Forum Views ()
Forum Replies ()
Read more with google mobile :
Inside a global cybercrime ring
|
Edition:
U.S.
Article
Comments (0)
Slideshow
Save
Email
Print
Reprints
Most Popular
Most Shared
Google to phase out China search partnerships
| Video
8:29am EDT
UPDATE 2-Republican senators see U.S. financial reform bill
10:02am EDT
Somali pirate killed in cargo ship hijack shooting
9:53am EDT
Portugal downgrade hits stocks, boosts dollar
| Video
10:57am EDT
Wal-Mart to slash grocery prices
19 Mar 2010
FACTBOX-US healthcare bill would provide immediate benefits
19 Mar 2010
For women, battle of bulge just got tougher
23 Mar 2010
BofA to start reducing mortgage principal
6:07am EDT
Inside a global cybercrime ring
11:12am EDT
Google to phase out China search partnerships
| Video
8:29am EDT
Google vs China
Remaining Google units exposed to angry Beijing
Google's gambit in pulling the plug on its flagship search engine in China leaves its remaining operations there exposed to the whimsy of Beijing, whose initial reaction is far from reassuring. Full Article | Video
Cracks in Great Chinese Firewall, even without Google
What's next for Google's China workers?
Text of Chinese official comments on Google
Factbox: Google's footprint in China
Timeline: Google's bumpy foray into China
Inside a global cybercrime ring
Jim Finkle
BOSTON
Wed Mar 24, 2010 11:12am EDT
Related News
Intel unveils new server chips ahead of AMD
Tue, Mar 16 2010
<
1 / 7
>
View Full Size
BOSTON (Reuters) - Hundreds of computer geeks, most of them students putting themselves through college, crammed into three floors of an office building in an industrial section of Ukraine's capital Kiev, churning out code at a frenzied pace. They were creating some of the world's most pernicious, and profitable, computer viruses.
Technology | Media
According to court documents, former employees and investigators, a receptionist greeted visitors at the door of the company, known as Innovative Marketing Ukraine. Communications cables lay jumbled on the floor and a small coffee maker sat on the desk of one worker.
As business boomed, the firm added a human resources department, hired an internal IT staff and built a call center to dissuade its victims from seeking credit card refunds. Employees were treated to catered holiday parties and picnics with paintball competitions.
Top performers got bonuses as young workers turned a blind eye to the harm the software was doing. "When you are just 20, you don't think a lot about ethics," said Maxim, a former Innovative Marketing programer who now works for a Kiev bank and asked that only his first name be used for this story. "I had a good salary and I know that most employees also had pretty good salaries."
In a rare victory in the battle against cybercrime, the company closed down last year after the U.S. Federal Trade Commission filed a lawsuit seeking its disbandment in U.S. federal court.
An examination of the FTC's complaint and documents from a legal dispute among Innovative executives offer a rare glimpse into a dark, expanding -- and highly profitable -- corner of the internet.
Innovative Marketing Ukraine, or IMU, was at the center of a complex underground corporate empire with operations stretching from Eastern Europe to Bahrain; from India and Singapore to the United States. A researcher with anti-virus software maker McAfee Inc who spent months studying the company's operations estimates that the business generated revenue of about $180 million in 2008, selling programs in at least two dozen countries. "They turned compromised machines into cash," said the researcher, Dirk Kollberg.
The company built its wealth pioneering scareware -- programs that pretend to scan a computer for viruses, and then tell the user that their machine is infected. The goal is to persuade the victim to voluntarily hand over their credit card information, paying $50 to $80 to "clean" their PC.
Scareware, also known as rogueware or fake antivirus software, has become one of the fastest-growing, and most prevalent, types of internet fraud. Software maker Panda Security estimates that each month some 35 million PCs worldwide, or 3.5 percent of all computers, are infected with these malicious programs, putting more than $400 million a year in the hands of cybercriminals. "When you include cost incurred by consumers replacing computers or repairing, the total damages figure is much, much larger than the out of pocket figure," said Ethan Arenson, an attorney with the Federal Trade Commission who helps direct the agency's efforts to fight cybercrime.
