Spanish police arrest Mariposa botnet ringleaders
By Martin James,
Spanish police have arrested three men believed to be the masterminds behind one of the world's largest botnets.
The men are accused of running the Mariposa botnet, which is believed to have infected nearly 13 million PCs with a virus that stole credit card details and other data.
The Spanish Guardia Civil made the arrests after two internet security firms – Canada's Defence Intelligence Inc and Spain's Panda Security SL – were able to infiltrate the ring and shut it down just before Christmas.
By that point Mariposa – the Spanish word for butterfly - had affected 12.7 million computers in 190 countries around the world, with victims including government agencies, schools, more than half of the world's 1,000 largest corporations and 40 per cent of banks.
The virus was programmed to take control of infected machines and record every key stroke made, sending the data back to Mariposa's servers, where it was analysed to try and identify passwords, credit card numbers and other private information.
Mariposa first appeared in December 2008, and spread through removable USB drives, MSN Messenger and peer-to-peer networks. The virus helped the three ringleaders steal banking credentials and launch distributed denial-of-service attacks, though unlike with some other botnets they did not use it to try and sell fake security software.
It was first spotted in April last year, and was taken down on December 23 last year thanks to the efforts of an informal group of volunteers calling itself the Mariposa Working Group.
“It was so nasty, we thought 'we have to turn this off. We have to cut off the head',” said Chris Davis, chief executive of Defense Intelligence. Security experts believe the total cost of removing the program could run into the millions.
The three men – known only by their web handles “Netkairo”, “Johnyloleante” and “Ostiator” at this stage – weren't skilled programmers, but had contacts who were. All three are Spanish citizens and have no previous convictions, according to Guardia Civil captain Cesar Lorenza.
“They're not like these people from the Russian mafia or Eastern European mafia who like to have sports cars and good watches and good suits. The most frightening thing is they are normal people who are earning a lot of money with cybercrime,” Lorenza commented.
According to Panda Security, not only did the men use their network of infected PCs to collect data, they also rented them out to other hackers. One of the three was caught in possession of 800,000 personal credentials. They each face up to six years in prison if convicted.
However, security experts warn it is likely that more than three people were behind Mariposa, and the network could easily be put back in place by others. “Mariposa's the biggest ever to be shut down, but this is only the tip of the iceberg. These things come up constantly,” Mark Rasch, former head of the US Department of Justice computer crimes unit, told Reuters.
You may also like...
You may also like...
advertisement
Latest Security Features
The trials and tribulations of social networking
As a business, you may be examining how to take advantage of social networking sites. Before you leap into the fray, take heed of the mistakes others have made before you.
- NO2ID on fighting the database state
- Building a better password
- Q&A: George Kurtz, CTO, McAfee
- Is mobile malware really a risk?
- Fear and loathing in the Mariposa aftermath
- Public vs private: Which cloud is best for business?
- Q&A: Gerhard Eschelbeck, chief technology officer at Webroot
- How the Digital Economy Act will affect your business
- Cyber war: Modern warfare 2.0
Latest Security Reviews
Kaspersky Internet Security 2011 review
Rating: ![]()
- G Data Software EndpointProtection Business review
- eSoft InstaGate 806 review
- M86 Security Secure Web Gateway 5000 review
- Google Maps Navigation review
- Netgear ProSecure UTM10 review
- ZoneAlarm DataLock review
- SmoothWall Guardian SWG-1208 review
- Symantec Backup Exec 2010 review
- WatchGuard XCS-770 review
advertisement
Most popular
- Government calls mobile broadband spectrum auction
- Sony Ericsson Xperia X10 Mini Pro review
- UK web guru handed key to the internet?
- Samsung Galaxy S review
- 100 million Facebook user info scraped
- HTC Hero to finally get Android 2.1 update
- Top 10 remote desktop applications
- Amazon sets UK Kindle launch date
- Head to Head: Office 2010 vs Open Office 3.1
- Top 10 future trends for mobile phones
Latest News Videos in Security
Video: Why security is everybody's responsibility
Rik Ferguson, senior security advisor at Trend Micro says it's up to all of us to make security work.
Whitepapers
Want more background on today's hottest IT trends?
Visit IT PRO's whitepaper library for more on virtualisation, encryption and other topics.
Register for IT PRO
You'll get exclusive member benefits including free whitepapers, downloads, Webinars and weekly newsletters full of the latest IT PRO news, reviews, insight and expertise.







Did you mean...?
"...including in many big corparations.." Surely you add stuff via your CMS with Firefox and a dictionary enabled? :p
By scottuss on Wednesday Mar 3