Fired Engineer at Fannie Mae Accused of Planting Malware Time Bomb

執筆者
Brian Prince
Brian Prince
Published: Jan 29, 2009
Updated: Feb 2, 2021
2 minute read
eWeek のコンテンツおよび製品のおすすめは、編集上の独立性を保っています。パートナーへのリンクをクリックすると、当社が報酬を得る場合があります。 詳細を見る

A fired Unix engineer stands accused of planting a malware time bomb at the mortgage firm Fannie Mae that had the potential to destroy countless computer files, federal officials said.

Rajendrasinh Makwana, 35, of Frederick, Md., was indicted on Jan. 27 for the attempted malware attack. Makwana was an employee for a firm called OmniTech, and worked at Fannie Mae’s facility in Urbana, Md., as a contract employee. After being terminated on Oct. 24, federal officials say Makwana retaliated by hiding malicious code on a Fannie Mae server and setting it to go active Jan. 31.

Five days later, another Unix engineer discovered the malicious script embedded within a pre-existing, legitimate script. According to a federal affidavit, the legitimate script runs every morning at 9 a.m. and validates that there are two storage area network paths running correctly and operationally through all Fannie Mae servers. The malicious script was at the bottom of the legitimate script and was separated by roughly one page of blank lines in an apparent attempt to hide the malicious script within a legitimate script.

Federal officials said Makwana was terminated because on or about Oct. 10 or Oct. 11 he created a computer script that changed the setting on the Unix servers without getting the nod of his supervisor. That script was not malicious.

“Despite Makwana’s termination, [his] computer access was not immediately terminated,” FBI agent Jessica A. Nye stated in the affidavit.

Nye goes on to explain that access to Fannie Mae’s computers for contractors’ employees was controlled by the company’s procurement department, which did not terminate Makwana’s computer access until late in the evening Oct. 24.

According to the affidavit, Fannie Mae’s nationwide internal computer network includes about 4,000 computer servers. Had the malicious script executed, the script would have propagated itself out to all 4,000 servers, thereby damaging all of Fannie Mae’s data. Nye estimated the damage would have cost millions and possibly shutdown operations at Fannie Mae for at least a week.

Sophos Senior Technology Consultant Graham Cluley noted in a blog post that the case underscores the damage disgruntled employees can potentially do to a network.

Advertisement

“Obviously this case is ongoing, and charges have not been proven against Makwana,” Cluley wrote. “But imagine what the impact could have been if an attack like this were not intercepted and had successfully struck a financial institution.”

*This story was updated with additional information.

Brian Prince

Brian Prince

Content Writer
eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

TechnologyAdvice が所有・運営しています。 © 2026 TechnologyAdvice. 無断転載を禁じます

広告主に関する開示:このサイトに掲載されている製品の一部は、TechnologyAdvice が報酬を受け取っている企業のものです。この報酬は、製品がこのサイトのどこにどのように表示されるか(表示される順序など)に影響する場合があります。TechnologyAdvice は、市場で入手可能なすべての企業やすべての種類の製品を掲載しているわけではありません。