{"id":16475,"date":"2019-10-01T10:17:04","date_gmt":"2019-10-01T18:17:04","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2019\/10\/01\/news-10215\/"},"modified":"2019-10-01T10:17:04","modified_gmt":"2019-10-01T18:17:04","slug":"news-10215","status":"publish","type":"post","link":"https:\/\/www.palada.net\/index.php\/2019\/10\/01\/news-10215\/","title":{"rendered":"Mariposa Botnet Author, Darkcode Crime Forum Admin Arrested in Germany"},"content":{"rendered":"<p><strong>Credit to Author: BrianKrebs| Date: Tue, 01 Oct 2019 16:33:19 +0000<\/strong><\/p>\n<p>A Slovenian man convicted of authoring the destructive and once-prolific\u00a0<a href=\"https:\/\/en.wikipedia.org\/wiki\/Mariposa_botnet\" target=\"_blank\" rel=\"noopener\">Mariposa botnet<\/a> and running the infamous\u00a0<a href=\"https:\/\/krebsonsecurity.com\/2015\/07\/the-darkode-cybercrime-forum-up-close\/\" target=\"_blank\" rel=\"noopener\">Darkode cybercrime forum<\/a> has been arrested in Germany on request from prosecutors in the United States, who&#8217;ve recently re-indicted him on related charges.<\/p>\n<div id=\"attachment_49132\" style=\"width: 603px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-49132 \" src=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2019\/10\/nicehash.png\" alt=\"\" width=\"593\" height=\"464\" \/><\/p>\n<p class=\"wp-caption-text\">NiceHash CTO Matja\u017e &#8220;Iserdo&#8221; \u0160korjanc, as pictured on the front page of a recent edition of the Slovenian daily Delo.si, is being held by German authorities on a US arrest warrant for operating the destructive &#8220;Mariposa&#8221; botnet and founding the infamous Darkode cybercrime forum.<\/p>\n<\/div>\n<p>The Slovenian Press Agency <a href=\"https:\/\/www.sta.si\/2682188\/nemci-po-nalogu-zda-prijeli-programerja-skorjanca\" target=\"_blank\" rel=\"noopener\">reported today<\/a> that German police arrested\u00a0<strong>Matja\u017e &#8220;Iserdo&#8221; \u0160korjanc <\/strong>last week, in response to a U.S.-issued international arrest warrant for his extradition.<\/p>\n<p>In December 2013, a Slovenian court sentenced \u0160korjanc to four years and ten months in prison for creating the malware that powered the \u2018<strong>Mariposa<\/strong>\u2018 botnet. Spanish for \u201cButterfly,\u201d Mariposa was a potent crime machine first spotted in 2008. Very soon after its inception, Mariposa was estimated to have infected <a href=\"https:\/\/krebsonsecurity.com\/2010\/03\/mariposa-botnet-authors-may-avoid-jail-time\/\" target=\"_blank\" rel=\"noopener\">more than 1 million hacked computers<\/a> \u2014 making it one of the largest botnets ever created.<\/p>\n<div id=\"attachment_1451\" style=\"width: 605px\" class=\"wp-caption aligncenter\"><a class=\"lightbox\" href=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2010\/03\/Screen-shot-2010-03-03-at-7.08.09-PM.png\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-1451\" src=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2010\/03\/Screen-shot-2010-03-03-at-7.08.09-PM.png\" alt=\"\" width=\"595\" height=\"328\" srcset=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2010\/03\/Screen-shot-2010-03-03-at-7.08.09-PM.png 962w, https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2010\/03\/Screen-shot-2010-03-03-at-7.08.09-PM-300x165.png 300w\" sizes=\"auto, (max-width: 595px) 100vw, 595px\" \/><\/a><\/p>\n<p class=\"wp-caption-text\">An advertisement for the ButterFly Bot.<\/p>\n<\/div>\n<p>\u0160korjanc and his hacker handle Iserdo were initially named in a <a href=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2019\/10\/2011-Skorjanc-Indictment.pdf\" target=\"_blank\" rel=\"noopener\">Justice Department indictment from 2011<\/a> (PDF) along with two other men who allegedly wrote and sold the Mariposa botnet code. But in June 2019, the DOJ unsealed\u00a0<a href=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2019\/10\/newdarkodecharges.pdf\" target=\"_blank\" rel=\"noopener\">an updated indictment<\/a>\u00a0(PDF)\u00a0naming\u00a0\u0160korjanc, the original two other defendants, and a fourth man (from the United States) in a conspiracy to make and market Mariposa and to run the Darkode crime forum.<\/p>\n<p>More recently, \u0160korjanc served as chief technology officer at <strong>NiceHash<\/strong>, a Slovenian company that lets users sell their computing power to help others mine virtual currencies like bitcoin. In December 2017, approximately USD $52 million worth of bitcoin <a href=\"https:\/\/krebsonsecurity.com\/2017\/12\/former-botmaster-darkode-founder-is-cto-of-hacked-bitcoin-mining-firm-nicehash\/\" target=\"_blank\" rel=\"noopener\">mysteriously disappeared from the coffers of NiceHash<\/a>. Slovenian police are reportedly <a href=\"https:\/\/news.bitcoin.com\/nicehash-returns-60-of-coins-stolen-in-the-hack\/\" target=\"_blank\" rel=\"noopener\">still investigating<\/a> that incident.