Skip to content

Comment on Researcher sets up illegal 420,000 node botnet for IPv4 Internet map

Comments

Using the botnet to run security patches is what fascinates me.

> But it soon found it was getting competition from a malicious botnet dubbed Aidra and the researcher adapted the binary to block this competitor where possible[...]

My understanding is that it's actually not that uncommon for botnet malware to patch the exploit that it came in on.

I too wonder if this is some deep principle at work or just something obvious.

You don't want other malware running on your botnet. They take up resources and may make the owner realise that their computer is infected. If you patch their biggest security holes, their computer keeps on running smoothly and nobody suspects a thing.

My take is it's obvious: they are already in and don't need to use that exploit again. This makes sure no one else gets access as well.

(On a related note: I think I remember HP demonstrate a remote mitigation tool in '07 that would use exploits to pop messages to logged in users or even shut down the machine.)

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.