Turk and Moroccan arrested for Zotob worm

Author caught within two weeks

Written by Tom Sanders in California, vnunet.com

Authorities have arrested 21-year old Atilla Ekici of Turkey and 18-year Morrocan Farid Essebar for creating and spreading the Zotob, Mytob and Rbot internet worms, the FBI has revealed.

The arrests were made on Thursday after an investigation by the FBI in close collaboration with Microsoft traced the code back to the two individuals.

"We were able to put the information together based on the work of our Internet Crime Investigation team working with the FBI, relying on electronic data to identify where this was coming from," said Microsoft general counsel Brad Smith.

He touted that the arrests were made only two weeks after the surfacing of the Zotob worm.

"This reflects that our entire industry is able to move much more quickly today than was the case two years ago."

The Moroccan who used the screen name "Diabl0" is believed to be the author of the initial worms and Ekici, AKA "Coder" paid him for the code, Louis Reigell of the FBI's Cyber Division said in a conference call. He couldn't say how much was paid for the worms.

It is common for worm authors to sell their creations.

The Zotob worm made headlines because it surfaced only days after Microsoft had published a security advisory about the vulnerability that the worm exploited. In the following days numerous variants of the worm surfaced.

The worm mainly affected systems running Windows 2000. Infected computers were recruited for botnets and would power down or reboot unexpectedly, which at one point crippled se veral large enterprises including American Express, DaimlerChrysler, United Parcel Service and Kraft Foods.

Mytob first started surfacing in March and the FBI back then started investigating the worm. The investigation became "very aggressive", said Reigell, in the weeks after the Zotob worm surfaced. It provided additional pointers to the worm's origin and lead to the arrests.

There are reasons to believe that others were involved in the case and both Reigell and Smith said that they expected that additional arrests be made.

The duo will be prosecuted locally. The two countries lack strong cyber crime legislation but could be charged for consumer fraud. The FBI will help the prosecution by providing evidence for their crimes.

Tags:

Reader comments

More from Computeractive

News

The latest home computing news

Downloads

The best PC tools, applications and more

Reviews

Independent opinions on new hardware and software

Step-by-step guides

Easy-to-follow projects with pictures

PC Help

Solve PC problems with our Q&A

Videos

PC projects demonstrated and product reviews

Articles

An in-depth look at how to get the best from your PC

Magazine

What's coming up in Computeractive

Forums

Get help with your PC problems from our readers

Competitions

Your chance to win computing prizes

Shopping

Great deals on products, services and more

Computeractive CD Rom 10
All 26 issues of Computeractive from 2007 on one CD-Rom.

Ultimate Guide to PC Troubleshooting
Everything you need to know to solve your PC problems.

Driving Test Success
The UK's best-selling driving test software.

Computeractive Back Issues
Missed an issue? Click here to find a back issue

Advertisement

Blogs

Windows Watch

Windows Watch

Keeping an eye on the latest XP and Vista news

More storage added to Windows Live Skydrive

19 Nov 2008The storage limit for Windows Live Skydrive is to be increased to a very respectable 25GB . As of just now my...

Download Junkie

Download Junkie

Your daily dose of download discussion

Convert your images into almost any format with XnView

20 Nov 2008Almost all image viewers, even basic freeware tools, enable you to convert the format of your images. Images are often gathered from...

Advertisement

Free email newsletters

Techno babble demystified...

[Display all definitions]

Or type in any computer-related word and click "Go"

Advertisement

Computeractive is not reponsible for content of Google adverts

Primary Navigation

© Incisive Media Ltd. 2008. Incisive Media Limited, Haymarket House,
28-29 Haymarket, London SW1Y 4RX, is a company registered in the United Kingdom with company registration number 04038503

Search computeractive.co.uk