Close
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Subscribe
Logo
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Subscribe
    Home Applications
    • Applications
    • Cloud
    • Cybersecurity

    Facebook, Security Investigators Unmask Five Men Behind Koobface Crime Ring

    Written by

    Fahmida Y. Rashid
    Published January 18, 2012
    Share
    Facebook
    Twitter
    Linkedin

      eWEEK content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More.

      Security researchers have publicly unmasked five people they believe are behind Koobface, a botnet that spreads on social-networking sites and directs users to Websites selling fake antivirus and other scams.

      Facebook has been fighting the malware for the past year and successfully took one of the command-and-control servers controlling the botnet offline last March, the social-networking site proclaimed Jan. 17 on the Facebook Security blog. Facebook has been Koobface-free for more than nine months, according to the post.

      “Facebook Security was able to perform a technical takedown of this ‘Command & Control’ mothership,” the company wrote.

      Security companies, Facebook and the Federal Bureau of Investigation have been tracking the gang for at least two years, according to The New York Times. The alleged gang members have been identified as Anton Korotchenko, Alexander Koltyshev, Roman Koturbach, Syvatoslav Polinchuk and Stanislav Avdeiko. They are currently operating out of Russia and are active on various social-networking sites, including checking in at its offices on FourSquare and posting on Twitter.

      “We’ve had a picture of one of the guys in a scuba mask on our wall since 2008,” said Ryan McGeehan, manager of investigations and incident response at Facebook, told The Times.

      Facebook’s security team “worked non-stop” to detect the malware, remediate affected users, and identify the responsible parties, Facebook said. The company said it would be sharing the data with the larger security community and law enforcement. “We won’t declare victory” until the authors are brought to justice, the company said.

      The Koobface Working Group, a team of security researchers from across the industry, had been tracking the group, Graham Cluley, senior technology consultant for Sophos, wrote on the Naked Security blog. A paper had been planned for the Virus Bulletin security conference last year, but the FBI asked the authors to cancel the presentation in order not to interfere with the investigation.

      “Up until now, Dr??émer and Kollberg’s research has been a closely guarded secret, known only to a select few in the computer security community and shared with various law-enforcement agencies around the globe,” Cluley wrote. After independent researcher Dancho Danchev posted details on one of the members on his personal blog on Jan. 9, “the cat was well and truly out of the bag,” Cluley said.

      Researchers were able to take advantage of a mistake the Koobface criminals made in the way they configured their Apache Web server and Web statistics tool on the C&C server to identify IP addresses and domains used by the attackers, according to Cluley’s detailed writeup of the investigation. Researchers were able to also gain access to back-ups, which helped them find images, phone numbers and nicknames that may be used to identify the attackers.

      Various Web searches helped uncover email addresses and nicknames associated with the phone numbers and nicknames as well as accounts on other social-networking sites such as Flickr, Twitter, YouTube and LiveJournal, according to Cluley. While nicknames aren’t as good as first and last names, they are usually “life-long” once picked, especially in the criminal underground where no one is using their real identity, Cluley said. “There is a need to distinguish between those that offer reliable cyber-crime services and those who don’t,” Cluley said.

      Cluley said the evidence has been turned over to law-enforcement agencies, but that none of the individuals the team had identified have been charged or found guilty of any crimes.

      The criminals allegedly made an estimated $2 million between 2009 and 2010 using Koobface’s network of infected computers scattered around the world to infect computers and redirecting users to malicious Websites, according to a 2010 report from the Information Warfare Monitor initiative. The money came from referral fees these sites paid for each visitor who came to their site as well as from users who paid to buy fake antivirus software. Koobface is known for targeting users on various social networks, including MySpace, hi5 and Facebook.

      Fahmida Y. Rashid
      Fahmida Y. Rashid

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      MOST POPULAR ARTICLES

      Artificial Intelligence

      9 Best AI 3D Generators You Need...

      Sam Rinko - June 25, 2024 0
      AI 3D Generators are powerful tools for many different industries. Discover the best AI 3D Generators, and learn which is best for your specific use case.
      Read more
      Cloud

      RingCentral Expands Its Collaboration Platform

      Zeus Kerravala - November 22, 2023 0
      RingCentral adds AI-enabled contact center and hybrid event products to its suite of collaboration services.
      Read more
      Artificial Intelligence

      8 Best AI Data Analytics Software &...

      Aminu Abdullahi - January 18, 2024 0
      Learn the top AI data analytics software to use. Compare AI data analytics solutions & features to make the best choice for your business.
      Read more
      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Video

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2024 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.