• Home
  • Blog
  • Android
  • Cars
  • Gadgets
  • Gaming
  • Internet
  • Mobile
  • Sci-Fi
Tech News, Magazine & Review WordPress Theme 2017
  • Home
  • Blog
  • Android
  • Cars
  • Gadgets
  • Gaming
  • Internet
  • Mobile
  • Sci-Fi
No Result
View All Result
  • Home
  • Blog
  • Android
  • Cars
  • Gadgets
  • Gaming
  • Internet
  • Mobile
  • Sci-Fi
No Result
View All Result
Blog - Creative Collaboration
No Result
View All Result
Home Internet

Trickbot—the for-hire botnet Microsoft attacked—is scrambling to stay alive

October 21, 2020
Share on FacebookShare on Twitter

People outside of Microsoft agreed that the takedown appears to be achieving results. Marcus Hutchins, a researcher who closely follows botnets, said that Trickbot has two classes of servers. Command servers update configurations and send commands, while plugin servers download modular tools used for things like bank fraud, infecting new computers, or sending spam.

Even a single command server can rapidly tell all infected computers where to find new control servers, so the partial takedown of them isn’t much of a body blow, Hutchins said. In fact, in the hours leading up to the publishing of this post, the botnet operators were able to add 13 new command servers.

Also I just looked and they pushed a new server list with 100% working servers.

— MalwareTech (@MalwareTechBlog) October 20, 2020

Where things get more optimistic for the takedown members is that, for some reason, none of the plugin servers are being replaced.

“Without the plugin servers, the bot is just a loader with nothing to load,” Hutchins told me. “Essentially, the botnet is out of action for now. As long as they have working C2s, they could revive it. But as it stands, they have not.”

“I’m not dead yet”

Hutchins said that the victory is by no means complete. For one thing, it’s possible the plugin servers may still be restored. And for another, at the time this post was going live, the Trickbot operators were actively deploying ransomware using what’s called the BazarLoader.

It’s still too early to declare victory. It’s not clear precisely why the plugin servers aren’t being replaced. If the plugin servers return, Trickbot’s normal malicious tricks will likely return.

“It’s definitely not dead,” Hutchins said, “just incapacitated.”

Next Post

Amazon's Alexa can now find you a new book to read

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

No Result
View All Result

Recent Posts

  • I tried Lenovo’s wild modular ThinkBook at MWC, and now my laptop feels outdated
  • Here’s a low-risk way to learn new skills from your couch
  • MWC 2026: Lenovo debuts Legion Go Fold Concept handheld
  • I finally found a notes app that doesn’t make me want to scream
  • Everything Lenovo announced at MWC 2026, including 6 new concepts

Recent Comments

    No Result
    View All Result

    Categories

    • Android
    • Cars
    • Gadgets
    • Gaming
    • Internet
    • Mobile
    • Sci-Fi
    • Home
    • Shop
    • Privacy Policy
    • Terms and Conditions

    © CC Startup, Powered by Creative Collaboration. © 2020 Creative Collaboration, LLC. All Rights Reserved.

    No Result
    View All Result
    • Home
    • Blog
    • Android
    • Cars
    • Gadgets
    • Gaming
    • Internet
    • Mobile
    • Sci-Fi

    © CC Startup, Powered by Creative Collaboration. © 2020 Creative Collaboration, LLC. All Rights Reserved.

    Get more stuff like this
    in your inbox

    Subscribe to our mailing list and get interesting stuff and updates to your email inbox.

    Thank you for subscribing.

    Something went wrong.

    We respect your privacy and take protecting it seriously