Wednesday, May 14, 2025
Germany Latest News
  • Sports
  • USA
  • Asia
  • Health
  • Life Style
  • Tech
  • Science
  • Latin America
  • Africa
  • Europe
No Result
View All Result
Germany Latest News

Mastermind behind sophisticated, massive botnet outs himself

by The Editor
December 5, 2017
in Tech
0
Mastermind behind sophisticated, massive botnet outs himself
EnlargeInvestigative Committee of Belarus

The mastermind behind some of the world's biggest and longest-running botnets has been jailed and his vast criminal infrastructure has been taken down, in part because of a careless operational security blunder that allowed authorities to identify his anonymous online persona.

Officials from the Republic of Belarus reported Monday they detained a participant in the sprawling Andromeda botnet network, which was made up of 464 separate botnets that spread more than 80 distinct malware families since 2011. On Tuesday, researchers with security firm Recorded Future published a blog post that said the participant was a 33-year-old Belarusian named Sergey Jarets.

To most people, Jarets was known only as "Ar3s," the moniker assigned to a highly respected elder in the criminal underground. In online discussions, Ar3s demonstrated expertise in malware development and the reverse engineering of software. He also acted as a reputable guarantor of deals that were hashed out online. As it turned out, the ICQ number of the figure he used as one of his primary contact methods was registered in several whitehat discussion forums to one Sergey Jaretz.

Recorded Future researchers said they eventually tracked the figure down to Jarets, who worked at OJSC "Televid" Tele-Radio Company, which broadcast throughout the Rechitsa area in the Gomel Region of Belarus. This LinkedIn profile shows Jarets was a technical director of OJSC "Televid" since 2003 and, among other things, was responsible for procurement, maintenance of the company’s computer network. The profile also showed he obtained a degree in software engineering around 2012.

"Based on the analysis of Ar3s's forum activities, linguistic patterns, and photo materials, Recorded Future earlier identified him as Sergey Jarets or Jaretz, a 33-year old male residing in Rechitsa, Gomel Region, Belarus," the authors of Tuesday's blog post wrote. The video below shows the man Belarusian authorities detained:

Malware as a service

Andromeda was primarily a service provided to other online criminals that made it easy for them to quickly spread their malicious wares. It allowed customers to build custom plug-ins for keylogging and rootkits for as little as $150, or it could serve as a platform for installing existing malware, including the Petya and Cerber ransomwares; the Neutrino bot for DDoS attacks; information-stealing malware known as Ursnif, Carberp, and Fareit; and the Lethic spam bot. The botnet network relied on more than 1,200 domains and IP addresses to control infected computers. Over the past six months, Microsoft detected or blocked the Andromeda bot on more than one million computers every month on average.

In many cases, the Andromeda malware was able to turn off firewalls, Windows updates, and User Account Control functions and prevent users from turning them back on until a computer was disinfected. Microsoft said Windows 10 machines were immune from the OS-tampering. Andromeda also recorded the keyboard-language settings. In the event the languages corresponded to to Belarus, Russia, Ukraine, or Kazahkstan, the malware would suspend infection operations, most likely in an attempt to prevent authorities in those countries from cracking down.

Jarets's alleged use of an easily traced ICQ number is a reminder of just how easy it is to make operational security mistakes. Andromeda also went by names including Gamarue and Wauchos. Microsoft and antivirus provider Eset have more information about the botnet and the takedown here and here.

Original Article

Ars Technica

Related posts

What Are the Pros and Cons of Sperm Freezing Technology?

What Are the Pros and Cons of Sperm Freezing Technology?

September 8, 2023
How Tech Partnerships Can Keep the E-Commerce Boom Going?

How Tech Partnerships Can Keep the E-Commerce Boom Going?

September 8, 2023
EnlargeInvestigative Committee of Belarus

The mastermind behind some of the world's biggest and longest-running botnets has been jailed and his vast criminal infrastructure has been taken down, in part because of a careless operational security blunder that allowed authorities to identify his anonymous online persona.

Officials from the Republic of Belarus reported Monday they detained a participant in the sprawling Andromeda botnet network, which was made up of 464 separate botnets that spread more than 80 distinct malware families since 2011. On Tuesday, researchers with security firm Recorded Future published a blog post that said the participant was a 33-year-old Belarusian named Sergey Jarets.

To most people, Jarets was known only as "Ar3s," the moniker assigned to a highly respected elder in the criminal underground. In online discussions, Ar3s demonstrated expertise in malware development and the reverse engineering of software. He also acted as a reputable guarantor of deals that were hashed out online. As it turned out, the ICQ number of the figure he used as one of his primary contact methods was registered in several whitehat discussion forums to one Sergey Jaretz.

Recorded Future researchers said they eventually tracked the figure down to Jarets, who worked at OJSC "Televid" Tele-Radio Company, which broadcast throughout the Rechitsa area in the Gomel Region of Belarus. This LinkedIn profile shows Jarets was a technical director of OJSC "Televid" since 2003 and, among other things, was responsible for procurement, maintenance of the company’s computer network. The profile also showed he obtained a degree in software engineering around 2012.

