HomeinetAuthorities shut down Avalanche malware network

Authorities shut down Avalanche malware network

Law enforcement and internet companies from around the world worked together to shut down Avalanche, one of the largest cyber malware networks ever discovered in the last decade.

Facebook Opens Data Center In North Carolina Avalanche

Their efforts resulted in the arrest of five suspects, the seizure of 37 servers, and the shutdown of another 221 servers.

According to statements from Europoland the US Department of Justice , the suspects used this infrastructure as a global criminal network responsible for distributing and hosting over 20 different malware families, ranging from ransomware to banking trojans.

This network, which authorities had nicknamed “Avalanche,” was provided for rent by its owners to send spam, host and spread their malware, host command and control (C&C) servers, and also to launder profits and stolen funds.

The overall effort involved researchers from more than 30 countries, law enforcement authorities from various countries including Europol, Eurojust, Interpol, FBI, the US Department of Justice, Internet organizations and companies such as ICANN, Symantec, the Shadowserver Foundation, the Registrar of Last Resort, and others.

Authorities reported that they seized or blocked over 800,000 domains used by various malware botnets. The large number of domains was because most of the botnets use a technique known as double fast flux DNS, which passes through a large number of domains per day to hide the location of their botnet's C&C server.

According to US CERT, the Avalanche network was used to host the following malware families:
Windows-encryption Trojan horse (WVT) (aka Matsnu, Injector, Rannoh, Ransomlock.P)
URLzone (aka Bebloh)
Citadel
VM-ZeuS (aka KINS)
Bugat (aka Feodo, Geodo, Cridex, Dridex, Emotet)
newGOZ (aka GameOverZeuS)
Tinba (aka TinyBanker)
Nymaim/GozNym
Vawtrak (aka Neverquest)
Marcher
Pandabanker
Ranbyus
Smart App
TeslaCrypt
Trusteer App
Xswkit

According to Symantec , the investigation into the Avalanche network began in early 2012 when criminals created and spread ransomware that used a fake police alert to lock their victims' files and then demand a ransom.

The ransomware was named Ransomlock.P, and it appeared in late 2011. German police officially launched an investigation into Avalanche because the ransomware used its name.

German authorities also reported that the fraudsters managed to steal over €6 million from German banks alone. Europol estimated that fraudsters using the Avalanche network may have stolen hundreds of millions of euros worldwide.

Europol also estimates that Avalanche botnets were sending a total of one million spam messages per week. But in addition to bank fraud and spam, authorities said the Avalanche network was also used to host malware for DDoS attacks.

Researchers believe that over 500,000 users still have computers infected with various types of malware distributed through this network. These users should be aware that while the malware's backend infrastructure is down, the malware is still present on their computers, and they should remove it.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS