Researchers infiltrate Kraken botnet, could clean it out

But they won't disinfect remotely, citing 'pretty big can of worms' as reason

A group of security researchers Wednesday said they have infiltrated one of the world's biggest botnets and can snatch control of compromised machines from the hackers.

But while 3Com's TippingPoint researchers say they have the ability to disinfect the systems by eradicating the malware installed on the hijacked PCs, the company has decided against the move, citing liability issues.

Pedram Amini, who leads TippingPoint's security research group, and Cody Pierce, a security researcher who is also part of that team, collaborated on a weeklong project that started with the idea of verifying the size of the "Kraken" botnet but ended with an ethical quandary.

Pierce created a fake Kraken command-and-control server by reverse engineering the list of domain names found in a captured sample of the bot, and then registered some of the sub-domains Kraken looks for. The server essentially acted as a command-and-control honeypot that waited for connections from PCs infected with the bot.

"Stated simply, Kraken infected systems worldwide start to connect to a server we control," Amini said in a post to a company blog.

The two researchers monitored the incoming communications from Kraken bots for seven days, Pierce said. "We listened and collected statistics for a week, and filtered out [for] the IP addresses and then the systems," he said on the telephone Wednesday." He was able to identify each infected machine by using the malware's encryption key, which was unique across the entire botnet.

The total count for the week: about 25,000 infected machines.

Others have estimated Kraken's size at between 185,000 and 600,000 compromised PCs. SecureWorks' Joe Stewart, who uses the moniker "Bobax" rather than Kraken for the botnet, pegged it at the lower number earlier this month based on an in-depth traffic analysis and bot-fingerprinting project.

In other words, TippingPoint had identified between 4 per cent and 14 per cent of the total Kraken botnet.

But the company's research didn't stop there. Pierce wrote code that would let him redirect infected PCs, or better yet, use the bot's built-in update mechanism -- something most malware includes -- to remove Kraken.

There, however, things got sticky. "This is where we got into the ethical discussion," Pierce said. He and Amini wanted to use that capability to clean out Kraken-infected systems. Their boss, David Endler, the director of TippingPoint's DVLabs, disagreed.

"From our point of view, if someone doesn't do something about bots, they'll just continue on and on," Pierce said. "If you have the opportunity to do something, take it."

Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.

Gregg Keizer

Computerworld

Comments

Comments are now closed.

Latest News Articles

Most Popular Articles

Follow Us

GGG Evaluation Team

Kathy Cassidy

STYLISTIC Q702

First impression on unpacking the Q702 test unit was the solid feel and clean, minimalist styling.

Anthony Grifoni

STYLISTIC Q572

For work use, Microsoft Word and Excel programs pre-installed on the device are adequate for preparing short documents.

Steph Mundell

LIFEBOOK UH574

The Fujitsu LifeBook UH574 allowed for great mobility without being obnoxiously heavy or clunky. Its twelve hours of battery life did not disappoint.

Andrew Mitsi

STYLISTIC Q702

The screen was particularly good. It is bright and visible from most angles, however heat is an issue, particularly around the Windows button on the front, and on the back where the battery housing is located.

Simon Harriott

STYLISTIC Q702

My first impression after unboxing the Q702 is that it is a nice looking unit. Styling is somewhat minimalist but very effective. The tablet part, once detached, has a nice weight, and no buttons or switches are located in awkward or intrusive positions.

Resources

Best Deals on GoodGearGuide

Latest Jobs

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?