
Symantec antivirus company specialists who conducted their own observations of the results of measures taken against the third largest traffic of the GRUM world, confirmed: the bot-network no longer guesses signs of life. This was reported by the ITAR-TASS agency.
GRUM was disconnected from the network on July 19 by the joint efforts of the specialists of the California company Fireye, which develops products for information security, the Russian group to respond to Cert-GIB information security incidents and the British organization of Spamhaus.
At the peak of activity through GRUM, in which, according to various sources, there were from 100 to 300 thousand infected computers, about 18 billion garbage messages per day were sent, which approximately corresponded to 18% of the global volume of spam. It was on this value, according to the company that it was reduced after the Fireye specialists managed to disable the control servers of the botte network located in the Netherlands and Panama.
Botnet, recall, is called a network consisting of hosts with "bots" launched on them (reduction from the word "robot") - autonomous software. Most often, the bot in the batch network is a program secretly installed on the victim’s computer and allows the attacker to perform certain actions using the resources of the infected computer. Botnets are used for various kinds of illegal or undesirable activities: spam mailing, passwords for passwords on a remote system, attacks on refusal to maintain (DDOS), etc. Botnets attacks are able to disable not only large Internet resources, but also entire network segments.
There were, however, fears that it was premature to talk about the termination of Botnet’s activity, since the organizers were not established and are free.
For some time, the owners of the defeated botnet did not leave attempts to restore control of infected computers.
Cybercriminals created seven new management and control centers in Russia and Ukraine. Fireye experts suggested that the hackers paid Steephost to the Ukrainian provider to access one of the segments of their network, since the GRUM bots are not able to go to a new command server after the old one was out of order.
At this stage, at the request of Fireye specialists, the operations joined the operation of Cert-GIB, the Russian group to respond to information security incidents created by Group-IB. The efforts of Russian experts managed to close Ukrainian servers.
According to experts from Cert-GIB, the turning off the servers used to control the botte net is a non-trivial task. Attackers rent ready -made subnets and register them for fake companies. It is useless to contact such organizations, as they ignore all requests.
In addition, it is not always possible to quickly establish that the company is a dummy. Therefore, you have to act alternative ways and turn to higher providers to turn off the subnets, which, of course, takes a certain time.