Court, Explained
U.S. Federal District Courts
←Back to docket
S.D.N.Y.Procedural orderFiled June 23, 2023

Google LLC v. Saeed

Judge
Valerie Caproni
Docket
1:23-cv-03369
Court
U.S. District Court · Southern District of New York
Pages
13
Civil ProcedureIntellectual PropertyTort
In one sentence

In Google LLC v. Saeed, Judge Caproni entered default judgment and a permanent injunction against alleged malware operators who did not defend.

Who this affects

Google, the defaulting defendants and people acting with them, Google users, and service providers connected to the identified domains and Internet infrastructure were affected. The injunction also addressed conduct affecting the public and Internet security.

What happened

In Google LLC v. Saeed, Google sued Zubair Saeed, Raheel Arshad, Mohammad Rasheed Siddiqui, and unidentified defendants over an alleged operation that distributed malware, infected computers, operated a botnet, and distributed altered software. Google brought claims under federal racketeering, computer-fraud, and trademark laws, along with a state-law claim for interfering with business relationships.

The court found that the defendants were properly served but did not appear or defend. It found that Google had proved its claims and that the defendants’ activities harmed Google, its users, and Internet security. The court also found that money alone could not adequately address the harm and that the public interest supported an injunction.

The court entered default judgment for Google and permanently barred the defendants and people acting with them from the listed malware, botnet, credential-theft, counterfeit-software, and trademark-related activities worldwide. It also authorized Google to serve the order on hosting and other service providers, ordered related steps to block or disable the identified infrastructure, and directed that Google’s $75,000 bond be returned. Judge Valerie E. Caproni ordered the case closed.

The detailed version

For law students, journalists, and other readers who want the full reasoning

Case
Google LLC v. Saeed · No. 1:23-cv-03369
Judge
Valerie Caproni
Date
June 23, 2023

Background

Google moved for default judgment and a permanent injunction against Zubair Saeed, Raheel Arshad, Mohammad Rasheed Siddiqui, and Does 1–15. Google alleged that the defendants participated in and operated a “Malware Distribution Enterprise” that distributed malware, infected devices, operated the CryptBot botnet, distributed cracked software, and carried out criminal schemes.

The complaint asserted claims under the Racketeer Influenced and Corrupt Organizations Act, the Computer Fraud and Abuse Act, Sections 32 and 43(a) of the Lanham Act, and New York common-law tortious interference with business relationships. The court found federal-question, trademark, and supplemental jurisdiction, and found personal jurisdiction and venue proper in the Southern District of New York. Among other reasons, the court cited alleged malware distribution to Google users in the district and commands sent to infected computers there.

Default and Findings

The defendants were served by methods approved by the court but did not timely appear, plead, or otherwise defend. The Clerk entered default under Rule 55(a) on May 18, 2023. The court found that the complaint pleaded sufficient facts and stated claims under the statutes and state law identified above.

The court found that Google had established actual success on each claim and had satisfied the requirements for permanent injunctive relief: irreparable injury, inadequate legal remedies, a balance of hardships favoring Google, and a public interest supporting the injunction.

The court found that the defendants’ activities threatened Internet and Google-platform security by transmitting malware, configuring and operating a botnet, distributing cracked software, compromising Google users’ devices, issuing commands to infected computers, and selling access to Google user accounts. The court stated that approximately 672,220 CryptBot victim devices in the United States had been infected during the preceding year. It also found trademark infringement involving, among others, Google Earth Pro and Google Chrome marks, creating a likelihood of confusion about the source or affiliation of the altered software and malware.

For the Computer Fraud and Abuse Act claim, the court found that the defendants knowingly and with intent to defraud accessed users’ computers without authorization, infected them with malware, and sought information such as account credentials for sale to others. For the Lanham Act claims, it found unauthorized use of Google marks in distributing altered software containing malware. For the racketeering claim, it found an enterprise, a common purpose, coordinated roles, a pattern of racketeering activity, and injury to Google’s business or property. It also found liability for tortious interference under New York law.

Judgment and Injunction

The court ordered that the defendants were in default and that judgment was awarded in favor of Google and against the defendants. The court permanently restrained the defendants and covered persons acting with them, anywhere in the world, from activities including unauthorized access to Google customers’ computers; sending malicious code; designing malware targeting Google products or users; operating or facilitating the CryptBot botnet; compromising computers and networks; stealing information, credentials, or cookies; selling access to Google user accounts; distributing pirated or cracked software; and using Google marks or misleading representations suggesting affiliation with Google.

The court separately prohibited use and infringement of the Google marks, false or deceptive designations connected with the defendants’ activities, and conduct suggesting that those activities, products, or services came from or were sponsored by Google.

Google was authorized to serve the order on persons and entities providing services to domains identified in the complaint. The order permitted Google to request reasonable efforts to identify and block related Internet traffic, disable or suspend services associated with the domains, prevent circumvention, preserve and produce identifying records, assist with implementation, and preserve related hardware, data, software, and evidence. Google could also serve the order on persons it determined were necessary to address activity connected with domains or Internet addresses identified as part of the enterprise or botnet without seeking further court permission.

Finally, the court ordered the Clerk to return Google’s $75,000 bond and directed that the open motions be terminated and the case closed.

Classification Note

This is classified as a procedural order because the court entered default judgment after the defendants failed to appear or defend. The court also made findings that Google had succeeded on the merits, but the order’s operative disposition was default judgment and ancillary injunctive relief.

The authoritative version

Read the full 13-page opinion on CourtListener, the free public archive maintained by the Free Law Project.

Open opinion PDF →
Summary written with AI assistance. See how summaries are made. Spot something wrong? Tell us.