Gozi malware hacker sentenced to three years in US prison

Gozi malware hacker sentenced to three years in US prison

A Romanian hacker who ran the infrastructure behind several malware strains was sentenced to three years in U.S. federal prison on Monday.


Prosecutors said 39-year-old Mihai Ionut Paunescu helped run “bulletproof hosting” service PowerHost[.]ro, which helped cybercriminals distribute the Gozi Virus, the Zeus Trojan, the SpyEye Trojan, and the BlackEnergy malware. Cybercriminals used the malware strains to steal financial information, among other purposes.


Paunescu rented servers and IP addresses from legitimate internet providers and then gave the tools to cybercriminals — allowing them to stay anonymous and launch attacks.


Paunescu was also accused of enabling other cybercrimes through his platforms, like distributed denial-of-service (DDoS) attacks and spam campaigns. He was convicted on one charge of conspiracy to commit computer intrusion.


“Paunescu ran a ‘bulletproof’ hosting service that enabled cyber criminals throughout the world to spread malware that stole confidential financial information, crashed websites, and caused other harm,” said U.S. Attorney Damian Williams.


“By allowing cybercriminals to acquire online infrastructure for their unlawful activity without revealing their true identities, Paunescu’s bulletproof hosting service shielded his criminal customers from both law enforcement and cybersecurity professionals, while enriching himself.”


Paunescu, who goes by the moniker “Virus,” was detained in June 2021 at El Dorado International Airport in Bogotá, Colombia after he was initially arrested in December 2012 in Bucharest, Romania. U.S. officials charged him in January 2013 for his role in distributing the Gozi malware, which was pivotal for cybercriminals stealing e-banking credentials and siphoning funds from victim accounts, but they were unable to secure extradition from Romania.


[embedded content]

The Record previously reported that while Paunescu helped a variety of cybercriminal operatio ..

Support the originator by clicking the read the rest link below.