<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://en.bharatpedia.org/w/index.php?action=history&amp;feed=atom&amp;title=Mariposa_botnet</id>
	<title>Mariposa botnet - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://en.bharatpedia.org/w/index.php?action=history&amp;feed=atom&amp;title=Mariposa_botnet"/>
	<link rel="alternate" type="text/html" href="https://en.bharatpedia.org/w/index.php?title=Mariposa_botnet&amp;action=history"/>
	<updated>2026-08-20T04:38:12Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.43.6</generator>
	<entry>
		<id>https://en.bharatpedia.org/w/index.php?title=Mariposa_botnet&amp;diff=430200&amp;oldid=prev</id>
		<title>Ajay Kumar: Created a new article</title>
		<link rel="alternate" type="text/html" href="https://en.bharatpedia.org/w/index.php?title=Mariposa_botnet&amp;diff=430200&amp;oldid=prev"/>
		<updated>2023-09-25T18:42:41Z</updated>

		<summary type="html">&lt;p&gt;Created a new article&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;{{Short description|Computer botnet}}&lt;br /&gt;
The &amp;#039;&amp;#039;&amp;#039;Mariposa botnet&amp;#039;&amp;#039;&amp;#039;, discovered December 2008,&amp;lt;ref name=telegraph&amp;gt;{{cite news|url=https://www.telegraph.co.uk/technology/7913767/FBI-arrests-mastermind-of-Mariposa-botnet-computer-code.html |title=FBI arrests &amp;#039;mastermind&amp;#039; of Mariposa botnet computer code |work=[[The Daily Telegraph]]|date=28 July 2010|accessdate=29 July 2010| location=London}}&amp;lt;/ref&amp;gt; is a [[botnet]] mainly involved in [[Confidence trick|cyberscamming]] and [[denial-of-service attack]]s.&amp;lt;ref name=washingtontimes&amp;gt;{{cite web|first=Ali |last=Zerdin|url=http://www.washingtontimes.com/news/2010/jul/28/cyber-mastermind-arrested-questioned-in-slovenia/ |title=Cyber mastermind arrested, questioned in Slovenia |work=[[The Washington Times]]|location=Washington, D.C. |date=28 July 2010 |accessdate=29 July 2010}}&amp;lt;/ref&amp;gt;&amp;lt;ref name=canada&amp;gt;{{cite web|url=http://www2.canada.com/topics/technology/story.html?id=3333655 |title=Suspected &amp;#039;Mariposa Botnet&amp;#039; creator arrested |work=[[Postmedia News|canada.com]] |date=28 July 2010 |accessdate=29 July 2010 |url-status=dead |archive-url=https://web.archive.org/web/20110511115226/http://www2.canada.com/topics/technology/story.html?id=3333655 |archive-date=May 11, 2011 }}&amp;lt;/ref&amp;gt; Before the botnet itself was dismantled on 23 December 2009, it consisted of up to 12 million unique IP addresses or up to 1 million individual [[zombie computer]]s infected with the &amp;quot;Butterfly (&amp;#039;&amp;#039;mariposa&amp;#039;&amp;#039; in Spanish) Bot&amp;quot;, making it one of the largest known botnets.&amp;lt;ref name=canada/&amp;gt;&amp;lt;ref name=defintel&amp;gt;{{cite web|first=Matt |last=Thompson |url=http://www.defintel.com/docs/Mariposa_Analysis.pdf |title=Mariposa Botnet Analysis |work=[[Defence Intelligence (company)|Defintel]] |date=7 October 2009|accessdate=29 July 2010}}&amp;lt;/ref&amp;gt;&amp;lt;ref name=krebs1&amp;gt;{{cite web|first=Brian |last=Krebs |url=http://krebsonsecurity.com/2010/05/accused-mariposa-botnet-operators-sought-jobs-at-spanish-security-firm/ |title=Accused Mariposa Botnet Operators Sought Jobs at Spanish Security Firm |accessdate=14 October 2014}}&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== History ==&lt;br /&gt;
&lt;br /&gt;
=== Origins and initial spread ===&lt;br /&gt;
