Skip to: Content
Skip to: Site Navigation
Skip to: Search

FBI set to kill secret-stealing Russian 'botnet.' Is your computer infected?

The FBI has seized control of a Russian cybercrime enterprise, but to kill it completely, officials may ask to rip some malware out of your computer. US diplomatic secrets could be at stake.

By Staff writer / May 6, 2011

Seeking to destroy a Russian botnet, the FBI seeks to reach into a million US computers to remove malicious software.



The FBI might be asking your permission soon to reach into your computer and rip something out. And you don’t know it’s there.

Skip to next paragraph

In a first for US law enforcement efforts to make the Internet more secure, the Federal Bureau of Investigation has seized control of a Russian cybercrime enterprise that has enslaved millions of personal computers and may have gained access to US diplomatic, military, and law enforcement computer systems.

As if WikiLeaks wasn’t bad enough.

But to destroy the criminal “botnet” for good, the FBI has to take yet another aggressive step that is alarming privacy rights advocates: remove the malware from the computers in the network. Hopefully all that gets taken out is the malware.

The FBI’s target is a “robot network” dubbed the “Coreflood botnet” by investigators. It’s a worldwide network created by a Russian cybercrime gang that took control of 2.3 million personal computers that vacuumed up vast amounts of US personal financial and government data for almost a decade before being targeted for extermination.

More than a million of the personal computers recruited into the botnet resided in the US, according to a filing by the Department of Justice in federal court in Connecticut last month.

As of three years ago, Coreflood was sucking up about a gigabyte of data per day and as much as 500 gigabytes a year – about equal to five library floors filled with academic journals. But it was not just credit card, wire transfer, and bank passwords – its primary target – that worried investigators.

At some point, investigators discovered, Coreflood sent back to Russia “master key” access to computer systems belonging to at least one US embassy in the Middle East – which made government officials more than a little nervous, a computer security firm investigator told the Monitor.

Also, as of this year, the Coreflood botnet had assimilated into the US portion of its network hundreds of thousands of computers belonging to 17 state or local government agencies, including one police department, three airports, and two defense contractors. Add to that list five banks or financial institutions, about 30 colleges or universities, and approximately 20 hospital or health-care companies as well as hundreds of businesses, according to the Justice Department’s court filing.

Botnets are nearly ideal for criminals

Anonymous and cheap to build, botnets are a nearly ideal criminal platform on the Internet for attacks aimed at shutting down company websites – unless a payment is made – and especially pilfering personal banking credentials. Symantec, the antivirus company, reported nearly 7 million botnets on the Internet in 2009. As powerful as the Coreflood botnet became, it is old enough that most updated antivirus programs should protect computers from infection.


Read Comments

View reader comments | Comment on this story