(BUSINESS WIRE)--Damballa Inc., the company transforming the fight against cyber threats, today announced the discovery of a new botnet that offers pay-for-delivery Distributed Denial of Service (DDoS) attacks. The ‘IMDDOS’ Botnet, named after the commercial name on the botnet website, has grown to be one of the largest active global botnets in less than four months from initial testing. According to Damballa, the infected hosts used in the DDoS attacks have become unwitting participants in the botnet and are widespread. The vast majority of infected hosts are in China, with the United States being in the top 10 countries affected. Internet Service Providers (ISPs) worldwide were affected, including the majority of North American ISPs, and a number of major corporate networks are hosting bot agents for the IMDDOS Botnet.
“The commercial nature of this botnet and the rapid growth and ultimate size are what make this discovery interesting”
The IMDDOS Botnet offers a commercial service for delivering DDoS attacks against any desired target. Hosted in China, this publicly available service is available for lease to anyone willing to establish an online account, input the domain(s) they wish to attack, and pay for the service. Throughout the Damballa period of study, the botnet grew large very quickly. Following testing by the criminal operators in April 2010, it reached a production peak of activity with 25,000 unique Recursive DNS (RDNS) lookups per hour attempting to resolve to the botnet’s command-and-control (CnC) servers. Damballa is currently working with ISPs and law enforcement officials to contain and nullify the threat.
A 16-page analysis of the discovery can be viewed at: www.damballa.com/IMDDOS. This analysis includes details of the technical infrastructure of the botnet and associated malware as well as an animated illustration of the IMDDOS Botnet’s global growth and impact from early testing stage to peak activity rendered in hourly increments.
A Denial of Service (DoS) attack is a technique used to overwhelm a website/domain in an effort to reduce its responsiveness or completely eliminate its ability to respond to new connection attempts. DoS attacks have historically been used to ‘take down’ political sites, abuse sites, commercial business websites and even military command centers as part of a coordinated targeted campaign.
A DDoS attack utilizes multiple PCs or servers to initiate a coordinated attack against a targeted system. The more assets involved in the attack, the larger the flood of requests and data that can be targeted at the victim. To create a very large army of assets that can launch DDoS attacks, botnets are used to rally and command unwitting victim machines into participating in the attacks.
“The commercial nature of this botnet and the rapid growth and ultimate size are what make this discovery interesting,” stated Gunter Ollmann, vice president of research for Damballa. “The public website hosting the DDoS service offering, with various ‘plans’ and attack options, speaks to the ease with which anyone can leverage criminal infrastructure. The malware used is simplistic, yet it was successful in spreading rapidly. And while it appears to be primarily a DDoS delivery platform, the size of the botnet reached impressive proportions, certainly large enough to wreak major havoc on any victim organization should it be pointed in the right direction.”
This discovery was made possible due to a global array of Damballa sensors, which provide worldwide visibility into CnC activity, combined with the understanding and quantification of statistical heuristics that can explain, and most importantly, quickly detect, the malicious nature of this botnet operation. Damballa tracks thousands of botnet operators and their growing cache of botnets every day. Each criminal botnet building campaign is observed, analyzed, automatically catalogued and categorized using a sophisticated array of clustering and machine learning systems. As the criminal botnet operators attempt to grow the botnet, their investments and modifications to their CnC hosting infrastructure are tracked and used as markers for eventual attribution. Damballa customers benefit from this advanced knowledge of the threat, being alerted to the presence of the malware and being able to terminate the CnC communications.
“Botnets are recognized by industry experts as being the delivery mechanism of choice for the vast majority of today’s cyber threats that plague corporate and ISP networks,” said Val Rahmani, CEO of Damballa. “Botnets and other cyber threats are attacking corporate networks and service providers at an alarmingly high rate and are causing security teams around the world to reevaluate their security investments. Damballa leads the security industry in delivering solutions that detect and terminate botnets and cyber threats, and our research and product teams are constantly innovating and bringing more powerful and automated weapons to the war against cybercrime.”
