You are here: silicon.com > Software > Malware

Malware

Zotob author linked to credit card fraud ring

And other virus nasties...

Tags: zotob, virus, fraud, worm

By Joris Evers

Published: 31 August 2005 09:55 BST

Turkish authorities have linked one of the suspects in the Zotob worm case to individuals thought to be part of a credit card fraud ring, according to the FBI.

Atilla Ekici, a 21-year-old Turk who used the nickname "Coder", may be affiliated with people thought to be part of a credit card fraud ring in Turkey, an FBI representative said on Tuesday. Ekici was one of two men arrested last week for allegedly unleashing several computer worms, including the Zotob worm that disrupted businesses worldwide two weeks ago.

Turkish authorities have identified about a dozen individuals thought to be involved in credit card fraud. The FBI representative said: "It is believed that these individuals have links to Coder. The investigation is still ongoing but there is no indication these people actually wrote or distributed the Zotob worm."

Zotob attacked computers running Microsoft's Windows 2000 operating system. The worm and its offshoots hit PCs and servers worldwide two weeks ago, including machines at ABC, CNN and Daimler Chrysler.

Ekici along with Farid Essebar, an 18-year-old Moroccan national born in Russia, are believed to be responsible for Zotob and the earlier Mytob and Rbot worms. Essebar was arrested in Morocco on Thursday of last week, the same day authorities nabbed Ekici.

The suspected link to a credit card fraud ring expands the possible financial motivation for the Zotob and Mytob worm attacks. The FBI last week said it believes Essebar wrote both worms and then sold them to Ekici.

Both Mytob and Zotob attack Windows computers and feature backdoor capabilities. Criminals could use this backdoor to install software that spies on users or to install "bot" programs that create "botnets", networks of hijacked PCs that are rented out to relay spam or attack other systems.

Meanwhile, experts at antivirus company Sophos said they believe Essebar may have had a hand in more than 20 computer pests. The teen's handle, "Diabl0", appears in more than 20 other viruses and worms, including Mydoom-BG and many versions of Mytob, which are currently dominating worldwide virus reports, according to Sophos.

Zotob and its variants exploited a security hole in the plug-and-play feature in the OS, for which Microsoft provided a fix earlier this month. Zotob included some of the code used in Mytob, an email worm that first started spreading in March. To date, more than 100 variants of Mytob have been spotted. The worm is distributed via mass email campaigns.

The investigation into the Mytob and Zotob worms is ongoing and other suspects may be arrested, according to the FBI.

Joris Evers writes for CNET News.com

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

  • Jobs
SAS Programmer/Statistician 25-34k Nottingham

Knowledge of Credit Card economics. You role will consist of working with high levels of data within the credit card industry, utilising you SAS ...

Project Manager c.48k Credit Reference Agency Experience (desirable)

Experience of the processes required to implement software solutions in a consumer finance (credit card; loans; store card; mortgage) environment. A ...

Risk Strategy & Development Senior Analyst London - 40,000

The department you will be joining works off transactions and other similar data from the brands credit card. In-depth experience throughout ...

CIO50 2008
The silicon.com CIO50 2008 profiles the most influential and innovative tech chiefs in the UK across all industries and organisation size, from the biggest FTSE100 companies to high growth dot-com start ups and the public sector. The list was voted on by the UK CIO community and a panel of experts. Find out more in our latest special report.





Quick Sitemap Links: