In our publication on April 14, we first announced the takedown of the Simda botnet, by Interpol, Microsoft, the Dutch National Cyber Crime Unit (NHTCU), the US Federal Bureau of Investigation (FBI), the New Technologies Department of the Police of the Grand Duchy of Luxembourg, the “K” Sector of the Digital Crime Department of the Russian Ministry of Internal Affairs, with the support of the INTERPOL Central National Bureau in Moscow, as well as the security companies Trend Micro and Kaspersky Lab.
Today Kaspersky Labsent us a press release about the suppression of the Simda botnet.
In a global operation coordinated by Global Complex for Innovation in Singapore, leading IT companies, including Kaspersky Lab, Microsoft, Trend Micro and the Digital Defense Institute of Japan, in collaboration with law enforcement authorities, have suspended the operation of the criminal botnet Simda, a network of thousands of “infected” computers around the world.
In a series of simultaneous operations on Thursday, April 9, 10 Command & Control servers were seized in the Netherlands, while corresponding servers in the US, Russia, Luxembourg and Poland were also shut down. The operation involved the Dutch National Cyber Crime Unit (NHTCU), the US Federal Bureau of Investigation (FBI), the New Technologies Department of the Grand Duchy of Luxembourg Police and the “K” Sector of the Digital Crime Department of the Russian Ministry of Internal Affairs, with the support of INTERPOL’s Central National Bureau in Moscow.
This development is expected to significantly disrupt the botnet's operation. It will also increase the cost and risk for cybercriminals who intend to continue their illegal activities, while also preventing victims' computers from participating in malicious actions.
What is Simda?
Simda is a “pay-per-install” malware used to distribute illegal software and various types of malware, including programs that can steal login credentials to financial resources. The “pay-per-install” model allows cybercriminals to make money by selling access to “infected” computers to other criminals, who then install additional programs on them.
Simda is distributed by a series of infected websites, which redirect to malicious exploit kits. Attackers compromise legitimate websites and servers, injecting malicious code into the pages that users visit. When users browse these pages, the malicious code “silently loads” content from the exploit-laden website and “infects” computers that do not have the latest software updates.
The Simda botnet has been detected in over 190 countries, with the US, UK, Russia, Canada and Turkey being the most affected countries. The bot is believed to have infected 770,000 computers worldwide, with the vast majority of its victims in the US (over 90,000 new infections since the beginning of 2015).
Active for years, Simda has been constantly evolving to exploit any vulnerability. In fact, it has been creating and distributing new, more elusive versions of its software every few hours. Currently, Kaspersky Lab’s “virus collection” contains more than 260,000 executable files belonging to different versions of the Simda malware.
Information and evidence are being gathered in order to identify the actors behind the Simda botnet, that is, the individuals who applied the business model of charging "accomplices" for criminal activities to their criminal activities.
“This successful operation highlights the value and need for collaboration between national and international law enforcement agencies and the private sector in combating the global threat of digital crime,” said Sanjay Virmani, Director of the INTERPOL Digital Crime Centre . “This operation has dealt a significant blow to the Simda botnet . INTERPOL will continue to support its member states in protecting citizens from digital crime and identifying other emerging threats,” he added.
“ Botnets are geographically distributed networks and suppressing them is usually a difficult task. This is why a collective effort by the private and public sectors is crucial. The contribution of all stakeholders is important in this joint effort. In this case, Kaspersky Lab’s role was to provide technical analysis of the botnet, collect telemetry data via the Kaspersky Security Network , and provide advisory support on suppression strategies,” commented Vitaly Kamluk, Principal Security Researcher at Kaspersky Lab, who is currently working with INTERPOL on secondment from the company.
The crackdown succeeded in shutting down the Command & Control servers used by the criminals to communicate with “infected” machines. However, it is important to note that some “infections” still exist. In order to help victims neutralize the “infection” from their computers, Kaspersky Lab has created a special website CheckIP. There, users can find out if their IP addresses have been detected by Simda’s Command & Control servers, which signals the possibility of their active or past “infection”. These IP addresses became available after the servers were shut down.
If a user's IP is identified, it does not necessarily mean that a computer is "infected". In some cases, an IP address may be used by several computers on the same network (for example, they could be connected to an Internet service provider). However, it is advisable for users to check and scan their system with a comprehensive security solution, such as the free Kaspersky Security Scan or the trial version of Kaspersky Internet Security.
To check if your system is part of the Simda botnet, you can visit the following address:https://checkip.kaspersky.com.
More information about the dismantling of the Simda botnet is available on Securelist.com.