Groups like Innovative Marketing build the viruses and collect the money but leave the work of distributing their merchandise to outside hackers. Once infected, the machines become virtually impossible to operate. The scareware also removes legitimate anti-virus software from vendors including Symantec Corp, McAfee and Trend Micro Inc, leaving PCs vulnerable to other attacks.
When victims pay the fee, the virus appears to vanish, but in some cases the machine is then infiltrated by other malicious programs. Hackers often sell the victim's credit card credentials to the highest bidder.
Removing scareware is a top revenue generator for Geek Choice, a PC repair company with about two dozen outlets in the United States. The outfit charges $100 to $150 to clean infected machines, a service that accounts for about 30 percent of all calls. Geek Choice CEO Lucas Brunelle said that scareware attacks have picked up over the past few months as the software has become increasingly sophisticated. "There are more advanced strains that are resistant to a lot of anti-virus software," Brunelle said.
Anti-virus software makers have also gotten into the lucrative business of cleaning PCs, charging for those services even when their products fall down on the job.
Charlotte Vlastelica, a homemaker in State College, Pennsylvania, was running a version of Symantec's Norton anti-virus software when her PC was attacked by Antispyware 2010. "These pop-ups were constant," she said. "They were layered one on top of the other. You couldn't do anything."
So she called Norton for help and was referred to the company's technical support division. The fee for removing Antispyware 2010 was $100. A frustrated Vlastelica vented: "You totally missed the virus and now you're going to charge us $100 to fix it?"
AN INDUSTRY PIONEER
"It's sort of a plague," said Kent Woerner, a network administrator for a public school district in Beloit, Kansas, some 5,500 miles away from Innovative Marketing's offices in Kiev. He ran into one of its products, Advanced Cleaner, when a teacher called to report that pornographic photos were popping up on a student's screen. A message falsely claimed the images were stored on the school's computer.
"When I have a sixth-grader seeing that kind of garbage, that's offensive," said Woerner. He fixed the machine by deleting all data from the hard drive and installing a fresh copy of Windows. All stored data was lost.
Stephen Layton, who knows his way around technology, ended up junking his PC, losing a week's worth of data that he had yet to back up from his hard drive, after an attack from an Innovative Marketing program dubbed Windows XP Antivirus. The president of a home-based software company in Stevensville, Maryland, Layton says he is unsure how he contracted the malware.
But he was certain of its deleterious effect. "I work eight-to-12 hours a day," he said. "You lose a week of that and you're ready to jump off the roof."
Layton and Woerner are among more than 1,000 people who complained to the U.S. Federal Trade Commission about Innovative Marketing's software, prompting an investigation that lasted more than a year and the federal lawsuit that sought to shut them down. To date the government has only succeeded in retrieving $117,000 by settling its charges against one of the defendants in the suit, James Reno, of Amelia, Ohio, who ran a customer support center in Cincinnati. He could not be reached for comment.
"These guys were the innovators and the biggest players (in scareware) for a long time," said Arenson, who headed up the FTC's investigation of Innovative Marketing.
Innovative's roots date back to 2002, according to an account by one of its top executives, Marc D'Souza, a Canadian, who described the company's operations in-depth in a 2008 legal dispute in Toronto with its founders over claims that he embezzled millions of dollars from the firm. The other key executives were a British man and a naturalized U.S. citizen of Indian origin.
According to D'Souza's account, Innovative Marketing was set up as an internet company whose early products included pirated music and pornography downloads and illicit sales of the impotence drug Viagra. It also sold gray market versions of anti-virus software from Symantec and McAfee, but got out of the business in 2003 under pressure from those companies.
It tried building its own anti-virus software, dubbed Computershield, but the product didn't work. That didn't dissuade the firm from peddling the software amid the hysteria over MyDoom, a parasitic "worm" that attacked millions of PCs in what was then the biggest email virus attack to date. Innovative Marketing aggressively promoted the product over the internet, bringing in monthly profits of more than $1 million, according to D'Souza.
The company next started developing a type of malicious software known as adware that hackers install on PCs, where they served up pop-up ads for travel services, pornography, discounted drugs and other products, including its flawed antivirus software. They spread that adware by recruiting hackers whom they called "affiliates" to install it on PCs.
