Monday, February 11, 2008

Minor Teen, Ancheta Associate Pleads Guily to Charges

Dan Goodin writes on The Register:

A young hacker accused of helping to corral more than 400,000 computers into a money-making botnet has pleaded guilty to criminal charges in connection with the scheme, which he admits damaged US military computers.

The defendant was identified only by the the initials B.D.H. because he was a juvenile when the crimes were committed. He is better known by the handle "SoBe" in internet relay channels frequented by hackers. He appeared in US District Court in Los Angeles on Monday, where he pleaded guilty to two counts of juvenile delinquency. His plea agreement contemplates a sentence of one year to 18 months in prison.

SoBe entered the public spotlight in November 2005 as an "unindicted co-conspirator" to Jeanson James Ancheta, who eventually pleaded guilty to four felony charges in connection with the same botnet. With SoBe located in Boca Raton, Florida, and Ancheta working in Downey, California, the two built a lucrative business by surreptitiously installing adware on computers and then pocketing affiliate fees. According to court documents, the pair collected at least $58,000 in 13 months, but it's possible they made much more.

"It's immoral, but the money makes it right," Ancheta told SoBe during one online chat, according to the indictment charging Ancheta.

More here.

Monday, May 08, 2006

Botmaster James Ancheta Sentenced to Five Years

An AFP newswire article, via Yahoo! News, reports that:

A US computer hacker was jailed for nearly five years for hijacking around 400,000 computers, including military servers, and infecting them with malicious software.

Sealing the first prosecution of its kind, US federal Judge Gary Klausner in Los Angeles sentenced "botmaster" Jeanson Ancheta, 20, to 57 months in jail for taking control of an array of computers he had corralled into his "Botnet."

Ancheta had pleaded guilty in January to infecting the computers with software that caused them to send spam, show ads and launch crippling attacks on Internet sites.

The crime was "extensive, serious and sophisticated," the judge told the court as he handed down the longest-known sentence for someone accused of spreading computer viruses.

More here.

Monday, April 24, 2006

F-Secure: Remember James Ancheta?


Image source: F-Secure / USA Today

Mikko writes over on the F-Secure "News from the Lab" Blog:

Remember James Ancheta? The botmaster that was caught and convicted earlier this year.

Now USA Today's Byron Acohido and Jon Swartz have done an extensive study into Ancheta's operations and even uncovered his arrest mug shot! Full story is available on usatoday.com.

More here.

Thursday, May 08, 2008

'I Was A Teenage Bot Master'

Dan Goodin writes on The Register:

One day in May 2005, a 16-year-old hacker named SoBe opened his front door to find a swarm of FBI agents descending on his family's three-story house in Boca Raton, Florida. With an arm in leg in casts from a recent motorcycle accident, one agent grabbed his good arm while others seized thousands of dollars worth of computers, video game consoles and other electronics. His parents looked on.

At that moment, some 2,700 miles away, in the Los Angeles suburb of Downey, California, the FBI was serving a separate search warrant on Jeanson James Ancheta, SoBe's 20-year-old employer and hacking mentor. It was the second time in six months Ancheta had been raided by the FBI, - a clear sign, had either bothered to notice, that their year-long botnet spree was unravelling.

More here.

Thursday, May 11, 2006

F-Secure: Ancheta Sentencing Poll Results

Sean writes over on the F-Secure "News from the Lab" Blog:

With 725 participants the results break down like this:

  • 294 - 40.6% thought that the sentence was Fair Enough or Just Right
  • 213 - 29.4% thought that it was Too Little
  • 161 - 22.2% thought that is was Too Much
  • 57 - 7.9% answered No Idea

We also received some e-mails on the matter. Reader Tony H. put it this way:

"Ancheta is believed to have had some 500,000 computers under his control. That works out to: Serving 1 year for every 100,000 or so machines he hit; Serving 1 month for every 9000 or so machines; Serving 1 week for every 2000 systems; Serving 1 day for every 300 or so systems; Serving 1 hour for every dozen systems; or Serving 5 minutes for each machine infected. Considering that it takes anywhere from 30 minutes to many hours of a skilled person's time to clean an infected system reliably, that means he's only going to lose 15% of the time he took from others - and he gets to sleep at least part of that time."

