Russian man pleads guilty in SpyEye malware case

Panin was the primary developer of the banking fraud malware, the DOJ says

Russian Aleksandr Andreevich Panin has pleaded guilty to conspiracy to commit wire and bank fraud for his role as primary developer and distributor of the SpyEye bank fraud Trojan, the U.S. Department of Justice said Tuesday.

Panin, known as Gribodemon and Harderman, was primary developer of SpyEye, a sophisticated, malicious computer Trojan designed to automate the theft of confidential personal and financial information, including online banking credentials, credit card information, user names and passwords, the DOJ said in a press release. The virus has infected an estimated 1.4 million computers worldwide since 2009.

The SpyEye code secretly infects victims' computers, enabling cybercriminals to remotely control the infected computers through command and control, or C2, servers. After a computer is infected and under their control, cybercriminals can remotely access the infected computers, without authorization, and steal victims' personal and financial information through a variety of techniques, including keystroke loggers, and credit card grabbers, the DOJ said. The victims' stolen personal and financial data is then transmitted to the C2 servers, where it is used to steal money from the victims' financial accounts.

Panin was the primary developer and distributor of the SpyEye malware package, the DOJ said. Operating from Russia from 2009 to 2011, he conspired with others, including codefendant Hamza Bendelladj, an Algerian national also known as Bx1, to develop, market and sell various versions of the SpyEye virus and component parts on the Internet, the agency alleged.

Panin allowed cybercriminals to customize their purchases to include tailor-made methods of obtaining victims' personal and financial information, and he marketed versions that specifically targeted designated financial institutions, the DOJ said. Panin advertised the SpyEye virus on online, invitation-only criminal forums. He sold versions of SpyEye for US$1,000 to $8,500.

Investigators believe he sold SpyEye to at least 150 clients, who, in turn, used them to set up their own C2 servers. One of Panin's clients, nicknamed Soldier, is believed to have made more than $3.2 million in a six-month period using SpyEye.

"Given the recent revelations of massive thefts of financial information from large retail stores across the country, Americans do not need to be reminded how devastating it is when cybercriminals surreptitiously install malicious codes on computer networks and then siphon away private information from unsuspecting consumers," Acting Assistant U.S. Attorney General Mythili Raman said in a statement.  "As this prosecution shows, cyber criminals -- even when they sit on the other side of the world and attempt to hide behind online aliases -- are never outside the reach of U.S. law enforcement."

SpyEye was the preeminent malware toolkit used from approximately 2009 to 2011, but it continues to infect computers today, the DOJ said.

In February 2011, using a federal search warrant, the U.S. Federal Bureau of Investigation searched and seized a SpyEye C2 server allegedly operated by Bendelladj in the U.S. state of Georgia, the DOJ said. The server controlled over 200 computers infected with the SpyEye virus and contained information from numerous financial institutions.

In June and July 2011, FBI covert sources communicated directly with Panin about SpyEye, the DOJ said. FBI sources then purchased a version of SpyEye from Panin that contained features designed to steal confidential financial information, initiate fraudulent online banking transactions, install keystroke loggers and initiate distributed denial of service attacks from computers infected with the malware.

On Dec. 20, 2011, a grand jury in U.S. District Court for the Northern District of Georgia returned a 23-count indictment against Panin, who had yet to be fully identified, and Bendelladj. The indictment charged one count of conspiracy to commit wire and bank fraud, 10 counts of wire fraud, one count of conspiracy to commit computer fraud, and 11 counts of computer fraud. A superseding indictment was subsequently returned identifying Panin by his name.

Bendelladj was apprehended at Suvarnabhumi Airport in Bangkok, Thailand, on Jan. 5, 2013, while he was in transit from Malaysia to Algeria. Bendelladj was extradited from Thailand to the U.S. last May. His charges are currently pending in the Northern District of Georgia.

Panin was arrested by U.S. authorities on July 1, 2013, when he arrived on a flight at Hartsfield-Jackson Atlanta International Airport. Reports at the time said he was taken into custody in the Dominican Republic and flown to Atlanta from there. Russian authorities were reported to have been outraged by the maneuver. The investigation also has led to the arrest of four of Panin's SpyEye clients and associates in the U.K. and Bulgaria.

On Jan. 28, Panin pleaded guilty to conspiring to commit wire and bank fraud. Sentencing is scheduled for April 29.

Grant Gross covers technology and telecom policy in the U.S. government for The IDG News Service. Follow Grant on Twitter at GrantGross. Grant's email address is grant_gross@idg.com.

Join the Good Gear Guide newsletter!

Error: Please check your email address.

Tags U.S. Federal Bureau of InvestigationAleksandr Andreevich PaninU.S. Department of JusticeMythili RamansecuritylegalmalwarecybercrimeHamza Bendelladj

Our Back to Business guide highlights the best products for you to boost your productivity at home, on the road, at the office, or in the classroom.

Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.

Grant Gross

IDG News Service
Show Comments

Essentials

Microsoft L5V-00027 Sculpt Ergonomic Keyboard Desktop

Learn more >

Lexar® JumpDrive® S57 USB 3.0 flash drive

Learn more >

Mobile

Lexar® JumpDrive® S45 USB 3.0 flash drive 

Learn more >

Exec

Audio-Technica ATH-ANC70 Noise Cancelling Headphones

Learn more >

HD Pan/Tilt Wi-Fi Camera with Night Vision NC450

Learn more >

Lexar® Professional 1800x microSDHC™/microSDXC™ UHS-II cards 

Learn more >

Lexar® JumpDrive® C20c USB Type-C flash drive 

Learn more >

Budget

Back To Business Guide

Click for more ›

Most Popular Reviews

Latest News Articles

Resources

PCW Evaluation Team

Azadeh Williams

HP OfficeJet Pro 8730

A smarter way to print for busy small business owners, combining speedy printing with scanning and copying, making it easier to produce high quality documents and images at a touch of a button.

Andrew Grant

HP OfficeJet Pro 8730

I've had a multifunction printer in the office going on 10 years now. It was a neat bit of kit back in the day -- print, copy, scan, fax -- when printing over WiFi felt a bit like magic. It’s seen better days though and an upgrade’s well overdue. This HP OfficeJet Pro 8730 looks like it ticks all the same boxes: print, copy, scan, and fax. (Really? Does anyone fax anything any more? I guess it's good to know the facility’s there, just in case.) Printing over WiFi is more-or- less standard these days.

Ed Dawson

HP OfficeJet Pro 8730

As a freelance writer who is always on the go, I like my technology to be both efficient and effective so I can do my job well. The HP OfficeJet Pro 8730 Inkjet Printer ticks all the boxes in terms of form factor, performance and user interface.

Michael Hargreaves

Windows 10 for Business / Dell XPS 13

I’d happily recommend this touchscreen laptop and Windows 10 as a great way to get serious work done at a desk or on the road.

Aysha Strobbe

Windows 10 / HP Spectre x360

Ultimately, I think the Windows 10 environment is excellent for me as it caters for so many different uses. The inclusion of the Xbox app is also great for when you need some downtime too!

Mark Escubio

Windows 10 / Lenovo Yoga 910

For me, the Xbox Play Anywhere is a great new feature as it allows you to play your current Xbox games with higher resolutions and better graphics without forking out extra cash for another copy. Although available titles are still scarce, but I’m sure it will grow in time.

Featured Content

Latest Jobs

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?