This site uses cookies. By continuing to browse the site you are agreeing to our use of cookies.  > Find out more here

 

All the latest UK technology news, reviews and analysis

Microsoft reaches agreement with web host linked to counterfeit Windows botnet

by James Dohnert

02 Oct 2012

View Comments

  • Tweet this
Microsoft logo

Microsoft has announced it has reached a settlement with the domain hosting firm responsible for hosting the Nitol botnet.

Microsoft struck a deal which will see 3322.org operator Peng Yong work with it and Chinese authorities to prevent his hosting company from supporting the infrastructure of the Nitol botnet. The settlement ends a lengthy Microsoft investigation into Chinese counterfeit Windows PCs.

"Fighting botnets will always be a complex and difficult endeavour as cyber criminals find new and creative ways to infect peoples' computers with malware, whether for financial gain or other nefarious purposes," said assistant general counsel for Microsoft Digital Crimes Unit, Richard Boscovich in a blog post.

"However, those working to combat cyber crime continue to make progress, and Microsoft remains committed to protecting its customers and services and to making it difficult for cyber criminals to take advantage of innocent people for their dirty work."

Last month, Microsoft announced the discovery of a counterfeit Windows PCs which were selling in China with pre-installed with malware.

The company found that consumers in China were purchasing knockoff Windows machines pre-packaged with the Nitol botnet during an investigation into PC supply chain lines in early September.

Nitol would carry out a distributed denial of service (DDoS) attack on systems and create backdoor access for more malware to cripple a user's computer. Microsoft discovered that Nitol was being supported by 3322.org and attempted to shut down the domain provider.

Yong will now work with the Chinese Computer Emergency Response Team (CN-CERT) to make sure 3322.org is no longer used to host botnets.

Yong will send any "black-listed" domains to CN-CERT where they will be moved to a sinkhole set up by the Chinese authorities. The 3322.org owner will also be obligated to help anyone affected by the Nitol botnet by fixing their systems.

Yong defended his company when news of the Nitol botnet first broke, claiming that 3322.org opposed hosting illegal content, but the size of its user base made it hard to police content.

Microsoft has begun notifying victims of the Nitol botnet by sharing infected IP information with the Shadow Server Foundation. The foundation is a group of volunteer internet security staff who gathers and track potential malware threats.

Do you agree

blog comments powered by Disqus

Poll

Business security poll

How concerned are you by the rising tide of cyber threats?

17%

55%

10%

9%

9%

Popular Threads

Powered by Disqus
BlackBerry Q5

BlackBerry Q5 video demo

BlackBerry's latest smartphone is a mid-tier handset that will cost less than the Q10 and Z10

Updating your subscription status Loading

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

newsletter sign-up button

mcafee

7 requirements for hybrid web delivery

It's no longer one or other with web security; you can now have a virtualisation and SaaS hybrid model

navisite

BYOD: the implications for the IT team

BYOD is important for employee satisfaction, but poses challenges in terms of security, productivity loss and costs

PHP Developer - £30,000 - £35,000

PHP Developer £30,000 - £35,000 We are looking for...

Senior Project Manager - must speak fluent German

Massive is looking for a diligent, motivated, fluent...

Corporate Treasurer - Banking - London

Corporate Treasurer - Banking London - £70k-£120k...

Product Manager – Insurance (Telematics)

Product Manager – Insurance (Telematics) £40k-£50k...

To send to more than one email address, simply separate each address with a comma.