Original URL: http://www.theregister.co.uk/2005/11/04/suspected_bot_master_busted/
In what prosecutors have labeled the first case of its kind in the nation, a federal grand jury charged Jeanson James Ancheta with 17 counts of conspiracy and computer crime stemming from his alleged profitable use of bot nets. Over nearly a year, Ancheta allegedly used automated software to infect Windows systems, advertised and sold access to the compromised PCs, and used the software to perpetrate click fraud, garnering tens of thousands of dollars in affiliate fees, according to a 58-page indictment released on Thursday.
"This is the first case to charge someone for using bots for generating profits," said James Aquilina, Assistant U.S. Attorney for the Central District of California and the prosecutor on the case."On the one hand, he is selling bots to other people so that they can (perform) denial-of-service attacks and spam to make money. And on the other hand, he is using bots to make affiliate income."
The arrest comes as authorities are turning up the heat on bot herders, the name for people that control millions of compromised computers worldwide. In October, Dutch authorities arrested three men in the Netherlands (http://www.securityfocus.com/news/11344) who allegedly controlled a network of more than 1.5 million compromised computers (http://www.securityfocus.com/brief/19). In August, the FBI and Microsoft helped authorities in Turkey and Morocco track down two men suspected of creating and spreading the Zotob worm (http://www.securityfocus.com/news/11297)--a program that consisted of bot software modified to exploit a flaw in Windows 2000.
The arrests have driven some developers of bot software underground (http://www.securityfocus.com/news/11311), but many security researchers are doubtful (http://www.securityfocus.com/news/11344) that convictions in the cases will significantly reduce the threat. One reason: Bot software increasingly forms the core of the newest worms (http://www.securityfocus.com/news/11285), such as Zotob, because the programs only need the exploit for the latest vulnerability to start spreading among computer systems.
However, previous cases have focused on other aspects of the crimes, not the actual underground trade in compromised computers, Aquilina said.
The latest case stems from two separate investigations into bot software. During the summer 2004, investigators started looking into an advertisement posted in the Internet Relay Chat (IRC) channel #botz4sale that linked to a price list for buying compromised computers. And in late 2004 and early 2005, computers at the Defense Information Security Agency (DISA) and the Weapons Division of the U.S. Naval Air Warfare Center in China Lake, California, became infected with bot software.
“ This is the first case to charge someone for using bots for generating profits. On the one hand, he is selling bots to other people so that they can (perform) denial-of-service attacks and spam to make money. And on the other hand, he is using bots to make affiliate income. ”
James Aquilina, Assistant U.S. Attorney, Central District of California
Prosecutors soon determined that a single person was behind both events and quickly focused on Ancheta. In raids executed in December 2004 and in May 2005 on Ancheta's Downey, California residence, prosecutors seized three computers and discovered chat logs that described numerous sales of small numbers of bots and the success of an alleged collaboration with a Florida man to garner affiliate fees through click fraud.
According to the indictment, Ancheta created a customized version of a publicly available bot software package known as "rxbot". He allegedly used the software to infect nearly 400,000 systems. While he made nearly $3,000 selling hundreds or thousands of compromised machines to would-be bot herders, the vast majority of his profit was from installing adware on the compromised systems and using them to generate pay-for-click affiliate fees, according to the indictment.
Ancheta allegedly received checks from GammaCash, an affiliate program run by Gamma Entertainment, and from LOUDcash, a program run by CDT, which was acquired by advertising firm 180solutions. Renamed Zango in April, 180solutions' CDT subsidiary had already canceled Ancheta's account, according to company spokesman Sean Sundwall.
The Bellevue, Washington-based company, whose past advertising tactics gained the ire of many Internet users, has aggressively pursued click fraudsters, Sundwall said.
On Thursday, the company announced that it had cooperated with the FBI in a separate investigation against the three Dutch men arrested in October on charges of controlling 1.5 million compromised PCs. While the company had not worked with the FBI and Department of Justice on the latest case, executives extended the offer to help, he said.
The company has also created a more secure version of its advertising software that should prevent the program from being installed without a computer users' knowledge, Sundwall said. The software will be released before the end of the year.
"We are aiming to remove any financial incentive (for fraudsters) to do this sort of thing," he said.
Ancheta appeared briefly in court on Thursday and is being held pending post-indictment arraignment on Monday and a bail hearing set for Tuesday, Assistant U.S. Attorney Aquilina said.
If found guilty of all charges, Ancheta could be sentenced to a maximum of 50 years in prison.
