Share this article

Facebook Breaks Up Cryptocurrency Mining Botnet 'Lecpetex'

Facebook has successfully dismantled a major bitcoin botnet operated by a small team of cyber criminals based in Greece.

Updated Sep 11, 2021, 10:57 a.m. Published Jul 9, 2014, 6:30 p.m.
facebookbtc

Facebook has successfully dismantled a major bitcoin botnet operated by a small team of cyber criminals based in Greece.

The Lecpetex botnet managed to infect 250,000 computers. At its peak it compromised as many as 50,000 Facebook accounts.

STORY CONTINUES BELOW
Don't miss another story.Subscribe to the Crypto Daybook Americas Newsletter today. See all newsletters

Lecpetex propagated through the social media platform using spam messages with malicious code inserted into zipped attachments.

Each zip archive contained an embedded Java file that would download and install a litecoin miner. It would also steal cookies and gain access to the victim's friend list, using it to send out even more spam.

However, mining was not its only function. The botnet was also used to distribute more dangerous malware designed to steal banking details, passwords and bitcoins.

My big fat Greek botnet

Facebook detected the Lecpetex botnet months ago and it is believed that it first started spreading in December.

The social media giant says it tracked more than 20 distinct waves of spam sent out by the botnet between December 2013 and June 2014.

On 30th April, Facebook asked the Cybercrime Subdivision of the Greek Police for assistance. Greek investigators managed to catch up with the botnet's authors on 3rd July and they were detained on the same day.

Greek police told Facebook that the perpetrators were in the process of establishing a ‘bitcoin mixing’ service that would enable them to launder the stolen bitcoins.

As Greek police started closing in on the operators, they left notes for them to find on compromised command and control servers.

One such message read:

“Hello people.. :) <!-- Designed by the SkyNet Team --> but am not the f***ing zeus bot/skynet bot or whatever piece of sh*t.. no fraud here.. only a bit of mining. Stop breaking my ballz [sic].”

Facebook published its findings on the botnet in an extensive blog post.

No word on damage caused

Although Facebook says it learned a few lessons while it dismantled the botnet, there is still no official information on the damage Lecpetex caused.

“Our analysis revealed two distinct malware payloads delivered to infected machines: the DarkComet RAT, and several variations of litecoin mining software. Ultimately the botnet operators focused on litecoin mining to monetize their pool of infected systems,” the company said.

Although the number of affected PCs is relatively low compared to many other botnets, it's likely that Lecpetex generated some litecoins, though the number is unknown. The ‘bitcoin mixing’ effort cited by Facebook also indicates that bitcoins were likely to have been stolen by the botnet.

According to Greek media reports, the operators of the botnet claimed they were using the data for "research purposes", not monetary gain. The pair were released from custody earlier this week.

More For You

Protocol Research: GoPlus Security

GP Basic Image

What to know:

  • As of October 2025, GoPlus has generated $4.7M in total revenue across its product lines. The GoPlus App is the primary revenue driver, contributing $2.5M (approx. 53%), followed by the SafeToken Protocol at $1.7M.
  • GoPlus Intelligence's Token Security API averaged 717 million monthly calls year-to-date in 2025 , with a peak of nearly 1 billion calls in February 2025. Total blockchain-level requests, including transaction simulations, averaged an additional 350 million per month.
  • Since its January 2025 launch , the $GPS token has registered over $5B in total spot volume and $10B in derivatives volume in 2025. Monthly spot volume peaked in March 2025 at over $1.1B , while derivatives volume peaked the same month at over $4B.

More For You

Coinbase Sees Crypto Recovery Ahead as Liquidity Improves and Fed Rate Cut Odds Climb

Coinbase

The crypto exchange also took note of a so-called AI bubble that continues to go strong and a weaker U.S. dollar.

What to know:

  • Coinbase Institutional is seeing a potential December recovery in crypto, citing improving liquidity and a shift in macroeconomic conditions that could favor risk assets like bitcoin.
  • The firm's optimism is driven by rising odds of Federal Reserve rate cuts, with markets pricing in a 93% chance easing next week, and improving liquidity conditions.
  • Several recent institutional developments, including Vanguard's crypto ETF policy reversal and Bank of America's greenlighting of crypto allocations, have contributed to bitcoin's rebound from recent lows.