HomeSecurityRamnit Botnet returns after ten months of absence!

The Ramnit Botnet returns after a ten-month absence!

At the end of February 2015, Europol, in cooperation with many security vendors «sank» the C&C servers of the Ramnit botnet, which were used for financial fraud.

Now, ten years later, IBM's X-Force Threat Intelligence reports that the cyber gang behind the first botnet has slowly started a second version of the botnet, using malicious advertisements to infect users with its banking trojans.

The Ramnit Botnet returns after a ten-month absence!

Ramnit debuted on the cybercrime scene in 2010 and slowly grew, until it became the fourth largest financial fraud botnet at the end of 2014, behind GameOver Zeus, Neverquest (Vawtrack), and Shylock .

Primarily targeting users in English-speaking countries such as the US, Australia and the UK, the botnet quickly found itself on the radar of cybersecurity companies such as Microsoft, Symantec and AnubisNetworks, which collaborated with Europol's European Cybercrime Centre (EC3) and managed to bring down Ramnit by sabotaging its main server.

IBM researchers report that the C&C server of the v1 Ramnit botnet is still sending instructions, but due to Europol's efforts, these commands never reach any of the infected computers.

But this does not matter, given that the creators of Ramnit appear to have abandoned the old botnet for a new one with improved functionality, which runs a new facet of the Ramnit banking trojan.

IBM security experts claim that there are no huge differences between the older version of the Ramnit trojan and the newer one, except for the way it is transmitted.

While the Ramnit v1 banking trojan relied on removable drives and network shares to spread to new victims, the second‑generation Ramnit botnet is built using malicious ads that redirect users to a web page where the Angler Exploit Kit is hosted, information that is also confirmed by a report from Malwarefor.me from the end of November.

These new versions of the Ramnit banking trojan, which run on a new C&C server infrastructure, appear to be the first banking fraud botnet to resurface, according to IBM. This has surprised security experts, who have only seen spam botnets reborn, with cybercrime and banking fraud groups content to say that their botnet fell and got away with it without being caught.

Furthermore, IBM experts said that because the first Ramnit botnet has not collaborated with other groups, its source code was never shared to be leaked nor has it ever been a hot topic on the underground market; this second version of the banking trojan must have been developed by the same people who brought the first version to light, given that they are the only ones who ever had access to the source code.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS