Endpoint

4/21/2016
04:30 PM
Connect Directly
Twitter
RSS
E-Mail
50%
50%

SpyEye Creators Sentenced To Long Prison Terms

FBI found that arrest halted the release of nasty SpyEye 2.0.

Two severe sentences handed down this week for the brains behind the SpyEye banking Trojan show that cybercriminals cannot avoid stiff penalties simply by limiting their activities to the development and distribution of malicious code. Still, the sentences also show that profiting directly from the use of malware can add up to harsher terms.

According to the US Department of Justice, SpyEye strains were used to infect over 50 million computers, stealing personally identifiable information and banking data, automatically stealing funds, and causing close to $1 billion in "financial harm to individuals and financial institutions around the globe." 

Despite the fact that he himself was not charged with stealing anything, primary SpyEye developer Aleksandr Andreevich Panin, a.k.a. "Gribodemon" and "Harderman," of Russia, was sentenced to nine years -- six months of prison (plus three years probation).  

His associate, Hamza Bendelladj, a.k.a. "Bx1," of Algeria, did profit directly from SpyEye. Not only did he develop and sell malicious plug-ins for botnets -- for proliferating malware and automating the theft of funds from victim bank accounts -- Bendelladj also stole personally identifiable information from close to half a million people, the court charged, and ran an online marketplace, VCC.sc, for selling this stolen credit card data.

For his crimes, Bendelladj was sentence to 15 years prison, plus three years probation. 

Gain insight into the latest threats and emerging best practices for managing them. Attend the Security Track at Interop Las Vegas, May 2-6. Register now!

These sentences come years after both men were arrested. Bendelladj was apprehended in Thailand in January 2013 and extradited to the US in May 2013; Panin was apprehended while in an Atlanta airport in July 2013.

SpyEye was developed to be the next Zeus. According to the DOJ, Panin allegedly received the source code and rights to sell Zeus from its creator, Evginy Bogachev, a.k.a "Slavik," and incorporated many Zeus components into SpyEye. 

In 2014, Loucif Kharouni, senior threat researcher with Trend Micro at the time, told Dark Reading that Panin was apprehended in the first place because he "got sloppy." He shared information on underground forums that Trend Micro researchers collaborating with law enforcement used to track him down. Kharouni said this was something that Zeus-creator Bogachev would never do. Bogachev remains at-large and is the FBI's most-wanted cybercriminal.

The arrest of Panin apparently interrupted the development of more advanced malware. From the DOJ release:

The FBI discovered that within months of his arrest, Panin was planning to release a new strain of SpyEye, called 'SpyEye 2.0', which, if released, would have been one of the most prolific and undetectable botnets distributed to date, and cause immeasurable losses to the international banking industry and individuals around the world.

In a blog today, Don Jackson, senior threat researcher at Damballa, which aided in the investigation, described the statement Panin gave at his sentencing hearing as "one of unqualified remorse, making no excuses, accepting full responsibility, and professing trust in the fairness of whatever sentence the judge pronounced. Although one knew it had to have been, it seemed more rehearsed than coached, and it seemed absolutely genuine."

Bendelladj, on the other hand, according to Jackson's report, "was described as extremely uncooperative," and "His apology and any assurances that he would never engage in such behavior again seemed perfunctory and hollow."

During the uncommonly long five-day sentencing hearing, Jackson reports, some of the points of contention -- all of which would, of course, affect the precise length of prison sentences -- showed how cybercrime uniquely twists traditional law. It raised questions like:

  • How many malware infections could be legally attributed to Bedelladj and how many should be attributed to other SpyEye customers?
  • What impact does the effectiveness and availability of anti-virus software have on the harm caused by these malware infections, and what impact does that have on sentencing? 
  • What exactly constitutes a payment card "access device" -- how much data is enough to grant access and does it count if is out-of-date? How many access devices were the defendants in possession of?

For more information, see the DOJ release

Related stories: 

 

Sara Peters is Senior Editor at Dark Reading and formerly the editor-in-chief of Enterprise Efficiency. Prior that she was senior editor for the Computer Security Institute, writing and speaking about virtualization, identity management, cybersecurity law, and a myriad ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Joe Stanganelli
50%
50%
Joe Stanganelli,
User Rank: Ninja
4/22/2016 | 9:28:54 AM
Accomplices
Accomplice culpability -- plain and simple.  It's no different than driving the getaway car or custom-designing the explosives for the bank's safe.  They knew what they were doing, and the law provides for that.
6 Security Trends for 2018/2019
Curtis Franklin Jr., Senior Editor at Dark Reading,  10/15/2018
6 Reasons Why Employees Violate Security Policies
Ericka Chickowski, Contributing Writer, Dark Reading,  10/16/2018
Getting Up to Speed with "Always-On SSL"
Tim Callan, Senior Fellow, Comodo CA,  10/18/2018
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Latest Comment: Too funny!
Current Issue
Flash Poll
The Risk Management Struggle
The Risk Management Struggle
The majority of organizations are struggling to implement a risk-based approach to security even though risk reduction has become the primary metric for measuring the effectiveness of enterprise security strategies. Read the report and get more details today!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-10839
PUBLISHED: 2018-10-16
Qemu emulator <= 3.0.0 built with the NE2000 NIC emulation support is vulnerable to an integer overflow, which could lead to buffer overflow issue. It could occur when receiving packets over the network. A user inside guest could use this flaw to crash the Qemu process resulting in DoS.
CVE-2018-13399
PUBLISHED: 2018-10-16
The Microsoft Windows Installer for Atlassian Fisheye and Crucible before version 4.6.1 allows local attackers to escalate privileges because of weak permissions on the installation directory.
CVE-2018-18381
PUBLISHED: 2018-10-16
Z-BlogPHP 1.5.2.1935 (Zero) has a stored XSS Vulnerability in zb_system/function/c_system_admin.php via the Content-Type header during the uploading of image attachments.
CVE-2018-18382
PUBLISHED: 2018-10-16
Advanced HRM 1.6 allows Remote Code Execution via PHP code in a .php file to the user/update-user-avatar URI, which can be accessed through an "Update Profile" "Change Picture" (aka user/edit-profile) action.
CVE-2018-18374
PUBLISHED: 2018-10-16
XSS exists in the MetInfo 6.1.2 admin/index.php page via the anyid parameter.