/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

Inside the Effort to Kill a Web Fraud ‘Botnet’

Working With Law Enforcement, Team Cuts Off Servers for Zombie Computers  —  For months, investigators at Microsoft Corp. hunkered down in front of their computer monitors, patiently stalking the shadowy figures behind what the company says is a major Web ad-fraud machine.

Wall Street Journal Christopher S. Stewart

Context & Ripple Effects

This is Microsoft's second high-profile botnet strike in just over two years, and the playbook looks familiar: in September 2011 the company detailed how it took down the Kelihos botnet, and this week it applied the same combination of in-house investigators and law-enforcement cooperation to an ad-fraud operation. The difference is scale of patience — months of monitoring the operators before moving.

The strike lands three days after PC World reported that the ZeroAccess click-fraud botnet had been disrupted but was 'not dead yet', underscoring the core limitation of server seizures against a resilient network. The story traveled widely for a corporate security action, with same-day pickups at Computerworld, WSJ's Digits blog, and Microsoft's own Digital Crimes Unit account.

First-order effects

  • Severing the command-and-control servers immediately cuts off the infected 'zombie' machines from their operators, halting whatever click fraud the network was generating at the moment of seizure.
  • The botnet operators lose their hosting infrastructure and revenue stream overnight, while Microsoft gains operational attribution — months of surveillance data on how the shadowy figures ran the machine.

Second-order effects

  • Because PC World reported ZeroAccess was 'not dead yet,' the surviving portion of the botnet forces responders into cleanup mode — disinfecting millions of infected PCs rather than declaring victory over a single seizure.
  • Other ad-fraud operations now have to assume their infrastructure is being watched by corporate investigators working with law enforcement, raising the cost of centralized command servers and pushing toward more distributed designs.

Third-order effects

  • The Kelihos-to-ZeroAccess sequence establishes a repeatable template — private company builds evidence, courts authorize server seizures, police execute — that positions companies like Microsoft as de facto cyber-enforcement actors alongside under-resourced agencies.
  • If takedowns keep proving temporary against P2P-style botnets, the industry's center of gravity shifts from one-off raids toward sustained sinkhole-and-monitor operations, with security firms competing on attribution capability rather than signatures.

The trend: Botnet takedowns are consolidating into a standing public-private playbook led by tech companies' investigative units, even as resilient botnet architectures blunt each raid's permanence.