2023-06-12 DOJ SDNY press_release 120 KB 6,706 chars

Romanian National Who Operated “Bulletproof Hosting” Service That Facilitated The Distribution Of Destructive Malware Sentenced To Three Years In Prison

Caption
United States v. Computer Intrusion, et al.
summary

Romanian national Mihai Ionut Paunescu, aka 'Virus,' was sentenced to three years in prison for operating a bulletproof hosting service that enabled the distribution of malware like Gozi, Zeus, SpyEye, and BlackEnergy, stealing financial data from over a million computers worldwide and causing tens of millions in losses, while profiting $3.51 million and forfeiting those ill-gotten gains.

paragraph

Mihai Ionut Paunescu pleaded guilty to conspiracy to commit computer intrusion for running a bulletproof hosting service that provided anonymous infrastructure to cybercriminals distributing the Gozi Virus, Zeus Trojan, SpyEye Trojan, and BlackEnergy malware. These malwares infected over one million computers globally—including NASA systems—stealing bank credentials and causing tens of millions of dollars in losses, while Paunescu earned $3.51 million by renting servers, IP addresses, and command-and-control systems designed to evade law enforcement. He was sentenced to three years in prison, ordered to forfeit $3,510,000, pay $18,945 in restitution, and received credit for over a year of pre-trial custody in Romania and Colombia.

narrative

Mihai Ionut Paunescu, a Romanian national known as 'Virus,' was sentenced to three years in prison for operating a bulletproof hosting service that enabled cybercriminals to distribute destructive malware including the Gozi Virus, Zeus Trojan, SpyEye Trojan, and BlackEnergy. These malwares infected over one million computers worldwide, including systems at NASA, and were designed to steal bank account credentials, leading to tens of millions of dollars in financial losses across the U.S., Europe, and beyond. Paunescu provided cybercriminals with anonymous server infrastructure, IP addresses, and command-and-control capabilities, actively relocating data to evade detection by security firms and law enforcement. He rented resources from legitimate ISPs and then resold them to criminals, monitoring blacklists and shifting infrastructure internationally to maintain service continuity. Paunescu generated $3.51 million in illicit profits from this scheme and pleaded guilty on February 24, 2023, before U.S. Magistrate Judge Valerie Figueredo. U.S. District Judge Lorna Schofield imposed the three-year sentence, credited Paunescu for over a year and two months of pre-trial detention in Romania and Colombia, and ordered him to forfeit $3.51 million and pay $18,945 in restitution. The U.S. Department of Justice credited international cooperation with Romanian and Colombian authorities for his arrest and extradition, highlighting the global nature of the cybercrime network he supported.

Enriched metadata

Scheme
cyber-fraud (100%)
Court
Southern District of New York
Outcome
pleaded · 2023-02-24
Restitution
$18,945,000,000
Classified cyber-fraud(confidence 100%). No EDGAR filing fingerprint (criminal/DOJ-side scheme). detection rule →
Parties
computer intrusionconfidential financial informationconsiderable moneydamian williamsgozi virusmihai ionut paunescupersonal bank account informationspyeye trojanzeus trojan
Keywords
gozi virusbulletproof hostinghosting servicecyber criminalspaunescuvirusservicegozibulletproofmalwarehostingoperated bulletprooffacilitated distributioncybercriminals

Extracted insights

Dollar amounts 2
  • $3.51M $3,510,000 $1M–$10M
  • $19K $18,945 $10K–$100K
Entities 9
  • person computer intrusion
  • person confidential financial information
  • person considerable money
  • person damian williams
  • person gozi virus
  • person mihai ionut paunescu
  • person personal bank account information
  • person spyeye trojan
  • person zeus trojan
Triples 20
  • MIHAI IONUT PAUNESCU was sentenced to three years in prison
  • MIHAI IONUT PAUNESCU operated “Bulletproof Hosting” Service
  • MIHAI IONUT PAUNESCU conspired to commit computer intrusion
  • MIHAI IONUT PAUNESCU enabled distribution of the Gozi Virus
  • MIHAI IONUT PAUNESCU enabled distribution of the Zeus Trojan
  • MIHAI IONUT PAUNESCU enabled distribution of the SpyEye Trojan
  • MIHAI IONUT PAUNESCU enabled distribution of the BlackEnergy malware
  • MIHAI IONUT PAUNESCU pled guilty before U.S. Magistrate Judge Valerie Figueredo
  • MIHAI IONUT PAUNESCU was sentenced by U.S. District Judge Lorna G. Schofield
  • Damian Williams announced sentencing of MIHAI IONUT PAUNESCU
  • Damian Williams is United States Attorney for the Southern District of New York
  • Gozi Virus infected over one million victim computers worldwide
  • Gozi Virus caused tens of millions of dollars in losses
  • Gozi Virus stole personal bank account information
  • Zeus Trojan was designed to steal confidential financial information
  • SpyEye Trojan was designed to steal confidential financial information
  • BlackEnergy was designed to launch World Wide Web-based DDoS attacks
  • MIHAI IONUT PAUNESCU facilitated distribution of destructive malware
  • MIHAI IONUT PAUNESCU made considerable money
  • MIHAI IONUT PAUNESCU will be required to forfeit ill-gotten gains
View original DOJ press releasejustice.gov
Extracted body text (6,706c)
Press Release Romanian National Who Operated “Bulletproof Hosting” Service That Facilitated The Distribution Of Destructive Malware Sentenced To Three Years In Prison Monday, June 12, 2023 Share FacebookLinks to other government and non-government sites will typically appear with the “external link” icon to indicate that you are leaving the Department of Justice website when you click the link. XLinks to other government and non-government sites will typically appear with the “external link” icon to indicate that you are leaving the Department of Justice website when you click the link. LinkedInLinks to other government and non-government sites will typically appear with the “external link” icon to indicate that you are leaving the Department of Justice website when you click the link. Email For Immediate Release U.S. Attorney's Office, Southern District of New York Damian Williams, the United States Attorney for the Southern District of New York, announced that MIHAI IONUT PAUNESCU, a/k/a “Virus,” was sentenced to three years in prison today in Manhattan federal court for conspiracy to commit computer intrusion in connection with running a “bulletproof hosting” service that enabled cybercriminals to distribute the Gozi Virus, the Zeus Trojan, the SpyEye Trojan, and the BlackEnergy malware, all of which were designed to steal confidential financial information. PAUNESCU also enabled other cybercrimes, such as initiating and executing distributed denial of service (“DDoS”) attacks and transmitting spam. PAUNESCU previously pled guilty before U.S. Magistrate Judge Valerie Figueredo on February 24, 2023. He was sentenced today by U.S. District Judge Lorna G. Schofield. U.S. Attorney Damian Williams said: “Paunescu ran a ‘bulletproof’ hosting service that enabled cyber criminals throughout the world to spread malware that stole confidential financial information, crashed websites, and caused other harm. By allowing cybercriminals to acquire online infrastructure for their unlawful activity without revealing their true identities, Paunescu’s bulletproof hosting service shielded his criminal customers from both law enforcement and cybersecurity professionals, while enriching himself. Paunescu now faces prison time and will be required to forfeit his ill-gotten gains.” In imposing today’s sentence, Judge Schofield said that PAUNESCU facilitated the distribution of “some of the most serious malware circulating at the time” and “made considerable money from it.” As alleged in the Complaint, the Indictment, other documents in this case, and statements made in court: The Gozi Virus is malicious computer code or “malware” that stole personal bank account information, including usernames and passwords, from the users of affected computers. The Gozi Virus infected over one million victim computers worldwide, among them at least 40,000 computers in the United States, including computers belonging to the National Aeronautics and Space Administration (“NASA”), as well as computers in Germany, Great Britain, Poland, France, Finland, Italy, Turkey, and elsewhere. The Gozi Virus caused tens of millions of dollars in losses to the individuals, businesses, and government entities whose computers were infected. Once