Microsoft offers $250,000 Conficker bounty
In an attempt to combat the worm that’s been plaguing the internet, the software giant is offering a $250,000 reward for information on the gang responsible.


Microsoft is putting up its own money in its attempt to combat the spread of the Conficker internet worm, also known as Downadup.
The software firm is offering anyone with information leading to the arrest and conviction of those responsible for the worm $250,000 (172,330).
It has also teamed up with the domain name administrator, the Internet Corporation for Assigned Names and Numbers (ICANN), to take down the servers spreading Conficker's attacks.
In a statement Greg Rattray, ICANN chief Internet security adviser, said late yesterday: "The best way to defeat potential botnets like Conficker is by the security and domain name system communities working together. ICANN represents a community that's all about coordinating those kinds of efforts to keep the internet globally secure and stable."
Microsoft first patched the critical bug in its Windows operating system that Conficker/Downadup exploits last October. But the spread of the network worm gathered pace through December to infect millions of PCs.
In the UK, the worm had reportedly affected the systems of the Ministry of Defence (MOD), as well as the National Health Service (NHS) IT systems of hospitals in Sheffield, towards the end of last year.
Although Microsoft's move is unusual, it is not unprecedented. It paid out the same bounty in 2004 to two people who identified Sven Jaschan, the teenager responsible for the Sasser and Netsky worms.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
And in 2003, Microsoft offered $500,000 (344,660) for the arrest and conviction of the people behind the Blaster and Sobig worms. At the time it said it would earmark a further $4.5 million (3.1 million) bounty to catch future virus writers.
Security firm Sophos welcomed news of the reward, but it questioned whether the amount on offer would be incentive enough to catch the worm's writers.
Graham Cluley, Sophos senior technology consultant, said the offer could do no harm.
"If a culprit isn't found then Microsoft hasn't lost anything, and it may just encourage some cybercriminals to come forward with information," he added. "But, while a $250,000 reward has successfully caught teenage hackers in the past, the bounty may not offer enough temptation to inform on an organised criminal gang making big money out of malware."
The security firm added that it was in Microsoft's interest to keep the pressure on Conficker's creators, as its reputation is always badly shaken whenever a computer virus causes widespread problems for its users.
A 25-year veteran enterprise technology expert, Miya Knights applies her deep understanding of technology gained through her journalism career to both her role as a consultant and as director at Retail Technology Magazine, which she helped shape over the past 17 years. Miya was educated at Oxford University, earning a master’s degree in English.
Her role as a journalist has seen her write for many of the leading technology publishers in the UK such as ITPro, TechWeekEurope, CIO UK, Computer Weekly, and also a number of national newspapers including The Times, Independent, and Financial Times.
-
Bigger salaries, more burnout: Is the CISO role in crisis?
In-depth CISOs are more stressed than ever before – but why is this and what can be done?
By Kate O'Flaherty Published
-
Cheap cyber crime kits can be bought on the dark web for less than $25
News Research from NordVPN shows phishing kits are now widely available on the dark web and via messaging apps like Telegram, and are often selling for less than $25.
By Emma Woollacott Published
-
‘Climate of fear’ is best weapon against cyber crime
News A member of the Serious Organised Crime Agency has claimed cyber criminals are best tackled through fear of prosecution.
By Jennifer Scott Published
-
ICANN: Most web domain registrations are faulty
News A new report on the accuracy of domain registrations has found 77 per cent of records have information that is missing, incorrect or deliberately falsified.
By Martin James Published
-
Kaminsky flaw fixed for .com and .net by 2011
News Verisign anticipates an industry-wide effort to finally rid the net of the Kaminsky flaw.
By Asavin Wattanajantra Published
-
ICANN's global domains could increase phishing attacks
News Allowing different character sets on the internet could leave users open to new kinds of phishing and web attacks.
By Asavin Wattanajantra Published