-----
Community News You Can Use
www.fayettefrontpage.com
Fayette Front Page
www.georgiafrontpage.com
Georgia Front Page
Follow us on Twitter: @GAFrontPage
Showing posts with label infected. Show all posts
Showing posts with label infected. Show all posts
Tuesday, September 14, 2010
Wednesday, July 28, 2010
FBI, Slovenian and Spanish Police Arrests Mariposa Botnet Creator, Operators
The FBI, in partnership with the Slovenian Criminal Police and the Spanish Guardia Civil, announced today significant developments in a two-year investigation of the creator and operators of the Mariposa Botnet. A botnet is a network of remote-controlled compromised computers.
The Mariposa Botnet was built with a computer virus known as “Butterfly Bot” and was used to steal passwords for websites and financial institutions. It stole computer users’ credit card and bank account information, launched denial of service attacks, and spread viruses. Industry experts estimated the Mariposa Botnet may have infected as many as 8 million to 12 million computers.
“In the last two years, the software used to create the Mariposa botnet was sold to hundreds of other criminals, making it one of the most notorious in the world,” said FBI Director Robert S. Mueller, III. “These cyber intrusions, thefts, and frauds undermine the integrity of the Internet and the businesses that rely on it; they also threaten the privacy and pocketbooks of all who use the Internet.”
In February, the Spanish Guardia Civil arrested three suspected Mariposa Botnet operators: “Netkairo,” “Jonyloleante,” and “Ostiator,” aka Florencio Carro Ruiz, Jonathan Pazos Rivera, and Juan Jose Bellido Rios. These individuals are being prosecuted in Spain for computer crimes.
Last week, the Slovenian Criminal Police identified and arrested the Mariposa Botnet’s suspected creator, a 23-year-old Slovenian citizen known as “Iserdo.” The work of the Slovenian and Spanish authorities was integral to this investigation.
FBI Cyber Division Assistant Director Gordon M. Snow said: “This case shows the value of strong partnerships among law enforcement agencies worldwide in the fight against cyber criminals. Cyber crime knows no boundaries, and without international collaboration, our efforts to dismantle these operations would be impossible. The FBI praises the work of our Slovenian and Spanish partners who worked closely with our agents in this case.”
In a statement, Slovenian Minister of the Interior Katarina Kresal and Director General Janko Gorsek, Slovenian Criminal Police, said: “We are glad to cooperate with the United States; the FBI’s assistance is invaluable and represents professional affirmation of our force. This case shows that cyber crime issues call for international police cooperation that shouldn’t be hindered by geographical borders. The FBI has demonstrated a high level of collaboration in which our countries were equal partners, which was crucial for the success of the investigation and reducing the threat on a global level. This partnership serves as a solid basis for future cooperation.”
Maj. Juan Salom, commander of the Guardia Civil’s Cyber Crime Division, noted: “The Mariposa case showed how the coordinated and joint actions of different international police forces, along with the efforts of the Internet security industry, have been able to face the global threat of cyber crime,” he said. “The cyber kingpins know that they are not invincible anymore because the global efforts of the FBI, Slovenian Criminal Police, and Spanish Guardia Civil have shown that it doesn’t matter where or how they try to hide, they will be located and prosecuted.”
From 2008 to 2010, the Slovenian citizen created “Butterfly Bot” and sold it to other criminals worldwide. In turn, these criminals developed networks of infected computers—botnets—and the Mariposa variety from Spain was the most notorious and largest. In addition to selling the Butterfly Bot program, the Slovenian citizen developed customized versions for certain customers and created and sold plug-ins (add-ons) to augment the botnet’s features and functionality.
This case is significant because it targeted not only the operators of the botnet but also the creator of the malicious software that was used to build and operate it. The success of this investigation was made possible because of the skill, professionalism, and commitment of the Slovenian Criminal Police’s Cyber Crime Division and the Spanish Guardia Civil’s Computer Crimes Group.
The FBI conducted this investigation with the assistance of the United States Attorney’s Office, District of Hawaii, and the Department of Justice’s Computer Crime and Intellectual Property Section, Office of International Affairs, and the Botnet Threat Focus Cell. The FBI also received invaluable assistance from the Mariposa Working Group.
------
Community News You Can Use
www.fayettefrontpage.com
Fayette Front Page
www.georgiafrontpage.com
Georgia Front Page
Follow us on Twitter: @GAFrontPage
The Mariposa Botnet was built with a computer virus known as “Butterfly Bot” and was used to steal passwords for websites and financial institutions. It stole computer users’ credit card and bank account information, launched denial of service attacks, and spread viruses. Industry experts estimated the Mariposa Botnet may have infected as many as 8 million to 12 million computers.
