Advertisement
Promo

Security threats Toolkit

Zotob suspects linked to underground network

Tom Espiner ZDNet.co.uk

Published: 30 Aug 2005 16:55 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

One of the virus writers suspected of creating the Zotob and Mytob worms has been linked to a notorious network of malware creators called 0x90-team.

Finnish antivirus expert Mikko Hyppönen, director of antivirus research at F-Secure, claimed in a blog posting on Monday that a virus writer nicknamed "Diabl0", who is believed to have been behind last week's virus outbreaks, had used the 0x90-team network in order to download malicious code.

F-Secure spokesman Patrick Runald said the 0x90-team (pronounced "zero ex ninety team") was a forum and file-sharing network dedicated to malware. Users could request and share malicious code such as the Zotob, Rbot and SDbot viruses. "Thousands of users used the forum," according to Runald.

The 0x90-team Web site has since been taken completely offline, probably by 0x90-team itself. This is because it was defaced on Saturday by unknown "hacktivists", according to Patrick Runald.

The 0x90-team Web site was hacked with a message which stated that the site had been defaced because it only offered third party products, but no "knowledge", according to Hyppönen. There was also a threat: "If you continue to hold this place to train script kiddies, we will come back."

Two men were arrested at the end of last week on suspicion of authoring both the Mytob and Zotob worms. Farid Essebar, an 18-year-old Moroccon national born in Russia, is suspected of being Diabl0. Atilla Ekici, a 21-year-old Turkish resident, is suspected of operating under the online alias "Coder".

Essebar was arrested in Morocco, while Ekici was arrested in Turkey. They will be prosecuted in the countries in which they were arrested, with the FBI providing the evidence.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
105 out of 211 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:





Video icon

Video

Sentry Posts Blog

Official Organizations Losing Data

How does this article from earlier today make you feel? How many more government, health service, or military officials are going to lose pen drives, DVDs, USB hard disks and even entire... More

1 comment

Twitter hack was DNS redirect

Twitter has said an attack on Thursday which took the site offline for many users was the result of a DNS redirect. A group calling itself the Iranian Cyber Army redirected users... More

1 comment

McKinnon lawyers seek judicial review

Lawyers seeking a judicial review for Nasa hacker Gary McKinnon lodged fresh evidence of his psychiatric state at the High Court on Thursday. Karen Todner, McKinnon's solicitor,... More

1 comment

Win a BlackBerry with Vlingo voice recognition

Win a BlackBerry with Vlingo voice recognition

What is ZDNet UK's usual tagline?

Competition closes - 14 Jan 2010


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters