<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>The Italian Honey Project &#187; Botnet 2.0</title>
	<atom:link href="http://www.honeynet.it/category/botnet/botnet-2-0/feed" rel="self" type="application/rss+xml" />
	<link>http://www.honeynet.it</link>
	<description>The Italian chapter of the Honeynet Research Alliance</description>
	<lastBuildDate>Wed, 11 Jan 2012 11:44:56 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Another botnet that uses Twitter as C&amp;C</title>
		<link>http://www.honeynet.it/botnet/another-botnet-that-uses-twitter-as-cc</link>
		<comments>http://www.honeynet.it/botnet/another-botnet-that-uses-twitter-as-cc#comments</comments>
		<pubDate>Wed, 15 Sep 2010 14:50:18 +0000</pubDate>
		<dc:creator>marco.riccardi</dc:creator>
				<category><![CDATA[Botnet]]></category>
		<category><![CDATA[Botnet 2.0]]></category>
		<category><![CDATA[social network]]></category>
		<category><![CDATA[Twitter botnets]]></category>

		<guid isPermaLink="false">http://www.honeynet.it/?p=348</guid>
		<description><![CDATA[
Security researchers have discovered another botnet that uses Twitter as a command and control channel.Malware-infected drones in the Mehika Twitter botnet, active in Mexico this summer, take instructions from a Twitter account maintained by hackers instead of conventional command and control servers. The use of Twitter as a botnet command channel was first detected in [...]
]]></description>
			<content:encoded><![CDATA[<blockquote><p>Security researchers have discovered another botnet that uses Twitter as a command and control channel.Malware-infected drones in the Mehika Twitter botnet, active in Mexico this summer, take instructions from a Twitter account maintained by hackers instead of conventional command and control servers. The use of Twitter as a botnet command channel was first detected in August 2009 before similar techniques were applied to abuse Facebook profiles as command channels a few months later in November.</p></blockquote>
<p>via <a href="http://www.theregister.co.uk/2010/09/15/mexican_twitter_botnet/">Mexican Twitter-controlled botnet unpicked • The Register</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.honeynet.it/botnet/another-botnet-that-uses-twitter-as-cc/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Social networks used as C&amp;C server &#8211; Facebook?</title>
		<link>http://www.honeynet.it/botnet/social-networks-used-as-cc-server-facebook</link>
		<comments>http://www.honeynet.it/botnet/social-networks-used-as-cc-server-facebook#comments</comments>
		<pubDate>Thu, 22 Jul 2010 07:20:23 +0000</pubDate>
		<dc:creator>marco.riccardi</dc:creator>
				<category><![CDATA[Botnet]]></category>
		<category><![CDATA[Botnet 2.0]]></category>
		<category><![CDATA[facebook]]></category>
		<category><![CDATA[social network]]></category>

		<guid isPermaLink="false">http://www.honeynet.it/?p=313</guid>
		<description><![CDATA[
Brazilian Banker is a financial Trojan that targets consumers of Brazilian-based banks and other banks in Latin America. The Lab recently traced a social network profile that contained encrypted instructions for a variant of the Brazilian banker Trojan via Speaking of Security&#8230; &#124; Blog Entry: RSA FraudAction Research Lab &#124; Cy: 1684. After google groups [...]
]]></description>
			<content:encoded><![CDATA[<blockquote><p>Brazilian Banker is a financial Trojan that targets consumers of Brazilian-based banks and other banks in Latin America. The Lab recently traced a social network profile that contained encrypted instructions for a variant of the Brazilian banker Trojan</p></blockquote>
<p>via <a href="http://rsa.com/blog/blog_entry.aspx?id=1684">Speaking of Security&#8230; | Blog Entry: RSA FraudAction Research Lab | Cy: 1684</a>.</p>
<p>After <a href="http://www.symantec.com/connect/blogs/google-groups-trojan">google groups</a> and <a href="http://asert.arbornetworks.com/2009/08/twitter-based-botnet-command-channel/">twitter </a>, here is <a href="http://www.symantec.com/connect/blogs/trojanwhitewell-what-s-your-bot-facebook-status-today">another </a>example about how a social network  (probably Facebook)  is being (mis)used by bot headers for issuing commands to their zombies.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.honeynet.it/botnet/social-networks-used-as-cc-server-facebook/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Mobile-based Botnet built by researchers leveraging the Google Android&#8217;s App Market</title>
		<link>http://www.honeynet.it/botnet/mobile-based-botnet-built-by-researchers-leveraging-the-google-androids-app-market</link>
		<comments>http://www.honeynet.it/botnet/mobile-based-botnet-built-by-researchers-leveraging-the-google-androids-app-market#comments</comments>
		<pubDate>Tue, 22 Jun 2010 15:34:24 +0000</pubDate>
		<dc:creator>marco.riccardi</dc:creator>
				<category><![CDATA[Botnet]]></category>
		<category><![CDATA[Botnet 2.0]]></category>
		<category><![CDATA[Android]]></category>
		<category><![CDATA[mobile]]></category>

