Malware, mayhem, and the McColo takedown

By Angela Gunn | Published November 13, 2008, 7:41 PM

The takedown of the McColo hosting service led to a gratifying, if temporary, decrease in spam this week -- but it could also portend a rise in malware infections.

As with the September takedown of Atrivo (nee Intercage), users around the net are currently enjoying the kind of respite from spam that comes when a major "evil ISP," as MessageLabs senior anti-spam technologist Matt Sergeant puts it, bites the dust.

McColo, which went offline after its upstream Internet providers decided to pull the plug, is believed to have been responsible for "command-and-control" functionality for botnets sending 65% of all spam. That number comes from Doug Bowers, senior director of anti-abuse engineering at Symantec, who acknowledges that spam traffic has been low since the takedown.

The hosting service is also believed to be the last of the giant "evil IPSs" located in the US, and though Sergeant says there's nothing necessarily keeping another American ISP from stepping into the breach, the likelihood is that the takedown will push spammers to international hosts.

"The aim," he told BetaNews, "in terms of global spam, is to increase costs for spammers. Despite making a lot of money, spammers have a low profit margin." Bowers adds that the US' robust infrastructure is most attractive for the kind of "services" McColo offered, but that inevitably such services will move elsewhere, perhaps to Eastern Europe.

Financial concerns might accomplish what law enforcement has not. The upstream providers have been long aware that something needed to be done, and they've been working with law enforcement, but Sergeant notes that law enforcement is "massively understaffed" where spam is concerned.

"Spam costs businesses millions if not billions each year; the economic cost of spam is about equal to that of illegal drugs. But there's little political impetus" to fix the junk-mail problem, he said.

The Internet's allegedly governing bodies haven't been any better at framing the problem and figuring out how to address it. ICANN has been, Sergeant says ruefully, "glacially slow" at clamping down on bad registrars, and though some security folk are rejoicing that ICANN will finally deliver on its death sentence for notorious registry EstDomains.com, it's mainly of interest as another vector of address, rather than as a strong measure to shut off the spam tap. (The end of EstDomains also hinges on a technicality concerning its ICANN contract, not because the Estonian firm offered an anonymous domain-name registration service much abused by spammers and their ilk [PDF available here].)

As for upstream providers, the decision to shut down a problem client's access usually means weighing the income the client pays against the embarrassment of associating with them. Beyond that, there's no particular upside in terms of traffic; spam is many bad things, but for the likes of the upstream providers, it's not a huge bandwidth hog.

A more ominous development, as Sergeant notes, is the potential for malware infections to evolve as a result of the takedown -- a thought that seems counterintuitive, perhaps, especially since the Atrivo takeover was credited with sticking the final stake in the heart of the Storm Worm's botnet.

As McColo's various nefarious clients regroup over the next few days, the Net will likely see a botnet-by-botnet return of the most notorious offenders. (Sergeant says there's evidence that the Srizbi botnet may already have restarted; Bowers' team hasn't seen it yet, but "the next day or two" will be most interesting.) It's possible that as they re-establish themselves, they'll do so bearing fresher, more pernicious code.

Or at least, Bowers says, a code of a different horror: "The takedown is likely to accelerate the trend toward peer-to-peer botnets, rather than the more centralized command-and-control structure [McColo's users employed]." In other words, enjoy the relative quiet in the wake of the giant takedown. We may not see its like again -- not because the spam's going away, but because the bad-guy dinosaurs might start making like mammals.

Comments

View comments by with a score of at least

Mac OS X servers stop spam better and a Mac is the best anti-malware solution to date.

Score: 0

|

Wow... usually I get about 200 spam messages a day... yesterday I only got 58...

Score: 0

|

lol, the irony is biting!

Score: 0

|

Haha.
That is quite some timing, indeed.

Score: 0

|

Personally, Ive seen an increase in the past couple of days, so someone has already picked up the baton.

Score: 0

|

Fantastic. Based on a single observation you are able to predict the events on the entire internet. Can I hire you?

Score: 0

|

He's just saying for himself. Looking through my spam logs I show no difference at all, not even 1%.

Score: 0

|

If a group was clever enough, they might pretend to be an evil ISP till they got enough info on these losers, then took them out of commission all at once.

Score: 0

|

EC's Kroes to US senators: Mind your own business on Oracle + Sun

If the AP is accurate, the EU's antitrust chief just told the United States Senate that any merger that takes place in the world is more her affair than theirs.

What does AT&T's 'Mark the Spot' app say about service quality?

That's a question for Betanews readers to answer in comments to this post.

Windows fix for TLS security bug still forthcoming, won't be Tuesday

Anyone looking for a fix for last month's discovery of a potentially serious security hole in TLS and SSL may have to wait until everyone is ready to act together.

Google rolls out real-time search, Near Me Now, extended personalization

Over time, searches from PCs and mobile phones will grow even "more personalized." But what about user privacy and search results that give you "the truth"?

Betanews Podcast: Rupert Murdoch and the buying stuff online problem

We'll have a more difficult time paying for online news if the underlying protocol for online payment has a big gaping hole in it.

Not the first, not the last, technology predictions for 2010

Carmi Levy | Wide Angle Zoom: The real truth is probably that what went around in 2009, will come around to haunt us next year.

Google Goggles: Hands on with the Shazam of the Real World

Google today unveiled Goggles, its visual search lab for Android devices that identifies objects by sight.

Microsoft: Windows 7 Family Pack wasn't 'pulled,' it just sold out

If you hurry, you may still be able to find the last Family Pack upgrade editions hanging around retail store shelves, but probably not so much online.

Clever iPhone game returns after being bumped over a name dispute

The game's simple concept and multitude of platforms and puzzles manage to pull off a retro, 8-bit style that's reminiscent of an old Atari game given a modern makeover.

Intel's marriage of CPU and GPU not ready for prime time

Although there will be an Intel component this month that can compute and plot in parallel, Betanews was told today, it won't be based on Project "Larrabee."

An alternative to Research in Motion's enterprise e-mail? There's an app for that

Good Technology today released an iPhone app compatible with its enterprise e-mail solution.