All the latest UK technology news, reviews and analysis

Alleged Koobface gang members exposed

by Phil Muncaster

17 Jan 2012

Be the first to comment

  • Tweet this
Concept image representing virus malware

Security researchers have revealed the identities of five men they suspect of helping to mastermind the notorious Koobface attacks on social networking users.

Koobface came to prominence in 2008 as a piece of Trojan software generating messages to friends of infected users prompting them to click on a malicious link. Once infected, users' computers became part of the growing Koobface botnet, earning the gang millions of dollars a year, according to Sophos.

The worm targetted social networking users to take advantage of the greater trust levels users of these sites have when it comes to clicking on links purporting to come from friends or contacts.

Now, independent researcher Jan Dromer and the SophosLabs researcher Dirk Kollberg, believe they have found the men responsible, tracking them back to an office in St Petersburg.

"As in real life, a perfect (cyber) crime is something of a myth. The simple truth is that today's cyber crime landscape is aimed at achieving maximum revenue with minimal investment and that implies a certain level of accepted imperfection," the two wrote in a Sophos blog post.

"It is this imperfection, paired with a sense of ‘criminal arrogance' and an uncontrollable threat environment such as the internet that ultimately led to the identification of multiple suspects forming the ‘Koobface gang'."

The researchers explained that an oversight by the gang enabled public access to one of their command and control (C&C) servers, which, in turn, allowed investigators to view a detailed daily back-up of the C&C software.

Sophos senior technology consultant Graham Cluley explained that the matter now rests with the Russian police.

"We know the gang's names, their phone numbers, where their office is, what they look like, what cars they drive, even their mobile phone numbers," he added. "Now we have to wait and see what, if any, action the authorities will take against the Koobface gang."

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

Flame virus poll

Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?

41%

0%

10%

49%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Symanteccloud

Social networking: a guide for IT managers

Social networking is almost ubiquitous. This white paper examines the benefits and risks and it looks at the different ways companies can reconcile them

Riverbed

Mitigating the risks of IT change

The importance of understanding your infrastructure

Field Service Engineer - Dublin

The Role: As a Field Service Engineer working from...

Global Technical Support Representative - French Speaker

The Role: Make the most of your IT knowledge in one...

Head of IT / Infrastructure Manager (Marketing Services Group)

Head of IT / Infrastructure Manager (Marketing Services...

Business Development Executive

A Multi-national data analytic's and cloud computing...

To send to more than one email address, simply separate each address with a comma.