Showing posts with label software piracy. Show all posts
Showing posts with label software piracy. Show all posts

Sunday, May 25, 2008

Oregon case reveals the tie between software piracy and identity theft!


(Photo courtesy of naveenium at Flickr)

Software Piracy is a multi-billion dollar issue. Whether it's hawked in a spam e-mail, a flea market or on a auction site -- it might not work as well as advertised -- and could even lead to identity theft.

You never know what might be installed in pirated software. The person selling it to you might add a little malicious software (containing a keylogger) and steal all your personal and financial information.

A recent case showing how pirated software leads to identity theft was announced by the Department of Justice:

An Oregon man pleaded guilty today to selling counterfeit computer software with a retail value of more than $1 million, in addition to aggravated identity theft and mail fraud, announced Assistant Attorney General of the Criminal Division Alice S. Fisher and Karin J. Immergut, U.S. Attorney for the District of Oregon. This case is part of the Justice Department’s initiative to combat online auction piracy.

Jeremiah Joseph Mondello, 23, of Eugene, Ore., pleaded guilty to one count each of criminal copyright infringement, aggravated identity theft and mail fraud before U.S. District Court Judge Ann L. Aiken in Eugene. Mondello faces up to 27 years in prison, a maximum fine of $500,000 and three years of supervised release. Sentencing has been set for July 23, 2008.

Although this only appears to be a small win in the overall problem, it illustrates the danger of installing unauthorized software on your system. You might get more than you bargained for:

Mondello admitted to stealing individuals’ identifying information to establish online payment accounts in their names. Mondello acquired victims’ names, bank account numbers and passwords by using a computer keystroke logger program to surreptitiously obtain this information. The keystroke logger program installed itself on the victim’s computer and then recorded the victim’s name and bank account information as the information was being typed. The program then electronically sent the information back to Mondello, and he used this stolen information to establish the online payment accounts.

In other words, the moral of the story is that the money you save buying knock-off software can easily be lost when the seller returns to clean out your financial assets.

Trust me, criminals are not honorable and they could care less, if you get left holding the bag.

Last, but not least, most victims of identity theft are able to get their financial institutions to write-off their losses. However, if they discover you used illegal software -- which happened to contain malicious capabilities -- my guess is they are going to deny your fraud claim.

DOJ credited the Software & Information Industry Association for their assistance in this conviction. This association represents the software industry and goes after software and content piracy. They provide a means to report instances of piracy and offer up to a million dollar reward for doing so.

Full press release on this matter, here.

Thursday, May 01, 2008

Internet Gangstas don't appreciate software piracy, either!

Crimeware salesmen, like most e-commerce types, take a dim view when their creations are knocked-off (pirated). To protect themselves, they warn their customers (Internet criminal types) that if their products are counterfeited, they can and will be reported to the anti-virus companies.

Specifically, the verbiage used as reported on the Symantec blog is, "the binary code of your bot will be immediately sent to antivirus companies."

The reason reporting reporting the binary code of a bot defeats the crimeware kit in question (Zeus) was mentioned in a previous post on this blog:

Known as the "Zeus kit," in honor of the Zeus Trojan, the kit is pretty resistant to computer security programs and has the ability to mask itself using a binary generator. The binary generator sends out a unique set of numbers every time it is used, making it hard for security programs to detect since they rely on spotting what is known as a "signature." Even if a security program recognizes one signature, the binary generator changes it the next time, and the security program will probably fail to recognize it.

Here are the details, as reported on the Symantec blog by Liam OMurchu:

Here is a perfect example. The screen shot below is taken from a typical underground software package. Shown in the screen shot are the terms and conditions of the sale—the “licensing agreement.” Yes, that’s right; some underground packages come with a licensing agreement. The document is written in Russian, but a translation is provided below.



2. The Client:
1. Does not have the right to distribute the product in any business or commercial purposes not connected with this sale.
2. May not disassemble / study the binary code of the bot builder.
3. Has no right to use the control panel as a means to control other bot nets or use it for any other purpose.
4. Does not have the right to deliberately send any portion of the product to anti-virus companies and other such institutions.
5. Commits to give the seller a fee for any update to the product that is not connected with errors in the work, as well as for adding additional functionality.

In cases of violations of the agreement and being detected, the client loses any technical support. Moreover, the binary code of your bot will be immediately sent to antivirus companies.


It should be noted that these crimeware kits, as I've written frequently, make it fairly easy for not very technical criminals to commit technical crimes. As noted in their licensing agreement, the criminals selling these kits in underground forums even provide technical support.

Interestingly enough, Liam noted:

Despite the clear licensing agreement and the associated warnings, this package still ended up being traded freely in underground forums shortly after it was released. It just goes to show you just can’t trust anyone in the underground these days.

Of course, in most instances, there is no honor among thieves.

