Chinese Police Arrest Makers of Fireball Adware

LASER_oneXM

Level 37
Thread author
Verified
Top Poster
Well-known
Feb 4, 2016
2,520
Beijing police have arrested the makers of the Fireball adware family, presumed to have infected millions of devices around the globe.

Chinese news outlets reported this week of the arrest of 14 employees of Rafotech, a Chinese digital marketing company, which Check Point named in its report as the authors of the Fireball adware.

Check Point published its Fireball report on June 2. Chinese media says local police received an anonymous complaint against the company the next day, and after a short investigation, Beijing's Public Security Bureau Network Security Corps moved in for the arrests on June 15.

Nine tried to destroy data during the arrest
Of the 14 arrested suspects, three are Rafotech's management, the company's CEO, CTO, and CFO. Nine persons are also accused of attempting to destroy data from their computers. All suspects admitted their crimes.

According to police, the company was headquartered in Beijing's Haidian district and was founded in 2015 by three high school students who went on to develop various adware families (Youndoo, Trotux, Startpageing123, Luckysearch123, Hohosearch, Yessearches) collectively referred to as Fireball.

Police say they estimate Rafotech made over 80 million yuan ($11.8 million) from distributing their adware.


Fireball adware infected 5 million computers (not 250 million)
Fireball malware was distributed via bundled software, and its primary goal was to hijack browser's search engine and redirect users to fake search engines where the Fireball crew made money from each search query. Some of these fake search engines received so much traffic that a few managed to break into the Alexa Top 1,000.
 
  • Like
Reactions: RoboMan and Parsh

RoboMan

Level 35
Verified
Top Poster
Content Creator
Well-known
Jun 24, 2016
2,400
I love reading threads about malware creators earning millions a year when i'm trying to get enough to buy a McDonald's meal.
 
  • Like
Reactions: DJ Panda

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top