LuminosityLink malware author pleads guilty
Full article608 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
Colton Grubbs admitted to prosecutors that he knew customers used the software to illegally hack into victims' machines.
The author of the LumunosityLink malware pleaded guilty in federal court on Monday. Colton Grubbs, a 21-year-old man from Kentucky, faced up to 25 years in prison had the case gone to trial.
LumunosityLink first earned a spotlight in 2015 when Proofpoint researchers looked past the benign advertisements for the product and found a “very aggressive key logger that injects its code in almost every running process on the computer.”
The malware was sold for $40 as a Remote Access Tool (RAT) that, according to the product’s advertising, “allows system administrators to manage a large amount of computers concurrently.” In reality, it was malware that allowed over 6,000 customersto take over thousands of computers in 78 countries.
Here was LuminosityLink’s website boasting about “powerful surveillance” capabilities:

LuminosityLink was sold on HackForums, an infamous information security community that routinely features heavily in cybercrime indictments. The Mirai botnet found its way to the website in 2016 and the Blackshades RAT was infamous malware sold widely on the site before its creators were arrested.
There is a significant link between Blackshades and LuminosityLink. Both were marketed on HackForums as benign software, both were actually potent hacking tools that bestowed serious firepower on otherwise amateur actors, which led to the creators being placed in handcuffs.
Despite some of the language used to market LuminosityLink, other aspects made the tool’s intent obvious. It was marketed in the “hacking tools and programs” subforum on HackForums. The marketing emphasized the fact that the malware could be silently installed without notification and that it included key loggers and a vast suite of surveillance tools, as well as profitable cryptomining capabilities and the ability to use victims’ machines in a botnet.
Grubbs admitted to prosecutors that he knew customers used the software to illegally hack into victims’ machines.
In July, 2017, Grubbs learned of an imminent FBI raid on his apartment. He tried to hide incriminating evidence including his laptop, hard drives and a debit card used with for cryptocurrency. He also transferred 114 bitcoin from his main wallet to an array of six other wallets, a transaction worth about $273,000 at the time.
Word of Grubbs’ trouble began to spread in 2017. Europol announced action against LuminosityLink in February 2018.
You can read the plea agreement below:
[documentcloud url=”http://www.documentcloud.org/documents/4600379-2018-07-16-Plea-Agreement.html” responsive=true height=500]
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Technology
Threats
Chinese espionage groups swarm to exploit triple-link chain of zero-days
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/luminositylink-malware-author-pleads-guilty/