		<guid isPermaLink="false">http://www.honeynet.it/?p=274</guid>
		<description><![CDATA[
In a talk at the hacker conference SummerCon last Friday researcher Jon Oberheide gave a demonstration of just how easy it may be to infect large numbers of phones running Google s Android OS with hidden software that turns the devices into a zombie-like &#8220;botnet&#8221; under the control of a cybercriminal&#8211;particularly if that software associates [...]
]]></description>
			<content:encoded><![CDATA[<blockquote><p>In a talk at the hacker conference SummerCon last Friday  researcher Jon Oberheide gave a demonstration of just how easy it may be to infect large numbers of phones running Google s Android OS with hidden software that turns the devices into a zombie-like &#8220;botnet&#8221; under the control of a cybercriminal&#8211;particularly if that software associates itself with a phenomenon as popular and tween-entrancing as the upcoming Twilight Eclipse film.</p></blockquote>
<p>via <a href="http://blogs.forbes.com/firewall/2010/06/21/researcher-builds-mock-botnet-of-twilight-loving-android-users/">Researcher Builds Mock Botnet Of ‘Twilight’-Loving Android Users « The Firewall &#8211; Forbes.com</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.honeynet.it/botnet/mobile-based-botnet-built-by-researchers-leveraging-the-google-androids-app-market/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Guidelines for ISP for facing Botnets</title>
		<link>http://www.honeynet.it/botnet/guidelines-for-isp-for-facing-botnets</link>
		<comments>http://www.honeynet.it/botnet/guidelines-for-isp-for-facing-botnets#comments</comments>
		<pubDate>Mon, 07 Jun 2010 07:52:00 +0000</pubDate>
		<dc:creator>marco.riccardi</dc:creator>
				<category><![CDATA[Botnet]]></category>
		<category><![CDATA[Botnet 2.0]]></category>
		<category><![CDATA[ISP]]></category>

		<guid isPermaLink="false">http://www.honeynet.it/?p=268</guid>
		<description><![CDATA[
Very interesting initiative from the Australian IIA.It should be adopted by any ISP in the world . I would like to underline the &#8220;e&#8221; point , because it highlights the importance about collaborative actions against cybercrime. e) Developing mechanisms for ISPs to share information and collaborate about cyber security compromises and developments affecting other Australian [...]
]]></description>
			<content:encoded><![CDATA[<p>Very interesting initiative from the Australian IIA.It should be adopted  by any ISP in the world . I would like to underline the &#8220;e&#8221; point , because it highlights the importance about <span style="text-decoration: underline;">collaborative </span>actions against cybercrime.</p>
<blockquote><p>e) Developing mechanisms for ISPs to share information and collaborate about<br />
cyber security compromises and developments affecting other Australian ISPs.</p>
<p><a href="http://iia.net.au/images/resources/pdf/icode-v1.pdf">Internet Industry code of practice </a></p></blockquote>
]]></content:encoded>
			<wfw:commentRss>http://www.honeynet.it/botnet/guidelines-for-isp-for-facing-botnets/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Twitter®-Controlled Botnet SDK At Large</title>
		<link>http://www.honeynet.it/botnet/twitter%c2%ae-controlled-botnet-sdk-at-large</link>
		<comments>http://www.honeynet.it/botnet/twitter%c2%ae-controlled-botnet-sdk-at-large#comments</comments>
		<pubDate>Tue, 25 May 2010 09:07:41 +0000</pubDate>
		<dc:creator>marco.riccardi</dc:creator>
				<category><![CDATA[Botnet]]></category>
		<category><![CDATA[Botnet 2.0]]></category>
		<category><![CDATA[Twitter botnets]]></category>

