Antivirus competitors join arms to take down a huge botnet

News
Apr 16, 20152 mins

Microsoft, Trend Micro, and Kaspersky Labs banded together to take down the SIMDA botnet, which is believed to have infected more than 700,000 machines.

A group of antivirus competitors joined together with Interpol to take down a massive botnet of more than 770,000 compromised machines worldwide.

Trend Micro, Microsoft, and Kaspersky Labs teamed up to go after SIMDA, an elaborate botnet in which malware modifies HOSTS files on Windows machines from reputable sites like Facebook, Bing, Yahoo, and Google Analytics, and redirects people to malicious sites. Even after the SIMDA backdoor has been removed, infected HOSTS files can remain.

Trend took the lead on the project and provided information such as the IP addresses of the affiliated servers and statistical information about the malware used. Crooks used the SIMDA malware to remotely access PCs and steal personal information as well as install and spread other malware. Research from Trend Micro found redirection servers located in 14 countries and infections were found in at least 62 countries.

If it wasn’t so criminal, SIMDA could be admirable for its impressive craftsmanship. The underlying backdoor Trojan morphed into a new, undetectable form every few hours, so it stayed ahead of the antivirus updates. It exploited known vulnerabilities in Java, Flash, and Silverlight, and then exploited SQL injection vulnerabilities and used exploit kits.

The takedown of the command and control servers occurred simultaneously worldwide last week and was organized by the Interpol Global Complex for Innovation in Singapore. It included the FBI in the U.S., the Dutch National High Tech Crime Unit, the Police Grand-Ducale Section Nouvelles Technologies in Luxembourg, and the Russian Ministry of the Interior’s Cybercrime Department, “K.”

Trend advises people to manually check HOSTS files and remove suspicious records, which is not something most users can do, so it offers its HouseCall app to do a scan of your PC if you are not a user of its products. In addition, Kaspersky Labs offers a site to check your IP address against a database of known infected computers.

Andy Patrizio is a freelance journalist based in southern California who has covered the computer industry for 20 years and has built every x86 PC he’s ever owned, laptops not included.

Andy writes the Data Center Explorer blog for Network World. His work has appeared in a variety of publications, including Tom's Guide, Wired, Dr. Dobbs Journal, Tech Target, Business Insider, and Data Center Knowledge. Earlier in his career, he held editorial positions at IT publications like InternetNews, PC Week and InformationWeek.

Andy holds a BA in Journalism from the University of Rhode Island.

More from this author