Holy Bouncing Autonomous Intelligent Botnets Batman

newsguy 3 Tallied Votes 1K Views Share

Thought that 2009 was the year that botnets died, well think again Batman, it was actually the year they bounced back. Compromised computers were responsible for distributing 83.4% of the 107 billion spam messages sent around the world, every single day, during 2009 according to a new Symantec report.

Indeed, the Symantec MessageLabs Intelligence 2009 report suggests that the shutdown of botnet hosting ISPs such as McColo towards the end of 2008 and Real Host in August this year didn't destroy the botnet threat but rather simply made those behind them re-evaluate and enhance command and control backup strategies so as to be able to recover from damage in hours rather than weeks.

Symantec predicts that botnets will become autonomous intelligent, with each node containing an inbuilt self-sufficient coding in order to coordinate and extend its own survival, during the course of 2010.

Cutwail, Mega-D, Rustock and handful of other botnets already have control of upwards of five million compromised computers. Cutwail alone was responsible for issuing 29% of all spam, that's 8,500 billion individual spam messages, between April and November 2009.

Cutwail also distributed the Bredolab Trojan dropper, disguised in the form of a .ZIP file attachment, designed to give the sender complete control of the target computer which then could be used to deploy other botnet malware, adware or spyware onto the victim’s computer. It is estimated that during the month of October, some 3.6 billion Bredolab malware emails were in circulation.

"2009 was the year that the threat landscape sharpened its skills, rather than just relying on large spam runs and malware attacks. We intercepted more variants with increased sophistication, efficiency as well as improvements in technology" said Paul Wood, MessageLabs Intelligence Senior Analyst, Symantec. "We stopped more than 21 million different types of spam campaigns in 2009, more than twice the amount seen in 2008, and saw a 23 percent increase in malware variants year-on-year. The significant increases suggest that, thanks to the increased availability of specialized criminal toolkits, it was easier to create, distribute and use spam and malware than ever before".

Evenbit commented: Well written and certainly an important subject. +5

Dani AI

Generated

As observed, the post-2008 takedowns did not end the botnet problem — operators adapted and made command-and-control more resilient. nailed the tone with the headline: the threat changed shape, not disappeared.

Operators moved toward resilient C2 patterns (fast-flux DNS, domain-generation algorithms, peer-to-peer C2, and covert HTTP/S channels) and adopted modular droppers so payloads could be swapped quickly. Detection therefore needs to emphasize behavior over single signatures: look for hosts with many outbound connections, rapid DNS churn, unexpected listeners or scheduled tasks, and encrypted flows on nonstandard ports.

Practical checklist for admins and incident responders:

  • Keep systems patched and endpoint protection (and EDR) updated.
  • Host checks: collect netstat -ano (Windows) or lsof -i (Linux) and review autoruns/scheduled tasks for unknown entries.
  • Network controls: apply egress filtering, block direct SMTP from endpoints, and alert on DNS patterns that show many short-lived records or high NXDOMAIN rates.
  • Response steps: isolate suspected machines, capture volatile data (memory) and disk images before wiping, run offline multi-engine scans, and restore from verified backups.
  • Prevention: enforce least privilege, segment networks, and maintain a tested incident-response playbook.

Layered defenses and visibility into both host behavior and DNS/network telemetry are the reliable counter to the kind of resilient botnets described in this thread.

AnonymousHoward 0 Newbie Poster

> Holy Bouncing Autonomous Intelligent Botnets Batman

This takes the prize for Best Security Headline of 2009, IMO :)
Good Job!

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.