{"id":3824,"date":"2024-05-30T15:20:19","date_gmt":"2024-05-30T20:20:19","guid":{"rendered":"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/cops-swarm-global-botnet-cybercrime-infrastructure-in-two-massive-ops"},"modified":"2024-05-30T15:20:19","modified_gmt":"2024-05-30T20:20:19","slug":"cops-swarm-global-cybercrime-botnet-infrastructure-in-2-massive-ops","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/05\/30\/cops-swarm-global-cybercrime-botnet-infrastructure-in-2-massive-ops\/","title":{"rendered":"Cops Swarm Global Cybercrime Botnet Infrastructure in 2 Massive Ops"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/blt06a446211787c344\/6658e857621f5238007e6ca3\/website_seized%281800%29_Jefrey_Blackler_Alamy.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/cops-swarm-global-cybercrime-botnet-infrastructure-in-2-massive-ops.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/cops-swarm-global-cybercrime-botnet-infrastructure-in-2-massive-ops.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Europol and the US Department of Justice are claiming big wins against a large swath of the global cybercrime <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/ics-ot-security\/various-botnets-pummel-tp-link-flaw-iot-attacks\" rel=\"noopener\">botnet infrastructure<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Europol coordinated the international effort to neutralize dropper botnet infrastructure for malware strains including IcedID, SystemBC, Pikabot, Smokeloader, Bumblebee, and <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/in-switch-trickbot-group-now-attacking-ukrainian-targets\" rel=\"noopener\">Trickbot<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, the agency said in a statement. The multinational law enforcement operation, which Europol described as the &#8220;largest ever operation against botnets,&#8221; lasted from May 27 to May 29, and resulted in the takedown of more than 100 servers suspected of being used to distribute ransomware and other malware. The takedown also netted the arrest of four suspects thought to be associated with the botnet.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;The actions focused on disrupting criminal services through arresting High Value Targets, taking down the criminal infrastructures and freezing illegal proceeds,&#8221; <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.europol.europa.eu\/media-press\/newsroom\/news\/largest-ever-operation-against-botnets-hits-dropper-malware-ecosystem\" rel=\"noopener\">Europol&#8217;s statement said<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">. &#8220;This approach had a global impact on the dropper ecosystem.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Within hours, the Department of Justice successfully shut down the &#8220;911 S5&#8221; botnet-for-hire operation and arrested its operator. The botnet is suspected to have quietly infiltrated and hijacked more than 19 million IP addresses to build a botnet used in all sorts of fraud and other unspeakable cybercrimes, according to the DoJ statement.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The 911 S5 botnet includes a &#8220;client interface,&#8221; which is used by cybercriminals to launder money earned by illicit means and illegally send it out of the US, according to the DoJ.&nbsp;In addition, the US estimated that the IP addresses linked to 911 S5 were behind 560,000 scam unemployment insurance claims, racking up losses of more than $5.9 billion. The botnet also helped run up millions in payments from US pandemic relief programs as well as various other scams, the DoJ said.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;Working with our international partners, the FBI conducted a joint, sequenced cyber operation to dismantle the 911 S5 Botnet \u2014 likely the world&#8217;s largest botnet ever,&#8221; FBI Director Christopher Wray said in a <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.justice.gov\/opa\/pr\/911-s5-botnet-dismantled-and-its-administrator-arrested-coordinated-international-operation\" rel=\"noopener\">statement on the botnet operation<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Cybersecurity professionals applaud the coordinated and concerted effort to disrupt the fundamental cybercrime infrastructure, but also acknowledge there&#8217;s still work to be done.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;The recent actions taken against botnets have deep implications for the cybersecurity industry,&#8221; says Chris Morales, CISO for Netenrich. &#8220;These operations disrupt the core infrastructure of cybercrime, targeting networks of compromised devices that are often used for malicious activities, such as DDoS attacks and data theft.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The worst-case scenario that could emerge after these law enforcement crackdowns on botnets is that the group could reconstitute its network with the millions of devices that remain infected, according to Toby Lewis, Darktrace&#8217;s global head of threat analysis.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;Attackers could regain command of a seized domain and swiftly reactivate the compromised devices that have been lying in wait,&#8221; Lewis says. &#8220;Law enforcement must remain vigilant, closely monitoring for any signs of the criminals attempting to establish new command and control servers or resurging botnet activity.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">But that worst-case possibility is unlikely to emerge, considering the arrests of the botnet operations top leadership, says John Bambenek, president at Bambenek Consulting.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;An arrest takes a criminal out of play which, depending on how much of the group was arrested, means those given campaigns aren&#8217;t coming back,&#8221; Bambenek says. &#8220;Eliminating such a large botnet, assuming they did it in a way that uninstalls the malware and secures the machine, means the criminal ecosystem will have to rebuild significant capacity for malware delivery.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Beyond diminished network capacity, Bugcrowd&#8217;s founder and chief strategy officer, Casey Ellis, explains there is a psychological cost being inflicted on the botnet ecosystem in the aftermath of the takedowns.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;The material impact to attackers is that [international law enforcement] just had it laid out to them, very clearly, that there\u2019s a capable, resourced, and persistent threat in play on the defender side,&#8221; Ellis says.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Tom Gorup, vice president of security services at Edigo, is also encouraged by the collaborative work of law enforcement to disable global botnet operations. But he hedges his enthusiasm with a warning that the fight is far from over for the cybersecurity community.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;The fact that law enforcement was not only able to take down the attacker infrastructure, but also incarcerate individuals involved is tremendous,&#8221; Gorup explains. &#8220;Although this take down is certain to have a positive impact on the safety of the Internet, our jobs aren\u2019t finished yet. Unfortunately, there are many more botnets similar to this.&#8221;<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/cops-swarm-global-botnet-cybercrime-infrastructure-in-two-massive-ops\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Europol and the US Department of Justice are claiming big<\/p>\n","protected":false},"author":12,"featured_media":3825,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-3824","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/cops-swarm-global-cybercrime-botnet-infrastructure-in-2-massive-ops.jpg?fit=1820%2C1081&ssl=1",1820,1081,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/cops-swarm-global-cybercrime-botnet-infrastructure-in-2-massive-ops.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/cops-swarm-global-cybercrime-botnet-infrastructure-in-2-massive-ops.jpg?fit=300%2C178&ssl=1",300,178,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/cops-swarm-global-cybercrime-botnet-infrastructure-in-2-massive-ops.jpg?fit=640%2C380&ssl=1",640,380,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/cops-swarm-global-cybercrime-botnet-infrastructure-in-2-massive-ops.jpg?fit=640%2C380&ssl=1",640,380,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/cops-swarm-global-cybercrime-botnet-infrastructure-in-2-massive-ops.jpg?fit=1536%2C912&ssl=1",1536,912,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/cops-swarm-global-cybercrime-botnet-infrastructure-in-2-massive-ops.jpg?fit=1820%2C1081&ssl=1",1820,1081,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/cops-swarm-global-cybercrime-botnet-infrastructure-in-2-massive-ops.jpg?fit=1024%2C608&ssl=1",1024,608,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/cops-swarm-global-cybercrime-botnet-infrastructure-in-2-massive-ops.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/cops-swarm-global-cybercrime-botnet-infrastructure-in-2-massive-ops.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/cops-swarm-global-cybercrime-botnet-infrastructure-in-2-massive-ops.jpg?fit=1820%2C1081&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/3824","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=3824"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/3824\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/3825"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=3824"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=3824"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=3824"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}