"Most affiliates installed the adware product on end-users' computers illegally through the use of browser hijacking and other nefarious methods," according to D'Souza. He said that Innovative Marketing paid its affiliates 10 cents per hijacked PC, but generated average returns of $2 to $5 for each of those machines through the sale of software and products promoted through the adware.
ANY MEANS BUT SPAM
The affiliate system has since blossomed. Hackers looking for a piece of the action can link up with scareware companies through anonymous internet chat rooms. They are paid through electronic wire services such as Western Union, Pay Pal and Webmoney which can protect the identity of both the sender and the recipient.
To get started, a hacker needs to register as an affiliate on an underground website and download a virus file that is coded with his or her affiliate ID. Then it's off to races.
"You can install it by any means, except spam," says one affiliate recruiting site, earning4u.com, which pays $6 to $180 for every 1,000 PCs infected with its software. PCs in the United States earn a higher rate than ones in Asia.
Affiliates load the software onto the machines by a variety of methods, including hijacking legitimate websites, setting up corrupt sites for the purposes of spreading viruses and attacks over social networking sites such as Facebook and Twitter.
"Anybody can get infected by going to a legitimate website," said Uri Rivner, an executive with RSA, one of the world's top computer security companies.
A scareware vendor distributed its goods one September weekend via The New York Times' website by inserting a single rogue advertisement. The hacker paid NYTimes.com to run the ad, which was disguised as one for the internet phone company Vonage. It contaminated PCs of an unknown number of readers, according to an account of the incident published in The New York Times.
Patrik Runald, a senior researcher at internet security firm Websense Inc, expects rogueware vendors to get more aggressive with marketing. "We're going to see them invest more money in that -- buying legitimate ad space," he said.
To draw victims to infected websites, hackers will also manipulate Google's search engine to get their sites to come up on the top of anyone's search in a particular subject. For instance, they might capitalize on news events of wide interest -- from the winners of the Oscars to the Tiger Woods scandal -- quickly setting up sites to attract relevant search times. Anti-virus maker Panda Security last year observed one scareware peddler set up some 1 million web pages that infected people searching for Ford auto parts with a program dubbed MSAntispyware2009. They also snare victims by sending their links through Facebook and Twitter.
Some rogue vendors manage their partnerships with hackers through software that tracks who installed the virus that generated a sale. Hackers are paid well for their efforts, garnering commissions ranging from 50 to 90 percent, according to Panda Security. SecureWorks, another security firm, estimates that a hacker who gets 1 to 2 percent of users of infected machines to purchase the software can pull in over $5 million a year in commissions.
Hackers in some Eastern European countries barely attempt to conceal their activities.
Panda Security found photos of a party in March 2008 that it said affiliate ring KlikVIP held in Montenegro to reward scareware installers. One showed a briefcase full of euros that would go to the top performer. "They weren't afraid of the legal implications, " said Panda Security researcher Sean-Paul Correll. "They were fearless."
BANKING
One of Innovative Marketing's biggest problems was the high proportion of victims who complained to their credit card companies and obtained refunds on their purchases. That hurt the relationships with its merchant banks that processed those transactions, forcing it to switch from banks in Canada to Bahrain. It created subsidiaries designed to hide its identity.
In 2005, Bank of Bahrain & Kuwait severed its ties with an Innovative Marketing subsidiary that had the highest volume of credit card processing of any entity in Bahrain because of its high chargeback rates, according to D'Souza.
Innovative Marketing then went five months without a credit card processor before finding a bank in Singapore -- DBS Bank -- willing to handle its account. The Singapore bank processed tens of millions of dollars in backlogged credit card payments for the company, D'Souza said.
To keep the chargeback rate from climbing even higher, Innovative Marketing invested heavily in call centers. It opened facilities in Ukraine, India and the United States. The rogueware was designed to tell the users that their PCs were working properly once the victim had paid for the software, so when people called up to complain it wasn't working, agents would walk them through whatever steps it took to make those messages come up.
Often that required disabling legitimate anti-virus software programs, according to McAfee researcher Dirk Kollberg, who spent hours listening to digitized audio recordings of customer service calls that Innovative Marketing kept on its servers at its Ukraine offices. He gathered the data by tapping into a computer server at its branch in Kiev that he said was inadvertently hooked up to Innovative's website. "At the end of the call," he said, "most customers were happy."