installed, the Gozi Virus – which was intentionally designed to be undetectable by anti-virus software – collected data from the infected computer in order to capture personal bank account information, including usernames and passwords. That data was then transmitted to various computer servers controlled by the cyber criminals who used the Gozi Virus. These cyber criminals then used the personal bank account information to transfer funds out of the victims’ bank accounts and ultimately into their own personal possession. Similar to the Gozi Virus, the Zeus Trojan and the SpyEye Trojan were designed to steal confidential financial information from victims’ computers. BlackEnergy was initially designed to launch World Wide Web-based DDoS attacks and later upgraded to include the ability to steal account access credentials. “Bulletproof hosting” services helped cyber criminals distribute the Gozi Virus with little fear of detection by law enforcement. Bulletproof hosts provided cyber criminals using the Gozi Virus with the critical online infrastructure they needed, such as Internet Protocol (“IP”) addresses and computer servers, in a manner designed to enable them to preserve their anonymity. PAUNESCU operated a “bulletproof hosting” service that helped cyber criminals to distribute some of the world’s most harmful malware, including the Gozi Virus, the Zeus Trojan, the SpyEye Trojan, and BlackEnergy, as well to as commit other cybercrimes, such as transmitting spam, which is an often used means of distributing malware. PAUNESCU rented servers and IP addresses from legitimate Internet service providers and then, in, turn rented those resources to cybercriminals; provided servers that cyber criminals used as command-and-control servers to conduct DDoS attacks; monitored the IP addresses that he controlled to determine if they appeared on a special list of suspicious or untrustworthy IP addresses; and relocated his customers’ data to different networks and IP addresses, including networks and IP addresses in other countries, to avoid being blocked as a result of private security or law enforcement scrutiny. * * * In imposing the sentence, Judge Schofield gave PAUNESCU credit for the approximately one year and two months that the defendant was held in Romanian and Colombian custody prior to his extradition to the United States. In addition to his prison sentence, PAUNESCU, 39, of Bucharest, Romania, was ordered to forfeit $3,510,000 and pay restitution in the amount of $18,945. Mr. Williams praised the investigative work of the Federal Bureau of Investigation. Mr. Williams also thanked the NASA Office of Inspector General and the Colombian National Police. In addition, Mr. Williams thanked the Department of Justice’s Computer Crime and Intellectual Property Section for its partnership in this matter. The U.S. Department of Justice’s Office of International Affairs of the Department’s Criminal Division, the Narcotic and Dangerous Drug Section Judicial Attachés in Bogota, Colombia, and the U.S. Marshal Service provided significant assistance in securing the defendant’s extradition from Colombia. The prosecution of this case is being handled by the Office’s Complex Frauds and Cybercrime Unit. Assistant U.S. Attorney Sarah Lai is in charge of the prosecution. Contact Nicholas Biase (212) 637-2600 Updated June 12, 2023 Topic Cybercrime Component USAO - New York, Southern Press Release Number: 23-216
OCR text (6,706c · html-text · 99% conf)
Press Release Romanian National Who Operated “Bulletproof Hosting” Service That Facilitated The Distribution Of Destructive Malware Sentenced To Three Years In Prison Monday, June 12, 2023 Share FacebookLinks to other government and non-government sites will typically appear with the “external link” icon to indicate that you are leaving the Department of Justice website when you click the link. XLinks to other government and non-government sites will typically appear with the “external link” icon to indicate that you are leaving the Department of Justice website when you click the link. LinkedInLinks to other government and non-government sites will typically appear with the “external link” icon to indicate that you are leaving the Department of Justice website when you click the link. Email For Immediate Release U.S. Attorney's Office, Southern District of New York Damian Williams, the United States Attorney for the Southern District of New York, announced that MIHAI IONUT PAUNESCU, a/k/a “Virus,” was sentenced to three years in prison today in Manhattan federal court for conspiracy to commit computer intrusion in connection with running a “bulletproof hosting” service that enabled cybercriminals to distribute the Gozi Virus, the Zeus Trojan, the SpyEye Trojan, and the BlackEnergy malware, all of which were designed to steal confidential financial information. PAUNESCU also enabled other cybercrimes, such as initiating and executing distributed denial of service (“DDoS”) attacks and transmitting spam. PAUNESCU previously pled guilty before U.S. Magistrate Judge Valerie Figueredo