Welcome Guest. | Log In | Register | Membership Benefits
  • |   Email this page E-mail
  • |  Print Print
  • |   Bookmark and Share

Microsoft Names Alleged Botnet Operator Behind Kelihos

Russian suspect worked for antivirus and software development firms in Russia

Jan 24, 2012 | 03:59 PM | 

By Kelly Jackson Higgins
Dark Reading
Microsoft is continuing its legal tear against botnets: It has now named the botnet operator of the Kelihos botnet that it helped take down last fall.

The alleged perpetrator, Andrey N. Sabelnikov, a Russian engineer, has been added to Microsoft’s legal suit filed in U.S. District Court in September in relation to the botnet. The company, which worked with Kaspersky Lab and Kyrus to take down the spamming botnet, says the initial claim named co-defendants Dominique Alexander Piatti and dotFREE Group SRO in Microsoft’s civil lawsuit cooperated and provided information that led to the latest legal action against Sabelnikov as part of a settlement in October.

“In today’s complaint, Microsoft presented evidence to the court that Mr. Sabelnikov wrote the code for and either created, or participated in creating, the Kelihos malware. Further, the complaint alleges that he used the malware to control, operate, maintain and grow the Kelihos botnet. These allegations are based on evidence Microsoft investigators uncovered while analyzing the Kelihos malware,” said Richard Domingues Boscovich, senior attorney for Microsoft’s Digital Crimes Unit. “Microsoft also alleges that Mr. Sabelnikov registered more than 3,700 ‘cz.cc’ subdomains from Mr. Piatti and dotFREE Group SRO, and misused those subdomains to operate and control the Kelihos botnet.”

Microsoft says Sabelnikov lives in St. Petersburg, Russia, and is a contractor for a software development and consulting firm who once worked as a software engineer and project manager at a firewall and antivirus firm. According to KrebsOnSecurity, that firm was Agnitum.

The Kelihos botnet was a relatively small one of some 41,000 infected bots, but was used to spam, steal financial information, and wage distributed denial-of-service attacks; it was capable of sending 3.8 billion spam e-mails per day. It’s now inactive, but Microsoft says there are still thousands of computers infected with its bot malware.

Meanwhile, Microsoft’s initial lawsuit alleged that Piatti, dotFREE Group SRO, and John Does 1-22 owned and used the “cz.cc” domain to register other subdomains used in Kelihos.

“Our investigation showed that while some of the defendants’ subdomains may have been legitimate, many were being used for questionable purposes with links to a variety of disreputable online activities. On Oct. 26, we successfully settled with defendants Dominique Alexander Piatti and dotFREE Group, allowing us to dismiss the case against them. Today, thanks to their cooperation and new evidence, we have named a new defendant to the civil lawsuit we believe to be the operator of the Kelihos botnet,” Boscovich said.

Have a comment on this story? Please click "Add Your Comment" below. If you'd like to contact Dark Reading's editors directly, send us a message.



Currently we allow the following HTML tags in comments:

Single tags

These tags can be used alone and don't need an ending tag.

<br> Defines a single line break

<hr> Defines a horizontal line

Matching tags

These require an ending tag - e.g. <i>italic text</i>

<a> Defines an anchor

<b> Defines bold text

<big> Defines big text

<blockquote> Defines a long quotation

<caption> Defines a table caption

<cite> Defines a citation

<code> Defines computer code text

<em> Defines emphasized text

<fieldset> Defines a border around elements in a form

<h1> This is heading 1

<h2> This is heading 2

<h3> This is heading 3

<h4> This is heading 4

<h5> This is heading 5

<h6> This is heading 6

<i> Defines italic text

<p> Defines a paragraph

<pre> Defines preformatted text

<q> Defines a short quotation

<samp> Defines sample computer code text

<small> Defines small text

<span> Defines a section in a document

<s> Defines strikethrough text

<strike> Defines strikethrough text

<strong> Defines strong text

<sub> Defines subscripted text

<sup> Defines superscripted text

<u> Defines underlined text

Dark Reading encourages readers to engage in spirited, healthy debate, including taking us to task. However, Dark Reading moderates all comments posted to our site, and reserves the right to modify or remove any content that it determines to be derogatory, offensive, inflammatory, vulgar, irrelevant/off-topic, racist or obvious marketing/SPAM. Dark Reading further reserves the right to disable the profile of any commenter participating in said activities.

Disqus Tips To upload an avatar photo, first complete your Disqus profile. | View the list of supported HTML tags you can use to style comments. | Please read our commenting policy.
Subscribe to RSS



Insider Threat Reports

report How to Prevent an Illicit Data Dump
There are no silver bullets when it comes to protecting company and customer data from loss or theft, but there are technological and procedural systems that will go a long way toward preventing a WikiLeaks-like data dump. Here are some tips and tricks to help protect your organization's most sensitive information.

report Email and Data Loss
Email encryption, rights management, email gateways, and full-on data loss prevention systems can keep corporate data secure. Here's a look at the pros and cons of each, to help you determine what?s best for your business.

report An Insider Threat Reality check
Heightened concern that users could inadvertently expose or leak -- or purposely steal -- an organization's sensitive data has spurred debate over the proper technology and training to protect the crown jewels. In this special retrospective of recent news coverage, Dark Reading takes a look at how organizations are handling the threat -- and what users are really up to.

Other reports from the Insider Threat Tech Center: