ReadWriteWeb

Bot Herders Used Google App Engine To Spread Malware

Written by Alex Williams / November 9, 2009 8:24 PM / 6 Comments

google_app_engine.thumbnail.jpgGoogle has confirmed news today that bot herders used Google App Engine to feed commands to networks of infected computers. According to Arbor Networks, the bot herd was discovered over the weekend. After being notified of the attack, Google quickly shut down the infected app engine.

Also on Monday, the Koobface botnet was attacking Google Reader to send malicious links through Twitter, Facebook and other social networks.

The breach is another sign that black hatters are taking a much keener interest in the cloud infrastructure for making attacks. And even Google is at risk.

Here's the news of today's attack, showing in some respects the depth of the breach and the reaction it caused. It's an interesting look at the importance of knowing when an attack actually happens and then how to respond.

arborimage.jpg

Bot herders are a nasty lot. They infect people's computers, turning them into nodes on a zombie network. The network can then be used to serve malware for all kinds of purposes such as for stealing password information from Twitter and Facebook and then using that information to commit fraud such as depleting bank accounts.

In this attack on Google App Engine, a url for downloading an infected application went across the network. This allowed the bots to feed commands to infect more computers and make them part of the network, too.

Update: A statement from Google App Engine about the incident:

"Google actively works to protect our users from malware. Using Google App Engine, or any of our products, for distribution or coordination of malware is a violation of our product policies, and we will disable any App Engine applications discovered to be used for these purposes."



Comments

Subscribe to comments for this post OR Subscribe to comments for all ReadWriteEnterprise posts

  1. Hey Alex thank you so much for sharing this interesting article with us, nice information.. This is really very helpful for me, as Bot Herders do i'll also try & use the Google Apps To Spread Malware..

    Posted by: clavier | November 9, 2009 10:58 PM



  2. Now the virus is everywhere, using a variety of services and software, Google can not avoid.

    Posted by: champions online resources | November 10, 2009 2:33 AM



  3. It just shows how aggressive these guys are getting to make money. Malware authors are always looking for new vectors to try to infect machines. This is why we preach so much about keeping machines patched, and security software up to date and running. Users have a lesser chance of becoming part of the problem.

    Beth Jones, SophosLabs

    Posted by: Beth Jones | November 10, 2009 5:35 AM



  4. This article should probably make an attempt to distinguish the too Google offerings, Google App Engine and Google Apps. The former was the compromised service, according the register, the latter is an enterprise email, calendar offering, and was not involved.

    Posted by: Chris Hinkle | November 10, 2009 10:23 AM



  5. this is why cloud computing is stupid; this and a couple of other reasons. if you're a real company, and have real intellectual property, and use cloud, you're a tard.

    Posted by: lemon obrien | November 10, 2009 1:07 PM



  6. so the question is: what is it that they (Google) are going to do about it. Offer any suggestions or give us rigths to free program to use?

    Posted by: MT | November 12, 2009 7:03 PM



Leave a comment

Optional: Sign in with Connect Facebook   Sign in with Twitter Twitter   Sign in with OpenID OpenID  |  
RWW SPONSORS