{"id":309,"date":"2017-12-04T20:04:07","date_gmt":"2017-12-04T20:04:07","guid":{"rendered":"http:\/\/ielrblog.com\/?p=309"},"modified":"2017-12-04T20:20:05","modified_gmt":"2017-12-04T20:20:05","slug":"international-cyber-operation-dismantles-andromeda-botnet","status":"publish","type":"post","link":"https:\/\/ielrblog.com\/index.php\/2017\/12\/04\/international-cyber-operation-dismantles-andromeda-botnet\/","title":{"rendered":"International Cyber Operation Dismantles Andromeda Botnet"},"content":{"rendered":"<p>On Monday, Europol <a href=\"https:\/\/www.europol.europa.eu\/newsroom\/news\/andromeda-botnet-dismantled-in-international-cyber-operation\">announced<\/a> that, the Federal Bureau of Investigation (FBI), in cooperation with several European government and private sector partners, had dismantled the Andromeda botnet, the longest-running botnet in existence.<\/p>\n<p><em>What is a botnet? <\/em><\/p>\n<p>The term \u201cbotnet\u201d is a portmanteau of the words \u201crobot\u201d and \u201cnetwork.\u201d A botnet is a network of connected computers infected with malware. Botnets allow malicious actors to remotely control a large network of infected computers. Whoever is in control of the botnet can remotely direct the infected computers to send spam emails and viruses, mine Bitcoins, and record sensitive information by downloading keyloggers.<\/p>\n<p>Botnets are also often employed by cybercriminals to launch denial of service (DoS) attacks. DoS attacks result in an interruption in the target\u2019s services, and the owner of the targeted website must often pay the attackers a fee, or comply with some other demand, to regain control of their site.<\/p>\n<p><em>The Andromeda Malware <\/em><\/p>\n<p>According to the Europol press release, the Andromeda malware was detected or blocked on an average of over one million machines each month. Discovered in 2011, this malware is modular and dynamic. It does not have one particular use, but rather, can be modified for many uses through freely-available modules that function as keyloggers, form grabbers, rootkits, etc. The malware is often used to remotely direct computers on the botnet to install additional malicious software. There are many different versions of Andromeda, and they use a variety of infection methods, among them illegal downloads, phishing campaigns, and malicious attachments.<\/p>\n<p><em>Connection to the Avalanche Platform \u00a0<\/em><\/p>\n<p>Andromeda was infamously used in the Avalanche network, an international criminal infrastructure platform that was <a href=\"https:\/\/www.europol.europa.eu\/newsroom\/news\/%E2%80%98avalanche%E2%80%99-network-dismantled-in-international-cyber-operation\">dismantled<\/a> by an international cyber operation in November 2016. Avalanche was used to launch massive malware attacks across the globe, and caused an estimated EUR 6 million in damages to the online banking system in Germany alone. In addition, experts estimate the malware attacks conducted via Avalanche cost hundreds of millions of euros worldwide.<\/p>\n<p>In the end, taking down Avalanche for good demanded close cooperation from the prosecutorial and investigative arms of 30 national governments. The collaborators used a method called sinkholing to ultimately disable the platform. \u00a0<a href=\"https:\/\/www.europol.europa.eu\/publications-documents\/operation-avalanche-infographic\">Sinkholing<\/a> involves redirecting traffic between infected computers to servers controlled by law enforcement authorities or a security company, usually by assuming the domains used by the criminals.<\/p>\n<p>Information obtained during the Avalanche investigation was shared with the appropriate authorities via Europol during the Andromeda case. Andromeda was subject to 48 hours of sinkholing, during which authorities collected approximately 2 million unique victim IP addresses from 233 countries.<\/p>\n<p>Law enforcement authorities have arrested a suspect in Belarus, but have yet to reveal the suspect\u2019s identity.<\/p>\n<script>(function() {\n\twindow.mc4wp = window.mc4wp || {\n\t\tlisteners: [],\n\t\tforms: {\n\t\t\ton: function(evt, cb) {\n\t\t\t\twindow.mc4wp.listeners.push(\n\t\t\t\t\t{\n\t\t\t\t\t\tevent   : evt,\n\t\t\t\t\t\tcallback: cb\n\t\t\t\t\t}\n\t\t\t\t);\n\t\t\t}\n\t\t}\n\t}\n})();\n<\/script><!