Microsoft Names Alleged Botnet Operator Behind Kelihos

InfoSec News <[email protected]> Wed, 25 Jan 2012 01:54:33 -0600 (CST)
Newsgroups gmane.comp.security.attrition.infosec-news,gmane.spam.detected
Message-ID <[email protected]>
  This message is in MIME format.  The first part should be readable text,
  while the remaining parts are likely unreadable without MIME-aware tools.

--742952673-1540692008-1327477802=:18919
Content-Type: TEXT/PLAIN; FORMAT=flowed; CHARSET=UTF-8
Content-ID: <alpine.DEB.2.02.1201250154222.19105-+lq4ijtN3NWD1tnzEPnUTA@public.gmane.org>
Content-Transfer-Encoding: quoted-printable

http://www.darkreading.com/insider-threat/167801100/security/client-secur=
ity/232500407/microsoft-names-alleged-botnet-operator-behind-kelihos.html

By Kelly Jackson Higgins
Dark Reading
Jan 24, 2012

Microsoft is continuing its legal tear against botnets: It has now named=20
the botnet operator of the Kelihos botnet that it helped take down last=20
fall.

The alleged perpetrator, Andrey N. Sabelnikov, a Russian engineer, has=20
been added to Microsoft=E2=80=99s legal suit filed in U.S. District Court=
 in=20
September in relation to the botnet. The company, which worked with=20
Kaspersky Lab and Kyrus to take down the spamming botnet, says the=20
initial claim named co-defendants Dominique Alexander Piatti and dotFREE=20
Group SRO in Microsoft=E2=80=99s civil lawsuit cooperated and provided=20
information that led to the latest legal action against Sabelnikov as=20
part of a settlement in October.

=E2=80=9CIn today=E2=80=99s complaint, Microsoft presented evidence to th=
e court that=20
Mr. Sabelnikov wrote the code for and either created, or participated in=20
creating, the Kelihos malware. Further, the complaint alleges that he=20
used the malware to control, operate, maintain and grow the Kelihos=20
botnet. These allegations are based on evidence Microsoft investigators=20
uncovered while analyzing the Kelihos malware,=E2=80=9D said Richard Domi=
ngues=20
Boscovich, senior attorney for Microsoft=E2=80=99s Digital Crimes Unit.=20
=E2=80=9CMicrosoft also alleges that Mr. Sabelnikov registered more than =
3,700=20
=E2=80=98cz.cc=E2=80=99 subdomains from Mr. Piatti and dotFREE Group SRO,=
 and misused=20
those subdomains to operate and control the Kelihos botnet.=E2=80=9D

Microsoft says Sabelnikov lives in St. Petersburg, Russia, and is a=20
contractor for a software development and consulting firm who once=20
worked as a software engineer and project manager at a firewall and=20
antivirus firm. According to KrebsOnSecurity, that firm was Agnitum.

[...]


--742952673-1540692008-1327477802=:18919
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_____________________________________________________
Did a friend send you this article? Make it your
New Year's Resolution to subscribe to InfoSec News!
http://www.infosecnews.org/mailman/listinfo/isn
--742952673-1540692008-1327477802=:18919--