Copyright © 2005, SecurityFocus (http://www.securityfocus.com/)
I Was A Teenage Bot Master (8 May 2008)
http://www.theregister.co.uk/2008/05/08/downfall_of_botnet_master_sobe_owns/
Québec cops bust massive botnet ring (21 February 2008)
http://www.theregister.co.uk/2008/02/21/canada_botnet_bust/
Thievin' teen bot herder admits to infecting military computers (12 February 2008)
http://www.theregister.co.uk/2008/02/12/bot_herder_cops_plea/
Germany nets ten phishing suspects (14 September 2007)
http://www.theregister.co.uk/2007/09/14/germany_phishing_arrests/
Judge pours generous portion of cold water on Zango (6 June 2007)
http://www.theregister.co.uk/2007/06/06/zango_request_denied/
So who sent you that spam? HP or Oracle? (28 March 2007)
http://www.theregister.co.uk/2007/03/28/bots_in_perimeter/
Man pleads guilty to spreading Trojan via IRC (22 February 2007)
http://www.theregister.co.uk/2007/02/22/trojan_plea/
Botnet 'pandemic' threatens to strangle the net (26 January 2007)
http://www.theregister.co.uk/2007/01/26/botnet_threat/
How a virus crashed Homeland Security (3 November 2006)
http://www.theregister.co.uk/2006/11/03/zotob_dhs_outbreak/
FBI-led probe nets phishing gang (3 November 2006)
http://www.theregister.co.uk/2006/11/03/operation_cardkeeper_phishing_arrests/
Zotob perp jailed (13 September 2006)
http://www.theregister.co.uk/2006/09/13/zotob_perps_jailed/
What are we going to do about click fraud? Form a committee! (3 August 2006)
http://www.theregister.co.uk/2006/08/03/iab_click_fraud_committee/
Medic database spam suspect collared (26 July 2006)
http://www.theregister.co.uk/2006/07/26/medic_spam_charges/
Botnet master jailed for five years (9 May 2006)
http://www.theregister.co.uk/2006/05/09/botnet_master_ancheta_jailed/
China poised to pinch US spam crown (21 April 2006)
http://www.theregister.co.uk/2006/04/21/spam_relay_hotlist/
Zombie PCs menace mankind (7 March 2006)
http://www.theregister.co.uk/2006/03/07/symantec_net_threat_report_2h2005/
Botnet control fears over IP telephony (26 January 2006)
http://www.theregister.co.uk/2006/01/26/voip_botnet_control_fears/
Malware potency increases as numbers drop (25 January 2006)
http://www.theregister.co.uk/2006/01/25/ibm_cybercrime_report_2005/
Bot herder pleads guilty to 'zombie' sales (24 January 2006)
http://www.theregister.co.uk/2006/01/24/zombie_herder_pleads/
CAN-SPAM working - FTC (21 December 2005)
http://www.theregister.co.uk/2005/12/21/can-spam/
Click fraud suit changes hand (9 December 2005)
http://www.theregister.co.uk/2005/12/09/outlaw_click_case/
Zone Labs sued over spyware classification (2 December 2005)
http://www.theregister.co.uk/2005/12/02/180solutions_sues_zone_labs/
Pump-and-dump spam domains go silent after botnet closure (14 November 2005)
http://www.theregister.co.uk/2005/11/14/spam_domain_dump/
Virus writers craft PnP botnet client (24 October 2005)
http://www.theregister.co.uk/2005/10/24/pnp_botnet_encore/
Arrests 'unlikely' to impact botnet threat (13 October 2005)
http://www.theregister.co.uk/2005/10/13/rise_of_the_botnets/
Victims coughing up to online extortionists (6 October 2005)
http://www.theregister.co.uk/2005/10/06/ibm_botnet_vb/
Bot herder websites in internet take-down (13 September 2005)
http://www.theregister.co.uk/2005/09/13/bot_herder_takedown/
Zotob arrests throws open trade in compromised PCs (30 August 2005)
http://www.theregister.co.uk/2005/08/30/zotob_arrests_follow-up/
Sophos service searches for zombie PCs (18 July 2005)
http://www.theregister.co.uk/2005/07/18/sophos_zombiealert/
AOL rebuts zombie network slur (16 June 2005)
http://www.theregister.co.uk/2005/06/16/aol_rebuffs_prolexic_zombie_report/
ISPs urged to throttle spam zombies (24 May 2005)
http://www.theregister.co.uk/2005/05/24/operation_spam_zombie/
© Copyright 2008