Story image

Microsoft, ESET & law enforcement disrupt Gamarue botnet

06 Dec 2017

Microsoft, ESET, the FBI, Interpol, Europol and other security stakeholders have collectively dismantled a major botnet operation known as Gamarue.

After a coordinated take down in November, law enforcement agencies were able to disrupt botnets and make an arrest.

The Gamarue botnet has been plaguing computers since 2011 and infected more than 1.1 million systems per month and heavily infected many countries in Asia. Gamarue is also known as Wauchos or Andromeda.

According to ESET, the Gamarue family’s was sold as a crime kit on the Dark Web. Its purpose was to steal credentials and to download and install additional malware.

“This malware family is a customizable bot, which allows the owner to create and use custom plugins. One such plugin allows the cybercriminal to steal content entered by users in web forms while another enables criminals to connect back and control compromised systems,” ESET explains further. 

Microsoft’s figures includes 1214 domains and IP addresses associated with the Command & Control centres; 464 distinct botnets; and 80 associated malware families.

Gamarue has also spawned independent botnets, with samples spread across social media, instant messaging, removable media, spam and exploit kits.

“There are multiple botnets, potentially all run by different people. The Botnets we were tracking for this operation were mainly involved in criminal activities to make a profit, not espionage,” ESET explains.

Microsoft approached ESET and together they tracked Gamarue’s botnets for a year and a half. They identified Command & Control servers for takedown and monitored what exactly was being installed on victims’ systems.

“In the past, Wauchos has been the most detected malware family amongst ESET users, so when we were approached by Microsoft to take part in a joint disruption effort against it, to better protect our users and the general public at large, it was a no-brainer to agree,” comments ESET senior malware researcher  Jean-Ian Boutin.

However in an FAQ, ESET reveals that Gamarue is still prevalent because it is actively distributed and the people running the botnets are trying not to get caught.

Although ESET says it has ‘sinkholed’ all known domains, it is too soon to know if Gamarue’s activity will stop or keep going.

“This particular threat has been around for several years now and it is constantly reinventing itself – which can make it hard to monitor. But by using ESET Threat Intelligence and by working collaboratively with Microsoft researchers, we have been able to keep track of changes in the malware’s behaviour and consequently provide actionable data which has proven invaluable in these takedown efforts.”

Thycotic debunks top Privileged Access Management myths
Privileged Access encompasses access to computers, networks and network devices, software applications, digital documents and other digital assets.
Veeam reports double-digit Q1 growth
We are now focussed on an aggressive strategy to help businesses transition to cloud with Backup and Cloud Data Management solutions.
Paving the road to self-sovereign identity using blockchain
Internet users are often required to input personal information and highly-valuable data from contact numbers to email addresses to make use of the various platforms and services available online.
Tech Data to distribute Nutanix backup solution in A/NZ
Tech Data will distribute HYCU Data Protection for Nutanix backup and recovery software to their network of partners across Australia and New Zealand.
Veeam releases v3 of its MS Office backup solution
One of Veeam’s most popular solutions, Backup for Office 365, has been upgraded again with greater speed, security and analytics.
Too many 'critical' vulnerabilities to patch? Tenable opts for a different approach
Tenable is hedging all of its security bets on the power of predictive, as the company announced general available of its Predictive Prioritisation solution within Tenable.io.
Safety solutions startup wins ‘radical generosity’ funding
Guardian Angel Security was one of five New Zealand businesses selected by 500 women (SheEO Activators) who contributed $1100 each.
Industrial control component vulnerabilities up 30%
Positive Technologies says exploitation of these vulnerabilities could disturb operations by disrupting command transfer between components.