Flashback makers missed out on their payday, Symantec says
The high-profile Flashback Trojan that is estimated to have infected more than 600,000 Macs at its peak earlier this year would have earned its creators $14,000 in the course of three weeks. — The only hitch is that the money isn't going anywhere.
Context & Ripple Effects
Flashback exploited an unpatched Java vulnerability without requiring a password, then grew to more than half a million reported Mac infections in early April. Even after Apple's fix, 140,000 machines were still affected, leaving a substantial but declining pool of compromised systems.
Symantec's estimate puts a small realized value on a botnet that had reached an estimated 600,000 Macs at its peak: the operators generated about $14,000 over three weeks but failed to collect it. That separates the reach of the infection from the attackers' ability to turn control of devices into usable proceeds.
First-order effects
- Flashback's operators lose the estimated $14,000 payout, despite having compromised a large number of Macs.
- Mac owners remain exposed while infections persist, but the attackers' failure to collect limits the immediate financial return from the campaign.
Second-order effects
- For security vendors including Symantec, the episode makes botnet disruption about blocking payment collection as well as removing malware from infected machines.
- The shrinking Flashback botnet, after its earlier scale, shows that a large installed base does not guarantee durable attacker revenue once remediation and disruption take hold.
Third-order effects
- If payment channels can be interrupted alongside cleanup, malware operators face pressure to favor campaigns with more reliable monetization rather than simply maximizing infected-device counts.
The trend: Botnet economics are increasingly shaped by whether attackers can convert device control into collectible revenue, not by infection scale alone.