On CBS.com: You a Survivor Fan?Play Survivor Fantasy
BNET Business Network:
BNET
TechRepublic
ZDNet

Posted on ZDNet News: Jul 7, 2004 12:33:00 PM

Reuters Logo Vast networks of home computers are being rented out without their owners' knowledge to spammers, fraudsters and digital saboteurs, security experts said on Wednesday.

The terminals have been infected by a computer virus, turning them into "zombies"--slaves to the commands of a malicious and unseen controller. Connect them all up, and the result is a powerful network of zombie PCs that security experts call a "botnet."

The programming crooks--often teenage bedroom hackers--are hiring out these networks to anyone who wants to commit Internet mischief.

"Small groups of young people creating a resource out of a 10,000- to 30,000-strong computer network are renting them out to anybody who has the money," a source in Scotland Yard's computer crime unit told Reuters.

There may be millions of such PCs around the world doing the bidding of crime gangs, experts say, and they can be rented for as little as $100 per hour.

By marshaling the muscle of a few thousand computers, a spammer can send a burst of e-mail messages to sell all manner of products in the name of unsuspecting computer users.

Fraudsters known as "phishers" use the networks both to send deceiving messages and host authentic-looking bank Web sites designed to steal financial details, authorities said.

A more sinister use of botnets is sabotage, police say. A fear is growing that a botnet could be used to take down a major data network or prominent Web sites.

"You're talking about serious firepower," the source said.

'Hitmen' PCs
Botnets have grown in number and ferocity since last summer, when a volley of digital contagions first hit the Internet, seeking to put unsuspecting home PCs under the command of a single programmer.

The hackers' task has been made easier by the growth in the number of homes connected to broadband--an essential prerequisite for a zombie.

A few months after these viruses first appeared, security experts and police noticed online discussion areas where blocs of virus-infected computers were on offer for those in the market for an army of "hitmen" terminals.

The commandeered machines were first rented out to spammers.

"The preferred method of spamming is now via botnets, and there's a lot of money to be made in hiring them out," said Mark Sunner, chief technology officer at security company MessageLabs.

Lately, botnets have been aimed at crippling Web sites. The ammunition in this case can be bought for a few thousand dollars, experts and investigators say.

"It's denial-of-service for hire," Steve Linford, founder of antispam organization Spamhaus Project, said in reference to a type of digital attack capable of crippling a company's network.

"If you want to take out a big site, you can rent a Russian botnet. When it is aimed at your computer there's nothing you can do," Linford said.

Police in Western Europe have had some luck dismantling a few networks and have made some arrests. But the racket runs deep, investigators say, extending from the United States to Western Europe and perhaps to Eastern European crime syndicates.

The list of botnet victims grows weekly. It includes a host of gambling Web sites and WorldPay, the online payment processing service owned by the Royal Bank of Scotland.

The investigative trail so far has led to computer-savvy teens looking to sell time on their army of commandeered PCs to spammers and fraudsters at the highest bid. Further up the chain, the trail runs cold.

"We think a big part of the operation--the virus-writing and the buying and selling of PC proxies--is kids," said Mikko Hypponen, antivirus research director at Finnish data security company F-Secure.

"We think crime groups are involved as well--but they seem to be using these kids as child labor."

Story Copyright  © 2004 Reuters Limited.  All rights reserved.

Story Copyright © 2004 Reuters Limited. All rights reserved.

SponsoredWhite Papers, Webcasts, and Downloads

  • Talkback
  • Most Recent of 35 Talkback(s)
Help the unknowing "accomplice" first
Certainly few people would allow their pc to act as a zombie, if they even knew it was corrupted.

When a zombie's IP is discovered - send them a notice and instructions on how to fix the prob... (Read the rest)
Posted by: artl Posted on: 12/28/05 You are currently: a Guest | | Terms of Use
Take botnets off line  seadog59 | 07/07/04
That's pretty harsh!  S.Howard-SarinZDNet Moderator | 07/07/04
not harsh enough  Valis Keogh | 07/10/04
I agree!  No_Ax_to_Grind | 07/07/04
Except that  Linux User 147560 | 07/07/04
Let the isp do the policing.  No_Ax_to_Grind | 07/07/04
Make Microsoft clean up the mess they caused  Squawkbox | 07/07/04
Good Post  Jeff Spicoli | 07/07/04
Amen! Bitty and M$hills always try to pass the buck!  Xunil_Sierutuf | 07/07/04
Car analogies SUCK.  No_Ax_to_Grind | 07/07/04
That's because you know the car analogy shows what crap M$ is!!  Jeff Spicoli | 07/07/04
Sure, they suck  AbsolutelyNot | 07/08/04
Oh PULEASE...  No_Ax_to_Grind | 07/07/04
Buuuuwahhaawha....!.....  Jeff Spicoli | 07/07/04
Innocent Web Site Visitors to Blame? C'mon, Axey ...  Judas I. | 07/08/04
Where were you the week before last, then?  AbsolutelyNot | 07/08/04
How so...  UncleBubba | 07/08/04
Serious potential problem with punishing the consumer  Jeff Spicoli | 07/07/04
Help the unknowing "accomplice" first  artl | 12/28/05
This makes no sense.  No_Ax_to_Grind | 07/07/04
Sure it does  Jeff Spicoli | 07/07/04
But how do they get paid?  John L. Ries | 07/07/04
Exactly my point. Thank you!  No_Ax_to_Grind | 07/07/04
So, just because you can't figure out how they do it ...  Judas I. | 07/08/04
While I'm..  Jeff Spicoli | 07/07/04
And that explains all anyone needs to know from you.  No_Ax_to_Grind | 07/07/04
...  Jeff Spicoli | 07/07/04
Re: But how do they get paid?  Andylb | 07/08/04
$100 per hour?  Harry Butts | 07/07/04
Did I read it wrong?  doodlius | 07/07/04
YES!!!  Jeff Spicoli | 07/07/04
You got it right  AbsolutelyNot | 07/08/04
Fine Zombies  Outside T. Box | 07/08/04
i think i love you.  Valis Keogh | 07/10/04
Crazy  medezark | 07/12/04

What do you think?

advertisement
advertisement

White Papers, Webcasts, and Downloads