Story image

Microsoft, ESET & law enforcement disrupt Gamarue botnet

06 Dec 17

Microsoft, ESET, the FBI, Interpol, Europol and other security stakeholders have collectively dismantled a major botnet operation known as Gamarue.

After a coordinated take down in November, law enforcement agencies were able to disrupt botnets and make an arrest.

The Gamarue botnet has been plaguing computers since 2011 and infected more than 1.1 million systems per month and heavily infected many countries in Asia. Gamarue is also known as Wauchos or Andromeda.

According to ESET, the Gamarue family’s was sold as a crime kit on the Dark Web. Its purpose was to steal credentials and to download and install additional malware.

“This malware family is a customizable bot, which allows the owner to create and use custom plugins. One such plugin allows the cybercriminal to steal content entered by users in web forms while another enables criminals to connect back and control compromised systems,” ESET explains further. 

Microsoft’s figures includes 1214 domains and IP addresses associated with the Command & Control centres; 464 distinct botnets; and 80 associated malware families.

Gamarue has also spawned independent botnets, with samples spread across social media, instant messaging, removable media, spam and exploit kits.

“There are multiple botnets, potentially all run by different people. The Botnets we were tracking for this operation were mainly involved in criminal activities to make a profit, not espionage,” ESET explains.

Microsoft approached ESET and together they tracked Gamarue’s botnets for a year and a half. They identified Command & Control servers for takedown and monitored what exactly was being installed on victims’ systems.

“In the past, Wauchos has been the most detected malware family amongst ESET users, so when we were approached by Microsoft to take part in a joint disruption effort against it, to better protect our users and the general public at large, it was a no-brainer to agree,” comments ESET senior malware researcher  Jean-Ian Boutin.

However in an FAQ, ESET reveals that Gamarue is still prevalent because it is actively distributed and the people running the botnets are trying not to get caught.

Although ESET says it has ‘sinkholed’ all known domains, it is too soon to know if Gamarue’s activity will stop or keep going.

“This particular threat has been around for several years now and it is constantly reinventing itself – which can make it hard to monitor. But by using ESET Threat Intelligence and by working collaboratively with Microsoft researchers, we have been able to keep track of changes in the malware’s behaviour and consequently provide actionable data which has proven invaluable in these takedown efforts.”

What MSPs can learn from Datto’s Channel Ransomware Report
While there have been less high profile attacks making the headlines, the frequency of attacks is, in fact, increasing.
Cisco expands security capabilities of SD­-WAN portfolio
Until now, SD-­WAN solutions have forced IT to choose between application experience or security.
AlgoSec delivers native security management for Azure Firewall
AlgoSec’s new solution will allow a central management capability for Azure Firewall, Microsoft's new cloud-native firewall-as-a-service.
How to configure your firewall for maximum effectiveness
ManageEngine offers some firewall best practices that can help security admins handle the conundrum of speed vs security.
Exclusive: Why Australian enterprises are prime targets for malware attacks
"Only 14% of Australian organisations are continuously training employees to spot cyber attacks."
Exclusive: Why botnets will swarm IoT devices
“What if these nodes were able to make autonomous decisions with minimal supervision, use their collective intelligence to solve problems?”
Bitdefender announces security integration with Kaseya
The new partnership will allow VSA by Kaseya’s cloud and on-premises users to deploy and manage security with Bitdefender Cloud Security for MSPs.
Why you should leverage a next-gen firewall platform
Through full lifecycle-based threat detection and prevention, organisations are able to manage the entire threat lifecycle without adding additional solutions.