Original URL: http://www.theregister.co.uk/2007/06/13/millionth_botnet_address/
Federal law enforcement agents targeting botnets recently recorded a grim milestone, identifying the millionth potential zombie victim, the FBI said Wednesday.
Operation Bot Roast, as the cyber crime project has come to be known, has now logged more than 1m IP addresses belonging to a botnet. That amounts to plenty of owners, most of whom are oblivious that their Windows 98 box is a cog the sprawling machine at the heart of cyber crime.
So the FBI is working with industry partners such as the CERT Coordination Center (http://www.cert.org/) at Carnegie Mellon University to notify victims, the agency announced in a release (http://www.fbi.gov/pressrel/pressrel07/botnet061307.htm). We wanted to know how a notification effort of this scale might work, so we put in a call to learn more.
It turns out it there will be no mass emails or phone calls informing victims their machines are compromised. Rather, the project amounts to a campaign to educate the masses that the information security revolution starts at home.
"The vast majority of people infected don't really know their computer has been attacked and their computers are part in a wide-ranging number of criminal activities," says Shawn Henry, the deputy assistant director in the FBI's cyber division. "They've got a responsibility to take a look at their equipment and their networks and ensure that they're secure."
Botnets have emerged as the swiss army knife of online crime. They facilitate identity theft by storing huge caches of pilfered personal information. They are the launch pad for most denial of service attacks. And they are the preferred means of churning out spam, which many researchers now estimate comprises 80 percent of the email landing in our inboxes.
In the last couple of years, malware writers have made great strides in designing bots that are largely undetectable to the untrained eye. Many bot applications go through the trouble of installing any missed Windows patches so the compromised machine isn't vulnerable to competing bot herders. The result is a machine that is secretly under the control of a criminal, essentially making it a zombie.
Among the newer uses of botnets is a phishing variation known as the "Rock Phish." Traditional phishing attacks are frequently thwarted when a bank or other target manages to get a domain name registrar to revoke the URL being used by the spoof site. Rock Phish scams solve this limitation by using bots to host the fraudulent sites. When a phishing target succeeds in cutting off a bot, the fraudsters can easily tap another drone to host the bogus site.
"It's the biggest phishing threat out there right now," says Uriel Maimon, a senior research scientist at RSA (http://rsa.com/). He estimates the Rock Phish method is responsible for almost half of today's phishing attacks and are being carried out by a single organized crime ring located in eastern Europe.
Joe Stewart, a senior researcher at SecureWorks (http://secureworks.com/), says Rock Phish attackers store a mountain of pilfered data on a central server and use bots as a kind of reverse proxy to obscure where it is located.
The term Rock Phish got its name from a now discontinued quirk in which the attackers used directory paths that contained the word "rock." The method currently targets at least 44 banks, and has proven particularly adept at keeping researchers in the dark, says Stewart.
Operation Bot Roast was created several months ago as an umbrella for the FBI's hundreds of ongoing investigations involving botnets, Henry says. Those investigations have spawned several arrests, including one in 2005 of a 20-year-old hacker who netted more than $61,000 and claimed to control more than 100,000 machines. Jeanson James Ancheta ultimately pleaded guilty and is now serving more than five years in federal prison.
More recently, other suspects of cyber crime have been nabbed as a result of the FBI's crackdown on botnets. Among them: Robert Alan Soloway, aka the Spam King, who was arrested (http://www.theregister.com/2007/05/31/spam_king_arrested/) in Seattle last month and accused of using a large botnet to send tens of millions of junk mails. The 27-year-old business man has pleaded not guilty and is awaiting trial in the case.
Two other individuals - Jason Michael Downey of Covington, Kentucky, and James C. Brewer of Arlington, Texas - have also recently been charged or arrested in connection with botnet-related crimes.
The FBI marked another significant milestone on Wednesday, announcing its Internet Crime Complaint Center (http://www.ic3.gov/), or IC3, logged its 1 millionth consumer complaint. The IC3 was established in 2000 and is a partnership between the FBI and the National White Collar Crime Center. Its mission is to provide a means for receiving, developing and referring criminal complaints related to cyber crime.
The IC3 has forwarded more than 461,000 criminal complaints, representing losses of about $647m, to federal, state or local law enforcement agencies.®
Disgruntled admin gets 63 months for massive data deletion (13 June 2008)
http://www.theregister.co.uk/2008/06/13/it_manager_rampage_sentence/
The rise of the Malware Mafia (11 April 2008)
http://www.theregister.co.uk/2008/04/11/organized_crime_embraces_net/
Notorious spammer pleads guilty to tax evasion and fraud (17 March 2008)
http://www.theregister.co.uk/2008/03/17/soloway_spammer_guilty_plea/
Bank scammers scammed, says security researcher (15 February 2008)
http://www.theregister.co.uk/2008/02/15/bank_scammers_scammed/
Thievin' teen bot herder admits to infecting military computers (12 February 2008)
http://www.theregister.co.uk/2008/02/12/bot_herder_cops_plea/
Experts paint bleak picture of security in 2017 (4 December 2007)
http://www.channelregister.co.uk/2007/12/04/security_in_2017/
Mum defends suspected Kiwi botmaster (4 December 2007)
http://www.theregister.co.uk/2007/12/04/kiwi_botmaster_follow_up/
NZ police cuff teenage botnet mastermind suspect (30 November 2007)
http://www.theregister.co.uk/2007/11/30/kiwi_teen_botmaster_arrest/
Botmaster owns up to 250,000 zombie PCs (9 November 2007)
http://www.theregister.co.uk/2007/11/09/botmaster_to_plea_guilty/
US phishermen trawl UK waters (18 October 2007)
http://www.theregister.co.uk/2007/10/18/phishing_trends/
Zombies flood broadband networks (18 September 2007)
http://www.theregister.co.uk/2007/09/18/arbor_botnet_survey/
Germany nets ten phishing suspects (14 September 2007)
http://www.theregister.co.uk/2007/09/14/germany_phishing_arrests/
Malware miscreants target parked domains (14 August 2007)
http://www.theregister.co.uk/2007/08/14/parked_domain_trojan_attack/
Spammers debut FDF spam (13 August 2007)
http://www.theregister.co.uk/2007/08/13/fdf_spam/
Fast flux foils botnet takedown (11 July 2007)
http://www.theregister.co.uk/2007/07/11/fast_flux_botnet/
Turing test challenges spam filters (6 July 2007)
http://www.theregister.co.uk/2007/07/06/fuzzy_image_spam/
Trojan creates bogus webmail accounts to punt drugs (6 July 2007)
http://www.theregister.co.uk/2007/07/06/webmail_trojan/
Storm Trojan feeds on Independence Day (4 July 2007)
http://www.theregister.co.uk/2007/07/04/july_4_storm_trojan/
MPack malware exposes cheapskate web hosts (3 July 2007)
http://www.theregister.co.uk/2007/07/03/mpack_reloaded/
Feds fiddle as cybertopia burns (2 July 2007)
http://www.theregister.co.uk/2007/07/02/feds_prosecute_adult_site/
Senior execs targeted in 'precision' malware attacks (2 July 2007)
http://www.theregister.co.uk/2007/07/02/personal_malware/
Lawmakers worry over government network breaches (29 June 2007)
http://www.theregister.co.uk/2007/06/29/congress_cyber_security/
Austrian domain registrar 'aids' phishers (21 June 2007)
http://www.theregister.co.uk/2007/06/21/austrian_registrar_phishing_row/
Phishermen, not zombies, causing biggest security woes (20 June 2007)
http://www.theregister.co.uk/2007/06/20/mcafee_security_trends/
DIY kits dumb down phishing (8 June 2007)
http://www.theregister.co.uk/2007/06/08/phishing_kit_survey_ibm/
DDoS attacks fall as crackers turn to spam (2 May 2007)
http://www.theregister.co.uk/2007/05/02/dos_trends_symantec/
Zombies infiltrate US military networks (16 April 2007)
http://www.theregister.co.uk/2007/04/16/military_botnet/
So who sent you that spam? HP or Oracle? (28 March 2007)
http://www.theregister.co.uk/2007/03/28/bots_in_perimeter/
China displaces Britain as botnet epicentre (19 March 2007)
http://www.theregister.co.uk/2007/03/19/symantec_threat_report/
Man pleads guilty to spreading Trojan via IRC (22 February 2007)
http://www.theregister.co.uk/2007/02/22/trojan_plea/
Phish fighters floored by DDoS assault (20 February 2007)
http://www.theregister.co.uk/2007/02/20/castlecops_ddos/
Employee fired for probing bad guys awarded $4.7m (16 February 2007)
http://www.theregister.co.uk/2007/02/16/sandia_verdict/
Anatomy sheds new light on Storm Worm (9 February 2007)
http://www.theregister.co.uk/2007/02/09/storm_worm_anatomy/
Dutch botnet duo sentenced (1 February 2007)
http://www.theregister.co.uk/2007/02/01/dutch_botnet_gang_sentenced/
Botnet 'pandemic' threatens to strangle the net (26 January 2007)
http://www.theregister.co.uk/2007/01/26/botnet_threat/
US tops spam relaying and malware leagues of shame (22 January 2007)
http://www.theregister.co.uk/2007/01/22/malware_spam_report_sophos/
Inboxes battered by Trojan spam deluge (19 January 2007)
http://www.theregister.co.uk/2007/01/19/trojan_storm/
Florida 'botmaster' charged with Akamai DDOS attack (24 October 2006)
http://www.theregister.co.uk/2006/10/24/akamai_ddos_attack_man_charged/
Botnet creators AIM high (21 September 2006)
http://www.theregister.co.uk/2006/09/21/pipeline_worm/
Zombies crawl over wiki exploits (7 September 2006)
http://www.theregister.co.uk/2006/09/07/wiki_exploit/
Botnet herder jailed over hospital attack (29 August 2006)
http://www.theregister.co.uk/2006/08/29/botnet_herder_jailed/
© Copyright 2008