Connect with us

News

Chinese national charged with operating ‘world’s largest botnet’ linked to billions in cybercrimes

Published

on

Chinese national charged with operating ‘world’s largest botnet’ linked to billions in cybercrimes
play

A Chinese national has been arrested for his role in operating a residential proxy service that was used to defraud billions of dollars from the U.S. government and fund his lavish lifestyle, which included buying luxury cars and property around the world, the Department of Justice announced Wednesday.

YunHe Wang, 35, was arrested on May 24 and charged with creating a massive network of hijacked computer devices, also known as a “botnet,” that was used to conduct cyber attacks, fraud, child exploitation, bomb threats, and export violations, the department alleged. Wang administered the botnet, called “911 S5,” through about 150 servers worldwide from 2014 to 2022, according to an indictment unsealed last week.

Advertisement

About 76 of the servers were leased from online service providers based in the United States, the indictment said. The botnet infected over 19 million IP addresses in nearly 200 countries, including over 613,000 IP addresses located in the United States, according to prosecutors.

The Justice Department announcement comes after Wang and his two co-conspirators, Jingping Liu and Yanni Zheng, were sanctioned by the Department of Treasury for their alleged involvement with the malicious botnet. The department also imposed sanctions on three luxury companies Wang owned or controlled.

Authorities also searched Wang’s residences and seized assets valued at about $30 million as well as identifying other property valued at roughly an additional $30 million, prosecutors said.

“The conduct alleged here reads like it’s ripped from a screenplay,” Matthew Axelrod, assistant secretary for export control at the Department of Commerce, said in a statement Wednesday. “A scheme to sell access to millions of malware-infected computers worldwide, enabling criminals over the world to steal billions of dollars, transmit bomb threats, and exchange child exploitation materials — then using the scheme’s nearly $100 million in profits to buy luxury cars, watches, and real estate.”

Advertisement

The Department of Justice partnered with the FBI and international law enforcement agencies in Singapore, Thailand, and Germany to dismantle the botnet and arrest Wang. The case is the latest in the federal government’s ongoing effort to thwart global cybercrime, which has become increasingly widespread.

These crimes can range from intellectual property theft to ransomware and can cost businesses billions of dollars in losses in addition to threatening critical sectors across the country, according to the Department of State. In recent years, federal authorities have expanded their international operations and country-to-country partnerships in order to better address cyber threats.

‘Urgency and severity of cyberattacks’: EPA urges water utilities to protect nation’s drinking water amid heightened cyberattacks

911 S5 Botnet ‘likely the world’s largest botnet ever’

FBI Director Christopher Wray said in a statement Wednesday that 911 S5 is “likely the world’s largest botnet ever.” According to the indictment, Wang allegedly spread his malware through Virtual Private Network programs and pay-per-install services, which allowed him to manage and control the roughly 150 servers.

Paying customers were then given access to proxied IP addresses that were linked to the hacked devices, the indictment said. Cybercriminals used those addresses to hide their locations and “anonymously commit a wide array of offenses,” the Department of Justice alleged.

Advertisement

“These offenses including financial crimes, stalking, transmitting bomb threats and threats of harm, illegal exportation of goods, and receiving and sending child exploitation materials,” according to the department. “Since 2014, 911 S5 allegedly enabled cybercriminals to bypass financial fraud detection systems and steal billions of dollars from financial institutions, credit card issuers, and federal lending programs.”

Specifically, the botnet targeted COVID-19 pandemic relief programs and filed an estimated 560,529 fraudulent unemployment insurance claims, according to the indictment. Federal authorities confirmed that more than $5.9 billion was stolen as a result.

The indictment further alleged that Wang had amassed about $99 million — either in cryptocurrency or fiat currency — from his sales of the infected proxied IP addresses. He used the illicit proceeds to purchase luxury assets and property.

Wang bought property in the United States, St. Kitts and Nevis, China, Singapore, Thailand, and the United Arab Emirates, according to the indictment. He also had dozens of other assets, such as luxury cars, watches, international bank accounts, and cryptocurrency wallets.

Wang was charged with conspiracy to commit computer fraud, substantive computer fraud, conspiracy to commit wire fraud, and conspiracy to commit money laundering. He faces a maximum of 65 years in prison.

Advertisement

Cybercrime, COVID fraud in the U.S.

Cybercrime is a “significant and growing threat” to the country’s national and economic security, according to the State Department. As people become more dependent on information and communication technologies, the department said more criminals continue to shift online.

Wang’s arrest also comes amid a push from federal officials for organizations to update and follow cybersecurity guidelines. Federal agencies have issued multiple advisories for cyberattacks committed by foreign groups in recent years.

In January, the FBI and Department of Justice announced that they had “disrupted a botnet of hundreds of U.S.-based small office/home office routers hijacked” by China-linked hackers. The group, known as “Volt Typhoon,” targeted critical infrastructure organizations in the United States, such as water systems and electric grids.

