Inside the Effort to Kill a Web Fraud ‘Botnet’
Working With Law Enforcement, Team Cuts Off Servers for Zombie Computers — For months, investigators at Microsoft Corp. hunkered down in front of their computer monitors, patiently stalking the shadowy figures behind what the company says is a major Web ad-fraud machine.
Context & Ripple Effects
This is Microsoft's second high-profile botnet strike in just over two years, and the playbook looks familiar: in September 2011 the company detailed how it took down the Kelihos botnet, and this week it applied the same combination of in-house investigators and law-enforcement cooperation to an ad-fraud operation. The difference is scale of patience — months of monitoring the operators before moving.
The strike lands three days after PC World reported that the ZeroAccess click-fraud botnet had been disrupted but was 'not dead yet', underscoring the core limitation of server seizures against a resilient network. The story traveled widely for a corporate security action, with same-day pickups at Computerworld, WSJ's Digits blog, and Microsoft's own Digital Crimes Unit account.
First-order effects
- Severing the command-and-control servers immediately cuts off the infected 'zombie' machines from their operators, halting whatever click fraud the network was generating at the moment of seizure.
- The botnet operators lose their hosting infrastructure and revenue stream overnight, while Microsoft gains operational attribution — months of surveillance data on how the shadowy figures ran the machine.
Second-order effects
- Because PC World reported ZeroAccess was 'not dead yet,' the surviving portion of the botnet forces responders into cleanup mode — disinfecting millions of infected PCs rather than declaring victory over a single seizure.
- Other ad-fraud operations now have to assume their infrastructure is being watched by corporate investigators working with law enforcement, raising the cost of centralized command servers and pushing toward more distributed designs.
Third-order effects
- The Kelihos-to-ZeroAccess sequence establishes a repeatable template — private company builds evidence, courts authorize server seizures, police execute — that positions companies like Microsoft as de facto cyber-enforcement actors alongside under-resourced agencies.
- If takedowns keep proving temporary against P2P-style botnets, the industry's center of gravity shifts from one-off raids toward sustained sinkhole-and-monitor operations, with security firms competing on attribution capability rather than signatures.
The trend: Botnet takedowns are consolidating into a standing public-private playbook led by tech companies' investigative units, even as resilient botnet architectures blunt each raid's permanence.