Google Brings Down Infamous Glupteba Botnet

Google's TAG, or the tech giant's Threat Analysis Group, announced that it has disrupted the activity of the infamous Glupteba botnet. Glupteba is a complex malware network that also employs crypto-mining malware in addition to its other capabilities.

According to estimations, at the time of the takedown, the Glupteba botnet spanned roughly one million compromised devices, including both computers running Windows and Internet of things devices.

Glupteba used a multitude of vectors and approaches to spread and infect new devices. Those ranged from fake pirated software containing malicious code to malicious documents, to even fake YouTube video links. Once deployed, the Glupteba malware offers a host of functionality to whatever bad party is operating it, including exfiltration of login credentials and files, as well as crypto mining capabilities. The malware can also set up proxies to enable the rerouting of external traffic, making it pass through infected systems and devices, thus propagating the malware further.

The research team managed to take down essential Glupteba infrastructure after experts dissecting the binaries of Glupteba spotted a git repository URL. This discovery led them down a path that eventually allowed them to identify a number of different online services that were being run by the botnet's operators. Those included services aimed at reselling stolen credentials and selling stolen credit cards to be later used for further malicious purposes, for example - serving malicious advertising.

According to Google's TAG, the security teams were eventually able to disrupt the command and control infrastructure of the botnet to the point where the operators should not be able to run or control the botnet, at least "for now".

To get a sense of the scope of the operation and the sweep it entailed, researchers detailed that the takedown included over 1300 Google accounts, a staggering 800+ Google Ads accounts, and multiple server takedowns, executed jointly with CloudFlare and other providers.

Despite this victory, Google's researchers warned that the bad actors operating the botnet might attempt a quick return, using the data stored in the blockchain.

December 8, 2021
Loading...

Cyclonis Backup Details & Terms

The Free Basic Cyclonis Backup plan gives you 2 GB of cloud storage space with full functionality! No credit card required. Need more storage space? Purchase a larger Cyclonis Backup plan today! To learn more about our policies and pricing, see Terms of Service, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.

Cyclonis Password Manager Details & Terms

FREE Trial: 30-Day One-Time Offer! No credit card required for Free Trial. Full functionality for the length of the Free Trial. (Full functionality after Free Trial requires subscription purchase.) To learn more about our policies and pricing, see EULA, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.