“INTRODUCTION ……. 1. A ‘protected computer’ includes a computer which is used in or affecting interstate or foreign commerce or communication…. A personal computer connected to the Internet is a ‘protected computer’. ….. 3. Defendant….used malicious software to take command and control of a network of compromised protected computers (a ‘botnet’) without the authorisation of the owners of those computers, and offered for sale the use of said botnet to others for unauthorized purposes. COUNT ONE (Damaging a computer or information) ….. 5. On or before June 28, 2010, and continuing until at least July 5, 2010, within the District of Columbia and elsewhere, defendant….did knowingly cause and attempt to cause the transmission of a program, information, code, or command, that is, a malicious computer software program, and an additional program, information, code, or command, that is, a secondary program, and, as a result of such conduct, intentionally caused and attempted to cause damage without authorization to ten or more protected computers during any one-year period. All in violation of Title 18, United States Code, Sections 1030(a)(5)(A), (b), and (c)(4)(A)(i)(VI) and Section 2.”
“ The government’s evidence will establish that AHZAZ transmitted and installed what he believed to be malicious code provided to him by an undercover FBI agent onto more than 100,000 compromised computers that AHZAZ surreptitiously controlled. …. ”
“ The key factor as far as this court is concerned is that these computers were under the control of the defendant as a result of them being infected with a program and that when the ‘installs’ occurred this must have been an unauthorised act …intended to impair the operation of a program or reliability of data, Section 3(2)(c) must apply. I accept this submission. The 1990 Act does not need any particular program or data to be identified to satisfy the need of the defendant’s intention. Furthermore, the use of the defendant’s own computer in the installation of the code supplied to him by the FBI onto computers that he controlled and which he intended to access would in my opinion constitute causing a computer to perform a function with intent to secure access to a program held in those other computers. To that extent this request is Section 17(2)(c) compliant.”
“ …the appellant …secured access to the data in the computers controlled in his botnet by altering the data on those computers. He used his computer to perform a function, the transmission of the malicious code, thus altering the data held on the computers in the botnet on which the code was installed…. Notably the intent to commit an offence under section 1(2) …[of the 1990 Act]…does not need to be directed at any particular program or data, a program or data of any particular kind or a program or data held in any particular computer. Thus causing a computer to transmit code intending to alter the data of another computer in an unauthorised manner and knowing it to be so, makes out the offence under section 1….”
“ This does not mean that the requesting state must prove the guilt of the person in English law. That would be absurd and would be a higher test than the prima facie case which had to be established under earlier legislation. The words ‘would constitute an offence’ simply mean ‘would, if proved, constitute’ the English offence….”