Email this article   Print article 


Estonian Man Pleads Guilty For Role In DNSChanger Attacks

By Robert Westervelt
February 05, 2013    10:32 AM ET

An Estonian man pleaded guilty in U.S. federal court for his role in spreading the DNSChanger malware, designed to hijack infected computers and redirect them to malicious websites. The scheme, which lasted for five years, is believed to have generated upward of $14 million in fraudulent Internet advertising revenue. At least 4 million computers in 100 countries were infected by the malware, creating a large botnet.

Valeri Aleksejev, 32, pleaded guilty to conspiracy to commit wire fraud and conspiracy to commit computer intrusion, according to a Reuters report. He faces up to 25 years in prison, deportation and the forfeiture of $7 million. Aleksejev was the first to enter a plea among the six Estonians and one Russian who were indicted in 2011. They were indicted on five charges each of wire and computer intrusion. One of the defendants, Vladimir Tsastsin, also was charged with 22 counts of money laundering.

[Related: Federal Government Acts Against Trojan]

The DNSChanger Botnet was taken down in 2011 when the FBI and Estonian national police made arrests in that country, while data centers in New York and Chicago that served as the command-and-control infrastructure for the botnet where shut down.

Users were impacted by DNSCharger when trying to access the websites of Apple iTunes, Netflix and Facebook and were instead redirected to unaffiliated businesses. The scam also involved replacing legitimate advertisements on websites with advertisements that resulted in payments to the fraudsters.

DNSChanger was first detected in 2006. The attacks were traced to a legitimate Estonian company, which was being used to control the compromised machines.

Antivirus has been able to detect the malware, but cleaning up the infected computers had been a challenge, experts said, because it involved changing DNS settings on the infected machines. In July, a U.S. federal court took action to take offline any remaining computers infected with the DNSChanger malware.

PUBLISHED FEB. 5, 2013

To continue reading this article, please download the free CRN Tech News app for your iPad or Windows 8 device.
Related: Videos | Slide Shows | Comments

SHARE THIS ARTICLE

More Security

Recent Articles

Tech 10: Hot Antivirus Alternatives For 2013

CRN identifies 10 vendors that have developed innovative ways to detect malware and analyze threats to better protect corporate networks. They take a giant step beyond traditional signature technologies.

10 Emerging Security Technologies Gaining Interest, Adoption

Despite some security defenses being only in their infancy, they are attracting interest for addressing BYOD issues, cloud security concerns and stolen account credentials. Here's a look at some of the top new security areas gaining industry interest.

5 Government Intelligence Facilities You've Never Heard Of

One facility has been around since the dawn of space exploration, while other buildings are still in construction. But, they all have serious data analysis and surveillance support activities associated with them.

  More Slide Shows




Related Videos
Loading...