Pushdo Spamming Botnet: It has returned more aggressively!
Security experts at Fidelis Cybersecurity have discovered a new variant of the Pushdo spamming botnet, which has infected machines in more than 50 countries worldwide. The botnet is capable of sending approximately 7.7 billion spam messages per day.
"Pushdo was very successful at what it did, so its release in various revisions or versions makes a lot of sense to the 'bad guys,'" said Mike Buratowski, vice president of Fidelis Cybersecurity.
Pushdo is among the longest-running botnets. It was around 2007 when law enforcement agencies carried out at least four operations to stop it.
The main infection vectors of the Pushdo botnet are spam messages and drive-by download attacks. In some cases, experts noticed that it was dropped by another malware.
The strength of the Pushdo botnet is its frequently changing command-and-control servers, which make it resistant to law enforcement efforts. The Pushdo BOT tries to contact a sequence of different C&C servers. If the first server does not respond, the malware moves on to the second, and so on.
"Pushdo has advanced Command-and-Control techniques beyond what has been previously published in the research community. The DGA portion of this infrastructure uses a refined algorithm and has moved entirely to domains registered in Kazakhstan (.kz)," according to the advisory published by Fidelis Cybersecurity.
The maximum number of infections is in India, Indonesia, Turkey and Vietnam. The latest version of the Pushdo botnet is used by cybercriminals to spread several strains of malware, including the Fareit data stealer, Cutwail spam malware and online banking menaces, such as Dyre and Zeus.
In order to mitigate the infection, Fidelis provided a set of Yara rules that could be used by network administrators to prevent bot agents from communicating with C&C servers.