The botnet was originally created by the DDP Team ([[Spanish language|Spanish:]] &amp;#039;&amp;#039;Días de Pesadilla Team&amp;#039;&amp;#039;, [[English language|English:]] &amp;#039;&amp;#039;Nightmare Days Team&amp;#039;&amp;#039;), using a [[malware]] program called &amp;quot;Butterfly bot&amp;quot;, which was also sold to various individuals and organisations.&amp;lt;ref name=washingtontimes/&amp;gt;&amp;lt;ref name=nzherald&amp;gt;{{cite web|url=http://www.nzherald.co.nz/technology/news/article.cfm?c_id=5&amp;amp;objectid=10661891 |title=FBI says cyber mastermind nabbed|work=[[The New Zealand Herald]]|date=28 July 2010 |accessdate=29 July 2010}} {{Dead link|date=October 2010|bot=H3llBot}}&amp;lt;/ref&amp;gt; The goal of this malware program was to install itself on an uninfected PC, monitoring activity for passwords, bank credentials and credit cards.&amp;lt;ref name=washingtontimes/&amp;gt; After that the malware would attempt to self-propagate to other connectible systems using various supported methods, such as [[Windows Live Messenger|MSN]], [[Peer-to-peer|P2P]] and [[USB]].&amp;lt;ref name=symantec&amp;gt;{{cite web|first=Peter |last=Coogan |url=http://www.symantec.com/connect/blogs/mariposa-butterfly-bot-kit |title=The Mariposa/Butterfly Bot Kit|work=[[NortonLifeLock|Symantec]]|date=7 October 2009|accessdate=29 July 2010}}&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
After completing its initial infection routine the malware would contact a [[Botnet#Command_and_control|command-and-control server]] within the botnet. This command and control server could be used by the controllers of the botnet, in order to issue orders to the botnet itself.&amp;lt;ref name=pandalabs&amp;gt;{{cite web|first=Luis |last=Corrons |url=http://pandalabs.pandasecurity.com/mariposa-botnet/ |title=Mariposa botnet|work=[[Panda Security]]|date=3 March 2010|accessdate=29 July 2010}}&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Operations and impact ===&lt;br /&gt;
The operations executed by the botnet were diverse, in part because parts of the botnet could be rented by third party individuals and organizations.&amp;lt;ref&amp;gt;{{cite web|work=Help Net Security |url=http://www.net-security.org/secworld.php?id=8962 |title=Massive Mariposa botnet shut down |date= 3 March 2010|accessdate=29 July 2010}}&amp;lt;/ref&amp;gt; Confirmed activities include [[denial-of-service attack]]s, [[e-mail spam]], theft of personal information, and changing the search results a browser would display in order to show advertisements and pop-up ads.&amp;lt;ref name=pandalabs/&amp;gt;&amp;lt;ref name=krebsonsecurity&amp;gt;{{cite web|url=http://krebsonsecurity.com/2010/03/mariposa-botnet-authors-may-avoid-jail-time/ |title=&amp;#039;Mariposa&amp;#039; Botnet Authors May Avoid Jail Time|work= Krebs on Security |date=4 March 2010 |accessdate=29 July 2010|first=Brian |last=Krebs}}&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Due to the size and nature of a botnet its total financial and social impact is difficult to calculate, but initial estimates calculated that the removal of the malware alone could cost &amp;quot;tens of millions of dollars&amp;quot;.&amp;lt;ref name=pandalabs/&amp;gt;&amp;lt;ref name=reuters&amp;gt;{{cite news|url=https://www.reuters.com/article/idUSN0218881320100302 |title=Spain busts ring accused of infecting 13&amp;amp;nbsp;mln PCs |publisher=Reuters |date= 2010-03-02|accessdate=2010-07-29}}&amp;lt;/ref&amp;gt; After the apprehension of the botnet&amp;#039;s operators government officials also discovered a list containing personal details on 800,000 individuals, which could be used or sold for [[Identity theft]] purposes.&amp;lt;ref name=reuters/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The countries most infected by the botnet were India, Mexico, Brazil and South Korea.&amp;lt;ref&amp;gt;{{cite web |title=13m users worldwide affected by Mariposa botnet |url=https://www.helpnetsecurity.com/2010/03/10/13m-users-worldwide-affected-by-mariposa-botnet/ |website=Help Net Security |date=10 March 2010}}&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Dismantling ===&lt;br /&gt;
