Story image

Microsoft, ESET & law enforcement disrupt Gamarue botnet

06 Dec 2017

Microsoft, ESET, the FBI, Interpol, Europol and other security stakeholders have collectively dismantled a major botnet operation known as Gamarue.

After a coordinated take down in November, law enforcement agencies were able to disrupt botnets and make an arrest.

The Gamarue botnet has been plaguing computers since 2011 and infected more than 1.1 million systems per month and heavily infected many countries in Asia. Gamarue is also known as Wauchos or Andromeda.

According to ESET, the Gamarue family’s was sold as a crime kit on the Dark Web. Its purpose was to steal credentials and to download and install additional malware.

“This malware family is a customizable bot, which allows the owner to create and use custom plugins. One such plugin allows the cybercriminal to steal content entered by users in web forms while another enables criminals to connect back and control compromised systems,” ESET explains further. 

Microsoft’s figures includes 1214 domains and IP addresses associated with the Command & Control centres; 464 distinct botnets; and 80 associated malware families.

Gamarue has also spawned independent botnets, with samples spread across social media, instant messaging, removable media, spam and exploit kits.

“There are multiple botnets, potentially all run by different people. The Botnets we were tracking for this operation were mainly involved in criminal activities to make a profit, not espionage,” ESET explains.

Microsoft approached ESET and together they tracked Gamarue’s botnets for a year and a half. They identified Command & Control servers for takedown and monitored what exactly was being installed on victims’ systems.

“In the past, Wauchos has been the most detected malware family amongst ESET users, so when we were approached by Microsoft to take part in a joint disruption effort against it, to better protect our users and the general public at large, it was a no-brainer to agree,” comments ESET senior malware researcher  Jean-Ian Boutin.

However in an FAQ, ESET reveals that Gamarue is still prevalent because it is actively distributed and the people running the botnets are trying not to get caught.

Although ESET says it has ‘sinkholed’ all known domains, it is too soon to know if Gamarue’s activity will stop or keep going.

“This particular threat has been around for several years now and it is constantly reinventing itself – which can make it hard to monitor. But by using ESET Threat Intelligence and by working collaboratively with Microsoft researchers, we have been able to keep track of changes in the malware’s behaviour and consequently provide actionable data which has proven invaluable in these takedown efforts.”

SecOps: Clear opportunities for powerful collaboration
If there’s one thing security and IT ops professionals should do this year, the words ‘team up’ should be top priority.
Interview: Culture and cloud - the battle for cybersecurity
ESET CTO Juraj Malcho talks about the importance of culture in a cybersecurity strategy and the challenges and benefits of a world in the cloud.
Enterprise cloud deployments being exploited by cybercriminals
A new report has revealed a concerning number of enterprises still believe security is the responsibility of the cloud service provider.
Ping Identity Platform updated with new CX and IT automation
The new versions improve the user and administrative experience, while also aiming to meet enterprise needs to operate quickly and purposefully.
Venafi and nCipher Security partner on machine identity protection
Cryptographic keys serve as machine identities and are the foundation of enterprise information technology systems.
Machine learning is a tool and the bad guys are using it
KPMG NZ’s CIO and ESET’s CTO spoke at a recent cybersecurity conference about how machine learning and data analytics are not to be feared, but used.
Seagate: Data trends, opportunities, and challenges at the edge
The development of edge technology and the rise of big data have brought many opportunities for data infrastructure companies to the fore.
Popular Android apps track users and violate Google's policies
Google has reportedly taken action against some of the violators.