New botnet enslaves millions of PCs in just three months

woofy

The Master of Disaster
Staff member
A newly-discovered botnet is 'practically indestructible', security researchers say.

TDL-4 is the rootkit component of the TDSS , which has been around since 2008. But in the three months since it hit the scene, it's sucked in more than four and a half million PCs around the world. About a third are based in the US.

And in this, its latest incarnation, it has the cheek to include its own version of an anti- capability, which scans slave machines for software that could enable it to be taken over by another botnet.
It can now delete around 20 of the world's most prolific malware packages, including Gbot, ZeuS and Optima.


It has its own method for communication between infected computers and the command and control servers, and can also use a public peer-to-peer network to sending commands to control infected computers.
Labs has published a detailed analysis of TDL-4.


"The changes in TDL-4 affected practically all components of the malware and its activity on the to some extent or other. The malware writers extended the program functionality, changed the algorithm used to encrypt the communication protocol between bots and the botnet command and control servers, and attempted to ensure they had access to infected even in cases where the botnet control centers are shut down," says Kaspersky researcher Sergey Golovanov.



"The owners of TDL are essentially trying to create an
 
Back
Top