Dorkbot, a malware family that operates with a botnet structure, was sinkholed by Polish authorities working with Microsoft and ESET.
Sinkholing is the process where webmasters set up a DNS server that sends fake information about the domains used by the botnet. So authorities and security companies installed DNS servers that told infected computers fake IPs for the botnet's command and control (C&C) servers, rendering it ineffective.
Dorkbot is a malware that we first saw in 2011, and was initially used to hijack accounts on Twitter, Facebook, PayPal, Gmail, Netflix, eBay, and other services.
The malware had spread to more than 190 countries via removable media, spam emails, but most often, through social networks.
At first, Dorkbot was only interested in account hijacking, but later it evolved, acquiring additional functions that allowed it to download and install other threats on infected systems. Among them were the Kasidet malware that could carry out DDoS attacks, as well as the Lethic spambot.
In addition to ESET, Microsoft, and the Polish Computer Emergency Response Team (CERT/PL), other organizations have also helped combat Dorkbot. These include Interpol, the FBI, the United States Department of Homeland Security, and more.
According to data provided by Microsoft, during the sinkholed process, Dorkbot was running on a network of 120,000 infected computers.
To help victims of the botnet, ESET offers a free tool that allows users to detect and remove Dorkbot from their systems.
| Dorkbot | DOWNLOAD Version: 1.1.0.5 Last updated: 2015-12-01 16:20:24 |
