Malware's next trick

Daily Newsletters

Sign up to ZDNet UK's daily newsletter.

ANALYSIS

In January this year, 20-year-old Jeanson James Ancheta pleaded guilty in a California court to charges that he had broken into government computers and taken control of them for purposes of fraud.

He had planted software on the systems at the China Lake Naval Facility in California's Mojave Desert, enabling him to manipulate computers on the network there. He had then used the computers to generate hits on Web site advertisements, for which the advertisers paid according to the traffic they received.

It sounds like an overelaborate and harmless prank, except that Ancheta admitted the scam had netted him $60,000 before it had been detected.

Furthermore, it emerged that he controlled some 400,000 computers around the world, which he could manipulate remotely to do his bidding — to generate advertisement traffic, to send out infected software to more vulnerable computers, to pump out spam.

Ancheta is typical of the new breed of criminal on the Internet, motivated by money and determined to work by stealth. The malware they plant on unsuspecting users' machines do not draw attention to themselves, but once installed, they work as slaves to their remote masters.

Users are rarely aware that their machines have been hijacked. The system continues to work, albeit slightly more slowly at times, and they have no control over the secret tasks it is being asked to perform.

Botnets, which are armies of these hijacked computers, have become the predominant feature of the Internet threat landscape. According to security company CipherTrust, more than 180,000 PCs are turned into zombies every day, and that figure is continually rising.

The botnets are used by their owners to defraud Internet advertisers, as in Ancheta's case, or they can be rented out by the hour to those who want to carry out cheap mass-mailing campaigns. Extortionists may also rent them to launch DDoS attacks on legitimate Web sites.

These professional operations are taking over where the traditional hobbyist hackers left off. "We are seeing less of the big virus outbreaks such as Sasser and Blaster, and so some people believe the situation is getting better, when in fact it is getting worse," said Mikko Hyppönen, chief research officer at security company F-Secure. "The bad boys are getting more professional and doing more targeted attacks."

He sees botnets as a major problem that cannot be easily fixed, because the hijacked machines are mostly home PCs connected to a broadband line. "It takes a lot of end-user support to explain to a grandmother how to configure the computer. So most ISPs are not doing anything about it," he said.

New phishing grounds
Most analysts forecast that phishing attacks too will continue to grow in number and in sophistication.

David Sancho, an antivirus engineer Trend Micro, gave an example of a recent attack in Germany which pretended to come from an electricity company. It asked recipients to check their bill by clicking on an attached PDF document, which is how the genuine electricity company operates. But the attachment in this case had a suffix of .pdf.exe, was actually a Trojan horse that planted spyware on the user's PC.

"Once active, it monitors every Internet connection, every access to Web pages and access to the bank, and reports it back to the creator of the Trojan," Sancho said. "It is smarter, because they don't have to set up a fake server."

F-Secure's Hyppönen also forecast that phishers will find ways to crack the one-time passwords that some banks have introduced as a security measure. In one case, the user has a list of authorisation codes on a slip of paper sent by the bank.

"The target is fooled into logging into a fake bank, where they ask for his authorisation code. The fake bank logs into the real bank with the one-time password and moves money around. Then it gets back to the customer, says there has been a problem and asks him to give the next code," Hyppönen said.

The biggest problem for the phishers, he said, is finding new suckers to fool. As more people become aware of phishing attacks, the attackers are going for smaller targets and into different languages, such as Greek, Czech and Finnish.

While Windows PCs remain the prime target for attacks, prepare to see more activity targeted at the mobile phone. F-Secure says it has now detected 179 mobile phone viruses and estimates that some tens of thousands of handsets are infected.

Nokia has reacted by launching handsets with antivirus protection built in, and the newly released version nine of the Symbian operating system has improved security, so it may be possible to nip some mobile viruses in the bud.

Or maybe not. F-Secure recently detected the first malicious Java software on a mobile phone, meaning it could affect most handsets, and not just the high-end models, Hyppönen said. And in March, he spotted a Trojan horse that plants itself on the mobile phone and calls a premium rate number in Russia, each time clocking up €5 (£3) for the criminal who sent it.

Even so, the rapidly growing world population of broadband users means that botnets will continue to be the main focus for Internet criminals. All of the people in the Rogues Gallery of the world's top 10 spammers, on the Spamhaus Project Web site, are constantly topping up their networks with new zombie machines owned by people with little concept of security. And they do not restrict themselves to mass emailing — their activities extend into child pornography, extortion and fraud.

And botnets open up another danger, according to Dave Rand, chief technologist for Internet content security at Trend Micro. Their combined computing power could be used to decrypt Internet traffic, he says. If that were to happen (and there is no sign of it yet), it could bring e-commerce to a grinding halt.

Post your comment

In order to post a comment you need to be registered and logged in.

