Pushdo Botnet Morphs To Elude Hunters

  /     /     /  
Publicated : 22/11/2024   Category : security


Pushdo Botnet Morphs To Elude Hunters


U.S., other national government agencies, contractors, and military networks found housing new Pushdo bots as botnet adds stealthier features to evade detection, takedown



A botnet of botnets that has been disrupted by researchers multiple times during the past few years has been retooled with features that make its detection more difficult and its takedown nearly impossible without legal action.
The
Pushdo botnet
-- which provides the infrastructure for other malware and botnets and spreads a malware downloader program that, in turn, drops Cutwail, Gameover Zeus, and BlackHole Trojans -- is now employing Domain Generation Algorithm (DGA) as a resilient backup command-and-control (C&C) infrastructure, RSA encryption to prevent researchers from taking over the botnet, and phony JPEG image files to hide C&C traffic.
Researchers with Damballa, Dell Secureworks, and Georgia Institute of Technology recently teamed to study this new variant of Pushdo, which was first spotted by Damballa and its homegrown DGA detection tool. Among the victims infected by Pushdo are several U.S. and other national government agencies, government contractors, and military networks, the researchers found.
This is the most elaborate [move by a] botnet trying to hide its own command and communications, says Brett Stone-Gross, senior security researcher at Dell Secureworks, who helped Damballa confirm the C&C traffic it had spotted using DGA was Pushdo. They added resiliency with the DGA, and along with that they implemented RSA encryption so researchers, law enforcement, or their rivals cant control the botnet and use it against itself. They are the only ones who can control their botnet, Stone-Gross says. All researchers can do is record IP addresses and metadata, he says.
And in the latest twist today -- possibly in response to the discovery of their new techniques features -- the Pushdo gang was spotted pushing yet another variant of the malware, one that generates .kz domains instead of .com domains, according to
Seculert, which also is studying Pushdo
. It seems like they noticed that they are being probed, as the variants were uploaded to the hijacked webserver few hours before the report went public, says Aviv Raff, CTO at Seculert.
Pushdo, which is run by a well-funded Eastern European cybercrime gang, boasts anywhere from 175,000 to a half-million bots each day, and is spread mainly via the massive and prolific Cutwail spam botnet. Pushdo basically acts as the infrastructure for botnet activity -- everything from traditional spam to spreading malicious Trojan like Zeus and SpyEye that steal financial credentials. Its mostly spread via the massive Cutwail botnet and has survived four takedowns in five years.
It shows that they probably make a good amount of money through spam email. Its like any business: Its important to maintain a resilient infrastructure, and if the infrastructure goes down, you lose money, Stone-Gross says.
The addition of DGA for its backup C&C basically allows Pushdo to prevent interference with its C&C -- think blacklisting or extracting C&C domain names -- by making the C&C domain names a moving target, dynamically generating domain names, and using just one at a time, which later gets discarded.
They are trying to build a system thats immune to takedown, says Jeremy Demar, senior researcher at Damballa. Demar says Pushdo downloads encrypted malware payloads so researchers cant analyze them or detect them.
[Pushdo botnets spam traffic cut by 80 percent in takedown. See
Major Disruption of Pushdo Botnet Wasnt The Original Goal
.]
Researchers saw some 1.1 million unique IP addresses making Pushdo C&C requests in a two-month period, and around 35,000 unique IPs connect each day. Pushdos DGA generates around 1,380 unique domain names daily.
India and Iran are home to the most Pushdo-infected machines, but Mexico, Thailand, Indonesia, and the U.S. also have Pushdo bots. An average of 23,000 unique hosts in the U.S. have tried connecting to Pushdos DGA domain names. The government and military victims -- which are a small percentage of the overall bot population -- likely were inadvertent infections, Damballas Demar says. Someone downloaded an email, he says.
The malware also generates fake traffic to legitimate websites in an attempt to mask its C&C communications. The C&C servers will also respond with a jpeg image with encrypted, embedded malware payloads to hide any additional files it wants to download, Demar wrote in a blog post.
Takedown of Pushdo would require legal intervention, the researchers say: VeriSign requires a court order before it takes action on its .com domain customers.
Damballas full report on Pushdo is available
here
(PDF) for download, and Dell Secureworks is
here
(PDF) for download.
Have a comment on this story? Please click Add Your Comment below. If youd like to contact
Dark Readings
editors directly,
send us a message
.

Last News

▸ Some DLP Products Vulnerable to Security Holes ◂
Discovered: 23/12/2024
Category: security

▸ Scan suggests Heartbleed patches may not have been successful. ◂
Discovered: 23/12/2024
Category: security

▸ IoT Devices on Average Have 25 Vulnerabilities ◂
Discovered: 23/12/2024
Category: security


Cyber Security Categories
Google Dorks Database
Exploits Vulnerability
Exploit Shellcodes

CVE List
Tools/Apps
News/Aarticles

Phishing Database
Deepfake Detection
Trends/Statistics & Live Infos



Tags:
Pushdo Botnet Morphs To Elude Hunters