Sunday, September 23, 2018

Operator of Counter Antivirus Service “Scan4you” Sentenced to 14 Years in Prison


A Latvian “non-citizen,” meaning a citizen of the former USSR who resided in Riga, Latvia, was sentenced to 168 months in prison today for offenses related to his operation of “Scan4you,” an online counter antivirus service that helped computer hackers determine whether the computer viruses and other malicious software they created would be detected by antivirus software, announced Assistant Attorney General Brian A. Benczkowski of the Justice Department’s Criminal Division, U.S. Attorney G. Zachary Terwilliger of the Eastern District of Virginia, and Special Agent in Charge Matthew J. DeSarno of the FBI Washington Field Office’s Criminal Division.

Ruslans Bondars, 38, was convicted on May 16, following a five-day jury trial, of one count of conspiracy to violate the Computer Fraud and Abuse Act, one count of conspiracy to commit wire fraud, and one count of computer intrusion with intent to cause damage and aiding and abetting.

“Ruslans Bondars helped malware developers attack American businesses,” said Assistant Attorney General Benczkowski.  “The Department of Justice and its law enforcement partners make no distinction between service providers like Scan4You and the hackers they assist:  we will hold them accountable for all of the significant harm they cause and work tirelessly to bring them to justice, wherever they may be located.”

“Ruslans Bondars designed and operated a service that provided essential aid to some of the world’s most destructive hackers,” said U.S. Attorney Terwilliger. “This prosecution demonstrates our commitment to combating global computer crime by taking away the essential tools upon which hackers rely.”

“We continue to face sophisticated cyber threats from state-sponsored hackers, hackers for hire, organized cyber syndicates, and terrorists,” said FBI Special Agent in Charge DeSarno. “This prosecution should serve as an example to those who assist or facilitate criminal hacking activity that they will be exposed and held accountable no matter where they are in the world.”

According to testimony at trial and court documents, from at least 2009 until 2016, Bondars operated Scan4you, which for a fee provided computer hackers with information they used to determine whether their malware would be detected by antivirus software, including and especially by antivirus software used to protect major U.S. retailers, financial institutions and government agencies from computer intrusions.

A Scan4you customer, for example, used the service to test malware that was subsequently used to steal approximately 40 million credit and debit card numbers, as well as approximately 70 million addresses, phone numbers and other pieces of personal identifying information, from retail store locations throughout the United States, causing one retailer approximately $292 million in expenses resulting from the intrusion.  

Another Scan4you customer used the service to assist the development of “Citadel,” a widely used malware strain that was used to infect over 11 million computers worldwide, including in the United States, and resulted in over $500 million in fraud-related losses.  The Citadel developer took advantage of a special feature of Scan4you that allowed its integration directly into the Citadel malware toolkit through an Application Programming Interface, or API.  The API tool allowed Scan4you users the flexibility to scan malware without the need to directly submit the malware to Scan4you’s website.

At its height, Scan4you was one of the largest services of its kind and had at least thousands of users.  Malware developed with the assistance of Scan4you included some of the most prolific malware known to the FBI and was used in major computer intrusions committed against American businesses.

Scan4you differed from legitimate antivirus scanning services in multiple ways.  For example, while legitimate scanning services share data about uploaded files with the antivirus community and notify their users that they will do so, Scan4you instead informed its users that they could upload files anonymously and promised not to share information about the uploaded files with the antivirus community.

In issuing the sentence, the court found a loss amount of $20.5 billion.  In addition to the term of imprisonment, U.S. District Judge Liam O’Grady ordered Bondars to serve three years of supervised release.  A decision regarding forfeiture and payment of restitution to victims of the offenses is forthcoming.

