Starting in November 2008, the Conficker worm, also known as Downadup or Kido, infiltrated somewhere between 9 and 15 million computers. It grounded French military aircraft that could not download flight plans, turned up on Royal Navy warships and submarines, and infected over 800 computers in Sheffield hospitals. Its entry point was a Windows flaw cataloged as MS08-067, which Microsoft had patched on October 23rd, 2008. By January 2009 an estimated 30 percent of Windows PCs were still unpatched, and a second variant spread through USB drives and the AutoRun feature.
This episode follows the contest between the worm’s authors and an industry coalition that came to be called the Conficker Cabal, which included Microsoft, Symantec, ICANN, and academic researchers. The malware blocked security tools, signed its updates with RSA cryptography, and generated 250 domains a day to look for orders. When defenders locked those domains down, it escalated. Then, with the world braced for catastrophe, the giant botnet delivered a payload so small that it changes how the whole story reads.
- The name Conficker is a near-perfect anagram of parts of trafficconverter.biz, a domain the worm contacted for updates, with an extra K added.
- Manchester City Council estimated 1.5 million pounds in disruption and banned all portable USB drives.
- Within weeks of academics publishing a corrected MD6 hashing algorithm, the worm’s authors had built it into their code.
- Variant D raised the daily domain count from 250 to 50,000 across 110 top level domains and added a peer-to-peer update network.
- In April 2009, Variant E installed the Waledac spam bot and scareware called SpyProtect 2009, then deleted itself. Half a million machines were still infected in 2019.
Leave a Reply