This site uses cookies. By continuing to browse the site you are agreeing to our use of cookies.  > Find out more here

 

All the latest UK technology news, reviews and analysis

Stricken Kelihos botnet rises from the dead

by Gareth Morgan

09 Mar 2012

View Comments

  • Tweet this
Concept image representing virus malware

The Kelihos botnet that Microsoft claimed to have taken down last year has re-emerged with a bag of new tricks aimed at rebuilding at infecting computers, according to security researchers.

They have warned that the resurgent Kelihos botnet is being used to steal credentials, install malware and distribute millions of German stock-related spam messages.

According to Swiss researchers at the Abuse.ch blog, the new version of Kelihos is using a .eu domain in combination with so-called fast flux techniques.

Fast flux is a DNS technique used by botnet operators to mask malware hosting websites behind an constantly-changing network of compromised machines, which act as proxies.

Previously Kelihos had used domains associated with the Czech Republic.

Security firm GFI has also warned that a new variant of Kelihos is on the loose, with those behind it seemingly intent on rebuilding the botnet.

“Despite the best efforts of Microsoft and a number of security specialists, the Kelihos Botnet has continued to gain momentum in the wild,” GFI warned.

Microsoft said it had shut down the Kelihos botnet last September.

At the time, it said: “When Microsoft takes a botnet down, we intend to keep it down.”

One of the people that Microsoft had accused of running Kelihos has strenuously denied involvement.

He recently told Gazeta.ru that despite having worked for an anti-virus firm, he did not have the technical expertise to develop a botnet.

“I specialise in interior design, architecture software systems,” he said according to a Google translation of the interview.

Security firm Kaspersky Labs, which worked with Microsoft on the initial Kelihos takedown reported seeing new variants of the botnet as early as January 2012.

V3 contacted Microsoft and Kaspersky for comment on the revelations but had received no reply at the time of publication.

Do you agree

blog comments powered by Disqus

Poll

Business security poll

How concerned are you by the rising tide of cyber threats?

17%

56%

10%

9%

8%

Popular Threads

Powered by Disqus
Sony Xperia Z vs Apple iPhone 5

Sony Xperia Z vs Apple iPhone 5 head to head video review

V3 pits Sony's rugged flagship against Apple's premier handset

Updating your subscription status Loading

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

newsletter sign-up button

mcafee

7 requirements for hybrid web delivery

It's no longer one or other with web security; you can now have a virtualisation and SaaS hybrid model

navisite

BYOD: the implications for the IT team

BYOD is important for employee satisfaction, but poses challenges in terms of security, productivity loss and costs

.NET Developer - Computer Gaming Company - Swindon

.NET Developer (ASP.NET, C#, C#.NET, dot NET, Web Application...

.NET Developer - Insurance Firm - Cannock, Staffordshire

.NET Developer (ASP.NET, C#, C#.NET, dot NET, Web Application...

Graduate / Junior .NET Developer - Times Top 100 Employer

Graduate / Junior .NET Developer (ASP.NET, C#, C#.NET...

BI / Data Warehouse Developer - Digital Download Site - London

BI / Data Warehouse Developer (SQL Server 2012, SSAS...

Keep up to date with the latest products, services and technologies from the world's leading IT companies. IThound.com brings you over 2,000 white papers, case studies and analyst reports.

To send to more than one email address, simply separate each address with a comma.