Kraken: The biggest, baddest botnet yet

《endurer注:1。Kraken: 相传在挪威海中出现的怪物。详见:

At the recent RSA 2008 gathering Damballa, an Internet security company devoted solely to researching botnet technology, is reporting some “not so good news.” In the article, “Kraken BotArmy-Twice as Big as Storm; Evades over 80% of Installed Antivirus Software” (pdf) Ashley Vandiver of Damballa explains:

在近期的RSA 2008上,一家独自投身于研究僵尸网络技术的互联网安全公司Damballa,正报道一个“不怎么好的消息”。在文章“Kraken僵尸网络队伍-有Storm僵尸网络的两倍大;可躲避超过80%的已安装的反病毒软件”中,Damballa的Ashley Vandiver说明:

《endurer注:1。Damballa:由Dagon和Wenke Lee成立的一家的公司,致力于开发能够保护用户的计算机不受这种类型攻击的方法。Damballa标榜自己是反僵尸网络的供应商,能够通过追踪计算机是否与那些已知是恶意的DNS服务器通讯,来鉴别出受到侵害的计算机。
2。Storm:2007年1月据国外媒体最新报道,名为“Storm worm”的木马开始传播,攻击了至少1600万台计算机,组建了一个大型僵尸网络。》

This new BotArmy, named “Kraken,” is twice as big as Storm, with over 400,000 distinct victims observed daily as compared to Storm’s 200,000 victims. Kraken has gone undetected on 80% of computers with antivirus software installed.


Remember Storm botnets?

For those not familiar with Storm, up until now it had the honor of being the largest and most notorious botnet to date. Experts consider the Storm botnet to be powerful enough to knock entire countries off the Internet. The Wikipedia entry “Storm botnet” gives an accurate accounting of how the Storm Worm — a trojan horse that spreads through e-mail — is used to recruit infected computers (zombies) into the Storm botnet. Estimates have the number of zombies to be around 200,000. The Wiki entry also does a nice job of explaining what a botnet is and how it can be such a threat.

对那些不熟悉Storm僵尸网络的人,直到现在,它是到迄今止存在的最大和最臭名昭著的僵尸网络之冠。专家们认为Storm僵尸网络足以中止整个国家的互联网。维基百科上的“Storm botnet”条上给出了Storm蠕虫的确切的记录—一个通过电子邮件传播的特洛伊木马—被用来将被感染的电脑(僵尸电脑)补充到Storm僵尸网络。估计拥有200,000台左右的僵尸电脑。维基百科条目也友好地解释了什么是僵尸网络,以及它如何造成如此的威胁。

Some very sophisticated coding goes into botnet programs. For example, servers controlling the botnet automatically change the software code at pre-determined times to avoid detection by antivirus applications. On top of that, all botnet management traffic is encrypted and uses peer-to-peer control techniques, which make monitoring and disabling the botnet very difficult.


On that same Wiki entry there is a very interesting quote from IBM researcher Joshua Corman:

在同一维基条目中,有一个对IBM研究员Joshua Corman的有趣引述:

“This is the first time that I can remember ever seeing researchers who were actually afraid of investigating an exploit. Researchers are still unsure if the botnet’s defenses and counter attacks are a form of automation, or manually executed by the system’s operators.If you try to attach a debugger, or query sites it’s reporting to, it knows and punishes you instantaneously. Over at SecureWorks, a botnet DDoS-ed a researcher.”

“这是我的记忆中第一次看到研究人员对研究一个漏洞利用感到害怕。研究人员仍不清楚,僵尸网络的防御和反攻击,是一种自动化的形式,还是该系统的操作者手动执行的。如果您尝试附加调试,或查询报道的网站,它知悉并立即惩罚你。看看SecureWorks ,一个僵尸网络DDoS过的研究人员。”

Kraken builds on Storm

Both Storm and Kraken rely on social engineering to propagate. Damballa believes that the preferred attack venue is to have the malware appear as an image file. When a user attempts to view the file, it’s all over. For those wondering if they may be infected, Damballa lists compromised public IP addresses on its Web site that it updates regularly. If perchance, you find a public IP address on the list that you are concerned about, Damballa has remediation instructions that explain how to identify the process and remove the malware.


《endurer注:1。be all over:全部结束(四处传播,奉承,占压倒优势)
2。concern about:对…的关心/忧虑》

What’s different about Kraken?

Instead of using peer-to-peer techniques to control the botnet, Kraken uses command and control (C&C) servers that are located in different parts of the world. Each infected computer has a list of the C&C servers. If the current C&C server is disabled, the zombies check in with the next server on the list. Using this approach eliminates the problem of having a portion of the botnet go down if one of the peers is taken off-line.


Now the scary stuff

It appears that infected computers don’t just belong to what researchers like to call the non-tech-savvy computer users. At last count, 50 Fortune 500 companies have compromised computers. Paul Royal, principal researcher at Damballa commented that Damballa is trying to figure out how the bot infestation is getting past the perimeter defenses of some of the best-protected networks in the world:

看来好像被感染的电脑不再属于研究人员喜欢称之为无技术常识电脑用户的人了。最新的统计,50个财富500强公司有受害的电脑。Damballa首席研究员Paul Royal评论说, damballa正试图弄清楚僵尸网络侵扰是如何越过一些世界上最佳保护网络的周边防御的:

《endurer注:1。It appears that:ad. 看来(看来好像)》

“Somehow, this thing is evading the canonical defense techniques that the enterprises use, such as intrusion detection systems and intrusion prevention systems. It should be caught by IDSes, IPSes and firewalls and it’s not.”


Final thoughts

For now, it appears that the Kraken botnet is just delivering massive amounts of spam. Damballa claims to have seen some infected machines sending over 500,000 spam messages per day. I do not even want to think about what a half a million infected machines sending 500,000 messages per day would do to most anti-spam services.

现在,看来kraken僵尸网络只是提供了发送的垃圾邮件。 Damballa声称已看到一些受感染的机器每天发送超过五十万的垃圾邮件。我甚至不敢想像50万受感染机器每天发送500000个邮件会给大多数反垃圾邮件服务带来什么。

《endurer注:1。do to:给与,加以,伤害》


