A newly-discovered botnet is ‘practically indestructible’, security researchers say.
TDL-4 is the rootkit component of the TDSS malware, which has been around since 2008. But in the three months since it hit the scene, it’s sucked in more than four and a half million PCs around the world. About a third are based in the US.
And in this, its latest incarnation, it has the cheek to include its own version of an anti-virus capability, which scans slave machines for software that could enable it to be taken over by another botnet.
It can now delete around 20 of the world’s most prolific malware packages, including Gbot, ZeuS and Optima.
It has its own encryption method for communication between infected computers and the command and control servers, and can also use a public peer-to-peer network to sending commands to control infected computers.