Exclusive: Microsoft and Symantec disrupt cyber crime ring

Wed Feb 6, 2013 5:24pm EST
 

By Jim Finkle

BOSTON (Reuters) - Software makers Microsoft Corp and Symantec Corp said they disrupted a global cyber crime operation by shutting down servers that controlled hundreds of thousands of PCs without the knowledge of their users.

The move made it temporarily impossible for infected PCs around the world to search the web, though the companies offered free tools to clean machines through messages that were automatically pushed out to infected computers.

Technicians working on behalf of both companies raided data centers in Weehawken, New Jersey, and Manassas, Virginia, on Wednesday, accompanied by U.S. federal marshals, under an order issued by the U.S. District Court in Alexandria, Virginia.

They seized control of one server at the New Jersey facility and persuaded the operators of the Virginia data center to take down a server at their parent company in the Netherlands, according to Richard Boscovich, assistant general counsel with Microsoft's Digital Crimes Unit.

Boscovich told Reuters that he had "a high degree of confidence" that the operation had succeeded in bringing down the cyber crime operation, known as the Bamital botnet.

"We think we got everything, but time will tell," he said.

The servers that were pulled off line on Wednesday had been used to communicate with what Microsoft and Symantec estimate are between 300,000 and 1 million PCs currently infected with malicious software that enslaved them into the botnet.

HIJACKING SEARCHES   Continued...

 
The interior of a Microsoft retail store is seen in San Diego January 18, 2012. REUTERS/Mike Blake