Ramnit, one of the world’s biggest botnets, ended up disabled by British, Dutch, German and Italian police.

Ramnit malware, which sought to steal victims’ banking login data, infected as many as 3.2 million Windows PCs and is sitting on over 350,000 compromised computers, officials said.

RELATED STORIES
Malware Couples with Backdoor Trojan
Botnets Continue their Rise
IBM Patches Mobile Offering
New Trojan for iOS

Anubis Networks, Microsoft and Symantec provided information to the law enforcement agencies, who worked together via the European Cybercrime Centre (EC3) working out of Europol.

Investigators were able to shut down the command and control servers for the malware so infected users should be safe from Ramnit.

Schneider Bold

Ramnit malware spread via malicious emails and messages sent over social networks. It would steal passwords for online banking sites, spy on people’s web activity, pilfer files and block anti-virus protection. Symantec said the group behind Ramnit has been operating for at least five years and “has evolved into a major criminal enterprise.” Most victims were in India, Indonesia and Vietnam.

“Through this operation, we are disrupting a cyber crime threat which has left to thousands of ordinary computer users in the UK at risk of having their privacy and personal information compromised,” said Steve Pye from the UK National Crime Agency’s National Cyber Crime Unit.

“This malware effectively gives criminals a back door so they can take control of your computer, access your images, passwords or personal data and even use it to circulate further spam messages or launch illegal attacks on other websites.

“As a result of this action, the UK is safer from Ramnit, but it is important that individuals take action now to disinfect their machines, and protect their personal information.”

Investigators will now look at the seized servers and perform some forensics in an effort to determine who their operators are. Without any arrests, the gang behind the malware will continue to operate and will likely set up fresh infrastructure to continue stealing people’s bank logins.

ISSSource

Pin It on Pinterest

Share This