Last Friday, on August 4, a jury in the US found Fabio Gasperini, an Italian citizen, guilty of one misdemeanor for computer intrusion and was required to forfeit a botnet that was allegedly used to hijack remote servers and perform click fraud. 

Bleeping Computer reported on Gasperini's arrest and extradition to the US earlier this year, at the end of April. Today, we're circling back to provide an account of the events of how Gasperini built his botnet and how an investigation by Forkbombus Labs led to a criminal complaint filed with the FBI, the botnet's downfall and subsequent arrests.

Crook used Shellshock flaw to take over QNAP NAS devices

This whole story starts in September 2014, after the public disclosure of Shellshock (CVE-2014-6271), a vulnerability in the Unix Bash shell that allowed remote attackers to take over Internet-connected devices running a Bash shell.

Gasperini is one of the many cyber-criminals who jumped on the Shellshock exploitation train after the bug's public disclosure. Unlike others, Gasperini focused his efforts on exploiting Shellshock for a single line of products, which were network attached storage (NAS) devices manufactured by QNAP Systems, Inc., a Taipei-based hardware manufacturer.

QNAP NAS devices
QNAP NAS devices

Gasperini used automated scans to discover QNAP NAS devices available online via port 80 and deployed the Shellshock vulnerability to run code on the vulnerable device.

An analysis of the malicious code by researchers at Forkbumbus Labs revealed the following capabilities:

● Adding a backdoor administrator user account.
● Creation of a publicly accessible unauthenticated webshell.
● Configuring an SSH daemon on port 26.
● Patching the infected QNAP NAS device for the Shellshock vulnerability, preventing further exploitation.
● Downloading and execution of a Lightaidra IRC Bot.
● Further (worm like) botnet propagation.
● Visiting advertisements in a fraudulent manner meant to emulate legitimate human activity.

A month after the disclosure of the Shellshock vulnerability, QNAP issued a security patch to protect customer devices against exploitation. Nonetheless, this didn't stop Gasperini's botnet from spreading.

According to a report provided to Bleeping Computer by Stu Gorton, co-founder and CTO of Forkbumbus Labs, Gasperini's botnet spread to over 2,500 QNAP NAS devices across 70 countries.

List of top affected countries

While building his botnet, Gasperini made several rookie mistakes that allowed the Forkbombus Labs team to track down his real-world identity.

Gasperini made several OpSec mistakes

For starters, some of the domains he used in the click-fraud scheme were registered to "gaspolo@gmail.com", his personal Gmail address. In addition, the malware dev also used his "Gaspolo" nickname in the botnet infrastructure.

Gasperini's real name was never revealed via the domain registration data, but when researchers attempted to reset the attacker's Gmail account password, Google revealed Gasperini's name.

Gasperini Gmail account reset

From here, it didn't take long for Forkbumbus researchers to track down Gasperini's other online identities on sites such as Blogspot or Facebook. These profiles revealed a man with an interest for server administration and other advanced technical topics.

Gasperini Facebook post

Forkbombus Labs gathered all the information it found on Gasperini and filed a criminal complaint with US authorities.

"Our researchers quickly identified long standing related activity and the motivation behind these attacks," Gorton said regarding Gasperini's guilty verdict. "This allowed our users to quickly identify the appropriate response for this activity and their needs. Through our combined efforts with the FBI, we were able to engage in root cause remediation of this activity, preventing millions of attacks from affecting our clients and the internet as a whole."

Operation HackinItaly

Following a joint investigation by the FBI, Dutch and Italian police, the Dutch arrested Gasperini in Amsterdam on June 18, 2016, where he moved from Rome, his hometown.

Police raided Gasperini's home and other raids took place in Rome, Reggio Calabria, and Venice, where Gasperini's brother and four accomplices lived. The codename of this operation was HackinItaly.

Authorities also charged the other five with hacking and money laundering, but US officials requested only Gasperini's extradition, which was approved earlier this year in April. Gasperini was indicted and arraigned in a US court on April 21, and a jury trial followed.

Gasperini appears to have learned the technical skills to operate his botnet after he worked together with his brother as the technical staff of an online betting site.

Besides running the botnet to allegedly perform click-fraud, authorities state that Gasperini later started renting traffic from the botnet to other sites. He invoiced these companies in his own name, but never more than €5,000 per invoice, the minimum value for which freelancers don't have to apply VAT (value added tax) in Italy.

Because occasional freelancers can't work for more than 30 days per calendar year, he used the personal tax codes of his brother and the other four accomplices to launder the money obtained from these contracts.

Gasperini sentenced to one year in prison

Authorities estimated the damages caused by Gasperini's botnet to €300,000 ($350,000).

After the verdict from last week, yesterday, on August 9, a US judge sentenced Gasperini to one year in prison, a $100,000 fine, and one year of supervised release following incarceration. Gasperini's prison setence is offset by his 13-month pretrial detention.

Updated: This article was updated in regards to information about the HackinItaly raids, verdicts, and sentencing.

Related Articles:

Passwords for Tens of Thousands of Dahua Devices Cached in IoT Search Engine

HNS Evolves From IoT to Cross-Platform Botnet

All That Port 8000 Traffic This Week! Yeah, That's Satori Looking for New Bots

Trik Spam Botnet Leaks 43 Million Email Addresses

Around 5% of All Monero Currently in Circulation Has Been Mined Using Malware