Attacks/Breaches
5/16/2013
05:30 PM
Connect Directly
Google+
Twitter
RSS
E-Mail
50%
50%

Pushdo Botnet Morphs To Elude Hunters

U.S., other national government agencies, contractors, and military networks found housing new Pushdo bots as botnet adds stealthier features to evade detection, takedown

A botnet of botnets that has been disrupted by researchers multiple times during the past few years has been retooled with features that make its detection more difficult and its takedown nearly impossible without legal action.

The Pushdo botnet -- which provides the infrastructure for other malware and botnets and spreads a malware downloader program that, in turn, drops Cutwail, Gameover Zeus, and BlackHole Trojans -- is now employing Domain Generation Algorithm (DGA) as a resilient backup command-and-control (C&C) infrastructure, RSA encryption to prevent researchers from taking over the botnet, and phony JPEG image files to hide C&C traffic.

Researchers with Damballa, Dell Secureworks, and Georgia Institute of Technology recently teamed to study this new variant of Pushdo, which was first spotted by Damballa and its homegrown DGA detection tool. Among the victims infected by Pushdo are several U.S. and other national government agencies, government contractors, and military networks, the researchers found.

"This is the most elaborate [move by a] botnet trying to hide its own command and communications," says Brett Stone-Gross, senior security researcher at Dell Secureworks, who helped Damballa confirm the C&C traffic it had spotted using DGA was Pushdo. "They added resiliency with the DGA, and along with that they implemented RSA encryption so researchers, law enforcement, or their rivals can't control the botnet and use it against itself. They are the only ones who can control their botnet," Stone-Gross says. All researchers can do is record IP addresses and metadata, he says.

And in the latest twist today -- possibly in response to the discovery of their new techniques features -- the Pushdo gang was spotted pushing yet another variant of the malware, one that generates .kz domains instead of .com domains, according to Seculert, which also is studying Pushdo. "It seems like they noticed that they are being probed, as the variants were uploaded to the hijacked webserver few hours before the report went public," says Aviv Raff, CTO at Seculert.

Pushdo, which is run by a well-funded Eastern European cybercrime gang, boasts anywhere from 175,000 to a half-million bots each day, and is spread mainly via the massive and prolific Cutwail spam botnet. Pushdo basically acts as the infrastructure for botnet activity -- everything from traditional spam to spreading malicious Trojan like Zeus and SpyEye that steal financial credentials. It's mostly spread via the massive Cutwail botnet and has survived four takedowns in five years.

"It shows that they probably make a good amount of money through spam email. It's like any business: It's important to maintain a resilient infrastructure, and if the infrastructure goes down, you lose money," Stone-Gross says.

The addition of DGA for its backup C&C basically allows Pushdo to prevent interference with its C&C -- think blacklisting or extracting C&C domain names -- by making the C&C domain names a moving target, dynamically generating domain names, and using just one at a time, which later gets discarded.

"They are trying to build a system that's immune to takedown," says Jeremy Demar, senior researcher at Damballa. Demar says Pushdo downloads encrypted malware payloads so researchers can't analyze them or detect them.

[Pushdo botnet's spam traffic cut by 80 percent in takedown. See Major Disruption of Pushdo Botnet Wasn't The Original Goal .]

Researchers saw some 1.1 million unique IP addresses making Pushdo C&C requests in a two-month period, and around 35,000 unique IPs connect each day. Pushdo's DGA generates around 1,380 unique domain names daily.

India and Iran are home to the most Pushdo-infected machines, but Mexico, Thailand, Indonesia, and the U.S. also have Pushdo bots. An average of 23,000 unique hosts in the U.S. have tried connecting to Pushdo's DGA domain names. The government and military victims -- which are a small percentage of the overall bot population -- likely were inadvertent infections, Damballa's Demar says. "Someone downloaded an email," he says.

The malware also generates fake traffic to legitimate websites in an attempt to mask its C&C communications. "The C&C servers will also respond with a jpeg image with encrypted, embedded malware payloads to hide any additional files it wants to download," Demar wrote in a blog post.

Takedown of Pushdo would require legal intervention, the researchers say: VeriSign requires a court order before it takes action on its .com domain customers.

Damballa's full report on Pushdo is available here (PDF) for download, and Dell Secureworks' is here (PDF) for download.

Have a comment on this story? Please click "Add Your Comment" below. If you'd like to contact Dark Reading's editors directly, send us a message.

Kelly Jackson Higgins is Executive Editor at DarkReading.com. She is an award-winning veteran technology and business journalist with more than two decades of experience in reporting and editing for various publications, including Network Computing, Secure Enterprise ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Register for Dark Reading Newsletters
Dark Reading Live EVENTS
INsecurity - For the Defenders of Enterprise Security
A Dark Reading Conference
While red team conferences focus primarily on new vulnerabilities and security researchers, INsecurity puts security execution, protection, and operations center stage. The primary speakers will be CISOs and leaders in security defense; the blue team will be the focus.
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: " I think Google Doodle is getting a little out of control"
Current Issue
Security Vulnerabilities: The Next Wave
Just when you thought it was safe, researchers have unveiled a new round of IT security flaws. Is your enterprise ready?
Flash Poll
[Strategic Security Report] Assessing Cybersecurity Risk
[Strategic Security Report] Assessing Cybersecurity Risk
As cyber attackers become more sophisticated and enterprise defenses become more complex, many enterprises are faced with a complicated question: what is the risk of an IT security breach? This report delivers insight on how today's enterprises evaluate the risks they face. This report also offers a look at security professionals' concerns about a wide variety of threats, including cloud security, mobile security, and the Internet of Things.
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2017-0290
Published: 2017-05-09
NScript in mpengine in Microsoft Malware Protection Engine with Engine Version before 1.1.13704.0, as used in Windows Defender and other products, allows remote attackers to execute arbitrary code or cause a denial of service (type confusion and application crash) via crafted JavaScript code within ...

CVE-2016-10369
Published: 2017-05-08
unixsocket.c in lxterminal through 0.3.0 insecurely uses /tmp for a socket file, allowing a local user to cause a denial of service (preventing terminal launch), or possibly have other impact (bypassing terminal access control).

CVE-2016-8202
Published: 2017-05-08
A privilege escalation vulnerability in Brocade Fibre Channel SAN products running Brocade Fabric OS (FOS) releases earlier than v7.4.1d and v8.0.1b could allow an authenticated attacker to elevate the privileges of user accounts accessing the system via command line interface. With affected version...

CVE-2016-8209
Published: 2017-05-08
Improper checks for unusual or exceptional conditions in Brocade NetIron 05.8.00 and later releases up to and including 06.1.00, when the Management Module is continuously scanned on port 22, may allow attackers to cause a denial of service (crash and reload) of the management module.

CVE-2017-0890
Published: 2017-05-08
Nextcloud Server before 11.0.3 is vulnerable to an inadequate escaping leading to a XSS vulnerability in the search module. To be exploitable a user has to write or paste malicious content into the search dialogue.