Attacks/Breaches
2/18/2011
12:10 PM
50%
50%

Botnet Victims Increased 654% In 2011

The top 10 botnets are responsible for 57% of all infections, says Damballa report.

Top 10 Security Stories Of 2010
(click image for larger view)
Slideshow: Top 10 Security Stories Of 2010

The botnet market is both growing and consolidating. The top 10 botnets of 2010 -- based on total number of PCs compromised -- began the year with 22% market share, but grew to account for 57% of all botnet infections by the end of the year. Meanwhile, in the same timeframe, the number of unique botnet victims grew by 654%.

Those findings come from a report, released on Tuesday, by anti-botnet security company Damballa. The report finds a botnet landscape that is changing rapidly, driven in part by the ready availability of inexpensive botnet-building toolkits.

Which botnets rule? The biggest botnets in 2010 (based on their percentage of victims) were the TDLBotnetA botnet run by RudeWarlockMob (15% market share), the RogueAVBotnet run by FreakySpiderCartel (6%), the ZeusBotnetB run by FourLakeRiders (5%), followed by Monkif (5%), Koobface.A (4%), and Conficker.C (3%). That list includes one-off botnets created and customized by criminal gangs, many of whom use DIY tools such as Zeus as the base.

Interestingly, 60% of botnets seen in 2010 didn't even exist in 2009. In fact, "only one botnet -- Monkif -- made it to the top 10 of both years," said Gunter Ollmann, VP of research for Damballa, in a blog post.

In general, what sets apart the botnet winners from losers is that the biggest ones get updated frequently with revised fraud targets. They also embrace the latest botnet features and functionality. That includes updating the malware on infected PCs, running multiple infection campaigns at once, generating one-of-a-kind malware for each victim, and using multiple infection vectors.

Today's top botnet are also succeeding thanks to a thriving ecosystem of best-of-breed, complementary services. "The federated ecosystem of botnet building means that malware authoring, drive-by-download infections, content delivery, and [command-and-control] hosting are increasingly distributed amongst multiple unaffiliated service providers," said Ollmann. "The increased accessibility to specialist service providers has made it easier for botnet operators to rapidly grow their botnets and monetize their ill-gotten gains."

Interestingly, this distributed approach to botnets means that a PC today can be infected with malware that places it under the control of multiple pieces of botnet-driven malware. According to Ollmann, "over 35% of botnet victims were simultaneously members of multiple botnets in 2010."

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading Tech Digest, Dec. 19, 2014
Software-defined networking can be a net plus for security. The key: Work with the network team to implement gradually, test as you go, and take the opportunity to overhaul your security strategy.
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-8142
Published: 2014-12-20
Use-after-free vulnerability in the process_nested_data function in ext/standard/var_unserializer.re in PHP before 5.4.36, 5.5.x before 5.5.20, and 5.6.x before 5.6.4 allows remote attackers to execute arbitrary code via a crafted unserialize call that leverages improper handling of duplicate keys w...

CVE-2013-4440
Published: 2014-12-19
Password Generator (aka Pwgen) before 2.07 generates weak non-tty passwords, which makes it easier for context-dependent attackers to guess the password via a brute-force attack.

CVE-2013-4442
Published: 2014-12-19
Password Generator (aka Pwgen) before 2.07 uses weak pseudo generated numbers when /dev/urandom is unavailable, which makes it easier for context-dependent attackers to guess the numbers.

CVE-2013-7401
Published: 2014-12-19
The parse_request function in request.c in c-icap 0.2.x allows remote attackers to cause a denial of service (crash) via a URI without a " " or "?" character in an ICAP request, as demonstrated by use of the OPTIONS method.

CVE-2014-2026
Published: 2014-12-19
Cross-site scripting (XSS) vulnerability in the search functionality in United Planet Intrexx Professional before 5.2 Online Update 0905 and 6.x before 6.0 Online Update 10 allows remote attackers to inject arbitrary web script or HTML via the request parameter.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Join us Wednesday, Dec. 17 at 1 p.m. Eastern Time to hear what employers are really looking for in a chief information security officer -- it may not be what you think.