Massive Windows Botnet Uncovered

Researchers at security firm Finjan have uncovered a massive botnet of Windows machines. The botnet is 1.9 million machines strong, with many of the machines located in the United States: 45% of them are located in the US. The researchers detailed their findings at the RSA Conference in San Fransisco.

The botnet in question is one of the largest ever found that is controlled by a single gang of cybercriminals. Apparently, the command and control server of the botnet are located in the Ukraine. The researchers claim that during their work, the number of infected computers increased by the hour.

The botnet is actually quite user friendly, as it has a nice backend management application through which the cybercriminals can control the machines in the botnet. From this backend, the criminals can instruct machines to download additional malware, which in turn are used to read local data from the machines. “When inspecting these files, we identified that they can perform the following actions: read email address and other details from the infected computer; communicate with other computers using HTTP protocol; execute a process; inject code into other processes; visit websites without end-users’ consent; register as a background service on the infected computer and a few dozen other commands,” the researchers write. They conclude that the criminals can basically do whatever the heck they want with and on the infected machines.

Finjan has shared the information about the botnet with the authorities.

30 Comments

  1. 2009-04-22 10:01 pm
    • 2009-04-23 7:41 am
  2. 2009-04-22 10:31 pm
    • 2009-04-22 11:56 pm
  3. 2009-04-23 12:24 am
    • 2009-04-23 12:27 am
      • 2009-04-23 12:38 am
        • 2009-04-23 2:40 am
          • 2009-04-23 4:28 pm
          • 2009-04-25 11:31 pm
      • 2009-04-23 3:14 pm
  4. 2009-04-23 1:57 am
    • 2009-04-23 2:34 am
    • 2009-04-23 5:34 am
      • 2009-04-23 11:56 am
        • 2009-04-23 3:41 pm
        • 2009-04-23 10:54 pm
    • 2009-04-23 6:05 am
      • 2009-04-23 7:47 am
        • 2009-04-23 9:08 am
          • 2009-04-23 6:26 pm
      • 2009-04-23 7:51 am
        • 2009-04-23 8:22 am
          • 2009-04-23 1:13 pm
    • 2009-04-23 6:35 am
  5. 2009-04-23 2:29 am
    • 2009-04-23 3:47 am
      • 2009-04-23 4:01 am
  6. 2009-04-23 6:02 pm
  7. 2009-04-23 8:59 pm