Microsoft's Kelihos botnet suspect used to work for computer security firm

Filed Under: Botnet, Featured, Law & order, Malware, Microsoft, Spam

Andrey Sabelnikov's LinkedIn photographMicrosoft has named a 31-year-old Russian, who used to work at a firm producing anti-virus and firewall software, believing him to be responsible for attacks perpetrated by the Kelihos botnet.

Andrey Sabelnikov, of St Petersburg, Russia, has been named in an amended complaint filed by the software giant with the US District Court.

Microsoft says it believes that Sabelnikov created the Kelihos malware, and alleges that he "used the malware to control, operate, maintain and grow the Kelihos botnet".

Furthermore, Microsoft alleges that Sabelnikov registered 3,723 "cz.cc" website subdomains, and misused those subdomains to operate and control the Kelihos botnet for the purposes of sending spam.

Diagram of Kelihos botnet

What is perhaps most surprising is Sabelnikov's background. According to his public LinkedIn profile, from 2005-2007 he was a senior developer and product manager at Agnitum, a Russian security firm well-known for its firewall software.

There is no suggestion that Agnitum are connected with the allegations, or that their security software - which includes anti-virus products - are compromised in any way.

Microsoft, working with the computer security industry, neutralised the Kelihos botnet in September 2011. Despite that Richard Boscovich, senior attorney for Microsoft's Digital Crimes Unit, says that thousands of computers remain infected and that the case "is not over."

A settlement was agreed last year between Microsoft and Dominique Piatti and his company dotFREE Group, which owned cz.cc, giving Microsoft control of the subdomains.

That also had the positive side effect of taking a number of websites offline that had been distributing the MacDefender family of malware which plagued Mac users last year.

, , , , , ,

One Response to Microsoft's Kelihos botnet suspect used to work for computer security firm

  1. superchicken says:

    what does sophos av detect this as?

Leave a Reply

Your email address will not be published. Required fields are marked *

*

You may use these HTML tags and attributes: <a href="" title="" rel=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <pre> <q cite=""> <strike> <strong>

About the author

Graham Cluley has worked in the computer security industry for more than 20 years, developing anti-virus software and doing quite a lot of talking about internet threats. He's won awards for his blogging, but is proudest of the text adventure games he wrote when he was still wearing short trousers. You can learn more about those (the games, not the trousers) at grahamcluley.com. Send Graham an email, subscribe to his updates on Facebook, follow him on Twitter and App.net, and circle him on Google Plus for regular updates.