HomeSecurityINTERPOL collaborates to take down Simda botnet

INTERPOL collaborates to take down Simda botnet

Simda

The Simda botnet was taken down on April 9, in a collaborative effort between international law enforcement agencies and private security and technology companies, with INTERPOL.

The botnet, known for spreading banking malware and creating a backdoor for all malware, has exploited more than 770,000 computers in 190 countries. The takedown managed to seize 14 command-and-control servers in the Netherlands, the US, Poland, Luxembourg and Russia.

According to researchers, Simda is a mysterious botnet used by cybercriminals to distribute various types of unwanted and malicious software. Due to its continuous functionality and security updates, it rarely appears on KSN radars despite the large number of visitors daily.

It uses hardcoded IP addresses to inform the owner about the stages of execution. It can modify the system's hosts file by downloading and executing additional elements from its own updated servers and, to redirect to malicious IPs, it adds its own entries for google-analytics.com and connect.facebook.net.

The Kaspersky Lab states that “This criminal enterprise provides the ability to exclusively distribute malware. This means that distributors can guarantee that only the client’s malware is installed on the machines. And so we find ourselves in a situation where Simda interprets a response from the C&C server, then deactivates itself, preventing the bot from starting after the next reboot, and immediately exits. This deactivation coincides with the modification of the system’s hosts file. And as a final touch, Simda replaces the original hosts file with one of its own.”

To analyze the spread of the infection, the Digital Crime Center ( IDCC ) in Singapore collaborated with Microsoft , Trend Micro , Kaspersky Lab , and Cyber ​​Defense of Japan. The team also included officials from the High Tech Crime Unit of the Netherlands and the Police Grand - Ducale Section Nouvelles Technologies of Luxembourg, the US Federal Bureau of Investigation, and the Russian Interior Ministry 's Cybercrime Department " K ".

Sanjay Virmani , Director of INTERPOL ’s Digital Crime Centre, said: “ This successful operation highlights the value and need for partnerships involving national and international law enforcement agencies, as well as the private sector, to combat the now global threat of cybercrime. The operation has dealt a major blow to the Simda botnet. INTERPOL will continue its work to help other member countries protect their citizens from cybercriminals and identify other emerging threats. ”

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS