PDA

View Full Version : Botnets Bouncing Back



anon
02.12.08, 23:03
Despite McColo's takedown, observers say that major senders of spam and malware are returning -- and may be stronger than ever.

Just weeks after the shutdown of major spam host McColo led to a sharp drop in unwanted e-mails, spammers and malicious botnets are showing signs of returning.

McColo's takedown (http://www.internetnews.com/security/article.php/3784561/Media+Spotlight+Scatters+a+Botnet+Host.htm) by its ISPs also hit botnets like Srizbi hard, since they had been hosted on McColo -- and their designs made them especially vulnerable to the loss of their host, according to Derek Manky, lead threat researcher for Fortinet.

"Srizbi, for example, was using hard-coded command-and-control servers hosted at McColo, and when these were taken offline, the botnet was rendered useless," Manky told InternetNews.com in an e-mail.

However, Srizbi, Rustock, Asprox and other botnets are beginning to come back to life, if shakily, experts said. And they may have new allies in the form of cash-strapped ISPs.

InternetNews Realtime IT News - Botnets Bouncing Back (http://www.internetnews.com/security/article.php/3788126/Botnets+Bouncing+Back.htm)