Army of zombie PCs out of control

Infection mainly through drive-by downloads on supposedly harmless sites.

Archive notice: This article was originally published on November 1, 2007. Links and embedded videos are preserved as part of the historical record.

Worldwide, around eight million computers are currently actively serving hackers and cybercriminals without their owners noticing. “The army of remotely controlled zombie computers is almost impossible to get under control,” Thorsten Urbanski, spokesman for the security company G DATA, reports in a conversation with pressetext.de. Thanks to ever-new infections, botnet masters reportedly manage to keep the number of computers integrated into the networks at a high level. Failed computers, whether through cleaning or deactivation, are continually replaced.

“According to our findings, cybercriminals manage every day to infect more than 500,000 PCs with malware and integrate them into their botnets. More than 50 percent of the infections are attributable to drive-by downloads. With this distribution concept, spam merely serves to lure users to infected websites. A Trojan downloader then starts in the background completely unnoticed,” says Ralf Benzmüller, Head of G DATA Security Labs. In his assessment, drive-by infections are clearly on the advance. One problem here is that many security solutions do not permanently scan http traffic.

Most Internet users have now become more cautious when receiving e-mails and delete the file attachments of suspicious messages without opening them. Therefore, those who want to place Trojans on other people’s computers must also come up with new ways. Forums and online communities are a hot spot for reaching websites with drive-by downloads. Links to infected sites are placed there and users are encouraged to click with false promises. “It even goes so far that supposedly free antivirus and antispyware solutions themselves turn out to be Trojans,” Urbanski says.

The user themself almost never notices an infection. One indication of it is the computer slowing down. The pests often sleep in the background and become active only in certain situations – for example, when the online banking page is visited. Activity during a spam wave either does not noticeably load the computer or is limited in time in such a way that the PC functions perfectly again after a few minutes, Urbanski explains. Experienced users can use the command-line command “netstat -ano” to display open network connections. This makes it possible to determine whether the computer is involved in a DDoS attack.

In addition to caution on the part of the user, effective protection is possible only if security suites are installed on the PC that permanently check all http traffic. Updating the operating system and browser is equally necessary in order to close security gaps with patches. The online gamer community is said to be particularly at risk from zombie infections. Many players switch off the firewall and virus protection completely during the gaming session in order to avoid annoying pop-ups from the security programs, which actually warn when something is not right with the computer. “This very group, which likes to fight zombies in the virtual world, is therefore a perfect target for the botnet masters,” Urbanski concludes.