Storm botnet connected to phishing ring

Experts fear hackers selling time on botnet

Written by Shaun Nichols in California

An investigation has uncovered a link between a recent phishing operation and the infamous Storm worm.

Security experts believe that the botnet of infected PCs is now being leased out by its operator to other criminal groups.

Researchers at security firm F-Secure uncovered the connection while investigating a group of phishing sites posing as UK bank Halifax.

The company found that the hosting of the phishing domain was being passed around among a number of IP addresses.

When researchers cross-checked the addresses with other domains, they found domains as 'hellosanta2008.com' and 'postcards2008.com' which had been linked to fraudulent greeting cards used to spread the Storm worm over the holiday season.

The findings suggest that the operators of the Storm botnet are now allowing the network of infected machines to be accessed by other groups for various criminal activities.

"We have not seen this before. But we have been expecting something along these lines," said F-Secure chief research officer Mikko Hyppönen in a blog posting.

F-Secure is among many security firms to warn that Storm could become a commercial entity in 2008.

Researchers fear that Storm's computing power could be rented out for various criminal activities.

Storm first appeared in early 2007, circulating malware disguised as film of flooding in Europe. Since then, the controllers have used everything from spam runs to fake greeting cards to snare victims.

Experts warn that the tactics used to build and operate Storm could become a model for future botnets.

Tags:

Further reading

Spam levels reach 95 per cent in 2007

Spammers getting more and more inventive   More...

vnunet.com analysis: The malware 'shadow economy'

Online criminals using techniques of the free market   More...

Hackers create new year Storm mutant

'Tis the season to spread malware   More...

The main internet threats for 2008

Mobile malware, botnets, phishing and ID theft   More...

Related articles

Storm resurfaces for Valentine's Day

Old worm, old trick   More...

Storm worm seeks out April fools

New malware attack no laughing matter   More...

Storm clouds Valentine's Day inboxes

Malware continues to recruit unwary users   More...

Hackers step up website attacks

Security forecast for 2008 makes grim reading   More...

Do you agree?

Advertisement

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Watch

16 May 2008

2.97 MBXP on OLPC, broken dreams and Yahoo fights back More...

15 May 2008

3.28 MBDark fibre, mobile TV and solar power More...

14 May 2008

2.66 MBOnline inequality, mobile thumbprints and corporate raids More...

Poll

HOME WORKING

HOME WORKING

Do you let any or all of your employees work from home?

Previous poll results

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Spotlight

OLPC

OLPC to ship with Windows XP

Microsoft teams up with One Laptop per Child project   More...

The Sims

The Sims goes flat-pack with Ikea

Virtual world gets Swedish wood   More...

Advertisement

Microsoft-Yahoo

Yahoo board fights back at Icahn

Investor accused of 'significant misunderstanding' in Microsoft saga   More...

MySpace

Woman charged over MySpace suicide

Lori Drew indicted on federal charges   More...

Advertisement