Malware, mayhem, and the McColo takedown

By Angela Gunn | Published November 13, 2008, 7:41 PM

The takedown of the McColo hosting service led to a gratifying, if temporary, decrease in spam this week -- but it could also portend a rise in malware infections.

As with the September takedown of Atrivo (nee Intercage), users around the net are currently enjoying the kind of respite from spam that comes when a major "evil ISP," as MessageLabs senior anti-spam technologist Matt Sergeant puts it, bites the dust.

McColo, which went offline after its upstream Internet providers decided to pull the plug, is believed to have been responsible for "command-and-control" functionality for botnets sending 65% of all spam. That number comes from Doug Bowers, senior director of anti-abuse engineering at Symantec, who acknowledges that spam traffic has been low since the takedown.

The hosting service is also believed to be the last of the giant "evil IPSs" located in the US, and though Sergeant says there's nothing necessarily keeping another American ISP from stepping into the breach, the likelihood is that the takedown will push spammers to international hosts.

"The aim," he told BetaNews, "in terms of global spam, is to increase costs for spammers. Despite making a lot of money, spammers have a low profit margin." Bowers adds that the US' robust infrastructure is most attractive for the kind of "services" McColo offered, but that inevitably such services will move elsewhere, perhaps to Eastern Europe.

Financial concerns might accomplish what law enforcement has not. The upstream providers have been long aware that something needed to be done, and they've been working with law enforcement, but Sergeant notes that law enforcement is "massively understaffed" where spam is concerned.

"Spam costs businesses millions if not billions each year; the economic cost of spam is about equal to that of illegal drugs. But there's little political impetus" to fix the junk-mail problem, he said.

The Internet's allegedly governing bodies haven't been any better at framing the problem and figuring out how to address it. ICANN has been, Sergeant says ruefully, "glacially slow" at clamping down on bad registrars, and though some security folk are rejoicing that ICANN will finally deliver on its death sentence for notorious registry EstDomains.com, it's mainly of interest as another vector of address, rather than as a strong measure to shut off the spam tap. (The end of EstDomains also hinges on a technicality concerning its ICANN contract, not because the Estonian firm offered an anonymous domain-name registration service much abused by spammers and their ilk [PDF available here].)

As for upstream providers, the decision to shut down a problem client's access usually means weighing the income the client pays against the embarrassment of associating with them. Beyond that, there's no particular upside in terms of traffic; spam is many bad things, but for the likes of the upstream providers, it's not a huge bandwidth hog.

A more ominous development, as Sergeant notes, is the potential for malware infections to evolve as a result of the takedown -- a thought that seems counterintuitive, perhaps, especially since the Atrivo takeover was credited with sticking the final stake in the heart of the Storm Worm's botnet.

As McColo's various nefarious clients regroup over the next few days, the Net will likely see a botnet-by-botnet return of the most notorious offenders. (Sergeant says there's evidence that the Srizbi botnet may already have restarted; Bowers' team hasn't seen it yet, but "the next day or two" will be most interesting.) It's possible that as they re-establish themselves, they'll do so bearing fresher, more pernicious code.

Or at least, Bowers says, a code of a different horror: "The takedown is likely to accelerate the trend toward peer-to-peer botnets, rather than the more centralized command-and-control structure [McColo's users employed]." In other words, enjoy the relative quiet in the wake of the giant takedown. We may not see its like again -- not because the spam's going away, but because the bad-guy dinosaurs might start making like mammals.

Comments

View comments by with a score of at least

Mac OS X servers stop spam better and a Mac is the best anti-malware solution to date.

Score: 0

|

Wow... usually I get about 200 spam messages a day... yesterday I only got 58...

Score: 0

|

lol, the irony is biting!

Score: 0

|

Haha.
That is quite some timing, indeed.

Score: 0

|

Personally, Ive seen an increase in the past couple of days, so someone has already picked up the baton.

Score: 0

|

Fantastic. Based on a single observation you are able to predict the events on the entire internet. Can I hire you?

Score: 0

|

He's just saying for himself. Looking through my spam logs I show no difference at all, not even 1%.

Score: 0

|

If a group was clever enough, they might pretend to be an evil ISP till they got enough info on these losers, then took them out of commission all at once.

Score: 0

|

Google Chrome 4: Yes, it's fast, but is it usable?

As Betanews readers have responded to our stories about Chrome's JavaScript superiority...Does that mean we'd actually use this browser? Well...

Video: Netflix on PlayStation 3

Netflix has come to the PlayStation 3 via Blu-ray and BD-Live.

Verizon Wireless launches new Android, Chocolate, and ruggedized phones

The lower-priced Eris joins the Droid, while the Chocolate gets a touchscreen and more music playback.

Early sales figures for Windows 7 nicely high, but do we know why?

Fans of triple-digit surges in figures quoted by Betanews will love this one, as it appears Microsoft rediscovered how to pull off a software launch.

Myka announces its latest Linux-based 'net top box'

Myka's ION brings Boxee, XMBC, and much more to HDTVs.

What hath Mac wrought? A remembrance after a quarter-century

The reason there's a Macintosh today is not because of some brilliant flash of engineering genius, but because Apple had the audacity to learn from its mistakes.

Early build of Moblin 2.1 improves connectivity, but not device support

The Linux Foundation's Atom-centric OS yesterday received a major overhaul with the project release of Moblin 2.1 for netbooks and nettops.

The iPhone's China syndrome: Sales of 5,000 and climbing

There's actually a country where Apple's device is not a godsend, where sales can be measured in the dozens.

New European counterpart to FCC will ensure 'a more neutral net'

Late Thursday night, the ruling telecom administrators of the EU's member nations signed away their final authority to a new entity overseen by the EC.

Sophos study suggests Windows 7 UAC's default setting is self-defeating

Without any anti-virus installed, a Sophos test showed, User Account Control was only capable of thwarting just one malware package out of ten samples chosen.

Indiscreet tweet trips awareness of Web SSL vulnerability

A group of high-level security engineers had been making progress on thwarting a low-level threat to the Web, until somebody blurted it all out on Twitter.