Attacks/Breaches

1/10/2018
12:00 AM
Dark Reading
Dark Reading
Products and Releases
50%
50%

Ohio Programmer Indicted for Infecting Thousands of Computers

Malicious software installed that gained access to victims' communications and personal information.

An Ohio man was charged in a 16-count indictment today for allegedly creating and installing malware on thousands of computers for more than 13 years in order to watch, listen to, and obtain personal data from unknowing victims, as well as produce child pornography.

Acting Assistant Attorney General John P. Cronan of the Justice Department’s Criminal Division, First Assistant U.S. Attorney David A. Sierleja for the Northern District of Ohio, and Special Agent in Charge Stephen D. Anthony of the FBI’s Cleveland Field Office made the announcement.

Phillip R. Durachinsky, 28, of North Royalton, Ohio, was charged with Computer Fraud and Abuse Act violations, Wiretap Act violations, production of child pornography, and aggravated identity theft.  

According to the indictment, Durachinsky is alleged from 2003 through Jan. 20, 2017, to have orchestrated a scheme to access thousands of protected computers owned by individuals, companies, schools, a police department, and the government, including one owned by a subsidiary of the U.S. Department of Energy.  He is alleged to have developed computer malware later named “Fruitfly” that he installed on computers and that enabled him to control each computer by accessing stored data, uploading files, taking and downloading screenshots, logging a user’s keystrokes, and turning on the camera and microphone to surreptitiously record images and audio. 

As alleged in the indictment, Durachinsky used the malware to steal the personal data of victims, including their logon credentials, tax records, medical records, photographs, banking records, Internet searches, and potentially embarrassing communications.  According to the indictment, Durachinsky used stolen logon credentials to access and download information from third-party websites.

Durachinsky is further alleged to have watched and listened to victims without their knowledge or permission and intercepted oral communications taking place in the room where the infected computer was located.  In some cases, the malware alerted Durachinsky if a user typed words associated with pornography.  According to the indictment, Durachinsky saved millions of images and often kept detailed notes of what he saw. 

“For more than 13 years, Phillip Durachinsky allegedly infected with malware the computers of thousands of Americans and stole their most personal data and communications,” said Acting Assistant Attorney General Cronan. “This case is an example of the Justice Department’s continued efforts to hold accountable cybercriminals who invade the privacy of others and exploit technology for their own ends.”

“This defendant is alleged to have spent more than a decade spying on people across the country and accessing their personal information,” said First Assistant U.S. Attorney Sierleja.

“Durachinsky is alleged to have utilized his sophisticated cyber skills with ill intent, compromising numerous systems and individual computers,” said Special Agent in Charge Anthony. “The FBI would like to commend the compromised entities that brought this to the attention of law enforcement authorities.  It is this kind of collaboration that has enabled authorities to bring this cyber hacker to justice.” 

The charges in the indictment are merely allegations, and the defendant is presumed innocent unless proven guilty beyond a reasonable doubt in a court of law.

The case was investigated by the FBI. This case is being prosecuted by Senior Counsel Brian L. Levine of the Criminal Division’s Computer Crime and Intellectual Property Section and Assistant U.S. Attorneys Daniel J. Riedl, Michelle M. Baeppler and Om M. Kakani of the Northern District of Ohio.

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Election Websites, Back-End Systems Most at Risk of Cyberattack in Midterms
Kelly Jackson Higgins, Executive Editor at Dark Reading,  8/14/2018
Intel Reveals New Spectre-Like Vulnerability
Curtis Franklin Jr., Senior Editor at Dark Reading,  8/15/2018
The Data Security Landscape Is Shifting: Is Your Company Prepared?
Francis Dinha, CEO & Co-Founder of OpenVPN,  8/13/2018
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-13435
PUBLISHED: 2018-08-16
** DISPUTED ** An issue was discovered in the LINE jp.naver.line application 8.8.0 for iOS. The Passcode feature allows authentication bypass via runtime manipulation that forces a certain method to disable passcode authentication. NOTE: the vendor indicates that this is not an attack of interest w...
CVE-2018-13446
PUBLISHED: 2018-08-16
** DISPUTED ** An issue was discovered in the LINE jp.naver.line application 8.8.1 for Android. The Passcode feature allows authentication bypass via runtime manipulation that forces a certain method's return value to true. In other words, an attacker could authenticate with an arbitrary passcode. ...
CVE-2018-14567
PUBLISHED: 2018-08-16
libxml2 2.9.8, if --with-lzma is used, allows remote attackers to cause a denial of service (infinite loop) via a crafted XML file that triggers LZMA_MEMLIMIT_ERROR, as demonstrated by xmllint, a different vulnerability than CVE-2015-8035 and CVE-2018-9251.
CVE-2018-15122
PUBLISHED: 2018-08-16
An issue found in Progress Telerik JustAssembly through 2018.1.323.2 and JustDecompile through 2018.2.605.0 makes it possible to execute code by decompiling a compiled .NET object (such as DLL or EXE) with an embedded resource file by clicking on the resource.
CVE-2018-11509
PUBLISHED: 2018-08-16
ASUSTOR ADM 3.1.0.RFQ3 uses the same default root:admin username and password as it does for the NAS itself for applications that are installed from the online repository. This may allow an attacker to login and upload a webshell.