Police have had limited success in cracking down on the scareware industry. Like Innovative Marketing, most rogue internet companies tend to be based in countries where laws permit such activities or officials look the other way.
Law enforcement agencies in the United States, Western Europe, Japan and Singapore are the most aggressive in prosecuting internet crimes and helping officials in other countries pursue such cases, said Mark Rasch, former head of the computer crimes unit at the U.S. Department of Justice. "In the rest of the world, it's hit or miss," he said. "The cooperation is getting better, but the level of crime continues to increase and continues to outpace the level of cooperation."
The FTC succeeded in persuading a U.S. federal judge to order Innovative Marketing and two individuals associated with it to pay $163 million it had scammed from Americans. Neither individual has surfaced since the government filed its original suit more than a year ago. But Ethan Arenson, the FTC attorney who handled the case, warned: "Collection efforts are just getting underway."
(Editing by Jim Impoco and Claudia Parsons)
Technology
Media
Add a Comment
More from Reuters
Inside a global cybercrime ring
It was a full-fledged company with a call center, HR department, and company parties. Employees cranked out code at a frenzied pace. The product? Computer viruses. Full Article
Law would identify cybercrime havens
Technology
Abortion fight looms
Battle lines are being drawn over federal funding of abortion -- a fight that could tip the balance in November's elections. Full Article
Win may threaten rest of Obama agenda
Factbox: What's next for Obama
Is this a sign of Dems' future strategy?
Politics
Deep divide over Jerusalem
For Israelis, Jerusalem is their "eternal and indivisible" capital. For Palestinians, there can be no peace deal until they have control over at least part of the city. Full Article | Related Story
Researchers dig up controversy
Factbox: A focus of faith and conflict
What's at stake? Why does it matter?
World
© Copyright 2010 Thomson Reuters
Editorial Editions:
Africa
Arabic
Argentina
Brazil
Canada
China
France
Germany
India
Italy
Japan
Latin America
Mexico
Russia
Spain
United Kingdom
United States
Reuters
Contact Us
Advertise With Us
Help
Journalism Handbook
Archive
Site Index
Video Index
Analyst Research
Mobile
Newsletters
RSS
Podcasts
Widgets
Your View
Labs
Thomson Reuters
Copyright
Disclaimer
Privacy
Professional Products
Professional Products Support
Financial Products
About Thomson Reuters
Careers
Online Products
Acquisitions Monthly
Buyouts
Venture Capital Journal
International Financing Review
Project Finance International
PEhub.com
PE Week
Thomson Reuters is the world's largest international multimedia news agency, providing investing news, world news, business news, technology news, headline news, small business news, news alerts, personal finance, stock market, and mutual funds information available on Reuters.com, video, mobile, and interactive television platforms. Thomson Reuters journalists are subject to an Editorial Handbook which requires fair presentation and disclosure of relevant interests.
NYSE and AMEX quotes delayed by at least 20 minutes. Nasdaq delayed by at least 15 minutes. For a complete list of exchanges and delays, please click here.
