Microsoft: Kelihos botnet still down, new one emerging

Old Kelihos remains on 10,000 computers
  • Liam Tung (CSO Online (Australia))
  • — 06 February, 2012 14:20

Microsoft says the 41,000-strong Kelihos botnet it knocked out last year is still out of action, but clarified a new one is being developed using similar code.

Microsoft issued a statement last Friday clarifying confusion after Kaspersky Lab published a report, which noted the limitations to ending a botnet's life by disrupting and seizing its command infrastructure, as Microsoft, Kaspersky and Kyrus Tech had last September.

Commenting on the emergence of the emergence of a Kelihos bot, Kaspersky Lab researcher Maria Garnaeva wrote that its role in the take down, which focussed on "sinkholing" the botnet's traffic after its domain names were seized, was good at disrupting an operation but not effective if the bot masters were still at large.

Microsoft may have found at least one of the people in such a position after naming Russian software developer Andrey Sabelnikov as the maker of Kelihos -- an allegation he has denied and says he will fight.

Garnaeva also said it was "impossible to neutralise a botnet by taking control over the controller machines or substituting the controller list without any additional actions" since a botnet master could, if they knew the list of active router IPs, regain control of the network with a bot update.

Microsoft's Digital Crimes Unit senior attorney Richard Boscovich confirmed it had evidence of a new botnet, consisting of very similar code to the old Kelihos.

However, he added that "this does not mean that the Kelihos botnet we took down is back in operation, but that a new version of Kelihos malware known as ‘Backdoor: Wion32/Kelihos.B’ is being used to create a new botnet."

Since the take down of the first Kelihos botnet, Microsoft's Malicious Software Removal Tool (MSRT) -- which removes "actively running" viruses, worms and Trojans, but not dormant malware -- has removed Kelihos from 28,000 of the estimated 41,000 machines running the original bot.

Boscovich estimated the current size of the botnet's infected fleet to be less than 10,000, but could not give any estimate for the size of the new one.

The botnet was used to send spam, harvest user information and promote illegal websites, such as sites containing child exploitation material as well as counterfeit pharmaceuticals.

Follow @CSO_Australia

Tags: Kelihos, Kelihos botnet, Microsoft

Comments

Post new comment

The content of this field is kept private and will not be shown publicly.
Users posting comments agree to the CSO comments policy.
Login or register to link comments to your user profile, or you may also post a comment without being logged in.
CSO Corporate Partners
  • FirEye
  • Clear Swift
  • Trend Micro
  • Sophos
  • NetIQ
rhs_login_lockGet exclusive access to CSO, invitation only events, reports & analysis.
CSO Directory

Security Risk Management Solutions

Protect resources and ensure security compliance through incident detection, response, and remediation.

Security Awareness Tip
Clearswift tips: Guidelines for introducing and policing an effective IT Policy

1. Make it clear that the policy is not about playing ‘Big Brother’ but to ensure the security of employees, company information and data and to safeguard the company’s reputation.
2. Invest time to get buy-in from managers and their teams.
3. Convey the message of flexibility – with regard to social media, it is not about blocking staff usage but working in everyone’s interests to ensure that threats are contained.
4. Introduce a regular company-wide training programme that everyone attends at regular intervals throughout the year, not merely as part of an induction programme.
5. Within the training programme make sure that there are specific examples to demonstrate each rule or regulation, and that there is a clear explanation of the dangers of casual or careless talk on social networking sites. Again use examples, employees need to understand the consequences of raising a throwaway comment that has negative connotations for the business, as much as they need to be aware of dangers of making a more direct but ill-considered attack on a competitor, regulator or even a fellow colleague. They need to be clearly advised on any impact on the company and/or legal action or inquires that may be raised as a result.
6. Alert employees to any changes in policy through regular clear communication.
7. Reinforce the operational policy guidelines regularly, cover everything from blogging to Facebook, LinkedIn and Twitter.
8. Ensure that the rules are fair and that they apply throughout the business.
9. Enforce the rules – if there is a deliberate or malicious contravening, disciplinary action needs to be taken. A policy isn’t worth having if it is seen to be lax and unenforced.
10. Review the policy regularly to ensure you keep up to date with new systems and technology.

Phil Vasic is Regional Director, APAC, at Clearswift, the software security company www.clearswift.com
Security ABC Guides

7 Ways to Protect Your Business Printers

Can a hacker burn down your business by remotely setting one of your printers on fire? Researchers at Columbia University have recently proposed such a scenario, although HP quickly denied that it's possible. However, even if your printers can't be used as remote firestarters, there are many risks involved in networking a printer.