Last week, cybersecurity led by Microsoft joined forces to take down TrickBot, one of the largest malware botnets and cybercrime operations in the threat landscape today. Even though Microsoft destroyed TrickBot’s infrastructure in the early days, the botnet survived, and its operators brought new command-and-control (C&C) servers online to continue their operations.
However, multiple cybersecurity industry sources told ZDNet that they expected TrickBot to retaliate, and Microsoft promised to continue its crackdown on the cyberthreat in the coming weeks. In an update released yesterday on its crackdown efforts, Microsoft confirmed a second wave of TrickBot crackdowns.

Microsoft said it has taken down 94% of the botnet's C&C servers, including the original servers and new ones brought online by its operators after the first takedown attempt. Specifically, the tech giant said that since the start of its operation through October 18, it had taken down 120 of the 128 servers it identified as Trickbot infrastructure around the world.
The eight servers that could not be taken down last week were classified as Internet of Things (IoT) devices. The reason these systems could not be immediately destroyed was that they were not located in web hosting companies and data centers, and the device owners could not be contacted via “email .” Additional coordination with local ISPs was required, but Microsoft noted that they are currently working to disable these devices.

According to cybersecurity firm Intel 471, TrickBot's "remnants" are found in Brazil, Colombia, Indonesia, and Kyrgyzstan.
Microsoft explained that it cannot determine how long TrickBot will survive, but it plans to “hunt” its infrastructure at least until November 3, the time of the US presidential election . Tom Burt, CVP of security and customer trust at Microsoft, said that the company is trying to prevent TrickBot from renting access to infected computers to ransomware gangs, something the TrickBot botnet group has been known to do in the past.

Additionally, Microsoft expressed concern that a ransomware attack could cause disruption to election systems – either directly, by directly encrypting election-related infrastructure, or indirectly, by affecting election-related supply chains.
