Google LLC v. Saeed
- Valerie Caproni
- 1:23-cv-03369
- U.S. District Court · Southern District of New York
- 13
In Google LLC v. Saeed, Judge Caproni entered default judgment and a permanent injunction against alleged malware operators who did not defend.
Google, the defaulting defendants and people acting with them, Google users, and service providers connected to the identified domains and Internet infrastructure were affected. The injunction also addressed conduct affecting the public and Internet security.
What happened
In Google LLC v. Saeed, Google sued Zubair Saeed, Raheel Arshad, Mohammad Rasheed Siddiqui, and unidentified defendants over an alleged operation that distributed malware, infected computers, operated a botnet, and distributed altered software. Google brought claims under federal racketeering, computer-fraud, and trademark laws, along with a state-law claim for interfering with business relationships.
The court found that the defendants were properly served but did not appear or defend. It found that Google had proved its claims and that the defendants’ activities harmed Google, its users, and Internet security. The court also found that money alone could not adequately address the harm and that the public interest supported an injunction.
The court entered default judgment for Google and permanently barred the defendants and people acting with them from the listed malware, botnet, credential-theft, counterfeit-software, and trademark-related activities worldwide. It also authorized Google to serve the order on hosting and other service providers, ordered related steps to block or disable the identified infrastructure, and directed that Google’s $75,000 bond be returned. Judge Valerie E. Caproni ordered the case closed.
The detailed version
- Google LLC v. Saeed · No. 1:23-cv-03369
- Valerie Caproni
- June 23, 2023
Background
Google moved for default judgment and a permanent injunction against Zubair Saeed, Raheel Arshad, Mohammad Rasheed Siddiqui, and Does 1–15. Google alleged that the defendants participated in and operated a “Malware Distribution Enterprise” that distributed malware, infected devices, operated the CryptBot botnet, distributed cracked software, and carried out criminal schemes.
The complaint asserted claims under the Racketeer Influenced and Corrupt Organizations Act, the Computer Fraud and Abuse Act, Sections 32 and 43(a) of the Lanham Act, and New York common-law tortious interference with business relationships. The court found federal-question, trademark, and supplemental jurisdiction, and found personal jurisdiction and venue proper in the Southern District of New York. Among other reasons, the court cited alleged malware distribution to Google users in the district and commands sent to infected computers there.
Default and Findings
The defendants were served by methods approved by the court but did not timely appear, plead, or otherwise defend. The Clerk entered default under Rule 55(a) on May 18, 2023. The court found that the complaint pleaded sufficient facts and stated claims under the statutes and state law identified above.
The court found that Google had established actual success on each claim and had satisfied the requirements for permanent injunctive relief: irreparable injury, inadequate legal remedies, a balance of hardships favoring Google, and a public interest supporting the injunction.
The court found that the defendants’ activities threatened Internet and Google-platform security by transmitting malware, configuring and operating a botnet, distributing cracked software, compromising Google users’ devices, issuing commands to infected computers, and selling access to Google user accounts. The court stated that approximately 672,220 CryptBot victim devices in the United States had been infected during the preceding year. It also found trademark infringement involving, among others, Google Earth Pro and Google Chrome marks, creating a likelihood of confusion about the source or affiliation of the altered software and malware.
For the Computer Fraud and Abuse Act claim, the court found that the defendants knowingly and with intent to defraud accessed users’ computers without authorization, infected them with malware, and sought information such as account credentials for sale to others. For the Lanham Act claims, it found unauthorized use of Google marks in distributing altered software containing malware. For the racketeering claim, it found an enterprise, a common purpose, coordinated roles, a pattern of racketeering activity, and injury to Google’s business or property. It also found liability for tortious interference under New York law.
Judgment and Injunction
The court ordered that the defendants were in default and that judgment was awarded in favor of Google and against the defendants. The court permanently restrained the defendants and covered persons acting with them, anywhere in the world, from activities including unauthorized access to Google customers’ computers; sending malicious code; designing malware targeting Google products or users; operating or facilitating the CryptBot botnet; compromising computers and networks; stealing information, credentials, or cookies; selling access to Google user accounts; distributing pirated or cracked software; and using Google marks or misleading representations suggesting affiliation with Google.
The court separately prohibited use and infringement of the Google marks, false or deceptive designations connected with the defendants’ activities, and conduct suggesting that those activities, products, or services came from or were sponsored by Google.
Google was authorized to serve the order on persons and entities providing services to domains identified in the complaint. The order permitted Google to request reasonable efforts to identify and block related Internet traffic, disable or suspend services associated with the domains, prevent circumvention, preserve and produce identifying records, assist with implementation, and preserve related hardware, data, software, and evidence. Google could also serve the order on persons it determined were necessary to address activity connected with domains or Internet addresses identified as part of the enterprise or botnet without seeking further court permission.
Finally, the court ordered the Clerk to return Google’s $75,000 bond and directed that the open motions be terminated and the case closed.
Classification Note
This is classified as a procedural order because the court entered default judgment after the defendants failed to appear or defend. The court also made findings that Google had succeeded on the merits, but the order’s operative disposition was default judgment and ancillary injunctive relief.
Read the full 13-page opinion on CourtListener, the free public archive maintained by the Free Law Project.