ESET: The operation, which consisted of law enforcement agencies from around the world, led by the FBI, Interpol and Europol, disrupted the Dorkbot, which included Command and Control servers in Asia, Europe and North America.
Furthermore, the operation led to the seizure of domains, thus depriving the botnet operators of the ability to control their victims' computers.
“We participate in interception operations to make the internet safer and our users protected. In the case of Dorkbot, ESET contributed with technical analysis and statistics on the malware, as well as the domains and internet addresses of the botnet’s C&C servers,” said Jean-Ian Boutin, Malware Researcher at ESET.
Dorkbot is a well-established botnet based on the Win32/Dorkbot malware , which spreads using various methods, including social media, spam, removable media, and exploit kits.
Once installed on the machine, it will attempt to disrupt the smooth operation of security software by blocking access to update servers and then connect to an IRC server to receive further commands.
In addition to stealing passwords on popular services like Facebook and Twitter, Dorkbot typically installs code from one of several malware families once it gains control of a particular system. Notably, the installation of Win32/Kasidet, the malware used to carry out DDoS attacks, also known as the Neutrino bot, and Win32/Lethic, a well-known spambot, are due to Dorkbot’s breach of systems.
"As we saw thousands of detections every week from almost all parts of the world and new samples arriving daily, Dorkbot seemed like a target that could be intercepted," commented Jean-Ian Boutin.
ESET solutions protect their users from the thousands of Dorkbot variants, along with many other forms of malware spread by Dorkbot botnets.
Internet users who believe their system may have been infected by Dorkbot can use ESET's free tool for a full scan.
More information about Dorkbot and its neutralization can be found in article on WeLiveSecurity, ESET's official blog on security (and beyond). For ongoing updates, interested parties can follow the hashtag #Dorkbot on social media.
