Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Cyberwarfare

DNSChanger Remains an Issue for Fortune 500

On July 9, the FBI will shutdown the temporary servers that enable systems infected by the DNSChanger malware to access the Web. For most, the shutdown will mean nothing; however that isn’t the case for 60 companies within the Fortune 500.

DNSChanger Malware

On July 9, the FBI will shutdown the temporary servers that enable systems infected by the DNSChanger malware to access the Web. For most, the shutdown will mean nothing; however that isn’t the case for 60 companies within the Fortune 500.

DNSChanger Malware

According to IID, 12% of the Fortune 500 and 4% of the major U.S. government agencies will have some computers that go dark on July 9, because they still haven’t cleaned their systems and removed the DNSChanger infection. The chances that a large number of systems within any of the Fortune 500 are infected are not likely, though IID’s numbers do mean that infection is showing somewhere in the organization.

Since it arrived to the Web in 2006, millions of systems were hit by DNSChanger. Fast-forward six years, and while six Estonians were arrested for running DNSChanger, despite the best efforts of the FBI, security community, and software vendors, more than 500,000 systems are still infected. Granted, this is a huge drop compared to the 4-6 million from years previous, but it is still a significant number.

The latest data from the DNSChanger Working Group shows that 303,867 IP addresses are infected. Of those, nearly 70,000 of them are in the U.S. Back in Feburary of this year, IIDs numbers showed that approximately half of the Forune 500 and Government organizations were infected, showing that significant progress has been made. 

In May, Google said that they would start warning users if they show signs of being infected DNSChanger. It is unknown how many warnings have been issued, or if there is a noticeable drop in infections since then, when they estimated the number of compromised hosts at 500,000.

Another issue is that while DNSChanger isn’t hijacking search results any longer, it can still activate the anti-virus aspect of its programming. When enabled, DNSChanger disables anti-virus protection on an infected system, so if a system is targeted by secondary malware, there is nothing to stop it from downloading and installing.

Related: DNSChanger is a Wake-up Call for Enterprise & Government DNS Resolver Management

Related: The Day The Internet Will Break For Millions

Advertisement. Scroll to continue reading.
Written By

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join the session as we discuss the challenges and best practices for cybersecurity leaders managing cloud identities.

Register

SecurityWeek’s Ransomware Resilience and Recovery Summit helps businesses to plan, prepare, and recover from a ransomware incident.

Register

People on the Move

Professional services company Slalom has appointed Christopher Burger as its first CISO.

Allied Universal announced that Deanna Steele has joined the company as CIO for North America.

Former DoD CISO Jack Wilmer has been named CEO of defensive and offensive cyber solutions provider SIXGEN.

More People On The Move

Expert Insights

Related Content

Cyberwarfare

WASHINGTON - Cyberattacks are the most serious threat facing the United States, even more so than terrorism, according to American defense experts. Almost half...

Cybercrime

Patch Tuesday: Microsoft calls attention to a series of zero-day remote code execution attacks hitting its Office productivity suite.

Cyberwarfare

Russian espionage group Nomadic Octopus infiltrated a Tajikistani telecoms provider to spy on 18 entities, including government officials and public service infrastructures.

Cyberwarfare

Several hacker groups have joined in on the Israel-Hamas war that started over the weekend after the militant group launched a major attack.

Cyberwarfare

An engineer recruited by intelligence services reportedly used a water pump to deliver Stuxnet, which reportedly cost $1-2 billion to develop.

Application Security

Virtualization technology giant VMware on Tuesday shipped urgent updates to fix a trio of security problems in multiple software products, including a virtual machine...

Application Security

Fortinet on Monday issued an emergency patch to cover a severe vulnerability in its FortiOS SSL-VPN product, warning that hackers have already exploited the...

Cyberwarfare

The war in Ukraine is the first major conflagration between two technologically advanced powers in the age of cyber. It prompts us to question...