The ZeroAccess botnet is one of the largest known botnets in operation, having infected more than 1.9 million computers worldwide, as observed by Symantec in August 2013. A key feature of the ZeroAccess botnet is its use of a peer-to-peer (P2P) command-and-control (C&C) architecture, which gives the botnet a high degree of availability and redundancy.
Since there is no central C&C server, it is not possible to simply disable the attacker servers to neutralize the botnet. Any time a computer is infected with ZeroAccess, the first thing it does is approach peers and exchange details on the P2P network. This way, the bots recognize others like them and can spread instructions and files across the network quickly and efficiently.
In the ZeroAccess botnet, there is constant communication between peers. Each peer is constantly connected to other peers to exchange lists and check for updated lists, making them highly resistant to any removal attempt.
The sinkhole method used by the botnet
Last May, technicians began to delve into the mechanism used by ZeroAccess bots to communicate with each other to see how they could implement the sinkhole method in the botnet. During this process, a specific vulnerability was examined that offered a difficult, but not impossible, way to use the sinkhole method in the botnet.
Additional lab tests were conducted and a practical way to free the peers from the botmaster was found. During this process, monitoring of the botnet continued, and on June 29, a new version of ZeroAccess was detected being distributed via the peer-to-peer network.
The updated version contained a number of changes, but mainly had modifications that improved the design flaws that made the botnet vulnerable. The weakness of the ZeroAccess P2P mechanism was reported by researchers in a report published in May 2013. This fact may have motivated the ZeroAccess botmaster to upgrade it, preventing any attempt to sinkhole the ZeroAccess botnet.
Seeing the changes, and already having a plan in place to implement, Symantec had only one option: to put the botnet response plan into action right away, or risk missing the opportunity. On July 16, the sinkhole process of ZeroAccess-infected systems began. This process resulted in the removal of more than half a million bots and was a blow to the number of bots controlled by the botmaster.
On average, it took just 5 minutes of P2P activity to initiate the ZeroAccess bot sinkhole. To understand the implications of this action, one must first understand the use of the ZeroAccess botnet.
ZeroAccess: courier service
Based on its construction and behavior, ZeroAccess appears to have been primarily designed to deliver payloads to infected computers. In the ZeroAccess botnet, the productive activity (from the attacker's perspective) is performed by the payloads downloaded by the infected computers, which can be summarized into two main types, which are aimed at revenue-generating activities.
Click fraud
One type of payload is a click fraud Trojan. Online advertisements download to the computer contain a Trojan that then creates fake clicks on the ads, making them appear to have been made by legitimate users. These fake clicks count towards the payment in pay-per-click (PPC) programs.
Bitcoin mining
This virtual currency has become a target for cybercriminals. The way each bitcoin exists is based on performing mathematical operations, also known as “mining,” on computer hardware. This activity has immediate value for the botmaster and a cost to unsuspecting victims. The implications of this activity were examined in depth using old computers available in the lab.
Everything you need to know about Bitcoin in 3 minutes [Video]
Stopping P2P botnets is difficult but not impossible
The investigation into this botnet revealed that despite the resilience of ZeroAccess' P2P architecture, Symantec was able to sinkhole a large number of bots. This means that these bots will no longer be available to receive commands from the botmaster, but will also be used by the botnet to distribute commands or renew/generate additional revenue.
Meanwhile, Symantec has been working closely with ISPs and CERTs globally to share information that will help infected computers be cleaned.
Source: techgear.gr

![Analyzing the ZeroAccess Botnet and its relationship to ad fraud and Bitcoins [Infographic] 1 Analyzing the ZeroAccess Botnet and its relationship to ad fraud and Bitcoins [Infographic]](https://cdnglobal.secnews.gr/wp-content/uploads/2013/10/21000204/ZeroAccess_botnet_infection-1.jpg)
![Analyzing the ZeroAccess Botnet and its relationship to ad fraud and Bitcoins [Infographic] 2 zeroaccess](https://cdnglobal.secnews.gr/wp-content/uploads/2013/10/21000203/zeroaccess-1.jpg)