Russian Hacker Who Operated Kelihos Botnet Pleads Guilty in US Federal Court

A Russian man who operates Kelihos Botnet Pleads in U.S. Federal Court to Fraud, Conspiracy, Computer Crime and Identity Theft Offenses.

Peter Levashov operated the botnet for decades to facilitate the malicious activities such as credentials harvesting, bulk spam e-mails, Delivering ransomware and other malware’s.

U.S. Attorney Durham said, “Mr. Levashov used the Kelihos botnet to distribute thousands of spam e-mails, harvest login credentials, and install malicious software on computers around the world.” He also participated in online forums to sell the stolen identities such as credit card information and another cybercrime tool.

Kelihos Botnet

The Kelihos botnet first appeared in December 2010, it is also known as a peer-to-peer botnet, it empowers every individual node to go about as a Command and Control server.

The first version of the botnet performed denial-of-service attacks and email spam, with the later version threat actors, added ability to steal Bitcoin wallets to mine cryptocurrencies.

Peter Levashov was arrested on April 7, 2017, in Barcelona by Spanish authorities based on the complaint and arrest warrant issued by the U.S District Court. At the time of arrest, Kelihos had at least 50,000 computers in botnet chain.

“Levashov lived quite comfortably while his criminal behavior disrupted the lives of thousands of computer users and today justice has finally arrived for Peter Levashov,” said FBI Special Agent in Charge Turner.

Levashov pleaded guilty before U.S. District Judge Robert N. Chatigny for damage to a protected computer, one count of conspiracy, one count of wire fraud and one count of aggravated identity theft. He is due to be sentenced on 6-Sept-2019 reads DoJ press release.

Related Read

Raise of IoT Botnets Responsible for Massive DDoS Attacks – Q2 2018 Threat Report

Android Based Malicious CryptoMiner Spreading by Worm that has Infected more than 5,000 devices in 24 hours

Ursnif Malware Variant Performs Malicious Process Injection in Memory using TLS Anti-Analysis Evasion Trick

Gurubaran

Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Recent Posts

CISA Warns of Palo Alto Networks PAN-OS Vulnerability Exploited in Wild

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a high-priority alert on a…

23 hours ago

US Treasury Department Breach, Hackers Accessed Workstations

The Biden administration confirmed that a Chinese state-sponsored hacking group breached the U.S. Treasury Department,…

1 day ago

TrueNAS CORE Vulnerability Let Attackers Execute Remote Code

Security researchers Daan Keuper, Thijs Alkemade, and Khaled Nassar from Computest Sector 7 disclosed a…

1 day ago

New Botnet Exploiting D-Link Routers To Gain Control Remotely

Researchers observed a recent surge in activity from the "FICORA" and "CAPSAICIN," both variants of…

2 days ago

Hackers Weaponize Websites With LNK File To Deliver Weaponized LZH File

The watering hole attack leverages a compromised website to deliver malware. When a user visits…

2 days ago

NFS Protocol Security Bypassed To Access Files From Remote Server

The NFS protocol offers authentication methods like AUTH_SYS, which relies on untrusted user IDs, and…

2 days ago