Other News on Wednesday, 24 March 2010 Netanyahu fears peace talks delay in settlement feud
Pirates seize British Virgin Islands cargo ship off Oman: EU
US-TECH Summary
Eurozone eyes crunch talks to break Greek stalemate
Clinton calls for new phase in Mexico drug war
|
U.S. peace push at risk, says Palestinian official
U.S. says Google on China was a business decision
France shelves key carbon tax plan
WTO rules on epic Airbus-Boeing dispute
Iraq's two main Shi'ite blocs discuss merger
Netanyahu fears peace talks delay in settlement feud
|
Russia tasks tycoon Vekselberg with modernisation drive
ICC prosecutor: Sudan poll like vote under Hitler
|
Egypt bans international Internet voice calls
South Africa police fire buckshot at township rioters
|
Google not guilty in Louis Vuitton case
Existing Homes Sales Dip In February, But Top Estimates
UN body rejects protection for shark species
Winter Music Conference Officially Begins--Dance Music Revelers Rejoice
Nintendo to launch 3D-capable DS in 2010/11
FDA Tells Doctors To Stop Using Rotavirus Vaccine With Benign Pig Virus In Children
Trade protection given to cool water shark
U.S. peace push at risk, says Palestinian official
|
TV and Internet use together growing in America
Last Supper is growing by Biblical proportions
Justin Currie Announces Upcoming U.S. Tour Starting June
Sarah Palin Travel Show To Hit Discovery Channel
Colombia rebels ready for hostage release: lawmaker
|
Paramore To Head Out On Honda Civic Tour This Summer
Iran frees Rafsanjani's grandson on bail: report
|
Whitman Tops Spending, Polls For GOP Gubernatorial Nod
Kelly Osbourne Joins "Dr. Phil" as Special Correspondent
Good-hearted Thief Returns Some Stolen Money
Chris Evans Scores "Captain America" Role
Officials: US missiles kill 3 in NW Pakistan
UN body rejects protection for shark species
Kawasaki rub salt in Melbourne wounds
China slams Google's bid to defy censors
Putin, China's Xi vow 'strategic' support in first meeting
Ex-President Carter urges talks with N.Korea
Samsung unveils new Galaxy S Android phone
|
Top US officials in Mexico for talks on drug violence
Indonesia sees need for more troops in Papua
Obama signs historic healthcare overhaul into law
U.S. says Google on China was a business decision
|
Man stabs, kills 8 children at Chinese school
Philippine police warn of election attacks
S.Korea govt seeks approval for $14.6 billion city
Brad Pitt attends London premiere of superhero film
Maruti Suzuki hits a million cars a year
Internet firm in China stops using Google services
Indonesian police detain 11 Afghan immigrants
US-ENTERTAINMENT Summary
"Dancing" waltzes to record with Gosselin, Aldrin
Vodka drinking is top killer of Russians: study
Alexis Cardenas, a Venezuelan and his violin, aims for Paris
Telling time with a wristful of dinosaur poo and meteorite
For World Cup, South Africa's football crafts go industrial
Controversy heightens over Yemen child marriage ban
To showcases Hong Kong cinema's ad hoc style
Brad Pitt attends London premiere of superhero film
Dancing waltzes to record with Gosselin, Aldrin
|
Akon denied visa to perform in Sri Lanka
|
Scream 4 set for 2011 release
|
Obama, Netanyahu seek to defuse U.S.-Israel tensions
U.S., Pakistan seek to turn page on caustic ties
|
Sprint unveils HTC WiMax phone EVO 4G
Britain kicks out Israeli diplomat in passport row
Three Rio defendants contest secrets charge: lawyer
|
Brazil fines Google for not censoring dirty jokes
Israel may replace Mossad agent expelled by UK: reports
|
In Chavez's Venezuela, the revolution will be blogged
Obama, Netanyahu seek to defuse U.S.-Israel tensions
|
U.S, Mexico eye new phase in drug war
|
ICC prosecutor: Sudan poll like vote under Hitler
Third Season Of "Mad Men" Receives DVD, Blu-ray Release
Russia, China push Iran to change nuclear stance
|
Friend, Roommate Of Michelle "Bombshell" McGee Gives "Inside Edition" Interview
Nigerian cabinet nominees include top banker
|
"Dancing With The Stars" Waltzes Away With Formidable Viewer Ratings
Schindlers List Selling Online For $2.2 Million
U.N. missions in some countries broke rules: watchdog
|
Pay Czar Orders Compensation Cuts At Five TARP Bail Out Firms
Congress Wants to Control Spread of Drone Technology
Former Top Israeli Army Brass Call Iran: Godfather Of Terrorist Organizations
Samsung unveils new Galaxy S Android phone
Walgreens Q2 Profit Rises On Strong Prescription Drug Sales
Fire in old Calcutta building kills 24, injures 20
U.S. Markets Rally On Earnings, Economic Data
Pakistan comes with specific wish list for U.S.
