Dorkbotは、インスタントメッセージ、USBドライブ、Webサイト、 Facebookなどのソーシャルメディアチャネルを通じて拡散するマルウェアワームのファミリーです。Code Shikaraは、Dorkbotファミリーに関連するコンピュータワームで、ソーシャルエンジニアリングを通じて攻撃します。特に2015年に蔓延したDorkbot感染システムは、スパムの送信、DDoS攻撃への参加、ユーザーの認証情報の収集など、さまざまな目的で使用されました。[ 1 ]
Dorkbotのバックドア機能により、リモート攻撃者は感染したシステムを悪用することができます。MicrosoftとCheck Point Researchの分析によると、リモート攻撃者は次のことができる可能性があります。[ 2 ] [ 3 ]
Dorkbotに感染したシステムは、スパムの送信、 DDoS攻撃への参加、銀行サービスを含むオンラインサービスのユーザー認証情報の収集などに悪用される可能性があります。 [ 2 ]
2015年5月から12月にかけて、Microsoftマルウェア対策センターは、Dorkbotが毎月平均10万台の感染マシンで検出されたことを報告した。[ 4 ]
2015年、米国国土安全保障省は、 Dorkbot感染を修復するために以下の措置を勧告しました。[ 2 ]
2011年、Code Shikaraはデンマークのサイバーセキュリティ企業CSISによって初めて特定されました。AV企業Sophosは2011年11月に、この脅威は主にソーシャルネットワークFacebookを介した悪意のあるリンクによって拡散すると報告しました。[ 5 ] [ 6 ]
In 2013, Bitdefender Labs caught and blocked the worm, which is capable of spying on users' browsing activities, meanwhile stealing their personal online/offline information and/or credentials, commonly known as cybercrime. The infection was originally flagged by the online backup serviceMediaFire, who detected that the worm was being distributed camouflaged as an image file. Despite the misleading extension, MediaFire successfully identified the malicious image as an .exe-file. The malicious Shikara Code poses as a .jpeg image, but is indeed an executable file. As an IRC bot, the malware is simply integrated by the attackers from a control and command server. Besides stealing usernames and passwords, the bot herder may also order additional malware downloads.
MediaFire had then taken steps to address incorrect and misleading file extensions in an update, which identified and displayed a short description by identifying specific file types. To help users for this specific threat, the file sharing service also blocked files with double extensions, such as .jpg.exe, .png.exe, or .bmp.exe. Just like usual malware, the Backdoor.IRCBot.Dorkbot can update itself once installed on the victim's computer or other related devices.[7]
The biggest risk is that someone's Facebook contacts may have had their account already compromised (due to sloppy password security, or granting access to a rogue application) and that the account user has been allured by clicking on a link seemingly posted by one of their friends.
Although the links pretend to point to an image, the truth is that a malicious screensaver is hidden behind an icon of two blonde women. After the code is launched, it attempts to download further malicious software hosted on a specific compromised Israeli domain. The malware is currently not present on the Israeli website. All that remains is a message, seemingly from the intruders, that says:
It is likely that they are using additional or other websites in continuing spreading their cyberattack(s). Some other popular baits tricking users to click on malicious links include Rihanna or Taylor Swiftsex tapes.[6][8]
2015年12月7日、FBIとマイクロソフトは合同タスクフォースでDorkbotボットネットを摘発した。[ 9 ]