Telstra has revealed the addition of almost one million new mobile services in the six months to December 2011, but Sensis revenues plummeted 24 percent in 12 months.
Less than a month ago, I wrote about Trojan authors using Twitter as a Command-and-Control mechanism. One couldn't imagine that this was the only new innovation and, sure-enough, it wasn't. Just a few days ago, Symantec's Gavin O Gorman wrote of a new mechanism for Trojans to communicate – Google groups!
Without reliable communications, botnets are essentially a one-use tool. However, once there is a two-way communications mechanism, they are a very useful device for a variety of purposes. Even with the ability to change their use mid-stream.
Trojan authors have explored a variety of methods to manage their botnets. There are endless tales of IRC, ICQ and any other chat channel being used as command mechanisms.
The latest method, as described by Gorman at Symantec, uses encrypted Google group postings to communicate. There is of course a downside. Google groups message are (mostly) anonymous, however they are not hidden. Messages to the newsgroup cannot be instantly removed, as Symantec researchers found; leaving a trail easily followed.
Gorman suggests in the blog that this is only an experiment into the potential uses of Google Groups as a Command-and-Control mechanism. Furthermore, due to the low profile it attempts to maintain, this appears to be an extensive experiment into methods of wider attack.
Currently, there are very few machines affected. Unfortunately, for the Trojan authors, there may not be many more as the method has been exposed to the light of day.
The lessons? For Internet users, very few, nothing seems to bother joe-user; for Trojan authors, more useful information; for anti-malware authors, an intriguing new vector to watch.
David Bass
| ComOps, a leading Australian provider of business software products and services, has won a competitive tender to deploy its Salvus safety, r…
How to Make Business Discovery Work for Your Business
Business Discovery takes its cues from consumer apps. Like Google, it encourages us- ers to hunt for and explore data without worrying about or even noticing the underly- ing technology. Their entire experience is working within an intuitive interface to get real-time, self-service results with only minimal training. ...more
Try an easy-to-use set of web-enabled
tools for business-class productivity services. Office 365 provides
anywhere-access to email, important documents, contacts, and calendars
on almost any device.