Welcome | Sign In
CRMBuyer.com
Applications

Malware Writers Using Open-Source Tactics

Print Version
E-Mail Article
Reprints
Malware Writers Using Open-Source Tactics

Among the devilish deeds that can be perpetrated by Trojans is the creation of "zombie networks" -- networks typically composed of home computers surreptitiously controlled by a badware's author. "We estimate that spam zombie networks are responsible for from anywhere to 25 to 30 percent of the spam on the Internet today, and it's growing," said Scott Chasin, CTO of e-mail defense solutions company MX Logic.


To thrive in today’s highly competitive business environment, you need innovative approaches to attract and retain customers. Click here to see how Salesforce.com, West Marine, and VForce-AAA Ohio use LiveOps to optimize their customer experiences.

The techniques used to develop open-source software like Linux have proven to be so effective that they've been adopted by malware writers to improve their mischievous ways.

"There's a community of worm builders creating, almost in an open-source fashion, Trojan source code that can be downloaded, compiled and released into the wild," said Scott Chasin, CTO of e-mail defense solutions company MX Logic in Denver, Colorado.

"A lot of these Trojans and their variants borrow from the open-source industry and are built off a community effort in an underground environment," he told LinuxInsider.

Click here for LiveOps

Zombie Networks

Among the devilish deeds that can be perpetrated by Trojans is the creation of "zombie networks" -- networks typically composed of home computers surreptitiously controlled by a badware's author.

Those networks are currently a prime delivery vehicle for spammers, according to Chasin. "We estimate that spam zombie networks are responsible for from anywhere to 25 to 30 percent of the spam on the Internet today, and it's growing," he maintained.

Some analysts peg the contribution of zombie networks to the spread of spam even higher. A report released in June by Sandvine, a broadband security firm in Waterloo, Ontario, Canada, estimated that as much as 80 percent of all unsolicited marketing e-mail emanates from residential ISP networks and home PCs.

Rich Target

"The collaboration between spammers and worm authors and a rich target environment of insecure PCs with broadband connections has created an opportunity for the continued existence of Trojan networks," Chasin observed.

Greater reliance by spammers on the zombies has created a cash market for the networks. A network of 20,000 zombies was reported by USA Today selling for US$2,000 to $3,000.

"Every person that does this kind of activity pretty much sets their own price," noted Joe Stewart, a senior security researcher at the Myrtle Beach, South Carolina, offices of LURHQ, a managed security services provider.

"It's what an individual author wants for his network," he told LinuxInsider. "It doesn't cost them anything to do what they're so they're talking 100 percent profit no matter what they charge."

Sanvine Cofounder and Chief Architect Don Bowman explained that zombie network creators have had to adopt their systems over time to counter defense measures taken against them.

Comcast Closes Door

A common defense adopted by ISPs is to monitor activity on port 25, the port most commonly used by spammers to avoid an ISP's outbound mail servers and ship their annoying payloads directly to other ISP's inbound servers.

If an ISP sees an unusual volume of mail emanating from one of its users on port 25, it will turn off that user's access to the port.

The technique can be quite effective. After it began a program in June to shut down port 25 to spammers, Philadelphia-based Comcast (Nasdaq: CMCSK), the nation's largest broadband ISP, reduced unsolicited e-mail originating on its network by 80 percent, spokesperson Jeanne Russo told LinuxInsider.

"Port 25 can be an open door for a spammer," she said. "By blocking port 25, we close that door. That makes a user less attractive to a spammer because they can't get their spam out."

Spammers Adapt

To counter port 25 measures, Bowman explained, zombie operators have tried to create larger networks and send fewer messages per PC.

"The first zombies that we saw would basically go as fast as they could for as long as they could until they were shut down," he said. "Now they use more stealth."

"They also tend to operate in hours when people are less likely to be at their PC," he added. "So in the Eastern time zone, they'll be more likely to be active in the late afternoon than in the evening."

"These spammers are smart," he continued. "They want to keep these PCs infected as long as possible."


Print Version E-Mail Article Reprints More by John P. Mello Jr.


Related News Alerts

Comcast Activate Alert | Search Archives

More by John P. Mello Jr.

FileMaker Pro Goes to 11
March 15, 2010
FileMaker has pushed out the 11th version of its Pro database product, and its new charting capabilities top the list of new features. Pie, bar and area charts can be created instantly and will change dynamically as the data underlying them changes. In addition, FileMaker 11 includes more than 30 "Start Solutions" that address the kind of real-world information needs for which business people buy a database.
Corel's X3 Photo Editor Paints a Pretty Picture
March 11, 2010
Corel has packed its latest version of PaintShop Photo Pro, X3, with a boatload of new features, many of which are aimed at smoothing out the photographer's workflow. It's tied in a new batch processing feature as well as Express Lab, which gives photo editors the power of combined tools. There's also better support for RAW files and a bonus Painter Photo Essentials 4 app for adding an artistic flourish.
Aperture's Makeover Delights Photogs
March 08, 2010
While Aperture's new features make it more attractive than ever to professional photographers, its main selling point appears to be its superior ability to automate a photographer's workflow. "For me, the most important thing about Aperture -- always has been and remains -- is that it is simply the most powerful archiving tool available," said photographer Bill Frakes.
Don't miss a story -- sign up for our FREE e-mail newsletters and view the latest headlines at a glance.
Tech News Flash [ View Sample ]
E-Commerce Minute [ View Sample ]
ECT News Network Weekly Newsletter [ View Sample ]
Shortcuts
ECT News Network Information
Reader Services
Corporate
ECT News Network