Discover Yahoo! With Your Friends

Explore news, videos, and much more based on what your friends are reading and watching. Publish your own activity and retain full control.

To get started, first

YOUR FRIENDS' ACTIVITY

    How the FBI and Interpol trapped the world's biggest Butterfly botnet

    The biggest criminal botnet ever identified, with millions of enslaved computers in 172 countries, now has a name of its own – and embedded within the software that created it are the names of its criminal bot masters.

    The world's biggest criminal botnet, that has enslaved tens of millions of computers across 172 countries, now has a name: “Metulji," Slovenian for "butterfly." But even this monster butterfly could get netted.

    Earlier this month, the FBI and Interpol conducted "Operation Hive," which resulted in the arrests of two Metulji operators in Bosnia and Slovenia.

    But that may be just the beginning. Despite its mammoth size, the Metulji botnet has an Achilles heel that law enforcement and cyber security experts are exploiting: its criminal creator kept meticulous records of his customers.

    RECOMMENDED: Epsilon security breach: 5 signs it's only the tip of the iceberg

    Cheap to build, botnets are a stealthy, anonymous, nearly ideal criminal platform for Internet attacks against company websites. But they are even better at quietly stealing bank logons, passwords, credit card numbers, and social security numbers, says Karim Hijazi, CEO of Unveillance, the Wilmington, Del., botnet tracking company that discovered Metulji.

    "We're already pretty sure this botnet has stolen credentials that resulted in thefts totaling in the millions of dollars," says Mr. Hijazi. "We still don't know how many computers are part of this botnet yet. But we expect to have a pretty good idea before long."

    The creator of the sophisticated software kit – who made his money by selling it to those who wanted to build their own botnets – kept careful track of his customers’ criminal nicknames, Mr. Hijazi says. His “Butterfly Bot Kit” was also used to create the infamous Mariposa botnet, another gigantic botnet that at one point in 2009 had 12 million computers in 100 nations under its spell.

    Just two years later, Mariposa has been neutralized by law enforcement – in large part by tracking down the purchasers of the software.

    "The key here is that during the Mariposa case we discovered the licensing mechanism inside the Butterfly framework," says Luis Corrons, technical director of Panda Labs, whose company is assisting in the analysis of the new botnet. "These licenses are in the form of bot master nicknames, which are ... tied to the sales made to all bot masters who purchased a Butterfly botnet."

    The Metulji botnet was created with a more advanced version of the Butterfly Bot Kit – but it, too, keeps purchase records. Since the Butterfly framework creator was arrested and his computers confiscated, it is "safe to assume" that law enforcement has "very good insight into who is running ANY Butterfly-based botnet out there," Mr. Corrons writes in an e-mail

    Oddly, despite a number of Mariposa-linked arrests last year in Spain and Slovenia, bot masters are still depending on the Butterfly framework to run their Metulji botnets.

    "Obviously, those bot masters are either not concerned about going to jail or just plain stupid," Corrons adds.

    RECOMMENDED: Gmail breach: Eight tips to protect your e-mail account

     

    239 comments

    • jayk  •  10 mths ago
      Why should they fear jail? the more money you steal, the less time you do.
      • A Yahoo! User 10 mths ago
        How so? Madoff isn't in jail. He's in FEDERAL PRISION. Which means he lives better than about 70% of the US population.
      • CB 10 mths ago
        ITS THAT THE AMERICAN WAY STEAL FROM THE POOR AND GIVE TO THE RICH CARTEL BANKSTERS ITS NO WONDER GREECE IS GOING UNDER THEY PLAYED THE SCAM ON THEM ................ THE GREEDY NOT THE NEEDY
    • Ntexas  •  10 mths ago
      i am starting an international sting operation. death to hackers. snitch on a hacker and get a minimum 25k bounty.
      • Joel 10 mths ago
        Haha only hackers know other hackers. And why would they need you 25k to snitch when they could just take your credit card number and buy your wife out from under you
      • bestillandknow 10 mths ago
        Yeaaaah!!! Except for the death thing, you have the right idea.
      • sam 10 mths ago
        Keep talking s***. You use a computer, idiot. They'll take your 25k and post a bounty on your own head with you own money
    • Im comin Lizbeth  •  10 mths ago
      the creators deserve the death penalty for the financial harm they have caused
    • Sandman760  •  10 mths ago
      lets see how good they realy are.......get rid of the spam on yahoo
      • mch8545 10 mths ago
        AND PHOTOS ARE SHOWN MAKE THEM LARGE ENOUGH FOR DETAILED VIEWING, LIKE FLOATING CHINESE GUYS....
      • initiate of odin 10 mths ago
        as well as bad spellers and idiots who use ALL CAPS.
      • Miked 10 mths ago
        There's no spam on yahoo.. around here, they like to call them "Articles"
    • Hoo Suk Dong  •  10 mths ago
      The minute they catch these guys, some other software developer will modify the software and start the "botnet" process all over again.
      • 100 10 mths ago
        you mean some other lazy fck, these a holes are not developing anything except a worn out spot in the chair in front of their computor in their parents basement at the age of 30, LOSERS!! cast out by the legitamate computor programmers, they probably dont take a bath more than once a month, hitting the bong between kitchen visits and bathroom visits, then back to the screen to get back at everyone who"did them wrong"
      • Jake 10 mths ago
        @100 you're angry and I'm not sure why.