"Based on the analysis of Ar3s's forum activities, linguistic patterns, and photo materials, Recorded Future earlier identified him as Sergey Jarets or Jaretz, a 33-year old male residing in Rechitsa, Gomel Region, Belarus," the authors of Tuesday's blog post wrote. The video below shows the man Belarusian authorities detained:

Malware as a service

Andromeda was primarily a service provided to other online criminals that made it easy for them to quickly spread their malicious wares. It allowed customers to build custom plug-ins for keylogging and rootkits for as little as $150, or it could serve as a platform for installing existing malware, including the Petya and Cerber ransomwares; the Neutrino bot for DDoS attacks; information-stealing malware known as Ursnif, Carberp, and Fareit; and the Lethic spam bot. The botnet network relied on more than 1,200 domains and IP addresses to control infected computers. Over the past six months, Microsoft detected or blocked the Andromeda bot on more than one million computers every month on average.

In many cases, the Andromeda malware was able to turn off firewalls, Windows updates, and User Account Control functions and prevent users from turning them back on until a computer was disinfected. Microsoft said Windows 10 machines were immune from the OS-tampering. Andromeda also recorded the keyboard-language settings. In the event the languages corresponded to to Belarus, Russia, Ukraine, or Kazahkstan, the malware would suspend infection operations, most likely in an attempt to prevent authorities in those countries from cracking down.

Jarets's alleged use of an easily traced ICQ number is a reminder of just how easy it is to make operational security mistakes. Andromeda also went by names including Gamarue and Wauchos. Microsoft and antivirus provider Eset have more information about the botnet and the takedown here and here.

Original Article

Ars Technica

Previous Post

Mark Hix is on a mission to use every part of the chicken

Next Post

Dealmaster: Get a Dell desktop PC with an 8th-gen Core CPU for $850

Next Post
Dealmaster: Get a Dell desktop PC with an 8th-gen Core CPU for $850

Dealmaster: Get a Dell desktop PC with an 8th-gen Core CPU for $850

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

RECOMMENDED NEWS

New dating app uses your DNA to help you find love

New dating app uses your DNA to help you find love

7 years ago
Trudeau ‘snubbed’ by Indian government

Trudeau ‘snubbed’ by Indian government

7 years ago
Mercedes-Benz SL R107: The best classic Merc you can buy

Mercedes-Benz SL R107: The best classic Merc you can buy

7 years ago
Cobalt mining, China, and the fight for Congo’s minerals

Cobalt mining, China, and the fight for Congo’s minerals

7 years ago

FOLLOW US

  • 139 Followers
  • 87.2k Followers
  • 202k Subscribers

BROWSE BY CATEGORIES

  • 1xbet Casino Russia
  • 1xbet Russian Top
  • Africa
  • Asia
  • Europe
  • Health
  • latest news
  • Latin America
  • Life Style
  • Mail Order Brides
  • Mostbet
  • Online dating
  • onlyfans
  • Pin Up
  • Pin Up Russia
  • Science
  • Sports
  • Tech
  • Uncategorized
  • USA

BROWSE BY TOPICS

2018 League Bali United Beijing BlackBerry Brazil Broja Budget Travel Bundesliga California Champions League Chelsea China Chopper Bike Coronavirus COVID COVID-19 Crime Doctor Terawan EU France French German Istana Negara Italy Kazakhstan Market Stories Mexico National Exam Nigeria Omicron Pakistan Police protests Qatar Ronaldo Russia Smart Voting Sweden TikTok Trump UK Ukraine US vaccine Visit Bali
No Result
View All Result

Recent Posts

  • OnlyFans Platform Analysis
  • How to Day German Fashion
  • Southeast Continental Capabilities
  • What is a Mail Order Wife?
  • What to Discuss on a First Date?

Categories

  • 1xbet Casino Russia
  • 1xbet Russian Top
  • Africa
  • Asia
  • Europe
  • Health
  • latest news
  • Latin America
  • Life Style
  • Mail Order Brides
  • Mostbet
  • Online dating
  • onlyfans
  • Pin Up
  • Pin Up Russia
  • Science
  • Sports
  • Tech
  • Uncategorized
  • USA

Tags

2018 League Bali United Beijing BlackBerry Brazil Broja Budget Travel Bundesliga California Champions League Chelsea China Chopper Bike Coronavirus COVID COVID-19 Crime Doctor Terawan EU France French German Istana Negara Italy Kazakhstan Market Stories Mexico National Exam Nigeria Omicron Pakistan Police protests Qatar Ronaldo Russia Smart Voting Sweden TikTok Trump UK Ukraine US vaccine Visit Bali
Federal Government focuses on “integrated security”
latest news

Federal Government focuses on “integrated security”

by The Editor
June 14, 2023
0

Berlin (dpa) – The Federal Government is responding to the challenges of an increasingly unstable world order by means of a “policy...

Read more

Recent News

  • OnlyFans Platform Analysis
  • How to Day German Fashion
  • Southeast Continental Capabilities

Category

  • 1xbet Casino Russia
  • 1xbet Russian Top
  • Africa
  • Asia
  • Europe
  • Health
  • latest news
  • Latin America
  • Life Style
  • Mail Order Brides
  • Mostbet
  • Online dating
  • onlyfans
  • Pin Up
  • Pin Up Russia
  • Science
  • Sports
  • Tech
  • Uncategorized
  • USA

Recent News

OnlyFans Platform Analysis

June 12, 2024

How to Day German Fashion

May 5, 2024
  • About
  • Advertise
  • Careers
  • Contact

© 2025 JNews - Premium WordPress news & magazine theme by Jegtheme.

No Result
View All Result
  • Sports
  • USA
  • Asia
  • Health
  • Life Style
  • Tech
  • Science
  • Latin America
  • Africa
  • Europe

© 2025 JNews - Premium WordPress news & magazine theme by Jegtheme.