Bredolab Botnet Suspect Busted in Takedown

Écrit par
Brian Prince
Brian Prince
Published: Oct 26, 2010
Updated: Feb 2, 2021
2 minute read
eWeek Le contenu et les recommandations de produits sont indépendants de la rédaction. Nous pouvons gagner de l'argent lorsque vous cliquez sur des liens vers nos partenaires. En savoir plus

Law enforcement officials in Armenia arrested a man Oct. 26 accused of masterminding a massive botnet operation.

According to reports, the 27-year-old suspect was arrested on suspicions of running the Bredolab botnet. Bredolab is a popular Trojan downloader used by cyber-criminals to infect Windows machines via drive-by downloads and spam e-mails.

In a takedown operation, the Dutch National Crime Squad’s High Tech Crime Team (THTC) worked in collaboration with a Dutch Web hosting company, the Dutch Forensic Institute, Internet security company Fox-IT and the Dutch Computer Emergency Response Team (CERT) to seize control of 143 malicious servers tied to the botnet.

According to the THTC, the botnet network used servers in the Netherlands from a reseller of LeaseWeb, the largest hosting provider in the country. LeaseWeb fully cooperated with the takedown effort, authorities said. During the investigation, the THTC found the network was capable of infecting 3 million computers a month. At the end of 2009, it was estimated that 3.6 billion e-mails with Bredolab payloads were being spammed out daily, the THTC reported.

During the takedown, the suspect made several attempts to take back control of the botnet, according to the Dutch authorities. When this failed, police say he launched a massive distributed denial-of-service attack on LeaseWeb with 220,000 infected computers. This attack was stopped after three computer servers he was using in Paris were disconnected from the Internet, authorities said.

A Symantec advisory on Bredolab noted many of the e-mails carrying the Trojan have the following themes: Western Union free money, UPS delivery failure and Facebook password changes.

“The suspect is believed by the computer crime authorities to have rented access to infected bot computers to other cybercriminals,” blogged Graham Cluley, senior technology consultant at Sophos. “No doubt the police will be interested to find out if the man has any information about others who may have exploited the botnet, and more arrests may follow.”

The 27-year-old was arrested at the international airport in Yerevan, authorities said.

eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

Propriété de TechnologyAdvice. © 2026 TechnologyAdvice. Tous droits réservés

Divulgation publicitaire : Certains des produits qui apparaissent sur ce site proviennent d'entreprises dont TechnologyAdvice reçoit une compensation. Cette compensation peut influencer la façon dont les produits apparaissent sur ce site, notamment l'ordre dans lequel ils apparaissent. TechnologyAdvice n'inclut pas toutes les entreprises ou tous les types de produits disponibles sur le marché.