Feeds

Bot herders hide master control channel in Google cloud

Google AppEngine co-opted

Security for virtualized datacentres

Cyber criminals' love affair with cloud computing just got steamier with the discovery that Google's AppEngine was tapped to act as the master control channel that feeds commands to large networks of infected computers.

The custom application was used to relay download commands to PCs that had already been infected and made part of a botnet, said Jose Nazario, the manager of security research at Arbor Networks. Google shut down the rogue app shortly after being notified of it.

The discovery is the latest to highlight bot herders' growing embrace of the cloud, in which applications and data are hosted on large, publicly available servers instead of stand-alone machines. Last Friday, researchers from Symantec found a Facebook account pumping commands to zombie drones. And in August, Nazario found several Twitter accounts that were doing much the same thing.

Also on Monday, researchers from anti-virus provider Trend Micro reported that the massive Koobface botnet was abusing Google Reader to spam malicious links to Facebook and other social networking sites.

Black hat hackers are being drawn to the cloud by many of the same benefits attracting everyone else, namely cheap and scalable processing exactly when it's needed. But they also like the anonymity and obscurity that come from using many such services.

"It's the low cost, it's the high availability," Nazario told The Reg. "And the security measures in place for most of these things are retroactive, meaning it takes somebody to identify and investigate and take them down. You're really free to swim in the huge flood of user generated content, as long as you don't stick out too much."

Google's AppEngine provides a framework for running custom applications that can handle requests from millions of computers. The app spotted by Nazario appeared to recycle code from Grey Pigeon and Hupigon toolkits available in the attacker underground.

Infected PCs that checked in with the malicious app were instructed to download the PCClient backdoor from a third-party server. Because the channel software was hosted on the heavily fortified Google, he was unable to get his hands on the source code itself or to observe other commands it may have carried out.

And that may be another reason why black hats are flocking to the cloud.

"Going to a company as big as Google and saying 'Can we get an image of that server,' that's a pretty high barrier," he said. ®

Secure remote control for conventional and virtual desktops

More from The Register

next story
NASTY SSL 3.0 vuln to be revealed soon – sources (Update: It's POODLE)
So nasty no one's even whispering until patch is out
Russian hackers exploit 'Sandworm' bug 'to spy on NATO, EU PCs'
Fix imminent from Microsoft for Vista, Server 2008, other stuff
Microsoft pulls another dodgy patch
Redmond makes a hash of hashing add-on
'LulzSec leader Aush0k' found to be naughty boy not worthy of jail
15 months home detention leaves egg on feds' faces as they grab for more power
Forget passwords, let's use SELFIES, says Obama's cyber tsar
Michael Daniel wants to kill passwords dead
FBI boss: We don't want a backdoor, we want the front door to phones
Claims it's what the Founding Fathers would have wanted – catching killers and pedos
prev story

Whitepapers

Forging a new future with identity relationship management
Learn about ForgeRock's next generation IRM platform and how it is designed to empower CEOS's and enterprises to engage with consumers.
Why cloud backup?
Combining the latest advancements in disk-based backup with secure, integrated, cloud technologies offer organizations fast and assured recovery of their critical enterprise data.
Win a year’s supply of chocolate
There is no techie angle to this competition so we're not going to pretend there is, but everyone loves chocolate so who cares.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
Intelligent flash storage arrays
Tegile Intelligent Storage Arrays with IntelliFlash helps IT boost storage utilization and effciency while delivering unmatched storage savings and performance.