Slashdot Mirror


Google Groups Used To Control Botnets

oDDmON oUT writes "'Maintaining a reliable command and control (C&C) structure is a priority for back door Trojan writers. ... Symantec has observed an interesting variation on this concept in the wild. A back door Trojan that we are calling Trojan.Grups has been using the Google Groups newsgroups to distribute commands,' writes Symantec employee Gavin O Gorman. He goes on to state that 'the Trojan itself is quite simple. It is distributed as a DLL,' and while the decrypted commands indicate it is used 'for reconnaissance and targeted attacks,' he does go on record as saying, 'It's worth noting that Google Groups is not at fault here; rather, it is a neutral party. The authors of this threat have chosen Google Groups simply for its bevy of features and versatility.'"

4 of 63 comments (clear)

  1. Re:Google Groups is just a way to Usenet by athakur999 · · Score: 5, Informative

    It's true Google Groups can be used to view Usenet groups, but you can also create groups that are completely independent of Usenet with it. That seems to be the case here.

    --
    "People that quote themselves in their signatures bother me" - athakur999
  2. This just in! by Anonymous Coward · · Score: 5, Funny

    Breaking news today:

    Free Web Service Abused, Professionals Shocked

    News at 11.

  3. Re:So? by sakdoctor · · Score: 5, Funny

    -----BEGIN BOTNET COMMAND OVER /.-----
    Version: v1.0.0

    TEx2OTNZRm9 mb1l4Q1B5N25P b3dxSjRCMkhSS WhzdDFBbV Ezd2lGSWtY R1pEMWJ qUHdtcG9z cktLNHd5 cDBZeg==

    -----END BOTNET COMMAND OVER /.-----

  4. Next up: Botnets surfing the google wave by ghmh · · Score: 5, Funny

    Who needs IRC or usenet or google groups when you can surf the google wave?

    Wonder whether this will get you access?

    Google Wave Sandbox Developer Signup

    Name: xxxx
    ....
    What do you intend to build?
    Botnet