Welcome Guest. | Log In | Register | Membership Benefits

Up-And-Coming Botnet Uses Same Malware Kit As Defunct Mariposa

'Butterfly bot' kit steals financial information, but its licensing model could ultimately lead authorities to its newest botmasters

Jun 29, 2011 | 03:44 PM | 

By Kelly Jackson Higgins
Dark Reading
A financial-fraud botnet built with the same malware kit used in the now-defunct Mariposa botnet remains active after arrests this month of two Eastern European men who allegedly ran it.

Researchers at Unveillance, Panda Labs, and Damballa have been studying the botnet, which has been dubbed "EvilFistSquad" by Damballa and "Metulji" by Unveillance and Panda, for some time now. Unveillance and Panda Labs today announced that the botnet has hit businesses and individuals across 172 or more countries, including the U.S., Russia, Brazil, China, Great Britain, India, and Iran. The botnet uses the Butterfly Bot Kit, a.k.a. Palevo, Pilleuz, and Rimecud, the malware that was used by the Mariposa botnet.

According to translated news reports out of Eastern Europe earlier this month here, here, and here, the FBI worked with Interpol in the arrest of two suspected hackers, Aljosa Borkovic and Darko Malinic, in the so-called Operation Hive case. The two men allegedly used the so-called EvilFistSquad botnet to steal several hundred thousand dollars from victims' bank accounts around the world. Borkovic reportedly had been arrested a few years ago for cybercrime; he since had lived in a luxury apartment in Banja Luka in Bosnia and Herzegovina, and drove expensive cars.

Damballa, which has been tracking Butterfly-based command-and-control traffic since 2007, ranks EvilFistSquad at No. 28 in the most prevalent botnets in the U.S. as of the first quarter of this year.

"Across our customer base -- ISPs and large enterprises -- the number of unique machines in the U.S. that are currently live and communicating with the [EvilFistSquad] command-and-communications infrastructure is just under 60,000 machines," says Gunter Ollmann, vice president for research at Damballa. Ollmann says there are three other Butterfly-based botnets his firm is tracking as well, but they are relatively small.

Karim Hijazi, CEO and president at Unveillance, says his firm estimates that the Metulji botnet is bigger than Mariposa in its heyday -- possibly twice the size, he says -- but is still confirming actual bot counts. He doesn't believe there's a direct connection between the operators of this botnet and those of the former Mariposa. "At first glance, I don't think these guys were tied to the guys in Spain other than using a similar kit -- just far more successfully, from the looks of it," he says. "Metulji" is Slovenian for "butterfly."

Before Mariposa was taken down in early 2010, it was a massive global botnet with close to 13 million infected machines in more than 190 countries -- including those of half of all Fortune 1000 firms. The botnet harvested banking credentials, credit card information, account information from social networking sites and online email services, and other usernames and passwords. A team made up of law enforcement officials in Spain, the FBI, Panda Security, Defence Intelligence, and Georgia Tech cut off the Mariposa botnet's command-and-control (C&C) infrastructure in one day in December, ultimately leading to the arrest of the alleged head botmaster and two of his partners by Spanish authorities.

Mariposa infected machines via email and Web exploits, as well as via instant messaging and USB drives, which were the most successful modes of infection for Mariposa. Several months after the takedown, a hacker known as "Iserdo," who allegedly wrote the Mariposa virus, was arrested in Slovenia.

Meanwhile, researchers say the new Metulji/EvilFistSquad botnet uses Butterfly Bot malware to infect its victims, and then steals bank account credentials and other personal information. The worm spreads via removable drives, namely USB sticks. The researchers say that while some of the botnet's domains were taken down, several other domains are still up, running, and harvesting stolen information from victim machines.

"All we can say at the moment is that we are analyzing the few thousand binaries involved to determine the exact connection with the Slovenian Butterfly Framework creator and the different botmasters identified from the Mariposa case," says Pedro Bustamante, senior research adviser for Panda Security. "It is obvious that any Butterfly-based botnet out there is related to the Mariposa case in some way or another, as the creator of the botnet framework was arrested by the Slovenian police last year and is now most likely pending extradition to the U.S., thanks to the involvement of the FBI."

The good news is that when Mariposa was taken down, researchers discovered the licensing model inside the malware framework, which then provides nicknames of the botmasters who license the Butterfly bot malware.

"There are other Butterfly-botnets out there. The key here is that during the Mariposa case, we discovered the licensing mechanism inside the Butterfly framework, and we were able to get the framework creator arrested. This gave law enforcement the list of all Butterfly botnet operators around the world," Bustamante says. "... It is safe to assume that law enforcement has a very good insight into who is running any Butterfly-based botnet out there."

