HomeSecurityZeroAccess Botnet “wakes up” after six months of “sleep”

ZeroAccess Botnet “wakes up” after six months of “sleep”

Activity from the peer-to-peer (P2P) botnet ZeroAccess, also known as Sirefef, was detected by security researchers on January 15, after a period of inactivity since July 2, 2014.

ZeroAccess Botnet

The botnet has returned to its old activity of distributing click-fraud templates to compromised systems, but there has been no increase in its size, according to Dell SecureWorks. This means that the botnet relies on hosts that have been infected in the past.

In December 2013, law enforcement agencies in Europe and the United States, along with Microsoft and A10 Networks, joined forces in an operation to combat ZeroAccess. Its P2P architecture, however, made it resilient as any infected computer on the network could act as a command & control server (C2C).

A P2P ensures that the botnet can be restarted at any time by its operators unless all infected systems are cleaned.

Click-fraud attacks are not directed against the user, because their goal is not to steal sensitive information, but they cause losses to advertisers, who are forced to pay for ads that are accessed by bots and not by the user.

The Dell SecureWorks Counter Threat Unit (CTU) research team notes that ZeroAccess administrators have not attempted to expand the network, resulting in a smaller botnet .

However, the term “smaller” still refers to tens of thousands of computers, as 55,208 unique IP addresses have taken part in the malicious actions, 38,094 of which are 32-bit systems and 17,114 run on a 64-bit platform.

“ ZeroAccess is split into two distinct botnets operating on different UDP ports: UDP 16464/16471 – which are used by compromised Windows systems running on 32-bit architecture, and UDP ports 16465/16470 – which are used by compromised Windows systems running on 64-bit architecture,” a blog post from CTU reports .

According to telemetry data from Dell, the most affected country is Japan, accounting for 27.7% of infections, followed by India (13.5%) and Russia (12.9%). Other countries where breaches have been detected include Italy (6.6%), the US (4.6%), Brazil (3.9%), Taiwan (3.8%), Romania (3.5%), Venezuela (2.2%) and Germany (2.0%).

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS