Kaspersky Analysis: Black Market in Botnets
Virus analyst Yury Namestnikov investigated the structure, functionality and business model of botnets for antivirus firm Kaspersky Lab with some surprising results.
Since the time decades ago when networks consisted of a few dozen centrally controlled computers, botnets have steadily increased in number. Kasperky's Namestnikov speaks of the current widely distributed systems of millions of hijackable systems with decentralized control. The reason behind these zombie networks, as he calls them, is the money to be made, and that with little technical know-how.
Getting on board the cybercrime business no longer requires you to be a programmer. Cybercrime forums are now easily available on the Web to help in creating zombie networks and infecting them with netbots. "Bots for sale" signs are everywhere. And to make it even more egregious, obfuscation and encryption can also be applied to the bot code to keep it from being detected.
A netbot generator next has to work for its distribution, per spam, forum and social network postings or drive-by downloads. Bots often include self-replication functions that act as viruses or worms.
The tricks cybercriminals employ are often quite simple. One is drive-by downloads. Before downloading an interesting video, a user might first need to install a special program. When the user visits a prepared website, the drive-by download exploits a security hole in the browser to download malware, without the user suspecting a thing.
Income for cybercriminals can come from distributed denial-of-service (DDoS) attacks, theft of confidential information, spams, phishing, search engine spamming, click fraud and distribution of adware and malicious programs. As Namestnikov notes in his analysis, "if chosen, any of these sources can provide a cybercriminal with a good income. But why choose? A botnet can perform all of these activities- at the same time!"
| Gallery (3 images) |
|---|
|
Subscribe to our Linux Newsletters
Find Linux and Open Source Jobs
Subscribe to our ADMIN Newsletters
Support Our Work
Linux Magazine content is made possible with support from readers like you. Please consider contributing when you’ve found an article to be beneficial.
News
-
KDE Unleashes Plasma 6.5
The Plasma 6.5 desktop environment is now available with new features, improvements, and the usual bug fixes.
-
Xubuntu Site Possibly Hacked
It appears that the Xubuntu site was hacked and briefly served up a malicious ZIP file from its download page.
-
LMDE 7 Now Available
Linux Mint Debian Edition, version 7, has been officially released and is based on upstream Debian.
-
Linux Kernel 6.16 Reaches EOL
Linux kernel 6.16 has reached its end of life, which means you'll need to upgrade to the next stable release, Linux kernel 6.17.
-
Amazon Ditches Android for a Linux-Based OS
Amazon has migrated from Android to the Linux-based Vega OS for its Fire TV.
-
Cairo Dock 3.6 Now Available for More Compositors
If you're a fan of third-party desktop docks, then the latest release of Cairo Dock with Wayland support is for you.
-
System76 Unleashes Pop!_OS 24.04 Beta
System76's first beta of Pop!_OS 24.04 is an impressive feat.
-
Linux Kernel 6.17 is Available
Linus Torvalds has announced that the latest kernel has been released with plenty of core improvements and even more hardware support.
-
Kali Linux 2025.3 Released with New Hacking Tools
If you're a Kali Linux fan, you'll be glad to know that the third release of this famous pen-testing distribution is now available with updates for key components.
-
Zorin OS 18 Beta Available for Testing
The latest release from the team behind Zorin OS is ready for public testing, and it includes plenty of improvements to make it more powerful, user-friendly, and productive.