<\/p>\n<div id=\"attachment_31625\" style=\"width: 604px\" class=\"wp-caption aligncenter\"><a class=\"lightbox\" href=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2015\/07\/dkhome.png\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-31625\" src=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2015\/07\/dkhome.png\" alt=\"\" width=\"594\" height=\"633\" srcset=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2015\/07\/dkhome.png 690w, https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2015\/07\/dkhome-580x618.png 580w\" sizes=\"auto, (max-width: 594px) 100vw, 594px\" \/><\/a><\/p>\n<p class=\"wp-caption-text\">The &#8220;sellers&#8221; page on the Darkode cybercrime forum, circa 2013.<\/p>\n<\/div>\n<p><span id=\"more-49124\"><\/span>It will be interesting to see what happens with the fourth and sole U.S.-based defendant added in the latest DOJ charges &#8212; <strong>Thomas K. McCormick<\/strong>, a.k.a &#8220;<strong>fubar<\/strong>&#8221; &#8212; allegedly one of the last administrators of Darkode. Prosecutors say McCormick also was a reseller of the Mariposa botnet, the <a href=\"https:\/\/krebsonsecurity.com\/?s=zeus&amp;x=0&amp;y=0\" target=\"_blank\" rel=\"noopener\">ZeuS banking trojan<\/a>, and a bot malware he allegedly helped create called &#8220;Ngrbot.&#8221;<\/p>\n<p>Between 2010 and 2013, Fubar would randomly chat me up on instant messenger apropos of nothing to trade information about the latest goings-on in the malware and cybercrime forum scene.<\/p>\n<p>Fubar frequently knew before anyone else about upcoming improvements to or new features of ZeuS, and discussed at length his interactions with Iserdo\/\u0160korjanc. Every so often, I would reach out to Fubar to see if he could convince one of his forum members to call off an attack against KrebsOnSecurity.com, an activity that had become something of a rite of passage for new Darkode members.<\/p>\n<p>On Dec. 5, 2013, federal investigators visited McCormick at his University of Massachusetts dorm room. According to a memo filed by FBI agents investigating the case, in that interview <span class=\"pullquote pqright\">McCormick acknowledged using the &#8220;fubar&#8221; identity on Darkode, but said he&#8217;d quit the whole forum scene years ago, <em>and that he&#8217;d even interned at Microsoft for several summers and at Cisco for one summer<\/em>.<\/span><\/p>\n<p>A subsequent search warrant executed on his dorm room revealed multiple removable drives that held tens of thousands of stolen credit card records. For whatever reason, however, McCormick wasn&#8217;t arrested or charged until December 2018.<\/p>\n<p>According to the FBI, back in that December 2013 interview McCormick voluntarily told them a great deal about his various businesses and online personas. He also apparently told investigators he talked with KrebsOnSecurity quite a bit, and that he&#8217;d tipped me off to some important developments in the malware scene. For example:<\/p>\n<p>&#8220;TM had found the email address of the Spyeye author in an old fake antivirus affiliate program database and that TM was able to find the true name of the Spyeye author from searching online for an individual that used the email address,&#8221; the memo states. &#8220;TM passed this information on to Brian Krebs.&#8221;<\/p>\n<p>Read more of the FBI&#8217;s interview with McCormick <a href=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2019\/10\/McCormickInterview.pdf\" target=\"_blank\" rel=\"noopener\">here<\/a> (PDF).<\/p>\n<p><a href=\"https:\/\/krebsonsecurity.com\/2019\/10\/mariposa-botnet-author-darkcode-crime-forum-admin-arrested-in-germany\/\" target=\"bwo\" >https:\/\/krebsonsecurity.com\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2019\/10\/nicehash.png\"\/><\/p>\n<p><strong>Credit to Author: BrianKrebs| Date: Tue, 01 Oct 2019 16:33:19 +0000<\/strong><\/p>\n<p>A Slovenian man convicted of authoring the destructive and once-prolific\u00a0Mariposa botnet and running the infamous\u00a0Darkode cybercrime forum has been arrested in Germany on request from prosecutors in the United States, who&#8217;ve recently re-indicted him on related charges.<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10643,10642],"tags":[16980,16982,23106,16983,23107,16984,16696,23108,16985,18959,23109,18962],"class_list":["post-16475","post","type-post","status-publish","format-standard","hentry","category-independent","category-krebs","tag-butterfly-bot","tag-darkode","tag-fubar","tag-iserdo","tag-mariposa-botnet","tag-matjaz-skorjanc","tag-neer-do-well-news","tag-ngrbot","tag-nicehash","tag-spyeye","tag-thomas-k-mccormick","tag-zeus"],"_links":{"self":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/16475","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=16475"}],"version-history":[{"count":0,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/16475\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=16475"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=16475"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=16475"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}