Original URL: http://www.channelregister.co.uk/2008/01/31/storm_worm_protection/
The creators of the Storm Worm botnet are known to US authorities but a lack of co-operation from their counterparts in St. Petersburg, Russia, is preventing action being taken.
St. Petersburg was the centre of the infamous Russian Business Network. It's also reckoned by some to be the city the Storm Worm (more properly Trojan) authors call home.
Dmitri Alperovitch director of intelligence analysis and hosted security at Secure Computing told The Washington Post that Russian President Vladimir Putin and political influence within the Federal Security Service (Russia's successor to the Soviet KGB) was hampering prosecution efforts. The implication is that elements of Russian intelligence agencies are protecting the city's cybercriminals.
"The right people now know who the Storm worm authors are," Alperovitch said. (http://blog.washingtonpost.com/securityfix/2008/01/unhappy_birthday_to_the_storm.html) 'It's incredibly hard because a lot of the FSB leadership and Putin himself originate from there, where there are a great deal of people with connections in high places."
Other security experts reckon that the Storm Worm gang are based in Russia but have no real idea of their location, much less their identities. David Emm, senior technology consultant at Kaspersky Lab UK, said coding similarities and packing techniques used with the worm suggest the authors of the malware and Russian hackers known to have attacked local websites are one and the same. Kaspersky, like antivirus firm F-Secure, reckons that the Storm Worm gang is a multinational effort based in Russia.
"We don't know who they are," said F-Secure chief research officer Mikko Hyppönen, "but we believe it's a Russian gang with an American or several Americans helping them to build the social engineering messages and the websites they use." ®
Rent-a-bot gang rises from the DDoS ashes (13 March 2008)
http://www.channelregister.co.uk/2008/03/13/loadscc_rises_again/
MayDay! MayDay! Ruskies reinvent cyber crime (13 February 2008)
http://www.theregister.co.uk/2008/02/13/new_botnet_advances/
Storm Worm turns one (18 January 2008)
http://www.channelregister.co.uk/2008/01/18/storm_worm_botnet/
Mexico and Africa to become malware hotspots (18 January 2008)
http://www.channelregister.co.uk/2008/01/18/future_cybercrime_hotspots/
Online crime gangs embrace open source ethos (17 January 2008)
http://www.channelregister.co.uk/2008/01/17/globalization_of_crimeware/
MP3sparks.com downed by links to Russian cybercrime gang (11 January 2008)
http://www.theregister.co.uk/2008/01/11/mp3sparks_cogent_abdallah/
New Year's Eve greetings disguise Storm Worm attacks (27 December 2007)
http://www.channelregister.co.uk/2007/12/27/storm_worm_seasonal_attacks/
Infamous RBN quits China (13 November 2007)
http://www.channelregister.co.uk/2007/11/13/rbn_quits_china/
Controversial Russian Business Network drops offline (8 November 2007)
http://www.channelregister.co.uk/2007/11/08/rbn_offline/
Storm Worm retaliates against security researchers (25 October 2007)
http://www.channelregister.co.uk/2007/10/25/storm_worm_backlash/
The balkanization of Storm Worm botnets (15 October 2007)
http://www.channelregister.co.uk/2007/10/15/storm_trojan_balkanization/
Storm Worm linked to spam surge (14 September 2007)
http://www.channelregister.co.uk/2007/09/14/storm_worm_analysis/
Storm Worm descends on Blogger.com (29 August 2007)
http://www.channelregister.co.uk/2007/08/29/storm_hits_blogger/
Storm worm authors switch tactics (20 August 2007)
http://www.channelregister.co.uk/2007/08/20/storm_vxers_refine_tactics/
© Copyright 2008