Huge 'botnet' amputated, but criminals reconnect

On Facebook
Life & Style blogs

Online House Hunter: England’s most romantic places

Our Online House Hunter goes in search of romance this Valentine's Day...

Online House Hunter: Rugby – a Dickens of a town

Charles Dickens didn't think much of the railway town of Rugby in Warwickshire, calling it Mugby. Bu...

Online House Hunter: Mortgage relief

Banks would appear to be finally relinquishing their stranglehold on mortgages. Our Online House Hun...

The sudden takedown of an Internet provider thought to be helping spread one of the most promiscuous pieces of malicious software out there appears to have cut off criminals from potentially millions of personal computers under their control.

But the victory was short-lived. Less than a day after a service known as "AS Troyak" was unplugged from the Internet, security researchers said Wednesday it apparently had found a way to get back online, and criminals were reconnecting with their unmoored machines.



The drama initially raised hopes of a sharp drop-off in fraud, because criminals could no longer communicate with many computers infected with a type of malware known as "ZeuS," which is mostly used to steal online banking usernames and passwords. Hundreds of criminal operations around the world use the malware.



It's unknown how many computers are infected with ZeuS, but it's estimated to be in the millions. Cisco said as many as 25 per cent of the world's ZeuS-infected machines were unplugged from the massive "botnet" overnight with the takedown of AS Troyak.



Botnets are networks of infected PCs that behave like criminals' remote-control robots. They steal identities en masse and are used to attack Web sites.



But instead of a slam-dunk victory, the incident wound up highlighting the whiplash pace at which criminals can resurrect their illicit businesses after what should have been a devastating setback.



RSA, the security division of EMC Corp., said dozens of malicious servers that criminals used to spread ZeuS were connected to the Internet by AS Troyak. The service inexplicably went dark Tuesday, severing the ties between criminals and ZeuS-infected machines under their control.



It's not publicly known who pulled the plug. It could have been law enforcement, security researchers, or even the criminals themselves if they decided to move their operations to other servers.



Shutting down malware operations is a constant cat-and-mouse game.



Some services exist solely to host malicious content, and when their connections to the Internet are severed, it's often relatively easy to find another provider willing to sell them a new connection.



RSA researchers wrote in a note to clients that their experience shows that "these kinds of drastic changes are usually short-lived, as in the long run, criminals tend to restructure their criminal activity and relaunch their online attacks."



That apparently happened - and quickly. By Wednesday, researchers said the servers appeared to be back online, through a new Internet provider.



Cisco researchers said a total of 68 command-and-control servers were brought down, but that it's unknown how many infected computers were connected to each of those.



But they added that the criminals may have known the servers were going to be brought down, because traffic to those servers spiked over the weekend, suggesting they were directing infected computers to point to new servers.



One of the most high-profile takedowns of a malicious Web site hosting service involved a company called McColo Corp. whose Internet service was severed in the winter of 2008 after researchers amassed evidence of the company's wrongdoing.



Worldwide spam volumes almost instantly dropped by half, but within days started climbing again.

Independent Comment
blog comments powered by Disqus

Day In a Page

Apple admits it has a human rights problem

Apple admits it has a human rights problem

After years of complaints and workers' suicides in China the technology giant faces up to the human cost of its gadgets
Peter Moore: 'I feel guilty I'm the only one alive'

Peter Moore interview

'I feel guilty I'm the only one alive'
Sellafield faces nuclear option as overspending threatens plant's future

Sellafield faces nuclear option

Overspending threatens plant's future
Israel blames Iran for embassy bomb attacks

Israel blames Iran for embassy bomb attacks

Tehran rejects Netanyahu's 'lies' after diplomats in India and Georgia targeted
Former manager enjoying Apoel crack at the big time

Tommy Cassidy interview

Former manager enjoying Apoel crack at the big time
James Lawton: Patience may not be a virtue this time, Roman – Andre Villas-Boas looks all at sea

James Lawton: AVB looks all at sea

Abramovich's visits to training reinforce the idea of a coach feeling pressure from above and below
The 10 Best sledges

The 10 Best sledges

Not all of them require snow...
Procrastination: Not now – I'm busy

Procrastination: Not now – I'm busy

Confronting the real reasons for puttting things off can help us beat it
Fun in the sunset years

Fun in the sunset years

A new movie follows retirees moving to India for low-cost care and a culture of respect for the elderly. For many Britons, it's already a reality
Picture preview: Lucian Freud drawings

Lucian Freud drawings

Picture preview
Silent revolution at the Baftas as the French take top awards

Silent revolution at the Baftas

The Artist wins in seven categories, with Meryl Streep the other big success story
Whitney Houston: The diva who had – and lost – it all

The diva who had – and lost – it all

Nick Hasted charts the highs and lows of Whitney Houston's life
How Picasso won over (some of) the British

How Picasso won over (some of) the British

Winston Churchill and Evelyn Waugh hated his work, but Picasso provided inspiration for a whole generation of UK artists
Topshop: A Decade Of Design

Topshop: A Decade Of Design

When London Fashion Week starts on Friday, Topshop will celebrate 10 years backing its brightest young stars
John Prescott: 'My wife thought I'd just retire, but I'm not a slippers man'

'My wife thought I'd just retire, but I'm not a slippers man'

At 73, John Prescott isn't mellowing. In fact he's taking a shot at becoming a police commissioner