Other botnet operators might use Tor to hide their command and control servers in the future, researchers say
By Lucian Constantin, IDG News Service December 07, 2012 02:05 PM ET
Print
Security researchers have identified a botnet controlled by its creators over the Tor anonymity network. It's likely that other botnet operators will adopt this approach, according to the team from vulnerability assessment and penetration testing firm Rapid7.
The botnet is called Skynet and can be used to launch DDoS (distributed denial-of-service) attacks, generate Bitcoins -- a type of virtual currency -- using the processing power of graphics cards installed in infected computers, download and execute arbitrary files or steal login credentials for websites, including online banking ones.
"One countermeasure that companies or ISPs could eventually enforce in their firewall is to drop all packets that originate
from known TOR nodes, in order to minimize the amount of potentially malicious traffic they receive," Botezatu said. "Of course,
they might also end up blacklisting a number of legit Tor users looking for anonymity."