Skip to main content

Suspended Sentence for Mirai Botmaster Daniel Kaye

Last month, KrebsOnSecurity identified U.K. citizen Daniel Kaye as the likely real-life identity behind a hacker responsible for clumsily wielding a powerful botnet built on Mirai, a malware strain that enslaves poorly secured Internet of Things (IoT) devices for use in large-scale online attacks. Today, a German court issued a suspended sentence for Kaye, who now faces cybercrime charges in the United Kingdom.
In February 2017, authorities in the United Kingdom arrested a 29-year-old U.K. man on suspicion of knocking more than 900,000 Germans offline in a Mirai attack in November 2016. Shortly after that 2016 attack, a hacker using the nickname “Bestbuy” told reporters he was responsible for the outage, apologizing for the incident.
Prosecutors in Europe had withheld Kaye’s name from the media throughout the trial. But a court in
Germany today confirmed Kaye’s identity as it handed down a suspended sentence on charges stemming from several failed attacks from his Mirai botnet — which nevertheless caused extensive internet outages for ISPs in the U.K., Germany and Liberia last year.
On July 5, KrebsOnSecurity published Who is the GovRAT Author and Mirai Botmaster BestBuy. The story followed clues from reports produced by a half-dozen security firms that traced common clues between this BestBuy nickname and an alter-ego, “Spiderman.”
Both identities were connected to the sale of an espionage tool called GovRAT, which is documented to have been used in numerous cyber espionage campaigns against governments, financial institutions, defense contractors and more than 100 corporations.
That July 5 story traced a trail of digital clues left over 10 years back to Daniel Kaye, a 29-year-old man who had dual U.K. and Israeli citizenship and who was engaged to be married to a U.K. woman.
A “mind map” tracing some of the research mentioned in this post.
Last week, a 29-year-old identified by media only as “Daniel K” pleaded guilty in a German court for launching the attacks that knocked 900,000 Deutsche Telekom customers offline. Prosecutors said Daniel K sold access to his Mirai botnet as an attack-for-hire service.
The defendant reportedly told the court that the incident was the biggest mistake of his life, and that he took money in exchange for launching attacks in order to help start a new life with his fiancee.
Today, the regional court in the western city of Cologne said it would suspend the sentence of one year and eight months against Kaye, according to a report from Agence France Presse.
While it may seem that Kaye was given a pass by the German court, he is still facing criminal charges in Britain, where authorities have already requested his extradition.
As loyal readers here no doubt know, KrebsOnSecurity last year was massively attacked by the first-ever Mirai botnet — an attack which knocked this site offline for almost four days before it came back online under the protection of Google’s Project Shield service.
In January 2017, this blog published the results of a four-month investigation into who was likely responsible for not only for writing Mirai, but for leaking the source code for the malware — spawning dozens of competing Mirai botnets like the one that Kaye built. To my knowledge, no charges have yet been filed against any of the individuals named in that story.

Comments

Popular posts from this blog

Missing Indian student commits suicide in Germany

  Prime News, Karnataka, June 23:- German police found the belongings of an Indian student who was missing, near a river raising the

Panda mania hits Germany as China’s cuddly envoys arrive

  BERLIN: Germany was bracing for panda mania as furry ambassadors arrive from China on Saturday, destined for a new life as stars of Berlin’s premier zoo.  The pair, named Meng Meng and Jiao Qing, will be

UPDATE 1-Poland expects long term deal for U.S. LNG supplies

Poland expects to sign a long-term deal for liquefied natural gas (LNG) supplies from the U.S. to reduce its reliance on Russian gas, the country's President Andrzej Duda said after meeting U.S. president Donald Trump. Poland imports most of the 16 billion cubic metres of gas it consumes a year from Russia, on the basis of a long-term deal with Gazprom which expires in 2022. Warsaw plans to replace the Russian gas after then with supplies from Norway via a planned pipeline as well as with more LNG from the U.S. coming to its terminal at the Baltic Sea. Duda spoke to Trump, who is visiting Warsaw, about Poland's security and gas supplies. "Let's hope for more supplies and further diversification of supplies of this commodity to Poland," Duda said