-- Mailchimp for WordPress v4.12.1 - https:\/\/wordpress.org\/plugins\/mailchimp-for-wp\/ --><form id=\"mc4wp-form-1\" class=\"mc4wp-form mc4wp-form-183\" method=\"post\" data-id=\"183\" data-name=\"Subscribe to our mailing list!\" ><div class=\"mc4wp-form-fields\"><label> Like this post? Sign up for our mailing list: <\/label>\r\n\t<input type=\"email\" name=\"EMAIL\" placeholder=\"Your email address\" required \/>\r\n<\/p>\r\n\r\n<p>\r\n\t<input type=\"submit\" value=\"Sign up\" \/>\r\n<\/p><\/div><label style=\"display: none !important;\">Leave this field empty if you're human: <input type=\"text\" name=\"_mc4wp_honeypot\" value=\"\" tabindex=\"-1\" autocomplete=\"off\" \/><\/label><input type=\"hidden\" name=\"_mc4wp_timestamp\" value=\"1775791557\" \/><input type=\"hidden\" name=\"_mc4wp_form_id\" value=\"183\" \/><input type=\"hidden\" name=\"_mc4wp_form_element_id\" value=\"mc4wp-form-1\" \/><div class=\"mc4wp-response\"><\/div><\/form><!-- \/ Mailchimp for WordPress Plugin -->\n","protected":false},"excerpt":{"rendered":"<p>On Monday, Europol announced that, the Federal Bureau of Investigation (FBI), in cooperation with several European government and private sector partners, had dismantled the Andromeda botnet, the longest-running botnet in existence. What is a botnet? The term \u201cbotnet\u201d is a portmanteau of the words \u201crobot\u201d and \u201cnetwork.\u201d A botnet is a network of connected computers [&hellip;]<\/p>\n","protected":false},"author":3,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_genesis_hide_title":false,"_genesis_hide_breadcrumbs":false,"_genesis_hide_singular_image":false,"_genesis_hide_footer_widgets":false,"_genesis_custom_body_class":"","_genesis_custom_post_class":"","_genesis_layout":"","jetpack_post_was_ever_published":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":false,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2}},"categories":[11],"tags":[],"class_list":{"0":"post-309","1":"post","2":"type-post","3":"status-publish","4":"format-standard","6":"category-transnational-organized-crime-cybercrime-narcotics","7":"entry"},"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.3 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>International Cyber Operation Dismantles Andromeda Botnet | IELR Blog<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/ielrblog.com\/index.php\/2017\/12\/04\/international-cyber-operation-dismantles-andromeda-botnet\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"International Cyber Operation Dismantles Andromeda Botnet | IELR Blog\" \/>\n<meta property=\"og:description\" content=\"On Monday, Europol announced that, the Federal Bureau of Investigation (FBI), in cooperation with several European government and private sector partners, had dismantled the Andromeda botnet, the longest-running botnet in existence. What is a botnet? The term \u201cbotnet\u201d is a portmanteau of the words \u201crobot\u201d and \u201cnetwork.\u201d A botnet is a network of connected computers [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/ielrblog.com\/index.php\/2017\/12\/04\/international-cyber-operation-dismantles-andromeda-botnet\/\" \/>\n<meta property=\"og:site_name\" content=\"IELR Blog\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/m.facebook.com\/intlenforcementlawreporter\/?ref=bookmarks\" \/>\n<meta property=\"article:published_time\" content=\"2017-12-04T20:04:07+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2017-12-04T20:20:05+00:00\" \/>\n<meta name=\"author\" content=\"Zarine Kharazian\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@ielr\" \/>\n<meta name=\"twitter:site\" content=\"@ielr\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Zarine Kharazian\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/ielrblog.com\\\/index.php\\\/2017\\\/12\\\/04\\\/international-cyber-operation-dismantles-andromeda-botnet\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/ielrblog.com\\\/index.php\\\/2017\\\/12\\\/04\\\/international-cyber-operation-dismantles-andromeda-botnet\\\/\"},\"author\":{\"name\":\"Zarine Kharazian\",\"@id\":\"https:\\\/\\\/ielrblog.com\\\/#\\\/schema\\\/person\\\/d97d5908cb441bbcaed11eaad074b544\"},\"headline\":\"International