Security Experts:

Connect with us

Hi, what are you looking for?



Bayrob Malware Operators Convicted in the U.S.

Two Romanians have been convicted in the United States for their role in a longstanding online fraud operation that incurred millions of dollars in losses.

Two Romanians have been convicted in the United States for their role in a longstanding online fraud operation that incurred millions of dollars in losses.

The two, Bogdan Nicolescu, 36, and Radu Miclaus, 37, both residents of Bucharest, Romania, were found guilty after a 12-day trial on 21 counts related to their scheme. They were indicted in December 2016 and are scheduled for sentencing on August 14, 2019.

According to court documents and testimony at trial, the two started the criminal conspiracy in 2007 with the development of proprietary malware known as Bayrob, which was being distributed via malicious emails purporting to be from Western Union, Norton AntiVirus and the IRS.

Bayrob was designed to harvest email addresses from the infected computers, including those stored in contact lists or email accounts, and then send malicious emails to these addresses, to spread further. The cybercriminals infected and controlled over 400,000 computers, primarily in the United States.

The cybercriminals leveraged control of these computers to harvest personal information from victims, including card information, usernames and passwords. They also disabled victims’ malware protection and blocked them from accessing websites associated with law enforcement.

Nicolescu and Miclaus also leveraged the control over the infected machines to mine for crypto-currency and to register email accounts with AOL. Over 100,000 email accounts were registered this way, and then employed to send tens of millions of malicious emails to the compromised contact lists.

The cybercriminals also intercepted requests to websites such as Facebook, PayPal, eBay and others, and redirected the victims to nearly identical domains to steal account credentials. They also injected fake pages into legitimate websites to trick users into following fake instructions.

Stolen credit card information was used to fund the criminal infrastructure, such as renting server space, registering domain names using fictitious identities, and paying for Virtual Private Networks (VPNs) to conceal identities.

The cybercriminals placed more than 1,000 fraudulent listings for automobiles, motorcycles and other high-priced goods on eBay and similar auction sites, using photos infected with malware, meant to redirect computers to fictitious webpages that resembled legitimate eBay pages.

These pages asked users to pay for goods through a nonexistent “eBay Escrow Agent,” who was a person hired by the defendants. The fraudulent escrow agents wired the money to others in Eastern Europe, who in turn gave it to the defendants, while the victims never received the items and never got their money back.

In an effort to launder the millions of dollars in losses caused this way, the Bayrob group hired money mules and created fictitious companies with fraudulent websites to pose as legitimate financial transactions. Money was wired to the fraudulent companies and then to Western Union or MoneyGram offices in Romania. The mules collected the money and delivered it to the defendants.

Related: Head of Money Mule Operation Extradited to the United States

Related: Bayrob Malware Operators Indicted in U.S.

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Click to comment

Expert Insights

Related Content


Zendesk is informing customers about a data breach that started with an SMS phishing campaign targeting the company’s employees.


The release of OpenAI’s ChatGPT in late 2022 has demonstrated the potential of AI for both good and bad.


A new study by McAfee and the Center for Strategic and International Studies (CSIS) named a staggering figure as the true annual cost of...


Video games developer Riot Games says source code was stolen from its development environment in a ransomware attack


The FBI dismantled the network of the prolific Hive ransomware gang and seized infrastructure in Los Angeles that was used for the operation.


Artificial intelligence is competing in another endeavor once limited to humans — creating propaganda and disinformation.


The Hive ransomware website has been seized as part of an operation that involved law enforcement in 10 countries.


A digital ad fraud scheme dubbed "VastFlux" spoofed over 1,700 apps and peaked at 12 billion ad requests per day before being shut down.