iTnews

Google cleans up after Glupteba malware botnet

By Juha Saarinen on Dec 8, 2021 6:37AM
Google cleans up after Glupteba malware botnet

Takes legal action against alleged Russian botnet operators.

Google's Threat Analysis Group (TAG) said it has disrupted the operation of the malicious Glupteba botnet, which infected around a million Windows computers to steal credentials and information, mine cryptocurrency and divert network traffic.

The multi-component Glupteba used to build the botnet is distributed through pay-per-install and traffic distribution system networks, Google said.

Glupteba first appeared on researchers’ malware radar in 2011, and has been actively distributed ever since.

It uses the immutable blockchain distributed database to protect lines of communications between the command and control servers and the botnet these control.

Whenever a command and control server is taken down, Glupteba queries the public blockchain to identify transactions with addresses controlled by the malware operators.

It then decrypts encrypted code contained in the message field of the transaction recorded on the blockchain to get the address of a backup command and control server to replace the one that's been taken down.

This novel use of blockchain is sparking fears that Glupteba cannot be completely eradicated unless its infrastructure using the immutable distributed database is neutralised.

The distribution mechanism for Glupteba included around 63 million Google Docs, 1183 Google accounts, 908 cloud projects and 870 Google Ads, which have now been terminated.

Google TAG was able to capture Glupteba binaries and discovered a Git code repository link in some of them.

This led Google to the Russian individuals that it believes are behind Glupteba, who were selling access to virtual machines with stolen credentials, network proxies and Extracard credit card numbers to be used for serving malicious ads and payment fraud on Google Ads.

Google accused Dimitry Starovikov and Alexander Filippov as being the operators of the botnet and has filed a legal complaint [pdf] against them.

A further 15 unnamed co-defendants are alleged to have joined the two Russian nationals in criminal activities.

Starovikov and Filippov are alleged by Google to have stolen accounts, engaged in credit card and ad fraud, set up network proxies on victims' machines, and engaged in cryptojacking, using the Glupteba malware.

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © iTnews.com.au . All rights reserved.
Tags:
gluptebagooglesecuritytag

Partner Content

Security "mindset shift" needed to protect organisations
Promoted Content Security "mindset shift" needed to protect organisations
Alienated from your own data? You’re not alone
Promoted Content Alienated from your own data? You’re not alone
Top 5 Benefits of Managed IT Services
Promoted Content Top 5 Benefits of Managed IT Services
"We're seeing some good policy put in place, but that's the exception"
Partner Content "We're seeing some good policy put in place, but that's the exception"

Sponsored Whitepapers

Planning before the breach: You can’t protect what you can’t see
Planning before the breach: You can’t protect what you can’t see
Beyond FTP: Securing and Managing File Transfers
Beyond FTP: Securing and Managing File Transfers
NextGen Security Operations: A Roadmap for the Future
NextGen Security Operations: A Roadmap for the Future
Video: Watch Juniper talk about its Aston Martin partnership
Video: Watch Juniper talk about its Aston Martin partnership
Don’t pay the ransom: A three-step guide to ransomware protection
Don’t pay the ransom: A three-step guide to ransomware protection

Events

  • iTnews Benchmark Awards 2022 - Finalist Showcase
  • IoT Impact Conference
  • Cyber Security for Government Summit
By Juha Saarinen
Dec 8 2021
6:37AM
0 Comments

Related Articles

  • Google adds phishing protection to Workspace apps
  • F5 BIG-IP systems vulnerable to remote takeover
  • Google's VirusTotal service vulnerable for over eight months
  • Record number of same-old zero days detected in 2021
Share on Twitter Share on Facebook Share on LinkedIn Share on Whatsapp Email A Friend

Most Read Articles

NBN Co sizes up six-figure customer exodus a year to fixed wireless

NBN Co sizes up six-figure customer exodus a year to fixed wireless

NBN Co to cut 160 applications under $200m IT simplification

NBN Co to cut 160 applications under $200m IT simplification

NBN Co's 250Mbps and gigabit growth is finally clear

NBN Co's 250Mbps and gigabit growth is finally clear

What to expect from the incoming Labor government

What to expect from the incoming Labor government

Digital Nation

COVER STORY: A Year in the Metaverse
COVER STORY: A Year in the Metaverse
CTO Juergen Mueller offers a glimpse into SAP's metaverse play
CTO Juergen Mueller offers a glimpse into SAP's metaverse play
Why do DeFi and DAOs matter to business?
Why do DeFi and DAOs matter to business?
Lendlease launches its own metaverse in Milan
Lendlease launches its own metaverse in Milan
COVER STORY: Data and IoT set digital agriculture on a sustainable future
COVER STORY: Data and IoT set digital agriculture on a sustainable future
All rights reserved. This material may not be published, broadcast, rewritten or redistributed in any form without prior authorisation.
Your use of this website constitutes acceptance of nextmedia's Privacy Policy and Terms & Conditions.