Feeds

Microsoft seizes Chinese dot-org to kill Nitol bot army

Takedown after infected new computers sold to victims

Top 5 reasons to deploy VMware with Tegile

Microsoft has disrupted the emerging Nitol botnet - and more than 500 additional strains of malware - by taking control of a rogue dot-org website. The takedown is the latest in Microsoft's war against armies of hacker-controlled PCs.

The Windows 8 giant's Operation b70 team discovered crooks were selling computers loaded with counterfeit software and malware - including a software nastie that takes control of each machine to carry out orders from the Nitol central command server.

Operation b70 uncovered the industrial-scale scam during an investigation into insecure supply chains [PDF]. Microsoft blames corrupt but unnamed resellers in China.

Computers in the Nitol botnet would communicate with a command server whose DNS was provided by Chinese-run 3322.org, which has been linked to malicious activity since 2008. Microsoft investigators also discovered that other servers using 3322.org, which offers its services for free, harboured more than 500 different strains of malware across more than 70,000 sub-domains. These nasties included key-stroke loggers and banking Trojans.

Microsoft obtained a US court order to seize control of 3322.org - a site Google's Safe Browsing system warned was home to "malicious software including 1609 exploits, 481 trojans and 6 scripting exploits". The order instructs the US-based Public Interest Registry, which operates the DNS for all .org domains, to redirect internet traffic for 3322.org to the Redmond giant's servers.

Sub-domains associated with the malware have been blocked while legitimate domains have been allowed to stay online, as a statement from Microsoft on the takedown explains:

On Sept 10, the court granted Microsoft’s request for an ex parte temporary restraining order against Peng Yong, his company and other John Does. The order allows Microsoft to host the 3322.org domain, which hosted the Nitol botnet, through Microsoft’s newly created domain name system (DNS). This system enables Microsoft to block operation of the Nitol botnet and nearly 70,000 other malicious subdomains hosted on the 3322.org domain, while allowing all other traffic for the legitimate subdomains to operate without disruption.

DNS security firm Nominum helped in the legal case, filed in the US District Court for the Eastern District of Virginia, as well as assisting Microsoft in filtering the 3322.org domain traffic.

The operation was part of the ongoing Project MARS (Microsoft Active Response for Security), which previously led to the successful takedown of the Waledac, Rustock and Kelihos botnets. ®

Beginner's guide to SSL certificates

More from The Register

next story
Regin: The super-spyware the security industry has been silent about
NSA fingered as likely source of complex malware family
Why did it take antivirus giants YEARS to drill into super-scary Regin? Symantec responds...
FYI this isn't just going to target Windows, Linux and OS X fans
Privacy bods offer GOV SPY VICTIMS a FREE SPYWARE SNIFFER
Looks for gov malware that evades most antivirus
Home Office: Fancy flogging us some SECRET SPY GEAR?
If you do, tell NOBODY what it's for or how it works
HACKERS can DELETE SURVEILLANCE DVRS remotely – report
Hikvision devices wide open to hacking, claim securobods
'Regin': The 'New Stuxnet' spook-grade SOFTWARE WEAPON described
'A degree of technical competence rarely seen'
Syrian Electronic Army in news site 'hack' POP-UP MAYHEM
Gigya redirect exploit blamed for pop-rageous ploy
Astro-boffins start opening universe simulation data
Got a supercomputer? Want to simulate a universe? Here you go
prev story

Whitepapers

Free virtual appliance for wire data analytics
The ExtraHop Discovery Edition is a free virtual appliance will help you to discover the performance of your applications across the network, web, VDI, database, and storage tiers.
Getting started with customer-focused identity management
Learn why identity is a fundamental requirement to digital growth, and how without it there is no way to identify and engage customers in a meaningful way.
The total economic impact of Druva inSync
Examining the ROI enterprises may realize by implementing inSync, as they look to improve backup and recovery of endpoint data in a cost-effective manner.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
Website security in corporate America
Find out how you rank among other IT managers testing your website's vulnerabilities.