Microsoft delivers fatal blow to yet another botnet
Microsoft said it delivered a fatal legal blow to Kelihos, a botnet that stole sensitive personal information stored on computers it infected, and was capable of delivering almost 4 billion spam messages per day.
The takedown was achieved in part by obtaining a secret court order shutting down 21 internet addresses, including cz.cc, a free domain name registration service based in the Czech Republic. The underlying lawsuit was unsealed only after the command and control servers that relied on the domains were severed from the internet, making it impossible for the 42,000 or so infected computers to receive updated software and instructions from the Kelihos operators.
The knockout is the third time Microsoft has combined its technical and legal might to disrupt a botnet menacing its customers. In March, Redmond took credit for bringing down Rustock, a rogue network that turned about 1.6 million PCs into spam-spewing monsters. That achievement came after Microsoft worked to identify the domains and servers used to administer Rustock, so they could be confiscated all at once.