Pakistani security forces kill 14 militants in NW
Climate catastrophe ushered in the dinosaurs:study
Rio Tinto trial to wrap up in China
California seeks to suspend Jackson doctor's license
China TV official pleads guilty to fireworks blaze
'Rare' fossil of new dinosaur species found in US
N.Korean leader has chronic kidney failure: expert
Sprint unveils HTC WiMax phone EVO 4G
|
Samsung unveils new Galaxy S Android phone
|
Amnesty tells Malaysia to protect migrant workers
China newspaper accuses Google of helping U.S. intelligence
|
Australia examines British evidence against Israel
Google users report erratic service in Beijing
|
U.S, Mexico eye new phase in drug war
Global Weather-Celsius
Michael Jackson's doctor faces license suspension
|
Oprah Winfrey settles defamation suit with headmistress
|
James Cameron blasts Glenn Beck
|
Film shows Kennedy battle for immigration reform
|
Evil queen from Sleeping Beauty to star in film
|
Bindi Irwin follows dad's wild footsteps into film
|
Sales full-blooded for New Moon DVD
|
Matisse's aha moment subject of U.S. museum show
|
NY dealer offers Schindler's List for sale
|
Shanghai trial of Rio Tinto staff ends, no verdict
Former Samsung chairman Lee returns to post
GM's EN-V concept car: auto redo for green future
NZ dollar eases on soft data; GDP & Greek aid eyed
Japan's exports log fastest rise in 30 years
Japan's exports up 45 percent in February
PAKISTAN
Nintendo to launch 3D portable game console
Seoul shares rise; Samsung Elec up,Daewoo Ship falls
Japan's trade surplus jumps nine-fold in February
Evil queen from "Sleeping Beauty" to star in film
Michael Jackson's doctor faces license suspension
"Avatar's" Blu-ray presales strong, Cameron says
Oprah Winfrey settles defamation suit with headmistress
NY dealer offers "Schindler's List" for sale
Sales full-blooded for "New Moon" DVD
Zach Braff: "Scrubs" won't return
Kevin Kline to star in HBO drama series
Elton John, Lady Gaga join rainforest fundraiser
From art, to souls, Swiss collector switches sights
Israel braces for more expulsions in passport row
Israel, undeterred, to build in East Jerusalem
|
Iraq militants promise more attacks on U.S. troops
Fresh Israeli airstrike on Gaza Strip
High-profile resignation in Irish church abuse scandal
|
England need 209 to win Bangladesh Test
China joins big-power talks on Iran sanctions
|
Samsung unveils new Galaxy S Android phone
UK cuts debt forecast, sets election stage
|
Five soldiers killed in latest attacks in Iraq
|
Struggle for Jerusalem goes on, four decades after war
|
Saudi says arrests militants planning attacks
|
Somali pirate killed in cargo ship hijack shooting
|
2 NATO service members killed in Afghanistan
Afghan President Karzai seeks help from China
Cambodia claims killing 88 Thais during 2008-9
News
News
Obama, Netanyahu fail to resolve settlement row
After century-long fight US enacts health reforms
Google still censoring for some China customers
Shanghai trial of Rio Tinto staff ends, no verdict
Inside a global cybercrime ring
|
Indonesian landslide kills at least 3, injures 11
Pentagon eyes more "humane" enforcement of gay ban
Rights group: Sri Lanka journalist still missing
Google to phase out China search partnerships
Amnesty Int'l: Malaysia should protect migrants
E.Asia launches $120bln currency swap pact
S.Korea bonds flat: PM voices caution on exit
Former Samsung boss Lee returns as chairman
Sarah Palin 'travel show coming to Discovery'
Indonesian prisons a breeding ground for terror: analyst
Sarah Palin 'travel show coming to Discovery'
R&B star Akon falls foul of Buddhist monks in S.Lanka
News
News
Greece at new risk of being pushed off euro
Bodies of missing Tenn. mom, Jo Ann Bain, and daughter found
Female Breasts Are Bigger Than Ever
AMD Trinity Accelerated Processing Units Now in Volume Production
The Avengers (2012 film), made the second biggest opening- and single-day gross of all-time
AMD to Start Production of piledriver
Ivy Bridge Quad-Core, Four-Thread Desktop CPUs
Islamists Protest Lady Gaga's Concert in Indonesia
Japan Successfully Broadcasts an 8K Signal Over the Air
ECB boosts loans to 1 trillion Euro to stop credit crunch
Egypt : Mohammed Morsi won with 52 percent
What do you call 100,000 Frenchmen with their hands up
AMD Launches AMD Embedded R-Series APU Platform
Fed Should not Ignore Emerging Market Crisis
Fed casts shadow over India, emerging markets
Why are Chinese tourists so rude? A few insights