Malware Distributor & Bot Network Master Sentenced To 4 Years


It seems to the feds are really cracking down on cybercrime recently, with a special kind of attention paid to botnets and their handlers. The sentences are getting stiffer too, this time with 4 years in prison for running a botnet and data theft.

I hope they keep it up, botnets are the scourge of the Internet and people should feel safe about their bank accounts and Paypal money. The Internet is becoming a bad neighborhood with people looking over their shoulders all the time.

A Los Angeles man was sentenced late Wednesday in federal court to four years in prison after pleading guilty last year to infecting as many as 250,000 computers and stealing thousands of peoples’ identities and hijacking their bank accounts.

The Los Angeles authorities said John Schiefer, 27, was the nation’s first defendant to plead guilty to wiretapping charges (.pdf) in connection to using botnets.

Schiefer, who went by the online handle “acidstorm,” faced as many as 60 years in prison and acknowledged using a botnet to remotely control computers across the United States. Once in control of the computers, the authorities said, (.pdf) his spybot malware allowed him to intercept computer communications. He mined usernames and passwords on accounts such as PayPal and made purchases totaling thousands of dollars without consent.

The first one to plead guilty eh? I guess the others will fall later with charges that can rack up some serious prison time with back to back sentences. I guess pleading guilty saved him from the possible 60 year sentence.

It must be hard to track the exact amount he conned from people and stole from Paypal accounts as there’s no real way to audit it. But as the law goes estimates are made by extrapolating whatever hard data they do have.

The authorities said he worked by day as an information security consultant with 3G Communications. After his guilty plea, Schiefer was hired at Mahalo, the so-called “human powered search engine.” Its founder, Jason Calacanis wrote that the company failed to realize that the Los Angeles company had hired a man who had pleaded guilty to being a hacker.

The defendant was among eight individuals indicted or successfully prosecuted in a crack down on black hat hackers who use armies of zombie computers to commit financial fraud, attack web sites with floods of traffic and send spam. The crimes at issue involved more than $20 million in losses, according to the FBI.

The FBI dubbed the eight cases “Operation Bot Roast II” — the second round of its investigations against botnets, one of the most dangerous threats online today. The first FBI crackdown on botnets was announced in June, 2007.

$20 million in losses seems a fairly generous estimate, but then I guess it makes for better headlines right? I wonder when “Operating Bot Roast III” will begin?

It won’t be too long I imagine, I hope they crack down on the botnets sending out spam – those are the ones that REALLY irk me.

Source: Wired (Thanks Navin)

Posted in: Legal Issues, Malware

, , , , , ,


Latest Posts:


Fuzzilli - JavaScript Engine Fuzzing Library Fuzzilli – JavaScript Engine Fuzzing Library
Fuzzilii is a JavaScript engine fuzzing library, it's a coverage-guided fuzzer for dynamic language interpreters based on a custom intermediate language.
OWASP APICheck - HTTP API DevSecOps Toolset OWASP APICheck – HTTP API DevSecOps Toolset
APICheck is an HTTP API DevSecOps toolset, it integrates existing tools, creates execution chains easily and is designed for integration with 3rd parties.
trident - Automated Password Spraying Tool trident – Automated Password Spraying Tool
The Trident project is an automated password spraying tool developed to be deployed on multiple cloud providers and provides advanced options around scheduling
tko-subs - Detect & Takeover Subdomains With Dead DNS Records tko-subs – Detect & Takeover Subdomains With Dead DNS Records
tko-subs is a tool that helps you to detect & takeover subdomains with dead DNS records, this could be dangling CNAMEs point to hosting services and more.
Arcane - Tool To Backdoor iOS Packages (iPhone ARM) Arcane – Tool To Backdoor iOS Packages (iPhone ARM)
Arcane is a simple script tool to backdoor iOS packages (iPhone ARM) and create the necessary resources for APT repositories.
SharpHose - Asynchronous Password Spraying Tool SharpHose – Asynchronous Password Spraying Tool
SharpHose is an asynchronous password spraying tool in C# for Windows environments that takes into consideration fine-grained password policies and can be run over Cobalt Strike's execute-assembly.


3 Responses to Malware Distributor & Bot Network Master Sentenced To 4 Years

  1. navin March 11, 2009 at 7:06 pm #

    cheers!! :)

  2. defcon March 16, 2009 at 2:14 pm #

    this dude should be made to clean up those computers and get community service, there is too many ppl in jail anyways and they come out more fucked up then when they come in

  3. John May 21, 2009 at 8:23 pm #

    I agree with defcon…. nerds