Liam notes that this licensing agreement is for much talked about Zeus kit, which has "drive-by" capabilities. If you are unfamiliar with what "drive by" means on the Internet, it means that your computer only needs to visit a site to become infected.

Here is a previous post, I recently did about the "drive by" problem, which is making the Internet a more dangerous place all the time:

Nowadays, all you need to do is visit the wrong site to have your personal information stolen!

Liam's post on the Symantec blog, here.

Thursday, December 27, 2007

Symantec awarded $21 million award against Chinese Software Pirates

On Christmas Eve, Symantec announced a legal victory against Chinese pirates selling their cloned software at super cheap prices.

Please note, I stole the super cheap description from Symantec's video called, The 12 days of Christmas Spam." The super cheap tag can either refer to price, or the quality of counterfeit software (personal thought).

From the press release:

Symantec Corp. (NASDAQ: SYMC) today announced that it was awarded $21 million in damages against a large network of distributors selling counterfeit Symantec software.

The judgments were handed down by the United States District Court for the Central District of California in Los Angeles, CA in favor of Symantec against ANYI, SILI Inc., Mark Ma, Mike Lee, John Zhang, Yee Sha, and related defendants.

"Our customers are the real winners as a result of this case," said Scott Minden, director, Symantec Legal department. "A judgment like this is a crippling blow against these particular syndicates and will drive them even further underground, making it more difficult for them to sell directly to unsuspecting users. It complicates their ability to operate behind the guise as legitimate businesses."
The investigation conducted by Symantec in collusion with the FBI and Chinese authorities also led to some criminal charges being filed in China.

It appears that this particular case involved pirated software being made to appear as if it was the real deal. According to industry experts, the counterfeiting problem has increased 10,000 percent in recent history.

The software industry alone estimates it loses $40 billion a year because of pirated software. I wonder how many jobs this equates to?

Pirated (super cheap software) is also hawked via the millions (billions?) of spam e-mails attacking our in boxes in record amounts. Recently, Symantec issued a report based on the spam data they monitor revealing that over the current holiday season 71percent of all e-mail sent is spam.

Counterfeit software also can contain malware (malicious software), which can lead to your system becoming a zombie (part of a botnet to facilitate more spam) and even steal your personal and financial details. These details are then used to steal money either from you directly, or to steal money from financial institutions.

I'm sometimes amazed how a lot of current criminal activity ties in together via the digital world. All the average person needs to do is to watch all the spam messages they get and consider all the different schemes that are behind them. The schemes are nothing new, but the digital age has enabled criminals to reach out to more people than ever before.

Either this is occurring naturally, or someone pretty organized people are running operations along the lines of major corporations?

Besides the more personal dangers of buying pirated software, there is a lot of evidence the activity is making a lot of money for organized crime, rogue governments and terrorist groups, alike.

Press release from Symantec, here.

Saturday, June 30, 2007

Japanese cop exposes confidential information on 6,000 people using P2P (file-sharing) software

Japanese police car picture courtesy of Flickr

We spend a lot of MONEY protecting computer systems and the information in them. Despite this, information is stolen or compromised from computers, pretty frequently.

One reason for this is it only takes one person, with access to compromise a system and it's security.

Recently, Japan Today, disclosed that a policeman did just this by using P2P file sharing software:

Personal information on some 12,000 people related to criminal investigations has leaked onto the Internet from a computer of a Tokyo police officer via Winny file-sharing software, the Metropolitan Police Department said Friday. This is believed to be the largest volume of data leaked from the police on record, the department said.

In case you've never been exposed to P2P (file sharing) software, it's normally used to share porn, movie, or music files.

Wikipedia lists the dangers of using this type of software, of which there are many:
  • poisoning attacks (e.g. providing files whose contents are different from the description)

  • polluting attacks (e.g. inserting "bad" chunks/packets into an otherwise valid file on the network)

  • defection attacks (users or software that make use of the network without contributing resources to it)

  • insertion of viruses to carried data (e.g. downloaded or carried files may be infected with viruses or other malware)

  • malware in the peer-to-peer network software itself (e.g. distributed software may contain spyware)

  • denial of service attacks (attacks that may make the network run very slowly or break completely)
  • filtering (network operators may attempt to prevent peer-to-peer network data from being carried)

  • identity attacks (e.g. tracking down the users of the network and harassing or legally attacking them)
  • spamming (e.g. sending unsolicited information across the network- not necessarily as a denial of service attack)

Using any of these services, normally slows a computer down to a slow crawl. It can even destroy your computer.


Besides that, it's illegal to share copyrighted material (I think it's considered stealing). Not a very good situation for a policeman to get caught up in. What was he thinking?


Japan Today story, here.


Here is another post, I wrote about the murky world of P2P last year:


How P2P Software like Limewire Compromises Personal and Financial Information

Attrition.org tracks how often information is compromised, and the reasons why, here.