We use cookies to provide you with a better experience. If you continue to use this site, we'll assume you're happy with this. Alternatively, click here to find out how to manage these cookies

hide cookie message
80,259 News Articles

Microsoft to tackle botnets with legal action

Take-down hasn't stopped all communication with botnet's controllers

Microsoft is planning to use the same legal tactic that it deployed last week to strike at the Waledac botnet's command-and-control centres, against a number of other botnets.

But the company also admitted that it had not yet severed all communications between the controllers of Waledac and the thousands of compromised Windows computers used by hackers to pitch bogus security software and send a small amount of spam.

"This shows it can be done," said Richard Boscovich, senior attorney with Microsoft's Digital Crimes Unit.

"Each botnet is different, of course, but this is another arrow in the quiver. This is not the last [effort].... We have other operations on the drawing board."

Last week, Microsoft announced that it had been granted a court order that yanked nearly 300 sites from the internet.

Those sites, Microsoft said, were a key link between hackers and the PCs that make up the Waledac botnet.

The legal tactic, which garnered accolades from many security professionals as a precedent-setting move, resulted in what Microsoft called "a major botnet takedown" of Waledac, a fact that some researchers disputed.

The same method can and will be applied to other botnets, Boscovich said.

He declined to say which zombie PC army is next on Microsoft's hit list. "Of course this is scalable," he said when asked whether the legal action against Waledac would work against other botnets, or was a one-off.

"This is another tool we can now use, another mechanism that is available."

In fact, when Microsoft officials sat down in early January to decide which botnet to target, they started with a list of six, then narrowed it to three, from which they selected Waledac. The remaining five unnamed botnets remain on Microsoft's list.

"We wanted to challenge ourselves technically," said Boscovich when asked why Waledac was chosen. "From the technical standpoint, it had a certain reputation."

Waledac does have a reputation. The malware that infects victimised PCs was created by, and the botnet is maintained by, hackers who previously flooded the internet with the Storm bot from early 2007 through mid-2008.

Waledac's makers "definitely know the ins and outs," Joe Stewart, director of malware analysis at SecureWorks and a noted botnet researcher, said.

Boscovich admitted that Waledac wasn't the world's biggest botnet, but said several things recommended it for the debut of Microsoft's legal approach to bot smashing.

Among them: the identified command-and-control domains were all registered with one domain registrar, VeriSign, which made it easier to co-ordinate the site shutdowns; and Microsoft had been in contact with several independent researchers who had dug deep into the malware's code and the botnet's behavior.

Even as Microsoft said it would again swing the legal sword, it also admitted it had not completely cut ties between the infected PCs and the hackers who control them.

"They were severely impacted [by the legal action], and we expect the severity of the impact to increase over the next several days," said T.J. Campana, a senior program manager who works for Boscovich in the company's Digital Crimes Unit.

When asked whether communications between the Waledac hackers and the botnet's PCs had been comprehensively severed, Campana answered, "By and large, the answer is no."

Last week, Microsoft claimed it had grabbed control of more than 60,000 bots in the Waledac collection after the court order shuttered the 277 targeted domains.

Several security researchers, however, questioned whether the tactic would cripple Waledac , or even disrupt its activities, since hackers have multiple mechanisms for passing commands to machines infected with Waledac.


IDG UK Sites

Nexus 6 vs Samsung Galaxy Note 4 comparison: What's the best Android phablet?

IDG UK Sites

The iPhone is doomed. Doomed to be marginally less successful than a very successful thing.

IDG UK Sites

How to prototype native mobile apps without writing code

IDG UK Sites

How to prepare for and update to OS X Yosemite: Get your Mac ready to download & install Apple's...