on February 24, 2023. He was sentenced today by U.S. District Judge Lorna G. Schofield. U.S. Attorney Damian Williams said: “Paunescu ran a ‘bulletproof’ hosting service that enabled cyber criminals throughout the world to spread malware that stole confidential financial information, crashed websites, and caused other harm. By allowing cybercriminals to acquire online infrastructure for their unlawful activity without revealing their true identities, Paunescu’s bulletproof hosting service shielded his criminal customers from both law enforcement and cybersecurity professionals, while enriching himself. Paunescu now faces prison time and will be required to forfeit his ill-gotten gains.” In imposing today’s sentence, Judge Schofield said that PAUNESCU facilitated the distribution of “some of the most serious malware circulating at the time” and “made considerable money from it.” As alleged in the Complaint, the Indictment, other documents in this case, and statements made in court: The Gozi Virus is malicious computer code or “malware” that stole personal bank account information, including usernames and passwords, from the users of affected computers. The Gozi Virus infected over one million victim computers worldwide, among them at least 40,000 computers in the United States, including computers belonging to the National Aeronautics and Space Administration (“NASA”), as well as computers in Germany, Great Britain, Poland, France, Finland, Italy, Turkey, and elsewhere. The Gozi Virus caused tens of millions of dollars in losses to the individuals, businesses, and government entities whose computers were infected. Once installed, the Gozi Virus – which was intentionally designed to be undetectable by anti-virus software – collected data from the infected computer in order to capture personal bank account information, including usernames and passwords. That data was then transmitted to various computer servers controlled by the cyber criminals who used the Gozi Virus. These cyber criminals then used the personal bank account information to transfer funds out of the victims’ bank accounts and ultimately into their own personal possession. Similar to the Gozi Virus, the Zeus Trojan and the SpyEye Trojan were designed to steal confidential financial information from victims’ computers. BlackEnergy was initially designed to launch World Wide Web-based DDoS attacks and later upgraded to include the ability to steal account access credentials. “Bulletproof hosting” services helped cyber criminals distribute the Gozi Virus with little fear of detection by law enforcement. Bulletproof hosts provided cyber criminals using the Gozi Virus with the critical online infrastructure they needed, such as Internet Protocol (“IP”) addresses and computer servers, in a manner designed to enable them to preserve their anonymity. PAUNESCU operated a “bulletproof hosting” service that helped cyber criminals to distribute some of the world’s most harmful malware, including the Gozi Virus, the Zeus Trojan, the SpyEye Trojan, and BlackEnergy, as well to as commit other cybercrimes, such as transmitting spam, which is an often used means of distributing malware. PAUNESCU rented servers and IP addresses from legitimate Internet service providers and then, in, turn rented those resources to cybercriminals; provided servers that cyber criminals used as command-and-control servers to conduct DDoS attacks; monitored the IP addresses that he controlled to determine if they appeared on a special list of suspicious or untrustworthy IP addresses; and relocated his customers’ data to different networks and IP addresses, including networks and IP addresses in other countries, to avoid being blocked as a result of private security or law enforcement scrutiny. * * * In imposing the sentence, Judge Schofield gave PAUNESCU credit for the approximately one year and two months that the defendant was held in Romanian and Colombian custody prior to his extradition to the United States. In addition to his prison sentence, PAUNESCU, 39, of Bucharest, Romania, was ordered to forfeit $3,510,000 and pay restitution in the amount of $18,945. Mr. Williams praised the investigative work of the Federal Bureau of Investigation. Mr. Williams also thanked the NASA Office of Inspector General and the Colombian National Police. In addition, Mr. Williams thanked the Department of Justice’s Computer Crime and Intellectual Property Section for its partnership in this matter. The U.S. Department of Justice’s Office of International Affairs of the Department’s Criminal Division, the Narcotic and Dangerous Drug Section Judicial Attachés in Bogota, Colombia, and the U.S. Marshal Service provided significant assistance in securing the defendant’s extradition from Colombia. The prosecution of this case is being handled by the Office’s Complex Frauds and Cybercrime Unit. Assistant U.S. Attorney Sarah Lai is in charge of the prosecution. Contact Nicholas Biase (212) 637-2600 Updated June 12, 2023 Topic Cybercrime Component USAO - New York, Southern Press Release Number: 23-216