Koobface server pops up in China after HK takedown
Whack-a-mole
Customer Success Testimonial: Recovery is Everything
Security experts in Hong Kong last week succeeded in taking down a key component of the Koobface botnet, only to witness the system popping up in China.
The Koobface FTP grabber component uploaded stolen FTP user names and passwords to the remote server, which was under the control of cybercrooks. These stolen login credentials gave a pass into corporate networks and valuable data before the server was taken down last week, largely thanks to the efforts of the Hong Kong Computer Emergency Response Team Coordination Centre (HKCERT).
In response, the Koobface gang moved their server to a hosting firm in China. Last month the command and control servers associated with Koobface underwent a complete refresh.
Koobface spread via messages on social networking sites like Facebook and Twitter. Cybercrooks behind the sophisticated malware make their money by distributing scareware packages onto compromised machines, and by other cyberscams, including information harvesting. The worm gets less press than the malware associated with the Google China attacks or the high-profile Conficker worm, though experts consider it both more sophisticated and a bigger security threat.
A blog post by Trend Micro with more details on the FTP grabber and the Hong Kong takedown operation can be found here. ®
COMMENTS
Did this post come through a time machine?
Did this post get written in the 80s and only just published?
I'm looking forward to exciting news about the future of ARCHIE and gopher.
(Although I know some important financial systems that are still using FTP)
Your spell check still doesn't accept "botnet", then...
So there's a meassive Chinese-built criminal bonnet, that's fine.
Also: so they can break into your FTP server, am I missing a point here? Did FTP suddenly get secure and important and I didn't notice?

IT infrastructure monitoring strategies
What you need to know about cloud backup
Agentless Backup is Not a Myth
Top 10 SIEM implementer’s checklist
Customer Success Testimonial: Recovery is Everything