“Hacker Ring” busted by the SQ and the RCMP (2)
I caught the reports that the Sécurité du Québec and the Royal Canadian Mounted Police raided 12 locations early wednesday, and arrested 16 “hackers” who allegedly were running through a botnet more than one million PCs tlocated in Manitoba, US, Brazil and Poland.
If you go through the news reports, this is all very spectacular. “Hackers” were aged from 17 to 26, and allegedly made up to $45 million through ID theft and phishing. Police is said to have begun investigation since the summer of 2006.
Bot networks are created through trojans, worms, or “malware”, propagated from PC to PC through backdoors. Worms creators for instance craft messages for the Valentine’s day or any other special event that might deceive innocent users. Upon opening the message, the worm is installed and begins to replicate by going through the user’s address book for instance.
Bot networks are rented to send spams. They can also be used for denial of service attacks, like the famously known attack on Estonian government websites in May last year. A few of them are also used for phising and Identity theft, although the latter use is stupid, because it’s always possible to retrace the creators of the scheme through DNS and investigations, which is what the SQ and RCMP did.
I find though that the official figures in this case were overblown. I’ve done some research and couldn’t find the name of the group, which is surprising for a botnet running 1M+ bots. It just seems a random group of teenagers who downloaded a couple of trojans and worms generators. It’s also funny to hear a SQ rep saying that they were guilty of “hacking”, a word I am sure he doesn’t really understand.




James Golick