“In the last two years, the software used to create the Mariposa botnet was sold to hundreds of other criminals, making it one of the most notorious in the world,” said FBI Director Robert S. Mueller, III. “These cyber intrusions, thefts, and frauds undermine the integrity of the Internet and the businesses that rely on it; they also threaten the privacy and pocketbooks of all who use the Internet.”
In February, the Spanish Guardia Civil arrested three suspected Mariposa Botnet operators: “Netkairo,” “Jonyloleante,” and “Ostiator,” aka Florencio Carro Ruiz, Jonathan Pazos Rivera, and Juan Jose Bellido Rios. These individuals are being prosecuted in Spain for computer crimes.
Last week, the Slovenian Criminal Police identified and arrested the Mariposa Botnet’s suspected creator, a 23-year-old Slovenian citizen known as “Iserdo.” The work of the Slovenian and Spanish authorities was integral to this investigation.
FBI Cyber Division Assistant Director Gordon M. Snow said: “This case shows the value of strong partnerships among law enforcement agencies worldwide in the fight against cyber criminals. Cyber crime knows no boundaries, and without international collaboration, our efforts to dismantle these operations would be impossible. The FBI praises the work of our Slovenian and Spanish partners who worked closely with our agents in this case.”
In a statement, Slovenian Minister of the Interior Katarina Kresal and Director General Janko Gorsek, Slovenian Criminal Police, said: “We are glad to cooperate with the United States; the FBI’s assistance is invaluable and represents professional affirmation of our force. This case shows that cyber crime issues call for international police cooperation that shouldn’t be hindered by geographical borders. The FBI has demonstrated a high level of collaboration in which our countries were equal partners, which was crucial for the success of the investigation and reducing the threat on a global level. This partnership serves as a solid basis for future cooperation.”
Maj. Juan Salom, commander of the Guardia Civil’s Cyber Crime Division, noted: “The Mariposa case showed how the coordinated and joint actions of different international police forces, along with the efforts of the Internet security industry, have been able to face the global threat of cyber crime,” he said. “The cyber kingpins know that they are not invincible anymore because the global efforts of the FBI, Slovenian Criminal Police, and Spanish Guardia Civil have shown that it doesn’t matter where or how they try to hide, they will be located and prosecuted.”
From 2008 to 2010, the Slovenian citizen created “Butterfly Bot” and sold it to other criminals worldwide. In turn, these criminals developed networks of infected computers—botnets—and the Mariposa variety from Spain was the most notorious and largest. In addition to selling the Butterfly Bot program, the Slovenian citizen developed customized versions for certain customers and created and sold plug-ins (add-ons) to augment the botnet’s features and functionality.
This case is significant because it targeted not only the operators of the botnet but also the creator of the malicious software that was used to build and operate it. The success of this investigation was made possible because of the skill, professionalism, and commitment of the Slovenian Criminal Police’s Cyber Crime Division and the Spanish Guardia Civil’s Computer Crimes Group.
The FBI conducted this investigation with the assistance of the United States Attorney’s Office, District of Hawaii, and the Department of Justice’s Computer Crime and Intellectual Property Section, Office of International Affairs, and the Botnet Threat Focus Cell. The FBI also received invaluable assistance from the Mariposa Working Group.
------
Community News You Can Use
www.fayettefrontpage.com
Fayette Front Page
www.georgiafrontpage.com
Georgia Front Page
Follow us on Twitter: @GAFrontPage
Thursday, October 1, 2009
No, Your Social Networking “Friend” Isn’t Really in Trouble Overseas
According to the Internet Crime Complaint Center (IC3), there has been an increase in the number of hijacked social networking accounts reported to www.ic3.gov.
One of the more popular scams involves online criminals planting malicious software and code onto to victim computers. It starts by someone opening a spam e-mail, sometimes from another hijacked friend’s account.
When opened, the spam allows the cyber intruders to steal passwords for any account on the computer, including social networking sites. The thieves then change the user’s passwords and eventually send out distress messages claiming they are in some sort of legal or medical peril and requesting money from their social networking contacts.
So far, nearly 3,200 cases of account hijackings have been reported to the IC3 since 2006.
