FBI shutters $14m major click-jacking fraud; 4 million computers affected

Summary:A massive click-jacking fraud led millions of users being served ads when seemingly accessing popular websites, which raked in over $14 million in online advertising revenue.

The FBI has been successful in closing a botnet of four million infected computers that led to a DNS malware scam, raking in over $14 million from online advertising clicks along the way.

The two-year investigation -- dubbed 'Operation Ghost Click' -- found that hackers were paid for the number of times users clicked on links from adverts, or how often adverts were displayed on sites, officials said.

Using malware known as 'DNSChanger', forcing machines to rely on rogue DNS servers, hackers pointed web searches to fraudulent IP addresses for over 15,000 domains.

This resulted in many popular websites, from iTunes to Amazon, not displaying the content that was meant to, and instead large advertisements were displayed, or rerouted to money-generating sites. The malware also prevented access to anti-virus sites to prevent the removal of the malware.

Both PCs and Macs were infected, The Register said. The BBC meanwhile said that the case was thought to be the "first case of its kind" because the suspects had set up their own DNS servers, rather than relying on infected others.

According to Trend Micro, on 8th November, the botnet was taken down with industry partners, including the anti-malware company, and the FBI after datacenters in New York and Chicago were raided. Thought to be the biggest cyber-criminal takedown in history, the scheme was thought to have been discovered over five years ago,

Seven men, including six Estonians and one Russian, who remains at large, were charged for the fraud which spread to more than 100 countries, and infected even high level government networks like NASA. Reports show that NASA was the first to discover the malicious software.

Estonia's embassy in the U.S. worked closely with the FBI on the investigation that led to the arrest.

In April 2007, a cyberattack on Estonia's critical national infrastructure shut the country down for days; an attack that was blamed on Russia. Russia denied any involvement.

Related:

Topics: Hardware, Government, Government : US

About

Zack Whittaker writes for ZDNet, CNET, and CBS News. He is based in New York City.

zdnet_core.socialButton.googleLabel Contact Disclosure

Kick off your day with ZDNet's daily email newsletter. It's the freshest tech news and opinion, served hot. Get it.

Related Stories

The best of ZDNet, delivered

You have been successfully signed up. To sign up for more newsletters or to manage your account, visit the Newsletter Subscription Center.
Subscription failed.