0 commentsWith Akamai claiming that their recent Denial of Service Attack was orchestrated via a complex bot net, I'm reminded of an e-mail that was sent to my BuddyGopher service last month.
We've been investigating the growth of an IRC botnet using a variant of Agobot/Gaobot/Phatbot to propagate itself across numerous university networks. Various reports suggest that anywhere from 10,000 to 60,000 systems have been part of this botnet, and that some keylogging software has been involved. These are unconfirmed reports, but they are quite plausible.
The botnet uses a number of different propagation mechanisms, but it is most successful in doing some social engineering. For example, infected systems will masquerade AOL Instant Messenger "buddies" by including a reference in away messages with something like:
i just made a screensaver! everyone check it out
Continue reading. Did AIM away messages contribute to the recent Akamai DDoS attack?