Malware Distributor & Bot Network Master Sentenced To 4 Years


It seems to the feds are really cracking down on cybercrime recently, with a special kind of attention paid to botnets and their handlers. The sentences are getting stiffer too, this time with 4 years in prison for running a botnet and data theft.

I hope they keep it up, botnets are the scourge of the Internet and people should feel safe about their bank accounts and Paypal money. The Internet is becoming a bad neighborhood with people looking over their shoulders all the time.

A Los Angeles man was sentenced late Wednesday in federal court to four years in prison after pleading guilty last year to infecting as many as 250,000 computers and stealing thousands of peoples’ identities and hijacking their bank accounts.

The Los Angeles authorities said John Schiefer, 27, was the nation’s first defendant to plead guilty to wiretapping charges (.pdf) in connection to using botnets.

Schiefer, who went by the online handle “acidstorm,” faced as many as 60 years in prison and acknowledged using a botnet to remotely control computers across the United States. Once in control of the computers, the authorities said, (.pdf) his spybot malware allowed him to intercept computer communications. He mined usernames and passwords on accounts such as PayPal and made purchases totaling thousands of dollars without consent.

The first one to plead guilty eh? I guess the others will fall later with charges that can rack up some serious prison time with back to back sentences. I guess pleading guilty saved him from the possible 60 year sentence.

It must be hard to track the exact amount he conned from people and stole from Paypal accounts as there’s no real way to audit it. But as the law goes estimates are made by extrapolating whatever hard data they do have.

The authorities said he worked by day as an information security consultant with 3G Communications. After his guilty plea, Schiefer was hired at Mahalo, the so-called “human powered search engine.” Its founder, Jason Calacanis wrote that the company failed to realize that the Los Angeles company had hired a man who had pleaded guilty to being a hacker.

The defendant was among eight individuals indicted or successfully prosecuted in a crack down on black hat hackers who use armies of zombie computers to commit financial fraud, attack web sites with floods of traffic and send spam. The crimes at issue involved more than $20 million in losses, according to the FBI.

The FBI dubbed the eight cases “Operation Bot Roast II” — the second round of its investigations against botnets, one of the most dangerous threats online today. The first FBI crackdown on botnets was announced in June, 2007.

$20 million in losses seems a fairly generous estimate, but then I guess it makes for better headlines right? I wonder when “Operating Bot Roast III” will begin?

It won’t be too long I imagine, I hope they crack down on the botnets sending out spam – those are the ones that REALLY irk me.

Source: Wired (Thanks Navin)

Posted in: Legal Issues, Malware

, , , , , ,


Latest Posts:


GKE Auditor - Detect Google Kubernetes Engine Misconfigurations GKE Auditor – Detect Google Kubernetes Engine Misconfigurations
GKE Auditor is a Java-based tool to detect Google Kubernetes Engine misconfigurations, it aims to help security & dev teams streamline the configuration process
zANTI - Android Wireless Hacking Tool Free Download zANTI – Android Wireless Hacking Tool Free Download
zANTI is an Android Wireless Hacking Tool that functions as a mobile penetration testing toolkit that lets you assess the risk level of a network using mobile.
HELK - Open Source Threat Hunting Platform HELK – Open Source Threat Hunting Platform
The Hunting ELK or simply the HELK is an Open-Source Threat Hunting Platform with advanced analytics capabilities such as SQL declarative language, graphing etc
trape - OSINT Analysis Tool For People Tracking Trape – OSINT Analysis Tool For People Tracking
Trape is an OSINT analysis tool, which allows people to track and execute intelligent social engineering attacks in real-time.
Fuzzilli - JavaScript Engine Fuzzing Library Fuzzilli – JavaScript Engine Fuzzing Library
Fuzzilii is a JavaScript engine fuzzing library, it's a coverage-guided fuzzer for dynamic language interpreters based on a custom intermediate language.
OWASP APICheck - HTTP API DevSecOps Toolset OWASP APICheck – HTTP API DevSecOps Toolset
APICheck is an HTTP API DevSecOps toolset, it integrates existing tools, creates execution chains easily and is designed for integration with 3rd parties.


3 Responses to Malware Distributor & Bot Network Master Sentenced To 4 Years

  1. navin March 11, 2009 at 7:06 pm #

    cheers!! :)

  2. defcon March 16, 2009 at 2:14 pm #

    this dude should be made to clean up those computers and get community service, there is too many ppl in jail anyways and they come out more fucked up then when they come in

  3. John May 21, 2009 at 8:23 pm #

    I agree with defcon…. nerds