Well, MS took down Nitol, a huge botnet which sold counterfeit software, and hosted over 70,000 malware domains which infected users with more than 500 Trojans, viruses and keystroke loggers. It was done as part of the M.A.R.S. (Microsoft Active Response for Security) which tracked down evildoers whose intent was to harm the world online community. This Op (Operation b70) was started by the Microsoft Digital Crimes Unit. Nitol has existed since 2008.
“Our research into Nitol uncovered that the botnet was being hosted on a domain linked to malicious activity since 2008. This study also revealed that in addition to hosting b70, 3322.org contained a staggering 500 different strains of malware hosted on more than 70,000 sub-domains. We found malware capable of remotely turning on an infected computer's microphone and video camera, potentially giving a cybercriminal eyes and ears into a victim's home or business. Additionally, we found malware that records a person's every key stroke, allowing cybercriminals to steal a victim's personal information. The Nitol botnet malware itself carries out distributed denial of service (DDoS) attacks that are able to cripple large networks by overloading them with Internet traffic, and creates hidden access points on the victim's computer to allow even more malware - or anything else for that matter - to be loaded onto an infected computer.” -http://blogs.technet.com/b/microsoft_blog/archive/2012/09/13/microsoft-disrupts-the-emerging-nitol-botnet-being-spread-through-an-unsecure-supply-chain.aspx
MS found computers manufactured in China loaded with counterfeit Windows loaded with malware, which could have been loaded at any point in the supply chain. How to know if a given computer is contaminated? Look for a deal that’s “too good to be true”. It is.
In addition to the routine malware, there was also Trojans which could record pictures and sound. Sound familiar?
Anyway, sincerest thanks and kudos to Microsoft.
It appears the company we love to hate can do what the real law enforcement agencies can’t.
Now if they could only put out an OS which didn’t make me crazy….
Sources:
http://blogs.technet.com/b/microsoft_blog/archive/2012/09/13/microsoft-disrupts-the-emerging-nitol-botnet-being-spread-through-an-unsecure-supply-chain.aspx
http://www.pcmag.com/article2/0,2817,2409742,00.asp