On 09/05/2013 09:42 PM, Pokokohua wrote:

>> * mirimir:*> That depends. If it's drawing on random clueless Windows users, as most> botnets do, I don't see why it wouldn't show up in honeypots. If it's> not showing up, it might be a feature rollout. Or it might not really be> a physical botnet, but rather something very cleaver that looks like one.
> Or perhaps this attack is only limited to creating new users via some
> method of manipulating the user creation system. That could explain
> why no honeypots would have detected such a wide spread infestation
> because in this scenario there wou.

See the "[tor-talk] Many more Tor users in the past week?" thread.

It's an existing botnet that's being converted to Tor for C&C.