Cyber Operation Dismantles Andromeda Botnet\",\"datePublished\":\"2017-12-04T20:04:07+00:00\",\"dateModified\":\"2017-12-04T20:20:05+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/ielrblog.com\\\/index.php\\\/2017\\\/12\\\/04\\\/international-cyber-operation-dismantles-andromeda-botnet\\\/\"},\"wordCount\":447,\"commentCount\":0,\"articleSection\":[\"Transnat'l Organized Crime, Cybercrime, Narcotics\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/ielrblog.com\\\/index.php\\\/2017\\\/12\\\/04\\\/international-cyber-operation-dismantles-andromeda-botnet\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/ielrblog.com\\\/index.php\\\/2017\\\/12\\\/04\\\/international-cyber-operation-dismantles-andromeda-botnet\\\/\",\"url\":\"https:\\\/\\\/ielrblog.com\\\/index.php\\\/2017\\\/12\\\/04\\\/international-cyber-operation-dismantles-andromeda-botnet\\\/\",\"name\":\"International Cyber Operation Dismantles Andromeda Botnet | IELR Blog\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/ielrblog.com\\\/#website\"},\"datePublished\":\"2017-12-04T20:04:07+00:00\",\"dateModified\":\"2017-12-04T20:20:05+00:00\",\"author\":{\"@id\":\"https:\\\/\\\/ielrblog.com\\\/#\\\/schema\\\/person\\\/d97d5908cb441bbcaed11eaad074b544\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/ielrblog.com\\\/index.php\\\/2017\\\/12\\\/04\\\/international-cyber-operation-dismantles-andromeda-botnet\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/ielrblog.com\\\/index.php\\\/2017\\\/12\\\/04\\\/international-cyber-operation-dismantles-andromeda-botnet\\\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/ielrblog.com\\\/index.php\\\/2017\\\/12\\\/04\\\/international-cyber-operation-dismantles-andromeda-botnet\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/ielrblog.com\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"International Cyber Operation Dismantles Andromeda Botnet\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/ielrblog.com\\\/#website\",\"url\":\"https:\\\/\\\/ielrblog.com\\\/\",\"name\":\"IELR Blog\",\"description\":\"Official Blog of the International Enforcement Law Reporter\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/ielrblog.com\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/ielrblog.com\\\/#\\\/schema\\\/person\\\/d97d5908cb441bbcaed11eaad074b544\",\"name\":\"Zarine Kharazian\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/ed80380bc8641773fc0a6e8c5dbfbcea53b521d2cddf4cd8e38d085691ea0a4d?s=96&d=monsterid&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/ed80380bc8641773fc0a6e8c5dbfbcea53b521d2cddf4cd8e38d085691ea0a4d?s=96&d=monsterid&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/ed80380bc8641773fc0a6e8c5dbfbcea53b521d2cddf4cd8e38d085691ea0a4d?s=96&d=monsterid&r=g\",\"caption\":\"Zarine Kharazian\"},\"url\":\"https:\\\/\\\/ielrblog.com\\\/index.php\\\/author\\\/zarine-kharazian\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"International Cyber Operation Dismantles Andromeda Botnet | IELR Blog","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/ielrblog.com\/index.php\/2017\/12\/04\/international-cyber-operation-dismantles-andromeda-botnet\/","og_locale":"en_US","og_type":"article","og_title":"International Cyber Operation Dismantles Andromeda Botnet | IELR Blog","og_description":"On Monday, Europol announced that, the Federal Bureau of Investigation (FBI), in cooperation with several European government and private sector partners, had dismantled the Andromeda botnet, the longest-running botnet in existence. What is a botnet? The term \u201cbotnet\u201d is a portmanteau of the words \u201crobot\u201d and \u201cnetwork.