Researcher: Worm infects 1.1M Windows PCs in 24 hours
It would make 'one big badass botnet,' says Finnish security company
Computerworld - The computer worm that exploits a months-old Windows bug has infected more than a million PCs in the past 24 hours, a security company said today.
Early Wednesday, Helsinki, Finland-based security firm F-Secure Corp. estimated that 3.5 million PCs have been compromised by the "Downadup" worm, an increase of more than 1.1 million since Tuesday.
"[And] we still consider this to be a conservative estimate," said Sean Sullivan, a researcher at F-Secure, in an entry to the company's Security Lab blog. Yesterday, F-Secure said the worm had infected an estimated 2.4 million machines.
The worm, which several security companies have described as surging dramatically during the past few days, exploits a bug in the Windows Server service used by all supported versions of Microsoft Corp.'s operating system, including Windows 2000, XP, Vista, Server 2003 and Server 2008.
Microsoft issued an emergency patch in late October, fixing the flaw with one of its rare "out of cycle" updates.
The soaring number of infections by Downadup -- also called "Conficker" by some security companies -- prompted Microsoft to add detection for the worm to its Malicious Software Removal Tool (MSRT), the anti-malware utility that the company updates and redistributes each month to Windows machines on Patch Tuesday. The MSRT scans for known malware, then scrubs the system of any it finds.
Like researchers at firms such as Symantec Corp. and Panda Security, Microsoft blamed lackadaisical patching for the infections. "A number of our customers have contacted our support team for assistance with containment in environments that were, largely, not patched when the worm was released," said Cristian Craioveanu and Ziv Mador, two researchers at Microsoft's Malware Protection Center, in a Tuesday blog entry. "Either Security Update MS08-067 was not installed at all or was not installed on all the computers."
Craioveanu and Mador said that the highest number of infection reports had come from the U.S., Canada, Mexico, Korea and several European countries, including the U.K., France and Germany.
Yesterday, F-Secure also reported that it was spying on Downadup's command-and-control process by registering domains it thought the worm would try to use to download additional malware to infected PCs. The worm generates hundreds of possible domain names daily using a complex algorithm, said Mikko Hypponen, F-Secure's chief research officer.
"This makes it impossible and/or impractical for us good guys to shut them all down," acknowledged Hypponen in a blog entry. "The bad guys only need to predetermine one possible domain for tomorrow, register it and set up a Web site, and they then gain access to all of the infected machines. Pretty clever." Even so, F-Secure has registered some of the possible hosting domains so that it can eavesdrop on the attackers and get an idea of the number of infected PCs.
Other security firms have tried to preempt hackers by registering domains that they may use, but with mixed results. Last November, FireEye Inc. tried to stay ahead of criminals operating the "Srizbi" botnet by registering several hundred domains being used to resurrect the infected PC army, but had to give up the game when it got too costly.
"We have registered a couple hundred domains," said Fengmin Gong, chief security content officer at FireEye, at the time. "But we made the decision that we cannot afford to spend so much money to keep registering so many [domain] names."
As soon as FireEye conceded, the hackers were able to re-establish communication with their bots.
Microsoft recommended that Windows users install the October update, then run the January edition of the MSRT to clean up compromised computers.
It's not clear whether the hackers behind Downadup are building a botnet of their own, said Joe Stewart, a senior security researcher at SecureWorks Inc., in an interview today. For the moment, they seem satisfied with feeding victims fake security software, which pesters users with pop-ups until they pay for the worthless program.
However, F-Secure's Hypponen sounded worried about the possibility that machines infected with Downadup would be converted into bots. "It would make for one big badass botnet," he said.
Downadup roundup
- Downadup worm now infects 1 in every 16 PCs, says Panda
- US-CERT: Microsoft's advice on Downadup leaves users open to attack
- FAQ: How to protect your PC against the Downadup worm
- 'Amazing' worm attack infects 9 million PCs
- 1 in 3 Windows PCs vulnerable to worm attack
- Researcher: Worm infects 1.1M Windows PCs in 24 hours
- 'Huge increase' in worm attacks plagues unpatched Windows PCs
- Microsoft releases emergency Windows patch to head off worm attack
Read more about Security in Computerworld's Security Topic Center.
Downadup



- Backup and Disaster Recovery eGuide
- As the digital universe grows beyond imagination, enterprise IT executives face the daunting task of keeping their little pieces of it backed up...
- Forrester Research: Know your Facts: Understanding The Realities Of Desktop And Application virtualization
- Read Now.
- Windows 7 Migration Made Easier with Desktop Virtualization
- Read Now.
- Virtualization 2.0: The Desktop Revolution
- Read Now.
- Securing Data in the Cloud
- This document is intended to give a broad overview of our security policies, processes and practices. All Security White Papers
- Desktop virtualization keys innovation drive
- View now.
- Survival Guide: Overcoming the Obstacles to Effective Risk Management
- This virtual meeting for IT managers and CIOs is based on a new IBM study. Senior Vice Presidents and a Chief Technology Officer...
- The Evolution of Managed File Transfer
- Managed file transfer has evolved greatly from its earliest meaning of scheduled FTP to today's meaning of complete file governance, including visibility, enforcement,...
- How to cut software management costs and avoid over-spending in the future
- View now!
- Get a $20 Amazon Gift Card - Just watch a Demo
- View now! All Security Webcasts