Bitcoins, Blockchains, and Botnets
blogs.akamai.com
blogs.akamai.com
This malware makes a single https request to https endpoint for which users can affect contents, api.blockcypher.com. This does not seem too much different from many other places which can be changed by user - reddit, hn user profile, airtable, github, comment section at random website, mailing list archive, etc...
I’d think the solution is going to be the same, too: contact the server and ask them to block URL. In this case, blockcypher should detect the api calls with the right properties (address, query string, user agent) and return error code on them. If they feel creative, maybe return modified answer which will break malware’s shell parser, but will not affect regular json calls.
If the blockcypher refuses to cooperate, you deal with it like you do with bulletproof hosting: add hostname to malicious domain list and block at all protected customers’ sites.
Who owns the recipient address is completely immaterial. So is the existence of other exporters. No one says they have to mess with blockchain or the site’s database - all they need is one api endpoint. How many non-malware accesses are there that use v1 api, query that specific address, use curl user agent, and send ?limit=2 query? I bet none. That script is not flexible at all, it has a single hardcoded URL.
Finally, regarding the slow blocking : it is a valid concern, but it exists no matter if there is a blockchain or not. Remember that story about bots using invisible characters in the comments below someone’s Instagram account? I wonder how long it took researchers to explain that those innocuous looking comments from fresh accounts are actually malware related. Or imagine using some sort of foreign-language web forum as C&C: the admins there might not want to cooperate with US-based cyber security researchers at all.
Already done at least in 2016: https://www.cyber.nj.gov/threat-center/threat-profiles/botne...
I do not see what new functionality will bitcoin bring to this.
That DHT malware link's interesting, thanks.
“This means for $1 about 2,500 disruption transactions can be placed in the wallet. In the case of the current IP address, the Satoshi values that must be sent to the wallet by the operators to recover control total 43,262 Satoshis, or about $16.50. The quick math at current market prices for BTC suggests that for every $1 spent on disruption, the operators will need to spend over $41,000 ($16.50*2,500) to recover their operations and get the orphaned infected systems back to their (current) IP address.”
The estimates given also do not factor transaction fees (currently 0.00041 BTC ~= 25 USD) , the estimated costs are only in value given to the attacker.
For this specific botnet continuous denial of service also doesn't make sense. The attacker could easily setup an upgrade at an ip that chooses a different public address.
It also relies solely on blockcypher's api. I wonder if they were contacted and what their stance was.
I think the main reason they don't use one they control is the potential to trace where the original funds come from. There might be things you can do to obfuscate things, like tumbling the coins. It's all a risk though.
Of course it would
Look at economic history: places where people are able to save effectively tend to grow significant investment in economically productive activities.
I would probably use another crypto. Dogecoin would probably allow for a bigger payload at a smaller price. Eliminating the api calls described could be possible by implementing such a thing on ethereum, including a full client and running it in light mode. However the described method is much more light-weight
Instead of seizing and shutting down the command and control system, why not let it run for awhile and secretly monitor who connects to it? Are the malware operators always connecting to the command and control system via Tor or equivalent? They never slip up? I find it amazing that these huge malware operators are so rarely tracked down.
Definitely an interesting use case for BTC to route around such censorship.
Also they could just do it with 4 transactions at 8-bits each too.
I'm not a good writer so ignore the rambling.
https://medium.com/@sharemywin/after-reading-avoiding-a-poin...
Interesting use of the Bitcoin infrastructure.
Put to work to semi-nefarious ends in this case, but likely not the only use case.
Very nice.