Newsletters
The Enterprise Security Supersite NewsFactor Sites:       NewsFactor.com     Enterprise Security Today     CRM Daily     Business Report     Sci-Tech Today  
   
Home Network Security Viruses & Malware Cybercrime Security Solutions More Topics...
Data Security
24/7/365 Network Uptime!
Average Rating:
Rate this article:  
Microsoft Busts Malware Botnet Tied to Counterfeit Windows
Microsoft Busts Malware Botnet Tied to Counterfeit Windows

By Adam Dickter
September 13, 2012 4:25PM

Bookmark and Share
"We found malware capable of remotely turning on an infected computer's microphone and video camera, potentially giving a cybercriminal eyes and ears into a victim's home or business," wrote Microsoft's Richard Domingues Boscovich
. "Additionally, we found malware that records a person's every keystroke" and sent it to the 3322.org botnet.
 


Microsoft is taking a bow for saving the public from potential malware infection through counterfeit Windows software by taking over a domain that hosted as many as 70,000 malicious subdomains.

The digital drama unfolded earlier this week when the cyber-sleuths at the tech giant's Digital Crimes Unit acted on research that showed that crooks were using fake software to infect computers with malware connecting to the Nitol botnet. The botnet activity via the domain 3322.org, dated back to 2008.

A botnet is a system of computers that has been compromised by hackers.

'Eyes and Ears' for Hackers

"We found malware capable of remotely turning on an infected computer's microphone and video camera, potentially giving a cybercriminal eyes and ears into a victim's home or business," wrote Richard Domingues Boscovich
, assistant general counsel of Microsoft's Digital Crimes Unit, on Microsoft's official blog Thursday. "Additionally, we found malware that records a person's every keystroke, allowing cybercriminals to steal a victim's personal information."

As part of its Project MARS (Microsoft Active Response for Security) program, Redmond, Wash.-based Microsoft filed suit in the U.S. District Court for the Eastern District of Virginia, seeking a temporary restraining order against an individual named Peng Yong, his company and other unnamed individuals, which was granted on Monday. Yong denies any wrongdoing.

That order allowed Microsoft to take control of the 3322.org domain through a new domain system that allows the company to block Nitol and nearly 70,000 other malicious sites while keeping traffic to legitimate sites flowing normally.

"In an operation like this, you are trying to take the servers that are botted offline once you identify them," explained technology consultant Rob Enderle of the Enderle Group. "Once you identify the IP address, you isolate the machines so they can't talk to anyone else, which effectively shuts them down. It's like what you would do with a person who has a communicable disease."

Good Hunting

He added that in Europe, Microsoft has disrupted malicious servers by having them physically shut down by law enforcement agents, but domestically is more likely to work to have them disconnected from other networks.

In granting the restraining order, the District Court said that "there is good cause to believe that Defendants have engaged in intentionally and/or negligent activity using the 3322.org domain that is maintained by the top level domain registry, the Public Interest Registry ("PIR"), located in Reston, Virginia."

Boscovich noted that it's the second botnet disruption carried out by the Digital Crimes Unit in the last six months.

In July, the unit announced that it had identified two defendants behind the Zeus botnet, which is believed to be responsible for a half-billion dollars in online fraud and identity theft. Those individuals were already serving time in the United Kingdom for Zeus-related malware charges, Boscovich said.
 

Tell Us What You Think
Comment:

Name:



Salesforce.com is the market and technology leader in Software-as-a-Service. Its award-winning CRM solution helps 82,400 customers worldwide manage and share business information over the Internet. Experience CRM success. Click here for a FREE 30-day trial.


 Data Security
1.   Tor Working To Fix Security Exploit
2.   Hackers Breached StubHub Accounts
3.   Juniper DDoS for High-IQ Networks
4.   Google Hacker Team to Hunt Bugs
5.   Cloud Firms Offer Azure Starter Kit


advertisement
Tor Working To Fix Security Exploit
Bug reportedly reveals ID of users
Average Rating:
Gartner Rates IT Security Companies
IBM, HP, McAfee, Splunk ranked well.
Average Rating:
Hackers Target Western Energy Firms
Appears to be state-sponsored group.
Average Rating:
Product Information and Resources for Technology You Can Use To Boost Your Business

Network Security Spotlight
Researchers Working To Fix Tor Security Exploit
Developers for the Tor privacy browser are scrambling to fix a bug revealed Monday that researchers say could allow hackers, or government surveillance agencies, to track users online.
 
Wall Street Journal Hacked Again
Hacked again. That’s the story at the Wall Street Journal this week as the newspaper reports that the computer systems housing some of its news graphics were breached. Customers not affected -- yet.
 
Dropbox for Business Beefs Up Security
Dropbox is upping its game for business users. The cloud-based storage and sharing company has rolled out new security, search and other features to boost its appeal for businesses.
 

Enterprise Hardware Spotlight
Microsoft Makes Design Central to Its Future
Over the last four years, Microsoft has doubled the number of designers it employs, putting a priority on fashioning devices that work around people's lives -- and that are attractive and cool.
 
Contrary to Report, Lenovo's Staying in Small Windows Tablets
Device maker Lenovo has clarified a report that indicated it is getting out of the small Windows tablet business -- as in the ThinkPad 8 and the 8-inch Miix 2. But the firm said it is not exiting that market.
 
Seagate Unveils Networked Drives for Small Businesses
Seagate is out with five new networked attached storage products aimed at small businesses. The drives are for companies with up to 50 workers, and range in capacity from two to 20 terabytes.
 

Navigation
Enterprise Security Today
Home/Top News | Network Security | Viruses & Malware | Cybercrime | Security Solutions | Mobile Security | Disaster Recovery | Windows Security
Data Security | EST Press Releases
NewsFactor Network Enterprise I.T. Sites
NewsFactor Technology News | Enterprise Security Today | CRM Daily

NewsFactor Business and Innovation Sites
Sci-Tech Today | NewsFactor Business Report

NewsFactor Services
FreeNewsFeed | Free Newsletters

About NewsFactor Network | How To Contact Us | Article Reprints | Careers @ NewsFactor | Services for PR Pros | Top Tech Wire | How To Advertise

Privacy Policy | Terms of Service
© Copyright 2000-2014 NewsFactor Network. All rights reserved. Article rating technology by Blogowogo. Member of Accuserve Ad Network.