Link.

Monday, January 23, 2006

California Man Pleads Guilty to Felony Hacking

An AP newswire article by Dan Goodin, via Yahoo! News, reports that:

A 20-year-old man pleaded guilty Monday to surreptitiously seizing control of hundreds of thousands of Internet-connected computers and renting the zombie network to people who mounted attacks on Web sites, served up pop-up ads and sent out spam.

Jeanson James Ancheta, of Downey, Calif., pleaded guilty in U.S. District Court in Los Angeles to four felony charges for crimes, including infecting machines at two U.S. military sites, that earned him more than $61,000, Assistant U.S. Attorney James Aquilina said.

Under a plea agreement, which still must be approved by a judge, Ancheta will receive from 4 years to 6 years in prison, forfeit a 1993 BMW and more than $58,000 in profit and pay $19,000 in restitution to the federal government to compensate for infecting the military computers, according to documents filed in the case.

He is scheduled to be sentenced May 1.

Wednesday, November 09, 2005

Alleged 'Botmaster" Held WIthout Bond

An AP newswire article, via Yahoo! News, reports that:

A man has been ordered held without bond on charges of spreading electronic viruses so he could gain control over military and other computers and sell access to hackers and spammers.

Authorities in California say Jeanson James Ancheta, 20, also downloaded adware programs onto some 400,000 of the infected computers, or "botnets," in order to profit from the placements.

Ancheta, who was arrested last week, pleaded not guilty Monday in federal court. Trial was set for Dec. 27.

Thursday, November 03, 2005

Alleged Pop-Up Hacker Busted

Kevin Poulsen writes in Wired News:

In the first U.S. prosecution of its kind, FBI agents arrested a 20-year-old Los Angeles man Thursday on charges that he cracked some 400,000 Windows machines and covertly installed pop-up-generating adware on them, in a scheme that allegedly brought in $60,000 in ill-gotten profits.

Jeanson Ancheta faces a 17-count federal indictment charging him with two counts of conspiracy and various forms of computer intrusion and money laundering. The government is also seeking the seizure of more than $60,000 in cash, a used BMW and some computer equipment from the alleged hacker.

According to prosecutors, in 2004 and early 2005 Ancheta used a customized form of the "rxbot" Trojan horse program to find and take control of large collections of vulnerable PCs, spinning them into "botnets" capable of being directed as one. He then installed ad-delivery programs from two adware firms: Quebec-based Gammacash and LOUDcash, which was purchased by adware giant 180solutions and renamed ZangoCash earlier this year.

Wednesday, March 19, 2008

Botnet Farmers Play the International Exchange Game

John Leyden writes on Channel Register:

Spyware authors are prepared to pay botnet farmers or webmasters much more for infecting PCs in the UK or Australia than machines in continental Europe.

Selling "installs" is a common practice in the cyber-underworld, the most notable example being in 2005 when Jeanson Ancheta was arrested for building a 400,000-strong botnet and installing adware from 180 solutions for a fee of $60,000. Cybercriminals have since moved on to installing spyware onto compromised machines.

The income that can be earned grows with the numbers of installs, and varies based on the geographical location of an installation. For example, installing spyware on 1,000 machines in Australia earns $100 but only $50 in the US, and a measly $3 in Asia. A sample price list obtained by net security services firm sheds fresh light on the phenomenon.

More here.

Tuesday, November 08, 2005

Accused U.S. 'Botmaster' denies hijacking thousands of computers

An AFP newswire article, via Yahoo! News, reports that:

An alleged computer hacker denied hijacking tens of thousands of computers, including US military servers, and infecting them with malicious software.

Alleged "botmaster" Jeanson Ancheta, 20, was arrested in Los Angeles last week on charges including damaging government computers used in national defense and hacking into computers to commit fraud and conspiracy.

The youth is accused of infecting "armies" of computers and turning them into "bots" that are then used to launch destructive attacks on servers or send huge quantities of spam, or unwanted e-mail.