Feeds

Conficker's 6m strong botnet confounds security probes

Cross-industry group baffled by super crypto shield of infamous botnet

Top 5 reasons to deploy VMware with Tegile

Analysis The unknown crooks behind the infamous Conficker worm may be quietly selling off parts of the huge botnet established by the malware, but virus fighters have no way of knowing because the cryptographic defences of its command and control network have proved uncrackable.

Conficker (aka Downadup) first appeared in November 2008, originally using a recently patched vulnerability in Windows Server Service to infect insecure systems. Later its ability to spread through network shares and to hop over onto PCs from infected USB sticks became its primary spreading mechanism.

Early victims included the Houses of Parliament and the Ministry of Defence in the UK. Conficker's aggressive scanning routines swamped legitimate traffic on compromised networks, creating all sorts of problems in the process.

Interest in the worm peaked around 1 April 2009 when its algorithm changed so that it "phoned home" to a far larger number of pre-programmed domains, sparking fears that new instructions would be applied activating a huge network of zombie computers to send spam or launch denial of service attacks.

In the event, 1 April came and went without anything of note happening, leading some to wrongly label the malware as a damp squib. Although the Conficker botnet remains largely dormant an estimated six million Windows PCs remain infected with the threat.

Wide open backdoor

These Windows boxes remain wide open to further attack not least because Conficker is programmed to turn off Windows update and anti-virus software on compromised machines, according to Rodney Joffe, a director of the Conficker Working Group. The still-active working group is made up of a team of security, domain name, law enforcement and government representatives brought together to fight the Conficker threat.

Early tasks of the group included blocking the registrations of domains that machines infected with early variants of Conficker were programmed to contact for further instructions. Subcommittees of the group focused on issues such as reverse engineering the malware's code, dealing with the sinkhole domains that infected bots were programmed to contact, and community outreach work.

Rodney Joffe, a senior technologist at net infrastructure firm Neustar, dismisses the theory that Conficker was a failed experiment or "research project" by cybercrooks, perhaps one that was too successful to be useful. In particular he's dismissive of the idea that the botnet remains dormant because activating it would provoke unwelcome law enforcement attention.

"Conficker was not a bust. It's still causing enormous problems and damage as a byproduct of infection," Joffe told El Reg.

Around six million systems remain infected with either the A or B variants of Conficker. The C variant, which used a P2P method of distribution, affects a lower number of around 120,000, as illustrated by an infection tracker maintained by the Conficker Working Group here.

Windows PCs infected with the C variant of Conficker were programmed to download Spyware Protect 2009 (a scareware package) and the Waledac botnet client, a strain of malware associated with spamming.

"These are different gangs and suggest the malware authors behind Conficker have a trading relationship with bad guys," Joffe explained.

Internet Security Threat Report 2014

More from The Register

next story
'Kim Kardashian snaps naked selfies with a BLACKBERRY'. *Twitterati gasps*
More alleged private, nude celeb pics appear online
Home Depot ignored staff warnings of security fail laundry list
'Just use cash', former security staffer warns friends
Hackers pop Brazil newspaper to root home routers
Step One: try default passwords. Step Two: Repeat Step One until success
UK.gov lobs another fistful of change at SME infosec nightmares
Senior Lib Dem in 'trying to be relevant' shocker. It's only taxpayers' money, after all
Who.is does the Harlem Shake
Blame it on LOLing XSS terroristas
Snowden, Dotcom, throw bombs into NZ election campaign
Claim of tapped undersea cable refuted by Kiwi PM as Kim claims extradition plot
Freenode IRC users told to change passwords after securo-breach
Miscreants probably got in, you guys know the drill by now
THREE QUARTERS of Android mobes open to web page spy bug
Metasploit module gobbles KitKat SOP slop
BitTorrent's peer-to-peer chat app Bleep goes live as public alpha
A good day for privacy as invisble.im also reveals its approach to untraceable chats
prev story

Whitepapers

Secure remote control for conventional and virtual desktops
Balancing user privacy and privileged access, in accordance with compliance frameworks and legislation. Evaluating any potential remote control choice.
Intelligent flash storage arrays
Tegile Intelligent Storage Arrays with IntelliFlash helps IT boost storage utilization and effciency while delivering unmatched storage savings and performance.
WIN a very cool portable ZX Spectrum
Win a one-off portable Spectrum built by legendary hardware hacker Ben Heck
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
Beginner's guide to SSL certificates
De-mystify the technology involved and give you the information you need to make the best decision when considering your online security options.