Microsoft seizes Chinese botnet domain

 

Wins court injunction against alleged owners.

Microsoft is preparing to seize a Chinese-owned domain and up to 70,000 sub-domains believed to host a malicious botnet aimed at performing distributed denial of service attacks through infected machines.

A United States District Court granted the software giant's request to host the 3322.org domain, beileved to be the source of the emerging Nitol botnet and more than 500 other different strains of malware with the potential for targeting millions of innocent people.

It placed a restraining order against the alleged owners of the domain — Peng Yong, Bei Tei Kang Mu Software Technology trading as Bitcomm Ltd, and up to three other unnamed people — for violating federal law, according to court papers.

The Associated Press reported that Peng was not aware of the court injunction and denies allegations of hosting malware.

Nitol spreads through the network and removable devices such as USB sticks. It performs distributed denial of service attacks and also allows attackers to run arbitrary software on infected systems.

The malware is most likely of Chinese origin and concentrated mainly that country, but has spread around the world with infections in the US, Russia, Australia and Germany and Microsoft.

Richard Boscovich, a former US federal prosecutor and now assistant general counsel for Microsoft's Digital Crime Unit, said the company had discovered instances of the malware being distributed on machines sold through retailers with counterfeit versions of Windows.

"What's especially disturbing is that the counterfeit software embedded with malware could have entered the [supply] chain at any point as a computer travels among companies that transport and resell the computer," Boscovich wrote in a blog entry.

He argued that as people can't tell if a supply chain is unsecure or not, exploitation of a broken one is an "especially dangerous vehicle for infecting people with malware".

The company had begun tracking down the source of the botnet and the insecure supply chain under Operation b70 since August last year, buying 20 computers from different cities in China.

One, a Hedy laptop running Windows XP Service Pack 3, was found to have been "carelessly or intentionally infected with Nitol".

Although the malware has come to the fore this year, Boscovich suggested the botnet was "being hosted on a domain linked to malicious activity since 2008".

However, Boscovich said that Peng had ignored past warnings by other online security firms.

According to cloud security firm Zscaler, the 3322.org domain accounted for more than 17 percent of the world's malicious web traffic in 2009 and, since the court order, over 37 million malware connections to the domain have been blocked.

Microsoft has taken action against several botnets in recent months, including tracking down two Russians allegedly behind the Zeus Botnet.

The company also claims to have disrupted the Waledac, Rustock and Kelihos botnets over the past two years.

Copyright © iTnews.com.au . All rights reserved.


Microsoft seizes Chinese botnet domain
 
 
 
 
Top Stories
NBN Co could miss revised June fibre targets
Analysis: Cutting it fine in the race to the line.
 
Review: Sydney's Opal smartcard
It's no Oyster card.
 
Rackspace puts price premium on Aussie public cloud
At least 17 percent more compared to US instances.
 
 
Sign up to receive iTnews email bulletins
   FOLLOW US...

Latest VideosSee all videos »

