Advertisement
Promo

Security threats Toolkit

F-Secure sees smaller botnets on the rise

Gemma Simpson silicon.com

Published: 01 Oct 2007 09:23 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Cybercriminals are downsizing their botnets to try and trick software security companies.

Computers infected with a virus unknowingly become "zombies" in a botnet — which is a network used to send out spam and to mount further attacks on other machines. The zombie army can be controlled remotely, with the botnet creators usually trying to build the largest possible botnet of compromised computers to rent out to gangs for as little as $100 (£49) for a couple of hours.

But researchers at antivirus company F-Secure have reported seeing these large networks being broken down into smaller groups of compromised computers because the creation of large botnets is not creating as much revenue for such cybercriminals.

Mika Stahlberg, programme manager of the security response team at F-Secure, said the company is still seeing very big botnets around the world but coders are no longer trying to build as big a botnet as they can because that does not make any more money than a collection of smaller botnets.

The botnet bandits are also erring on the side of caution by steering away from larger botnets, because, if the central server controlling such a network goes down, then the whole of the botnet is lost, according to F-Secure.

Stahlberg added: "These people don't want to put all their eggs in one basket and are, therefore, running smaller botnets."

The malware writers are also getting lazy, according to F-Secure, and are no longer attempting to catch out companies by using increasingly complex viruses.

Read this

Feature
Feature: Locating the real threats to corporate security

With organised criminals seizing the opportunities of cybercrime, how accurate is the established belief that company insiders are the biggest threat to IT security?

Read more +

Sean Sullivan, technical expert at F-Secure, said virus writers can no longer beat security companies with complex codes and are therefore trying to do it through creating "malware factories" which swamp the security companies.

Sullivan added: "It used to be a big event when a virus came along, but now we get 10,000 [malware samples] a day, most of which are variations on the same code."

F-Secure employs a 16-strong response team in its Finnish headquarters to monitor and detect malware activity using tools such as a mobile-phone bunker to test viruses and a Google Earth mashup.

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Did you find this article useful?
3 out of 6 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:





Video icon

Video

Sentry Posts Blog

Malicious Mobile Apps a Growing Concer...

Malicious Mobile Apps a Growing Concern Author: Eric Everson, MBA, MSIT-SE The phrase “mobile security” does not usually mean much to anyone, until of course they encounter their... More

Post a comment

Malicious Mobile Code: What You Need t...

Malicious Mobile Code: What You Need to Know. Author: Eric Everson, MBA, MSIT-SE The thought of someone hacking into your mobile phone to steal your personal data added to the growing... More

1 comment

Bletchley Park calls for operators for...

The home of World War II codebreaking has called for engineers to operate an electro-mechanical machine developed by mathematician Alan Turing. The Turing Bombe was a brute-force... More

2 comments


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters