Welcome Guest. | Log In | Register | Membership Benefits
  • |   Email this page E-mail
  • |  Print Print
  • |   Bookmark and Share

Malware-Serving ISP Taken Down, Researchers Say

'Troyak' went dark overnight, cutting off service to many Zeus botnets

Mar 11, 2010 | 04:48 PM | 

By Tim Wilson

A network frequently used for malware delivery was shut down last night, probably against the will of its operators.

Troyak.org, a Kazakhstani "Internet service provider" well-known for serving Zeus botnets and other malware delivery methods, went dark overnight, resulting in the shutdown of as many as 25 percent of the world's Zeus botnets, according to researchers at Cisco's ScanSafe and RSA's FraudAction security research units.

The two groups of researchers did not definitively agree on the cause of the outage, but they agreed one likely source is backbone network service providers, possibly working with law enforcement agencies, which might have taken the action to cut service off from botnets and malware distributors.

Less than 24 hours after the outage, many components of the ISP began to operate again. But malware delivery has temporarily dropped off significantly across the Web, and it's likely the Troyak network is at least crippled, the researchers say.

"There are those who say that a takedown like this doesn't do much good because the network can get back into service fairly quickly, but I disagree," says Mary Landesman, head security researcher at ScanSafe. "A shutdown hits criminals where it hurts the most -- in the wallet. Rising costs will become a deterrent to some of this activity."

According to Sean Brady, product manager for the Identity Protection & Verification Group at RSA, Troyak is an upstream provider for several smaller malware-bearing "ISPs."

"Up until midday Tuesday, these networks, some of which are well-known 'bulletproof' hosting services, hosted a great number of malware-hosting servers," according to an RSA report. "[Troyak] connected dozens of malware servers to the Internet, including the Rock Phish gang's JabberZeus drop server, Gozi Trojan servers, as well as many of the Trojan infection and drop servers that RSA regularly monitors."

Landesman suggests the effort to go upstream to stop malware delivery, typically through network service providers, could be a step in the right direction. Microsoft took action to cut activity on the Waledac botnet earlier this month, she notes.

"In addition to adding costs for the criminals, it also increases awareness at the service-provider level," Landesman says. "It's becoming harder for service providers to turn a blind eye to criminal activity that's taking place on their networks."

Brady concurs. "It's analogous to going after organized crime -- you have to go after the money," he says. "Even if it's short-lived, this is a positive development for IT."

Have a comment on this story? Please click "Discuss" below. If you'd like to contact Dark Reading's editors directly, send us a message.



Currently we allow the following HTML tags in comments:

Single tags

These tags can be used alone and don't need an ending tag.

<br> Defines a single line break

<hr> Defines a horizontal line

Matching tags

These require an ending tag - e.g. <i>italic text</i>

<a> Defines an anchor

<b> Defines bold text

<big> Defines big text

<blockquote> Defines a long quotation

<caption> Defines a table caption

<cite> Defines a citation

<code> Defines computer code text

<em> Defines emphasized text

<fieldset> Defines a border around elements in a form

<h1> This is heading 1

<h2> This is heading 2

<h3> This is heading 3

<h4> This is heading 4

<h5> This is heading 5

<h6> This is heading 6

<i> Defines italic text

<p> Defines a paragraph

<pre> Defines preformatted text

<q> Defines a short quotation

<samp> Defines sample computer code text

<small> Defines small text

<span> Defines a section in a document

<s> Defines strikethrough text

<strike> Defines strikethrough text

<strong> Defines strong text

<sub> Defines subscripted text

<sup> Defines superscripted text

<u> Defines underlined text

Dark Reading encourages readers to engage in spirited, healthy debate, including taking us to task. However, Dark Reading moderates all comments posted to our site, and reserves the right to modify or remove any content that it determines to be derogatory, offensive, inflammatory, vulgar, irrelevant/off-topic, racist or obvious marketing/SPAM. Dark Reading further reserves the right to disable the profile of any commenter participating in said activities.

Disqus Tips To upload an avatar photo, first complete your Disqus profile. | View the list of supported HTML tags you can use to style comments. | Please read our commenting policy.
Subscribe to RSS



Security Services Reports

report Hosted Web Security Services: Block Malware Before Your Border
Security service providers are now delivering a wide range of packaged offerings, including Web content filtering, anti-malware, data leak prevention, and many other capabilities. How can your organization take advantage of these Web security services, and how can you choose the right provider? This Dark Reading Tech Center report offers a look at these services and some recommendations on how best to implement them.

report You've Got (Secure) Mail: Using Service Providers to Boost Protection
The SaaS market is still in its infancy, but hosted e-mail security firms are leading the way, thanks to ease of implementation and many obvious benefits. Still, these services are not without risks. In this Dark Reading Tech Center report, we'll discuss how to determine what mix of in-house and hosted email security makes sense for your organization.

report Security Services Strategies For Small and Midsize Firms
Infosec managers in small and midsize enterprise often feel like an army of one, constantly pinching pennies. But the paradigm shift from expensive on-premises management to off-premises hosting is good news for you, because today more than ever, the small business has access to large-enterprise security technologies via the phenomenon of subscription-based licensing. In this report, you'll discover how you can use security services strategically to gain economies of scale -- and a really deep bench.

Other reports from the Security Services Tech Center: