Massive Botnet Returns From the Dead To Spam On
CWmike writes "Gregg Keizer reports that the big spam-spewing Srizbi botnet, shut down two weeks ago when McColo was shuttered, has been resurrected and is again under the control of criminals, security researchers said today. As of late Tuesday, infected PCs were able to successfully reconnect with new command-and-control servers, which are now based in Estonia, said Fengmin Gong, chief security content officer at FireEye. The comeback confirms what researchers noted last week, that Srizbi had a fallback strategy. So, in the end, that strategy paid off for the criminals who control the botnet."
Further proof that crime doesn't pay. Unless you have a reliable business plan, of course.
-=Bang Bang=-
Now do it again. Rinse, repeat, until there's nowhere left for them to host the "command and control" servers.
:-(
The sooner the better. My good:spam ratio is almost 5:95 at the moment
If I had an Ass, I'd call it Fanny Bottom, then I could slap my Ass; Fanny Bottom, on the Arse.
..most is how efficiently the bad guys always work. Its just astounding.
Real men read Slashdot articles at -1, bottom up.
I have worked in more than a few offices that have no backup plans for when things go wrong; power outs, network outages, supply chain disruptions, and the like would stop work cold. I find it amusing that a band of criminals are running a more flexible and 'professional' operation than many ligament businesses.
We are the Borg...
Is this because some idiot(s) let McColo get back online for a number of hours, or was that fallback already in place before the McColo initial shut down? These major ISP backbone providers reall need to be talking to each other when they blacklist a site so that one rogue provider doesn't undermine the good efforts of all the rest.
"It's the height of ridiculousness to say for those 9 lines you get hundreds of millions."
Anyone who is surprised by this, raise your hand. If someone was able to write the requisite application to gather the botnet, one would expect the same programmer to have the foresight to write in a way to re-gather and restart the botnet at a later point in time.
Damn_registrars has no butt-hole. Damn_registrars has no use for a butt-hole.
While the command and control was down, they missed the chance to take out the bots too.
how efficiently the bad guys always work.
Not really - we only ever hear about the efficient ones here. Head on over to Fark (or even Youtube:) to get some examples of bad guys working....inefficiently.
Last post!
Are you under the impression that ISP's cannot be bribed, confused, or flat out lied to using stolen credit card information? Boy, I wish I had your ISP to tell me what singles ads are lying about.
What you seem to be overlooking is the fact that there is a huge profit motive in spam. As such, there is a huge profit motive in maintaining as large a botnet as possible. One thing botnet owners often do is try to steal bots from other nets. To combat this, they will often patch the holes they used to gain control of the bots in the first place, and any other holes they know of. Essentially, it is in botnet owners' best interests to make their bots as secure as possible against determined attackers (i.e., other botnet owners).
This leaves basically two reasonably reliable (legal) options for removing bots from the network: physical access to clean (or format) the infected computer offline, or persuading the bot's ISP that the bot is a bot and should have 'net access removed until such time as it is cleaned.