ESET unites with Microsoft and law enforcement agencies to disrupt Gamarue botnets


The worldwide partners took action against servers and domains used to spread the Andromeda malware.

Organizations participating in the Andromeda investigation included the Europol European Cybercrime Center, the FBI, the Luneburg Central Criminal Investigation Inspectorate in Germany, the Joint Cybercrime Action Task Force, Eurojust and private-sector partners.

Additionally, during the operation, law enforcement has arrested a man in Belarus which might be the leader in Andromeda cybercrime gang.

In a separate statement, Europol, quoting Microsoft, said that the Andromeda's "main goal was to distribute other malware families" and that the malware and associated botnet "was associated with 80 malware families and, in the last six months...was detected on or blocked an average of over 1 million machines every month". Linked with 80 malware families, Andromeda has been detected on or blocked on almost 1.1 million machines every month on average over the past six months.

A crime-kit sold on the dark web, Gamarue offer high levels of customisation, allowing the user to build and deploy custom plugins - notable examples of malicious activity distributed using the self-service kit include building plugins to steal content entered into web forms while another allows attackers to control compromised systems. He is also the developer of the Win32/Gamarue HTTP bot, the Windows SMTP Bruter v.1.2.3 and the "Swf-Inj Service" that hijacks web traffic using malware.

Microsoft approached ESET and together they tracked Gamarue's botnets for a year and a half. It took Microsoft and ESET 18 months to identify the command and control communications behind Gamarue and then provide that information to the authorities. However, they did not name the suspect.

"This is another example of worldwide law enforcement working together with industry partners to tackle the most significant cybercriminals and the dedicated infrastructure they use to distribute malware on a global scale".

"This particular threat has been around for several years now and it is constantly reinventing itself - which can make it hard to monitor".

One of the malware families cited was the Avalanche Network, a botnet network that at one stage was responsible for two-thirds of all phishing attacks globally that brought down following a four-year investigation by global law enforcement agencies in December 2016. From there ESET and Microsoft were able to not only able to track the botnet but also locate the aforementioned servers.

More than 1,500 malicious domains used to control the botnet were subject to sinkholing and all traffic from infected computers were rerouted to less risky sites. The clear message is that public-private partnerships can impact these criminals and make the internet safer for all of us, ' said Steven Wilson, the Head of Europol's European Cybercrime Centre.

The operation to eliminate the Andromeda botnet also resulted in sinkholing of 1500 domains of the malicious software, as well as the capturing of approximately 2 million unique Andromeda victim IP addresses from 223 countries.



Related Posts

American voters aren't happy about the GOP's tax plan
Those same swing voters favor Democrats over Republicans for control of the House and Senate next year by 15 percentage points. As of Wednesday, the bill had average ratings of 32% approval and 46% disapproval, based on polls from five organizations.

Apple's Cook sees Tencent as 'great partner'
The US tech giant said earlier it had moved its Chinese cloud data onto the servers of a local partner in the Chinese province of Guizhou.

The Ameritas Investment Partners Inc. Decreases Stake in American Eagle Outfitters (AEO)
The company was maintained on Thursday, March 2 by FBR Capital. (AEO) was a Hold - from a survey of 15 analysts. The total value of these holdings, in millions, is $2,341. 105 funds opened positions while 667 raised stakes.

Jamia Millia Islamia student found dead inside his auto near Sarojini Market
Police said that it was Rizwan's father who found him lying in a pool of blood inside the vehicle parked outside the girl's house. A bullet injury was found on the right temple of the body. "A team of forensic experts have collected samples", the officer said.

The Eagle Bancorp, Inc. (EGBN) Upgraded to "Outperform" by FIG Partners
Finally, Boenning Scattergood reissued a "buy" rating on shares of Eagle Bancorp in a research note on Thursday, October 19th. Bontempo Ohly Capital Mgmt Llc sold 11,982 shares as the company's stock declined 9.03% while stock markets rallied.

B-1B, F-22 jets hold attack drills in Korea
Jeffrey Feltman, the UN's political affairs chief, traveled to the Asian country to discuss Pyongyang's nuclear program. North Korea has condemned the military exercise as a provocation amid heavy tensions between Washington and Pyongyang.

Marvel have announced a Wolverine podcast and it sounds deady
The agents team up with deputy Bobby Reid (Andrew Keenan-Bolger) to investigate their main suspect, Logan ( Richard Armitage ). Instead, Wolverine will be voiced by Richard Armitage, who played Thorin Oakenshield in The Hobbit trilogy.

Angels agree to terms with top 17-year-old prospect Kevin Maitan
That will make him the Angels' No. 1 prospect immediately, as their previous top prospect, Jo Adell, wasn't even in the Top 100. They still have $1.315 million to offer Ohtani, though the Japanese superstar does not appear to be concerned with money.

Supreme Court Leaning Towards A Positive NJ Sports Betting Ruling
Frank Pallone, D-N.J., announced that he would introduce a bill on Monday that aims to repeal the federal ban on sports betting. Only four states - Nevada, Montana, Delaware and OR - are allowed to facilitate sports gambling under a 1992 federal law.

U.S. defence secretary Mattis seeks more cooperation with Pakistan on terror fight
Mattis' trip to Pakistan comes at the end of a short trip to the region, including stops in Egypt, Jordan and Kuwait. He said Pakistani leaders went to Kabul and met with Afghan President Ashraf Ghani.

© 2015 ExpressNewsline. All Rights reserved.