skynet-tor-powered-botnet

I remember reading about this on reddit awhile back and thought “wow”.

Now it appears Rapid7 has a full breakdown of this botnet, which you can read about here.

The summary:

“Skynet runs all its C&C servers as Hidden Services and all compromised computers are configured to be part of the Tor network as well.

The advantages of this approach are:

  • The botnet traffic is encrypted, which helps prevent detection by network monitors.
  • By running as an Hidden Service, the origin, location, and nature of the C&C are concealed and therefore not exposed to possible takedowns. In addition, since Hidden Services do not rely on public-facing IP addresses, they can be hosted behind firewalls or NAT-enabled devices such as home computers.
  • Hidden Services provide a Tor-specific .onion pseudo top-level domain, which is not exposed to possible sinkholing.
  • The operator can easily move around the C&C servers just by re-using the generated private key for the Hidden Service.

Long story short, Tor, due to its design and internal mechanics, makes it a perfect protocol for botnets. Because of this, all critical communications of Skynet to its C&C servers are tunneled through a Tor SOCKS proxy running locally on compromised computers.”

Yikes.

 

botnet-op

Advertisements

Say something!

Please log in using one of these methods to post your comment:

WordPress.com Logo

You are commenting using your WordPress.com account. Log Out / Change )

Twitter picture

You are commenting using your Twitter account. Log Out / Change )

Facebook photo

You are commenting using your Facebook account. Log Out / Change )

Google+ photo

You are commenting using your Google+ account. Log Out / Change )

Connecting to %s

[ hamcomputers ]

Technical Support enthusiasts.

Happenin's in the 'Ham

We are here to keep you updated with all the free, cheap, and amazing events around Birmingham!

CaliBama Belle

A Southern Belle with a Golden State of Mind

We Share the Same Sky

Desiring but another day to ebb the pull, damn the flow and spend an evening wading creeks that meander.

Shedrick Flowers Photography

'dem sexy internets

The Immortal Jukebox

A Blog about Music and Popular Culture

The Bitcoin Wife

All things fresh and fabulous in the Bitcoin world.

Unlearning Economics

Musings on the Current State of Economics

Intellectual Detox

Reconstructing a more accurate view of reality

Thought Catalog

Thought Catalog is a digital youth culture magazine dedicated to your stories and ideas.

AudenX

'dem sexy internets

Bourbon & Kale

A Left Coast Guide to Longevity and Southern Guide to Sanity

EARMILK

'dem sexy internets

Jesse's Café Américain

'dem sexy internets

MineForeman

Bitcoin Stuff

Bitcoin Foundation

'dem sexy internets

%d bloggers like this: