Feeds

Superworm seizes 9m PCs, 'stunned' researchers say

Downadup goes up and up

  • alert
  • submit to reddit

Build a business case: developing custom apps

Downadup, the superworm that attacks a patched vulnerability in Microsoft Windows, is making exponential gains if estimates from researchers at F-Secure are accurate. They show 6.5 million new infections in the past four days, bringing the total number of machines it has compromised to almost 9 million.

The astronomical growth stunned some researchers, although others cautioned the numbers could be inflated since the counting of infected computers is by no means an exact science. Most agreed F-Secure's estimate was certainly plausible and if it proved to be correct, represented a major development in the world of cyberthreats.

"This thing has gotten way out of hand," said Paul Ferguson, a security researcher for anti-virus provider Trend Micro who has spent the past several weeks tracking the worm's progress. "It seems pretty spectacular to me that there could be that much growth."

A confluence of factors are responsible for the growth of Downadup, which also goes by the name Conficker.

For one, the underlying vulnerability allows for self-replicating attacks in the 2000, XP, and Server 2003 versions of Windows. And for another, the malware authors have cleverly designed exploits that spread via flash and network drives, online trojans, and social engineering features that allow it to spread like wildfire within a local network once a single machine is compromised.

Another important contribution to the outbreak seems to be the legions of administrators and users of Windows machines who have failed to heed repeated admonitions to update. Despite Microsoft releasing an emergency patch for the vulnerability almost three months ago, nearly one in three Windows machines have yet to apply it, according to research from security provider Qualys.

Some Skepticism

Not all security watchers are convinced there really are 9 million machines infected by Downadup. Paul Royal, chief scientist with anti-botnet company Damballa, said his researchers have counted only about 500,000 unique IP addresses connecting to Downadup's master control server. That would imply an average of 18 infected machines behind each address, a number he says is unlikely.

The skepticism prompted F-Secure researchers to explain its methodology for the mind-boggling number. By infiltrating Downadup's control channel and analyzing logs of machines that connected, researchers discovered a counter believed to show the number of other PCs the compromised machine has infected.

After creating a script that totaled all those numbers together, F-Secure deduced 8.97 million machines have been compromised, up from 2.4 million on Tuesday.

Endpoint data privacy in the cloud is easier than you think

More from The Register

next story
Microsoft's Euro cloud darkens: US FEDS can dig into foreign servers
They're not emails, they're business records, says court
'Things' on the Internet-of-things have 25 vulnerabilities apiece
Leaking sprinklers, overheated thermostats and picked locks all online
iWallet: No BONKING PLEASE, we're Apple
BLE-ding iPhones, not NFC bonkers, will drive trend - marketeers
Multipath TCP speeds up the internet so much that security breaks
Black Hat research says proposed protocol will bork network probes, flummox firewalls
Plug and PREY: Hackers reprogram USB drives to silently infect PCs
BadUSB instructs gadget chips to inject key-presses, redirect net traffic and more
Only '3% of web servers in top corps' fully fixed after Heartbleed snafu
Just slapping a patched OpenSSL on a machine ain't going to cut it, we're told
How long is too long to wait for a security fix?
Synology finally patches OpenSSL bugs in Trevor's NAS
Israel's Iron Dome missile tech stolen by Chinese hackers
Corporate raiders Comment Crew fingered for attacks
prev story

Whitepapers

7 Elements of Radically Simple OS Migration
Avoid the typical headaches of OS migration during your next project by learning about 7 elements of radically simple OS migration.
Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Consolidation: The Foundation for IT Business Transformation
In this whitepaper learn how effective consolidation of IT and business resources can enable multiple, meaningful business benefits.
Solving today's distributed Big Data backup challenges
Enable IT efficiency and allow a firm to access and reuse corporate information for competitive advantage, ultimately changing business outcomes.
A new approach to endpoint data protection
What is the best way to ensure comprehensive visibility, management, and control of information on both company-owned and employee-owned devices?