14 June 2023

Bulletproof hoster who helped distribute Gozi and Zeus sentenced to 3 years in prison


Bulletproof hoster who helped distribute Gozi and Zeus sentenced to 3 years in prison

Romanian national Mihai Ionut Paunescu was sentenced to three years in prison for running PowerHost[.]ro, a bulletproof service that enabled cybercriminals to distribute various banking and information stealing malware families, including the Gozi (Ursnif), Zeus, and SpyEye trojans, as well as the BlackEnergy malware.

BlackEnergy is a Russia-linked piece of malware previously observed in campaigns targeting government organizations and power grids in Ukraine,

BlackEnergy was created by researcher Dmytro Oleksiuk (aka Cr4sh) in 2007 as a DDoS trojan. By the end of 2007 cybersecurity firm Arbor Networks identified about 30 botnets build using BlackEnergy. In 2009, Oleksiuk tried to distance himself from his creation and wrote in his blog that the source code of his tool was publicly accessible and anyone could use it.

The second version of the malware first spotted in 2010 implemented capabilities beyond DDoS. The third version of BlackEnergy released in 2014 was equipped with a variety of plug-ins.

Paunescu offered servers and IP addresses rented from legitimate providers to cybercriminals who could use them as an infrastructure for conducting distributed denial-of-service attacks or dessiminate spam emails. Paunescu also monitored IPs to determine if they were marked as suspicious or untrustworthy, and relocated his customers’ data to different networks and IP addresses when blocked by private security firms or law enforcement agencies.

Paunescu was initially arrested in Romania in December 2012 and released on bail and he was arrested again in Colombia in 2021. He was extradited to the United States last year and he pled guilty in February 2023.

In addition to his prison sentence, Paunescu was ordered to forfeit $3,510,000 and pay restitution in the amount of $18,945.


Back to the list

Latest Posts

What is Vulnerability Management? A Beginner's Guide

What is Vulnerability Management? A Beginner's Guide

In this article will try to cover basics of vulnerability management process and why it is important to every company.
11 September 2024
Cyber Security Week in Review: September 6, 2024

Cyber Security Week in Review: September 6, 2024

In brief: the US charges Russian GRU hackers for attacks on Ukraine, Apache, Cisco, Zyxel patch high-risk flaws, Google fixes Android zero-day, and more.
6 September 2024
Threat actors using MacroPack Red Team framework to deploy Brute Ratel, Havoc and PhantomCore

Threat actors using MacroPack Red Team framework to deploy Brute Ratel, Havoc and PhantomCore

Some of the documents appeared to be part of legitimate Red Team exercises, while other were intended for malicious purposes.
5 September 2024