Spanish police arrest Mariposa botnet ringleaders
By Martin James,
Spanish police have arrested three men believed to be the masterminds behind one of the world's largest botnets.
The men are accused of running the Mariposa botnet, which is believed to have infected nearly 13 million PCs with a virus that stole credit card details and other data.
The Spanish Guardia Civil made the arrests after two internet security firms – Canada's Defence Intelligence Inc and Spain's Panda Security SL – were able to infiltrate the ring and shut it down just before Christmas.
By that point Mariposa – the Spanish word for butterfly - had affected 12.7 million computers in 190 countries around the world, with victims including government agencies, schools, more than half of the world's 1,000 largest corporations and 40 per cent of banks.
The virus was programmed to take control of infected machines and record every key stroke made, sending the data back to Mariposa's servers, where it was analysed to try and identify passwords, credit card numbers and other private information.
Mariposa first appeared in December 2008, and spread through removable USB drives, MSN Messenger and peer-to-peer networks. The virus helped the three ringleaders steal banking credentials and launch distributed denial-of-service attacks, though unlike with some other botnets they did not use it to try and sell fake security software.
It was first spotted in April last year, and was taken down on December 23 last year thanks to the efforts of an informal group of volunteers calling itself the Mariposa Working Group.
“It was so nasty, we thought 'we have to turn this off. We have to cut off the head',” said Chris Davis, chief executive of Defense Intelligence. Security experts believe the total cost of removing the program could run into the millions.
The three men – known only by their web handles “Netkairo”, “Johnyloleante” and “Ostiator” at this stage – weren't skilled programmers, but had contacts who were. All three are Spanish citizens and have no previous convictions, according to Guardia Civil captain Cesar Lorenza.
“They're not like these people from the Russian mafia or Eastern European mafia who like to have sports cars and good watches and good suits. The most frightening thing is they are normal people who are earning a lot of money with cybercrime,” Lorenza commented.
According to Panda Security, not only did the men use their network of infected PCs to collect data, they also rented them out to other hackers. One of the three was caught in possession of 800,000 personal credentials. They each face up to six years in prison if convicted.
However, security experts warn it is likely that more than three people were behind Mariposa, and the network could easily be put back in place by others. “Mariposa's the biggest ever to be shut down, but this is only the tip of the iceberg. These things come up constantly,” Mark Rasch, former head of the US Department of Justice computer crimes unit, told Reuters.
You may also like...
Sponsored Links
advertisement
You may also like...
Latest Security Analysis & Insight
Striving to solve the security skills crisis
The Cyber Security Challenge is doing a fine job, but flat registration growth and weak Government funding are cause for concern, Tom Brewster discovers.
- Would you employ a hacker or malware writer?
- Q&A: Raj Samani, CTO McAfee
- Erase and rewind: the EU and privacy
- My email address is [CENSORED]
- Is there such a thing as a secure tablet?
- 2011: The year in news
- BYOD: Old or new, good or bad?
- Are the cookie laws crumbling already?
- Sticking security where the sun don't shine
Latest Security Reviews
Check Point 2210 Appliance review
Rating: ![]()
advertisement
Most popular
- Virgin remains on top in broadband speed race
- Will someone rid me of these troublesome Macs?
- MPs call for infection detection database
- A data shock warning for Orange customers
- What can Intel bring to the smartphone market?
- T-Mobile announces 'UK's first' fully unlimited deals
- Nokia Lumia 710 review
- Cisco launches turbo-powered wireless access point
- Facebook unveils $10bn IPO plans
- Head to Head: Mac OS X 10.7 Lion vs Windows 7
Latest News Videos in Security
IT PRO Podcast: Are UK data protection laws flawed?
We bring in two experts to talk about the problems with UK data protection law and the way it is managed.
Register for IT PRO
You'll get exclusive member benefits including free whitepapers, downloads, Webinars and weekly newsletters full of the latest IT PRO news, reviews, insight and expertise.
![My email address is [CENSORED]](http://cdn.itpro.co.uk/images/front_picture_library_IT_Pro/dir_227/it_photo_113980_36.jpg)





Did you mean...?
"...including in many big corparations.." Surely you add stuff via your CMS with Firefox and a dictionary enabled? :p
By scottuss on Wednesday Mar 3