All the latest UK technology news, reviews and analysis

Massive UK and US botnet uncovered

by Phil Muncaster

22 Apr 2009

Be the first to comment

  • Tweet this
Ukraine flag
Finjan said the botnet was under the control of six people based in the Ukraine

A botnet of nearly two million compromised computers, most of them in the UK and US, has been discovered by web security firm Finjan.

The botnet is notable not just because of its scale, but also the speed with which it was formed and the fact that many government and corporate PCs, as well as consumer devices, were infected.

According to Finjan's chief technology officer, Yuval Ben-Itzhak, the average size of botnets last year was around 500,000 machines. He said this particular network has only been in use since February this year, controlled by just six people using a server hosted in the Ukraine.

"They managed to infect so many people by compromising legitimate web sites and inserting malware code, so when people visited the sites, their browser was exploited," said Ben-Itzhak.

"They can send commands to each of the [infected computers] recording keystrokes and passwords, and stealing data, and can also use them for sending spam, or for denial-of-service attacks."

He added that only four of the 39 anti-virus scanning tools they tested were unable to detect the malware used to infect the machines in the botnet.

"Our recommendation is to take a multi-layered approach, including traditional anti-virus and real-time content analysis tools to inspect content without a signature, and data leak prevention in and outbound," advised Ben-Itzhak.

He added that web site owners should put in place web application firewalls to minimise the risk of SQL injection and cross-site scripting attacks.

Finjan said it has now provided information about the Ukraine-based command and control server to UK and US law enforcers, and told those government agencies and companies whose computers are infected.

Rik Howard, director of intelligence at managed security services firm iDefense, said the news highlights the fact that some government agencies have the same problems securing their computer systems as commercial organisations.

"In my estimation, government patching cycles are maybe not always as aggressive as commercial organisations, and they may want to consider that," he advised.

"You should also never underestimate the power of the machine that has been offline for a while and hasn't been brought up to speed with patches before it's brought online again."

Howard added that the size of the botnet was somewhat surprising, given that the trend iDefense has observed appears to be of online criminals using smaller networks which are more nimble and harder to detect.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

The workplace of the future poll - in association with IBM

What will be the biggest change to corporate technology in the future?

89%

6%

1%

3%

1%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Riso

Colour printing: why the bill keeps outstripping the budget

The wrong printers, for the wrong tasks on the wrong contracts

Qlikview

Magic quadrant for business intelligence platforms

Who leads the BI pack and who should we be watching out for?

Chief, Partner Solutions / Director, Client solutions

Chief, Partner Solution / Director, Client Solutions...

ASP.NET, C# Developer, .NET - MS Gold Partner - Preston

ASP.NET, C# Developer, .NET - MS Gold Partner - Preston...

SQL Server DBA - Ecommerce Brand - Southampton, Hampshire

SQL Server DBA (Database Administrator, Administration...

.NET Developer - Financial Services - Basingstoke, Hampshire

.NET Developer - Financial Services - Basingstoke, Hampshire...

Keep up to date with the latest products, services and technologies from the world's leading IT companies. IThound.com brings you over 2,000 white papers, case studies and analyst reports.

To send to more than one email address, simply separate each address with a comma.