		<guid isPermaLink="false">http://www.honeynet.it/?p=262</guid>
		<description><![CDATA[
BitDefender has released an emergency update to protect against a potential pandemic caused by the emergence of a botnet self-development kit controllable via the popular social media service Twitter®. In order to create their custom bot, an attacker only has to launch the SDK, enter a Twitter username that would act as a command &#38; [...]
]]></description>
			<content:encoded><![CDATA[<p>BitDefender has released an emergency update to protect against a potential pandemic caused by the emergence of a botnet self-development kit controllable via the popular social media service Twitter®. In order to create their custom bot, an attacker only has to launch the SDK, enter a Twitter username that would act as a command &amp; control center and modify the resulting bot’s name and icon to suit their distribution method.</p>
<p>via <a href="http://www.malwarecity.com/blog/twitter-controlled-botnet-sdk-at-large-813.html">Twitter®-Controlled Botnet SDK At Large &#8211; Malware City Blogs</a>.</p>
<p>Nice report,take a look at the video below:</p>
<p><a href='http://www.youtube.com/watch?v=sI0y_PUhoLk&#038;feature=player_embedded' >Twitter botnet </a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.honeynet.it/botnet/twitter%c2%ae-controlled-botnet-sdk-at-large/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Botnet as a service</title>
		<link>http://www.honeynet.it/botnet/botnet-as-a-service</link>
		<comments>http://www.honeynet.it/botnet/botnet-as-a-service#comments</comments>
		<pubDate>Tue, 25 May 2010 08:22:07 +0000</pubDate>
		<dc:creator>marco.riccardi</dc:creator>
				<category><![CDATA[Botnet]]></category>
		<category><![CDATA[Botnet 2.0]]></category>
		<category><![CDATA[Underground Economy]]></category>
		<category><![CDATA[Dark Clouds]]></category>

		<guid isPermaLink="false">http://www.honeynet.it/?p=260</guid>
		<description><![CDATA[
Cyber criminals are renting out their botnets for just £5.99 an hour, enabling unskilled crooks to launch DDoS attacks. [...] They found the herders used many of the typical advertising tools to attract people, from banner advertising to forum marketing, and then charged just under £45 for a full day of botnet attacks capable of [...]
]]></description>
			<content:encoded><![CDATA[<blockquote><p>Cyber criminals are renting out their botnets for just £5.99 an hour, enabling unskilled crooks to launch DDoS attacks.</p>
<p>[...]</p>
<p>They found the herders used many of the typical advertising tools to attract people, from banner advertising to forum marketing, and then charged just under £45 for a full day of botnet attacks capable of taking down websites and applications.</p></blockquote>
<p>via <a href="http://www.itpro.co.uk/623623/cyber-criminals-charge-just-6-for-access-to-a-botnet#close=1">Cyber criminals charge just £6 for access to a botnet | IT PRO</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.honeynet.it/botnet/botnet-as-a-service/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Cracking Down on Botnets &#8211;  Microsoft  against Waledac</title>
		<link>http://www.honeynet.it/botnet/the-official-microsoft-blog-%e2%80%93-news-and-perspectives-from-microsoft-cracking-down-on-botnets</link>
		<comments>http://www.honeynet.it/botnet/the-official-microsoft-blog-%e2%80%93-news-and-perspectives-from-microsoft-cracking-down-on-botnets#comments</comments>
		<pubDate>Thu, 25 Feb 2010 20:15:36 +0000</pubDate>
		<dc:creator>marco.riccardi</dc:creator>
				<category><![CDATA[Botnet]]></category>
		<category><![CDATA[Botnet 2.0]]></category>
		<category><![CDATA[Media]]></category>
		<category><![CDATA[Press]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[P2P]]></category>
		<category><![CDATA[waledac]]></category>

