Email this article   Print article 


Estonian Man Pleads Guilty For Role In DNSChanger Attacks

By Robert Westervelt
February 05, 2013    10:32 AM ET

An Estonian man pleaded guilty in U.S. federal court for his role in spreading the DNSChanger malware, designed to hijack infected computers and redirect them to malicious websites. The scheme, which lasted for five years, is believed to have generated upward of $14 million in fraudulent Internet advertising revenue. At least 4 million computers in 100 countries were infected by the malware, creating a large botnet.

Valeri Aleksejev, 32, pleaded guilty to conspiracy to commit wire fraud and conspiracy to commit computer intrusion, according to a Reuters report. He faces up to 25 years in prison, deportation and the forfeiture of $7 million. Aleksejev was the first to enter a plea among the six Estonians and one Russian who were indicted in 2011. They were indicted on five charges each of wire and computer intrusion. One of the defendants, Vladimir Tsastsin, also was charged with 22 counts of money laundering.

[Related: Federal Government Acts Against Trojan]

The DNSChanger Botnet was taken down in 2011 when the FBI and Estonian national police made arrests in that country, while data centers in New York and Chicago that served as the command-and-control infrastructure for the botnet where shut down.

Users were impacted by DNSCharger when trying to access the websites of Apple iTunes, Netflix and Facebook and were instead redirected to unaffiliated businesses. The scam also involved replacing legitimate advertisements on websites with advertisements that resulted in payments to the fraudsters.

DNSChanger was first detected in 2006. The attacks were traced to a legitimate Estonian company, which was being used to control the compromised machines.

Antivirus has been able to detect the malware, but cleaning up the infected computers had been a challenge, experts said, because it involved changing DNS settings on the infected machines. In July, a U.S. federal court took action to take offline any remaining computers infected with the DNSChanger malware.

PUBLISHED FEB. 5, 2013

To continue reading this article, please download the free CRN Tech News app for your iPad or Windows 8 device.
Related: Videos | Slide Shows | Comments

SHARE THIS ARTICLE

More Security

Recent Articles

Head-To-Head: Symantec Vs. McAfee In Endpoint Protection

McAfee and Symantec are archrivals with a firm grip on the North American security market. CRN pits both vendors' endpoint security products against each other and names a winner.

The 8 Steps Behind The Massive $45M Cyber Bank Heist

More than $45 million was stolen from banks in the U.S. and 19 other countries in a scheme that law enforcement is calling an international conspiracy to drain millions from bank accounts using stolen debit cards and PIN numbers. Here's how they did it.

Name Of The Game: Top 10 States For Identity Theft

A Federal Trade Commission report provides statistics on identity theft and fraud complaints in 2012. Learn which state has the dubious distinction of having the most victims.

  More Slide Shows




Related Videos
Loading...