Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Attacks/Breaches

5/16/2013
05:30 PM
Connect Directly
Google+
Twitter
RSS
E-Mail
50%
50%

Pushdo Botnet Morphs To Elude Hunters

U.S., other national government agencies, contractors, and military networks found housing new Pushdo bots as botnet adds stealthier features to evade detection, takedown

A botnet of botnets that has been disrupted by researchers multiple times during the past few years has been retooled with features that make its detection more difficult and its takedown nearly impossible without legal action.

The Pushdo botnet -- which provides the infrastructure for other malware and botnets and spreads a malware downloader program that, in turn, drops Cutwail, Gameover Zeus, and BlackHole Trojans -- is now employing Domain Generation Algorithm (DGA) as a resilient backup command-and-control (C&C) infrastructure, RSA encryption to prevent researchers from taking over the botnet, and phony JPEG image files to hide C&C traffic.

Researchers with Damballa, Dell Secureworks, and Georgia Institute of Technology recently teamed to study this new variant of Pushdo, which was first spotted by Damballa and its homegrown DGA detection tool. Among the victims infected by Pushdo are several U.S. and other national government agencies, government contractors, and military networks, the researchers found.

"This is the most elaborate [move by a] botnet trying to hide its own command and communications," says Brett Stone-Gross, senior security researcher at Dell Secureworks, who helped Damballa confirm the C&C traffic it had spotted using DGA was Pushdo. "They added resiliency with the DGA, and along with that they implemented RSA encryption so researchers, law enforcement, or their rivals can't control the botnet and use it against itself. They are the only ones who can control their botnet," Stone-Gross says. All researchers can do is record IP addresses and metadata, he says.

And in the latest twist today -- possibly in response to the discovery of their new techniques features -- the Pushdo gang was spotted pushing yet another variant of the malware, one that generates .kz domains instead of .com domains, according to Seculert, which also is studying Pushdo. "It seems like they noticed that they are being probed, as the variants were uploaded to the hijacked webserver few hours before the report went public," says Aviv Raff, CTO at Seculert.

Pushdo, which is run by a well-funded Eastern European cybercrime gang, boasts anywhere from 175,000 to a half-million bots each day, and is spread mainly via the massive and prolific Cutwail spam botnet. Pushdo basically acts as the infrastructure for botnet activity -- everything from traditional spam to spreading malicious Trojan like Zeus and SpyEye that steal financial credentials. It's mostly spread via the massive Cutwail botnet and has survived four takedowns in five years.

"It shows that they probably make a good amount of money through spam email. It's like any business: It's important to maintain a resilient infrastructure, and if the infrastructure goes down, you lose money," Stone-Gross says.

The addition of DGA for its backup C&C basically allows Pushdo to prevent interference with its C&C -- think blacklisting or extracting C&C domain names -- by making the C&C domain names a moving target, dynamically generating domain names, and using just one at a time, which later gets discarded.

"They are trying to build a system that's immune to takedown," says Jeremy Demar, senior researcher at Damballa. Demar says Pushdo downloads encrypted malware payloads so researchers can't analyze them or detect them.

[Pushdo botnet's spam traffic cut by 80 percent in takedown. See Major Disruption of Pushdo Botnet Wasn't The Original Goal .]

Researchers saw some 1.1 million unique IP addresses making Pushdo C&C requests in a two-month period, and around 35,000 unique IPs connect each day. Pushdo's DGA generates around 1,380 unique domain names daily.

India and Iran are home to the most Pushdo-infected machines, but Mexico, Thailand, Indonesia, and the U.S. also have Pushdo bots. An average of 23,000 unique hosts in the U.S. have tried connecting to Pushdo's DGA domain names. The government and military victims -- which are a small percentage of the overall bot population -- likely were inadvertent infections, Damballa's Demar says. "Someone downloaded an email," he says.

The malware also generates fake traffic to legitimate websites in an attempt to mask its C&C communications. "The C&C servers will also respond with a jpeg image with encrypted, embedded malware payloads to hide any additional files it wants to download," Demar wrote in a blog post.

Takedown of Pushdo would require legal intervention, the researchers say: VeriSign requires a court order before it takes action on its .com domain customers.

Damballa's full report on Pushdo is available here (PDF) for download, and Dell Secureworks' is here (PDF) for download.

Have a comment on this story? Please click "Add Your Comment" below. If you'd like to contact Dark Reading's editors directly, send us a message.

Kelly Jackson Higgins is the Executive Editor of Dark Reading. She is an award-winning veteran technology and business journalist with more than two decades of experience in reporting and editing for various publications, including Network Computing, Secure Enterprise ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: Our Endpoint Protection system is a little outdated... 
Current Issue
The Year in Security: 2019
This Tech Digest provides a wrap up and overview of the year's top cybersecurity news stories. It was a year of new twists on old threats, with fears of another WannaCry-type worm and of a possible botnet army of Wi-Fi routers. But 2019 also underscored the risk of firmware and trusted security tools harboring dangerous holes that cybercriminals and nation-state hackers could readily abuse. Read more.
Flash Poll
Rethinking Enterprise Data Defense
Rethinking Enterprise Data Defense
Frustrated with recurring intrusions and breaches, cybersecurity professionals are questioning some of the industrys conventional wisdom. Heres a look at what theyre thinking about.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-19740
PUBLISHED: 2019-12-12
Octeth Oempro 4.7 allows SQL injection. The parameter CampaignID in Campaign.Get is vulnerable.
CVE-2019-19746
PUBLISHED: 2019-12-12
make_arrow in arrow.c in Xfig fig2dev 3.2.7b allows a segmentation fault and out-of-bounds write because of an integer overflow via a large arrow type.
CVE-2019-19748
PUBLISHED: 2019-12-12
The Work Time Calendar app before 4.7.1 for Jira allows XSS.
CVE-2017-18640
PUBLISHED: 2019-12-12
The Alias feature in SnakeYAML 1.18 allows entity expansion during a load operation, a related issue to CVE-2003-1564.
CVE-2019-19726
PUBLISHED: 2019-12-12
OpenBSD through 6.6 allows local users to escalate to root because a check for LD_LIBRARY_PATH in setuid programs can be defeated by setting a very small RLIMIT_DATA resource limit. When executing chpass or passwd (which are setuid root), _dl_setup_env in ld.so tries to strip LD_LIBRARY_PATH from th...