So why would botmasters use the same kit that ran the former Mariposa? "Obviously, those botmasters are either not concerned about going to jail or just plain stupid," he says.

Another clue that the perpetrators either weren't worried about, or aware of, getting caught: Unveillance researchers say one of the arrested men used the same email address to register multiple domains for the botnet, and even used his real name and address at times.

Have a comment on this story? Please click "Add Your Comment" below. If you'd like to contact Dark Reading's editors directly, send us a message.



Currently we allow the following HTML tags in comments:

Single tags

These tags can be used alone and don't need an ending tag.

<br> Defines a single line break

<hr> Defines a horizontal line

Matching tags

These require an ending tag - e.g. <i>italic text</i>

<a> Defines an anchor

<b> Defines bold text

<big> Defines big text

<blockquote> Defines a long quotation

<caption> Defines a table caption

<cite> Defines a citation

<code> Defines computer code text

<em> Defines emphasized text

<fieldset> Defines a border around elements in a form

<h1> This is heading 1

<h2> This is heading 2

<h3> This is heading 3

<h4> This is heading 4

<h5> This is heading 5

<h6> This is heading 6

<i> Defines italic text

<p> Defines a paragraph

<pre> Defines preformatted text

<q> Defines a short quotation

<samp> Defines sample computer code text

<small> Defines small text

<span> Defines a section in a document

<s> Defines strikethrough text

<strike> Defines strikethrough text

<strong> Defines strong text

<sub> Defines subscripted text

<sup> Defines superscripted text

<u> Defines underlined text

Dark Reading encourages readers to engage in spirited, healthy debate, including taking us to task. However, Dark Reading moderates all comments posted to our site, and reserves the right to modify or remove any content that it determines to be derogatory, offensive, inflammatory, vulgar, irrelevant/off-topic, racist or obvious marketing/SPAM. Dark Reading further reserves the right to disable the profile of any commenter participating in said activities.

Disqus Tips To upload an avatar photo, first complete your Disqus profile. | View the list of supported HTML tags you can use to style comments. | Please read our commenting policy.
Subscribe to RSS



Insider Threat Reports

report How to Prevent an Illicit Data Dump
There are no silver bullets when it comes to protecting company and customer data from loss or theft, but there are technological and procedural systems that will go a long way toward preventing a WikiLeaks-like data dump. Here are some tips and tricks to help protect your organization's most sensitive information.

report Email and Data Loss
Email encryption, rights management, email gateways, and full-on data loss prevention systems can keep corporate data secure. Here's a look at the pros and cons of each, to help you determine what?s best for your business.

report An Insider Threat Reality check
Heightened concern that users could inadvertently expose or leak -- or purposely steal -- an organization's sensitive data has spurred debate over the proper technology and training to protect the crown jewels. In this special retrospective of recent news coverage, Dark Reading takes a look at how organizations are handling the threat -- and what users are really up to.

Other reports from the Insider Threat Tech Center:

Related Content

Protection from Insider Threats
Preventing data misuse by trusted users is the most difficult information protection challenge. Insiders already have full authorization to the data, making traditional IT secure methods in effective. Learn about a more powerful security approach and proven strategies to prevent insider misuse.

Strategies for Protecting Intellectual Property
A company's intellectual property (IP) represents a significant portion of assets and a critical component of competitive differentiation, but the potential value of any IP is directly linked to its limit of acceptable use. Learn how you can put your IP to work within collaborative environments without undue risk and maximize competitive advantages.

Protecting Against WikiLeaks Type Events and the Insider Threat
The sensitive information supplied to WikiLeaks and other social justice websites comes from trusted insiders. Get the answers to the open gaps left in the WikiLeaks story and learn how you can prevent insider threats that are just as detrimental in your organization.

Insider Threat: An Inside Look at a Fortune 100 Company's Prevention Program
The ways and means by which a privileged user can successfully steal proprietary data today is staggering. One venerable company that suffered a devastating incident decided to do something about it. Find out how it built one of the most productive insider threat prevention programs in the Fortune 100.

Protection of Intellectual Property and Trade Secrets across a Global Enterprise
As a designer and manufacturer of industrial technology, this Fortune 50 company knew that securing their intellectual property (IP) and trade secret data was essential. It created a program to identify risks to their IP and trade secrets and soon caught a privileged user attempting to compromise IP. Download this case study to see a real example of intellectual property protection at work.




Featured Webcasts
Featured Whitepapers
Featured Reports