The surge in malicious cyber incidents coincides with the rise in online communication during the COVID-19 pandemic, according to a 2023 cyberthreat study. Citing FBI data, the study said cybercrime increased by 400% during the pandemic.

Advertisement

“Cybercriminals find the uncertainty brought by changing daily habits opportune and the increased virtual existence is converted into available attack vectors,” the study noted.

In the four years since the onset of the pandemic, the Internal Revenue Service has investigated over 1,600 tax and money laundering cases related to COVID-19 fraud potentially worth about $8.9 billion, the agency said in March. Cases included fraudulently obtained loans, credits and payments meant for U.S. workers, families and small businesses under the Coronavirus Aid, Relief and Economic Security, or CARES, Act.

Contributing: Josh Meyer, USA TODAY

Continue Reading
Advertisement
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.

News

Cyprus arrests alleged Iranian spy near RAF base

Published

on

Cyprus arrests alleged Iranian spy near RAF base

Unlock the Editor’s Digest for free

A British citizen has been arrested for allegedly spying on behalf of Iran near a UK air base in Cyprus, which serves as the RAF’s main hub for Middle East operations.

Cypriot authorities said on Saturday that they had detained a man on “terrorism and espionage” charges.

People in the UK familiar with the arrest did not dispute local Cypriot media reports that the alleged spy was suspected of working for Iran.

Advertisement

He is alleged to have monitored the UK’s Akrotiri base on the eastern Mediterranean island as well as the Cypriot Andreas Papandreou air base, which is sometimes used by the US air force.

The Foreign Commonwealth & Development Office said that the man was British and they were “in contact [with] the authorities in Cyprus regarding the arrest”.

Cypriot officials initially described the suspect as an Azerbaijani. The UK was unable to confirm immediately if he held dual nationality.

After appearing in court in Cyprus on Saturday, the man was detained for eight days on suspicion of espionage.

“Today following a co-ordinated operation by the police headquarters a person was arrested who seems to be related to terrorists acts,” the Cypriot government said.

Advertisement

They added that a regional court had issued a detention order “for criminal acts related, among others, to terrorism and espionage”.

They declined to comment further citing national security reasons.

A Cypriot official said they had been monitoring the individual with allies for the past month. Cypriot media reported the local police operation had been supported by the UK’s overseas intelligence service, MI6, and Israel’s Mossad.

Israeli foreign minister Gideon Sa’ar said on Saturday that a planned attack on Israeli citizens by Iran’s Islamic Revolutionary Guard Corps had been averted due to co-operation between Israeli and Cypriot security services.

“Thanks to the activity of the Cypriot security authorities, in co-operation with Israeli security services, the terror attack was thwarted,” Sa’ar said on X, without elaborating.

Advertisement

The UK Ministry of Defence directed enquiries to the FCDO, which works closely with MI6, as well as assisting British nationals when they are arrested overseas.

It is the UK government’s long-standing policy to neither confirm nor deny claims relating to intelligence matters.

The arrest comes as Israel’s war with Iran enters its eighth day and as the US weighs entering the conflict to destroy Tehran’s nuclear programme.

The UK has moved additional fighter jets and other military assets to the region in what Prime Minister Sir Keir Starmer has called a contingency measure. Some of the Typhoon jets were expected to be sent to Cyprus.

On Friday, UK military aircraft were sabotaged at Brize Norton, the RAF’s biggest base, by the Palestine Action activist group, which breached security and sprayed paint into the engines of several planes.

Advertisement

The UK is expected to proscribe Palestine Action as a terrorist organisation next week.

There has been little indication that the UK would join strikes on Iranian territory. Starmer has emphasised de-escalation and diplomacy this week but has also said Iran must not acquire a nuclear weapon.

Starmer hinted last weekend that UK military assets could be used to defend Israel as it trades strikes with Iran. Iran has threatened to strike UK forces in the region if it supports Israel.

RAF jets helped shoot down Iranian projectiles launched against Israel in April last year and assisted with target identification in October, but the UK has not been involved in the latest fighting.

Israel’s ambassador to London said this week they had not requested or discussed help from the UK.

Advertisement

Starmer may also have to weigh whether to allow the US to use the joint UK-US base of Diego Garcia in the Chagos Archipelago if the Trump administration decides to enter the war.

B2 stealth bombers, some of which are positioned on the island, are the only military aircraft capable of delivering the largest ‘bunker-buster’ bombs believed to be capable of penetrating Iran’s underground nuclear site near Fordow.

On Friday UK foreign secretary David Lammy met Iran’s foreign minister Abbas Araghchi and his counterparts from France and Germany.

Lammy said they were trying to offer Iran a diplomatic “off-ramp” but have also warned Tehran that it should hold talks with the US even without a ceasefire with Israel.

