Popular Posts
-
Rackspace Hosting, Inc. (RAX) Raised to "Hold" at Zacks Investment Research ...
-
Bluehost WordPress Hosting Reviews: Best Low Cost Wordpress Friendly Web Hosting from ThreeHosts.comContact Center Solutions Industry News Sep 12, 2013 (PRWeb.com via COMTEX) -- Threehosts.com compares top blog hosting servi...
-
Large or small, every business needs a website. A company without a Web presence leaves many opportunities on the table, as a well-designe...
-
I want to share something from the first chapter of my upcoming book Front-end Development with ASP.NET Core, Angular, and Bootstrap. Wh...
-
JACKSONVILLE, Fla., June 09, 2016 (GLOBE NEWSWIRE) -- Web.com (NASDAQ:WEB), a leading provider of Internet services and online marketing...
-
Starting a web hosting business is a great way to operate a company that will provide a valuable service to both individuals and fellow ...
-
Web hosting companies in UK rent space on their servers for your website data to be stored on and allow users to access it through the W...
-
Tweet Rackspace Hosting, Inc. (NYSE:RAX) had its price objective decreased by analysts at JMP Securities ...
-
Introduction I am writing this article as a result of my learning for deploying ASP.NET Core web applications on Linux boxes. There is a ...
-
Tweet Rackspace Hosting (NYSE:RAX) shares traded up 4.8% during mid-day trading on Wednesday following insider buying activity, M...
Blog Archive
- December (19)
- November (25)
- October (28)
- September (26)
- August (28)
- July (31)
- June (26)
- May (27)
- April (28)
- March (30)
- February (28)
- January (31)
- December (31)
- November (30)
- October (31)
- September (29)
- August (44)
- July (56)
- June (53)
- May (54)
- April (48)
- March (55)
- February (44)
- January (3)
- December (5)
- November (5)
- October (26)
- September (25)
- August (29)
- July (26)
- June (18)
- September (1)
About Me
Total Pageviews
Krebs on Security
In what's being billed as an unprecedented global law enforcement response to cybercrime, federal investigators in the United States, United Kingdom and Europe today say they've dismantled a sprawling cybercrime machine known as "Avalanche" — a distributed, cloud-hosting network that for the past seven years has been rented out to fraudsters for use in launching countless malware and phishing attacks.
The global distribution of servers used in the Avalanche crime machine. Source: Shadowserver.org
According to Europol, the action was the result of a four-year joint investigation between Europol, Eurojust the FBI and authorities in the U.K. and Germany that culminated on Nov. 30, 2016 with the arrest of five individuals, the seizure of 39 Web servers, and the sidelining of more than 830,000 web domains used in the scheme.
Built as a criminal cloud-hosting environment that was rented out to scammers, spammers other ne'er-do-wells, Avalanche has been a major source of cybercrime for years. In 2009, when investigators say the fraud network first opened for business, Avalanche was responsible for funneling roughly two-thirds of all phishing attacks aimed at stealing usernames and passwords for bank and e-commerce sites. By 2011, Avalanche was being heavily used by crooks to deploy banking Trojans.
The U.K.'s National Crime Agency (NCA), says the more recent Avalanche fraud network comprised up to 600 servers worldwide and was used to host as many as 800,000 web domains at a time.
"Cyber criminals rented the servers and through them launched and managed digital fraud campaigns, sending emails in bulk to infect computers with malware, ransomware and other malicious software that would steal users' bank details and other personal data," the NCA said in a statement released today on the takedown. The criminals used the stolen information for fraud or extortion. At its peak 17 different types of malware were hosted by the network, including major strains with names such as goznym, urlzone, pandabanker and loosemailsniffer.At least 500,000 computers around the world were infected and controlled by the Avalanche system on any given day."
The Avalanche network was especially resilient because it relied on a hosting method known as fast-flux, a kind of round-robin technique that lets botnets hide phishing and malware delivery sites behind an ever-changing network of compromised systems acting as proxies.
"The complex setup of the Avalanche network was popular amongst cybercriminals, because of the double fast flux technique offering enhanced resilience to takedowns and law enforcement action," Europol said in its statement.
It's worth noting here that Avalanche has for many years been heavily favored by crime gangs to deploy Zeus and SpyEye malware variants involved in cleaning out bank accounts for a large number of small to mid-sized businesses. These attacks relied heavily on so-called "money mules," people willingly or unwittingly recruited into helping fraudsters launder stolen funds.
At the time of the takedown, the Avalanche cybercrime infrastructure spanned more than 180 countries, according to The Shadowserver Foundation, a nonprofit group that helped authorities gain control over the Avalanche domains. Read more on Shadowserver's role in this effort here.

The Avalanche crime infrastructure. Image: Europol
Tags: Avalanche, double fast-flux, Eurojust, Europol, fbi, NCA, Shadowserver Foundation, U.K. National Crime Agency
This entry was posted on Thursday, December 1st, 2016 at 1:50 pm and is filed under Other. You can follow any comments to this entry through the RSS 2.0 feed. You can skip to the end and leave a comment. Pinging is currently not allowed.
Source: Krebs on Security
0 comments:
Post a Comment