Feeds

Half Life hacker refused FBI sting bait

German cracker now faces US DDoS-for-hire charges

Using blade systems to cut costs and sharpen efficiencies

Games developer Valve worked with the FBI to set up a sting operation to capture a suspected hacker soon after source code for Half Life 2 leaked onto P2P networks in 2003.

The source code of the then-unreleased shoot-em-up game began circulating in September 2003. The breach that lead to the leak was traced back to an attack on Valve's network which involved compromising the email account of Valve's managing director, Gabe Newell. IRC transcripts discussing the hack (pdf) were forwarded to the FBI.

In February 2004 Valve received an email from a hacker who claimed credit for the breach (though not the source code leak), citing technical details to bolster his claim.

Valve maintained correspondence with the hacker, at the behest of the FBI, obtaining clues that suggested the hacker was a German called Axel Gembe, of Schonau, Germany, who'd previously applied for a job with Valve.

Following a phone interview, during which the hacker confirmed his identity as Gembe and explained how he'd hacked into Valve's network, a fake job interview in the US was arranged for the then 21-year-old, Wired reports. A similar trick worked in the case of a Kazakh hacker who was tricked into travelling to the US in 2001 only to find himself cuffed and subsequently convicted for attempting to blackmail New York mayor Michael Bloomberg. In both cases the FBI's Seattle office mounted the sting operation.

But Gembe resisted the fake job offer ruse and remained in his native Germany, where he was charged with the Valve hack and sentenced to probation.

Last month Gembe was indicted in the US over separate allegation that he created the original version of the Agobot botnet client, sharing it with US black-hats who used the software to establish a network of compromise PCs and mount denial of service attacks against a rival satellite TV retailer. Jay Echouafni, 41, skipped bail while awaiting trial on these charges, while his former employee, Paul Ashley, served two years behind bars after pleading guilty to involvement in the DDoS-for-hire scam.

It's unclear whether US authorities will seek to extradite Gembe. ®

The smart choice: opportunity from uncertainty

More from The Register

next story
Yorkshire cops fail to grasp principle behind BT Fon Wi-Fi network
'Prevent people that are passing by to hook up to your network', pleads plod
HIDDEN packet sniffer spy tech in MILLIONS of iPhones, iPads – expert
Don't panic though – Apple's backdoor is not wide open to all, guru tells us
NEW, SINISTER web tracking tech fingerprints your computer by making it draw
Have you been on YouPorn lately, perhaps? White House website?
LibreSSL RNG bug fix: What's all the forking fuss about, ask devs
Blow to bit-spitter 'tis but a flesh wound, claim team
Black Hat anti-Tor talk smashed by lawyers' wrecking ball
Unmasking hidden users is too hot for Carnegie-Mellon
Attackers raid SWISS BANKS with DNS and malware bombs
'Retefe' trojan uses clever spin on old attacks to grant total control of bank accounts
Manic malware Mayhem spreads through Linux, FreeBSD web servers
And how Google could cripple infection rate in a second
Don't look, Snowden: Security biz chases Tails with zero-day flaws alert
Exodus vows not to sell secrets of whistleblower's favorite OS
prev story

Whitepapers

Seven Steps to Software Security
Seven practical steps you can begin to take today to secure your applications and prevent the damages a successful cyber-attack can cause.
Consolidation: The Foundation for IT Business Transformation
In this whitepaper learn how effective consolidation of IT and business resources can enable multiple, meaningful business benefits.
Designing a Defense for Mobile Applications
Learn about the various considerations for defending mobile applications - from the application architecture itself to the myriad testing technologies.
Build a business case: developing custom apps
Learn how to maximize the value of custom applications by accelerating and simplifying their development.
Consolidation: the foundation for IT and business transformation
In this whitepaper learn how effective consolidation of IT and business resources can enable multiple, meaningful business benefits.