Criminal gangs engage in turf war over botnets
Three criminals gangs vie for supremacy in war to create mega zombie computer botnets.


Internet users are in the middle of a pitch battle between rival criminal gangs as they seek to drive off each other's malware from victim's computers.
According to a new report from anti-virus company Kaspersky, three separate groups behind the Warezov, Zhelatin and Bagle worms are creating rival botnets to sell to spammers and this is bringing them in to conflict with each other.
Each group makes a lot of money from spammers who use the gangs' botnets to churn out spam. In order to make more money, each gang needs to have more compromised computers so these gangs are forcing each other's viruses off target computers and palnting their own malware to gain control and add the host to their own botnet.
"War had been declared in cyberspace between the groups producing Warezov and Zhelatin," said Alexander Gostev, senior virus analyst at Kaspersky Lab. "Taking into account the size of the botnets used by both groups, and their clear aim to conduct a large number of attacks, the situations was clear: this is threatening to become one of the most serious problems on the internet in recent years."
He said that until now, the best known cyber conflict was that between Mydoom, Bagle and NetSky, back in spring 2004. The network was flooded with dozens of variants of these worms: they scanned victim machines for their competitors and took their place, deleting the original worm. The war was brought to an end by the arrest of 18 year old Sven Jaschan, the author of NetSky, in Germany.
But, warned Gostev, Jaschan's creations remain one of the most widespread worms in mail traffic.
"Out of all the malware authors involved, only the authors of Bagle have remained active," he said "It's true that they disappeared into the shadows for a while, and didn't react in any way to the appearance of Warezov, which is why we thought that they might have been involved in creating this worm."
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
But in January Bagle suddenly reappeared, and one variant of this worm became the most widespread malicious program in mail traffic.
Gostev said that three groups, from different countries, are all busy with the same thing - creating botnets to send spam and harvest email addresses.
He said that almost 32 per cent of all malicious code in mail traffic in March 2007 was made up of Trojan-Spy.HTML.Bankfraud.ra. "This was clearly a result of the epidemics caused by Bagle, Zhelatin and Warezov," said Gostev.
Rene Millman is a freelance writer and broadcaster who covers cybersecurity, AI, IoT, and the cloud. He also works as a contributing analyst at GigaOm and has previously worked as an analyst for Gartner covering the infrastructure market. He has made numerous television appearances to give his views and expertise on technology trends and companies that affect and shape our lives. You can follow Rene Millman on Twitter.
-
Enterprises face delicate balancing act with data center sustainability goals
News High energy consumption, raw material requirements, and physical space constraints are holding back data center sustainability efforts, according to new research from Seagate.
By Emma Woollacott
-
Cleo attack victim list grows as Hertz confirms customer data stolen
News Hertz has confirmed it suffered a data breach as a result of the Cleo zero-day vulnerability in late 2024, with the car rental giant warning that customer data was stolen.
By Ross Kelly