Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - News & Analysis - Botnet Businesses Face Growing Pains – Too Much of a Good Thing?
News & Analysis

Botnet Businesses Face Growing Pains – Too Much of a Good Thing?

ISBuzz TeamBy ISBuzz TeamSeptember 13, 2013Updated:July 8, 20244 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Damballa
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

A few months ago we started tracking a botnet (arbitrarily named LazyAlienBikers) whose origins we did not know and whose malware was undetected.  Later on it would come to be associated with MEvade malware.  What’s interesting about this particular botnet, and how has it evolved?

Through analysis of our various Big Data systems [*pauses for groans*, but what else would you call a collection of massive data sets that allows us to discover advanced threats without having to see the malware first] we were able to identify the important details – parse out the related C&C infrastructure, identify traffic patterns, cluster component-related indicators, scope the victims, map out additional infrastructure, follow the herd as the threat evolved, etc.  On occasion we even stumbled across related binaries…

After building a sufficiently confident case that our customers wouldn’t want any piece of this action, we started flagging compromised devices for our customers, raising awareness, (and blocking these communications where customers wanted us to) and doing more escalation and follow-up, and that was it for a while – and so we continued to watch the threat evolve, work on attribution and continue to protect our customers.  Finally, at long last, other people started taking notice, especially when the bots started their fateful march on the Tor network.  This certainly was not the first botnet we’d seen use Tor but the size of it was beyond obvious.

To me, the most interesting aspect of this operation is how the evolution backfired.

 

Background

Size:

Initially we estimated LazyAlienBikers to control several million infected nodes (not less than 1.4 million or more than 5 million).  The wide range is due to a vast array of confounding variables including systemic bias from sampling methodology:

–  Differing infection rates amongst fixed broadband versus mobile versus non-broadband subscribers

–  …amongst North America verses Africa verses Asia

–  …IP churn rate, device to IP ratios

–  …callback frequency from one variant/component to the next

–  …etc.

More recently, the switch to Tor and the overwhelming deviation in Tor project metrics seems to corroborate the range and suggest that the actual number is toward the higher end.

Behavior:

LazyAlienBikers is present in over 80% of enterprise networks we monitor.  The behavior of the infection varies significantly from one asset to the next and from environment to environment.

For example:

% of Infected Enterprises                               Behavior

20% – Malware infections failing to establish a connection to the control server (at least while in the monitored environment)

44% – Connected to C&C Control Server, but essentially lay dormant, doing little more than updates from time to time

22% – Active infection, identifying paths with small amounts of successful data exfiltration

14% – Active infection, with vast quantities of data exfiltration

NOTES: Some customers took immediate corrective actions or had Damballa Failsafe blocking enabled.  While 14% of customers had significant data exfiltration, only select devices were observed exfiltrating significant data.

Timeline:

We started tracking the botnet this year, but due to its size there’s evidence to suggest it started further back .  It has evolved over time, in terms of both the C&C infrastructure, protocol, and of course malware used.  Some significant recent dates in the evolution:

•  June 28: Microsoft first distinguished MEvade from other malware families.  Sample coverage was still sparse, but MS deserves credit for being the first (and subsequently most consistent) amongst AV scanners to provide any distinctive coverage at all.

•  July 11: The LAB threat actor changes domain usage tactics to focus more on dyndns providers such as Afraid, No-IP, and ChangeIP.  These are used for multiple functions such as using SSH to connect over standard http(s) ports and dropping new malware binaries.

•  August 19: Ramps up Tor usage.

•  September 6: AV industry at large is talking about it, thanks to Fox-IT, Trend, and others…

•  September 9: Many samples still seem to go undetected by major AV vendors.  Including, sadly, some of the oldest samples.  Those that are detected are often only with the most aggressive heuristics and/or cloud reputation (which isn’t a bad thing in and of itself, but means not all of their enterprise configurations and environments are covered).

So there’s the background.  This was a pretty substantial botnet to be so ignored for so long, the hallmark of a successful threat actor.  So what changed?  Why did a botnet nobody else seemed to notice for a very long time suddenly take front page?  Essentially, they were too good.

To learn about the motivation and network behavior then read the full article from Damballa

For more information on LazyAlienBikers/MEvade, visit 

Mark Gilbert, Security Researcher Damballa 

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Exploited Faster, Patched Slower: Verizon DBIR 2026 Shows Security Teams Losing Ground

May 20, 20265 Mins Read

Security’s Blind Spot: The Threats Hiding in “Low-Severity” Alerts

May 6, 20265 Mins Read

Why OSINT deserves the same status as other intelligence disciplines

March 17, 20266 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}