Coordinated action takes down Ramnit botnet infrastructure

Posted by   Virus Bulletin on   Feb 26, 2015

Malware remains present on infected machines; 2012 Virus Bulletin paper worth studying.

A coordinated action from Anubisnetworks, Microsoft and Symantec, together with Europol has done serious damage to the infrastructure behind the 'Ramnit' botnet.

Ramnit is one of those botnets that lurk in the background of the Internet. Its infections mainly occur in countries where the security community tends to have less visibility, with the top three infected countries being India, Indonesia and Vietnam. It is believed to have infected more than 3 million computers in total, and the number of infected machines at the time of the takedown remained fairly high at around 350,000.

Ramnit stole banking credentials, cookies and other kinds of personal information from the machines it infected, while it could also open backdoors and steal FTP credentials. The latter were then used by the malware to propagate further.

While the botnet's current infrastructure has been taken down, the malware remains present on the machines. Time will tell whether the botnet owners will be able to revive it, but for now they have been delivered a significant blow.

In November 2012, Virus Bulletin published an article by Fortinet researcher Chao Chen, who thoroughly analysed Ramnit and all its modules. Given that the infected machines haven't been cleaned up, the article is well worth studying for anyone wanting a full understanding of how the malware operates.

  Ramnit, like many modern pieces of malware, is highly modular. This diagram shows the process used to download modules.

Posted on 26 February 2015 by Martijn Grooten


Latest posts:

VB2017 paper: The life story of an IPT - Inept Persistent Threat actor

At VB2017 in Madrid, Polish security researcher and journalist Adam Haertlé presented a paper about a very inept persistent threat. Today, we publish both the paper and the recording of Adam's presentation.

Five reasons to submit a VB2018 paper this weekend

The call for papers for VB2018 closes on 18 March, and while we've already received many great submissions, we still want more! Here are five reasons why you should submit a paper this weekend.

First partners of VB2018 announced

We are excited to announce the first six companies to partner with VB2018.

VB2018: looking for technical and non-technical talks

We like to pick good, solid technical talks for the VB conference programme, but good talks don't have to be technical and we welcome less technical submissions just as much.

Partner with VB2018 for extra visibility among industry peers

Partnering with the VB conference links your company to a successful and well-established event, demonstrates your commitment to moving the industry forward, allows you to meet potential clients, be visible to industry peers and build lasting…