Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.


06:40 PM
Connect Directly

Number of Botnet Command & Control Servers Soared in 2019

Servers worldwide that were used to control malware-infected systems jumped more than 71% compared to 2018, Spamhaus says.

For the second year in a row, the number of servers used by attackers worldwide to control malware-infected systems increased sharply.

The Spamhaus Project, which tracks both the domain names and the IP addresses used by threat actors for hosting botnet command-and-control servers (C2), identified 17,602 such servers hosted on a total of 1,210 different networks worldwide in 2019.

The number represented a big 71.5% jump over the 10,263 botnet C2 servers that Spamhaus detected and blocked in 2018, and a near doubling in number from the 9,500 servers in 2018. Botnet C2s, in fact, accounted for 41% of all the listings on Spamhaus' block list in 2019, compared to just 15% in 2017 and 25% last year.

The sharp increase is an indication of the growing popularity of botnets as an attack vector among threat actors, Spamhaus said in a report this week. About 60% of the new botnet C2s that Spamhaus detected in 2020 were associated with credential-stealing malware such as Lokibot and AZORult. About 20% -- the next highest proportion -- were used to control data-stealing Remote Access Trojans (RATs), the most prolific of which was Nanocore.

The Spamhaus Block List (SBL) is a real-time database of IP addresses and URLs associated with known spam sources and threats like botnet C2s. Companies and ISP can use the database tandem with other block lists to block spam and other online threats.

As with previous years, Spamhaus' data showed that some of the ISPs that hosted the highest number of botnet C2s last year were based in the United States. Over 1,580 botnet servers in 2019, for instance, were hosted on Cloudflare alone -- more than double the 629 hosted by second-place Alibaba of China.

In many cases, the command-and-control servers were running on compromised websites and servers belonging to customers of ISPs such as Cloudflare. This likely made it difficult for them to spot the illegal activity. But a substantial proportion were also set up via fraudulent registrations, as a result of weaknesses in the ISPs customer-vetting and verification processes, Spamhaus said.

But for the first time ever, Russia took the top spot among countries hosting the most number of command-and-control servers. The number of botnet C2s in the country soared 143% over 2018 to 4,712, compared to 4,007 in the United States.

Lax Customer Vetting

Spamhaus attributed the increase in Russia to threat actors taking advantage of the relatively lax registration procedures among Internet Service Providers in the country. China, too, leapt up the charts from 13th spot in 2018 to the fourth spot last year with 770 servers, an increase that Spamhaus attributed to lax registration procedures as well.

US-based Namecheap was once again the most abused domain registrar, with almost 25% of all botnet C2s detected and blocked last year - all registered via the company. But China and Russia both had more registrars on the top 20 list last year than the US. "They are mostly being legitimately abused," says Vincent Hanna, a researcher at The Spamhaus Project. "The registrar market is one of very thin margins and lots of automation. Neither leaves much space for careful vetting of customers and orders."

According to Spamhaus, its botnet data from 2019 showed that ISPs in the East in general are lagging behind their Western counterparts when it comes to sign-up procedures and in enforcement of their terms and conditions.

Western companies on the list of ISPs hosting the most botnet C&Cs have a high volume, but they are few in number. "At the same time many more eastern companies have fraudulent customers, signaling that abuse procedures and customer-vetting problems are more widespread there, and not limited to a handful of companies," Hanna says.

The most abused Top Level Domains (TLDs) in 2019 were the .com and .net domains. More than 50% of botnet C2s were hosted on these two domains alone. Other heavily abused TLDs included dot ru, dot info, dot cm, and dot pw, the top level domain for Palau. Several other previously abused domains however fell off the most abused list including, .review, .stream, .bid, and .trade.

For registrars and ISPs, careful customer vetting is key. "Finding the fraudulent registrations is often not that hard, but it needs to be done," Hanna says. "Registries that care about the reputation of the entire TLD will proactively go out and try to find problematic registrations themselves."

Related Content:

Botnets Serving Up More Multipurpose Malware

What's in a Botnet? Researchers Spy on Geost Operators

MasterMana Botnet Shows Trouble Comes at Low Cost

8 Ways Businesses Unknowingly Help Hackers

Jai Vijayan is a seasoned technology reporter with over 20 years of experience in IT trade journalism. He was most recently a Senior Editor at Computerworld, where he covered information security and data privacy issues for the publication. Over the course of his 20-year ... View Full Bio

Recommended Reading:

Comment  | 
Print  | 
More Insights
Newest First  |  Oldest First  |  Threaded View
COVID-19: Latest Security News & Commentary
Dark Reading Staff 8/10/2020
Researcher Finds New Office Macro Attacks for MacOS
Curtis Franklin Jr., Senior Editor at Dark Reading,  8/7/2020
Healthcare Industry Sees Respite From Attacks in First Half of 2020
Robert Lemos, Contributing Writer,  8/13/2020
Register for Dark Reading Newsletters
White Papers
Cartoon Contest
Write a Caption, Win an Amazon Gift Card! Click Here
Latest Comment: It's a technique known as breaking out of the sandbox kids.
Current Issue
Special Report: Computing's New Normal, a Dark Reading Perspective
This special report examines how IT security organizations have adapted to the "new normal" of computing and what the long-term effects will be. Read it and get a unique set of perspectives on issues ranging from new threats & vulnerabilities as a result of remote working to how enterprise security strategy will be affected long term.
Flash Poll
The Changing Face of Threat Intelligence
The Changing Face of Threat Intelligence
This special report takes a look at how enterprises are using threat intelligence, as well as emerging best practices for integrating threat intel into security operations and incident response. Download it today!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
PUBLISHED: 2020-08-13
ABBYY network license server in ABBYY FineReader 15 before Release 4 (aka allows escalation of privileges by local users via manipulations involving files and using symbolic links.
PUBLISHED: 2020-08-13
njs through 0.4.3, used in NGINX, has an out-of-bounds read in njs_json_stringify_iterator in njs_json.c.
PUBLISHED: 2020-08-13
njs through 0.4.3, used in NGINX, allows control-flow hijack in njs_value_property in njs_value.c. NOTE: the vendor considers the issue to be "fluff" in the NGINX use case because there is no remote attack surface.
PUBLISHED: 2020-08-13
An Uncontrolled Search Path Element (CWE-427) vulnerability in SmartControl version 4.3.15 and versions released before April 15, 2020 may allow an authenticated user to escalate privileges by placing a specially crafted DLL file in the search path. This issue was fixed in version 1.0.7, which was r...
PUBLISHED: 2020-08-13
Lua through 5.4.0 allows a stack redzone cross in luaO_pushvfstring because a protection mechanism wrongly calls luaD_callnoyield twice in a row.