Industry View
Bad Actors Exposed: McColo, ZlKon, HostFresh and the Damage Done
Much of today's cyber crime is supported by bad-actor sites that enable questionable and criminal activities. A look at McColo, ZlKon, HostFresh and other "sinister" players.
By Alex Lanstein, Senior Security Researcher, FireEye Inc.
October 08, 2009 — CSO —
Today, cyber criminals who operate the most sophisticated stealth malware and botnets rely on a remarkably small number of network and hosting service providers, known to the industry as bad actors. These bad actors supply the infrastructure needed to host drive-by download exploits, command-and-control servers, stolen data drop sites, and other more functional network needs such as DNS and reliable uplinks. Having a stable, controllable network allows malware operators to remove one difficult piece of the puzzle and Internet Service Providers (ISPs) are lining up to take their money. Even given that these networks are very well known, it has proven difficult -- in some cases impossible -- to stop cyber criminals and these bad actors due to legal, economic and technical hurdles.
The cyber crime spree that is underway is supported by bad actors that turn a blind eye to the questionable and criminal activities transpiring over their networks. Research from FireEye and others have exposed notorious examples like McColo, ZlKon, HostFresh and many more. The Federal Trade Commission scored a rare victory when it took down 3fn based on findings that 3fn, "recruits, knowingly hosts, and actively participates in the distribution of spam, child pornography, and other harmful electronic content."
However, these bad actors are difficult to bring to justice due to the international nature of their crimes, the slow response time with which they react to shutdowns and the general lack of funding and focus for cyber law enforcement.
Hosting providers in the Eastern Bloc openly market spam e-mail services, ICQ-based spam and spam hosting among their service offerings since they are well outside the jurisdiction of would-be law enforcement. Meanwhile, their U.S.-based equivalents are much more covert, leveraging hosting fronts, multi-national partnerships, IP space sharing agreements and others to hide the real entity behind a business.
Cybersecurity experts say a handful of ISPs and domain name registrars work closely with cyber criminals to set up malicious websites that sell fake software, host and distribute malware, facilitate botnet communications and other important services to perpetrate these online criminal endeavors. Cyber criminals are making billions by holding companies for ransom using DDoS attacks, selling off confidential information, sending phishing spam, as well as selling storage services for pirated movies, music, and illegal images. The monetization possibilities of malware and botnets are so numerous that the creativity of the cyber criminal is the only limit at this point. Underlying all these schemes is a need for a stable cyber infrastructure to provide the criminals with a platform for their various online businesses.
bad actors
Security Directions: A Virtual Conference
Available On Demand Sept. 30 - Dec. 30
Join us for a virtual event with candid, expert information on top security challenges and issues - all from the comfort of your desktop.
Protecting PII: How to Work with IT to Manage Risk
Understand the critical nature of the test data privacy problem and get tips on how to work with IT to implement a test data privacy program.



