Pakistanis angry over detentions in Times Sq. case Monday, May 24, 2010
ISLAMABAD – Relatives of three men detained by Pakistan for alleged links to the suspect in the attempted Times Square bombing say the men are innocent.
They
AFP - Thursday, August 6TAIPEI (AFP) - - Taiwan's Beijing-friendly government on Wednesday denied boycotting an Australian film festival amid a row over the e
BERLIN (Reuters) - Chancellor Angela Merkel suffered a double blow on Thursday as a senior party ally in east German
Minister seeks closure of anti-Berlusconi websites Wednesday, December 16, 2009
ROME (AFP) - – The Italian government moved Tuesday to close down Internet sites encouraging further violence against Prime Minister Silvio Berlusconi, who
By ELAINE KURTENBACH,AP Business Writer AP - Wednesday, March 18SHANGHAI - Asia's stock market rally seemed to be running out of steam Wednesday, despite an
Edition:
U.S.
Africa
Arabic
Argentina
Brazil
Canada
China
France
Germany
India
Italy
Japan
Latin America
Mexico
Russia
Spain
United Kingdom
Home
Business
Business Home
Economy
Davos 2012
Technology
Media
Small Business
Legal
Deals
Earnings
Summits
Business Video
The Freeland File
Markets
Markets Home
U.S. Markets
European Markets
Asian Markets
Global Market Data
Indices
M&A
Stocks
Bonds
Currencies
Commodities
Futures
Funds
peHUB
World
World Home
U.S.
Brazil
China
Euro Zone
Japan
Mexico
Russia
India Insight
World Video
Reuters Investigates
Decoder
Politics
Politics Home
Election 2012
Issues 2012
Candidates 2012
Tales from the Trail
Political Punchlines
Supreme Court
Politics Video
Tech
Technology Home
MediaFile
Science
Tech Video
Tech Tonic
Opinion
Opinion Home
Chrystia Freeland
John Lloyd
Felix Salmon
Jack Shafer
David Rohde
Bernd Debusmann
Nader Mousavizadeh
Lucy P. Marcus
David Cay Johnston
Bethany McLean
Edward Hadas
Hugo Dixon
Ian Bremmer
Mohamed El-Erian
Lawrence Summers
Susan Glasser
The Great Debate
Steven Brill
Geraldine Fabrikant
Breakingviews
Equities
Credit
Private Equity
M&A
Macro & Markets
Politics
Breakingviews Video
Money
Money Home
Global Investing
MuniLand
Unstructured Finance
Linda Stern
Mark Miller
John Wasik
James Saft
Analyst Research
Alerts
Watchlist
Portfolio
Stock Screener
Fund Screener
Personal Finance Video
Money Clip
Life
Health
Sports
Arts
Faithworld
Business Traveler
Entertainment
Oddly Enough
Lifestyle Video
Pictures
Pictures Home
Reuters Photographers
Full Focus
Video
Reuters TV
Reuters News
Article
Comments (0)
Follow Reuters
Facebook
Twitter
RSS
YouTube
Read
Mark Wahlberg apologizes for 9/11 comments
18 Jan 2012
Republicans fume as Keystone oil pipeline rejected
|
18 Jan 2012
Severed hands, feet found near mystery head in Hollywood
18 Jan 2012
Suddenly, Romney faces fight in South Carolina
|
18 Jan 2012
Russia says will stand firm with China on Syria
18 Jan 2012
Discussed
123
Romney opens 21-point lead in South Carolina: Reuters/Ipsos poll
109
Obama set to reject Keystone oil pipeline: sources
94
Ohio woman loses appeal on ”White Only” pool sign
Watched
Was there a rape on Big Brother?
Wed, Jan 18 2012
Will Russia spill blood?
Tue, Jan 17 2012
Obama rejects Keystone pipeline
Wed, Jan 18 2012
Virus infections stop after suspects named
Tweet
Share this
Email
Print
Related News
GSM phones vulnerable to hijack scams -researcher
Tue, Dec 27 2011
Analysis & Opinion
Belgian police raid Catholic Church offices over abuse files for third day running
Why doesn’t unemployment create more crime?
Related Topics
Tech »
Media »
Facebook »
By Joseph Menn and Jim Finkle
Wed Jan 18, 2012 8:53pm EST
(Reuters) - One of the most common sources of computer intrusions has stopped infecting new machines after security researchers working with Facebook released the names of five suspected ringleaders.
After more than two years of work, a pair of researchers on Tuesday published the names, aliases and photographs of a gang they accused of running a criminal enterprise known as Koobface that had primarily targeted Facebook after it cropped up in 2008.
German security researchers Jan Droemer and Dirk Kollberg said that servers that ran the Koobface operation stopped responding on Tuesday morning after they released an in-depth report via Kollberg's employer, the UK anti-virus software maker Sophos.
Some computers used to control Koobface had previously been disabled and it had not spread through Facebook connections since early last year.
But until the new disclosures, the Koobface gang had continued to target other social networks as a long-running FBI probe failed to result in arrests in Russia.
Koobface spread primarily through captured social networking accounts that prompted friends to install software to view a video. Initially content with small-scale advertising fraud, the group had also begun to distribute more pernicious software, including the Zeus trojans for bank-account theft, according to another researcher collaborating with Facebook, Gary Warner of the University of Alabama-Birmingham.
Kaspersky Lab, a large security software company, said its database showed that the Koobface virus had afflicted between 400,000 and 800,000 computers during its heyday in 2010.
