Police arrest hackers behind explosive Fireball malware that infected 250 million computers

The malware has been circulating for a couple of years, and its reach has been incredibly pervasive.
 By 
Yi Shu Ng
 on 
Police arrest hackers behind explosive Fireball malware that infected 250 million computers
Credit: AFP/Getty Images

At least nine of the ring of hackers that developed the "Fireball" malware have been arrested by Chinese authorities, according to state-run news outlets.

Fireball's reach was one of the world's most extensive. News of it emerged a month ago, and it's been estimated to have infected 250 million computers worldwide -- or about 20 percent of corporate networks.

The hackers behind it worked at a Beijing digital marketing company named Rafotech, had earned more than 80 million yuan ($11.84 million) generating fake clicks and traffic to other websites, according to Chinese paper Beijing Youth Daily.

Fireball piggybacked on Rafotech's legitimate software, and hijacked browsers to force people to download other software.

It is likely to have been spread through spam, and via other programs installed -- typically cracked, pirated apps, says Ars Technica.

Original image replaced with Mashable logo
Original image has been replaced. Credit: Mashable

Israeli-based antivirus firm Check Point tracked the infection through looking at data rankings from Alexa, and was responsible for coming up with the 250 million infected figure.

These numbers have been disputed by Microsoft, which said that it had been tracking Fireball since 2015, and has cleaned about 40 million Fireball infections.

Still, Fireball's reach has clearly been impactful.

If Check Point's larger estimates are correct, the number of infected computers would dwarf the WannaCry ransomware attack, which was estimated to have infected 200,000 computers, and the Mirai botnet, which at one point infected half a million computers.

How they were busted

Rafotech's operations were exposed by a local security researcher, which sent data to local police, according to state-run Xinhua.

The security researcher said that he was able to analyse Fireball's transmission methods after reading overseas research on the malware, and provided evidence that Rafotech's freeware contained the same malicious code as found in Fireball. He then used digital signatures to determine the company's registration information, and the people responsible in the company.

Nine of Rafotech's employees were arrested on charges of sabotaging computer systems, while two more were detained, Xinhua reported.

Police in Haidian district said that the nine ran Rafotech's core operations, and while young, had years of experience in the IT industry, and knew anti-detection techniques.

The company had around 100 employees, Xinhua added, some of whom were involved in developing its freeware. "They did consult lawyers before doing what they did," according to Haidian police. "They tried to understand what was illegal so they would escape prosecution."

Mashable Image
Yi Shu Ng

I am an intern with Mashable Asia, focusing on viral news, lifestyle news and feature news in the region.

Mashable Potato

Recommended For You
Do you have one of these 17 browser extensions? They could be tracking your browsing history.
safari and chrome apps on phone

FBI investigates Steam games with hidden malware
Steam logo on laptop

Iran-linked hackers launch cyberattack against U.S. medtech company Stryker
Stryker logo on medical equipment

Everything you need to know about the malware stealing data from Mac users
MacBook in the dark using Terminal

Popular Chrome extension disabled for containing malware
Google Chrome logo

More in Tech
The Earth is glowing in new Artemis II pictures of home
One half of the Earth is seen floating in space through the open door of the Orion spacecraft.

Doomsday Clock now closest to midnight ever
A photograph of the Doomsday Clock, stating "It is 85 seconds to midnight."

Hurricane Erin: See spaghetti models and track the storm’s path online
A map showing the predicted path of Tropical Storm Erin.

Tropical Storm Erin: Spaghetti models track the storm’s path
A prediction cone for Tropical Storm Erin.

NASA to build a nuclear reactor on the moon by 2030, report states
The lunar surface.

Trending on Mashable
NYT Connections hints today: Clues, answers for April 3, 2026
Connections game on a smartphone

Wordle today: Answer, hints for April 3, 2026
Wordle game on a smartphone

What's new to streaming this week? (April 3, 2026)
A composite of images from film and TV streaming this week.

Google launches Gemma 4, a new open-source model: How to try it
Google Gemma

The biggest stories of the day delivered to your inbox.
These newsletters may contain advertising, deals, or affiliate links. By clicking Subscribe, you confirm you are 16+ and agree to our Terms of Use and Privacy Policy.
Thanks for signing up. See you at your inbox!