Wednesday, May 29, 2024

Two Hackers of Bayrob Malware Gang Convicted for Infecting more than 400,000 Computers Worldwide

Two Romanian hackers Bogdan Nicolescu, 36, and Radu Miclaus, 37, belonging to Bayrob group convicted for infecting 400,000 computers around the world with malware and for stealing millions of dollars.

They have been convicted by a federal jury today for 21 counts related to infecting victims computer with malware to exfiltrate the credit card details and sold them in dark web, mining cryptocurrency and for online frauds.

“According to trial and court documents, Nicolescu, Miclaus, and a co-conspirator who pleaded guilty, collectively operated a criminal conspiracy from Bucharest, Romania.”

They developed the malware in 2007, and then deliver the malware through phishing emails that pose to be from Western Union, Norton AntiVirus and the IRS.

When users open’s the attachment, the malware gets installed to the system and harvest email addresses from the infected computer. The gang controlled 400,000+ botnet for cryptocurrency mining.

By having control over the computer they exfiltrate personal information, credit card information, user names, and passwords. They also disable antivirus software in victims and block law enforcement agencies websites.

The defendants used stolen email credentials to copy a victim’s email contacts. They also activated files that forced infected computers to register email accounts with AOL. The defendants registered more than 100,000 email accounts using this method.

“They then sent malicious emails from these addresses to the compromised contact lists. Through this method, they sent tens of millions of malicious emails,” reads Department of Justice press release.

By having control over the system, if a user visits pages such as Facebook, PayPal, eBay or others they intercept the request and redirect them phishing sites to grab login credentials.

They use to infect fake pages in trusted websites such as eBay to make victims believe that they getting instructions from a legitimate source.

Also, they use to place fraudulent listings for automobiles, motorcycles and other high-priced goods on eBay that delivers malware.

Bayrob group

Symantec has exposed the group, gaining insight into its key players, tactics, malware, and the potential impact and criminal activity undertaken.

“The Bayrob group laundered this money by hiring “money transfer agents” and created fictitious companies with fraudulent websites designed to give the impression they were actual businesses engaged in legitimate financial transactions.”

You can follow us on LinkedinTwitterFacebook for daily Cybersecurity updates also you can take the Best Cybersecurity courses online to keep your self-updated.

Ex-NSA Contractor got jailed for Stealing the Country’s Most Sensitive Classified Secrets Data for 20 years

Leader of the Hacker Group Jailed for Stealing $15 Million from Russian Banks


Latest articles

Researchers Exploited Nexus Repository Using Directory Traversal Vulnerability

Hackers target and exploit GitHub repositories for a multitude of reasons and illicit purposes.The...

DDNS Service In Fortinet Or QNAP Embedded Devices Exposes Sensitive Data, Researchers Warn

Hackers employ DNS for various purposes like redirecting traffic to enable man-in-the-middle attacks, infecting...

PoC Exploit Released For macOS Privilege Escalation Vulnerability

A new vulnerability has been discovered in macOS Sonoma that is associated with privilege...

CatDDoS Exploiting 80+ Vulnerabilities, Attacking 300+ Targets Daily

Malicious traffic floods targeted systems, servers, or networks in Distributed Denial of Service (DDoS)...

GNOME Remote Desktop Vulnerability Let Attackers Read Login Credentials

GNOME desktop manager was equipped with a new feature which allowed remote users to...

Kesakode: A Remote Hash Lookup Service To Identify Malware Samples

Today marks a significant milestone for Malcat users with the release of version 0.9.6,...

Cisco Firepower Vulnerability Let Attackers Launch SQL Injection Attacks

 A critical vulnerability has been identified in Cisco Firepower Management Center (FMC) Software's web-based...
Guru baran
Guru baran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Free Webinar

Live API Attack Simulation

94% of organizations experience security problems in production APIs, and one in five suffers a data breach. As a result, cyber-attacks on APIs increased from 35% in 2022 to 46% in 2023, and this trend continues to rise.
Key takeaways include:

  • An exploit of OWASP API Top 10 vulnerability
  • A brute force ATO (Account Takeover) attack on API
  • A DDoS attack on an API
  • Positive security model automation to prevent API attacks

Related Articles