Malware, mayhem, and the McColo takedown

By Angela Gunn | Published November 13, 2008, 7:41 PM

The takedown of the McColo hosting service led to a gratifying, if temporary, decrease in spam this week -- but it could also portend a rise in malware infections.

As with the September takedown of Atrivo (nee Intercage), users around the net are currently enjoying the kind of respite from spam that comes when a major "evil ISP," as MessageLabs senior anti-spam technologist Matt Sergeant puts it, bites the dust.

McColo, which went offline after its upstream Internet providers decided to pull the plug, is believed to have been responsible for "command-and-control" functionality for botnets sending 65% of all spam. That number comes from Doug Bowers, senior director of anti-abuse engineering at Symantec, who acknowledges that spam traffic has been low since the takedown.

The hosting service is also believed to be the last of the giant "evil IPSs" located in the US, and though Sergeant says there's nothing necessarily keeping another American ISP from stepping into the breach, the likelihood is that the takedown will push spammers to international hosts.

"The aim," he told BetaNews, "in terms of global spam, is to increase costs for spammers. Despite making a lot of money, spammers have a low profit margin." Bowers adds that the US' robust infrastructure is most attractive for the kind of "services" McColo offered, but that inevitably such services will move elsewhere, perhaps to Eastern Europe.

Financial concerns might accomplish what law enforcement has not. The upstream providers have been long aware that something needed to be done, and they've been working with law enforcement, but Sergeant notes that law enforcement is "massively understaffed" where spam is concerned.

"Spam costs businesses millions if not billions each year; the economic cost of spam is about equal to that of illegal drugs. But there's little political impetus" to fix the junk-mail problem, he said.

The Internet's allegedly governing bodies haven't been any better at framing the problem and figuring out how to address it. ICANN has been, Sergeant says ruefully, "glacially slow" at clamping down on bad registrars, and though some security folk are rejoicing that ICANN will finally deliver on its death sentence for notorious registry EstDomains.com, it's mainly of interest as another vector of address, rather than as a strong measure to shut off the spam tap. (The end of EstDomains also hinges on a technicality concerning its ICANN contract, not because the Estonian firm offered an anonymous domain-name registration service much abused by spammers and their ilk [PDF available here].)

As for upstream providers, the decision to shut down a problem client's access usually means weighing the income the client pays against the embarrassment of associating with them. Beyond that, there's no particular upside in terms of traffic; spam is many bad things, but for the likes of the upstream providers, it's not a huge bandwidth hog.

A more ominous development, as Sergeant notes, is the potential for malware infections to evolve as a result of the takedown -- a thought that seems counterintuitive, perhaps, especially since the Atrivo takeover was credited with sticking the final stake in the heart of the Storm Worm's botnet.

As McColo's various nefarious clients regroup over the next few days, the Net will likely see a botnet-by-botnet return of the most notorious offenders. (Sergeant says there's evidence that the Srizbi botnet may already have restarted; Bowers' team hasn't seen it yet, but "the next day or two" will be most interesting.) It's possible that as they re-establish themselves, they'll do so bearing fresher, more pernicious code.

Or at least, Bowers says, a code of a different horror: "The takedown is likely to accelerate the trend toward peer-to-peer botnets, rather than the more centralized command-and-control structure [McColo's users employed]." In other words, enjoy the relative quiet in the wake of the giant takedown. We may not see its like again -- not because the spam's going away, but because the bad-guy dinosaurs might start making like mammals.

Comments

View comments by with a score of at least

Mac OS X servers stop spam better and a Mac is the best anti-malware solution to date.

Score: 0

|

Wow... usually I get about 200 spam messages a day... yesterday I only got 58...

Score: 0

|

lol, the irony is biting!

Score: 0

|

Haha.
That is quite some timing, indeed.

Score: 0

|

Personally, Ive seen an increase in the past couple of days, so someone has already picked up the baton.

Score: 0

|

Fantastic. Based on a single observation you are able to predict the events on the entire internet. Can I hire you?

Score: 0

|

He's just saying for himself. Looking through my spam logs I show no difference at all, not even 1%.

Score: 0

|

If a group was clever enough, they might pretend to be an evil ISP till they got enough info on these losers, then took them out of commission all at once.

Score: 0

|

PDC 2009: What have we learned this week?

There was the freebie that no one will forget, the heebie-jeebies courtesy of Scott Guthrie, and a teensy bit clearer picture of how this cloud thingie should work.

Live report: Will Google Chrome OS change Linux?

The mysteries of just what Chrome OS is, and how much of an operating system it truly is, may be resolved today.

PDC 2009: Microsoft cares about Web browser performance

The effort to give users of the world's dominant Web browser the impression of quality, is a personal one for the man who leads that battle.

Nokia re-affirms its commitment to Symbian, sort of

Maemo won't necessarily be replacing Symbian in the Nokia N-Series, but that's definitely a place where it will be found.

E-book readers will be in short supply this holiday season

E-readers are hot this year, and a lot of compelling new products have been released, but are there enough electrophoretic displays to go around?

Sony looks to finally open a single storefront for downloads

Sony has had many different download portals for movies, music, e-books, and games, and now it's looking to make a single shop for all of it.

Tuning out the tablet: Time to give the endless speculation a rest

Wide Angle Zoom: Wishing and hoping and thinking and praying....won't put an iTablet on the market.

Five improvements for IT managers in 2010

If businesses are to improve their efficiency for next year, they need to stop and reassess the basic tenets of their job.

AOL's spinoff from Time Warner to shed 2,500 jobs

As AOL moves toward become an independent company again, it will cut nearly a third of its workforce.

Gartner: SMS-based money transfer will be bigger than mobile browsing, search

Gartner issues its predictions for the 10 things our phones will be doing in 2012.

Don't forget to upgrade to Firefox 3.6 beta 3 today

Mozilla has released the latest beta its Firefox 3.6 browser software, just over one week after beta 2.