Showing posts with label underground. Show all posts
Showing posts with label underground. Show all posts

Friday, March 12, 2010

It's botnet shutdown season

Lately it seems to be botnet-takedown season. For one, Microsoft went the legal route and ask a judge permission to reroute domain name servers related to the Waledac botnet in order to shut it down permanently. Actually, the process is more complicated than that but the domain server procedure was the only non-technical issue that needed external approval.

Then, Panda announced that after a few months of investigation, they provided enough data to the police so they could apprehend three criminals behind a huge botnet managed from Spain. Second takedown of the month and a pretty big one at about 13 million bots involved.

Lately, a few industry researchers followed quite a few Zeus Command and Control servers to a single provider and managed to cut their internet connection, therefore stopping those botnets from working at all. After a few reconnections and counter-attacks by the provider, apparently it's shutting down for good. Third take-down of the month!

These three stories have a single enemy in common: botnets. They have quickly become the biggest enemy of the computer user, but that's not new. What's more recent is the fact that they have become so popular among criminals as a quick way of making money that the criminal underground is steaming with new tools to create and maintain botnets for profit. This "new" software category has become a market that criminals are exploiting to trade with other criminals. Of course there's also fraud in there but who are you going to complain if a fellow criminal scammed you? There are figures like the garant who can verify if the seller is legit. It's some sort of escrow system where some trusted people check the product before the transaction goes through. It's like a real market where malware weapons are being exchanged for money.

Botnet-DIY Kits like Zeus are being sold by thousands of dollars. Piracy is so rampant that the Zeus author has put anti-piracy measures in place. Now, there are some other groups that regularly crack those protections and sell pirated versions of the kit for a lower price. Honor among pirates is a thing of the past and the poor user is the one who will suffer.

The only hope we have is to keep hammering C&C centers, disconnecting them from the internet until they all get the message that letting criminals establish botnets is as bad as being accomplices of the criminal act. This is the only way of getting rid of "bulletproof" hosting providers that ignore abuse complaints and are uncooperative with the police. I hope we keep taking botnets down... it's been a good month.

Thursday, February 25, 2010

Kneber say never

The Zeus malware has been featured in the media lately and I thought I'd talk about it here. The news rage last week started with a security company announcing that they had found a big botnet out there with about 74,000 people infected. These guys dubbed the botnet "kneber" because the domain names involved in this case mentioned a Hillary Kneber. From there, all marketing departments in all security companies went crazy asking "Do we know anything about this new Kneber botnet??".

So digging a bit deeper into the mysterious new botnet that appeared from thin air, it turns out that this is nothing more than our old friend Zeus. This led to a whole new wave of people discussing whether this was important or not and how.

In any case, Zeus is a do-it-yourself malware kit. You can purchase the software, configure your bots and spread them around so you can grow your own botnet with information-stealing capabilities perfectly targeted to your audience (ehm... victims). Obviously the criminals behind the Kneber botnet followed those instructions and managed to get 74,000 people infected. Actually, there's lots of other malware toolkits for sale out there from shady companies that often include tech support and antivirus detection protection among other services.

So this is the world we live in today, one where anybody can make profit in the internet by stealing other people's money. It's as easy as buying a malware kit and building your own botnet. At any moment there are hundreds of different "Zeus" botnets commanded by different criminal groups. Some of them are much bigger than 74,000 PCs and there's really no need to report each one of them as news because they are not. Nevertheless, if this served to raise awareness about Zeus and about how cybercriminals carry out their internet business, maybe something good came out of it.

Saturday, February 13, 2010

You got a Valentine card! click here to open...

Tomorrow will be Valentine's day, the day of love and romance. In the last 10 years it has also been well known for being a favorite theme used by malware writers to lure unsuspecting users to get infected. "Your loved one sent you an e-card. Click here to retrieve it" is already a classic and it doesn't look like it will leave us anytime soon. There is a deeper problem other than people looking for love through the internet though: users are the natural victims of social engineering attacks.

My automated script to parse email messages won't care about love letters sent to him, paypal trying to freeze his account or the big Nigerian fortune recently available to him. Humans, on the other hand, are prone to these and other tricks that exploit naiveness, greed, generosity or any other very human passions that move us. You'd think awareness campaigns have lessened this to some extent but criminals still use the same tricks over and over with a high degree of success.

Just this week I read the story of an ex-scammer from a Nigerian gang telling some of their techniques and the kind of money they're making with the age-old "Give us some money to get a very big payout". People are still falling for the same tricks!!

The IT security industry can make super-sophisticated software that stop zero-day exploits, detect viruses trying to penetrate the computer's defenses, stop bots from making phone-home connections and any other technical attack but what we'll never be able to do is stop the user from clicking on that malicious link because he wants to see the porn video they told him was going to be displayed.

If you think about it, we're trying to save the user from... yes, the user. The problem of creating tight security measures to keep a user safe is that he will try to bypass them because that valentine ecard is more important to him than firewalls, antivirus or any other fancy three-letter-acronym software thrown at them. As somebody in an IT security list I'm subscribed to recently quoted "The problem of making something foolproof is that fools are very ingenious". I suspect we'll keep getting fake valentines that lead to malware for years to come.

Thursday, November 5, 2009

The invisible enemy is really close

Working in the security industry, one sees very often the impact malware has on the affected users. There have been many articles dedicated to the shift from malware writing as a hobby to malware writing as a business but this is a very important step to differentiate because it affects the kind of malware we see today.

If we think of our personal computers as our virtual houses, some time ago we wanted security against our neighborhood bully. Dangerous? Sure. Destructive? You bet.

Now, our enemy is a white collar thief. He'll get into our houses and tap our phones, he'll follow us to our bank and write down our PIN codes and he'll look at the places we shop and will let other people know so they can flood our doorsteps with ads. More importantly, he will put cameras in our houses to check new changes in our lifestyle and will sell access to those cameras to other criminals. Does this sound like a complete change of the malware picture? I bet it does.

There are two consequences to this shift. First, this has created a malware underground society that buys and sells malware kits, server backends, stolen information and all sorts of bad things related to their criminal operations. Second, the malware being used in these attacks is advanced. Not advanced in ideas but in operations.

Let me explain myself: before, there were malware brains and script kiddies. The brains created advanced malware just for kicks and script kiddies propagated it around for pure fun ("David infected this PC... Yoohoo!"). These guys haven't gone away today, they're still there, but the criminals today are taking the brains' ideas and polishing them professionally with state-of-the-art technology paid for by their own criminal enterprises.

So now we have a technologically-advanced enemy trying to quietly get into our lives to steal our money and sell our private information. Thus the invisible enemy.

It's an interesting time to be in the security industry. Now tell me that catching these criminals is less important than catching file-sharing users... some people need to step back into reality.

Welcome to my blog, I'll try to post my ramblings weekly... enjoy!