Attacks/Breaches

8/30/2018
05:00 PM
Connect Directly
Twitter
LinkedIn
RSS
E-Mail
50%
50%

Botnets Serving Up More Multipurpose Malware

Attackers increasingly are distributing malware that can be used for a variety of different tasks, Kaspersky Lab says.

In a troubling trend for enterprises, an analysis of botnet activity in the first six months of 2018 shows that multifunctional malware tools are becoming increasingly popular among attackers.

Kaspersky Lab inspected more than 150 malware families and their modifications across some 60,000 botnets around the world and found that the share of multipurpose Remote Access Tools has almost doubled on botnets since the beginning of 2017 - from 6.5% to 12.2%.

The three most widespread of these RATs or backdoors—Njrat, DarkComet, and Nanocore—are all malware tools that attackers can relatively easily modify for different purposes or adapt for distribution in specific regions. Kaspersky Lab discovered Njrat to have command and control centers in 99 countries, mainly because of how easily attackers can use it to configure a personal backdoor with very little knowledge of malware development. Nanocore and DarkComet have C2 centers in over 80 countries for the same reason.

Similarly, Trojans capable of being modified and controlled by different command and control servers and used for different purposes were another category of malware that grew in Q1, though not quite as dramatically as RATs. Kaspersky Lab's analysis showed that the share of such Trojans increased from 32.9% in the second half of 2017 to around 34.3% in the first six months of 2018.

Over the same period, the proportion of single-purpose tools being distributed through botnets declined substantially. For example, the share of special-purpose banking Trojans distributed via botnets dropped over 9.2%, from around 22.5% in the second half of 2017 to 13.3% of all malicious files in the first half of 2018.

Similarly, the share of spamming bots, which are another category of single-purpose malware, dropped to 12.2% this year from almost 19% in H2 of 2017. DDoS bots—another category of single-purpose tool—followed a similar pattern dropping from around 3% in Q3 and Q4 last year to about 2.7% in the first six months of this year.

Botnets on a Budget

One factor driving the trend is the relatively high costs of operating a botnet, says Alexander Eremin, security expert at Kaspersky Lab. Bots can be costly, so botmasters are looking for every opportunity to make money from their malware tools. Multi-purpose malware allows bot owners to quickly adapt their network for different purposes: from delivering spam, for instance, to distributing banking Trojans and ransomware, he says.

"[The] trend is driven by significant botnet ownership costs. Criminals will attempt to take everything at the first chance," Eremin notes. "The emergence of multifunctional malware means that users need powerful protection as criminals try to steal users’ credentials, money, sensitive data, using the same malware sample."

Botnets increasingly are being used according to the needs of the operator at that time, so it is often difficult to identify the primary specialization of a botnet, he says.

The Kaspersky Lab report is the second in recent weeks to warn about an increase in multi-purpose and adaptive malware tools. Earlier this month security vendor Proofpoint said it had seen a recent increase in the use of modular downloaders that allow attackers to modify malware after it has been installed on a system.

Basically, the tools allow adversaries to fingerprint infected systems and then modify or update the malware based on items of interest that the downloader might identify on a system.

Modular malware like the multiple-purpose tools that Kaspersky Lab highlighted in its report this week is problematic for enterprises because of how it can be quickly adapted for a variety of different tasks.

Related Content:

 

Black Hat Europe returns to London Dec 3-6 2018  with hands-on technical Trainings, cutting-edge Briefings, Arsenal open-source tool demonstrations, top-tier security solutions and service providers in the Business Hall. Click for information on the conference and to register.

Jai Vijayan is a seasoned technology reporter with over 20 years of experience in IT trade journalism. He was most recently a Senior Editor at Computerworld, where he covered information security and data privacy issues for the publication. Over the course of his 20-year ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Crowdsourced vs. Traditional Pen Testing
Alex Haynes, Chief Information Security Officer, CDL,  3/19/2019
New Mirai Version Targets Business IoT Devices
Dark Reading Staff 3/19/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: Reading Schneier's Friday Squid Blog again?
Current Issue
5 Emerging Cyber Threats to Watch for in 2019
Online attackers are constantly developing new, innovative ways to break into the enterprise. This Dark Reading Tech Digest gives an in-depth look at five emerging attack trends and exploits your security team should look out for, along with helpful recommendations on how you can prevent your organization from falling victim.
Flash Poll
The State of Cyber Security Incident Response
The State of Cyber Security Incident Response
Organizations are responding to new threats with new processes for detecting and mitigating them. Here's a look at how the discipline of incident response is evolving.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-6149
PUBLISHED: 2019-03-18
An unquoted search path vulnerability was identified in Lenovo Dynamic Power Reduction Utility prior to version 2.2.2.0 that could allow a malicious user with local access to execute code with administrative privileges.
CVE-2018-15509
PUBLISHED: 2019-03-18
Five9 Agent Desktop Plus 10.0.70 has Incorrect Access Control (issue 2 of 2).
CVE-2018-20806
PUBLISHED: 2019-03-17
Phamm (aka PHP LDAP Virtual Hosting Manager) 0.6.8 allows XSS via the login page (the /public/main.php action parameter).
CVE-2019-5616
PUBLISHED: 2019-03-15
CircuitWerkes Sicon-8, a hardware device used for managing electrical devices, ships with a web-based front-end controller and implements an authentication mechanism in JavaScript that is run in the context of a user's web browser.
CVE-2018-17882
PUBLISHED: 2019-03-15
An Integer overflow vulnerability exists in the batchTransfer function of a smart contract implementation for CryptoBotsBattle (CBTB), an Ethereum token. This vulnerability could be used by an attacker to create an arbitrary amount of tokens for any user.