You can also log in with Facebook. Log in or create your ZDNet UK account below

  • Login

Will not be displayed with your comment

By signing up for this service, you indicate that you agree to our Terms and Conditions and have read and understood our Privacy Policy. Questions about membership? Find the answers in the Community FAQ

Get ZDNet UK's daily newsletter

Enter your email address to sign up

ZDNet UK Live

Freebies202

Duplicate comments are not made intentionally. Its very good to know that now you are keeping check on this problem because sometimes a commenter...

7 hours ago by Freebies202 on Microsoft fixes blog comments, speeds up blogs with open source
kevinmchapman

"the very significant number of users" and "many (most) of us" - you have no evidence for these statements. It is a fact that most users are saying...

15 hours ago by kevinmchapman on A tale of two distros: Ubuntu and Linux Mint
Marg Menzies Harrison

Another grammar faux pas is the improper use of "you". When sitting down down in a restaurant, for example, I get cringe when the waitress...

17 hours ago by Marg Menzies Harrison via Facebook on 10 flagrant grammar mistakes that make you look stupid
zdnetukuser

And NOW, folks, for Canonical's next trick... Kubuntu is late. Here's a pencil. Draw your own conclusions. cf.:...

17 hours ago by zdnetukuser on Linux Minterface
Moley

@kevinmchapman. The discussion here reflects the very significant number of users who really do like the traditional menu system and who wish to...

19 hours ago by Moley on A tale of two distros: Ubuntu and Linux Mint
kevinmchapman

Er, no... It is an efficient means of finding the application/file/setting you need in one place. The icons are a simply a fallback for when you...

21 hours ago by kevinmchapman on A tale of two distros: Ubuntu and Linux Mint
TerryRK

Isn't the provision of a text based search an admission by the developers that the mass of icons approach does not work? I don't need to use a...

22 hours ago by TerryRK on A tale of two distros: Ubuntu and Linux Mint
kevinmchapman

"Unity and GNOME 3 both abandon the old text-based cascading menus in favour of a graphical icon-driven system." Point truly missed. Both use a...

23 hours ago by kevinmchapman on A tale of two distros: Ubuntu and Linux Mint
TerryRK

whs001 - Thank you, I'm glad you liked the article. I absolutely agree with you on your first point. I should perhaps have made it clearer that...

23 hours ago by TerryRK on A tale of two distros: Ubuntu and Linux Mint
Dennis Nilsson

If we allow corporate interest to dictate the way our government circumvents due process against foreign entities then we should accept the same...

24 hours ago by Dennis Nilsson via Facebook on ACTA stumbles in Germany
GHar123

I totally dislike pirating of works, I fear that artists will be deterred from creating works if they think that they are going to get ripped off....

1 day ago by GHar123 on ACTA stumbles in Germany
JCB33

How dare film makers, artists or anybody that invests in creativity stop us pirating their works for free. I want to be able to walk into my local...

1 day ago by JCB33 on ACTA stumbles in Germany
Moley

@GrueMaster. I prefer horses for courses rather than one size fits all. I, and I suspect most other computer users, do not really wish to have...

1 day ago by Moley on A tale of two distros: Ubuntu and Linux Mint
greycynic

The product that scares me every time I have to use it is the Office 2007 version of Excel. The first bug that I found was applying the median...

1 day ago by greycynic on Ten flawed products that derail productivity
GrueMaster

Nice review and very informative. One thing I'd like to add (in reply to whs001's 1st question), the main reason to have the same interface from...

1 day ago by GrueMaster on A tale of two distros: Ubuntu and Linux Mint
Frederick Wrigley

I'be been using Mint 12 since the RC came out, and I am far more happy with the Cinnamon, the Mate, and, yes (with extensions), theGnome 3...

1 day ago by Frederick Wrigley via Facebook on A tale of two distros: Ubuntu and Linux Mint
bdantas

Excellent article. One small correction, though--although a fresh installation of Linux Mint 12 will, indeed, provide the user with a version of...

2 days ago by bdantas on A tale of two distros: Ubuntu and Linux Mint
Alan Ralph

In related news, the ISPs club together to get the members of the Home Affairs Select Committee (ya goofed on that part, ZDNet UK) copies of "The...

2 days ago by Alan Ralph via Facebook on MPs urge ISPs to take down terrorist material
Alan Ralph

In related news, the ISPs club together to get the members of the Home Affairs Select Committee (ya goofed on that part, ZDNet UK) copies of "The...

2 days ago by Alan Ralph via Facebook on MPs urge ISPs to take down terrorist material
Moley

For Gnome 2 die-hards, it is possible to add icons to the bottom panel (or top top panel, if you prefer) which provide the exact Gnome 2...

2 days ago by Moley on A tale of two distros: Ubuntu and Linux Mint