{"id":36010,"date":"2020-10-23T09:23:10","date_gmt":"2020-10-23T08:23:10","guid":{"rendered":"https:\/\/www.intelligentcio.com\/africa\/?p=36010"},"modified":"2020-10-23T09:23:12","modified_gmt":"2020-10-23T08:23:12","slug":"eset-takes-part-in-global-operation-to-disrupt-trickbot","status":"publish","type":"post","link":"https:\/\/www.intelligentcio.com\/africa\/2020\/10\/23\/eset-takes-part-in-global-operation-to-disrupt-trickbot\/","title":{"rendered":"ESET takes part in global operation to disrupt Trickbot"},"content":{"rendered":"\n<p>ESET researchers have participated in a global operation to disrupt the Trickbot botnet, which has since 2016, infected over a million computing devices.<\/p>\n\n\n\n<p>Along with partners Microsoft, Lumen\u2019s Black Lotus Labs Threat Research, NTT and others, the operation impacted Trickbot by tanking their command and control servers.<\/p>\n\n\n\n<p>ESET contributed to the effort with technical analysis, statistical information and known command and control server domain names and IPs. Trickbot is known for stealing credentials from compromised computers and more recently, has been observed mostly as a delivery mechanism for more damaging attacks, such as ransomware.<\/p>\n\n\n\n<p>ESET Research has been tracking its activities since its initial detection in late 2016.<\/p>\n\n\n\n<p>\u201cOver the years we\u2019ve tracked it. Trickbot compromises have been reported in a steady manner, making it one of the largest and longest-lived botnets out there. Trickbot is one of the most prevalent banking malware families and this malware strain represents a threat for Internet users globally,\u201d explained Jean-Ian Boutin, Head, Threat Research at ESET.<\/p>\n\n\n\n<p>&#8220;Throughout its existence, this malware has been distributed in a number of ways. Recently, a chain we observed frequently is Trickbot being dropped on systems already compromised by Emotet, another large botnet. In the past, Trickbot malware was leveraged by its operators mostly as a banking trojan, stealing credentials from online bank accounts and trying to perform fraudulent transfers,&#8221; he said.<\/p>\n\n\n\n<p>Boutin added that: \u201cThrough our monitoring of Trickbot campaigns, we collected tens of thousands of different configuration files, allowing us to know which websites were targeted by Trickbot\u2019s operators. The targeted URLs mostly belong to financial institutions. Trying to disrupt this elusive threat is very challenging as it has various fallback mechanisms, and its interconnection with other highly active cybercriminal actors in the underground makes the overall operation extremely complex.\u201d<\/p>\n","protected":false},"excerpt":{"rendered":"<p>ESET researchers have participated in a global operation to disrupt the Trickbot botnet, which has since 2016, infected over a million computing devices. Along with partners Microsoft, Lumen\u2019s Black Lotus Labs Threat Research, NTT and others, the operation impacted Trickbot by tanking their command and control servers. ESET contributed to the effort with technical analysis, [&hellip;]<\/p>\n","protected":false},"author":18,"featured_media":36011,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[565,5,36,19,13],"tags":[154,13536,176,2327,13535],"class_list":["post-36010","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-banking-finance","category-enterprise-security","category-intelligent-technology","category-regional-news","category-top-stories","tag-eset","tag-eset-research","tag-microsoft","tag-ntt","tag-trickbot"],"acf":[],"publishpress_future_workflow_manual_trigger":{"enabledWorkflows":[]},"_links":{"self":[{"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/posts\/36010","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/users\/18"}],"replies":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/comments?post=36010"}],"version-history":[{"count":1,"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/posts\/36010\/revisions"}],"predecessor-version":[{"id":36012,"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/posts\/36010\/revisions\/36012"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/media\/36011"}],"wp:attachment":[{"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/media?parent=36010"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/categories?post=36010"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/tags?post=36010"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}