Feeds

Microsoft seizes Chinese dot-org to kill Nitol bot army

Takedown after infected new computers sold to victims

Build a business case: developing custom apps

Microsoft has disrupted the emerging Nitol botnet - and more than 500 additional strains of malware - by taking control of a rogue dot-org website. The takedown is the latest in Microsoft's war against armies of hacker-controlled PCs.

The Windows 8 giant's Operation b70 team discovered crooks were selling computers loaded with counterfeit software and malware - including a software nastie that takes control of each machine to carry out orders from the Nitol central command server.

Operation b70 uncovered the industrial-scale scam during an investigation into insecure supply chains [PDF]. Microsoft blames corrupt but unnamed resellers in China.

Computers in the Nitol botnet would communicate with a command server whose DNS was provided by Chinese-run 3322.org, which has been linked to malicious activity since 2008. Microsoft investigators also discovered that other servers using 3322.org, which offers its services for free, harboured more than 500 different strains of malware across more than 70,000 sub-domains. These nasties included key-stroke loggers and banking Trojans.

Microsoft obtained a US court order to seize control of 3322.org - a site Google's Safe Browsing system warned was home to "malicious software including 1609 exploits, 481 trojans and 6 scripting exploits". The order instructs the US-based Public Interest Registry, which operates the DNS for all .org domains, to redirect internet traffic for 3322.org to the Redmond giant's servers.

Sub-domains associated with the malware have been blocked while legitimate domains have been allowed to stay online, as a statement from Microsoft on the takedown explains:

On Sept 10, the court granted Microsoft’s request for an ex parte temporary restraining order against Peng Yong, his company and other John Does. The order allows Microsoft to host the 3322.org domain, which hosted the Nitol botnet, through Microsoft’s newly created domain name system (DNS). This system enables Microsoft to block operation of the Nitol botnet and nearly 70,000 other malicious subdomains hosted on the 3322.org domain, while allowing all other traffic for the legitimate subdomains to operate without disruption.

DNS security firm Nominum helped in the legal case, filed in the US District Court for the Eastern District of Virginia, as well as assisting Microsoft in filtering the 3322.org domain traffic.

The operation was part of the ongoing Project MARS (Microsoft Active Response for Security), which previously led to the successful takedown of the Waledac, Rustock and Kelihos botnets. ®

Endpoint data privacy in the cloud is easier than you think

More from The Register

next story
14 antivirus apps found to have security problems
Vendors just don't care, says researcher, after finding basic boo-boos in security software
Microsoft's Euro cloud darkens: US FEDS can dig into foreign servers
They're not emails, they're business records, says court
'Things' on the Internet-of-things have 25 vulnerabilities apiece
Leaking sprinklers, overheated thermostats and picked locks all online
iWallet: No BONKING PLEASE, we're Apple
BLE-ding iPhones, not NFC bonkers, will drive trend - marketeers
Multipath TCP speeds up the internet so much that security breaks
Black Hat research says proposed protocol will bork network probes, flummox firewalls
Only '3% of web servers in top corps' fully fixed after Heartbleed snafu
Just slapping a patched OpenSSL on a machine ain't going to cut it, we're told
Plug and PREY: Hackers reprogram USB drives to silently infect PCs
BadUSB instructs gadget chips to inject key-presses, redirect net traffic and more
How long is too long to wait for a security fix?
Synology finally patches OpenSSL bugs in Trevor's NAS
prev story

Whitepapers

7 Elements of Radically Simple OS Migration
Avoid the typical headaches of OS migration during your next project by learning about 7 elements of radically simple OS migration.
Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Consolidation: The Foundation for IT Business Transformation
In this whitepaper learn how effective consolidation of IT and business resources can enable multiple, meaningful business benefits.
Solving today's distributed Big Data backup challenges
Enable IT efficiency and allow a firm to access and reuse corporate information for competitive advantage, ultimately changing business outcomes.
A new approach to endpoint data protection
What is the best way to ensure comprehensive visibility, management, and control of information on both company-owned and employee-owned devices?