Google takes down Glupteba botnet

Share post:

Google’s Threat Analysis Group (TAG) reported that it has interrupted the functioning of Glupteba, a sophisticated botnet. As a resiliency mechanism, the virus infected over one million Windows systems globally and placed its command-and-control server addresses on Bitcoin’s blockchain.

Over the past year, TAG collaborated with the CyberCrime Investigation Group to terminate approximately 63 million Google Docs that were found to have distributed malware. The organization also collaborated with internet infrastructure and hosting companies, such as Cloudflare, to demolish the virus by shutting down servers and putting interstitial warning pages in front of dangerous domains.

Google also filed a case against two Russians, Dmitry Starovikov and Alexander Filippov, who are accused of co-managing the botnet with 15 other unnamed defendants, calling the operation a “modern technological and borderless incarnation of organized crime.”

Glupteba has been observed stealing user passwords and cookies, mining cryptocurrency on compromised hosts, and deploying and operating proxy components targeting Windows computers and IoT devices. The botnet has been seen targeting victims in countries such as the United States, India, Brazil, and Southeast Asia.

The sources for this piece include an article in TheHackerNews.

SUBSCRIBE NOW

Related articles

Cyber Security Today, Week in Review for week ending Friday May 17, 2024

Welcome to Cyber Security Today. This is the Week in Review for the week ending Friday, May 17th,...

Cyber Security Today, May 17, 2024 – Malware hiding in Apache Tomcat servers

Malware hiding in Apache Tomcat servers, new backdoors found, and more Welcome to Cyber Security Today. It's Friday, May...

MIT students exploit blockchain vulnerability to steal 25 million dollars

Two MIT students have been implicated in a highly sophisticated cryptocurrency heist, where they reportedly exploited a vulnerability...

Cyber Security Today, May 15, 2024 – Ebury botnet still exploits Linux servers, Microsoft, SAP and Apple issue security updates

The Ebury botnet continues to exploit Linux servers, Microsoft, SAP and Apple issue security updates, and more. Welcome to...

Become a member

New, Relevant Tech Stories. Our article selection is done by industry professionals. Our writers summarize them to give you the key takeaways