Feeds

Botnets claim 7-fold increase in victims

Are we winning the cybercrime war yet?

SANS - Survey on application security programs

Botnets used in banking credential theft and other criminal enterprises made huge gains in 2010, claiming more than seven times as many victims as the previous year, according to a report issued by a security firm that follows the large networks of infected machines.

The dramatic increase was fueled by improvements in DIY botnet construction kits, which allowed internet-based fraudsters to construct new networks that quickly gained traction, the report from Damballa said. As a result, six of the 10 biggest botnets of 2010 weren't in existence the previous year. New infection technology that targets a hard drive's targets a hard drive's master boot record and changes the machine's boot options also played role.

“Throughout the year, the Top 10 largest botnets increased their total share of all bot infected victims,” the report (PDF) states. “At the beginning of the year approximately 22% of observed botnet victims were infected with malware attributed to just ten botnet operators. By the end of the year, this proportion had grown to nearly 57% - more than doubling their share of global botnet victims.”

In the run-up to Christmas week, the total number of unique botnet victims was 654 percent higher than the same population was at the beginning of the year. The average incremental growth throughout the year was 8 percent.

In addition to the release of refurbished Zeus crimeware kit, other DIY kits available in underground forums are marketed under names such as Phoenix, Darkness, BlackEnergy, and Eleonore. The packages allow criminals to quickly build botnets without having to write the code from scratch.

Damballa's report contrasted with the findings of anther Atlanta-based security firm, Secure Works, which was recently purchased by Dell. Secure Works' Spambot Evolution 2011 said botnets that specialize in sending spam largely marked time last year, with fewer new families emerging and only incremental changes in existing ones.

Like the botnets observed by Damballa, many of the spambots described by Secure Works researcher Joe Stewart made vast improvements in concealing the infections. For instance, Rustock, the biggest spam network with an estimated 250,000 zombies, waits as long as five days after taking hold of a system before it begins sending junk messages. Rustock control servers also run a TOR exit node, “likely in an attempt to avoid disconnection by network administrations who might think the abuse is originating elsewhere,” Stewart writes. ®

High performance access to file storage

More from The Register

next story
Obama allows NSA to exploit 0-days: report
If the spooks say they need it, they get it
Putin tells Snowden: Russia conducts no US-style mass surveillance
Gov't is too broke for that, Russian prez says
Snowden-inspired crypto-email service Lavaboom launches
German service pays tribute to Lavabit
Mounties always get their man: Heartbleed 'hacker', 19, CUFFED
Canadian teen accused of raiding tax computers using OpenSSL bug
Heartbleed exploit, inoculation, both released
File under 'this is going to hurt you more than it hurts me'
Arts and crafts store Michaels says 3 million credit cards exposed in breach
Meanwhile, Target investigators prepare for long process in nabbing hackers
Canadian taxman says hundreds pierced by Heartbleed SSL skewer
900 social insurance numbers nicked, says revenue watchman
prev story

Whitepapers

SANS - Survey on application security programs
In this whitepaper learn about the state of application security programs and practices of 488 surveyed respondents, and discover how mature and effective these programs are.
Combat fraud and increase customer satisfaction
Based on their experience using HP ArcSight Enterprise Security Manager for IT security operations, Finansbank moved to HP ArcSight ESM for fraud management.
The benefits of software based PBX
Why you should break free from your proprietary PBX and how to leverage your existing server hardware.
Top three mobile application threats
Learn about three of the top mobile application security threats facing businesses today and recommendations on how to mitigate the risk.
3 Big data security analytics techniques
Applying these Big Data security analytics techniques can help you make your business safer by detecting attacks early, before significant damage is done.