        Most of the top-class criminal "genius" hackers could do amazing things for good if they were so inclined. The software they develop and the way it acts is some of the most impressive stuff ever written. It's truly sad there isn't a better use for that talent (other than the good guys that are employed for the tech companies, hunting down these flaws to seal em up before a bad hacker exploits the weakness).
      • Beowolfe 10 mths ago
        @HooSukDong......that's not a reason to stop trying to stop them. Remember, the oldest human artifacts ever found were keys. Humans have been stealing for a very long time.
    • citizenUSA  •  10 mths ago
      Ya....but they can't catch the Banksters that are stealing our money
      • Lord Velos 10 mths ago
        You said it! Banks are thieving my money more than anyone else these days!
      • Alter Ego 10 mths ago
        Screw that, capture the out of control senate and it's leader.
      • JCW of LA 10 mths ago
        Yes! you are absolutely right. Those bankster are licensed by our government to steal our money legally.
    • Ernest Cruzen  •  10 mths ago
      I wish the government would stop being loud-mouth and braggard on how, just report they were arrested- don't give any details for the enemies and criminals can always find counter-measures and may even make it harder to arrest them and in the worst case scenario, the good guys will never know and not be able to arrest in the future. Remember loose lips sink ships.
    • A Yahoo! user  •  10 mths ago
      So much rage for small-time criminals when billions were looted from treasury coffers during the financial crisis and nary a single scoundrel has had to pay the price for it. Where is the outrage?
    • What Was That Again  •  10 mths ago
      Sounds more like a scare tactic than criminal investigation. "We might know who you are, so tell us your names now!" I imagine most people involved are simply chucking to themselves and switching to plans B, C and D.
    • The Mindful Lunatic  •  10 mths ago
      The funny yet ironic ting is, having found these guys the government will most likely give them a slap on the wrists, and then offer them a job. It happens! Some of the most vicious and creative hackers in the world who were once against corporations and governments are now employees of such institutions! Illegal activity and shady actions are rewarded and not disciplined...
    • MarkB  •  10 mths ago
      Bankers don't need botnets to steal money.
    • tanya r  •  10 mths ago
      Endless Conspiracys...Anyone hacking my computer will die of bordom...Great Aunt Jen's jelly receipes did I mention she will be 93 this year.....I think you get the point
    • Anonymous  •  10 mths ago
      Now that was well spent tax dollars to protect us. Thank you.
    • StevenG  •  10 mths ago
      Just go after the execs @ Bank of America, biggest thieves in the country.
    • Old Rusty Tulsa  •  10 mths ago
      When caught just chop off the balls, that will get there attention.
    • RichardD  •  10 mths ago
      The article says a lot without saying anything. Typical want to write a story but can't say anything.
    • tomcib  •  10 mths ago
      These scumbags make the Russians look like they have class.
    • A Yahoo! User  •  10 mths ago
      Take these %%$%#$## and shoot them.When people like these cause so much grief to so many people they deserve nothing less than the death penalty,and it would be a deterrent to others.
    • Ralph  •  10 mths ago
      Cultural Learnings of America for Make Benefit Glorious Nation of Slovenia
    • Soupah  •  10 mths ago
      No surprise there that the criminals hail from Eastern Europe. Biggest perpetrators of fraud in the financial industry hail from this area of the world. Bosnians, Slovenians, Armenians, Russians.... I don't trust any of them.
