IRC bots controlling infected PCs in distributed networks
IRC bots controlling infected PCs in distributed networks

Botnets multiplying over IRC

Honeynet Project reports hundreds of attacks a month

Iain Thomson

A newly published report by the Honeynet Project and Research Alliance has shown that internet relay chat (IRC) is crucial to hackers running so-called botnets of virus-infected PCs.

The team, which uses test machines to analyse hacker behaviour, found many IRC bots which were being used to control infected PCs in distributed networks.

Advertisement

Home users with broadband are increasingly being targeted for infection since their PCs generally have poor security and can be used remotely without the user knowing.

"We have identified many different versions of IRC-based bots with varying degrees of sophistication and implemented commands, but all have something in common," the report stated.

"The bot joins a specific IRC channel on an IRC server and waits there for further commands. This allows an attacker to remotely control this bot and use it for fun and for profit."

Such networks are powerful; 1,000 compromised machines would have more bandwidth than most corporate IT systems. The bots spread by trying to propagate via open ports, with over 80 per cent using ports 445, 139, 137 and 135 - which are all used by Windows software.

"A lot of these people like IRC because it's old school," said Olaf Linder, director of Symantec's security services.

"It is a text-based system and has been around since the dawn of the internet. It's also anonymous, which is another big advantage."

The team tracked more than 1,000 botnets in the past four months, and observed 226 distributed denial of service attacks, in some cases using botnets of more than 50,000 computers. Hackers running the botnets were found to openly discuss progress with each other over IRC.

The report suggested that the chief culprits running botnets are "young males with surprisingly limited coding skills" who have regular nicknames and chatter a lot via IRC.

The Honeynet Project report can be found here.

  • Have your say
  • Send to a friend
  • Print
  • Digg
  • Reddit
  • Share

Tags:

Do you agree?

Further reading

MyDoom.BQ installs a backdoor channel to IRC

MyDoom variant opens backdoor IRC channel

Hackers able to take complete control of affected PCs

All Party Internet Group calls for tougher line on hackers

UK clamps down on denial-of-service attacks

Pressure grows for specific DoS offence and two-year jail sentence

Gone phishing

Phishing is becoming ever more prevalent and ever more dangerous

Noomy.A virus spreading via chat rooms

IRC users hoodwinked with promise of software cracks and Kournikova screensavers

Related whitepapers

Related jobs

Most watched

standard plug

UK folding plug system in action

Inventor develops innovative answer to bulky UK plugs

iPhone

Video Review: iPhone 3GS

We put Apple's latest iPhone through its paces

Analysis and Reports

Continuous Availability for Microsoft SharePoint

This paper examines how to create continuous availability for Microsoft SharePoint by implementing high availability and disaster recovery solutions.

Database security: Preventing enterprise data leaks at the source

This report looks at the challenge of information protection and control (IPC) and how enterprises must adopt database security best practices

Poll

International Women’s Day poll

International Women’s Day poll

Have measures to encourage women into the IT profession been successful?

View poll results

Advertisement

White paper library

Keep up to date with the latest products, services and technologies from the world's leading IT companies; IThound.com brings you over 6,000 white papers, case studies and analyst reports.

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Spotlight

Top 10 computer games of all time

As the game Bafta winners are unveiled, we celebrate the...

Google Street View

Google Street View under fire again

Web giant criticised for showing images of secret SAS base...

Rosalie Marshall

Government should consider monitoring PR efforts more closely

A release on tech workers' hobbies shows the government might...

Internet Explorer

MIX10: Microsoft shows browser and mobile future

Microsoft's MIX10 event showed where the firm is heading with...

Primary Navigation