All the latest UK technology news, reviews and analysis

FBI and DoJ action cuts Coreflood botnet activity by 90 per cent

by Iain Thomson

28 Apr 2011

Be the first to comment

  • Tweet this

Court documents released by the FBI and the US Department of Justice (DoJ) show that activity on the Coreflood botnet is down by 90 per cent in the US following last month's shutdown.

Five command-and-control servers in the US were seized by law enforcement in a co-ordinated action, and replaced with new systems which ordered infected PCs to shut down the malware they were running.

At the same time, Estonian police took similar action with servers based within their borders.

The newly released DoJ court documents (PDF) state that the servers were receiving around 800,000 messages a day from infected computers when they were seized on 13 April. Nine days later this had dropped to under 100,000, and the number is still falling steadily.

Coreflood activity is down 90 per cent in the US, and 75 per cent in the rest of the world, which law enforcement attributes to the botnet's being unable to contact people outside the US or command-and-control servers overseas.

"The reduction in the size of the Coreflood botnet was attributed to two factors. First, because Coreflood was no longer running, it was no longer able to update itself and avoid detection by anti-virus software," said the DoJ.

"Second, the FBI, with the assistance of internet service providers, has made significant efforts to identify and notify the victims of Coreflood, who in turn have taken measures to remove Coreflood from thousands of infected computers."

Those infected with the malware are being notified and instructed on how to clean their systems, the DoJ said. In one case a hospital network had around 2,000 of its 14,000 computers infected.

However, the DoJ also said that it will soon reconfigure the command-and-control servers to delete the malware automatically, so long as the owner of the system has given permission.

"The government respectfully advises the court that the substitute server, or another similar server, will be configured to respond to command-and-control requests from infected computers by issuing instructions for Coreflood to uninstall itself, but only as to infected computers of identifiable victims who have provided written consent to do so," the filing reads.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

Flame virus poll

Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?

39%

0%

10%

51%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Symanteccloud

Social networking: a guide for IT managers

Social networking is almost ubiquitous. This white paper examines the benefits and risks and it looks at the different ways companies can reconcile them

Riverbed

Mitigating the risks of IT change

The importance of understanding your infrastructure

Java Developer, Algo Trading, FX, Trading Strategies

Java Deveoper/Programmer/Software Engineer, Algo Trading...

Lead and Senior Developers Wanted

Austin Fraser has the pleasure of appointing a number...

Java Developer - Great move up for a Junior Developer

Austin Fraser has the pleasure of appointing a Java Developer...

Senior J2EE Application Developer

Austin Fraser has the pleasure of appointing a Senior...

To send to more than one email address, simply separate each address with a comma.