Microsoft and chums use US trademark law to trash Trickbot malware network
- Reference: 1602527409
- News link: https://www.theregister.co.uk/2020/10/12/trickbot_c2_takedown_microsoft/
- Source link:
Coming on the heels of a US government operation to disrupt the botnet late last week, as reported by infosec blogger Brian Krebs, the multinational effort to take down C2 infrastructure is being billed as part of an attempt to protect the American presidential elections taking place on 3 November.
"We disrupted Trickbot through a court order we obtained as well as technical action we executed in partnership with telecommunications providers around the world," [1]blogged MS veep Tom Burt. "We have now cut off key infrastructure so those operating Trickbot will no longer be able to initiate new infections or activate ransomware already dropped into computer systems."
An order granted by the US District Court for Eastern Virginia authorised Microsoft and chums to "disable the IP addresses, render the content stored on the command and control servers inaccessible, suspend all services to the botnet operators, and block any effort by the Trickbot operators to purchase or lease additional servers."
Fighting an online malware network in this way is rather like trying to kill a Hydra by cutting off its heads: you'll slow it down, but it's unlikely to roll over and die.
Slovakian infosec firm ESET was one of Redmond's partners. Jean-Ian Boutin, head of threat research, said: "Over the years we've tracked it, Trickbot compromises have been reported in a steady manner, making it one of the largest and longest-lived botnets out there. Trickbot is one of the most prevalent banking malware families, and this malware strain represents a threat for internet users globally."
Yes, there's lots of COVID-19-themed scuminess around – but otherwise the level of cybercrime is the same [2]READ MORE
Trickbot is malware-as-a-service. Originally a [3]banking trojan known as Dyre , the malware is now capable of being used to infiltrate a target network and drop other malware, such as ransomware. Britain's National Cyber Security Centre has a clear and detailed explanation and plain-language mitigation information [4]here .
Additional firms involved in the counter-Trickbot effort included Lumen's Black Lotus Labs, NTT, Broadcom-owned Symantec, and others.
Companies notable by their absence from the list were ones from Britain, however. Although Microsoft's legal counsel managed to use US trademark law to seize and take down Trickbot's C2 infrastructure on the grounds that the malware occasionally impersonates the Windows operating system, UK criminal law doesn't help British companies take strong action against malware operators.
The Computer Misuse Act 1990 makes it a criminal offence to log into any system without the owner/operator's permission as well as doing any " [5]unauthorised acts " to a computer that create a risk of causing "serious damage". As such, [6]academics and security businesses have called for a reform.
The sloppily worded law was drafted in the late 1980s and has not kept pace with modern technology; there is a theoretical, albeit real, risk that a person or company in the UK deliberately disrupting malware C2 infrastructure could commit a crime in the process no matter how pure their motives.
Krebs, for what it's worth, reckons some of the Trickbot C2 servers remain online in spite of this crackdown and associated PR flurry. ®
Get our [7]Tech Resources
[1] https://blogs.microsoft.com/on-the-issues/2020/10/12/trickbot-ransomware-cyberthreat-us-elections/
[2] https://www.theregister.com/2020/04/22/secureworks_phishing_coronavirus_flat/
[3] https://www.theregister.com/2016/10/18/one_of_the_worlds_worst_trojans_feared_back_and_targeting_aussie_banks/
[4] https://www.ncsc.gov.uk/news/trickbot-advisory#:~:text=Trickbot%20is%20an%20established%20banking,PII%20to%20commit%20identity%20fraud.
[5] https://www.legislation.gov.uk/ukpga/1990/18/section/3ZA
[6] https://www.theregister.com/2020/06/29/computer_misuse_act_reform_cyberup_letter_pm/
[7] https://whitepapers.theregister.com/
"...there is a theoretical, albeit real, risk that a person or company in the UK deliberately disrupting malware C2 infrastructure could commit a crime in the process no matter how pure their motives. "
So?
Call me. I'll do it.
“ Call me. I'll do it.”
Too late I’ve paid them to let me do it.
I've got a better idea...
What if microsoft patches the vulns allowing the Trickbot infections in the first place instead of "fighting the botnet's C2 servers"?
Re: I've got a better idea...
What's that? Disallow end users from running 3rd party software unless downloaded from their Store?
These infections don't propagate like the worms did a couple decades ago.
Our we winning yet?
Attempting to drain the lake, rather than fixing the hole in the boat.
"Although Microsoft's legal counsel managed to use US trademark law to seize and take down Trickbot's C2 infrastructure on the grounds that the malware occasionally impersonates the Windows operating system, UK criminal law doesn't help British companies take strong action against malware operators."
Good. I don't want companies to be able to misuse trademark law. If you want to take down malware networks (and you do), write a law that allows you to do that.
An 'imaginative' use of a law to do something good today, is an imaginative use of the law to do something bad tomorrow.