		<guid isPermaLink="false">http://www.honeynet.it/?p=176</guid>
		<description><![CDATA[
The takedown of the Waledac botnet that Microsoft executed this week – known internally as “Operation b49” – was the result of months of investigation and the innovative application of a tried and true legal strategy. [..] In a recent analysis, Microsoft found that between December 3-21, 2009, approximately 651 million spam emails attributable to [...]
]]></description>
			<content:encoded><![CDATA[<blockquote><p>The takedown of the Waledac botnet that Microsoft executed this week – known internally as “Operation b49” – was the result of months of investigation and the innovative application of a tried and true legal strategy.</p>
<p>[..]</p>
<p>In a recent analysis, Microsoft found that between December 3-21, 2009, approximately 651 million spam emails attributable to Waledac were directed to Hotmail accounts alone, including offers and scams related to online pharmacies, imitation goods, jobs, penny stocks and more.</p>
<p>[..]</p>
<p>This action has quickly and effectively cut off traffic to Waledac at the “.com” or domain registry level, severing the connection between the command and control centers of the botnet and most of its thousands of zombie computers around the world.</p></blockquote>
<p>via <a href="http://blogs.technet.com/microsoft_blog/archive/2010/02/25/cracking-down-on-botnets.aspx">The Official Microsoft Blog – Cracking Down on Botnets</a>.</p>
<p>Well done.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.honeynet.it/botnet/the-official-microsoft-blog-%e2%80%93-news-and-perspectives-from-microsoft-cracking-down-on-botnets/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Zeus “in-the-cloud” &#8211; CA Security Advisor Research Blog</title>
		<link>http://www.honeynet.it/botnet/zeus-%e2%80%9cin-the-cloud%e2%80%9d-ca-security-advisor-research-blog</link>
		<comments>http://www.honeynet.it/botnet/zeus-%e2%80%9cin-the-cloud%e2%80%9d-ca-security-advisor-research-blog#comments</comments>
		<pubDate>Thu, 10 Dec 2009 14:36:01 +0000</pubDate>
		<dc:creator>marco.riccardi</dc:creator>
				<category><![CDATA[Botnet]]></category>
		<category><![CDATA[Botnet 2.0]]></category>
		<category><![CDATA[Intelligence]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[zbot]]></category>
		<category><![CDATA[zeus]]></category>

		<guid isPermaLink="false">http://www.honeynet.it/?p=155</guid>
		<description><![CDATA[
A new wave of a Zeus bot (Zbot) variant was spotted taking advantage of Amazon EC2’s cloud-based services for its C&#38;C (command and control) functionalities. via Zeus “in-the-cloud” &#8211; CA Security Advisor Research Blog.
]]></description>
			<content:encoded><![CDATA[<blockquote><p>A new wave of a Zeus bot (Zbot) variant was spotted taking advantage of Amazon EC2’s cloud-based services for its C&amp;C (command and control) functionalities.</p></blockquote>
<p>via <a href="http://community.ca.com/blogs/securityadvisor/archive/2009/12/09/zeus-in-the-cloud.aspx">Zeus “in-the-cloud” &#8211; CA Security Advisor Research Blog</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.honeynet.it/botnet/zeus-%e2%80%9cin-the-cloud%e2%80%9d-ca-security-advisor-research-blog/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>[The Register] Bot herders hide master control channel in Google cloud</title>
		<link>http://www.honeynet.it/botnet/the-register-bot-herders-hide-master-control-channel-in-google-cloud</link>
		<comments>http://www.honeynet.it/botnet/the-register-bot-herders-hide-master-control-channel-in-google-cloud#comments</comments>
		<pubDate>Sat, 21 Nov 2009 16:41:41 +0000</pubDate>
		<dc:creator>marco.riccardi</dc:creator>
				<category><![CDATA[Botnet]]></category>
		<category><![CDATA[Botnet 2.0]]></category>
		<category><![CDATA[Press]]></category>

		<guid isPermaLink="false">http://www.honeynet.it/?p=150</guid>
		<description><![CDATA[
Cyber criminals&#38;apos; love affair with cloud computing just got steamier with the discovery that Google&#38;apos;s AppEngine was tapped to act as the master control channel that feeds commands to large networks of infected computers. The custom application was used to relay download commands to PCs that had already been infected and made part of a [...]
]]></description>
			<content:encoded><![CDATA[<blockquote><p>Cyber criminals&amp;apos; love affair with cloud computing just got steamier with the discovery that Google&amp;apos;s AppEngine was tapped to act as the master control channel that feeds commands to large networks of infected computers.</p>
<p>The custom application was used to relay download commands to PCs that had already been infected and made part of a botnet, said Jose Nazario, the manager of security research at Arbor Networks. Google shut down the rogue app shortly after being notified of it.</p></blockquote>
<p>via <a href="http://www.theregister.co.uk/2009/11/09/bot_herders_coopt_google_appengine/?">Bot herders hide master control channel in Google cloud • The Register</a>.</p>
<p>Really interesting article about new botmaster techniques regarding botnet management, explained by Jose Nazario. The are some linked articles  about using <a href="http://www.theregister.co.uk/2009/11/03/trojan_cnc_pokes_facebook/" target="_blank">Facebook</a> and <a href="http://www.theregister.co.uk/2009/08/13/twitter_master_control_channel/">Twitter</a> for the same purpose.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.honeynet.it/botnet/the-register-bot-herders-hide-master-control-channel-in-google-cloud/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

