FBI Works with Hackers to Stop Bank Robbing Virus

Tweet

A massive hacking operation that was infecting computers around the world and stealing at least $10 million in the US alone has been foiled by a joint operation between the US and British police along with assistance from hackers and cybersecurity firms.

US prosecutors announced on Tuesday that they had achieved a victory in the ‘war on malware’ that saw them take control of a network of machines used to distribute the virus known as Bugat, Cridex or Dridex.

Enslaved computers

The malware operated by slipping into the computers of the unsuspecting and stealing their passwords before siphoning money from their bank accounts.  It relied on a network of enslaved computers to distribute the software and experts believe it could have infected as many as 125,000 computers.

Separately, the US Department of Justice have also filed criminal charges against a 30 year old man called Andrey Ghinkul, believed to be the hacker behind the whole operation.  He was arrested in Cyprus and US prosecutors have sought to have him extradited to the US to stand trial.

US Attorney David J Hickton of Pennsylvania said that the operation had struck a blow to one of the most ‘pernicious malware threats in the world’.  The indictment said that Ghinkul’s thieving had gone on for years but also that he wasn’t working alone.

Poisonous attachments

Investigators think that Ghinkul and others were sending official looking spam that conned people into opening poisonous email attachments and using this method were able to steal some $3.5 million from Penneco Oil in Pennsylvania back in in 2012.  The money was sent to accounts in Belarus and Ukraine, according to the indictment.

Ghinkul used a similar method to attempt to steal almost $1 million from the Sharon City school district in the state in 2011 but the attempt failed.

The takedown was a joint operation between the FBI, the National Crime Agency of the UK, the Cybercrime Centre of Europol and the Bundeskriminalamt of Germany.  They worked with private companies including Dell SecureWorks as well as cybersecurity companies Fox-IT, S21sec and Spamhaus.

It was researchers at Dell SecureWorks that first spotted the bank detail stealing program back in 2010, then known as Bugat.  It would spy on people’s web browsing, recognising when they were visiting their bank’s website and collect the usernames and passwords they used to send to hackers.

The software continued to evolve and became known as Cridex then later as Dridex as it became more capable and smarter.  The network that has just been shut down had made the Dridex version the most popular malware currently affecting networks around the world – if a network was hit, Dridex was the most likely culprit.

Waves

The software send out somewhere in the region of 350,000 emails each day, according to cybersecurity firm Proofpoint, who offer a secure company email system.

Dell SecureWorks began working on a project earlier in the year to disrupt this system and teamed up with law enforcement to get legal permission to hack the botnet setup.  This happened on August 28th and the Dridex malware immediately stopped working.

Finally, last week the operation included grabbing the botnet itself when a secret operation saw the company sneak into host computers that operate the network of enslaved computers and took it out of the control of the hackers.


Tweet

Related posts: