Slashdot Mirror


The 'Malware Economy' Evolves

superglaze writes "ZDNet UK has a feature on how the malware economy is turning into a recognizable traditional IT economy. Leasing botnets? Malware support? Welcome to the new age of computing. As the piece suggests, it's all gone Darwinian. 'One indication of the maturity of the black economy, according to Telafici, was the recent case of a hacker who wrote a packer [software used to bypass antivirus protection], "threw in the towel recently as it wasn't profitable enough -- there's too much competition. They opened the source code and walked away."'"

7 of 100 comments (clear)

  1. Only high profit crime by Anonymous+Monkey · · Score: 3, Interesting

    This is only logical. A criminal will work for the quick buck. BnE is great when lots of people are leaving their windows open and you are the only burglar, but once every one is on the BnE bandwagonit's time to switch to mugging or extortion.

    --
    We are the Borg...
  2. Re:Malware and ex-emailer by Opportunist · · Score: 4, Interesting

    And this won't change as long as you're not responsible for your computer's actions.

    We have a license for everything. You need a license to drive, to prove you're able to steer a car without causing a problem. We (at least here) need a license for a gun, so you prove you're not just some maniac who wants to kill his wife's sisters. But even for "non-lethal" things like some jobs you need to prove you're able to handle what's put into your hands sufficiently professionally that you don't cause harm to anyone else.

    Now, I wouldn't really want a "driving license" for computers, but I'd very much enjoy seeing people taking some more responsibility for their computers and what they do to others on the internet. As we see now, this has become an economic problem. We waste a lot of bandwidth and work hours fighting spam, we have the sword of a DDoS looming over our heads due to botnets ready to strike, and it all boils down to people using rooted boxes and not even knowing it.

    Before you start crying about your freedom to use the net, be aware that sooner or later our legislators WILL react. They have to, the pressure from the industry is already tangible. And in our current environment, the result is very likely not one where people get better educated and more responsibility, instead we'll probably see laws regulating what kinds of machines you may attach to the net (and the accompanying locking of "insecure" machines from participation), and we know the current definition of "secure". It will pretty much lead to machines so heavily DRMed that Vista looks like open source compared to it.

    So either we start pushing towards more personal responsibility or we'll have something dumped on us that is the maybe least favorable alternative. Because the industry WILL start lobbying for protection from those rooted machines. And they don't care if you can use your computer for anything but playing prepared content. Actually, some would definitly like that.

    --
    We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
  3. The real money in spam? Selling to spammers by uptownguy · · Score: 4, Interesting

    This has to do with SPAM and not botnets...

    It's been said before, probably better than I can: The "mark" in the spam economy is NOT the person receiving the email. The "mark" is the person foolish enough to buy the Spam-in-a-box kit thinking they will be able to get a single person to buy their w0tches or v1agra. The money in spam is made not from the person foolish enough to buy the w0tches. The money is made in selling the service to spam millions of people.

    --


    I would have to say that explosives are the most abused technology in all of history.
  4. Re:Malware and ex-emailer by deviated_prevert · · Score: 3, Interesting

    I concur with what you are saying but what about the malicious propaganda side of things http://www.google.ca/search?hl=en&sa=X&oi=spell&resnum=1&ct=result&cd=1&q=linux+botnet&spell=1 It seems to me that there is also lots of miss information out there, mostly in the form of blogs from so-called security experts, trying desperately to defame open source software!

    --
    This message was not sent from an iPhone because Peter Sellers really was a deviated prevert without a dime for the call
  5. Utility Computing by Crispin+Cowan · · Score: 3, Interesting

    No kidding :-) I said in a public forum about 4 years ago that botnets are the first and only successful example of commercial utility computing, where a vendor tries to rent out time on large compute clusters.

    This works much better for botnet vendors than for Amazon EC2 or HP Utility Data Center, because the really valuable resource the botnets are renting is a routable IP address that hasn't been shut down yet. Computers are nearly free, but IP addresses that work are not.

  6. Re:Malware and ex-emailer by houstonbofh · · Score: 4, Interesting

    I still don't understand why ISPs are not doing more about this. SPAM uses a large amount of the precious and limited bandwidth, but they filter p2p? I get 10 to 20 spam an hour. As I have more than one e-mail client (one on laptop, one at home, one at work...) each one gets passed off the SIP mail server 3 times for me. It also passes in to the ISP mail server once, so 20-30 messages times 4, times 24 hours times each user ads up to how much bandwidth? And this is why I can't seed my Ubuntu images?

  7. Here's the actual paper. by Animats · · Score: 4, Interesting

    Here's the actual paper from which came most of the material in the article: "The Commercial Malware Industry", from the University of Auckland. More technical details.

    New threats of interest:

    • Some viruses now use error correcting codes so that attempts to patch them out will be repaired.
    • Windows Genuine Advantage blackmail trojan. Pops up message requesting payment of money or will disable your computer. (p.39)
    • Location-aware malware - used to find location for credit card number, so phony transactions can be generated from a physically nearby node. (p. 41)
    • "The most popular brands of antivirus software have an 80% miss rate" - AusCERT (p. 46)
    • Malware that detects and removes anti-virus and anti-rootkit tools is available. Once one of these is loaded, it runs before anti-virus software, even in Safe Mode. (p. 48)
    • "eGold Siphoner" detects valid sessions connecting to eGold.com and transfers funds by hijacking the authenticated session. (p. 52)