Hundreds Of Thousands Of Bots Lay Dormant

According to a <a href="http://www.darkreading.com/security/attacks/showArticle.jhtml?articleID=212101163">story</a> that ran in our sister site, DarkReading.com, 500,000 bots from a recently severed botnet army may now lay dormant, awaiting their next set of orders.

2 Min Read
Dark Reading logo in a gray background | Dark Reading

According to a story that ran in our sister site, DarkReading.com, 500,000 bots from a recently severed botnet army may now lay dormant, awaiting their next set of orders.This news follows last week's sudden fall of the McColo hosting service, credited to Brian Krebs, security reporter for The Washington Post, who said at the time that the McColo hosting service could have been responsible for 75% of the spam circulating the Internet.

Now that the master network has been crushed, DarkReading's Kelly Jackson Higgins asks: what's now going on with all of those dislocated bots that had previously been used to generate all of that spam:

"Researchers have spotted these errant bots over the past week attempting to phone home to their former command and control (C&C) servers. While the industry continues to celebrate a nearly 70% nosedive (albeit temporary) in spam volume without McColo to host the world's biggest spamming botnets anymore, these orphaned bots are still at risk -- and possibly still spewing spam, security experts say.

"They are probably already infected with multiple things. You hardly ever find just one bot on these computers," says Joe Stewart, director of malware research for SecureWorks. "You may find three or four different spam bots on the same machine. And who knows what else -- password stealers and other rogue ware."

"

Stewart is no doubt correct. The systems acting as a home to these bots are most likely infected with numerous types of malware. If history is any indication, either the previous owner of the bot network will regain control, or others will start trying to highjack as many of those bots as they can for their own networks.

It should be interesting to see how this shakes out in the coming weeks.

About the Author

George V. Hulme, Contributing Writer

An award winning writer and journalist, for more than 20 years George Hulme has written about business, technology, and IT security topics. He currently freelances for a wide range of publications, and is security blogger at InformationWeek.com.

Keep up with the latest cybersecurity threats, newly discovered vulnerabilities, data breach information, and emerging trends. Delivered daily or weekly right to your email inbox.

You May Also Like


More Insights