Investigations on a Cybercrime Hub in Estonia

Tartu, Estonia is the hometown of an Internet company that, from the outside, looks just like any other legitimate Internet service provider ISP. On its website see Figure 1, the company lists services such as hosting and advertising. According to publicly available information, it posted more than US$5 million in revenue and had more than 50 employees in 2007.

In reality, however, this company has been serving as the operational headquarters of a large cybercrime network since 2005. From its office in Tartu, employees administer sites that host codec Trojans and command and control C&C servers that steer armies of infected computers. The criminal outfit uses a lot of daughter companies that operate in Europe and in the United States. These daughter companies’ names quickly get the heat when they become involved in Internet abuse and other cybercrimes. They disappear after getting bad publicity or when upstream providers terminate their contracts.

via Investigations on a Cybercrime Hub in Estonia | Malware Blog | Trend Micro.

Share this article:
  • Twitter
  • Facebook
  • MySpace
  • LinkedIn
  • FriendFeed
  • Ping.fm
  • Google Bookmarks
  • Live
  • StumbleUpon
  • Reddit
  • Technorati
  • Digg
  • Fark
  • del.icio.us
  • RSS
  • email
  • Print
  • PDF

August 26, 2009   Posted in: Malware

Leave a Reply