Security Firm Symantec Analyzes the Profitability of the OSX.Flashback Botnet

filevaultSecurity firm Symantec previously estimated that the authors of the Flashback malware that affected hundreds of thousands of Macs at its peak could have been generating up to $10,000 per day by hijacking users' ad clicks. Further analysis from the company suggests that the developers may have only earned $14,000 over the three weeks the malware was active.

From our analysis we have seen that, for a three-week period starting in April, the botnet displayed over 10 million ads on compromised computers but only a small percentage of users who were shown ads actually clicked them, with close to 400,000 ads being clicked. These numbers earned the attackers $14,000 in these three weeks, although it is worth mentioning that earning the money is only one part of the puzzle—actually collecting that money is another, often more difficult, job. Many PPC providers employ anti-fraud measures and affiliate-verification processes before paying. Fortunately, the attackers in this instance appear to have been unable to complete the necessary steps to be paid.

It is estimated the actual ad-clicking component of Flashback was only installed on about 10,000 of the more than 600,000 infected machines. In other words, utilizing less than 2% of the entire botnet the attackers were able to generate $14,000 in three weeks, meaning that if the attackers were able to use the entire botnet, they could potentially have earned millions of dollars a year.

Symantec notes that the malware developers displayed more than 10 million hijacked ads and could have delivered many more if the developers had been more successful in their attacks.

Some security specialists have said that the Mac OS is "really vulnerable" to further infections, though these claims should perhaps be taken with a grain of salt -- those security specialists make their living off vulnerabilities and it is in their best interest to promote awareness of them.

Top Rated Comments

DavidTheExpert Avatar
123 months ago
those security specialists make their living off vulnerabilities, and it is in their best interest to promote awareness of them.

I'll say. The more afraid we are, the more we'll pay for their placebo security software.

I say the best security is knowing how to avoid infections in the first place. If you can learn not to download mysterious files, you're half way there.
Score: 8 Votes (Like | Disagree)
gnasher729 Avatar
123 months ago
I wish I made $14,000 in 3 weeks :(
Your maths is wrong.

This isn't one person making $14,000 profit for three weeks of work. There is a lot more work than three weeks of hacking, with many more people involved, for a scheme that managed to produce $14,000 in revenue for three weeks and then fizzled out. A complex software project producing a total of $14,000 in revenue.

I did a quick calculation using the total annual revenue of my company and the number of developers employed, using a number of 230 working days, and I couldn't spend more than three or four days of work for one developer for $14,000 revenue.

I wouldn't be surprised if websites like macrumors did get more additional ad revenue due to people reading stories about flashback and clicking on ads on macrumors, than these hackers made.

PS. Seems at least one of those hackers was angry because I told them they are stupid and doing a lot of work for very little money.
Score: 6 Votes (Like | Disagree)
Diode Avatar
123 months ago
Thanks StrikerShoot, I love a good infographics, but I have a good understanding of the threats Malware poses, and likewise the criminal mind behind a hacker. I'm thinking Godfather 3 style, going legit.

I was thinking without all the malicious aspects, voluntary opt-in Adnets where you technically farm all their clicks, think of it as an investment opportunity with micro returns. Micro input, micro returns. Still returns!

It sounds heaps like a scheme/existing web advertising but with the user opted-in, subscription based system.

A lot of malware / phishing scams are run by organized crime in Russia.
Score: 5 Votes (Like | Disagree)
soundguyami Avatar
123 months ago
No way

It would be a cold day in hell before I would ever buy a Symantec product for mac. Their PC editions are resource killing crap. I would put MSE up against them any day.
Score: 4 Votes (Like | Disagree)
StrikerShoot Avatar
123 months ago
This has got to be a business model right.

Ad-hijacking. Earn heaps through people clicking on Ads, invest, profit, repay people.

Considering how Flashback infects Macs, seems like a hackers' basic business model to me..

Score: 4 Votes (Like | Disagree)
gnasher729 Avatar
123 months ago
I'm waiting for the next story about how an antivirus software update goes bad and destroys the system. Those are always fun to hear about.

That was yesterday. Does that count as "the next story"? Headline: "'Catastrophic' Avira antivirus update bricks Windows PCs"

http://www.theregister.co.uk/2012/05/16/avira_update_snafu/

This "anti-virus" software thought it had found viruses in essential parts of Windows, that are actually signed by Microsoft. Someone commented "Either the bad guys cracked Microsoft's code signing; in that case we can just give up. Or they didn't, in that case the anti-virus software was wrong. In either case, the anti-virus software shouldn't touch anything that is code-signed by Microsoft".
Score: 3 Votes (Like | Disagree)

Top Stories

affinity designer contour tool

Serif Updates Affinity Photo, Designer, and Publisher With New Tools and Functions