"The thing that we are most excited about is that the botnet is down," said Facebook security official Ryan McGeehan. "Our decision to become transparent about this has had a 24-hour impact. Only time will tell if it's permanent but it was certainly effective."
Droemer and Kollberg said that they had planned to hold off on publishing their data until law enforcement had captured the suspects. They released it earlier, with Facebook's blessing, after one of those suspects, who goes by the alias "Krotreal," was named last week by another researcher.
Facebook Chief Security Officer Joe Sullivan said he had endorsed the release because he felt the exposure might disrupt the group.
Indeed, those identified have erased social networking profiles cited by the researchers, and many of the phone numbers have been reassigned.
"Krotreal," for example, renamed his account on the Russian social networking site twice, then deleted it altogether, along with his Twitter feed and LiveJournal accounts.
None of the five alleged members of the hacking group could immediately be traced to the reported office addresses or phone numbers in St Petersburg, Russia's second-largest city. (The report is online here).
At the MobSoft address named by Sophos, a Reuters reporter found a dilapidated building that once belonged to a company controlling seaport currency trade in the Soviet Union. Today the building, near a port docking station, is mostly occupied by shipping companies. An employee of one of the firms told Reuters he had never heard of a firm by the name of MobSoft.
"Our company has been renting an office here for three years, but there is no firm named MobSoft here and there has never been one," he said. Neither the building's concierge nor its manager, who had been in her job for the past 15 years, knew about MobSoft or the suspected hacker group.
The legal address for MobSoft found in online directories, and in the SKRIN stock exchange companies' database, led Reuters to an apartment complex a few blocks away from the Mariinsky theatre, whose ballet troupe ranks with Moscow's Bolshoi as Russia's most prestigious.
There was no response when the Reuters reporter rang the bell and knocked on the old wooden rusty-colored door.
Calls to the numbers provided in the Sophos reports yielded no valid leads. One of the names listed under the telephone numbers matched that in the report. But most did not.
At the official MobSoft number, Reuters reached a man calming a crying baby who said strangers had started calling him recently with questions about Koobface and MobSoft. He said he had not heard of either.
The two German researchers said they suspected that the hackers had been working out of a third location in St. Petersburg.
NO INVESTIGATION REQUESTED
Russia's anti-cybercrime unit, the Interior Ministry's K Directorate, said it has yet to investigate the matter because it has not been asked to.
"An official request needs to be filed to the K Directorate first, and when it's filed, we will certainly investigate and work on it," said Larisa Zhukova, a representative at the cyber unit, told Reuters.
"The request must come from the victim, that is Facebook. Because anyone can say or write anything, but it is all unfounded so far," she added.
If submitted, a request would undergo a 30-day review, followed by an initial check.
"Even if it turns into a criminal case, the investigative unit will decide on possible charges. It is hard to hypothesize on a possible sentence right now," she said, adding she had no information on whether the operational staff of the investigative unit knew about the situation.
A spokesman for the FBI did not respond to a request for comment.
Members of Facebook's security staff declined to comment on their discussions with law enforcement officials. Others working with Facebook said that the MVD, or Interior Ministry, had indeed been involved, with little visible progress.
"I like that we're getting the dialogue about the challenges of cross-border enforcement," Sullivan, the Facebook security officer, said. "Ultimately, the goal here is to have an impact. As a security team, we don't have the luxury that every case ends in an arrest."
(Reporting by Joseph Menn in San Francisco; Jim Finkle in Boston; Liza Dobkina in St Petersburg; Nastassia Astrasheuskaya and Maria Kiselyova in Moscow; Jeremy Pelofsky in Washington)
Tech
Media
Facebook
Tweet this
Link this
Share this
Digg this
Email
Reprints
We welcome comments that advance the story through relevant opinion, anecdotes, links and data. If you see a comment that you believe is irrelevant or inappropriate, you can flag it to our editors by using the report abuse links. Views expressed in the comments do not represent those of Reuters. For more information on our comment policy, see http://blogs.reuters.com/fulldisclosure/2010/09/27/toward-a-more-thoughtful-conversation-on-stories/
Comments (0)
Be the first to comment on reuters.com.
Add yours using the box above.
Edition:
U.S.
Africa
Arabic
Argentina
Brazil
Canada
China
France
Germany
India
Italy
Japan
Latin America
Mexico
Russia
Spain
United Kingdom
Back to top
Reuters.com
Business
Markets
World
Politics
Technology
Opinion
Money
Pictures
Videos
Site Index
Legal
Bankruptcy Law
California Legal
New York Legal
Securities Law
Support & Contact
Support
Corrections
Advertise With Us
Connect with Reuters
Twitter
Facebook
LinkedIn
RSS
Podcast
Newsletters
Mobile
About
Privacy Policy
Terms of Use
Our Flagship financial information platform incorporating Reuters Insider
An ultra-low latency infrastructure for electronic trading and data distribution
A connected approach to governance, risk and compliance
Our next generation legal research platform
Our global tax workstation
Thomsonreuters.com
About Thomson Reuters
Investor Relations
Careers
Contact Us
Thomson Reuters is the world's largest international multimedia news agency, providing investing news, world news, business news, technology news, headline news, small business news, news alerts, personal finance, stock market, and mutual funds information available on Reuters.com, video, mobile, and interactive television platforms. Thomson Reuters journalists are subject to an Editorial Handbook which requires fair presentation and disclosure of relevant interests.
NYSE and AMEX quotes delayed by at least 20 minutes. Nasdaq delayed by at least 15 minutes. For a complete list of exchanges and delays, please click here.