Statements on the arrest by the Cybercrime Directorate of two Greek citizens - creators of the malicious software codenamed "Lecpetex" which infected hundreds of thousands of computers worldwide
Spokesperson's Statements
Good morning,
The Cybercrime Prosecution Directorate, within the framework of a months-long systematic and thorough investigation, managed to uncover the illegal online activity of two (2) Greek citizens, who created and used for illegal purposes (Cracking), the worldwide widespread malicious software with the code name "Lecpetex".
These are two Greek citizens, aged 31 and 27, who were arrested by a warrant yesterday (2-7-2014) morning in areas of Attica. A case has been filed against them for forming and participating in a criminal organization-gang, computer fraud, violation of computer privacy, as well as violation of the legislation for the protection of personal data.
In particular, the investigation of the case began after appropriate utilization of online postings and information regarding the activity of Greek hackers on the internet, who in recent months, using malicious software, had breached a large number of computer systems, mainly through social media.
The prosecution authorities were informed of the above, which issued relevant Orders and Resolutions for the lifting of the confidentiality of communications. This was followed by a multi-month, methodical - systematic digital online investigation by specially trained police officers of the Cybercrime Prosecution Directorate, in the context of which the criminal activity of the two arrested was identified and verified.
In particular, the digital investigation of the case revealed that the two people involved were the creators of the malicious software with the international code name "Lecpetex", which they spread mainly through social media, infecting a large number of computer systems worldwide.
It is worth noting that the management company of the social networking website, in order to address the significant malfunctions caused by this particular virus in its computer systems, changed its privacy policy several times, introducing special security mechanisms for all of its users, thus affecting the overall smooth operation of its network.
The arrested individuals have often managed to overcome these mechanisms, using advanced techniques and software, thus succeeding in attacking the development mechanisms and systems, not only of this particular social networking page, but also of other online companies around the world, thus making the virus one of the most serious threats worldwide in terms of malware.
The details regarding the methodology of action and the individual elements and data of the case will be presented to you by the Head of the Cybercrime Prosecution Directorate, Brigadier General Mr. Emmanouil Sfakianakis.
Statements by Brigadier General Emmanuel Sfakianakis
This is the most significant case that the Cybercrime Prosecution has ever handled, with serious implications for the global online computing system. We managed to prevent a significant threat to computer security, which caused major problems for millions of internet users around the world.
Regarding their methodology, it consisted of sending personal messages to social media users, to which they attached the malware as an attachment. In this way, they aimed to trick users into opening the file, which then infected their computer.
It is noted that the perpetrators used – exploited the social networking site's online platform, as their malware, through its ability to self-propagate, managed to infect all the contacts – friends of the initially infected user by automatically sending them similar malicious messages. In this way, the number of infected computers expanded geometrically, on a global scale.
Alternatively, the perpetrators distributed the malware using Peer 2 Peer file sharing programs, through which they made available free “cracked” versions of popular games, songs, and movies, but with the malware attached to them. This resulted in users who “free downloaded” these files infecting their computers.
As shown by international research, the above illegal activity, which is now observed among the majority of internet users and through which users download games, software, songs, movies for free from various websites, causes annual damage to their computer systems (PC, Laptop, etc.) which exceeds 1.5 billion euros and this is due to various malfunctions (damage) caused to their computer systems by malicious software.
It is noted that there is a large number of internet users who are tempted by the opportunities offered by "free downloading" and are unaware of the potential risks and damage they may cause to their computer systems.
As the investigation progressed, the perpetrators were using the virus for specific selfish purposes, mainly concerning:
- In using the computing power of infected machines (hundreds of thousands) to produce virtual online money (bitcoin mining). Specifically, the malicious software, after its installation, used the infected computers to produce digital-virtual currencies (bitcoin) and
- In the interception of electronic wallets. The perpetrators, using the virus, stole the passwords of electronic wallets containing digital-virtual currencies (bitcoins) and transferred them to other electronic wallets, which were under their control.
The online virtual currencies (bitcoins) collected by the perpetrators: a) were forwarded to specialized mixing services, via a special network (TOR) to which internet users can only access through the use of specialized software. In this way, they concealed the traces of the origin of the illegal profits that had come from the production of bitcoins and from the electronic wallets that they had intercepted and b) they converted them into euros using the services of special electronic exchange offices available on the internet, ultimately collecting the illegal profits.
- In the interception of passwords of all kinds. Specifically, by using the virus, they intercepted passwords from emails and accounts of all kinds (e-banking, Paypal, etc.) and registered them in a database. A typical example is the interception by the perpetrators of the security code (password) of the email address of the Ministry of Merchant Shipping, in which the perpetrators gained access to its content.
It is noted that from the progress of the investigation, the perpetrators had recently been planning to implement their own money laundering service, by mixing digital-virtual currencies (bitcoin mixing service), which they intended to make available through the TOR network.
In coordinated searches carried out at the homes of the two citizens, in the presence of a Public Prosecutor, and in particular from the inspection carried out on their computers, the following was found:
- the source code of the malware, which they used to infect the victims' computer systems,
- the account they maintained with the bitcoin mixing service “bitcoin fog” (at the TOR address), with the aim of hiding the traces of the origin of the bitcoins,
- the account they maintained on the electronic exchange “Kraken” (at the address “www.kraken.com”) for converting bitcoins into regular currency (e.g. euros), as well as the history of withdrawals from the said service,
- a folder in which twenty-six thousand six hundred and ten (26,610) files with various stolen internet user passwords from various services they used were stored,
- folder in which 114 files with hacked electronic wallets were stored,
- sample of the source code they were developing to build their own bitcoin mixing service.
The seized digital evidence will be sent to the Criminal Investigations Directorate for further laboratory examination, which is expected to accurately identify the computer systems they had under their control, as well as the financial benefits they had obtained.
The two arrested with a case filed against them are being taken to the Athens First Instance Prosecutor's Office.
[gview file=”lecpetex.pdf” save=”0″]
You can watch the video from the press conference here: zougla.gr/webtv
SecNews editorial team note: SecNews, analyzing the complexity of the case and the information made public by the I.D.I.E., estimates that the creators of the software are exceptional experts with a very high level of training. Furthermore, it has not been clarified so far whether there was a financial benefit, which will arise from the final analysis of the digital evidence.
In any case, perhaps the leading state officials of the state and the competent services should pay special attention and interest to this specific case, since it is an unprecedented case for Greek data! In practice, the creators of the software should perhaps be utilized by the Greek state for the security of critical infrastructures and the increase ofthe country's defense capabilities against cyberattacks.
As we have mentioned in similar cases in the past, such people (in the event that, of course, no criminal or financial offenses are proven)
constitute national capital for the country, as is the case in countries such as China, the USA, Russia and elsewhere.





