Thursday, December 13, 2012

Skynet Botnet Controlled Over Tor

A botnet has been discovered that uses a hidden Tor IRC service for command and control. Although Tor tends to be on the slow side, the extra layers of anonymity make it significantly difficult and maybe even impossible to locate either the C&C servers, or the people running them.

All kinds of direct hack attacks probably occur over the Tor network. This use however, is interesting in that there currently is no known method for shutting them down. I expect that once a compromised server is found, researchers will begin looking for vulnerabilities on the hidden Tor services in the hopes of finding a vulnerability that exposes the actual IP information.

The article discusses how the bots are being used to mine bitcoins.

Either way, this is interesting, and probably will soon be the de facto way to run botnets.

No comments:

Post a Comment