\u201d A botnet is a network of connected computers [&hellip;]","og_url":"https:\/\/ielrblog.com\/index.php\/2017\/12\/04\/international-cyber-operation-dismantles-andromeda-botnet\/","og_site_name":"IELR Blog","article_publisher":"https:\/\/m.facebook.com\/intlenforcementlawreporter\/?ref=bookmarks","article_published_time":"2017-12-04T20:04:07+00:00","article_modified_time":"2017-12-04T20:20:05+00:00","author":"Zarine Kharazian","twitter_card":"summary_large_image","twitter_creator":"@ielr","twitter_site":"@ielr","twitter_misc":{"Written by":"Zarine Kharazian","Est. reading time":"2 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/ielrblog.com\/index.php\/2017\/12\/04\/international-cyber-operation-dismantles-andromeda-botnet\/#article","isPartOf":{"@id":"https:\/\/ielrblog.com\/index.php\/2017\/12\/04\/international-cyber-operation-dismantles-andromeda-botnet\/"},"author":{"name":"Zarine Kharazian","@id":"https:\/\/ielrblog.com\/#\/schema\/person\/d97d5908cb441bbcaed11eaad074b544"},"headline":"International Cyber Operation Dismantles Andromeda Botnet","datePublished":"2017-12-04T20:04:07+00:00","dateModified":"2017-12-04T20:20:05+00:00","mainEntityOfPage":{"@id":"https:\/\/ielrblog.com\/index.php\/2017\/12\/04\/international-cyber-operation-dismantles-andromeda-botnet\/"},"wordCount":447,"commentCount":0,"articleSection":["Transnat'l Organized Crime, Cybercrime, Narcotics"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/ielrblog.com\/index.php\/2017\/12\/04\/international-cyber-operation-dismantles-andromeda-botnet\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/ielrblog.com\/index.php\/2017\/12\/04\/international-cyber-operation-dismantles-andromeda-botnet\/","url":"https:\/\/ielrblog.com\/index.php\/2017\/12\/04\/international-cyber-operation-dismantles-andromeda-botnet\/","name":"International Cyber Operation Dismantles Andromeda Botnet | IELR Blog","isPartOf":{"@id":"https:\/\/ielrblog.com\/#website"},"datePublished":"2017-12-04T20:04:07+00:00","dateModified":"2017-12-04T20:20:05+00:00","author":{"@id":"https:\/\/ielrblog.com\/#\/schema\/person\/d97d5908cb441bbcaed11eaad074b544"},"breadcrumb":{"@id":"https:\/\/ielrblog.com\/index.php\/2017\/12\/04\/international-cyber-operation-dismantles-andromeda-botnet\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/ielrblog.com\/index.php\/2017\/12\/04\/international-cyber-operation-dismantles-andromeda-botnet\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/ielrblog.com\/index.php\/2017\/12\/04\/international-cyber-operation-dismantles-andromeda-botnet\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/ielrblog.com\/"},{"@type":"ListItem","position":2,"name":"International Cyber Operation Dismantles Andromeda Botnet"}]},{"@type":"WebSite","@id":"https:\/\/ielrblog.com\/#website","url":"https:\/\/ielrblog.com\/","name":"IELR Blog","description":"Official Blog of the International Enforcement Law Reporter","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/ielrblog.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/ielrblog.com\/#\/schema\/person\/d97d5908cb441bbcaed11eaad074b544","name":"Zarine Kharazian","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/ed80380bc8641773fc0a6e8c5dbfbcea53b521d2cddf4cd8e38d085691ea0a4d?s=96&d=monsterid&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/ed80380bc8641773fc0a6e8c5dbfbcea53b521d2cddf4cd8e38d085691ea0a4d?s=96&d=monsterid&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/ed80380bc8641773fc0a6e8c5dbfbcea53b521d2cddf4cd8e38d085691ea0a4d?s=96&d=monsterid&r=g","caption":"Zarine Kharazian"},"url":"https:\/\/ielrblog.com\/index.php\/author\/zarine-kharazian\/"}]}},"jetpack_publicize_connections":[],"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/pas6ng-4Z","jetpack-related-posts":[],"_links":{"self":[{"href":"https:\/\/ielrblog.com\/index.php\/wp-json\/wp\/v2\/posts\/309","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ielrblog.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ielrblog.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ielrblog.com\/index.php\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/ielrblog.com\/index.php\/wp-json\/wp\/v2\/comments?post=309"}],"version-history":[{"count":8,"href":"https:\/\/ielrblog.com\/index.php\/wp-json\/wp\/v2\/posts\/309\/revisions"}],"predecessor-version":[{"id":317,"href":"https:\/\/ielrblog.com\/index.php\/wp-json\/wp\/v2\/posts\/309\/revisions\/317"}],"wp:attachment":[{"href":"https:\/\/ielrblog.com\/index.php\/wp-json\/wp\/v2\/media?parent=309"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ielrblog.com\/index.php\/wp-json\/wp\/v2\/categories?post=309"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ielrblog.com\/index.php\/wp-json\/wp\/v2\/tags?post=309"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}