The FBI Washington Field Office investigated the case.  Trial Attorneys C. Alden Pelker and Ryan K. Dickey of the Criminal Division’s Computer Crime and Intellectual Property Section (CCIPS) and Assistant U.S. Attorneys Kellen Dwyer and Laura Fong of the Eastern District of Virginia prosecuted the case. The Government of Latvia, including the Latvia State Police International Cooperation Department, the Latvia State Police Cybercrime Unit, and the General Prosecutor’s Office of the Republic of Latvia – International Cooperation Division, provided assistance and support during the investigation.  Additional assistance was provided by the Criminal Division’s Office of International Affairs, the FBI’s Atlanta Field Office and the Operational Technology Division, and the U.S. Attorney’s Offices for the District of Minnesota and the Northern District of Georgia.

Saturday, September 22, 2018

Rhode Island Man Sentenced for Cyberstalking


Howard Bishop engaged in an endless pattern of abusive and threatening behavior toward a former girlfriend and her family, causing the woman to be taken into protective custody

PROVIDENCE, RI – A North Smithfield, R.I., man who repeatedly sent emails and text messages to a former girlfriend threatening, in specific and horrifying detail, to harm or kill her and her family was sentenced today to 41 months in federal prison on cyberstalking charges, announced United States Attorney Stephen G. Dambruch and Harold H. Shaw, Special Agent in Charge of the FBI Boston Division.

Howard S. Bishop, 39, was arrested in Rhode Island by FBI agents in January 2018, approximately four months after relocating from Texas to his family’s home in North Smithfield.

The threats from Bishop against his former girlfriend in Texas, and her family, were so severe that the woman was placed in FBI protective custody until Bishop was arrested. Her family hired around-the-clock armed security to guard their home.

At sentencing, U.S. District Court Chief Judge William E. Smith also ordered Bishop to serve 3 years supervised release upon completion of his term of incarceration. Bishop pleaded guilty in May to transmitting in interstate commerce communications containing threats to injure another person, and with harassing or intimidating another person, using an interactive computer service or electronic communication service, that placed a person in reasonable fear of death or serious bodily injury and caused substantial emotional distress.

The U.S. Sentencing Guidelines range of imprisonment in this matter is 33 – 41 months. The government recommended the Court impose a sentence of 41 months in prison.

According to court records, in February 2011, a former girlfriend of Bishop obtained a protective order against him in Travis County, TX, after their relationship ended. After the relationship ended, Bishop engaged in an endless pattern of abusive and threatening behavior towards the woman. In January 2012, Bishop was found guilty of violating the order and received a sentence of two years’ probation. In December 2017, a misdemeanor warrant was issued in Travis County for the arrest of Bishop for again violating the protective order.

According to court documents, beginning in November 2016, and continuing until his arrest in Rhode Island in January 2018, Bishop sent hundreds of harassing and threatening messages via the Internet to the former girlfriend and her family. They expressed extreme fear for their safety.

Bishop has been detained in federal custody since his arrest.

The case was prosecuted by Assistant U.S. Attorney Lee H. Vilker.

The matter was investigated by the FBI.

Friday, September 21, 2018

Hackers’ Cooperation with FBI Leads to Substantial Assistance in Other Complex Cybercrime Investigations


Defendants Responsible for Creating the “Mirai” and Clickfraud Botnets Continue to Assist FBI as Part of their Sentencing

Anchorage, Alaska – U.S. Attorney Bryan Schroder announced today that three defendants have been sentenced for their roles in creating and operating two botnets, which targeted “Internet of Things” (IoT) devices.  Paras Jha, 22, of Fanwood, New Jersey; Josiah White, 21, of Washington, Pennsylvania; and Dalton Norman, 22, of Metairie, Louisiana, were sentenced today by Chief U.S. District Judge Timothy M. Burgess.  On Dec. 8, 2017, Jha, White, and Norman pleaded guilty to criminal Informations in the District of Alaska charging them each with conspiracy to violate the Computer Fraud & Abuse Act in operating the Mirai Botnet.  Jha and Norman also pleaded guilty to two counts each of the same charge, one in relation to the Mirai botnet and the other in relation to the Clickfraud botnet.