Cyber thieves are also using spam to promote phishing sites, claiming a violation of the terms of service agreement or creating some other issue which needs to be resolved. Other spam entices users to download an application or view a video. Some of these messages appear to be sent from friends, giving the perception of legitimacy. Once the user responds to a phishing site, downloads an application, or clicks on a video link, the electronic device they’re using becomes infected.
Some applications advertised on social networking sites appear legitimate but install malicious code or rogue anti-virus software. These empty applications can give cyber criminals access to your profile and personal information. These programs will automatically send messages to your contacts, instructing them to download the new application too.
Infected users are often unknowingly spreading malware by having links to infected websites posted on their webpage without the user’s knowledge. Since the e-mail or video link appear to be endorsed by a friend, social networking contacts are more likely to click on these links.
Although social networking sites are generally a safe place to interact with friends and acquaintances, keep in mind these suggestions to protect yourself while navigating the Internet:
* Adjust website privacy settings. Some networking sites have provided useful options to assist in adjusting settings to help protect your identity.
* Be selective when adding friends. Once added, contacts can access any information marked as viewable by all friends.
* Limit access to your profile to only those contacts you trust with your personal information.
* Disable options, such as photo sharing, that you might not regularly use. You can always enable these options later.
* Be careful what you click on. Just because someone posts a link or video to their wall does not mean it is safe.
* Familiarize yourself with the security and privacy settings and learn how to report a compromised account.
* Each social networking site may have different procedures on how to handle a hijacked or infected account; therefore, you may want to reference their help or FAQ page for instructions.
If your account has been hijacked or infected, report it to by visiting www.ic3.gov or www.lookstoogoodtobetrue.com.
The Internet Crime Complaint Center is a partnership between the FBI and National White Collar Crime Center (NW3C).
-----
www.fayettefrontpage.com
Fayette Front Page
www.georgiafrontpage.com
Georgia Front Page
One of the more popular scams involves online criminals planting malicious software and code onto to victim computers. It starts by someone opening a spam e-mail, sometimes from another hijacked friend’s account.
When opened, the spam allows the cyber intruders to steal passwords for any account on the computer, including social networking sites. The thieves then change the user’s passwords and eventually send out distress messages claiming they are in some sort of legal or medical peril and requesting money from their social networking contacts.
So far, nearly 3,200 cases of account hijackings have been reported to the IC3 since 2006.
Cyber thieves are also using spam to promote phishing sites, claiming a violation of the terms of service agreement or creating some other issue which needs to be resolved. Other spam entices users to download an application or view a video. Some of these messages appear to be sent from friends, giving the perception of legitimacy. Once the user responds to a phishing site, downloads an application, or clicks on a video link, the electronic device they’re using becomes infected.
Some applications advertised on social networking sites appear legitimate but install malicious code or rogue anti-virus software. These empty applications can give cyber criminals access to your profile and personal information. These programs will automatically send messages to your contacts, instructing them to download the new application too.
Infected users are often unknowingly spreading malware by having links to infected websites posted on their webpage without the user’s knowledge. Since the e-mail or video link appear to be endorsed by a friend, social networking contacts are more likely to click on these links.
Although social networking sites are generally a safe place to interact with friends and acquaintances, keep in mind these suggestions to protect yourself while navigating the Internet:
* Adjust website privacy settings. Some networking sites have provided useful options to assist in adjusting settings to help protect your identity.
* Be selective when adding friends. Once added, contacts can access any information marked as viewable by all friends.
* Limit access to your profile to only those contacts you trust with your personal information.
* Disable options, such as photo sharing, that you might not regularly use. You can always enable these options later.
* Be careful what you click on. Just because someone posts a link or video to their wall does not mean it is safe.
* Familiarize yourself with the security and privacy settings and learn how to report a compromised account.
* Each social networking site may have different procedures on how to handle a hijacked or infected account; therefore, you may want to reference their help or FAQ page for instructions.
If your account has been hijacked or infected, report it to by visiting www.ic3.gov or www.lookstoogoodtobetrue.com.
The Internet Crime Complaint Center is a partnership between the FBI and National White Collar Crime Center (NW3C).
-----
www.fayettefrontpage.com
Fayette Front Page
www.georgiafrontpage.com
Georgia Front Page
Labels:
atlanta,
crime,
fayette front page,
georgia,
georgia front page,
hijack,
infected,
internet,
malicious,
passwords. fbi,
scams,
social networks
Subscribe to:
Posts (Atom)