STUDENT CONVICTED FOR USING UNIVERSITY COMPUTER NETWORK AS BOTNET ZOMBIES
Steven M. Dettelbach, United States Attorney for the Northern District of Ohio, announced Mitchell L. Frost, age 23, of Bellevue, Ohio, appeared before U.S. Magistrate Judge Nancy A. Vecchiarelli and pleaded guilty to a two-count Information filed on May 14,2010, which charged Frost with causing damage to a protected computer system and possessing 15 or more unauthorized access devices.
According to court documents, Frost admitted that between August 2006, and March 2007, while enrolled as a student at the University of Akron, he used the University’s computer network to access IRC channels on the Internet to control other computers and computer networks via computers intentionally infected and taken over, known as “BotNet” zombies, which were located throughout the United States and in other countries.Frost also admitted gaining access to other computers and computer networks by various means, including scanning the Internet searching for computer networks which were vulnerable to attack or unauthorized intrusion, gaining unauthorized access to and control over such computers, and fraudulently obtaining user names and passwords for users on such systems.
Frost admitted using the compromised computers to spread malicious computer codes,
commands and information to even more computers, all for the purpose of harvesting and obtaining information and data from the compromised computer networks,including user names,passwords, credit card numbers, and CVV security codes, and for the purpose of launching Distributed Denial of Service (DDoS) attacks on computer systems and Internet websites.
Frost admitted that between August 2006 and March 2007, Frost initiated DDoS attacks
on numerous computers connected to the Internet hosting various websites, including
www.joinrudy2008.com, www.billoreilly.com, and www.anncoulter.com, among others,
temporarily interrupting operation of the websites, which required the site owners to intervene and repair their computer systems.
Frost also admitted initiating denial of service attacks against the University of Akron computer server on or about March 14, 2007, which caused the entire university of Akron computer network to be knocked off-line for approximately 8 ½ hours, preventing all students, faculty and staff members from accessing the network. This denial of service attack required the University of Akron to employ diagnostic and remedial measures to restore computer service causing losses in excess of $10,000.
Frost will be sentenced on August 5, 2010, by U.S. District Judge Lesley Wells.His sentence will be determined by the Court after review of factors unique to this case, including his prior criminal record, if any, his role in the offense and the characteristics of the violation. In all cases the sentence will not exceed the statutory maximum and in most cases it will be less than the maximum.
ALLEGED $100M SCAREWARE SELLERS FACING CHARGES
Three men are facing federal fraud charges for allegedly raking in more than US$100 million while running an illegal "scareware" business that tricked victims into installing bogus software.
Two of the men, Bjorn Sundin and Shaileshkumar Jain, operated an antivirus company called Innovative Marketing, which sold products such as WinFixer, Antivirus 2008, Malware Alarm and VirusRemover 2008. The third man charged, James Reno, ran Byte Hosting Internet Services, the company that operated Innovative Marketing's call centers.
The company's products generated so many consumer complaints that the FTC brought a civil action against Innovative Marketing and Byte Hosting in 2008, effectively putting them out of business.
A grand jury in Chicago handed down the criminal charges, meaning the three men now face jail time if convicted.
Reno is expected to turn himself in for arraignment, the U.S. Department of Justice said in a press release Thursday. Authorities believe that Jain and Sundin are living in Ukraine and Sweden, respectively.
In a September 2009 e-mail to the IDG News Service, Reno said he was a young and naïve businessmen who was taken advantage of by Innovative Marketing. "I made some mistakes, of course," he said, "however they kept us in the dark on a lot of their operation."
According to prosecutors, Innovative Marketing set up fictitious advertising agencies that would buy online inventory from media companies, pretending to represent legitimate companies. They then pushed out ads with hidden computer code that generated scary-looking pop-up messages, designed to look like operating system errors or antivirus scans.
The end result was always the same. To get rid of the pop-up warnings, users would have to buy Innovative Marketing's worthless software, prosecutors allege.
Byte Hosting's call centers were then used to "deflect complaints from victims who purchased Innovative Marketing software products," the Department of Justice (DoJ) said.
The scheme convinced victims in more than 60 countries to buy more than 1 million bogus programs, the DoJ said.

No comments:
Post a Comment