After cooperating extensively with the FBI, Jha, White, and Norman were each sentenced to serve a five-year period of probation, 2,500 hours of community service, ordered to pay restitution in the amount of $127,000, and have voluntarily abandoned significant amounts of cryptocurrency seized during the course of the investigation.  As part of their sentences, Jha, White, and Norman must continue to cooperate with the FBI on cybercrime and cybersecurity matters, as well as continued cooperation with and assistance to law enforcement and the broader research community.  According to court documents, the defendants have provided assistance that substantially contributed to active complex cybercrime investigations as well as the broader defensive effort by law enforcement and the cybersecurity research community.

Jha, White, and Norman became subjects of a federal investigation when, in the summer and fall of 2016, they created a powerful botnet – a collection of computers infected with malicious software and controlled as a group without the knowledge or permission of the computers’ owners.  The Mirai Botnet targeted IoT devices – non-traditional computing devices that were connected to the Internet, including wireless cameras, routers, and digital video recorders.  The defendants attempted to discover both known and previously undisclosed vulnerabilities that allowed them to surreptitiously attain control over the victim devices for the purpose of forcing the devices to participate in the Mirai Botnet.  At its peak, Mirai consisted of hundreds of thousands of compromised devices.  The defendants used the botnet to conduct a number of powerful distributed denial-of-service, or “DDoS” attacks, which occur when multiple computers, acting in unison, flood the Internet connection of a targeted computer or computers.  The defendants’ involvement with the original Mirai variant ended in the fall of 2016, when Jha posted the source code for Mirai on a criminal forum. Since then, other criminal actors have used Mirai variants in a variety of other attacks.

Additionally, from December 2016 to February 2017, the defendants successfully infected over 100,000 primarily U.S.-based computing devices, such as home Internet routers, with malicious software.  That malware caused the hijacked home Internet routers and other devices to form a powerful botnet.  The victim devices were used primarily in advertising fraud, including “clickfraud,” a type of Internet-based scheme that makes it appear that a real user has “clicked” on an advertisement for the purpose of artificially generating revenue.

“Cybercrime is a worldwide epidemic that reaches many Alaskans,” said U.S. Attorney Bryan Schroder.  “The perpetrators count on being technologically one step ahead of law enforcement officials.  The plea agreement with the young offenders in this case was a unique opportunity for law enforcement officers, and will give FBI investigators the knowledge and tools they need to stay ahead of cyber criminals around the world.”

“The sentences announced today would not have been possible without the cooperation of our partners in international law enforcement and the private sector,” said Special Agent in Charge of FBI’s Anchorage Field Office, Jeffery Peterson.  “The FBI is committed to strengthening those relationships and finding innovative ways to counter cybercrime.  Cyber criminals often develop their technical skills at a young age.  This case demonstrates our commitment to hold criminals accountable while encouraging offenders to choose a different path to apply their skills.”

These cases were investigated by the FBI’s Anchorage Field Office.  The Mirai Botnet and Clickfraud Botnet cases were prosecuted by Assistant U.S. Attorney Adam Alexander of the District of Alaska and Trial Attorney C. Alden Pelker of the Computer Crime and Intellectual Property Section of the Justice Department’s Criminal Division.  Additional assistance was provided by the FBI’s Newark, New Orleans and Pittsburgh Field Offices, Homeland Security Investigations (HSI) Atlanta – Greenville South Carolina Office, the U.S. Attorneys’ Offices for the Eastern District of Louisiana and New Jersey, the United Kingdom’s National Crime Agency, the French General Directorate for Internal Security, the Police Service of Northern Ireland, the National Cyber-Forensics & Training Alliance, Palo Alto Networks Unit 42, Google, Cloudflare, Coinbase, Flashpoint, Oath, 360.cn and Akamai.  Former Department of Justice prosecutors Ethan Arenson, Harold Chun, and Yvonne Lamoureux provided invaluable support during their tenure at DOJ.