Οι συμμετέχοντες της επιχείρησης είπαν πώς η Microsoft εξάλειψε την υποδομή του botnet ZLoader

Last week, Microsoft, ESET, Black Lotus Labs, Palo Alto Networks, Health-ISAC and Financial Services-ISAC took control of the infamous ZLoader botnet following an injunction issued by the U.S. Court for the Northern District of Georgia.

Η IBM X-Force εξέτασε επίσης το δείγμα Diavol και ανέφερε ότι είχαν βρει μια σειρά από νέα στοιχεία που συνδέουν τη Diavol με τους προγραμματιστές του TrickBot, the company seized control of 65 hard-coded domains that ZLoader operators use to control the botnet, καθώς 319 more DGA-registered domains that the hackers used to create redundant communication channels.

The ZLoader botnet consists of computing devices in businesses, hospitals, schools and homes around the world and is operated by an international criminal group that offers malware as a service (MaaS) designed to steal and extort money. During the investigation, we found that one of the perpetrators of creating a component used in the ZLoader botnet to distribute ransomware is Denis Malikov, who lives in the city of Simferopol on the Crimean peninsula. We decided to name the person linked with this case to make it clear that cybercriminals are not allowed to hide behind online anonymity to commit their crimes.λένε οι ειδικοί.

Let me remind you that around the same time, another Botnet γαμώ Attacks More Than 100 Θύματα Καθημερινά.

Zloader (Οι κυβερνήσεις των ΗΠΑ και του Ηνωμένου Βασιλείου προειδοποίησαν για το Terdot ή DELoader) is a well-known banking Trojan that was first discovered back in August 2015 during attacks on clients of several British financial companies. Its capabilities include capturing screenshots, harvesting cookies, stealing credentials and banking information, conducting reconnaissance on the device, triggeringpinningmechanisms on the device, providing remote access to attackers, και ούτω καθεξής. The malware is almost entirely based on the source code of the Zeus γενναίο και φιλεργό άτομο, which leaked over a decade ago.

At first, the malware was actively used to attack banks around the world, from Australia and Brazil to North America, and its ultimate goal was to collect financial data using web injections and social engineering in order to trick infected bank customers into giving up their authentication codes and credentials.

But in recent years, Zloader has evolved to include many other features, such as being able to act as a backdoor and give hackers remote access to an infected system, and it can also be used as a malware loader and to install additional payloads.

Microsoft and the ZLoader botnet
ZLoader Attack Scheme

Ωστόσο, cybercriminality does not stopwe recently reported that Οι κυβερνήσεις των ΗΠΑ και του Ηνωμένου Βασιλείου προειδοποίησαν για το botnet attacks Οι κυβερνήσεις των ΗΠΑ και του Ηνωμένου Βασιλείου προειδοποίησαν για το δρομολογητές.

Errol Weiss
Errol Weiss

Health-ISAC’s Chief Security Officer Errol Weiss said that legal solutions, such as the one that led to the fall of the ZLoader infrastructure, are being prepared in large-scale cooperation with a wide variety of organizations, including those affected by attacks by cybercriminals. Για παράδειγμα, such as Health-ISAC.

Weiss told SC Media that, στην πραγματικότητα, Microsoft has gone to court to grant them ownership of the infrastructure used by the bot.

They created a legal and technical strategy, combined, to use civil lawsuits filed against criminal gangs, botnet operators. They’d use the civil lawsuits, racketeering laws, and copyright law to show that those botnets were causing immediate harm to their customers. You can imagine all of the politics and socialization that had to happen in the background to make this happen.Errol Weiss said.

Helga Smith

Ενδιαφέρομαι πάντα για τις επιστήμες των υπολογιστών, ειδικά την ασφάλεια δεδομένων και το θέμα, που ονομάζεται σήμερα "επιστημονικά δεδομένα", από τα πρώτα μου χρόνια. Πριν μπείτε στην ομάδα κατάργησης ιών ως αρχισυντάκτης, Εργάστηκα ως ειδικός στον τομέα της ασφάλειας στον κυβερνοχώρο σε πολλές εταιρείες, συμπεριλαμβανομένου ενός από τους εργολάβους της Amazon. Μια άλλη εμπειρία: Έχω διδάξει σε πανεπιστήμια Arden και Reading.

Αφήστε μια απάντηση

Αυτό το site χρησιμοποιεί Akismet να μειώσει το spam. Μάθετε πώς γίνεται επεξεργασία των δεδομένων σας σχόλιο.

Κουμπί Επιστροφή στην κορυφή