Monday, November 18, 2024
HomeBotnetGoogle Disrupt The Glupteba Botnet Controls More Than 1 Million Windows PCs

Google Disrupt The Glupteba Botnet Controls More Than 1 Million Windows PCs

Published on

Google’s Threat Analysis Group (TAG) has discovered and disrupted the Glupteba botnet recently that has infected nearly 1 million Windows PCs all over the world. This malware was detected on Tuesday by the security team of Google.

It is being said that it is the largest malware attack till now, and the experts are pointing that the threat actors must be from Russia. So, that’s why they are investigating the whole matter to know all the key details regarding the attack.

However, this is the ‘botnet’ that is being used by the threat actors and is continuously affecting the devices known as Glupteba, which was also used in mine cryptocurrencies. 

- Advertisement - SIEM as a Service

Google Disrupted The Botnet With a Legal Order

It is being claimed that Google has filed a temporary restraining order and a complaint against two Russian defendants Dmitry Starovikov and Alexander Filippov, and other 15 unknown people in the Southern District of New York.

The complaint states that the motive of the threat actors is to steal user accounts and credit card information. Apart from this, the threat actors also do the following things:-

  • Sell ad placement
  • Proxy access on infected devices
  • Mining for cryptocurrency in the affected computer
  • Trademark infringement
  • Other cyber schemes

C2 Backup Mechanism of Glupteba

This botnet’s command and control (C2) communication usually applies HTTPS to transmit all the given commands and binary updates among the control servers and the infected systems.

Not only this, the threat actors have used a backup mechanism using the Bitcoin Blockchain to add flexibility to their support. Moreover, the infected systems can recover all the backup domains encrypted in the most advanced transaction from the given below bitcoin wallet addresses:-

  • ‘1CgPCp3E9399ZFodMnTSSvaf5TpGiym2N1’
  • ’15y7dskU5TqNHXRtu5wzBpXdY5mT4RZNC6′
  • ‘1CUhaTe3AiP9Tdr4B6wedoe9vNsymLiD97’

The attackers are generally attacking large technology companies like Google and Microsoft. Therefore, with the help of their own online products these companies are continuously fighting against all cybercrime.

Here, the threat actors have utilized the Google services to spread the malicious software. But, Google has claimed that they have done the following things to mitigate such threats, and they are:- 

  • Google removed more than 63 million documents from its Google Docs network
  • Google has canceled nearly 1,100 email accounts that were utilized by attackers to expand the Glupteba network.

Google has worked with the internet infrastructure providers to obstruct the botnet, but the reports declared that it has only temporarily stopped the botnet. 

However, the experts are trying their best to circumvent this unwanted situation, and that’s why Google has notified all its employees to stay alerted from this kind of malware attack.

You can follow us on Linkedin, Twitter, Facebook for daily Cybersecurity, and hacking news updates.

Balaji
Balaji
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Latest articles

Critical TP-Link DHCP Vulnerability Let Attackers Execute Arbitrary Code Remotely

A critical security flaw has been uncovered in certain TP-Link routers, potentially allowing malicious...

Chinese SilkSpecter Hackers Attacking Black Friday Shoppers

SilkSpecter, a Chinese financially motivated threat actor, launched a sophisticated phishing campaign targeting e-commerce...

Cybercriminals Launch SEO Poisoning Attack to Lure Shoppers to Fake Online Stores

The research revealed how threat actors exploit SEO poisoning to redirect unsuspecting users to...

Black Basta Ransomware Leveraging Social Engineering For Malware Deployment

Black Basta, a prominent ransomware group, has rapidly gained notoriety since its emergence in...

Free Webinar

Protect Websites & APIs from Malware Attack

Malware targeting customer-facing websites and API applications poses significant risks, including compliance violations, defacements, and even blacklisting.

Join us for an insightful webinar featuring Vivek Gopalan, VP of Products at Indusface, as he shares effective strategies for safeguarding websites and APIs against malware.

Discussion points

Scan DOM, internal links, and JavaScript libraries for hidden malware.
Detect website defacements in real time.
Protect your brand by monitoring for potential blacklisting.
Prevent malware from infiltrating your server and cloud infrastructure.

More like this

Russia-Linked Hackers Attacking Governmental And Political Organizations

Two pro-Russian threat actors launched a distributed denial-of-service (DDoS) attack campaign against Japanese organizations...

ErrorFather Hackers Attacking & Control Android Device Remotely

The Cerberus Android banking trojan, which gained notoriety in 2019 for its ability to...

GorillaBot Emerged As King For DDoS Attacks With 300,000+ Commands

The newly emerged Gorilla Botnet has exhibited unprecedented activity, launching over 300,000 DDoS attacks...