The Europol and security giants dismantled the Ramnit botnet

The Ramnit botnet has been shut down in a joint effort by the Europol and the security firms Symantec, Microsoft, and Anubis Networks.

Another success For the Europol and its allies Microsoft, Symantec, and Anubis Networks. The organizations in a joint effort have shut down command and control servers of the popular Ramnit botnet. The Joint Cybercrime Action Taskforce* (J-CAT) and CERT-EU also provided a significant support to the operations.

“On 24 February, Europol’s European Cybercrime Centre (EC3) coordinated a joint international operation from its operational centre in The Hague, which targeted the Ramnit botnet that had infected 3.2 million computers all around the world.” states the official announcement issued by the Europol.

According to cyber security experts, the Ramnit is one of the world’s biggest botnets, which infected up to 3.2 million machines worldwide.

The group behind Ramnit botnet seems to be active since 2010, but quickly evolved in the time thanks to continuous improvement. A botnet could be used for several fraudulent activities, Ramnit one was mainly used by crooks for financial frauds.

Police enforcement from several European countries, including Germany, Italy, the Netherlands, and the UK, have seized the control infrastructure for the Ramnit botnet.

“Representatives from the various countries, Microsoft, Symantec and AnubisNetworks worked together with Europol officials to shut down command and control servers and to redirect 300 Internet domain addresses used by the botnet’s operators.” reported the Europol.

Europol Deputy Director Operations, Wil van Gemert, has expressed its satisfaction for the operation highlighting the importance of collaboration between several entities to fight the criminal ring operating the Ramnit botnet.

“This successful operation shows the importance of international law enforcement working together with private industry in the fight against the global threat of cybercrime,” said Wil van Gemart.

“We will continue our efforts in taking down botnets and disrupting the core infrastructures used by criminals to conduct a variety of cybercrimes,” 

Symantec published a blog post in which describes the evolution of the Ramnit agent since 2010, The experts revealed that the malicious code and its controllers rapidly evolved over the time.

The latest variant of Ramnit (W32.Ramnit.B) has abandoned the file infection routine and implemented a range of several alternative infection methods.

“Ramnit (W32.Ramnit) began life as worm, first appearing in 2010 and spreading quickly due to aggressive self-propagation tactics. Once it compromised a computer it sought out all EXE, DLL, HTM, and HTML files on the local hard disk and any removable drives and attempted to infect them with copies of itself. ” reported Symantec.

Symantec explained that the Ramnit malware is composed of six standard modules, “Spy module,” “Cookie grabber,” “Driver scanner,” “Anonymous FTP server,”VNC module,” and FTP grabber.

Microsoft and Symantec have released a removal tool for Ramnit, users that fear their computer may have been infected, could download the software. For further information please visit www.getsafeonline.org or www.cyberstreetwise.com.

[adrotate banner=”9″] [adrotate banner=”12″]

Pierluigi Paganini

(Security Affairs – cybercrime, Ramnit botnet)

[adrotate banner=”5″]

[adrotate banner=”13″]

Pierluigi Paganini

Pierluigi Paganini is member of the ENISA (European Union Agency for Network and Information Security) Threat Landscape Stakeholder Group and Cyber G7 Group, he is also a Security Evangelist, Security Analyst and Freelance Writer. Editor-in-Chief at "Cyber Defense Magazine", Pierluigi is a cyber security expert with over 20 years experience in the field, he is Certified Ethical Hacker at EC Council in London. The passion for writing and a strong belief that security is founded on sharing and awareness led Pierluigi to find the security blog "Security Affairs" recently named a Top National Security Resource for US. Pierluigi is a member of the "The Hacker News" team and he is a writer for some major publications in the field such as Cyber War Zone, ICTTF, Infosec Island, Infosec Institute, The Hacker News Magazine and for many other Security magazines. Author of the Books "The Deep Dark Web" and “Digital Virtual Currency and Bitcoin”.

Recent Posts

Nation-state actors exploited two zero-days in ASA and FTD firewalls to breach government networks

Nation-state actor UAT4356 has been exploiting two zero-days in ASA and FTD firewalls since November…

7 hours ago

Hackers hijacked the eScan Antivirus update mechanism in malware campaign

A malware campaign has been exploiting the updating mechanism of the eScan antivirus to distribute…

14 hours ago

US offers a $10 million reward for information on four Iranian nationals

The Treasury Department's Office of Foreign Assets Control (OFAC) sanctioned four Iranian nationals for their…

21 hours ago

The street lights in Leicester City cannot be turned off due to a cyber attack

A cyber attack on Leicester City Council resulted in certain street lights remaining illuminated all…

21 hours ago

North Korea-linked APT groups target South Korean defense contractors

The National Police Agency in South Korea warns that North Korea-linked threat actors are targeting…

1 day ago

U.S. Gov imposed Visa restrictions on 13 individuals linked to commercial spyware activity

The U.S. Department of State imposed visa restrictions on 13 individuals allegedly linked to the…

2 days ago

This website uses cookies.