Microsoft's Kelihos botnet suspect used to work for computer security firm

Filed Under: Botnet, Featured, Law & order, Malware, Microsoft, Spam

Andrey Sabelnikov's LinkedIn photographMicrosoft has named a 31-year-old Russian, who used to work at a firm producing anti-virus and firewall software, believing him to be responsible for attacks perpetrated by the Kelihos botnet.

Andrey Sabelnikov, of St Petersburg, Russia, has been named in an amended complaint filed by the software giant with the US District Court.

Microsoft says it believes that Sabelnikov created the Kelihos malware, and alleges that he "used the malware to control, operate, maintain and grow the Kelihos botnet".

Furthermore, Microsoft alleges that Sabelnikov registered 3,723 "" website subdomains, and misused those subdomains to operate and control the Kelihos botnet for the purposes of sending spam.

Diagram of Kelihos botnet

What is perhaps most surprising is Sabelnikov's background. According to his public LinkedIn profile, from 2005-2007 he was a senior developer and product manager at Agnitum, a Russian security firm well-known for its firewall software.

There is no suggestion that Agnitum are connected with the allegations, or that their security software - which includes anti-virus products - are compromised in any way.

Microsoft, working with the computer security industry, neutralised the Kelihos botnet in September 2011. Despite that Richard Boscovich, senior attorney for Microsoft's Digital Crimes Unit, says that thousands of computers remain infected and that the case "is not over."

A settlement was agreed last year between Microsoft and Dominique Piatti and his company dotFREE Group, which owned, giving Microsoft control of the subdomains.

That also had the positive side effect of taking a number of websites offline that had been distributing the MacDefender family of malware which plagued Mac users last year.

, , , , , ,

You might like

One Response to Microsoft's Kelihos botnet suspect used to work for computer security firm

  1. superchicken ยท 1353 days ago

    what does sophos av detect this as?

Leave a Reply

Fill in your details below or click an icon to log in: Logo

You are commenting using your account. Log Out / Change )

Twitter picture

You are commenting using your Twitter account. Log Out / Change )

Facebook photo

You are commenting using your Facebook account. Log Out / Change )

Google+ photo

You are commenting using your Google+ account. Log Out / Change )

Connecting to %s

About the author

Graham Cluley runs his own award-winning computer security blog at, and is a veteran of the anti-virus industry having worked for a number of security companies since the early 1990s. Now an independent security analyst, he regularly makes media appearances and gives computer security presentations. Follow him on Twitter at @gcluley