The Evolution of Malicious IRC Bots
Click here to download now
Overview: New variants are emerging at the rate of almost 1000 a month making IRC bots the most prevalent Win32 threat in the wild. Their modular design and open source nature has allowed them to thrive, outwitting many signature based antivirus products simply due to the vast numbers of variants being produced. This white paper examines the core features of popular IRC bots and tracks their evolution from a single code base. This analysis demonstrates how many of the common IRC bots such as Agobot, Randex, Spybot and Phatbot share common source code.


