Skip to main content

Mariposa Botnet Developer Arrested in Slovenia

Image used with permission by copyright holder

The Slovenian Criminal Police, working with the FBI and the Spanish Guardia Civil, have announced the arrest of a 23-year-old Slovenian programmer known as “Iserdo,” suspected of being the creator of the Mariposa/buttery botnet that has infected millions of computers around the world. The Maroposa bot was designed to pilfer financial information like credit card and bank account information; it can also be used to stage denial-of-service attacks and to spread malware to other computers. Experts estimate the Mariposa botnet may have infected anywhere from 8 to 12 million Windows computers around the world, including some high-profile infections at major companies and financial institutions.

The arrest follows the arrest of three suspected Mariposa botnet operators in Spain earlier this year.

“In the last two years, the software used to create the Mariposa botnet was sold to hundreds of other criminals, making it one of the most notorious in the world,” said FBI Director Robert S. Mueller, III, in a statement. “These cyber intrusions, thefts, and frauds undermine the integrity of the Internet and the businesses that rely on it; they also threaten the privacy and pocketbooks of all who use the Internet.”

Iserdo is alleged to have created the “Butterfly Bot” and sold it to other cybercriminals around the world from 2008 to 2010. From Iserdo’s code, the criminals developed wide-ranging botnets, of which the Mariposa botnet running out of Spain was the largest. Iserdo then went on to develop add-ons for his original application to enhance the malware’s capabilities; he, in turn, sold these enhancements to the botnet operators.

The Mariposa bot was perhaps too successful for its own good: while it’s not terribly unusual in the Windows world for botnet to infect a few hundred thousand computers, the larger they get, the more attention they attract from law enforcement. With Mariposa inhabiting millions of computers worldwide, it became a top priority for cybercrime investigators and Internet security experts. However, not all successful botnets get torn down by law enforcement: nobody has ever been arrested in connection with the Conficker worm, which is estimated to have infected as many PCs as Mariposa.

Editors' Recommendations

Topics
Geoff Duncan
Former Digital Trends Contributor
Geoff Duncan writes, programs, edits, plays music, and delights in making software misbehave. He's probably the only member…
This PowerPoint ploy could help hackers empty your bank account
A hacker typing on an Apple MacBook laptop, which shows code on its screen.

 

With various cybersecurity threats on a constant rise, it certainly feels like dangerous malware is around every corner. This time, it found its way into PowerPoint presentations disguised as helpful guides on how to protect yourself against phishing. The irony of it all is strong, but the worst part is that this malware could help attackers empty your bank account.

Read more
Is ChatGPT creating a cybersecurity nightmare? We asked the experts
A person's hand holding a smartphone. The smartphone is showing the website for the ChatGPT generative AI.

ChatGPT feels pretty inescapable right now, with stories marveling at its abilities seemingly everywhere you look. We’ve seen how it can write music, render 3D animations, and compose music. If you can think of it, ChatGPT can probably take a shot at it.

And that’s exactly the problem. There's all manner of hand-wringing in the tech community right now, with commenters frequently worrying that AI is about to lead to a malware apocalypse with even the most green-fingered hackers conjuring up unstoppable trojans and ransomware.

Read more
Microsoft just gave you a new way to stay safe from viruses
A dark mystery hand typing on a laptop computer at night.

Microsoft has just taken a vital step towards better protecting your devices from malware, and it’s one that could stop viruses dead in their tracks. Interestingly, though, the Redmond giant seems to have made no mention of the change, despite its significance.

The new policy might sound minor on the surface: Microsoft’s SharePoint cloud storage service can apparently now scan files that are encrypted or password-protected. Previously, this wasn’t thought to be possible.

Read more