Reports

Which are principal cities hostages of malicious botnets?

Which are principal cities hostages of malicious botnets? Symantec has tried to reply the difficult questions with an interesting study.

It is not a mystery, there is a strict link between cybercrime and Geography. Cyber criminal organization used different tactics and offer different products depending on the country where they operate. Russian criminal communities specialize in the sale of payment card data and hacking services, the Chinese ones focus on mobile meanwhile the Brazilian crooks shows great expertise in the banking trojan.

Today I desire to present the findings of an interesting research conducted by Symantec on the botnet diffusion. Let me highlight that botnet location doesn’t mean that the country also hosts control infrastructure neither that criminal organizations live in the same area.

“This map reveals which countries and cities unwittingly played host to the most bot-infected devices, such as PCs, Macs, smartphones, tablets and connected home devices, across Europe, the Middle East and Africa (EMEA) in 2015.” states Symantec. “The rankings, tables and percentages are determined by total bot volumes for each country and city. The measure of ‘Bot density’ refers to a comparison of the bot population to the number of internet users in any given country or city, and calculated by dividing the amount of internet users, as reported by Internet World Stats on September 20, 2016, by total number of unique bot infections detected in a given city or country in 2015.”

The experts of the security firm discovered that the Turkey (18.5% of EMEA’s total bot population) there is the highest number of infected machines recruited in botnets, Istanbul and the capital city Ankara contain the highest number of botnet controlled devices in EMEA.

Bad news for my country, Italy is at the second place (9.8% of EMEA’s total bot population) followed by the Hungary at the third place (9.1%
of EMEA’s total bot population), Rome is third in the ranking of  places with highest bot population, followed by Budapest and Szeged.

The availability of botnets for sale and rent is a precious commodity for cyber criminal organizations that could use them for many illegal activities, such as DDoS attacks and spam campaigns.

In many cases, botnets are composed of compromised IoT devices (i.e.  Cameras, routers, modems, and sensors) that could be used to launch powerful attacks.

Hungary ranks as the top country for bot density, Hungarian Internet users have a one in 393 chance of using a compromised device that is part of a botnet, meanwhile, in Italy the experts have found one bot for every 1829 internet users.

It is curious the data related to the principality of Monaco where people have the second largest chance of one of their devices being recruited in a botnet. Internet users in the principality have a one in 457 chance of owning a bot.

Give a look at the interactive map, by clicking on a country it is possible to see all the data collected in the study.

[adrotate banner=”9″]

Pierluigi Paganini

(Security Affairs – botnet, cybercrime)

Pierluigi Paganini

Pierluigi Paganini is member of the ENISA (European Union Agency for Network and Information Security) Threat Landscape Stakeholder Group and Cyber G7 Group, he is also a Security Evangelist, Security Analyst and Freelance Writer. Editor-in-Chief at "Cyber Defense Magazine", Pierluigi is a cyber security expert with over 20 years experience in the field, he is Certified Ethical Hacker at EC Council in London. The passion for writing and a strong belief that security is founded on sharing and awareness led Pierluigi to find the security blog "Security Affairs" recently named a Top National Security Resource for US. Pierluigi is a member of the "The Hacker News" team and he is a writer for some major publications in the field such as Cyber War Zone, ICTTF, Infosec Island, Infosec Institute, The Hacker News Magazine and for many other Security magazines. Author of the Books "The Deep Dark Web" and “Digital Virtual Currency and Bitcoin”.

Recent Posts

SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 47

Security Affairs Malware newsletter includes a collection of the best articles and research on malware…

33 minutes ago

Security Affairs newsletter Round 526 by Pierluigi Paganini – INTERNATIONAL EDITION

A new round of the weekly Security Affairs newsletter has arrived! Every week, the best…

3 hours ago

Two Linux flaws can lead to the disclosure of sensitive data

Qualys warns of two information disclosure flaws in apport and systemd-coredump, the core dump handlers in Ubuntu, Red Hat Enterprise…

21 hours ago

Meta stopped covert operations from Iran, China, and Romania spreading propaganda

Meta stopped three covert operations from Iran, China, and Romania using fake accounts to spread…

2 days ago

US Treasury sanctioned the firm Funnull Technology as major cyber scam facilitator

The U.S. sanctioned Funnull Technology and Liu Lizhi for aiding romance scams that caused major…

2 days ago

ConnectWise suffered a cyberattack carried out by a sophisticated nation state actor<gwmw style="display:none;"></gwmw><gwmw style="display:none;"></gwmw>

ConnectWise detected suspicious activity linked to a nation-state actor, impacting a small number of its…

2 days ago