Author Topic: Criminal Botnets operating like wolf packs.....  (Read 3932 times)

0 Members and 1 Guest are viewing this topic.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33913
  • malware fighter
Criminal Botnets operating like wolf packs.....
« on: April 09, 2009, 08:27:38 PM »
Through cooperatimg cybercriminals are able to infect computers with truckloads of malware.
Such a malicious wolfpack is called a BotnetWeb, re: http://blog.fireeye.com/research/2009/04/botnetweb.html
"a collection of heterogeneous Botnets, that is used in a combination for the single purpose of infecting with malware, and is being herded by one or more closely related criminal groups",
this according to the way Atif Atif Mushtaq, researcher for FireEye Malware Intelligence Lab defines it.
This researcher found that various malware infections may be closely related,
that these actions are run by the same group or another group pays them to infect.

The 'Virut' BotnetWeb can be an example of what a tremendous threat comes from these kinds of wolf packs. Re: http://www.msfn.org/board/index.php?showtopic=128757
Those infected by virut will have dozens of other malware installed within minutes of infection,
like bots, Trojans, key loggers and a load of fake-virus scanners.
Removing one infection does not help much against those that stay behind.

A collective.
Cooperation does not only give an increase of infection capability onto a system,
because of the various layers it is enrolled, it is very difficult to take out those malcreants,
that partake in these actions,

"Unless we block the top level nodes (the generic downloaders)
they just will  keep on launching new and updated malware", according to Mushtaq.
He is almost certain a similar situation arose when spamhoster McColo was taken down.
Over 45% of all malware that is currently around, is part of a malicious BotnetWeb.

"We all know how big this malware problem has become.
If you look at malware separately, it is a threat that can be damaging to computers in various ways.
But as a collective they form very threatening wolf packs.
We should never forget that these Bot armies were used to launch cyberattacks on countries as well."

pol
« Last Edit: April 09, 2009, 08:57:35 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Confused Computer User

  • Avast Evangelist
  • Advanced Poster
  • ***
  • Posts: 700
  • The answer is 42
Re: Criminal Botnets operating like wolf packs.....
« Reply #1 on: April 09, 2009, 10:36:07 PM »
Hi polonus,

Thank you for the article. I hope you don't mind but my knowledge of computers is not so good. Can you answer a few questions.

1. What is a Botnet? As I think of it I imagine that Virus X infects computer A and then Spreads to B,C and D and then spreads among these computers' connections creating effectively a net of infected computers.
2. When you say BotnetWeb you mean that a series of viruses X & Company merge their networks and help each other spread further. Is this right?
3. Does the use of Multiple Security programs reduce the risk of such BotnetWebs spreading/growing bigger?

Thank you and sorry for the level of my question?
Computer Systems:

Intel Pentium 4 641 / 2GB RAM / Vista Home Basic SP2 / avast! 5.0 Home / SAS Free / MBAM Free / Windows Defender / Windows Firewall / Spyware Blaster/ Secunia PSI / Firefox 3.6 / Opera 10.5

Core2Duo T8300 / 4GB RAM / Vista Home Premium SP2 (32 bit version) / Same Software.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33913
  • malware fighter
Re: Criminal Botnets operating like wolf packs.....
« Reply #2 on: April 10, 2009, 01:02:52 AM »
Hi Confused Computer User,

Question 1. Also called a "zombie army," a botnet is a large number of compromised computers that are used to create and send spam or viruses or flood a network with messages as a denial of service attack. The computer is compromised via a Trojan that often works by opening an Internet Relay Chat (IRC) channel that waits for commands from the person in control of the botnet. There is a thriving botnet business selling lists of compromised computers to hackers and spammers. There must be millions of users worldwide that do no longer own their computer but have lost it to a criminal botnet by not having any proper protection, being without a firewall, not upgraded or patched OS or third party software, n00b zombie computers mean a threat to users that take their computer security seriously. ISPs should isolate these computers and insist the users should cleanse the malware, but the situation persists like it is, similar to the spamming problem that is not seriously being tackled where it should for the obvious reason that always is given (conflict of interests)
Question 2. Malware gangs like to link malicious botnets together or hire the services of one to serve malware to unaware or ill=protected users. The enrollment of the multi-layered functioning of the BotnetWeb makes it so much more difficult to take individual malcreants out and increases malware spreading enormously.
Question3. Yes for you as an individual user it does because you can make sure your computer is not enlisted in such a zombie army. It also asks for an effort by webmasters to make hacks of their websites and malware injection less likely. That is why certain parties (Polonus included) strife for the implementation of a mutual server-browser dual Content Security Policy by which the browser user know what to expect from the server and the server knows what to expect from a browser, so interference by malcreants is less likely, the initiative is called CSP, you can install the extension in Firefox for instance, and hope it is generally adhered. But the biggest risk is from the whole army of grannies and nannies that use a computer without any basic knowledge of computer protection or even a desire to know about this and so putting other users at risk. Everybody that uses Windows by default or as it comes out of the box forms a danger to the workings of the Internet and the security of other computer users,

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Confused Computer User

  • Avast Evangelist
  • Advanced Poster
  • ***
  • Posts: 700
  • The answer is 42
Re: Criminal Botnets operating like wolf packs.....
« Reply #3 on: April 10, 2009, 01:11:55 AM »
Thank you for the time and effort. I can say that I'm a bit wiser (and reassured I was not too far off)

But the biggest risk is from the whole army of grannies and nannies that use a computer without any basic knowledge of computer protection or even a desire to know about this and so putting other users at risk.

Easy on the grannies. I'm trying to get mine to use the computer for browsing newspapers. Of course her grandson (me) will make sure the computer is virus free and up to date with the latest patches. (Me thinks Ubuntu might work better for her)  ;D

Thank you again for the detailed reply.
Computer Systems:

Intel Pentium 4 641 / 2GB RAM / Vista Home Basic SP2 / avast! 5.0 Home / SAS Free / MBAM Free / Windows Defender / Windows Firewall / Spyware Blaster/ Secunia PSI / Firefox 3.6 / Opera 10.5

Core2Duo T8300 / 4GB RAM / Vista Home Premium SP2 (32 bit version) / Same Software.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33913
  • malware fighter
Re: Criminal Botnets operating like wolf packs.....
« Reply #4 on: April 10, 2009, 01:29:33 AM »
Hi Confused Computer User,

With all respect, I did not mean any grandmother personally, there are a lot of chips of the good block, and I am sure your "gran" is one of those. Besides the person who writes you these reports is not actually a young master either and  has passed 61 in January this year, but still can think like a 16 year old,

Damian
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Confused Computer User

  • Avast Evangelist
  • Advanced Poster
  • ***
  • Posts: 700
  • The answer is 42
Re: Criminal Botnets operating like wolf packs.....
« Reply #5 on: April 10, 2009, 02:41:22 AM »
Hi Confused Computer User,

With all respect, I did not mean any grandmother personally, there are a lot of chips of the good block, and I am sure your "gran" is one of those. Besides the person who writes you these reports is not actually a young master either and  has passed 61 in January this year, but still can think like a 16 year old,

Damian

I realized that, simply making a joke.
Congratulations are in order and the traditional: And Many More!
Computer Systems:

Intel Pentium 4 641 / 2GB RAM / Vista Home Basic SP2 / avast! 5.0 Home / SAS Free / MBAM Free / Windows Defender / Windows Firewall / Spyware Blaster/ Secunia PSI / Firefox 3.6 / Opera 10.5

Core2Duo T8300 / 4GB RAM / Vista Home Premium SP2 (32 bit version) / Same Software.