In-depth

Fear and loathing in the Mariposa aftermath

When Luis Corrons helped take down the Mariposa botnet he was a proud man, but he had no idea about what was to follow.

When the Mariposa botnet was uncovered and shut down just before Christmas 2009, the security experts involved would have been forgiven for thinking it was the end of that particular saga.

But even after the arrests of three men in March this year, the story was not yet over for a man who was at the centre of taking down the criminal ring.

Luis Corrons, technical director of PandaLabs, was a key player in the Mariposa narrative and deserves commendation for the part he played. After the arrests, however, he was tracked by men who claimed to have been the masterminds behind the operation and at one point even feared for his own safety.

The end is just the beginning

The end of Mariposa, the Spanish word for butterfly, was the start of a strange and occasionally disturbing part of Corrons' life as an internet security guru.

In the months following his work helping bring down one of the world's largest botnets, Corrons continued with his everyday duties, among other things posting regular updates on PandaLabs' security blog.

One day, as he awaited the arrival of a journalist to show around his workplace, Corrons walked past two innocuous looking men. They turned to him and asked: "Hey, aren't you Luis Corrons?"

Slightly taken aback, Corrons simply confirmed who he was. Astonishingly, the unassuming gentlemen identified themselves as Ostiator and Netkairo the aliases of two of the arrested men involved in the Mariposa project.

Corrons would later learn that a mix-up at reception, confusing the two men for the expected journalist, had meant the pair had gained access to the PandaLabs building.

"I was scared. I was really scared," Corrons told IT PRO.

"This can't be real. At the time it was just those two guys and myself on the stairs, no one else around and I was like uh oh, what is going to happen?' I didn't know what they were doing there... How the hell did they enter the building?"

"Maybe they wanted to teach me a lesson," he added.

This was to be the beginning of a very odd relationship between the three men.

Featured Resources

Managing security risk and compliance in a challenging landscape

How key technology partners grow with your organisation

Download now

Evaluate your order-to-cash process

15 recommended metrics to benchmark your O2C operations

Download now

AI 360: Hold, fold, or double down?

How AI can benefit your business

Download now

Getting started with Azure Red Hat OpenShift

A developer’s guide to improving application building and deployment capabilities

Download now

Most Popular

School laptops sent by government arrive loaded with malware
malware

School laptops sent by government arrive loaded with malware

21 Jan 2021
How to move Windows 10 from your old hard drive to SSD
operating systems

How to move Windows 10 from your old hard drive to SSD

21 Jan 2021
How to recover deleted emails in Gmail
email delivery

How to recover deleted emails in Gmail

6 Jan 2021