Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.


06:40 PM
Connect Directly

Number of Botnet Command & Control Servers Soared in 2019

Servers worldwide that were used to control malware-infected systems jumped more than 71% compared to 2018, Spamhaus says.

For the second year in a row, the number of servers used by attackers worldwide to control malware-infected systems increased sharply.

The Spamhaus Project, which tracks both the domain names and the IP addresses used by threat actors for hosting botnet command-and-control servers (C2), identified 17,602 such servers hosted on a total of 1,210 different networks worldwide in 2019.

The number represented a big 71.5% jump over the 10,263 botnet C2 servers that Spamhaus detected and blocked in 2018, and a near doubling in number from the 9,500 servers in 2018. Botnet C2s, in fact, accounted for 41% of all the listings on Spamhaus' block list in 2019, compared to just 15% in 2017 and 25% last year.

The sharp increase is an indication of the growing popularity of botnets as an attack vector among threat actors, Spamhaus said in a report this week. About 60% of the new botnet C2s that Spamhaus detected in 2020 were associated with credential-stealing malware such as Lokibot and AZORult. About 20% -- the next highest proportion -- were used to control data-stealing Remote Access Trojans (RATs), the most prolific of which was Nanocore.

The Spamhaus Block List (SBL) is a real-time database of IP addresses and URLs associated with known spam sources and threats like botnet C2s. Companies and ISP can use the database tandem with other block lists to block spam and other online threats.

As with previous years, Spamhaus' data showed that some of the ISPs that hosted the highest number of botnet C2s last year were based in the United States. Over 1,580 botnet servers in 2019, for instance, were hosted on Cloudflare alone -- more than double the 629 hosted by second-place Alibaba of China.

In many cases, the command-and-control servers were running on compromised websites and servers belonging to customers of ISPs such as Cloudflare. This likely made it difficult for them to spot the illegal activity. But a substantial proportion were also set up via fraudulent registrations, as a result of weaknesses in the ISPs customer-vetting and verification processes, Spamhaus said.

But for the first time ever, Russia took the top spot among countries hosting the most number of command-and-control servers. The number of botnet C2s in the country soared 143% over 2018 to 4,712, compared to 4,007 in the United States.

Lax Customer Vetting

Spamhaus attributed the increase in Russia to threat actors taking advantage of the relatively lax registration procedures among Internet Service Providers in the country. China, too, leapt up the charts from 13th spot in 2018 to the fourth spot last year with 770 servers, an increase that Spamhaus attributed to lax registration procedures as well.

US-based Namecheap was once again the most abused domain registrar, with almost 25% of all botnet C2s detected and blocked last year - all registered via the company. But China and Russia both had more registrars on the top 20 list last year than the US. "They are mostly being legitimately abused," says Vincent Hanna, a researcher at The Spamhaus Project. "The registrar market is one of very thin margins and lots of automation. Neither leaves much space for careful vetting of customers and orders."

According to Spamhaus, its botnet data from 2019 showed that ISPs in the East in general are lagging behind their Western counterparts when it comes to sign-up procedures and in enforcement of their terms and conditions.

Western companies on the list of ISPs hosting the most botnet C&Cs have a high volume, but they are few in number. "At the same time many more eastern companies have fraudulent customers, signaling that abuse procedures and customer-vetting problems are more widespread there, and not limited to a handful of companies," Hanna says.

The most abused Top Level Domains (TLDs) in 2019 were the .com and .net domains. More than 50% of botnet C2s were hosted on these two domains alone. Other heavily abused TLDs included dot ru, dot info, dot cm, and dot pw, the top level domain for Palau. Several other previously abused domains however fell off the most abused list including, .review, .stream, .bid, and .trade.

For registrars and ISPs, careful customer vetting is key. "Finding the fraudulent registrations is often not that hard, but it needs to be done," Hanna says. "Registries that care about the reputation of the entire TLD will proactively go out and try to find problematic registrations themselves."

Related Content:

Botnets Serving Up More Multipurpose Malware

What's in a Botnet? Researchers Spy on Geost Operators

MasterMana Botnet Shows Trouble Comes at Low Cost

8 Ways Businesses Unknowingly Help Hackers

Jai Vijayan is a seasoned technology reporter with over 20 years of experience in IT trade journalism. He was most recently a Senior Editor at Computerworld, where he covered information security and data privacy issues for the publication. Over the course of his 20-year ... View Full Bio

Recommended Reading:

Comment  | 
Print  | 
More Insights
Newest First  |  Oldest First  |  Threaded View
Overcoming the Challenge of Shorter Certificate Lifespans
Mike Cooper, Founder & CEO of Revocent,  10/15/2020
US Counterintelligence Director & Fmr. Europol Leader Talk Election Security
Kelly Sheridan, Staff Editor, Dark Reading,  10/16/2020
7 Tips for Choosing Security Metrics That Matter
Ericka Chickowski, Contributing Writer,  10/19/2020
Register for Dark Reading Newsletters
White Papers
Current Issue
Special Report: Computing's New Normal
This special report examines how IT security organizations have adapted to the "new normal" of computing and what the long-term effects will be. Read it and get a unique set of perspectives on issues ranging from new threats & vulnerabilities as a result of remote working to how enterprise security strategy will be affected long term.
Flash Poll
How IT Security Organizations are Attacking the Cybersecurity Problem
How IT Security Organizations are Attacking the Cybersecurity Problem
The COVID-19 pandemic turned the world -- and enterprise computing -- on end. Here's a look at how cybersecurity teams are retrenching their defense strategies, rebuilding their teams, and selecting new technologies to stop the oncoming rise of online attacks.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
PUBLISHED: 2020-10-21
Prior to 0.10.0-beta, LND (Lightning Network Daemon) would have accepted a counterparty high-S signature and broadcast tx-relay invalid local commitment/HTLC transactions. This can be exploited by any peer with an open channel regardless of the victim situation (e.g., routing node, payment-receiver,...
PUBLISHED: 2020-10-21
Prior to 0.11.0-beta, LND (Lightning Network Daemon) had a vulnerability in its invoice database. While claiming on-chain a received HTLC output, it didn't verify that the corresponding outgoing off-chain HTLC was already settled before releasing the preimage. In the case of a hash-and-amount collis...
PUBLISHED: 2020-10-20
Cross-site request forgery in Nagios XI 5.7.3 allows a remote attacker to perform sensitive application actions by tricking legitimate users into clicking a crafted link.
PUBLISHED: 2020-10-20
Improper neutralization of special elements used in an OS command in Nagios XI 5.7.3 allows a remote, authenticated admin user to execute operating system commands with the privileges of the apache user.
PUBLISHED: 2020-10-20
Improper neutralization of argument delimiters in a command in Nagios XI 5.7.3 allows a remote, authenticated admin user to write to arbitrary files and ultimately execute code with the privileges of the apache user.