English

Hello 

Create Profile

Creating your profile will enable you to submit photos and stories to get published on News24.


Please provide a username for your profile page:

This username must be unique, cannot be edited and will be used in the URL to your profile page across the entire 24.com network.

Settings

Location Settings

News24 allows you to edit the display of certain components based on a location. If you wish to personalise the page based on your preferences, please select a location for each component and click "Submit" in order for the changes to take affect.









Facebook Sign-In

Hi News addict,

Join the News24 Community to be involved in breaking the news.

Log in with Facebook to comment and personalise news, weather and listings.

 
 

Huge botnet down, up again

2010-03-11 13:26
line

kalahari.com

San Jose - The sudden takedown of an internet provider thought to be helping spread one of the most promiscuous pieces of malicious software out there appears to have cut off criminals from potentially millions of personal computers under their control.

But the victory was short-lived. Less than a day after a service known as "AS Troyak" was unplugged from the internet, security researchers said on Wednesday it apparently had found a way to get back online, and criminals were reconnecting with their unmoored machines.

The drama initially raised hopes of a sharp drop-off in fraud, because criminals could no longer communicate with many computers infected with a type of malware known as "ZeuS", which is mostly used to steal online banking usernames and passwords. Hundreds of criminal operations around the world use the malware.

It's unknown how many computers are infected with ZeuS, but it's estimated to be in the millions. Cisco Systems Inc said as many as 25% of the world's ZeuS-infected machines were unplugged from the massive "botnet" overnight with the takedown of AS Troyak.

Botnets are networks of infected PCs that behave like criminals' remote-control robots. They steal identities en masse and are used to attack websites.

Cat-and-mouse game

But instead of a slam-dunk victory, the incident wound up highlighting the whiplash pace at which criminals can resurrect their illicit businesses after what should have been a devastating setback.

RSA, the security division of EMC Corp, said dozens of malicious servers that criminals used to spread ZeuS were connected to the internet by AS Troyak. The service inexplicably went dark on Tuesday, severing the ties between criminals and ZeuS-infected machines under their control.

It's not publicly known who pulled the plug. It could have been law enforcement, security researchers, or even the criminals themselves if they decided to move their operations to other servers.

Shutting down malware operations is a constant cat-and-mouse game.

Some services exist solely to host malicious content, and when their connections to the internet are severed, it's often relatively easy to find another provider willing to sell them a new connection.

RSA researchers wrote in a note to clients that their experience shows that "these kinds of drastic changes are usually short-lived, as in the long run, criminals tend to restructure their criminal activity and re-launch their online attacks".

That apparently happened - and quickly. By Wednesday, researchers said the servers appeared to be back online, through a new internet provider.

Spam

Cisco researchers said a total of 68 command-and-control servers were brought down, but that it's unknown how many infected computers were connected to each of those.

But they added that the criminals may have known the servers were going to be brought down, because traffic to those servers spiked over the weekend, suggesting they were directing infected computers to point to new servers.

One of the most high-profile takedowns of a malicious website hosting service involved a company called McColo Corp whose internet service was severed in the winter of 2008 after researchers amassed evidence of the company's wrongdoing.

Worldwide spam volumes almost instantly dropped by half, but within days started climbing again.

- AP

Add your view to this conversation - comment below

Read more on:    internet  |  cybercrime

Read News24’s Comments Policy

Comment on this story
0 comments
Add your comment
Comment 0 characters remaining

inside news24

 

140
1
1 of 10

Latest comment in Sci-Tech

Blackpoison says... Sounds like aliens on Venus are trying to hide something from us earthlings.... Read the article...

 
Traffic
Lottery
 
  • Wednesday Ladysmith - 22:09 PM
    Road name: N11 Both Ways
    ROADWORK - two sets of stop / go controls just south of the R68 Dundee exit - expect waiting times of up to 20 minutes between Ladysmith and Newcastle (ends March 2013)
  • Saturday Pretoria - 08:07 AM
    Road name: N1 Both Ways
    ROADWORKS - lane closures on both carriageways for long term roadworks between the N4 Witbank Highway Interchange and the Zambesi Drive exit - EXPECT DELAYS (until Jan 2013)
 
More traffic reports...
 

Jobs [change area]

Cars[change area]

VOLKSWAGEN

Polo 1.6 Comfortline 5-dr MY05
2007
R 139,995.00

PEUGEOT

406 2.2 ST
2002
R 84,990.00

TOYOTA

Hilux 2.7 Raider VVT-i RB D-Cab PU MY09
2009
R 210,950.00

Property [change area]

Vulintaba Country Estate, Upper Drakensberg

A lifestyle estate beyond compare. Home Package Options From R990 000

HOUSES FOR SALE IN Noordhoek

Houses R 13 995 000

Travel - Look, Book, Go!

Casa Rex, Vilanculos

Spend 5 nights in at the magical Mozambican resort of Casa Rex from R7983 per person sharing. Includes accommodation, return flights, taxes and transfers. Book now!

Kalahari.com - shop online today

Darksiders II

Something threatens earth and ironically it’s up the Horseman of Death to be the saviour of mankind. Buy now.

Hot new releases on DVD

Fresh off the cinema circuit and straight into your personal collection. Buy now

Cool music for Dad

Fishing, driving or relaxing, get the tunes that make up the soundtrack to suit Dads every mood. Buy now.

Great books to consider

Gripping titles and best sellers that will inspire the dormant reader within anyone to resurface. Buy now.

Helicopters

Get into the Pilots seat with the Syma Radio Control Helicopter. Buy now.

OLX Free Classifieds [change area]

pool table

For Sale, Toys - Games - Hobbies in South Africa, Gauteng, Johannesburg. Date May 6

Lexus: IS

Vehicles, Cars in South Africa, Gauteng, Johannesburg. Date May 7

stylish bachelor furnished in sandton from 1st of june

Real Estate, Houses - Apartments for Rent in South Africa, Gauteng, Johannesburg. Date May 7

BlackBerry Curve 8520

Wi-Fi enabled With the BlackBerry Curve 8520 connect to your home...

From R1569.00

I'm shopping for:

Horoscopes
Aquarius
Aquarius

Your heart is with a friend who is going through a difficult time, but your soul is with an activity that you know brings you...read more

There are new stories on the homepage. Click here to see them.