[ISN] Microsoft turns to FBI in hunt for Rustock ringleader

From: InfoSec News <alerts_at_private>
Date: Fri, 23 Sep 2011 04:50:00 -0500 (CDT)
http://www.theregister.co.uk/2011/09/22/microsoft_refers_rustock_to_fbi/

By Dan Goodin in San Francisco
The Register
22nd September 2011

Microsoft lawyers have sealed their victory over the operators of what 
was once the world's biggest source of spam after winning a court case 
giving them permanent control over the IP addresses and servers used to 
host the Rustock botnet.

The seizure was completed earlier this month when a federal judge in 
Washington state awarded Microsoft summary judgement in its novel 
campaign against Rustock, which at its height enslaved about 1.6 million 
PCs and sent 30 billion spam messages per day. The complex legal action 
ensured that IP addresses and more than two dozen servers for Rustock 
were seized simultaneously to prevent the operators from regrouping.

Now the attorneys are turning over the evidence obtained in the case to 
the FBI in hopes that the Rustock operators can be tracked down and 
prosecuted. Microsoft has already offered a $250,000 bounty for 
information leading to their conviction. It has also turned up the 
pressure by placing ads in Moscow newspapers to satisfy legal 
requirements that defendants be given notice of the pending lawsuit.

According to court documents (PDF), the Rustock ringleader is a Russian 
citizen who used the online handle Cosma2k to buy IP addresses that 
hosted many of the Rustock command and control servers. Microsoft 
investigators claimed the individual distributed malware and was 
involved in illegal spam pitching pharmaceutical drugs.

[...]


_____________________________________________________________
Register now for the #HITB2011KUL - Asia's premier
deep-knowledge network security event now in it's 9th year!
http://conference.hitb.org/hitbsecconf2011kul/
Received on Fri Sep 23 2011 - 02:50:00 PDT

This archive was generated by hypermail 2.2.0 : Fri Sep 23 2011 - 02:56:37 PDT