The Avengers of security teamed up to try and take down the TrickBot botnet null


The backend infrastructure of the TrickBot botnet has been disabled thanks to the work of Microsoft and a coalition of security firms and telecoms.
The software giant’s Defender team worked together with FS-ISAC, ESET, Lumen’s Black Lotus Labs, NTT and Broadcom’s cybersecurity division Symantec to accomplish the feat which took months of preparation.
First spotted in 2016, TrickBot was initially a banking trojan that was a successor to Dyre before it evolved to perform a number of other malicious activities including spreading laterally through a network, stealing saved credentials in browsers, stealing cookies and infecting Linux machines.
The malware is usually delivered via email campaigns that leverage current events or financial lures in order to trick users into opening malicious file attachments or links to websites hosting malicious files. After infecting a system with TrickBot, cybercriminals then used it to install reconnaissance tools such as PowerShell Empire, Metasploit and Cobalt Strike to steal credentials and network configuration information.
Taking down TrickBot
In order to take down the TrickBot botnet, Microsoft, ESET, Symantec and other partners spent months collecting over 125,000 samples of the malware. They then analyzed these samples and extracted and mapped information about how the malware worked including the servers the botnet used to control infected computers.
After collecting this information on TrickBot’s inner workings, Microsoft then went to the US District Court for the Eastern District of Virginia where the company asked a judge to grant it control over the botnet’s servers.
Corporate vice president of customer security and trust at Microsoft, Tom Burt provided further insight on how the company used the court’s ruling to disable TrickBot’s backend infrastructure in a blog post, saying:
“As we observed the infected computers connect to and receive instructions from command and control servers, we were able to identify the precise IP addresses of those servers. With this evidence, the court granted approval for Microsoft and our partners to disable the IP addresses, render the content stored on the command and control servers inaccessible, suspend all services to the botnet operators, and block any effort by the Trickbot operators to purchase or lease additional servers.”
While TrickBot appears to be out of commission for now, the botnet could return as other botnets have managed to survive similar takedown attempts in the past. Only time will tell if Microsoft and its partner’s efforts were successful though even then, another botnet will likely rise up to take TrickBot’s place.
Via ZDNet
The backend infrastructure of the TrickBot botnet has been disabled thanks to the work of Microsoft and a coalition of security firms and telecoms. The software giant’s Defender team worked together with FS-ISAC, ESET, Lumen’s Black Lotus Labs, NTT and Broadcom’s cybersecurity division Symantec to accomplish the feat which took…
Recent Posts
- Adidas plugs its website and app into Amazon’s ‘Buy with Prime’ program
- An iOS update will give iPhone 15 Pro owners Visual Intelligence
- Is that Asus’s first portable heater? No, it’s the new ROG XG eGPU with a 600w RTX 5090 card and (wealthy) creatives will love it
- Nickelodeon’s next Avatar animated series is finally coming together
- Hackers are targeting Signal with new QR code-linked cyberattack
Archives
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- January 2023
- December 2022
- November 2022
- October 2022
- September 2022
- August 2022
- July 2022
- June 2022
- May 2022
- April 2022
- March 2022
- February 2022
- January 2022
- December 2021
- November 2021
- October 2021
- September 2021
- August 2021
- July 2021
- June 2021
- May 2021
- April 2021
- March 2021
- February 2021
- January 2021
- December 2020
- November 2020
- October 2020
- September 2020
- August 2020
- July 2020
- June 2020
- May 2020
- April 2020
- March 2020
- February 2020
- January 2020
- December 2019
- November 2019
- September 2018
- October 2017
- December 2011
- August 2010