There is a new trojan spreading through the wild called Phatbot. This Bot spreads itself by scanning large blocks of Internet addresses and infects computers that has a vulnerability it knows how to exploit. How it infects computers is not that original, but how the bots are controlled by their master is. The creator of this particular Bot controls these bots through a P2P network called WASTE.
Phatbot is a direct decendant of a Bot called Agobot. Agobot had many similarities with Phatbot, but was mostly controlled through an IRC channel in which it would connect to when the computer started. The creator of Phatbot decided to use a little known P2P network called Waste which was created by a division of AOL called Nullsoft.
The Bots connect to a Gnutella Server where they are then able to see other Phatbot's that are connected to the network. This way they can connect to each other and create a Peer-2-Peer network in which they can communicate with each other. The creator can then issue commands to the Bot in order to make it do certain tasks.
THe main danger of this Bot is the amount of commands it has and the types of vulnerabilities it can exploit. From what has been diagnosed this Bot can scan for most of the known Windows exploits, steal passwords, cd keys, paypal cookies, sniff traffic, send spam from your computer, and much more. You will probably hear more about this Bot in the days to come, and be sure to update your virus protections every day as a new update will most likely be coming out soon.