Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.


06:40 PM
Connect Directly

Number of Botnet Command & Control Servers Soared in 2019

Servers worldwide that were used to control malware-infected systems jumped more than 71% compared to 2018, Spamhaus says.

For the second year in a row, the number of servers used by attackers worldwide to control malware-infected systems increased sharply.

The Spamhaus Project, which tracks both the domain names and the IP addresses used by threat actors for hosting botnet command-and-control servers (C2), identified 17,602 such servers hosted on a total of 1,210 different networks worldwide in 2019.

The number represented a big 71.5% jump over the 10,263 botnet C2 servers that Spamhaus detected and blocked in 2018, and a near doubling in number from the 9,500 servers in 2018. Botnet C2s, in fact, accounted for 41% of all the listings on Spamhaus' block list in 2019, compared to just 15% in 2017 and 25% last year.

The sharp increase is an indication of the growing popularity of botnets as an attack vector among threat actors, Spamhaus said in a report this week. About 60% of the new botnet C2s that Spamhaus detected in 2020 were associated with credential-stealing malware such as Lokibot and AZORult. About 20% -- the next highest proportion -- were used to control data-stealing Remote Access Trojans (RATs), the most prolific of which was Nanocore.

The Spamhaus Block List (SBL) is a real-time database of IP addresses and URLs associated with known spam sources and threats like botnet C2s. Companies and ISP can use the database tandem with other block lists to block spam and other online threats.

As with previous years, Spamhaus' data showed that some of the ISPs that hosted the highest number of botnet C2s last year were based in the United States. Over 1,580 botnet servers in 2019, for instance, were hosted on Cloudflare alone -- more than double the 629 hosted by second-place Alibaba of China.

In many cases, the command-and-control servers were running on compromised websites and servers belonging to customers of ISPs such as Cloudflare. This likely made it difficult for them to spot the illegal activity. But a substantial proportion were also set up via fraudulent registrations, as a result of weaknesses in the ISPs customer-vetting and verification processes, Spamhaus said.

But for the first time ever, Russia took the top spot among countries hosting the most number of command-and-control servers. The number of botnet C2s in the country soared 143% over 2018 to 4,712, compared to 4,007 in the United States.

Lax Customer Vetting

Spamhaus attributed the increase in Russia to threat actors taking advantage of the relatively lax registration procedures among Internet Service Providers in the country. China, too, leapt up the charts from 13th spot in 2018 to the fourth spot last year with 770 servers, an increase that Spamhaus attributed to lax registration procedures as well.

US-based Namecheap was once again the most abused domain registrar, with almost 25% of all botnet C2s detected and blocked last year - all registered via the company. But China and Russia both had more registrars on the top 20 list last year than the US. "They are mostly being legitimately abused," says Vincent Hanna, a researcher at The Spamhaus Project. "The registrar market is one of very thin margins and lots of automation. Neither leaves much space for careful vetting of customers and orders."

According to Spamhaus, its botnet data from 2019 showed that ISPs in the East in general are lagging behind their Western counterparts when it comes to sign-up procedures and in enforcement of their terms and conditions.

Western companies on the list of ISPs hosting the most botnet C&Cs have a high volume, but they are few in number. "At the same time many more eastern companies have fraudulent customers, signaling that abuse procedures and customer-vetting problems are more widespread there, and not limited to a handful of companies," Hanna says.

The most abused Top Level Domains (TLDs) in 2019 were the .com and .net domains. More than 50% of botnet C2s were hosted on these two domains alone. Other heavily abused TLDs included dot ru, dot info, dot cm, and dot pw, the top level domain for Palau. Several other previously abused domains however fell off the most abused list including, .review, .stream, .bid, and .trade.

For registrars and ISPs, careful customer vetting is key. "Finding the fraudulent registrations is often not that hard, but it needs to be done," Hanna says. "Registries that care about the reputation of the entire TLD will proactively go out and try to find problematic registrations themselves."

Related Content:

Botnets Serving Up More Multipurpose Malware

What's in a Botnet? Researchers Spy on Geost Operators

MasterMana Botnet Shows Trouble Comes at Low Cost

8 Ways Businesses Unknowingly Help Hackers

Jai Vijayan is a seasoned technology reporter with over 20 years of experience in IT trade journalism. He was most recently a Senior Editor at Computerworld, where he covered information security and data privacy issues for the publication. Over the course of his 20-year ... View Full Bio

Recommended Reading:

Comment  | 
Print  | 
More Insights
Newest First  |  Oldest First  |  Threaded View
Ransomware Is Not the Problem
Adam Shostack, Consultant, Entrepreneur, Technologist, Game Designer,  6/9/2021
How Can I Test the Security of My Home-Office Employees' Routers?
John Bock, Senior Research Scientist,  6/7/2021
New Ransomware Group Claiming Connection to REvil Gang Surfaces
Jai Vijayan, Contributing Writer,  6/10/2021
Register for Dark Reading Newsletters
White Papers
Cartoon Contest
Write a Caption, Win an Amazon Gift Card! Click Here
Latest Comment: Google's new See No Evil policy......
Current Issue
The State of Cybersecurity Incident Response
In this report learn how enterprises are building their incident response teams and processes, how they research potential compromises, how they respond to new breaches, and what tools and processes they use to remediate problems and improve their cyber defenses for the future.
Flash Poll
How Enterprises are Developing Secure Applications
How Enterprises are Developing Secure Applications
Recent breaches of third-party apps are driving many organizations to think harder about the security of their off-the-shelf software as they continue to move left in secure software development practices.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
PUBLISHED: 2021-06-18
RIOT-OS 2021.01 before commit 44741ff99f7a71df45420635b238b9c22093647a contains a buffer overflow which could allow attackers to obtain sensitive information.
PUBLISHED: 2021-06-18
SerenityOS contains a buffer overflow in the set_range test in TestBitmap which could allow attackers to obtain sensitive information.
PUBLISHED: 2021-06-18
SerenityOS in test-crypto.cpp contains a stack buffer overflow which could allow attackers to obtain sensitive information.
PUBLISHED: 2021-06-18
SerenityOS before commit 3844e8569689dd476064a0759d704bc64fb3ca2c contains a directory traversal vulnerability in tar/unzip that may lead to command execution or privilege escalation.
PUBLISHED: 2021-06-18
RIOT-OS 2021.01 before commit 85da504d2dc30188b89f44c3276fc5a25b31251f contains a buffer overflow which could allow attackers to obtain sensitive information.