All the latest UK technology news, reviews and analysis

Microsoft names Kelihos botnet suspect

by Khidr Suleman

24 Jan 2012

Be the first to comment

  • Tweet this

Microsoft has named the suspect that it believes was involved in operating the Kelihos botnet that was shutdown in September.

In an amended complaint filed with the US District Court for the Eastern District of Virginia, Microsoft alleged that Russian citizen Andrey Sabelnikov was responsible for the operations of the notorious botnet.

Sabelnikov has been accused of registering more than 3,700 "cz.cc" subdomains and using them to operate and control the Kelihos botnet, according to Richard Domingues Boscovich, senior attorney of Microsoft's digital crimes unit, writing on the Official Microsoft Blog.

"Microsoft presented evidence to the court that Sabelnikov wrote the code for and either created, or participated in creating, the Kelihos malware. Further, the complaint alleges that he used the malware to control, operate, maintain and grow the Kelihos botnet," he said.

"Further, the complaint alleges that he used the malware to control, operate, maintain and grow the Kelihos botnet. These allegations are based on evidence Microsoft investigators uncovered while analysing the Kelihos malware."

The firm has already settled two cases against owners whose sub domains were used to operate the botnet after the firm reached a deal with Dominique Alexander Piatti and his company dotFree Group, a hosting firm accused of harbouring malware writers and botnet distributors, in November.

Microsoft warned, though, that while the Kelihos botnet has been inactive since September, there are still thousands of computers infected with its malware.

"This case is certainly not over. Look for more updates as the Kelihos investigation and Microsoft's overall fight to disrupt botnets continue," Boscovich added.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

Flame virus poll

Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?

41%

0%

10%

49%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Symanteccloud

Social networking: a guide for IT managers

Social networking is almost ubiquitous. This white paper examines the benefits and risks and it looks at the different ways companies can reconcile them

Riverbed

Mitigating the risks of IT change

The importance of understanding your infrastructure

Pharma IT Quality Manager

On behalf of our client, a major player in the pharmaceutical...

Martini Repo Developer / Lead Developer, Singapore

Qualifications & Skills - Previous development...

Senior Project Manager

Harvey Nash is currently recruiting a senior project...

.Net Developer

URS supplies integrated engineering, environmental and...

To send to more than one email address, simply separate each address with a comma.