Microsoft Wins Major Victory Against Zombie PC Networks
Microsoft has convinced a judge to grant it legal ownership of 276 web domains previously used to control networks of infected PCs. It's the first time this has happened, and the company believes it could be used as a legal weapon.
The case involves a botnet, created from computers infected with the Waledeac worm. A botnet is short form for "robot network" -- or quite simply, a network of infected computers controlled by one or few individuals.
Botnet Sends 1.5 Billion Spam Email Messages Per Day
At one point an estimated 80,000 computers were under part of the botnet and were being used to send 1.5 billion spam emails every day, around one per cent of the global total.
Hackers (and spammers) commonly use the tactic of infecting PCs and sending spam messages in order to legitimize (and fool) Email Service Providers (ESPs). Before such a tactic was invented, spam emails typically came from only 1 source, making unsolicited messages easier to detect and refuse.
Legal Action Cuts Problem Domains Off
While Microsoft distributed tools to help remove threats such as the Waledac worm, it was legally restricted in what it could do to prevent infected computers from being controlled after the fact.
That changed earlier this year, when it began a case against the owners of the domains which issued instructions to the infected machines.
A court ruled in February that traffic to and from these domains should be cut, which effectively meant the website addresses no longer hooked up to the specific machines issuing command-and-control orders, thus leaving infected machines unable to make contact with their master.
In addition, Microsoft was able to take "ethical countermeasures to downgrade much of the remaining peer-to-peer command and control communication" with a clear conscience. (Source: technet.com)
Microsoft Given Permanent Ownership of Botnet Domains
Although the owners of the domains didn't respond to the court action, they did respond in the form of an attempted cyber-attack on Microsoft lawyers and researchers. The company went back to court this week to argue that this proved the defendants were aware of the case but had chosen not to defend it.
On this basis, Microsoft requested that the court give it permanent ownership of the domains in order to prevent future use of the botnet. In what is being seen as an unusual ruling, the court has agreed to this forcible transfer of ownership.
The defendants will have 14 days to object and make their case; otherwise, the ruling will automatically take effect. Given the history of the case and the potential for individuals to face criminal charges, it seems a virtual lock that there won't be any objection. (Source: technet.com)
Legal Technique To be Used Again
Microsoft has indicated that it will use this tactic again in the future. A senior company attorney, Richard Boscovich, says "It's open season on botnets. The hunting licenses have been handed out, and we're coming back for more." (Source: usatoday.com)
One drawback is that the technique will only work for web domains that come under US jurisdiction, such as those ending in .com, .net and .org. Although that takes care of a large proportion of domains, it leaves plenty of country-specific domains where other tactics will be required.
Most popular articles
- Which Processor is Better: Intel or AMD? - Explained
- How to Prevent Ransomware in 2018 - 10 Steps
- 5 Best Anti Ransomware Software Free
- How to Fix: Computer / Network Infected with Ransomware (10 Steps)
- How to Fix: Your Computer is Infected, Call This Number (Scam)
- Scammed by Informatico Experts? Here's What to Do
- Scammed by Smart PC Experts? Here's What to Do
- Scammed by Right PC Experts? Here's What to Do
- Scammed by PC / Web Network Experts? Here's What to Do
- How to Fix: Windows Update Won't Update
- Explained: Do I need a VPN? Are VPNs Safe for Online Banking?
- Explained: VPN vs Proxy; What's the Difference?
- Explained: Difference Between VPN Server and VPN (Service)
- Forgot Password? How to: Reset Any Password: Windows Vista, 7, 8, 10
- How to: Use a Firewall to Block Full Screen Ads on Android
- Explained: Absolute Best way to Limit Data on Android
- Explained: Difference Between Dark Web, Deep Net, Darknet and More
- Explained: If I Reset Windows 10 will it Remove Malware?
My name is Dennis Faas and I am a senior systems administrator and IT technical analyst specializing in cyber crimes (sextortion / blackmail / tech support scams) with over 30 years experience; I also run this website! If you need technical assistance , I can help. Click here to email me now; optionally, you can review my resume here. You can also read how I can fix your computer over the Internet (also includes user reviews).
We are BBB Accredited
We are BBB accredited (A+ rating), celebrating 21 years of excellence! Click to view our rating on the BBB.