    [ [ [['Connery is an experienced stuntman', 2]], 'http://yhoo.it/KeQd0p', '[Slideshow: See photos taken on the way down]', ' ', '630', ' ', ' ', ], [ [['Connery is an experienced stuntman', 7]], ' http://yhoo.it/KpUoHO', '[Slideshow: Death-defying daredevils]', ' ', '630', ' ', ' ', ], [ [['know that we have confidence in', 3]], 'http://yhoo.it/LqYjAX ', '[Related: The Secret Service guide to Cartagena]', ' ', '630', ' ', ' ', ], [ [['We picked up this other dog and', 5]], 'http://yhoo.it/JUSxvi', '[Related: 8 common dog fears, how to calm them]', ' ', '630', ' ', ' ', ], [ [['accused of running a fake hepatitis B', 5]], 'http://bit.ly/JnoJYN', '[Related: Did WH share raid details with filmmakers?]', ' ', '630', ' ', ' ', ], [ [['accused of running a fake hepatitis B', 3]], 'http://bit.ly/KoKiqJ', '[Factbox: AQAP, al-Qaeda in Yemen]', ' ', '630', ' ', ' ', ], [ [['have my contacts on or glasses', 3]], 'http://abcn.ws/KTE5AZ', '[Related: Should the murder charge be dropped?]', ' ', '630', ' ', ' ', ], [ [['have made this nation great as Sarah Palin', 5]], 'http://yhoo.it/JD7nlD', '[Related: Bristol Palin reality show debuts June 19]', ' ', '630', ' ', ' ', ], [ [['have made this nation great as Sarah Palin', 1]], 'http://bit.ly/JRPFRO', '[Related: McCain adviser who vetted Palin weighs in on VP race]', ' ', '630', ' ', ' ', ], [ [['A JetBlue flight from New York to Las Vegas', 3]], 'http://yhoo.it/GV9zpj', '[Related: View photos of the JetBlue plane in Amarillo]', ' ', '630', ' ', ' ', ], [ [['the 28-year-old neighborhood watchman who shot and killed', 15]], 'http://news.yahoo.com/photos/white-house-stays-out-of-teen-s-killing-slideshow/', 'Click image to see more photos', 'http://l.yimg.com/cv/ip/ap/default/120411/martinzimmermen.jpg', '630', ' ', 'AP', ], [ [['Titanic', 7]], 'http://news.yahoo.com/titanic-anniversary/', ' ', 'http://l.yimg.com/a/p/us/news/editorial/b/4e/b4e5ad9f00b5dfeeec2226d53e173569.jpeg', '550', ' ', ' ', ], [ [['He was in shock and still strapped to his seat', 6]], 'http://news.yahoo.com/photos/navy-jet-crashes-in-virginia-slideshow/', 'Click image to see more photos', 'http://l.yimg.com/cv/ip/ap/default/120406/jet_ap.jpg', '630', ' ', 'AP', ], [ [['xxxxxxxxxxxx', 11]], 'http://news.yahoo.com/photos/russian-grannies-win-bid-to-sing-at-eurovision-1331223625-slideshow/', 'Click image to see more photos', 'http://l.yimg.com/a/p/us/news/editorial/1/56/156d92f2760dcd3e75bcd649a8b85fcf.jpeg', '500', ' ', 'AP', ] ]
    [ [ [['did not go as far his colleague', 8]], '29438204', '0' ], [ [[' the 28-year-old neighborhood watchman who shot and killed', 4]], '28924649', '0' ], [ [['because I know God protects me', 14], ['Brian Snow was at a nearby credit union', 5]], '28811216', '0' ], [ [['The state news agency RIA-Novosti quoted Rosaviatsiya', 6]], '28805461', '0' ], [ [['measure all but certain to fail in the face of bipartisan', 4]], '28771014', '0' ], [ [['matter what you do in this case', 5]], '28759848', '0' ], [ [['presume laws are constitutional', 7]], '28747556', '0' ], [ [['has destroyed 15 to 25 houses', 7]], '28744868', '0' ], [ [['short answer is yes', 7]], '28746030', '0' ], [ [['opportunity to tell the real story', 7]], '28731764', '0' ], [ [['entirely respectable way to put off the searing constitutional controversy', 7]], '28723797', '0' ], [ [['point of my campaign is that big ideas matter', 9]], '28712293', '0' ], [ [['As the standoff dragged into a second day', 7]], '28687424', '0' ], [ [['French police stepped up the search', 17]], '28667224', '0' ], [ [['Seeking to elevate his candidacy back to a general', 8]], '28660934', '0' ], [ [['The tragic story of Trayvon Martin', 4]], '28647343', '0' ], [ [['Karzai will get a chance soon to express', 8]], '28630306', '0' ], [ [['powerful storms stretching', 8]], '28493546', '0' ], [ [['basic norm that death is private', 6]], '28413590', '0' ], [ [['songwriter also saw a surge in sales for her debut album', 6]], '28413590', '1', 'Watch music videos from Whitney Houston ', 'on Yahoo! Music', 'http://music.yahoo.com' ], [ [['keyword', 99999999999999999999999]], 'videoID', '1', 'overwrite-pre-description', 'overwrite-link-string', 'overwrite-link-url' ] ]