Authorities have disabled the Avalanche malware network

Οι αρχές επιβολής του νόμου και οι εταιρείες του διαδικτύου από όλο τον κόσμο συνεργάστηκαν για να κλείσουν το Avalanche, ένα από τα μεγαλύτερα malware in cyberspace that have ever been discovered in the last decade.

Facebook Opens Data Center in North Carolina Avalanche

Their attempts resulted in the arrest of five suspects, 37 server confiscation and the closure of other 221 servers.

According to statements by Europol and his US Department of Justice , suspects used this infrastructure as a global criminal network that was responsible for spreading and hosting over 20 different malware families ranging from ransomware to bank trojans.

This network, to which the authorities had given the nickname "Avalanche“(Avalanche), its owners provided it for rent for her spam, hosting and spreading their malware, hosting command and control (C&C) servers, but also to launder profits and stolen funds.

The overall effort has been contributed by researchers from more than 30 countries, law enforcement authorities from various countries including Europol, Eurojust, Interpol, the FBI, the US Department of Justice, organizations and internet companies such as ICANN, Symantec, Shadowserver Foundation, Registrar of Last Resort, and others.

Authorities reported that more than 800.000 domains used for various malware were seized or blocked . The large number of domains was because most of the botnets use a technique known as double fast flux DNS, which goes through a large number of domains per day to hide the location of the botnet's C&C server .

According to US CERT, the Avalanche network was used to host the following malware families:
Windows-encryption Trojan horse (WVT) (aka Matsnu, Injector, Rannoh, Ransomlock.P)
URLzone (aka Bebloh)
Citadel
VM-ZeuS (aka KINS)
Bugat (aka Feodo, Geodo, Cridex, , Emotes)
newGOZ (aka GameOverZeuS)
Tinba (aka TinyBanker)
Nymaim / GozNym
Vawtrak (aka Neverquest)
Marcher
Pandabanker
Ranbyus
Smart App
TeslaCrypt
Trusteer App
Xswkit

According to Symantec The στο δίκτυο Avalanche ξεκίνησε στις αρχές του 2012 όταν οι κακοποιοί δημιούργησαν και εξάπλωσαν ένα ransomware που χρησιμοποιούσε μία ψεύτικη προειδοποίηση της αστυνομίας ώστε οι μπορέσουν να κλειδώσουν τα αρχεία των θυμάτων τους και κατόπιν να ζητήσουν λύτρα.

The name of the ransomware was Ransomlock.P, and appeared at the end of 2011. The German police formally launched the Avalanche survey because ransomware used its name.

The German authorities also reported that crooks managed to steal more than € 6.000.000 from the German banks alone. Europol is estimated that fraudsters who have used the Avalanche network may have stolen hundreds of millions of euros around the world.

Europol also estimates that Avalanche's botnets sent a total of one million spam messages a week. But in addition to bank fraud and spam, the authorities have announced that the Avalanche network was also used to host malware for DDoS attacks.

Researchers believe that over 500.000 users still have infected computers with various types of malware distributed through this network. These users should be aware that while the malware backend infrastructure is down, malware still exists on their computers, and they should be removed.

iGuRu.gr The Best Technology Site in Greecefgns

every publication, directly to your inbox

Join the 2.087 registrants.

Written by Dimitris

Dimitris hates on Mondays .....

Leave a reply

Your email address is not published. Required fields are mentioned with *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).