Original Article Text

Click to Toggle View

Developer guilty of using kill switch to sabotage employer's systems. A software developer has been found guilty of sabotaging his ex-employer's systems by running custom malware and installing a "kill switch" after being demoted at the company. Davis Lu, 55, of Houston, was a software developer for an Ohio company, reportedly Eaton Corp, from November 2007 to October 2019. Eaton Corporation is a global power management company that provides electrical, hydraulic, and mechanical solutions for various industries. Following a corporate restructuring in 2018, Lu lost responsibilities at his job and was found guilty of sabotaging his employer's computer systems and network with custom malware and kill switches. The malicious activities included code that ran in an "infinite loop," exhausting a production server's resources and eventually causing the system to crash and prevent user logins. These infinite loops were designed to exhaust Java threads by repeatedly generating new threads without proper termination. According to Lu's indictment, Lu also deleted coworker's user profiles and implemented a "kill switch" that would lock out all users if his account in the company's Windows active directory was disabled. The "kill switch" code, named "IsDLEnabledinAD," was an abbreviation of "Is Davis Lu enabled in Active Directory." This kill switch was automatically triggered when Lu was terminated on September 9, 2019, causing thousands of employees to lose access to systems. On the day he was directed to return his company laptop, Lu reportedly deleted encrypted data. The DOJ says internet search queries also revealed that Lu had been researching ways to elevate privileges, hide processes, and quickly delete files. The Department of Justice says that Lu's activities and system disruption cost the company hundreds of thousands of dollars. A jury convicted Lu of causing intentional damage to protected computers, a charge that carries a maximum penalty of 10 years in prison. A sentencing date has not been set.  

Daily Brief Summary

CYBERCRIME // Developer Sabotages Ex-Employer's Systems with Malware and Kill-Switch

Davis Lu, a former software developer, was convicted for intentionally damaging his ex-employer Eaton Corp’s computer systems using malware and a "kill switch."

After a demotion post-2018 corporate restructuring, Lu enacted revenge through disruptive software that crashed production servers and blocked user access.

His sabotage included infinite loops in code draining server resources and deleting coworker profiles to cripple operations.

The kill switch, named "IsDLEnabledinAD," was activated upon his termination, locking thousands of employees out of company systems.

Further malicious activities included the deletion of encrypted data from his company laptop upon returning it, following his termination.

Lu's actions, driven by searches on escalating privileges and hiding processes, led to significant financial losses for Eaton Corp, estimated in the hundreds of thousands of dollars.

He faces up to 10 years in prison for a charge of causing intentional damage to protected computers; a sentencing date remains undecided.