Privacy Digest

News that can impact your privacy.
Login/Register
What is OpenID?
  • Log in using OpenID
  • Cancel OpenID login
  • Create new account
  • Request new password
Home Blogs MacRonin's blog
    • FAQ
    • Wishlists
    • Contact
    • Categories/RSS

Bookmark Us

Bookmark Privacy Digest 
Bookmark This Page 

Syndicate

Syndicate content
more

Advertisements

Tracking System
Tracking System
Private Detectives
Quality Security Services in California
Fleet Management
Hosting

Popular content

Last viewed:

  • Does High Court Nominee, Sonia Sotomayor, Adopt RIAA Stance ?
  • JP: Rakuten selling data on customers Admits passing on credit card, e-mail details
  • Outspoken Privacy Advocate Joins FTC
  • Anti-Secrecy Bill Gets Secret Hold
  • Behind Closed Doors
  • More Details on the Chinese Attack Against Google (Schneier)
  • Stop Badware Nostalgia: Press Coverage 2006

tags in Topics

Activists Alert Anonymity Companies Congress Copyright Court (US) Databases Data Mining Editorial EFF Entertainment Exploits Fourth Amendment Government Hmmm ID Infrastructure Law Enforcement Laws Politics Privacy Remember Reports Rights Security Spin Zone Surveillance Telecommunications Tracking
more tags

View blog authority
Congressional Research
Broadcast Flag

Hacker Launches Botnet Attack via P2P Software

Submitted by MacRonin on June 30, 2008 - 3:22am
  • Bot- Nets
  • Court (US)
  • Exploits
  • Hmmm
  • Law Enforcement
  • P2P
  • Privacy
  • Scams
  • Security

Hacker Launches Botnet Attack via P2P Software - Via Threat Level:

A 19-year-old hacker is agreeing to plead guilty to masterminding a botnet to obtain thousands of victims' personal data in an anonymous scheme a federal cybercrime official described Friday as the nation's first such attack in which peer-to-peer software was the "infection point."

The defendant, Jason Michael Milmont, launched the assault last year from his Cheyenne, Wyoming residence, and anonymously controlled as many as 15,000 computers at a time, said Wesley L. Hsu, chief of the Cyber and Intellectual Property Crimes Section for federal prosecutors in  Los Angeles. As part of the deal, in which a judge could hand him up to five years imprisonment, Milmont has agreed to pay $73,000 in restitution, the government said.

"It's the first time that we know of that peer-to-peer software was used as the infection point," Hsu said in an interview with Threat Level.

The malware infection became commonly known as the Nugache Worm, which embedded itself in the Windows OS.

According to the plea agreement, the worm was installed in various ways. The first incarnation of infections came from a website Milmont created that offered free installation of Limewire, the popular peer-to-peer file sharing program. He embedded that software downloads with his malware.

"Any time you download something from the internet, it's possible somebody has appended software to it that isn't supposed to be there," Hsu said.

Hsu said Milmont is expected soon to enter his plea to one count of unlawfully accessing computers in a Wyoming federal court. Milmont's attorney, Robert R. Rose, did not immediately respond for comment.

Another incarnation of the infection included using AOL instant messenger as the delivery point of his malware. The malware would spread itself via chats, with a message asking a buddy to view a photo on a website such as MySpace.com or Photobucket.com. The user would be taken to a spoofed website, and would become infected with the Nugache Worm, the plea deal said.

"All of the data stored on the compromised machines would be available to defendant, including, but not limited to, credit card information," according to the plea agreement.

The agreement also said that he took control of financial accounts of his victims.

"After obtaining this information from a victim's computer, defendant used his/her financial institution's online user name and password to access the account online," the agreement said. "Defendant then changed the victim's e-mail address to a similar e-mail that he controlled and the mailing address to an address in Cheyenne, Wyoming, typically an address that was listed for sale."

He would also change the telephone number on a victim's account to a number he controlled using Skype. "He paid for this service by using the credit card numbers harvested from his botnet," the plea agreement said.

Illustration: d70focus/Flickr


See Also:

  • Citibank Hack Blamed for Alleged ATM Crime Spree
  • Judge Weighing Ameritrade Hack Lawsuit Settlement -- UPDATE
  • Stakeouts, Lucky Breaks Snare Six More in Citibank ATM Heist
  • Judge Scuttles Ameritrade Hacking Settlement
  • Hacker Hijacks Website of Hacking Tool Maker
  • Citibank Replaces Some ATM Cards After Online PIN Heist -- Update
  • Comcast Hijackers Say They Warned the Company First
  • DDoS Attacker Pleads Guilty, Agrees to Two Years' Prison

(Read Original Article - Via Threat Level.)

Bookmark/Search this post with:
  • Twitter Twitter
  • Digg Digg
  • StumbleUpon StumbleUpon
  • Technorati Technorati
  • del.icio.us del.icio.us
  • Facebook Facebook
  • Furl Furl
  • LinkedIn LinkedIn
  • Yahoo Yahoo
  • MacRonin's blog
  • Add new comment

Recent blog posts

  • In Bid to Sway Sales, Cameras Track Shoppers
  • Unprecedented 25-Year Sentence Sought for TJX Hacker
  • EFF Appeals Dismissal of Warrantless Wiretapping Case
  • Viacom Makes Its Case Against Yesterday's YouTube
  • Obama supports Senators draft plan to rework U.S. immigration policy - Includes National Biometric ID card for all.
  • Domain Names Can't Defend Themselves
  • Hacker Disables More Than 100 Cars Remotely
  • Judges Approves $9.5 Million Facebook ‘Beacon’ Accord
  • Hooking Up The Big Brother Machine... And Fighting It
  • Court: State Can Dump Non-Sex Offenders Into Registry
more

Performancing Metrics

Compilation © Copyright 1997-2010 Paul Hardwick, with Web Hosting provided by MacRonin.com.