Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
TRENDING TODAY
Home > News > Security > Security Blog

January 30th, 2013, 21:59 GMT · By

BLOG

Jabberbot Malware Uses Jabber Protocol for C&C Communications

SHARE:

Adjust text size:


Jabberbot uses XMPP protocol for C&C communications Enlarge picture - Jabberbot uses XMPP protocol for C&C communications
Cybercriminals often rely on legitimate services for communications between their command and control (C&C) servers and the malware they develop. Another example is Win32/Jabberbot.A, a malware that uses the Extensible Messaging and Presence Protocol (XMPP), better known as the Jabber protocol.

ESET researchers explain that Jabberbot has been mainly targeting users from Ukraine, but they’re uncertain how it’s spread.

For communications, Jabberbot uses one shared account on all the infected hosts, trednet@jabber.ru. Each instance generates one pseudorandom resource identifier, utilized by the botmaster to communicate with each individual bot.

From a master Jabber account, the cybercriminal sends instructions to delete files, execute system commands, open files, download remote files, or upload files from the infected hosts.

No encryption and no authentication are used, despite the fact that the XMPP protocol and the jabber.ru service support Transport Layer Security (TLS).

This particular threat is not sophisticated and the botnet can be easily taken down. However, experts highlight that Jabberbot demonstrates the fact that XMPP can be used for a reliable C&C infrastructure if a proper design is implemented.

Here is the detailed analysis made by ESET.

TELL US WHAT YOU THINK:

1,247 hits · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Cybercriminals Use Anti-Spam System for Communication Between Malware and Server

McAfee: 631 Botnet Command and Control Servers Currently Active in the US

AlienVault and Kaspersky Help Organizations Neutralize Red October Attack

Cybercriminals Behind Red October Start Shutting Down C&C Infrastructure

Real-Time Map from Trend Micro Shows Global Botnet Activity

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2013 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM