On mySimon: Columbia Sportswear Bugathermo Boots
BNET Business Network:
BNET
TechRepublic
ZDNet

By Munir Kotadia
Posted on ZDNet News: May 25, 2005 1:08:00 PM

Virus authors are choosing not to create global epidemics--such as Melissa or Blaster--because that distracts them from their core business of creating and selling botnets, according to antivirus experts.

Botnets are groups of computers that have been infected by malware that allows the author to control the infected PCs, and then typically use them to send spam or launch DDoS attacks.

Speaking at the AusCERT conference on Australia's Gold Coast on Tuesday, Eugene Kaspersky, founder of Kaspersky Labs, said that the influence of organised crime on the malware industry has led to a change of tactics, echoing comments made in March of this year by Mikko Hyppönen of F-Secure. Instead of trying to create viruses and worms that infect as many computers as possible, malware authors are instead trying to infect 5,000 or 10,000 computers at a time to create personalized zombie armies.

"Do I need a million computers to send spam? No. To do a DDoS attack, 5,000 or 10,000 PCs is more than enough. That is why virus writers and hackers have changed their tactics of infection--they don't need a global epidemic," said Kaspersky.

According to Kaspersky, organized criminals are advertising networks of zombie computers for rent on underground newsgroups and Web pages. When they receive an order for a botnet of a certain size, they set about trying to infect computers using infected email attachments or socially-engineered spam with links to malicious Web pages. As soon as they infect enough computers to fulfill the order, they stop using that particular piece of malware.

"It seems that if, say, the virus author needs 5,000 infected computers, they put the Trojan on a Web page and wait for 5,000 machines to be infected. Then they remove the Trojan because that is enough. When they get a new request for another zombie network, they release a new Trojan--they are able to control the number of infected computers," said Kaspersky.

Adam Biviano, senior systems engineer at antivirus firm Trend Micro, agrees. He said that by only infecting a relatively small number of computers, the malware has a better chance of flying 'under the radar' and not being spotted by antivirus companies.

"It makes sense to have a discreet number of PCs under your control and be able to sell that on," said Biviano, who added: "With 5,000 PCs under your control--none of which are being destroyed or showing actual qualifiable damage as a result--you will fit under the radar, probably make some money and you probably won't get arrested."

Kaspersky said that to fight this new tactic antivirus companies have to be more thorough by scouring Web pages and e-mail attachments for new and obscure pieces of malware--to ensure as few Trojans as possible get through to users.

"Before releasing the new infected code they test it using antivirus scanners and they don't release the new Trojan or worm if it is detected. I believe that if only 1,000 machines are infected, anti-virus companies will never receive the infected file. That is why antivirus companies have to collect data reactively and get samples as quickly as possible," said Kaspersky.

Vincent Gullotto, vice-president of McAfee's antivirus emergency response team, told ZDNet Australia that antivirus companies are responding to the new threat by proactively seeking out new forms of malware.

"It is standard for us, Kaspersky, Symantec and some of the other prominent antivirus companies scour the Web in many different ways. We go out looking for [malware] with a very aggressive search and we do passive searches where we have machines that are just sitting around waiting to get attacked. When we see a machine getting attacked we grab a sample rather quickly so we can add it to our database," said Gullotto.

SponsoredWhite Papers, Webcasts, and Downloads

  • Talkback
  • Most Recent of 80 Talkback(s)
Seriously though...
The reason the "International Computing community's police" aren't cracking down is because in most countries what they are doing is not considered a crime. Even in the U.S. there are only a few laws... (Read the rest)
Posted by: Tellco Posted on: 06/08/05 You are currently: a Guest | | Terms of Use
small trojans on websites  anglemilt | 05/25/05
use a text editor and an ftp program  linuxoverwindows | 05/25/05
Just what we need...  Carrion | 05/25/05
Actually...  Brian@... | 05/25/05
That's my point...  Carrion | 05/25/05
Some of these users...  ladyjet@... | 05/25/05
A bad drive in a car with bad brakes  voska | 05/25/05
Not a clue  thirstydog@... | 05/25/05
I know EXACTLY what I'm talking about  Carrion | 05/25/05
No you don't  tgrady | 05/25/05
No you don't  renaissance2000 | 05/25/05
how do you do that?  johnpharvey@... | 05/30/05
Here's your Sign  GregSalts | 05/25/05
Another options is:  ladyjet@... | 05/25/05
In Theory  renaissance2000 | 05/25/05
Not a "platform" issue  tgrady | 05/25/05
Linux is vulnerable too  jescocom | 05/26/05
its simple  linuxoverwindows | 05/25/05
I Need Help  ladyk45 | 05/25/05
No Problem  IT Scion | 05/25/05
Thanks for the tip, and the link. happy  dennis_44149 | 05/25/05
a little help  cgwynn1 | 05/31/05
Virus help site  Gueze | 05/31/05
i thought it was just me  fofyve | 05/25/05
Most small ISPs do care...  ladyjet@... | 05/25/05
malware  Ogandydancer | 05/25/05
criminally created Malware, Trojan Horses, Viruses, Worms and etc.  deafyharv | 05/25/05
cant go after the criminals...  linuxoverwindows | 05/25/05
What about tar and feathers?  ladyjet@... | 05/25/05
Rope  TotalKayeos | 05/26/05
Seriously though...  Tellco | 06/08/05
hahahahahahahahahahaha  Reverend MacFellow | 05/25/05
Actually  IT Scion | 05/25/05
I'll second that notion!  rocky1 | 05/25/05
Wrong Paradigm  Yagotta B. Kidding | 05/25/05
Way off base  HelpDesk Dave | 05/25/05
Actually  nightshade0143 | 05/26/05
Nightshade  IT Scion | 05/27/05
Plus  IT Scion | 05/27/05
you could use a typewriter  pablito@... | 05/25/05
Uhhh...  RatMcGee | 05/25/05
Amazing...  RAnthony | 05/25/05
Not a MS issue!  rocky1 | 05/25/05
Also  IT Scion | 05/25/05
Trojans to order  Anton Philidor | 05/25/05
VIRUSES FROM MICROSOFT???!!!  the_webninja@... | 05/25/05
Comment on: " VIRUSES FROM MICROSOFT???!!!"  celticwatch | 05/25/05
re VIRUSES FROM MICROSOFT???!!!  NotMSUser | 05/25/05
Paranoia??? Update the drivers  GetReal-mac.com | 05/25/05
Simple fixes  Anton Philidor | 05/25/05
Yes it is!  Altern_z | 05/25/05
Its not!  jkcdlm1 | 05/25/05
They fixed it.  HiRezL | 05/26/05
DO THIS!  osreinstall | 05/25/05
Better yet,,,  Bagmaster50 | 05/25/05
Too Involved  osreinstall | 05/26/05
Winblows users get what they deserve  Chad_z | 05/25/05
Really?  tgrady | 05/25/05
I've not had an infection on my Win boxes either  FilledOut | 05/25/05
Cartoon os?  jkcdlm1 | 05/25/05
I use Windows 2000  voska | 05/25/05
Yea  IT Scion | 05/26/05
What's wrong with cartoony?  HiRezL | 05/26/05
reply to chad  poetdowns | 05/26/05
Sounds like a Ghost in the Shell episode  darkside@... | 05/25/05
Just run out to Best Buy and pick up a Linux distro  FilledOut | 05/25/05
Small empty ponies comin' through the Gates...  RatMcGee | 05/25/05
Time to switch to Linux!!!  craig@... | 05/25/05
Umm  IT Scion | 05/26/05
RE: Umm  nightshade0143 | 05/26/05
Well  IT Scion | 05/26/05
Anti-virus companies and SETI  mvsarno@... | 05/26/05
Hmmmm  HiRezL | 05/26/05
A simple plan  rottweilerus | 05/26/05
I've seen it first hand.  Fusion_z | 05/26/05
It might be just the AV ur using  FilledOut | 05/26/05
one solution  poetdowns | 05/26/05
Down with MS (or not)  TotalKayeos | 05/26/05
Give this boy a cigar!  osreinstall | 05/26/05
lmao...nice disclaimer(nt)  IT Scion | 05/26/05

What do you think?

advertisement
advertisement

White Papers, Webcasts, and Downloads

SmartPlanet

Click Here