Skip to main content

The context you need, when you need it

When news breaks, you need to understand what actually matters — and what to do about it. At Vox, our mission to help you make sense of the world has never been more vital. But we can’t do it on our own.

We rely on readers like you to fund our journalism. Will you support our work and become a Vox Member today?

Join now

U.S. Leads Global Effort to Disrupt Cyber Crime Ring

The botnet, known as GameOver Zeus, or GOZ, has caused $100 million in losses to consumers and businesses since it first surfaced in 2007.

Gualtiero Boffi/Shutterstock

A U.S.-led international operation disrupted a crime ring that had infected hundreds of thousands of PCs around the globe with malicious software used for stealing banking credentials and cyber extortion, the Justice Department said on Monday.

Authorities used technical and legal tactics to interrupt the so-called botnet’s operations, shutting down the servers the cyber criminals used to control infected machines and causing those machines to “phone home” to servers controlled by law enforcement.

“These schemes were highly sophisticated and immensely lucrative, and the cyber criminals did not make them easy to reach or disrupt,” Leslie Caldwell, who heads the Justice Department’s criminal division, told a news conference.

The botnet, known as GameOver Zeus, or GOZ, derives its name from a version of the Zeus credential-stealing software, which U.S. court documents said have caused $100 million in losses to consumers and businesses since it first surfaced in 2007. Court documents released on Monday said that between 500,000 and one million machines worldwide were infected with the malicious software, or malware.

Its primary purpose was to capture banking credentials, though it has been known to change recipients of legitimate payments orders, for example targeting U.S. hospitals’ payroll operations.

A botnet is a group of computers under the control of someone other than the computers’ owners. They are typically assembled through viruses and are the key tool in spam, online bank fraud and denial-of-service attacks on websites.

GOZ was also used to distribute Cryptolocker, malicious software known as “ransomware” that encrypts data of an infected computer, making it inaccessible to the user. Cyber criminals would essentially take the machine hostage, promising to unscramble the data if the user paid them a ransom of as much as $700, the Justice Department said.

The U.S. Department of Homeland Security set up a website to help victims remove the GOZ malware. The European Cybercrime Centre also participated in the operation, along with Australia, Canada, France, Germany, Italy, Japan, Luxembourg, New Zealand, Ukraine and the United Kingdom.

Intel, Microsoft, security software companies F-secure, Symantec, and Trend Micro; and Carnegie Mellon University also supported the operation.

The U.S. government kept the effort secret until Monday when it unsealed a 14-count indictment accusing Russian national Evgeniy Mikhaylovich Bogachev of involvement in the alleged conspiracy.

The suspect, who authorities said is known online as Lucky12345, is charged with writing computer code used to compromise banking systems and assist others in stealing banking credentials, according to court documents.

Prosecutors said the victims of the attacks included Capital One Bank, Bank of Georgetown in Washington, and First National Bank of Omaha.

Bogachev and his group infected thousands of business computers with software that captured passwords, account numbers, and other information used to log in to online bank accounts, prosecutors said.

(Reporting by Jim Finkle, Aruna Viswanatha and Julia Edwards; Additional reporting by Alina Selyukh; Editing by Jonathan Oatis)

This article originally appeared on Recode.net.

See More:

More in Technology

Future Perfect
The 5 most unhinged revelations from Elon Musk’s lawsuit against OpenAIThe 5 most unhinged revelations from Elon Musk’s lawsuit against OpenAI
Future Perfect

The Musk v. OpenAI trial is over. Here are the receipts.

By Sara Herschander
Podcasts
Are humanoid robots all hype?Are humanoid robots all hype?
Podcast
Podcasts

AI is making them better — but they’re not going to be doing your chores anytime soon.

By Avishay Artsy and Sean Rameswaram
Future Perfect
The old tech that could help stop the next airborne pandemicThe old tech that could help stop the next airborne pandemic
Future Perfect

Glycol vapors, explained.

By Shayna Korol
Future Perfect
Elon Musk could lose his case against OpenAI — and still get what he wantsElon Musk could lose his case against OpenAI — and still get what he wants
Future Perfect

It’s not about who wins. It’s about the dirty laundry you air along the way.

By Sara Herschander
Life
Why banning kids from AI isn’t the answerWhy banning kids from AI isn’t the answer
Life

What kids really need in the age of artificial intelligence.

By Anna North
Culture
Anthropic owes authors $1.5B for pirating work — but the claims process is a Kafkaesque messAnthropic owes authors $1.5B for pirating work — but the claims process is a Kafkaesque mess
Culture

“Your AI monster ate all our work. Now you’re trying to pay us off with this piece of garbage that doesn’t work.”

By Constance Grady