The US Justice Department has announced that they’ve finally caught the owner of one of the most prolific botnets in the world. Called Kelihos, this botnet extended to around 100,000 computers and is responsible for generating spam, phishing attacks and stealing login information.
Prosecutors were aware of the operator of this botnet for a long time, but his Russian citizenship precluded all attempts to arrest or extradite him to the US. The man in question is Peter Yuryevich Levashov.
Working with US officials, Spanish authorities finally arrested Levashov when he took a vacation there. Spain has an extradition treaty with the US.
Proof that Levashov is the operator of Kelihos is in the form of an IP address that Levashov used to operate Kelihos. The same IP address was used to access Levashov’s email, iCloud and Gmail accounts.
ArsTechnica reports that Levashov was a wanted man even before Kelihos, however. He’s been on the FBI’s watchlist since 2009 at least, listed as among the world’s top 10 spammers and charged with maintaining another botnet.
Kelihos-infected computers are now being redirected to benign servers and the addresses of infected computers will be sent to specialised groups who will help in the disinfection process.
In its statement on the matter, the Justice Department notes that “a number of free and paid antivirus programs are already capable of detecting and removing Kelihos, including the Microsoft Safety Scanner .”
Full details of the arrest, including the events leading up to it, the evidence, etc., can be found here .
)
)
)
)