Cybercriminals Use 1.7 Million Compromised PCs in Botnet Advertising Fraud Scam

Stu Sjouwerman | Dec 10, 2018
botnet_Alert-1

The Russian-born, botnet-driven advertising fraud scam, 3ve, generated over $29 million in revenue using fileless malware variant Kovter, botnets, and unsuspecting users.

The U.S. Department of Justice announced last week that it had indicted eight individuals – mostly from the Russian Federation – as part of a multiyear FBI investigation into cybercriminal organizations that perpetrate digital advertising fraud. Using a combination of malware, botnets, and computer infrastructure located around the world, this scam, pronounced “eve”, sought out to earn money through digital advertising click fraud.

The cybercriminals leveraged an impressive arsenal of tech to pull this off:

  • 1 Million compromised IP addresses
  • 1000+ Data Center nodes
  • 60,000 accounts selling ad inventory
  • 10,000+ counterfeited websites
  • 700,000 actively infected endpoint at any given time

What made this scam work was the 1.7 million infected endpoints – necessary to ensure the click fraud looked like it was coming from legitimate web users.

Cybercriminals will take advantage of users as unwitting pawns in scams like this. While your organization isn’t the final victim, a compromised endpoint can be sold off on the dark web to other bad guys looking to leverage it for ransomware, data theft, cryptomining, or fraud.

Organizations can protect themselves against these kinds of attacks through Security Awareness Training. By educating users about social engineering scams, phishing attacks, and how to securely interact with both email and the web, organizations can minimize the attack surface, reducing the likelihood of becoming a victim.

In the case of the 3ve scam, any suspects currently located in Russia will probably never see the inside of a court room as, historically, Russia has never extradited a cybercrime suspect. So, it seems, that while the FBI has arrested 3 of the 8 men responsible, they all will likely be free soon to launch their next campaign. Train your users!


Find out how affordable new-school security awareness training is for your organization. Get a quote now.

 
Get A Quote
Request A Demo
 

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.