BACK CHANNELS AND BITCOINS: ZEROACCESS' SECRET C&C COMMUNICATIONS

James Wyke · 2013

ZeroAccess is one of the most widespread threats currently plaguing the Internet. The total number of infected machines is in the tens of millions with the number of active infections holding in low seven fi gures. This huge botnet is designed to generate revenue for its owners through a variety of illicit means including click fraud, Bitcoin mining and pay-perinstall schemes. Although ZeroAccess has morphed signifi cantly during its lifetime, the current incarnation has stabilized on a UDP-based peer-to-peer protocol for its command and control. This protocol is extremely noisy and easy to spot at a network level, generally because fi xed, high-number ports are used. However, the ZeroAccess authors use other, much more subtle and harder-to-spot techniques to monitor and control their botnet. In this paper, we examine the secret communications channels used to administer the ZeroAccess botnet. We detail the various ways in which covert command and control traffi c is embedded into legitimate-seeming network data, evading casual analysis. We look at how the authors have established a pattern of deliberate misdirection, using a variety of fake data designed to lure researchers away from genuine targets.

Read the paper · More papers on PaperTik