Version: 2008
  • On CHOW: Sexy vampire party

August 26, 2005 11:29 AM PDT

Arrests made in probe of worm that hit ABC, others

  • 30 comments
Law enforcement officials have arrested two men suspected of unleashing of a pair of computer worms, including last week's Zotob, which hit servers at American Express, The New York Times and elsewhere.

Farid Essebar, age 18, a Moroccan national born in Russia, was arrested in Morocco, and 21-year-old Atilla Ekici, a Turkish resident, was arrested in Turkey, Paul Bresson, a spokesman for the FBI, said Friday. Both suspects were detained Thursday and will be prosecuted in the countries in which they were arrested, Bresson said.

Bresson said that Essebar, who went by the nickname "Diabl0," and Ekici, known as "Coder," are suspected of creating both the Mytob and Zotob worms.

The Zotob worm attacked computers running Microsoft's Windows 2000 operating system, and the worm and its offshoots last week hit PCs and servers worldwide, including machines at ABC, CNN and Daimler Chrysler.

Zotob included some of the code used in Mytob, an e-mail worm that first started spreading in March. To date, more than 100 variants of Mytob have been spotted. The worm is distributed via mass e-mail campaigns and features so-called backdoor capabilities, allowing attackers to remotely control infected computers.

Both Mytob and Zotob attacked computers running Windows. Zotob and its variants exploited a security hole in the plug-and-play feature in the OS, for which Microsoft provided a fix earlier this month.

The FBI initiated the investigation into Mytob and Zotob, cooperating with Microsoft and others to trace the origins of the worms, Bresson said. Law enforcement agencies in Morocco and Turkey were instrumental in the investigation, he said.

The bureau alleges that Essebar wrote both the Mytob and Zotob worms and then sold them to Ekici. "We believe that there was financial gain on (Essebar's) part," Louis Reigel, assistant director of the FBI's Cyber Division, said in a conference call with the media. He did not provide further details.

The investigation started in late March, after the Mytob release, Reigel said.

The probe intensified when Zotob hit. Microsoft's Internet crime investigation team dissected the worm and found leads to the two suspects, Brad Smith, Microsoft's general counsel, said on the conference call.

"The trail that we ultimately were able to follow that led to these individuals is a trail that came to light in the last two weeks, after the launch of Zotob," Smith said.

Microsoft hails the arrests as an example of a successful partnership between the private sector and law enforcement. "Our entire industry, especially in partnership with law enforcement, is able to move much more quickly and in a more sophisticated way today than was the case, say, two years ago, and that is certainly part of what made it possible to get to this point within two weeks," Smith said.

The actual legal charges against the individuals are not yet known. Turkey and Morocco will charge the suspects, and the FBI will provide evidence for the prosecution, Reigel said.

The investigation into the Mytob and Zotob worms is ongoing and others may be arrested, Reigel said: "The Moroccan and Turkish authorities are doing a full investigation to determine if there were other individuals involved."

See more CNET content tagged:
Zotob worm, Brad Smith, investigation, probe, Turkey

Add a Comment (Log in or register) (30 Comments)
  • prev
  • 1
  • next
Thas was fast
by R. U. Sirius August 26, 2005 11:38 AM PDT
Good job FBI.

Now can you please get some more of the spammers too?
Reply to this comment
Thas was fast
by R. U. Sirius August 26, 2005 11:38 AM PDT
Good job FBI.

Now can you please get some more of the spammers too?
Reply to this comment
A way for the Turkish and Moroccan governments to make money from this...
by M C August 26, 2005 1:29 PM PDT
Caning webcasts.
Reply to this comment
A way for the Turkish and Moroccan governments to make money from this...
by M C August 26, 2005 1:29 PM PDT
Caning webcasts.
Reply to this comment
Arabs?
by August 26, 2005 2:48 PM PDT
These guyz sound like they are Arabs. Financial gain? This thing
smells. I hope the security folks are all over this like a blanket.
Reply to this comment
I doubt it.
by open-mind August 26, 2005 3:48 PM PDT
Neither virus was as malicous as they could have been. They could have easily deleted/corrupted tons of data or made all the machines unbootable. I think it seemed more like an experiment.
View reply
Arabs?
by August 26, 2005 2:48 PM PDT
These guyz sound like they are Arabs. Financial gain? This thing
smells. I hope the security folks are all over this like a blanket.
Reply to this comment
I doubt it.
by open-mind August 26, 2005 3:48 PM PDT
Neither virus was as malicous as they could have been. They could have easily deleted/corrupted tons of data or made all the machines unbootable. I think it seemed more like an experiment.
View reply
Arrests made in probe of worm that hit ABC,others
by August 27, 2005 11:15 AM PDT
I'm glad to know that someone is doing something about these worms/viruses!! The individuals who waste their God given intelligents to harm or destroy are no better than terrorists!! What is sad though is the fact that nothing would have gotten done if the worm hadn't been directed at large companies first.
Reply to this comment
Arrests made in probe of worm that hit ABC,others
by August 27, 2005 11:15 AM PDT
I'm glad to know that someone is doing something about these worms/viruses!! The individuals who waste their God given intelligents to harm or destroy are no better than terrorists!! What is sad though is the fact that nothing would have gotten done if the worm hadn't been directed at large companies first.
Reply to this comment
seeded with propaganda?
by August 27, 2005 1:45 PM PDT
just a hunch.. I think there could be an effort
to "root out" certian people by feeding them with
h/p tools and ideas... I am quite familiar with
the stuff and have found it increasingly hard to
find nowadays... I have also noticed that most of
the activity nowadays is coming from east
Europe... language barriers? maybe.. but I
noticed after 911 many "backup networks" started
hosting bomb making instructions and military
information.. obviously suspicious.. I have also
noticed linux updates slipstreamed with cloaked
stuff.. broken opensource projects.. no, this
isnt the work of individuals.. nor some cave
dwellers...

united we stand! divided and jobless.. yah! enjoy
that new orange hummer.. you deserve it!
Reply to this comment
seeded with propaganda?
by August 27, 2005 1:45 PM PDT
just a hunch.. I think there could be an effort
to "root out" certian people by feeding them with
h/p tools and ideas... I am quite familiar with
the stuff and have found it increasingly hard to
find nowadays... I have also noticed that most of
the activity nowadays is coming from east
Europe... language barriers? maybe.. but I
noticed after 911 many "backup networks" started
hosting bomb making instructions and military
information.. obviously suspicious.. I have also
noticed linux updates slipstreamed with cloaked
stuff.. broken opensource projects.. no, this
isnt the work of individuals.. nor some cave
dwellers...

united we stand! divided and jobless.. yah! enjoy
that new orange hummer.. you deserve it!
Reply to this comment
Yo, FBI, you should be arresting Bill Gates
by aabcdefghij987654321 August 28, 2005 6:18 AM PDT
Week after week of exploits...because of Microsoft's disdain for anything secure that may threaten the monopoly. Microsoft's monopolistic decisions have cost lives and countless billions of dollars. And yet, nothing ever changes.
Reply to this comment
Yo, FBI, you should be arresting Bill Gates
by aabcdefghij987654321 August 28, 2005 6:18 AM PDT
Week after week of exploits...because of Microsoft's disdain for anything secure that may threaten the monopoly. Microsoft's monopolistic decisions have cost lives and countless billions of dollars. And yet, nothing ever changes.
Reply to this comment
Arrest MS Apologists, too
by cjohn17 August 28, 2005 6:46 AM PDT
They should also pick up the Microsoft apologists who make
excuses for this shoddy software and makes these kind of attacks
possible. Why? Because they give MS cover and don't insist on a
better, safer product line.
Reply to this comment
Yeah - that's the ticket...
by Milly Staples August 28, 2005 8:40 AM PDT
... arrest anyone who has an opinion, no matter on what issue, just because some zealot thinks that the person with the opinion is wrong-headed and should be locked up, shot, beaten, caned, whatever, for exercising their American right to free speech.

