July brings an end to Operation Ghost Click

Share this article

Operation Ghost ClickIn November of 2011, the FBI arrested and charged six Estonians for running an international fraud-ring that effected millions of computers around the world. Using sophisticated Malware, these individuals redirected individuals to their servers. They were not after changing content, but changing the ads. Their scheme defrauded $14 million dollars from USA citizens alone. The arrest of these individuals was a result of two years of investigation under Operation Ghost Click. Simply confiscating the servers used by the fraud-ring would have left millions of users without access to Internet. Consequently, the FBI worked with the Internet Systems Consortium (ISC) to deploy temporary clean DNS servers.

The Internet actually uses binary numbers and not names to route requests to servers and return the response to your machine. In the early days of Internet (meaning in the 1970’s), you needed to manually route an email from your system to another system. I had a chart on my office wall that I used to write the “bang address,” a bang is the geek word for an exclamation mark, that identified every computer that message had to pass through to get to the destination. As the Internet grew, this system became a bit unwieldy. The eventual solution to this problem was the Domain Name System (DNS). DNS is a distributed database that converts domain names to binary addresses. Every computer that connects to the Internet has a DNS client that talks to the DNS servers to resolve the name to a binary address. Once the address is known, the computer can send a request to another computer, and the other computer can return the answer.

The fraud-ring used malware called DNSChanger to send DNS name resolution requests to a fake name server. Consequently, the Web traffic from infected computers was sent to fake Web servers. To make matters worse, the malware disabled updates from anti-virus software to avoid removal of the malware. After the FBI broke up the fraud-ring, the ISC installed temporary DNS servers that would redirect DNS requests from the infected machines to the correct address. The temporary servers were only to be in place until March of 2012. To assist the users of infected machines, the FBI obtained a court order extending the use of the temporary DNS servers until July 9, 2012.

Of the millions of computers that were originally infected by the malware, there are more than 300,000 remaining computers that are still infected. Once the court order expires, ISC will shutdown the temporary name servers, and those computers that are still infected will no longer be able to resolve domain names to IP addresses. In effect, those computers are disconnected from the Internet. To prevent this from happening, there is a final push to discover and fix the remaining computers infected by the DNSChanger malware.

The FBI created the DCWG Web site to detect, fix, and protect your computer against DNSChanger. You can just follow the instructions on the site, and learn more about the DNSChanger malware. The detection portion does not, in any way, change your computer. When you click the Detect icon, you get either a green page (not infected), or a red page (infected). Since the DNSChanger malware did not infect Linux, iPhone, iPad, or Android devices, users of these devices should always get a green page. The Fix icon provides a list of free software that you can use to remove the malware, should your computer be infected.

The Protect icon takes you to a page that provides references to protecting your computer. The link to Stop Badware is worth reading by everyone. The Internet can be a bad neighborhood, but by taking proper precautions everyone can enjoy safe surfing.

Print Friendly, PDF & Email

Comments