News: 1649965526

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Microsoft-led move takes down ZLoader botnet domains

(2022/04/14)


Microsoft has announced a months-long effort to take control of 65 domains that the ZLoader criminal botnet gang has been using as command-and-control servers.

The tech giant's Digital Crimes Unit obtained a court order to take down the domains, which are now directed to a Microsoft-controlled sinkhole so they can't communicate with the botnet.

In addition to the 65 hardcoded domains, the court order also allows Microsoft to take control of an additional 319 registered domains that the botnet uses as a backup communication channel. Microsoft said it's working to block future registration of these so-called domain generation algorithm domains.

[1]

The investigation also tied the ZLoader botnet to directly to Denis Malikov, who lives in Simferopol on the Crimean Peninsula, which was annexed by Russia from Ukraine in 2014. According to Microsoft, he is one of the creators of a component that the botnet uses to distribute ransomware.

[2]

[3]

"We chose to name an individual in connection with this case to make clear that cybercriminals will not be allowed to hide behind the anonymity of the internet to commit their crimes," [4]wrote Amy Hogan-Burney, general manager of Microsoft's Digital Crimes Unit.

From banking trojan to ransomware

ZLoader is a variant of the Zeus banking trojan that has been around for at least 15 years. While its earlier use was primarily to steal account login IDs and passwords for financial theft, it has evolved over the years and added new capabilities.

These include defense, like disabling security and anti-virus tools to evade detection, and offensive [5]capabilities such as "capturing screenshots, collecting cookies, stealing credentials and banking data, performing reconnaissance, launching persistence mechanisms, misusing legitimate security tools, and providing remote access to attackers," according to the Microsoft's 365 Defender Threat Intelligence Team.

Microsoft was keen to stress this was a cooperative effort, with security shops ESET, Lumen's threat-intel arm Black Lotus Labs, Palo Alto Networks' Unit 42's team and Avast Threat Labs helping out. It also thanked the Financial Services Information Sharing and Analysis Centers (FS-ISAC) and the Health Information Sharing and Analysis Center (H-ISAC) for "additional data and insights."

[6]

While the newly announced operation will have severely inconvenienced the botnet's operators, based on past experience they'll be back. In October 2020 Microsoft launched a [7]similar operation against the Trickbot network, but it was back up and running within two weeks, the US Cybersecurity and Infrastructure Security Agency [8]warned in an advisory. ZLoader is likely to be revived soon as well, since it has proven very popular so far and there's a lot of money to be made.

[9]Microsoft details how China-linked crew's malware hides scheduled Windows tasks

[10]Stolen-data market RaidForums taken down in domain seizure

[11]Feds take down Kremlin-backed Cyclops Blink botnet

[12]Ryuk ransomware recovery cost us $8.1m and counting, says Baltimore school authority

ZLoader is also sold on underground forums along with other types of commodity malware. "When purchased, affiliates are given all they need to set up their own servers with administration panels and to start building their bots," security firm ESET [13]explained . "Affiliates are then responsible for bot distribution and maintaining their botnets."

More recently, the malware has been linked to ransomware gangs Ryuk, DarkSide and BlackMatter. ZLoader has also moved away from using email as an initial vector and instead turned toward ads on search engines that trick users into visiting malicious websites, the Microsoft Defender team added.

These campaigns look like a legitimate company or product such as Java, TeamViewer, Zoom, and Discord. "For the delivery stage of the attack, the actors would purchase Google Ads for key terms associated with those products, such as 'zoom videoconference,' the threat intel group explained.

Of course, clicking on these phony ads then directs users to a malicious domain, which allows the botnets to infect the device and start using it to communicate with ZLoader servers. ®

Get our [14]Tech Resources



[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YliZkhO4CGrh1qCnMSrg3AAAAAQ&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YliZkhO4CGrh1qCnMSrg3AAAAAQ&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YliZkhO4CGrh1qCnMSrg3AAAAAQ&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[4] https://blogs.microsoft.com/on-the-issues/2022/04/13/zloader-botnet-disrupted-malware-ukraine/

[5] https://www.microsoft.com/security/blog/2022/04/13/dismantling-zloader-how-malicious-ads-led-to-disabled-security-tools-and-ransomware/

[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YliZkhO4CGrh1qCnMSrg3AAAAAQ&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[7] https://www.theregister.com/2020/10/12/trickbot_c2_takedown_microsoft/

[8] https://www.cisa.gov/uscert/ncas/alerts/aa20-302a

[9] https://www.theregister.com/2022/04/14/microsoft-tarrask-malware-in-windows/

[10] https://www.theregister.com/2022/04/12/raidforums_market_arrest/

[11] https://www.theregister.com/2022/04/06/takedown_cyclops_blink/

[12] https://www.theregister.com/2021/06/16/baltimore_ryuk_ransomware_dollars_8_1m_recovery_cost/

[13] https://www.welivesecurity.com/2022/04/13/eset-takes-part-global-operation-disrupt-zloader-botnets/

[14] https://whitepapers.theregister.com/



Whack-a-Mole

HildyJ

Don't know if you Brits have the arcade game Whack-a-Mole. Basically you have a big mallet and you whack the moles as they pop up from random holes. It's cathartic, even though you can never win.

Similarly, killing off botnets, dark web souks, and hackers is also cathartic and you also can never win.

But better to have tried.

History is repeating itself?

Phones Sheridan

And no mention of the [1] clusterfuck that Microsoft made the last time they got a court order to swipe domains and cut off 4 million people.

We were using No-IP as our fail-over load balancing supplier at the time, and Microshaft cut us off for 3 days, all while [2] lying through their teeth that genuine customers were unaffected.

The one thing we took away from it, using Cloud suppliers for any critical service, is an all-eggs-in-one-basket approach.

[1] https://www.theregister.com/2014/07/01/microsoft_takes_over_noip_domains_to_block_malware_marketing/

[2] https://www.theregister.com/2014/07/01/sorry_chaps_microsoft_unborks_legitimate_noip_users_domains/

Give a man a fish, and you feed him for a day.
Teach a man to fish, and he'll invite himself over for dinner.
-- Calvin Keegan