In May 2009 the Mariposa Working Group (MWG) was formed as an informal group, composed of [[Defence Intelligence (company)|Defence Intelligence]], the [[Georgia Tech Information Security Center]] and [[Panda Security]], along with additional unnamed security researchers and law enforcement agencies. The goal of this group was the analysis and extermination of the Mariposa botnet itself.&amp;lt;ref name=pandalabs/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
On 23 December 2009 the Mariposa Working Group managed to take control of the Mariposa Botnet, after seizing control of the [[Botnet#Command_and_control|command-and-control servers]] used by the botnet. The operational owners of the botnet eventually succeeded in regaining control over the botnet, and in response launched a [[denial-of-service attack]] on Defence Intelligence.&amp;lt;ref name=pandalabs/&amp;gt; The attack itself managed to knock out Internet connectivity for a large share of the ISP&amp;#039;s customers, which included several Canadian universities and government agencies.&amp;lt;ref&amp;gt;{{cite news|last=Larraz |first=Teresa |url=https://www.reuters.com/article/idUSTRE6214ST20100303 |title=UPDATE 1-Spain busts ring accused of infecting 13 mln PCs|work=[[Reuters]] |date= 3 March 2010|accessdate=29 July 2010}}&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
On 3 February 2010, the [[Civil Guard (Spain)|Spanish national police]] arrested Florencio Carro Ruiz (alias: Netkairo) as the suspected leader of the DDP Team. Two additional arrests were made on 24 February 2010. Jonathan Pazos Rivera (alias: Jonyloleante) and Juan José Ríos Bellido (alias: Ostiator) were arrested on the suspicion of being members of DDP.&amp;lt;ref name=canada/&amp;gt;&amp;lt;ref name=pandalabs/&amp;gt;&amp;lt;ref name=thetechherald&amp;gt;{{cite web|first=Steve |last=Ragan |url=http://www.thetechherald.com/article.php/201009/5330/Mariposa-botnet-12-7-million-bots-strong-knocked-offline |title=Mariposa botnet – 12.7 million bots strong – knocked offline |work=The Tech Herald |date=3 March 2010 |accessdate=29 July 2010 |url-status=dead |archive-url=https://web.archive.org/web/20100725032024/http://www.thetechherald.com/article.php/201009/5330/Mariposa-botnet-12-7-million-bots-strong-knocked-offline |archive-date=25 July 2010 }}&amp;lt;/ref&amp;gt;&amp;lt;ref name=wtopnews&amp;gt;{{cite web|url=http://www.wtopnews.com/?sid=2013636&amp;amp;nid=108 |title=Cyber mastermind arrested, questioned in Slovenia|work=[[WTOP-FM]] |accessdate=29 July 2010}} {{Dead link|date=December 2013}}&amp;lt;/ref&amp;gt;&amp;lt;ref&amp;gt;{{cite web|url=https://www.fbi.gov/news/pressrel/press-releases/fbi-slovenian-and-spanish-police-arrest-mariposa-botnet-creator-operators|title=FBI, Slovenian and Spanish Police Arrest Mariposa Botnet Creator, Operators|location=Washington, D.C.|date=28 July 2010|work=[[Federal Bureau of Investigation|FBI National Press Office]]|accessdate=27 December 2013}}&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
