New Botnet Is "Practically Indestructible"

Earnest Cavalli

New member
Jun 19, 2008
5,352
0
0
New Botnet Is "Practically Indestructible"



Researchers working for antivirus firm Kapersky Labs have discovered a new botnet so cleverly constructed that it has been dubbed "practically indestructible."

Before you start harumphing and reminiscing about the old days when tech geeks couldn't even define "hyperbole," much less spout the stuff like the biggest geyser ever, hear them out. This thing is just devious.

Dubbed "TDL-4" -- they've got hyperbole down, and that's the best name they could come up with? -- the new botnet is reportedly already infecting 4.5 million Windows PCs worldwide. The botnet's owners use public peer-to-peer filesharing networks to transmit information to the system, and all such transmissions are encrypted with a custom algorithm.

The really insidious bit is what the TDL-4 code (it calls itself "Top Bot [http://www.securelist.com/en/analysis/204792180/TDL4_Top_Bot]") does once it gets into your computer. Instead of installing itself to C: like any respectable program, the code takes root in the computer's boot record. That screen that shows up before Windows actually loads? In essence, that's where Top Bot lives. This makes it nearly undetectable by the vast majority of antivirus software, and since it activates prior to Windows even coming online, Microsoft's flagship operating system has no power over it.

This also means that formatting your computer, a process that restores every Windows component to its most basic state, has no effect on Top Bot.

Not content to simply make your computer a slave to its illicit masters, Top Bot also goes after other malware. The logic, New Scientist points out, is that a user might notice if a half dozen viruses were bogging their computer down. That's attention that Top Bot doesn't want to attract, so it's programmed to reroute the outgoing communications of 20 common malware programs, effectively rendering them inert.

As with the vast majority of these sorts of botnets, researchers claim the system is most likely used to generate spam email and aid in a wide range of online attacks.

On the one hand, the words "nefarious" and "insidious" come to mind in regards to this thing's ability to infect new hosts. On the other hand, I'm almost impressed by the clever technological design in place here.

I guess that's like Bishop praising the xenomorphs in Aliens [http://www.amazon.com/Aliens-Two-Disc-Collectors-Sigourney-Weaver/dp/B00012FXAE]. Analytically, I can see that they're a fascinating example of adaptive evolution, but that doesn't do much for John Hurt's burst ribcage.

Source: New Scientist [http://www.newscientist.com/blogs/onepercent/2011/07/researchers-discover-indestruc.html]

Permalink
 

Tireseas_v1legacy

Plop plop plop
Sep 28, 2009
2,419
0
0
Didn't they say that about the Death Star? Can we all agree that "indestructible" is an invitation to be proven wrong...

Also, interesting botnet... It's like a parasite, except it kills the other ones... Ingenious...

Could we harness it as a weapon?
 

bjj hero

New member
Feb 4, 2009
3,180
0
0
Do people really have nothing better to do with their time than come up with this kind of shit?

Look outside... There is daylight, there are girls too, nice things to eat and drink, fun things to explore and do. Much better than sitting in your cave and coming up with better ways to spoil someone elses computer.
 

Penguinplayer

New member
Mar 31, 2009
71
0
0
This is... actually pretty cool.

But now I have a constant paranoia, cause you never know when you are infected.
 

let's rock

New member
Jun 15, 2011
372
0
0
You do know that there are ways to modify you're boot record, right? If you are really good at softwarwe, you can go into you're boot with a master boot boot cd, highlight it, and click delete. Nothing is indestructable, look at the titanic and death star. As long as it doesn't start singing "Daisy Bell" I have no concern. Also, try being careful on the internet so it can't install in the first place :)
 

manythings

New member
Nov 7, 2009
3,297
0
0
The Gentleman said:
Didn't they say that about the Death Star? Can we all agree that "indestructible" is an invitation to be proven wrong...

Also, interesting botnet... It's like a parasite, except it kills the other ones... Ingenious...

Could we harness it as a weapon?
It already is one and it's privately owned by dou... super awesome guys I bet are fun to party with and I will happily allow to instate themselves as overlords.

let said:
You do know that there are ways to modify you're boot record, right? If you are really good at softwarwe, you can go into you're boot with a master boot boot cd, highlight it, and click delete. Nothing is indestructable, look at the titanic and death star.
Yes, it's likely that of all the people who were consulted and studied this issue none of them actually used a computer before and, therefore, such a solution would never have been attempted let alone reported if successful.
 

Hal10k

New member
May 23, 2011
850
0
0
This is pure unrefined paranoia fuel. Also, who is that handsome fellow in the article picture?
 

BrownGaijin

New member
Jan 31, 2009
895
0
0
First thought: Well... this sucks.

Second thought: No seriously this sucks.

Third thought: It's times like this where we need the real David Lightman and Lazlo Hollyfeld to step up to the plate. Chris Knight, and Mitch Taylor can come and play too.

Fourth thought: Nope still sucks.
 

Tireseas_v1legacy

Plop plop plop
Sep 28, 2009
2,419
0
0
bjj hero said:
Do people really have nothing better to do with their time than come up with this kind of shit?

Look outside... There is daylight, there are girls too, nice things to eat and drink, fun things to explore and do. Much better than sitting in your cave and coming up with better ways to spoil someone elses computer.
In theory, you could use the combined power of the thousands of PCs that the bot has infected to hack a bank, steal millions of dollars, and buy a goddamn island...

If I had a choice, yeah, I'd do it too...
 

Fooz

New member
Oct 22, 2010
1,055
0
0
Hal10k said:
This is pure unrefined paranoia fuel. Also, who is that handsome fellow in the article picture?
haha, alright botnet, how are you?

i personally think you are awesome and would never think about offending you
 

Vanbael

Arctic fox and BACON lover
Jun 13, 2009
626
0
0
let said:
As long as it doesn't start singing "Daisy Bell" I have no concern.
Yeah, that's my main concern. In any case, I'm being careful on where I go from now on. What a way to fuel paranoia. Good luck to the people researching this to find a way to bring it down.
 

ThreeKneeNick

New member
Aug 4, 2009
741
0
0
This is a really creepy read if you just happen to randomly be listening to this while reading it.

Im scared. Somebody hold me!
 

Uber Waddles

New member
May 13, 2010
544
0
0
Well, color me purple and slap me in the face with a feather duster.

... and by that I mean wow, that is total dicks right there. I have to wonder whats the point of it? I mean, more than likely, one of the major anti-virus companys is gonna find a way to get rid of it. And its not really doing anything nefarious, other than spamming people about a Prince in Zimbabwe, and dicking with other people who are just dicks.

This kinda sounds like something a 13 year old would do for fun, just troll and annoy as many people as humanly possible without causing any real, substantial damage.
 

Jodah

New member
Aug 2, 2008
2,280
0
0
let said:
You do know that there are ways to modify you're boot record, right? If you are really good at softwarwe, you can go into you're boot with a master boot boot cd, highlight it, and click delete. Nothing is indestructable, look at the titanic and death star. As long as it doesn't start singing "Daisy Bell" I have no concern. Also, try being careful on the internet so it can't install in the first place :)
And doing that fixes one computer out of 4.5 million. The problem with this one is that it takes a good amount of technical knowledge to remove. The average person doesn't have said knowledge.