Microsoft is taking control of the ZLoader botnet infrastructure, which is used to spread malware and ransomware.

See also: Fodcha Botnet: Targets over 100 victims per day with DDoS
The ZLoader malware has infected thousands of organizations, primarily in the US, Canada, and India, and is known to have distributed the Conti ransomware.
The ZLoader campaign operators evolved the malware from a basic banking trojan into a more sophisticated piece of malware capable of monetizing compromised devices by selling access to other affiliate groups. By leveraging and misusing legitimate tools like Cobalt Strike and Splashtop, affiliates gain keyboard access to affected devices, which can then be used for other malicious activities, such as stealing credentials or downloading additional payloads, including ransomware. ZLoader has previously been linked to ransomware infections such as Ryuk, DarkSide, and BlackMatter.
Microsoft has now received a court order from the U.S. District Court for the Northern District of Georgia allowing it to seize 65 domains used by the ZLoader gang for command and control (C&C) for its botnet created by malware that infected businesses, hospitals, schools, and homes.
These domains are now directed to a “Microsoft sinkhole,” outside the control of the ZLoader gang.
Microsoft also gained control of the domains used by ZLoader for the domain generation algorithm (DGA), which is used to automatically create new domains for the C2 .
Microsoft led the effort against ZLoader in collaboration with researchers from ESET, Lumen's Black Lotus Labs, and Palo Alto Networks Unit 42. Avast assisted Microsoft's European DCU investigation. According to ESET, Zloader had approximately 14,000 unique samples and more than 1,300 unique C&C servers.
See also: US shuts down Cyclops Blink botnet
Microsoft acknowledges that ZLoader has not been “completely stopped” and is also working with Internet to identify and remediate infections on infected systems. The case has also been referred to law enforcement.

Microsoft in 2020 used a similar legal-technical approach to take down the Trickbot botnet.
Microsoft in its technical analysis of ZLoader notes that the group used Google Ads to distribute the Ryuk ransomware, allowing it to bypass email security and display it in the browser. Malicious ads and emails were the primary delivery mechanisms. Each campaign impersonated well-known technology brands, including Java, Zoom, TeamViewer , and Discord.
See also: Qbot botnet uses new infection techniques
To deliver the emails, the group often used Microsoft Office and macro to infect machines. The lures to trick victims into opening a document and enabling the macros included COVID -19, late invoice payments , and fake resumes.
Information source: zdnet.com