On 18 July 2010, Matjaž Škorjanc (alias: Iserdo), the creator of the &amp;quot;Butterfly bot&amp;quot; malware, was arrested in [[Maribor]] by [[Slovenian police]] for the first time,&amp;lt;ref&amp;gt;{{cite news |url=http://www.rtvslo.si/crna-kronika/fbi-potrdil-aretacijo-stajerskega-hekerja-ta-ze-na-prostosti/235675 |title=FBI potrdil aretacijo štajerskega hekerja; ta že na prostosti |language=sl|trans-title=FBI Confirms the Arrest of the Styrian Hacker; He Is Already at Large |date=28 July 2010}}&amp;lt;/ref&amp;gt; but released due to lack of evidence. He was arrested again in October 2011.&amp;lt;ref&amp;gt;{{cite news |url=http://www.delo.si/novice/kronika/afera-mariposa-skorjanc-se-ni-zelel-zagovarjati.html |title=Afera Mariposa: Škorjanc se ni želel zagovarjati |newspaper=Delo.si |language=sl|date=6 August 2012 |trans-title=Mariposa Affair: Škorjanc Refuses to Defend Himself}}&amp;lt;/ref&amp;gt; In December 2013 Škorjanc was convicted in Slovenia of &amp;quot;creating a malicious computer program for hacking information systems, assisting in wrongdoings and money laundering.&amp;quot;&amp;lt;ref&amp;gt;{{cite news|title=Creator of Mariposa Botnet Sentenced to 58 Months in Prison|date=23 December 2013|work=Security Week|url=http://www.securityweek.com/creator-mariposa-botnet-sentenced-58-months-prison|accessdate=27 December 2013}}&amp;lt;/ref&amp;gt; He was sentenced to 4 years and 10 months imprisonment and fined [[Euro|€]]3,000 ($3,000).&amp;lt;ref&amp;gt;{{cite news|title=Hacker sentenced for &amp;#039;malicious&amp;#039; programme|work=IOL|url=http://www.iol.co.za/scitech/technology/security/hacker-sentenced-for-malicious-programme-1.1626367|date=24 December 2013|accessdate=27 December 2013}}&amp;lt;/ref&amp;gt; The court also ordered the seizure of Škorjanc&amp;#039;s property acquired with the proceeds of crime.&amp;lt;ref&amp;gt;{{cite news|title=Mariposa botnet &amp;#039;mastermind&amp;#039; jailed in Slovenia|date=24 December 2013|work=[[BBC News]]|url=https://www.bbc.co.uk/news/technology-25506016|accessdate=27 December 2013}}&amp;lt;/ref&amp;gt; After he appealed the verdict his fine was in February 2015 raised for additional 25,000 EUR.&amp;lt;ref&amp;gt;{{cite news|url=http://www.sta.si/vest.php?id=2100646|title=Mariposa Botnet Hacker Fails with Appeal at Higher Court|date=5 February 2015|archive-url=https://archive.today/20150308094953/http://www.sta.si/vest.php?id=2100646|archive-date=2015-03-08|url-status=dead|publisher=Slovenian Press Agency}}&amp;lt;/ref&amp;gt; &lt;br /&gt;
&lt;br /&gt;
On 5 June, 2019, US law enforcement opened a new case in the operations of the Mariposa (Butterfly Bot, BFBOT) malware gang. FBI has moved forward with new charges and arrest warrants against four suspects including [[NiceHash]]&amp;#039;s operator Matjaž Škorjanc.&amp;lt;ref&amp;gt;{{Cite news|url=https://www.zdnet.com/article/eight-years-later-the-case-against-the-mariposa-malware-gang-moves-forward-in-the-us/|title=Eight years later, the case against the Mariposa malware gang moves forward in the US|date=2019-06-11|work=ZDNet|access-date=2019-06-11|language=en-US}}&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
{{Reflist|30em}}&lt;br /&gt;
&lt;br /&gt;
== External links ==&lt;br /&gt;
*[http://defintel.com/docs/Mariposa_Analysis.pdf Analysis of the Mariposa botnet]&lt;br /&gt;
&lt;br /&gt;
{{Botnets}}&lt;br /&gt;
{{Hacking in the 2000s}}&lt;br /&gt;
{{Hacking in the 2010s}}&lt;br /&gt;
&lt;br /&gt;
{{DEFAULTSORT:Mariposa Botnet}}&lt;br /&gt;
[[Category:Internet security]]&lt;br /&gt;
[[Category:Distributed computing projects]]&lt;br /&gt;
[[Category:Spamming]]&lt;br /&gt;
[[Category:Botnets]]&lt;br /&gt;
[[Category:Cybercrime in India]]&lt;/div&gt;</summary>
		<author><name>Ajay Kumar</name></author>
	</entry>
</feed>