*Hard to kill. Harder to know if it's dead.
via SANS
–Kelihos Botnet Still Active After Takedown
(March 29, 2012)
Despite an attempted shutdown last week, the Kelihos botnet appears to
be still active. Within a day after an announcement from a group of
researchers that Kelihos had been knocked offline, others were reporting
evidence of the botnet's activity. The researchers poisoned the botnet
with their own code, redirecting infected machines to their own sinkhole
server instead of the botnet's command-and-control servers. Some of the
researchers maintain that the activity is part of a new variant of the
botnet, not the one targeted in the takedown.
http://www.theregister.co.uk/2012/03/29/kelhios_bot_not_dead_yet/
http://www.darkreading.com/advanced-threats/167901091/security/attacks-breaches/232700540/it-s-already-baaack-kelihos-botnet-rebounds-with-new-variant.html
[Editor's Comment (Northcutt): This story keeps reminding me of the "Why
won't you die" scene in Vendetta. There is more to this story than
technology, the Dave Dittrich Honeynet blog post with a FAQ on Kelios
references a code of conduct for these types of activities that often
involve extraordinary intervention:
https://www.honeynet.org/node/836
http://www.youtube.com/watch?v=LGGPufySwZ4 ]