Feeds

Kelihos botnet BACK FROM THE DEAD

Bloodied spam-spewing zombie staggers in

Internet Security Threat Report 2014

The spam-spewing Kelihos botnet has returned from the dead.

Microsoft collaborated with Kaspersky Lab to run a successful takedown operation last September. The takedown decapitated the botnet by shutting down command-and-control server nodes, directing the bots on infected computers to contact a server under the control of security researchers, rather than one controlled by the attackers.

In the case of the Kelihos peer-to-peer botnet, Kaspersky researchers pushed out a new peer address, which the existing infected PCs began polling for new instructions.

This "sink-holing" action meant that compromised machines in the network were no longer receiving instruction and spam templates every time they "phoned home" to command nodes. Even so the machines were still infected and left with an open back door that might be exploited by cybercrooks. A deliberate decision was taken NOT to patch infected machines, a problematic process that's illegal in some countries. Instead it was left to users to fix the security on their compromised machines.

Almost inevitably many didn't bother.

Over time miscreants have used the botnet's complex back-channel network of proxy servers to regain control of compromised machines. These machines have been infected with a new variant of Kelihos that uses modified encryption schemes and algorithms to mask communication. Two different keys are being used, suggesting that more than one gang is controlling the botnet, according to a new analysis Maria Garnaeva, a security researcher with Kaspersky Lab.

""As you can see, two different RSA keys are used within a tree which makes us think that probably two different groups are in possession of each key and are currently controlling the botnet," Garnaeva explains.

"Our investigation revealed that the new version appeared as early as September 28, right after Microsoft and Kaspersky Lab announced the neutralisation of the original Hlux/Kelihost botnet," she added.

At its peak, Kelihos spewed out as many as 4 billion junk mail messages, spam-vertised unlicensed pharmaceuticals, stock scams and other tat from around 45,000 malware-infected zombie PCs. Current spam levels are nowhere near this bad, even though they still pose a problem.

The reappearance of spam from the botnet underlines that sinkholing alone is not effective in killing off botnets. Security experts knew this even at the start. Garnaeva suggests that only patching infected machines or taking botnet controllers out of circulation would be truly effective.

Last week Microsoft filed an amended lawsuit alleging that a Russian national was involved in both creating the original Kelihos malware and running the botnet network. Andrey Sabelnikov of St Petersburg, a software developer and former employee at two Russian security firms, denies any wrongdoing. ®

Remote control for virtualized desktops

More from The Register

next story
You really need to do some tech support for Aunty Agnes
Free anti-virus software, expires, stops updating and p0wns the world
Privacy bods offer GOV SPY VICTIMS a FREE SPYWARE SNIFFER
Looks for gov malware that evades most antivirus
Patch NOW! Microsoft slings emergency bug fix at Windows admins
Vulnerability promotes lusers to domain overlords ... oops
HACKERS can DELETE SURVEILLANCE DVRS remotely – report
Hikvision devices wide open to hacking, claim securobods
Astro-boffins start opening universe simulation data
Got a supercomputer? Want to simulate a universe? Here you go
State Dept shuts off unclassified email after hack. Classified mail? That's CLASSIFIED
Classified systems 'not affected' - but, is this reconnaissance?
prev story

Whitepapers

Why and how to choose the right cloud vendor
The benefits of cloud-based storage in your processes. Eliminate onsite, disk-based backup and archiving in favor of cloud-based data protection.
A strategic approach to identity relationship management
ForgeRock commissioned Forrester to evaluate companies’ IAM practices and requirements when it comes to customer-facing scenarios versus employee-facing ones.
How to determine if cloud backup is right for your servers
Two key factors, technical feasibility and TCO economics, that backup and IT operations managers should consider when assessing cloud backup.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.
Protecting against web application threats using SSL
SSL encryption can protect server‐to‐server communications, client devices, cloud resources, and other endpoints in order to help prevent the risk of data loss and losing customer trust.