All the latest UK technology news, reviews and analysis

Kroxxu botnet hits a million web users

by Phil Muncaster

22 Nov 2010

Be the first to comment

  • Tweet this
password screen

Security experts have uncovered a dangerous new botnet which has already infected over 100,000 domains and one million systems worldwide, although it is still unclear how the cyber criminals are monetising their efforts.

The Kroxxu botnet has been designed solely to steal FTP passwords but, unlike traditional botnets, it is able to spread through infected web sites alone rather than individual PCs, according to researchers at Avast Software who have been tracking it for over a year.

The stolen passwords enable Kroxxu's creators to add a script tag to the original web site content which then makes it possible to upload and modify files on infected servers and spread to other servers globally.

The malware relies heavily on redirects to obfuscate itself, while various components of the network are able to perform different roles, known as " indirect cross infection".

"Kroxxu's indirect cross infections are based on all parts being equal and interchangeable," said Jiri Sejtko, head virus researcher at Avast.

"If one part is used as an initial redirector, it may also be used as a final distribution part at the same or even a different time. This gives it an enormous range of designed-in duplicity."

Avast has not yet discovered how the botnet organisers are making money from the scam, but Setjko suspects they could be selling stolen credentials or hacked space on infected servers, or using key-loggers to spread other spam.

The botnet has infected 1,000 domains a month since its discovery in October 2009, and many of the PHP redirectors and malware distributors placed in the sites have survived for months at a time.

By infecting legitimate sites, the botnet could have a serious impact on the success of URL blocking software, warned Avast.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

Flame virus poll

Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?

37%

0%

11%

52%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Symanteccloud

Social networking: a guide for IT managers

Social networking is almost ubiquitous. This white paper examines the benefits and risks and it looks at the different ways companies can reconcile them

Riverbed

Mitigating the risks of IT change

The importance of understanding your infrastructure

Availability & Capacity Lead

About Us WorldPay provides a globally connected, locally...

Change & Configuration Administrator

About Us WorldPay provides a globally connected, locally...

SQL Server Developer - SSIS - Zurich

SQL Server Developer - Our client, an international...

IT Technical Service Delivery Manager / ITIL / Reigate - 65K

IT Technical Service Delivery Manager / ITIL / Reigate...

To send to more than one email address, simply separate each address with a comma.