The malware that has occupied researchers for most of this year does something none of its predecessors did. When people probe it, it attacks them.
Several groups investigating the Storm network have reported that sustained scanning of infected machines is followed by their own connections being flooded off the internet. The botnet noticed it was being examined and spent some of its capacity making the examination stop.
That single behaviour tells you the whole story of what has changed.
The viruses I grew up reading about wanted to be noticed. They displayed messages, corrupted files, reformatted drives on a particular date. They were vandalism, and the reward was the vandal knowing it had worked. That model has been dead for a while but the public mental image of a computer virus has not caught up.
What is running now wants the machine to keep working perfectly. An infected PC that gets slow is an infected PC that gets taken to a repair shop, and a repair shop is where the asset is destroyed. So the software is careful. It uses a small share of the connection, it runs when the machine is idle, it does not touch documents. The owner has no reason to suspect anything, and the owner is not the customer anyway. The customer is whoever rents the network by the hour to send spam or knock a site over.
The structural change is the harder problem. Earlier botnets had a control server somewhere, and the standard response was to find it and have it taken offline, at which point every infected machine in the world became inert. It was slow and it required cooperation across jurisdictions, but it worked, because there was a head to cut off.
This one has no head. Infected machines find each other directly and pass instructions between themselves. There is no server whose removal ends it. Take out any given node and the rest reroute, which is exactly the property the internet was designed to have, now being used against the people trying to clean it up.
Size estimates range from a few hundred thousand machines to several million, and the range itself is informative. Nobody can count it, because counting requires probing, and probing gets you flooded.
What I take from this is that the defensive posture most people still hold is wrong in its shape. Antivirus software compares files against a list of things already known to be bad, which handles last year’s problem well. It does not help against something that arrives as an attachment a colleague appears to have sent, changes its own code frequently enough that the list never catches up, and then behaves impeccably.
The uncomfortable conclusion is that a great many machines running current, updated protection are part of this and will never find out. Their owners are not careless. They are simply not the intended victim, and nothing about the experience of using the computer will ever tell them.