French police take down global malware botnet

(Image credit: Shutterstock.com)

French police have revealed they took down a signficiant malware campaign that had infected nearly a million machines.

The force teamed up with security firm Avast to tackle the Retadup worm, which had distributed a malicious cryptocurrency miner that would leave victim devices severely handicapped.

According to the Cybercrime Fighting Centre (C3N) of the French National Gendarmarie, 850,000 unique infections were recorded, mainly affecting Windows devices in Latin America.

Compromised

Avast began monitoring Retadup in March 2019, and, spotting that its operations were running mainly out of France shared its intelligence with the C3N to begin the fightback. 

The agency was able to take control of its command and control (C&C) server and replace it with a disinfection system that would respond to incoming bot requests with a specifically tailored response, causing the connected pieces of malware to self-destruct.

The C3N and Avast also flagged that some of the Retadup servers were located in the US, and called in the help of the FBI to take these down to lessen the botnet even further.

Avast found that Retadup was also in some cases delivering the Stop ransomware and Arkei password stealer to victims’ computers. Avast noted that in an ironic twist, the malware authors had also infected themselves with the Neshta fileinfector, showing that even they should have used antivirus protection.

In addition, 85 percent of the botnet's victims did not have any third-party antivirus protection installed, with the majority of victims using Windows 7, highlighting the importance of keeping systems updated.

TOPICS
Mike Moore
Deputy Editor, TechRadar Pro

Mike Moore is Deputy Editor at TechRadar Pro. He has worked as a B2B and B2C tech journalist for nearly a decade, including at one of the UK's leading national newspapers and fellow Future title ITProPortal, and when he's not keeping track of all the latest enterprise and workplace trends, can most likely be found watching, following or taking part in some kind of sport.

Latest in Security
Data Breach
Thousands of healthcare records exposed online, including private patient information
China
Juniper patches security flaws which could have let hackers take over your router
Representational image depecting cybersecurity protection
GitLab has patched a host of worrying security issues
Ai tech, businessman show virtual graphic Global Internet connect Chatgpt Chat with AI, Artificial Intelligence.
AI agents can be hijacked to write and send phishing attacks
China
Volt Typhoon threat group had access to American utility networks for the best part of a year
Abstract image of cyber security in action.
MassJacker malware targets those looking for pirated software
Latest in News
Brad Pitt looks over his right shoulder with 'F1' written behind him
Apple Original Films will take you behind-the-scenes of a racing cockpit in this new thrilling F1 movie trailer
AI writer
Coding AI tells developer to write it himself
Reacher looking down at another character from the Prime Video TV series Reacher
Reacher season 3 becomes Prime Video’s biggest returning show thanks to Hollywood’s biggest heavyweight
Image showing detail of the Leica D-Lux 8
Still can't get a Fujifilm X100VI? This premium Leica compact costs less, and it's in stock
Man using iMessage on an iPhone
Apple will finally enable encrypted RCS messages between iOS and Android, and it's about time
Google Messages update
Google Messages could soon follow WhatsApp with an upgrade that makes it much easier to join group chats