November 11, 2006

BotMaster Criminal Jeanson James Ancheta pleads guilty and gets 57 months (almost 5 years) in federal prison.

While I'm overjoyed to see this Spyware Affiliate, hacker, cracker, BotNet slime bag, and criminal go to federal prison, I'm going to examine the enablers. Jeanson James Ancheta admitted generating for himself and an unindicted coconspirator more than $107,000 in advertising affiliate proceeds by silently downloading Spyware/Adware to more than 400,000 infected computers that he controlled. Ancheta was also ordered to pay approximately $15,000 in restitution to the Weapons Division of the United States Naval Air Warfare Center in China Lake and the Defense Information Systems Agency. He also forfeited to the government more than $60,000 in cash, a BMW automobile and computer equipment.

Enabler #1 - Mom and Dad

Your nearly as accountable as your son. Let me get this straight, your 19 year old kid sits in his bedroom all day and spends large amounts of money without a real job, yet YOU do nothing. Your offspring spends $600 a week on new clothes and car parts, yet you don't become involved. Your tears and that of your family mean zilch to me. Engage your kids. Learn exactly what they are doing. Take a College course and ask your friends. Read my entry on parental involvement to combat abuse.

Enabler #2 - The Unindicted coconspirator

This "partner in crime" resides in Boca Raton, Florida and uses a screen name of "SoBe". The legal papers in this case have additional details so it's obvious that the FBI and other authorities know where he lives and his real name. Since this criminal is a resident of another state, I can understand why he was not part of this legal action. However, lets get him and send him to jail for at least 5 years. If he is to young to go to federal prison, lets get Mom and Dad and send "SoBe to a juvenile detention facility for 5 years.

Enabler #3 - Hosting/Dedicated Server providers

Ancheta and his partner needed dedicated servers to run their IRC channel and BotNet, which infects computers. The following companies provided dedicated servers for this criminal activity: EasyDedicated, FDCServers, The Planet, and Sago Networks. It's clear to me that these hosting Companies are enablers. Why would ANY hosting company let a client run an IRC channel/service on their boxes? Where were the alerts for all the traffic these criminals BotNets generated, inspite of the fact that none of them ran a Web Site (Port 80). Lets get serious and terminate these accounts without turning a blind eye for money.

Enabler #4 - The Spyware Companies

Ancheta admitted generating for himself and an unindicted coconspirator more than $107,000 in advertising affiliate proceeds by silently downloading adware/Spyware to more than 400,000 infected computers that he controlled via his IRC channel/service and BotNet. He earned money from the following Spyware enabler programs: GammaCash, and LoudCash. LoudCash was owned by CDT, Inc and CDT was acquired by 180solutions in April of 2005. This company is currently known as ZangoCash.

Naturally, the "rogue affiliate" excsue rears it's ugly head. I can hear the chant, "Ancheta and partners were Affiliates who crossed the line and violated our own Network policies." HA! I'm not buying it. My back of the envelope calculations indicates that total payments of $107,000 represents at least 300,000 silent downloads of Spyware which these companies paid Ancheta for. ALL without a valid web site and forged HTTP referals. Where was the spot check on the site which referrred the download. This is easy stuff! Go look at the sites! Does the whois owner of the referring site match your affiliates name and address via whois? Did you Spyware enablers provide your mentally challenged Advertisers with a "make good" for these non compliant installs? I think NOT. In my world, each and every one of these Companies needs to be sued and hopefully senior management will spend time in federal prison after the appropriate court/legal procedures.

Fianl thoughts

Ancheta also sold the use of his BotNets to other criminals. These payments used PayPal (owned by EBay) to transfer funds and it appears they cooperated but I'm still woundering why they also didn't sue lots of folks. Matter of fact, I can't recall ANY legal action started by PayPal. Tips for PayPal: your service is the money laundering capital of the world. Criiminals like Ancheta and the folks who rented his BotNet are using your service to transfer money. FREEZE their funds without warning and then SUE all of them. Exactly how hard is that to understand.

Sources for the entry:

Grand Jury Inditement

Press Release - US Attorney, Los Angeles and another US Attorney Press Release

http://www.thejournalnews.com/apps/pbcs.dll/article?AID=/20060501/BUSINESS01/605010305/1066

Posted by Steve_S at November 11, 2006 12:56 PM