News: 1602527409

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Microsoft and chums use US trademark law to trash Trickbot malware network

(2020/10/12)


Microsoft and other global infosec companies have mounted a joint operation to sabotage command-and-control (C2) infrastructure used by the Trickbot malware.

Coming on the heels of a US government operation to disrupt the botnet late last week, as reported by infosec blogger Brian Krebs, the multinational effort to take down C2 infrastructure is being billed as part of an attempt to protect the American presidential elections taking place on 3 November.

"We disrupted Trickbot through a court order we obtained as well as technical action we executed in partnership with telecommunications providers around the world," [1]blogged MS veep Tom Burt. "We have now cut off key infrastructure so those operating Trickbot will no longer be able to initiate new infections or activate ransomware already dropped into computer systems."

An order granted by the US District Court for Eastern Virginia authorised Microsoft and chums to "disable the IP addresses, render the content stored on the command and control servers inaccessible, suspend all services to the botnet operators, and block any effort by the Trickbot operators to purchase or lease additional servers."

Fighting an online malware network in this way is rather like trying to kill a Hydra by cutting off its heads: you'll slow it down, but it's unlikely to roll over and die.

Slovakian infosec firm ESET was one of Redmond's partners. Jean-Ian Boutin, head of threat research, said: "Over the years we've tracked it, Trickbot compromises have been reported in a steady manner, making it one of the largest and longest-lived botnets out there. Trickbot is one of the most prevalent banking malware families, and this malware strain represents a threat for internet users globally."

Yes, there's lots of COVID-19-themed scuminess around – but otherwise the level of cybercrime is the same [2]READ MORE

Trickbot is malware-as-a-service. Originally a [3]banking trojan known as Dyre , the malware is now capable of being used to infiltrate a target network and drop other malware, such as ransomware. Britain's National Cyber Security Centre has a clear and detailed explanation and plain-language mitigation information [4]here .

Additional firms involved in the counter-Trickbot effort included Lumen's Black Lotus Labs, NTT, Broadcom-owned Symantec, and others.

Companies notable by their absence from the list were ones from Britain, however. Although Microsoft's legal counsel managed to use US trademark law to seize and take down Trickbot's C2 infrastructure on the grounds that the malware occasionally impersonates the Windows operating system, UK criminal law doesn't help British companies take strong action against malware operators.

The Computer Misuse Act 1990 makes it a criminal offence to log into any system without the owner/operator's permission as well as doing any " [5]unauthorised acts " to a computer that create a risk of causing "serious damage". As such, [6]academics and security businesses have called for a reform.

The sloppily worded law was drafted in the late 1980s and has not kept pace with modern technology; there is a theoretical, albeit real, risk that a person or company in the UK deliberately disrupting malware C2 infrastructure could commit a crime in the process no matter how pure their motives.

Krebs, for what it's worth, reckons some of the Trickbot C2 servers remain online in spite of this crackdown and associated PR flurry. ®

Get our [7]Tech Resources



[1] https://blogs.microsoft.com/on-the-issues/2020/10/12/trickbot-ransomware-cyberthreat-us-elections/

[2] https://www.theregister.com/2020/04/22/secureworks_phishing_coronavirus_flat/

[3] https://www.theregister.com/2016/10/18/one_of_the_worlds_worst_trojans_feared_back_and_targeting_aussie_banks/

[4] https://www.ncsc.gov.uk/news/trickbot-advisory#:~:text=Trickbot%20is%20an%20established%20banking,PII%20to%20commit%20identity%20fraud.

[5] https://www.legislation.gov.uk/ukpga/1990/18/section/3ZA

[6] https://www.theregister.com/2020/06/29/computer_misuse_act_reform_cyberup_letter_pm/

[7] https://whitepapers.theregister.com/

DavCrav

"Although Microsoft's legal counsel managed to use US trademark law to seize and take down Trickbot's C2 infrastructure on the grounds that the malware occasionally impersonates the Windows operating system, UK criminal law doesn't help British companies take strong action against malware operators."

Good. I don't want companies to be able to misuse trademark law. If you want to take down malware networks (and you do), write a law that allows you to do that.

An 'imaginative' use of a law to do something good today, is an imaginative use of the law to do something bad tomorrow.

sitta_europea

"...there is a theoretical, albeit real, risk that a person or company in the UK deliberately disrupting malware C2 infrastructure could commit a crime in the process no matter how pure their motives. "

So?

Call me. I'll do it.

Anonymous Coward

“ Call me. I'll do it.”

Too late I’ve paid them to let me do it.

I've got a better idea...

slimshady76

What if microsoft patches the vulns allowing the Trickbot infections in the first place instead of "fighting the botnet's C2 servers"?

Re: I've got a better idea...

Sandtitz

What's that? Disallow end users from running 3rd party software unless downloaded from their Store?

These infections don't propagate like the worms did a couple decades ago.

Our we winning yet?

Jay Lenovo

Attempting to drain the lake, rather than fixing the hole in the boat.

In science it often happens that scientists say, 'You know that's a really
good argument; my position is mistaken,' and then they actually change
their minds and you never hear that old view from them again. They really
do it. It doesn't happen as often as it should, because scientists are
human and change is sometimes painful. But it happens every day. I cannot
recall the last time something like that happened in politics or religion.
-- Carl Sagan, 1987 CSICOP keynote address