Original URL: http://www.channelregister.co.uk/2006/02/20/stealth_spam/
Botnet controllers are switching to stealth tactics in a bid to avoid detection. Instead of mass mail-outs of spam and malicious code, they are adopting slower distribution tactics in a bid to avoid appearing on corporate security radars.
UK-based web security firm BlackSpider Technologies reports that one huge botnet, responsible for issuing 50m identical spam emails per day, compromises at least 150,000 distinct IP addresses. The use of a large number of machines - each sending out an average of 330 emails a day or around 40 per hour during the course of a working day - is a change from days of yore when a handful of compromised email servers would have been used to do the same job.
It's well known that packages such as Send-safe.com are used by spammers to control the distribution of junk mail broadband-connected PCs infected by viruses such as SoBig, but BlackSpider's figures on the mail-out rate from compromised machines add a fresh perspective to the problem.
BlackSpider Technologies CTO James Kay said this low mail-out rate means users of compromised machines will not notice anything untoward with their net connection. Because they don't notice anything amiss, the spambot remains undetected. "It’s about time law enforcement agencies took the botnet issue far more seriously. Ninety-eight per cent of spam and malicious code comes from machines with bad or unknown reputations, and we should be slapping online ASBOs (anti-social behaviour orders) on them to stop this criminal cycle," Kay said.
Kay added that spam purveyors are adopting the same stealth tactics as VXers. "It’s not dissimilar to the low-volume virus distribution tactic that we first saw last year, when hackers realised that releasing viruses in smaller numbers kept them out of sight of anti-virus vendors for far longer, causing more damage." ®
SoBig anniversary marks birth of the botnet (9 January 2008)
http://www.channelregister.co.uk/2008/01/09/sobig_anniversary/
Spam: now made in China (4 December 2006)
http://www.channelregister.co.uk/2006/12/04/china_propagates_spam/
BT debuts 'spam-buster' system (12 October 2006)
http://www.channelregister.co.uk/2006/10/12/bt_spam_buster/
Virus infections drop, spam on the up (4 October 2006)
http://www.theregister.co.uk/2006/10/04/viruses_down_spam_up/
Open source blamed for malware development (18 July 2006)
http://www.channelregister.co.uk/2006/07/18/open_source_virus_development/
Junk mail scumbags in harvesting attack (26 June 2006)
http://www.channelregister.co.uk/2006/06/26/directory_harvest_attack/
Ransomware Trojan cracked (6 June 2006)
http://www.channelregister.co.uk/2006/06/06/ransomeware_trojan/
Spam deluge eclipses email virus threat (1 June 2006)
http://www.channelregister.co.uk/2006/06/01/may_malware_report_blackspider/
Virus writers at war (5 April 2006)
http://www.channelregister.co.uk/2006/04/05/vxers_at_war/
Joe-job spammers shift tactics to evade filters (30 March 2006)
http://www.channelregister.co.uk/2006/03/30/joe_job_twist/
Three charged with Seattle hospital botnet attack (14 February 2006)
http://www.channelregister.co.uk/2006/02/14/seattle_hospital_botnet/
Botnet control fears over IP telephony (26 January 2006)
http://www.channelregister.co.uk/2006/01/26/voip_botnet_control_fears/
Malware potency increases as numbers drop (25 January 2006)
http://www.channelregister.co.uk/2006/01/25/ibm_cybercrime_report_2005/
Bot herder pleads guilty to 'zombie' sales (24 January 2006)
http://www.channelregister.co.uk/2006/01/24/zombie_herder_pleads/
Pump-and-dump spam domains go silent after botnet closure (14 November 2005)
http://www.channelregister.co.uk/2005/11/14/spam_domain_dump/
Virus writers craft PnP botnet client (24 October 2005)
http://www.channelregister.co.uk/2005/10/24/pnp_botnet_encore/
Arrests 'unlikely' to impact botnet threat (13 October 2005)
http://www.channelregister.co.uk/2005/10/13/rise_of_the_botnets/
Dutch smash 100,000-strong zombie army (7 October 2005)
http://www.channelregister.co.uk/2005/10/07/dutch_police_smash_zombie_network/
Bot herder websites in internet take-down (13 September 2005)
http://www.channelregister.co.uk/2005/09/13/bot_herder_takedown/
Send-Safe spam tool gang evicted by MCI (1 March 2005)
http://www.theregister.co.uk/2005/03/01/send-safe_evicted/
© Copyright 2008