Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.


06:40 PM
Connect Directly

Number of Botnet Command & Control Servers Soared in 2019

Servers worldwide that were used to control malware-infected systems jumped more than 71% compared to 2018, Spamhaus says.

For the second year in a row, the number of servers used by attackers worldwide to control malware-infected systems increased sharply.

The Spamhaus Project, which tracks both the domain names and the IP addresses used by threat actors for hosting botnet command-and-control servers (C2), identified 17,602 such servers hosted on a total of 1,210 different networks worldwide in 2019.

The number represented a big 71.5% jump over the 10,263 botnet C2 servers that Spamhaus detected and blocked in 2018, and a near doubling in number from the 9,500 servers in 2018. Botnet C2s, in fact, accounted for 41% of all the listings on Spamhaus' block list in 2019, compared to just 15% in 2017 and 25% last year.

The sharp increase is an indication of the growing popularity of botnets as an attack vector among threat actors, Spamhaus said in a report this week. About 60% of the new botnet C2s that Spamhaus detected in 2020 were associated with credential-stealing malware such as Lokibot and AZORult. About 20% -- the next highest proportion -- were used to control data-stealing Remote Access Trojans (RATs), the most prolific of which was Nanocore.

The Spamhaus Block List (SBL) is a real-time database of IP addresses and URLs associated with known spam sources and threats like botnet C2s. Companies and ISP can use the database tandem with other block lists to block spam and other online threats.

As with previous years, Spamhaus' data showed that some of the ISPs that hosted the highest number of botnet C2s last year were based in the United States. Over 1,580 botnet servers in 2019, for instance, were hosted on Cloudflare alone -- more than double the 629 hosted by second-place Alibaba of China.

In many cases, the command-and-control servers were running on compromised websites and servers belonging to customers of ISPs such as Cloudflare. This likely made it difficult for them to spot the illegal activity. But a substantial proportion were also set up via fraudulent registrations, as a result of weaknesses in the ISPs customer-vetting and verification processes, Spamhaus said.

But for the first time ever, Russia took the top spot among countries hosting the most number of command-and-control servers. The number of botnet C2s in the country soared 143% over 2018 to 4,712, compared to 4,007 in the United States.

Lax Customer Vetting

Spamhaus attributed the increase in Russia to threat actors taking advantage of the relatively lax registration procedures among Internet Service Providers in the country. China, too, leapt up the charts from 13th spot in 2018 to the fourth spot last year with 770 servers, an increase that Spamhaus attributed to lax registration procedures as well.

US-based Namecheap was once again the most abused domain registrar, with almost 25% of all botnet C2s detected and blocked last year - all registered via the company. But China and Russia both had more registrars on the top 20 list last year than the US. "They are mostly being legitimately abused," says Vincent Hanna, a researcher at The Spamhaus Project. "The registrar market is one of very thin margins and lots of automation. Neither leaves much space for careful vetting of customers and orders."

According to Spamhaus, its botnet data from 2019 showed that ISPs in the East in general are lagging behind their Western counterparts when it comes to sign-up procedures and in enforcement of their terms and conditions.

Western companies on the list of ISPs hosting the most botnet C&Cs have a high volume, but they are few in number. "At the same time many more eastern companies have fraudulent customers, signaling that abuse procedures and customer-vetting problems are more widespread there, and not limited to a handful of companies," Hanna says.

The most abused Top Level Domains (TLDs) in 2019 were the .com and .net domains. More than 50% of botnet C2s were hosted on these two domains alone. Other heavily abused TLDs included dot ru, dot info, dot cm, and dot pw, the top level domain for Palau. Several other previously abused domains however fell off the most abused list including, .review, .stream, .bid, and .trade.

For registrars and ISPs, careful customer vetting is key. "Finding the fraudulent registrations is often not that hard, but it needs to be done," Hanna says. "Registries that care about the reputation of the entire TLD will proactively go out and try to find problematic registrations themselves."

Related Content:

Botnets Serving Up More Multipurpose Malware

What's in a Botnet? Researchers Spy on Geost Operators

MasterMana Botnet Shows Trouble Comes at Low Cost

8 Ways Businesses Unknowingly Help Hackers

Jai Vijayan is a seasoned technology reporter with over 20 years of experience in IT trade journalism. He was most recently a Senior Editor at Computerworld, where he covered information security and data privacy issues for the publication. Over the course of his 20-year ... View Full Bio

Recommended Reading:

Comment  | 
Print  | 
More Insights
Newest First  |  Oldest First  |  Threaded View
Inside the Ransomware Campaigns Targeting Exchange Servers
Kelly Sheridan, Staff Editor, Dark Reading,  4/2/2021
Beyond MITRE ATT&CK: The Case for a New Cyber Kill Chain
Rik Turner, Principal Analyst, Infrastructure Solutions, Omdia,  3/30/2021
Register for Dark Reading Newsletters
White Papers
Current Issue
2021 Top Enterprise IT Trends
We've identified the key trends that are poised to impact the IT landscape in 2021. Find out why they're important and how they will affect you today!
Flash Poll
How Enterprises are Developing Secure Applications
How Enterprises are Developing Secure Applications
Recent breaches of third-party apps are driving many organizations to think harder about the security of their off-the-shelf software as they continue to move left in secure software development practices.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
PUBLISHED: 2021-04-10
A command execution vulnerability in SonicWall GMS 9.3 allows a remote unauthenticated attacker to locally escalate privilege to root.
PUBLISHED: 2021-04-09
Zoom Chat through 2021-04-09 on Windows and macOS allows certain remote authenticated attackers to execute arbitrary code without user interaction. An attacker must be within the same organization, or an external party who has been accepted as a contact. NOTE: this is specific to the Zoom Chat softw...
PUBLISHED: 2021-04-09
Use after free in screen sharing in Google Chrome prior to 89.0.4389.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
PUBLISHED: 2021-04-09
Use after free in V8 in Google Chrome prior to 89.0.4389.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
PUBLISHED: 2021-04-09
Heap buffer overflow in TabStrip in Google Chrome on Windows prior to 89.0.4389.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.