, and distributed two products that were extremely popular with cybercriminals around the world. The first is the “NanoCore RAT,” a type of malware that is used to steal information from victim computers, including sensitive information such as passwords, emails, and instant messages. The NanoCore RAT even allowed users to surreptitiously activate the webcam on the victim computers in order to spy on the victims. Huddleston’s NanoCore RAT was used to infect and attempt to infect tens of thousands of computers. Huddleston’s other product, “Net Seal,” was licensing software that he used to distribute malware for co-conspirators for a fee. For instance, Huddleston used Net Seal to assist Zachary Shames in the distribution of malware to 3,000 people that was in turn used to infect 16,000 computers. In his guilty plea, Huddleston admitted that he intended his products to be used maliciously.

The case was prosecuted by Senior Counsel Ryan K. Dickey of the Criminal Division’s Computer Crime and Intellectual Property Section and Assistant U.S. Attorney Kellen S. Dwyer of the Eastern District of Virginia.

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Election Websites, Back-End Systems Most at Risk of Cyberattack in Midterms
Kelly Jackson Higgins, Executive Editor at Dark Reading,  8/14/2018
Intel Reveals New Spectre-Like Vulnerability
Curtis Franklin Jr., Senior Editor at Dark Reading,  8/15/2018
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-13435
PUBLISHED: 2018-08-16
** DISPUTED ** An issue was discovered in the LINE jp.naver.line application 8.8.0 for iOS. The Passcode feature allows authentication bypass via runtime manipulation that forces a certain method to disable passcode authentication. NOTE: the vendor indicates that this is not an attack of interest w...
CVE-2018-13446
PUBLISHED: 2018-08-16
** DISPUTED ** An issue was discovered in the LINE jp.naver.line application 8.8.1 for Android. The Passcode feature allows authentication bypass via runtime manipulation that forces a certain method's return value to true. In other words, an attacker could authenticate with an arbitrary passcode. ...
CVE-2018-14567
PUBLISHED: 2018-08-16
libxml2 2.9.8, if --with-lzma is used, allows remote attackers to cause a denial of service (infinite loop) via a crafted XML file that triggers LZMA_MEMLIMIT_ERROR, as demonstrated by xmllint, a different vulnerability than CVE-2015-8035 and CVE-2018-9251.
CVE-2018-15122
PUBLISHED: 2018-08-16
An issue found in Progress Telerik JustAssembly through 2018.1.323.2 and JustDecompile through 2018.2.605.0 makes it possible to execute code by decompiling a compiled .NET object (such as DLL or EXE) with an embedded resource file by clicking on the resource.
CVE-2018-11509
PUBLISHED: 2018-08-16
ASUSTOR ADM 3.1.0.RFQ3 uses the same default root:admin username and password as it does for the NAS itself for applications that are installed from the online repository. This may allow an attacker to login and upload a webshell.