iTnews Academy: Microsoft Windows Server 2012 - Hyper-V
iTnews Academy: Microsoft Windows Server 2012 - Hyper-V
Interview: Australia's 'cloud-last' policy is dangerous.
Interview: Australia's 'cloud-last' policy is dangerous.
Interview: Vivek Kundra on Australia's 'cloud last' policy
Bankwest builds continuous delivery capability
Bankwest builds continuous delivery capability
To automatically deploy test/dev sandboxes by mid-year.
Veterans' Affairs sets sights on modernisation
Veterans' Affairs sets sights on modernisation
Data safe with Human Services, CIO says.
Citi Australia drops platform customisations
Citi Australia drops platform customisations
Technology chief shifts focus from building to leveraging systems.
VicRoads restructures IT team
VicRoads restructures IT team
Department moves to align with industry benchmarks.
Zurich Australia extends IT team offshore
Zurich Australia extends IT team offshore
Malaysian staff served from Australian data centres.
Leigh Berrell - Utilities CIO of the Year
Leigh Berrell - Utilities CIO of the Year
Yarra Valley Water CIO Leigh Berrell accepts his Benchmark Award for Utilities CIO of the Year.
Wayne McMahon - Retail CIO of the Year
Wayne McMahon - Retail CIO of the Year
Domino's Pizza CIO Wayne McMahon accepts his Benchmark Award for Retail CIO of the Year.
Inside Perpetual's ongoing IT transformation
Inside Perpetual's ongoing IT transformation
CIO Jenny Levy discusses how outsourcing will help the firm "simplify, refocus and grow".
Managing Complexity - Defence's Daniel McCabe
Managing Complexity - Defence's Daniel McCabe
Daniel McCabe, Assistant Secretary of Australia's Department of Defence, provides the audience at the iTnews Data Centre Strategy Summit with a deep dive into the organisation's data centre consolidation program.
How Facebook designed the data centre from scratch - Marco Magarelli
How Facebook designed the data centre from scratch - Marco Magarelli
The full keynote by Facebook data centre architect Marco Magarelli at the Australian Data Centre Strategy Summit. Magarelli details the design considerations behind the social network's Prineville, Oregon; North Carolina and Luleå, Sweden data centres.
Modernising Legacy Data Centres - Telstra's Jon Curry
Modernising Legacy Data Centres - Telstra's Jon Curry
Telstra general manager of managed data centres Jon Curry guides the audience at the iTnews Australian Data Centre Summit through the build of the telco's Clayton, Victoria data centre.
NSW Government launches NABERS data centre rating tools
NSW Government launches NABERS data centre rating tools
Matthew Clark from the NSW Department of Environment guides facilties managers through the details of the new NABERS data centre energy rating tool at the Australian Data Centre Strategy Summit.
NABERS launch panel: Australian Data Centre Strategy Summit
NABERS launch panel: Australian Data Centre Strategy Summit
Matthew Clark (NSW Dept of Environment), Greg Boorer (Canberra Data Centres), Glenn Allan (National Australia Bank), Mike Andrea (Strategic Directions) and Bob Sharon (Green Global Consulting) discuss the impact of the NABERS data centre rating.
Judges notes: Fortescue Metals [The Benchmark Awards]
Judges notes: Fortescue Metals [The Benchmark Awards]
iTnews' panel of judges discuss Fortescue Metals 'New World of Work" project, one of three shortlisted finalists for the Industrials category of the CIO Benchmark Awards.
Judges notes: Retail [The Benchmark Awards]
Judges notes: Retail [The Benchmark Awards]
iTnews' panel of judges discuss the shortlisted finalists for the Retail category of the CIO Benchmark Awards.
Judges notes: Pacific Aluminium [The Benchmark Awards]
Judges notes: Pacific Aluminium [The Benchmark Awards]
iTnews' panel of judges discuss Pacific Aluminium's lightning fast service desk refresh, one of three shortlisted finalists for the Industrials category of the CIO Benchmark Awards.
Judges notes: Domino's Pizza [The Benchmark Awards]
Judges notes: Domino's Pizza [The Benchmark Awards]
iTnews' panel of judges discuss Domino's Pizza's shift to hosted services, one of three shortlisted finalists for the Retail category of the CIO Benchmark Awards.
Judges notes: McDonald's Australia [The Benchmark Awards]
Judges notes: McDonald's Australia [The Benchmark Awards]
iTnews' panel of judges discuss McDonald's Australia's new self-service portal for employees, one of three shortlisted finalists for the Retail category of the CIO Benchmark Awards.
Latest articles on BIT Latest Articles from BIT
How to use Microsoft OneNote to organise your minutes, memos and more
Jun 18, 2013
You might already have OneNote, but you might have never used it. Here's how to use it to ...
Microsoft’s new Office Mobile app for iPhone looks handy, but there’s a catch
Jun 17, 2013
Click here to see what the biggest hurdle to using Microsoft's just-announced Office Mobile app ...
A handy app for finding the cheapest parking
Jun 14, 2013
This app takes the hassle and the cost out of finding a car park in the city. It is available on ...
Small business rallying cry continues before election
Jun 13, 2013
Hate paperwork? Find taxes too complicated? Then the organisers of this nation-wide petition ...
I want to save money: can I spend less on Microsoft Office?
Jun 11, 2013
Can't afford Microsoft Office? Here is a basic introduction to some options if you're looking to ...
Latest Comments
Polls
Will you quit any cloud services in light of PRISM?

   |   View results
Yes
  60%
 
No
  40%
TOTAL VOTES: 65

Vote