Thursday February 4, 2021 1:58 am PST by
Serif today announced across-the-board updates for its popular suite of Affinity creative apps, including Affinity Photo, Affinity Designer, and the Apple award-winning Affinity Publisher for Mac, all of which were among the first professional creative suites to be optimized for Apple's new M1 chip. "After another year which saw record numbers of people switching to Affinity, it's exciting to...
studio buds family

Beats Studio Buds Debuting Today With Active Noise Cancellation, Stemless Design, and More for $150

Monday June 14, 2021 8:00 am PDT by
We've seen a lot of teasers about the Beats Studio Buds over the past month since they first showed up in Apple's beta software updates, and today they're finally official. The Beats Studio Buds are available to order today in red, white, and black ahead of a June 24 ship date, and they're priced at $149.99. The Studio Buds are the first Beats-branded earbuds to truly compete with AirPods...
maxresdefault

Craig Federighi and Greg Joswiak Discuss iPadOS 15, macOS Monterey, Privacy, Shortcuts on Mac, and More

Saturday June 12, 2021 6:12 am PDT by
As is tradition, Apple executives Craig Federighi and Greg Joswiak joined Daring Fireball's John Gruber in an episode of The Talk Show to discuss several announcements that Apple made over this weeks WWDC, including iPadOS 15, macOS Monterey, and a large focus around privacy. Federighi kicks off the conversation discussing the common architecture, now thanks to Apple silicon, across all of...
youtube apple tv

YouTube Discontinuing 3rd-Generation Apple TV App, AirPlay Still Available

Wednesday February 3, 2021 3:09 pm PST by
YouTube is planning to stop supporting its YouTube app on the third-generation Apple TV models, where YouTube has long been available as a channel option. A 9to5Mac reader received a message about the upcoming app discontinuation, which is set to take place in March.Starting early March, the YouTube app will no longer be available on Apple TV (3rd generation). You can still watch YouTube on...
adobe photoshop sketch ipad

Adobe Removing Photoshop Sketch and Illustrator Draw From App Store in July

Saturday June 26, 2021 4:02 pm PDT by
Adobe this week reminded customers that its Photoshop Sketch and Illustrator Draw apps will no longer be available for download on iOS and Android starting July 19. Adobe plans to stop supporting the apps for existing users on January 10, 2022. In a support document, Adobe said users can easily migrate to its Fresco app, which combines many Photoshop Sketch and Illustrator Draw drawing and...
REC ASA CODE2016 20160601 205816 2745

Elon Musk Reportedly Demanded to Become Apple CEO as Part of Potential Tesla Acquisition [Update: Musk Denies]

Friday July 30, 2021 9:04 am PDT by
Tesla CEO Elon Musk reportedly once demanded that he be made Apple CEO in a brief discussion of a potential acquisition with Apple's current CEO, Tim Cook. The claim comes in a new book titled "Power Play: Tesla, Elon Musk and the Bet of the Century," as reviewed by The Los Angeles Times. According to the book, during a 2016 phone call between Musk and Cook that touched on the possibility of ...
homepod feature blue2

Looking to Grab a HomePod Before They're Gone? These Retailers Still Have Stock

Monday March 15, 2021 6:54 am PDT by
Apple last week discontinued the original HomePod, marking just over three years on the market for the full-size smart speaker. If you're looking to purchase the larger HomePod before it's completely gone, there are still some options online today. The biggest retailer with remaining stock on the HomePod is Apple itself, which has the White HomePod for $299.00 on its website. Space Gray is...
september 2021 event ar logo

Apple's September 14 Event Page Features AR Logo on iPhone

Tuesday September 7, 2021 9:23 am PDT by
Apple this morning announced a digital-only event that will be held on Tuesday, September 14, and if you view the event webpage on an iPhone, you can tap on the logo to open up Apple's Safari AR viewer and you'll see the three-dimensional logo move in real-time in the real world. Just open up the event site on an ‌iPhone‌ or iPad and tap right on the logo to open up the AR version. The...
iphone 11 night mode photos

Apple Reveals New Night Mode Photo Feature Exclusive to iPhone 11 Series

Tuesday September 10, 2019 12:23 pm PDT by
Apple today announced the iPhone 11, iPhone 11 Pro, and the iPhone 11 Max, all-new models that boast improved cameras, and specifically, a dramatic new Night Mode photo feature. Last year, Google introduced its impressive Night Sight camera mode, a software-based feature that allows users to take detailed pictures in dark environments using Google Pixel smartphones. Apple's new Night...
iPhone 13 Dummy Thumbnail 2

Kuo: iPhone 13 to Feature LEO Satellite Communications to Make Calls and Texts Without Cellular Coverage

Sunday August 29, 2021 7:39 am PDT by
The iPhone 13 will feature low earth orbit (LEO) satellite communication connectivity to allow users to make calls and send messages in areas without 4G or 5G coverage, according to the reliable analyst Ming-Chi Kuo. In a note to investors, seen by MacRumors, Kuo explained that the iPhone 13 lineup will feature hardware that is able to connect to LEO satellites. If enabled with the relevant...