HT TECH wants to start sending you push notifications. Click allow to subscribe

Microsoft seeks to defend US election in botnet takedown

Beginning early Monday, Trickbot operators are expected to began losing communication with the millions of computers they had painstakingly infected over a period of months, even years.

By: BLOOMBERG
Updated on: Oct 13 2020, 01:00 IST
Microsoft (REUTERS)

A coalition of technology companies used a federal court order unsealed Monday to begin dismantling one of the world’s most dangerous botnets in an effort to preempt disruptive cyber-attacks before next month’s U.S. presidential election.The takedown is a highly coordinated event, spearheaded by the software giant Microsoft Corp. and involving telecommunications providers in multiple countries. If the operation succeeds, it will disable a global network of infected computers created by a popular malicious software known as Trickbot.

Beginning early Monday, Trickbot operators are expected to began losing communication with the millions of computers they had painstakingly infected over a period of months, even years. The loss of the botnet -- as a network of infected computers is known -- will make it more difficult for Russian-based cybercriminals and other digital marauders to do their work. It will likely take months or years for the criminals to recover, if at all.

You may be interested in

Mobiles Tablets Laptops
7% OFF
Apple iPhone 15 Pro Max
  • Black Titanium
  • 8 GB RAM
  • 256 GB Storage
₹148,900₹159,900
Buy now
28% OFF
Samsung Galaxy S23 Ultra 5G
  • Green
  • 12 GB RAM
  • 256 GB Storage
₹107,999₹149,999
Buy now
Google Pixel 8 Pro
  • Obsidian
  • 12 GB RAM
  • 128 GB Storage
₹106,998
Check details
Apple iPhone 15 Plus
  • Black
  • 6 GB RAM
  • 128 GB Storage
₹87,900
Check details
21% OFF
Acer Swift Go SFG14 41 NX KG3SI 002 Laptop
  • Pure Silver
  • 8 GB RAM
  • 512 GB SSD
₹58,999₹74,999
Buy now
39% OFF
Acer Aspire 5 A515 57G Laptop
  • Gray
  • 16 GB RAM
  • 512 GB SSD
₹54,949₹89,999
Buy now
22% OFF
Acer Aspire 3 A315 24 NX KDESI 004 Laptop
  • Silver
  • 8 GB RAM
  • 512 GB SSD
₹33,499₹42,999
Buy now
40% OFF
Asus VivoBook 15 X515JA BQ322WS Laptop
  • Transparent Silver
  • 8 GB RAM
  • 512 GB SSD
₹31,350₹51,990
Buy now
34% OFF
Xiaomi Pad 6
  • Mist Blue
  • 6 GB RAM
  • 128 GB Storage
₹26,299₹39,999
Buy now
55% OFF
Lenovo Tab M10 5G
  • Abyss Blue
  • 6 GB RAM
  • 128 GB Storage
₹20,999₹47,000
Buy now
21% OFF
Realme Pad 2
  • Imagination Grey
  • 6 GB RAM
  • 128 GB Storage
₹19,749₹24,990
Buy now
Honor Pad X9
  • Gray
  • 4 GB RAM
  • 128 GB Storage
₹14,999
Check details

Also read: Microsoft's Edge inches closer to Google Chrome with these new features in its version 86

Also read: Looking for a smartphone? To check mobile finder click here.

By dramatically dismantling Trickbot’s network, Microsoft and its partners believe they will likely head-off ransomware attacks that could compromise voting systems before the U.S. presidential election on Nov. 3, said Tom Burt, vice president of Microsoft’s customer security and trust division.

“They could tie-up voter registration roles, election night reporting results and generally be extremely disruptive,” Burt said. “Taking out one of the most notorious malware groups, we hope, will reduce the risk of ransomware’s impact on the election this year.”Coordinated takedowns like the one Monday have become increasingly common in the last several years, although the legal and technical hurdles involved are substantial. In this case, Microsoft and its partners were able to obtain a federal court order founded on Trickbot’s infringement of Microsoft’s trademarks, but ultimately aimed at disconnecting communications channels the attackers use to control the malicious software.By presenting evidence to a federal judge -- and by leveraging the requirement that foreign companies comply with U.S. law -- private companies can be as effective as governments at dismantling the global infrastructure of big cybergangs. But in this case, Microsoft and the U.S. government may be treading some of the same ground.

While Microsoft and its partners were preparing for its takedown, U.S. Cyber Command mounted an unrelated operation to temporarily disrupt Trickbot as part of an effort to prevent problems prior to next month’s elections, the Washington Post reported last week. When asked about the government attack, Defense Department spokesman Russell Goemaere said, “As a matter of policy we cannot comment on ongoing operations.”Trickbot malware is known to be used by several criminal groups, including at least two major Eastern European or Russian ransomware gangs. Those criminal hackers specialize in encrypting data on a user’s infected computer, then demanding money to restore access to the legitimate owner.One of the gangs, known as Conti, appears to specialize in targeting American local and state governments, said Brett Callow, a threat analyst at the New Zealand-based cybersecurity company Emsisoft. The other ransomware gang widely identified with Trickbot is called Ryuk. Since January, at least 78 governmental entities have been subjected to ransomware attacks, according to Emsisoft.

The Russian connection to some of those attacks is especially worrying. Since 2016, the Department of Homeland Security, cyber-researchers and Western intelligence have repeatedly warned of further Russian meddling in the 2020 election, especially with the use of ransomware.

Burt said Microsoft’s action amounts to a robust defense of American election infrastructure, which was revealed to be vulnerable after Russian hackers ransacked Democratic Party emails and targeted election systems in all 50 states in 2016.Trickbot has been identified by Europol as a particularly nasty form of malware because of how it’s able to pivot and spread across networks undetected. It typically embeds inside computers and internet-connected devices. After thoroughly mapping a computer network, Trickbot attackers will search for passwords and other stored data in order to steal money from banking and financial services websites.

In some cases, Trickbot’s operators then hand off those infected computers to ransomware groups like Ryuk and Conti, who then encrypt the data until the user pays a hefty ransom.Microsoft and partners analyzed about 61,000 different samples of the Trickbot malware during its investigation this year. Along the way, researchers purposefully infected several of their own computers with the TrickBot malware. “This placed the computers under the control of the cybercriminals operators,” which allowed Microsoft’s researchers to monitor Trickbot’s communications with those infected machines. The research helped identify the various layers of Trickbot’s communications platform, and ultimately helped Microsoft map out the botnet, according to court filings.

Among Microsoft’s partners in the Trickbot takedown is the FS-ISAC, or Financial Services information Sharing and Analysis Center. Its members, including many large banks, have been studying Trickbot, which started out as a banking Trojan, for many years.

To help with Microsoft’s crackdown, the group used a sample of eight members and gathered data on 500 fraud attempts using Trickbot over a year and a half, according to Teresa Walsh, head of intelligence at FS-ISAC. Bad actors tried to steal $7 million during these attempts and succeeded at siphoning off $1 million. The botnet has targeted over 300 banks worldwide and has evolved beyond a banking Trojan, Walsh said.

Written by Kartikay Mehrotra.

Catch all the Latest Tech News, Mobile News, Laptop News, Gaming news, Wearables News , How To News, also keep up with us on ,Twitter, Facebook, , and Instagram. For our latest videos, subscribe to our YouTube channel.

First Published Date: 13 Oct, 01:00 IST

Sale

Mobiles Tablets Laptops
7% OFF
Apple iPhone 15 Pro Max
  • Black Titanium
  • 8 GB RAM
  • 256 GB Storage
₹148,900₹159,900
Buy now
13% OFF
Xiaomi 14
  • Matte Black
  • 12 GB RAM
  • 512 GB Storage
₹69,999₹79,999
Buy now
11% OFF
Apple iPhone 15 Plus
  • Black
  • 6 GB RAM
  • 128 GB Storage
₹79,800₹89,900
Buy now
3% OFF
Samsung Galaxy Z Fold5
  • Icy Blue
  • 12 GB RAM
  • 256 GB Storage
₹154,999₹159,999
Buy now
57% OFF
Lenovo Tab M10 5G
  • Abyss Blue
  • 6 GB RAM
  • 128 GB Storage
₹19,999₹47,000
Buy now
28% OFF
Realme Pad 2
  • Imagination Grey
  • 6 GB RAM
  • 128 GB Storage
₹17,999₹24,999
Buy now
20% OFF
Samsung Galaxy Tab S9 5G 256GB
  • Graphite
  • 8 GB RAM
  • 256 GB Storage
₹86,999₹108,699
Buy now
28% OFF
realme Pad 2 WiFi
  • Imagination Grey
  • 6 GB RAM
  • 128 GB Storage
₹17,999₹24,999
Buy now
23% OFF
Infinix INBook X1 Neo XL22 Laptop Intel Celeron Quad Core 8 GB 256 GB SSD Windows 11
  • Blue
  • 4 GB RAM
  • 128 GB SSD
₹22,990₹29,990
Buy now
36% OFF
Infinix INBook X1 Pro Laptop
  • Black
  • 8 GB RAM
  • 256 GB SSD
₹44,990₹69,999
Buy now
29% OFF
Asus VivoBook 15 X515JA EJ522TS Laptop
  • Grey
  • 8 GB RAM
  • 512 GB SSD
₹44,689₹62,889
Buy now
34% OFF
Asus ROG Strix G17 G713QM K4215TS Laptop
  • Black
  • 16 GB RAM
  • 1 TB SSD
₹180,990₹272,990
Buy now
NEXT ARTICLE BEGINS