Advertisement
Continue Reading

News

Columbia activist Mahmoud Khalil says Trump administration has failed

Published

on

Columbia activist Mahmoud Khalil says Trump administration has failed

Columbia University activist Mahmoud Khalil has said the Trump administration failed to suppress pro-Palestinian voices, following his release from more than three months in immigration detention.

“My existence is a message” to the Trump administration, he told the BBC after returning to New Jersey from a detention centre in Louisiana. “All these attempts to suppress Pro-Palestinian voices have failed now.”

Mr Khalil was a prominent voice in the New York university’s pro-Palestinian protests last year, and his 8 March arrest sparked demonstrations in New York and Washington DC.

The US government wants to deport him, arguing his activism is detrimental to foreign policy interests.

Speaking at the airport in Newark, New Jersey, Mr Khalil vowed to continue to advocate for Palestinian rights, and for the rights of the immigrants “who are left behind in that facility” where he was jailed in Louisiana.

Advertisement

He accused the White House of attempting to “dehumanise anyone who does not agree with the administration”.

Mr Khalil’s remarks come a day after a judge ordered him released from jail after determining that he was not a flight risk or threat to his community while his immigration proceedings continue.

The Trump administration has vowed to appeal against his release, as it continues its efforts to remove him from the US.

Continue Reading

News

Japan scraps US meeting after Washington demands more defence spending

Published

on

Japan scraps US meeting after Washington demands more defence spending

Unlock the White House Watch newsletter for free

Japan has cancelled a top-level meeting with the US after the Trump administration abruptly told Tokyo to spend more on defence, sparking anger in Washington’s closest Asian ally.

US secretary of state Marco Rubio and defence secretary Pete Hegseth were due to meet Japan’s defence minister Gen Nakatani and foreign minister Takeshi Iwaya in Washington on July 1 for annual security talks known as the “2+2”.

But Tokyo scrapped the meeting after the US asked Japan to boost defence spending to 3.5 per cent, higher than its earlier request of 3 per cent, according to three people familiar with the matter, including two officials in Tokyo.

Advertisement

The new, higher demand was made in recent weeks by Elbridge Colby, the third-most senior official at the Pentagon, and sparked anger in Tokyo.

The tension over security issues comes as the allies hold tough trade talks after President Donald Trump in April imposed “reciprocal” tariffs on Japan.

One senior Japanese official said the decision to cancel the July 1 meeting was also related to the July 20 Upper House elections where the ruling Liberal Democratic party is expected to suffer a loss of seats.

Christopher Johnstone, a former senior US government Japan expert, said Tokyo viewed 2+2 meetings as a “very high priority” because they provided “politically valuable opportunities to showcase the strength of the US-Japan alliance”. He said postponing the meeting until after the Japanese election signalled “significant unease in Tokyo about the state of the bilateral relationship and its outlook”.

“Tokyo appears to have concluded that the political risk of a meeting before the election was higher than the potential gain — a pretty extraordinary assessment, if true,” said Johnstone, partner at The Asia Group, a consultancy.

Advertisement

The friction between Washington and Tokyo comes as the US puts pressure on European and Asian allies to boost defence spending.

Speaking at the IISS Shangri-La Dialogue defence forum in Singapore last month, Hegseth urged Asia-Pacific allies to follow the “newfound example” of Europeans pledging to spend more and cited the threats in the region from China and North Korea.

“The US is now playing hardball with allies in the Asia-Pacific,” said one defence official.

Colby has been at the forefront of that push. In his US Senate confirmation hearing in March, his calls for Tokyo to increase defence spending drew a rebuke from Prime Minister Shigeru Ishiba, who said Tokyo would decide its own budget.

“The Trump administration’s inconsistent and unrealistic message on its expectations for allied defence spending levels in Asia risks backfiring and undermining those officials and experts who are most supportive of the United States in some key foreign capitals,” said Zack Cooper, an Asia security expert at the American Enterprise Institute.

Advertisement

Colby has taken other positions that have raised anxiety among US allies. The Financial Times recently revealed that he was conducting a review of Aukus, the landmark security agreement between the US, UK and Australia designed to help Canberra procure a fleet of nuclear-powered submarines.

The FT also reported in May that he had told European countries that they should focus their militaries on the Euro-Atlantic region and less on the Asia-Pacific. The stance marked a shift from the Biden administration’s push to involve European allies in Asia to send a unified message of deterrence to China.

In another example of the shift, the Trump administration is not pushing Nato allies to reference the Indo-Pacific in the communiqué at the alliance’s summit in The Hague next week.

At the 2024 summit, members said the Indo-Pacific was “important for Nato”. But three people familiar with the draft of the communiqué that will be released next week said it did not mention the region.

Former president Joe Biden had invested heavily in securing the language, arguing that the European and Indo-Pacific theatres were linked.

Advertisement

Japan’s defence ministry did not comment on whether the talks had been cancelled, and said no decision had been made on the timing of the next meeting. The state department and Pentagon did not comment.

 

Continue Reading

Trending