Yeah, I really look forward to living in YOUR world.
View reply
Arrest MS Apologists, too
by cjohn17 August 28, 2005 6:46 AM PDT
They should also pick up the Microsoft apologists who make
excuses for this shoddy software and makes these kind of attacks
possible. Why? Because they give MS cover and don't insist on a
better, safer product line.
Reply to this comment
Yeah - that's the ticket...
by Milly Staples August 28, 2005 8:40 AM PDT
... arrest anyone who has an opinion, no matter on what issue, just because some zealot thinks that the person with the opinion is wrong-headed and should be locked up, shot, beaten, caned, whatever, for exercising their American right to free speech.

Yeah, I really look forward to living in YOUR world.
View reply
Probe of worm
by Ringmaster1 August 29, 2005 3:46 AM PDT
I think we should severly punish any person found responsible for creating worms, viruses, etc. If these people are trying to impress others, of their capability for jobs, we should develop creative programs that would make this possible. Those persons creating or participating in the destruction of valid programs should receive severe penalties to make them aware that this type of foolishness will not be tolerated by society!
Reply to this comment
Wake up
by August 30, 2005 12:58 AM PDT
Typical western/american thinking. Virus/worm writers are often the best of the best and you want to lock them up. Fine with me. But know that it's not an effective way of solving problems. Think of microsoft. Offering huge bounties for info on virus/worm writers. Now what if they'd spend that money on security enhancements. Or better yet: why don't they employ the virus writers to help them fix their mess of an operating system. Money talks and while people are busy blaming the virus writers they forget to mention the guys who let the door wide open. Namely microsoft. Try to see with eyes unclouded by hate. The blame rests on the virus writers for making a destructive virus, on Microsoft for having a product more full of security holes than swiss cheese and on the sysadmins who do not patch /upgrade their systems. It's not one man's fault. Also the important part is not the finger pointing. It's how to solve this issue.
Probe of worm
by Ringmaster1 August 29, 2005 3:46 AM PDT
I think we should severly punish any person found responsible for creating worms, viruses, etc. If these people are trying to impress others, of their capability for jobs, we should develop creative programs that would make this possible. Those persons creating or participating in the destruction of valid programs should receive severe penalties to make them aware that this type of foolishness will not be tolerated by society!
Reply to this comment
Wake up
by August 30, 2005 12:58 AM PDT
Typical western/american thinking. Virus/worm writers are often the best of the best and you want to lock them up. Fine with me. But know that it's not an effective way of solving problems. Think of microsoft. Offering huge bounties for info on virus/worm writers. Now what if they'd spend that money on security enhancements. Or better yet: why don't they employ the virus writers to help them fix their mess of an operating system. Money talks and while people are busy blaming the virus writers they forget to mention the guys who let the door wide open. Namely microsoft. Try to see with eyes unclouded by hate. The blame rests on the virus writers for making a destructive virus, on Microsoft for having a product more full of security holes than swiss cheese and on the sysadmins who do not patch /upgrade their systems. It's not one man's fault. Also the important part is not the finger pointing. It's how to solve this issue.
(30 Comments)
  • prev
  • 1
  • next
advertisement

Latest tech news headlines

RSS Feeds

Add headlines from CNET News to your homepage or feedreader.

More feeds available in our RSS feed index.

Markets

Market news, charts, SEC filings, and more

Related quotes

Microsoft (0.69%) 0.20 29.21
Dow Jones Industrials (0.25%) 25.17 10,272.14
S&P 500 (0.34%) 3.69 1,096.70
NASDAQ (0.51%) 10.99 2,162.07
CNET TECH (0.39%) 6.10 1,577.68
  Symbol Lookup
advertisement

Inside CNET News

Scroll Left Scroll Right