+44 (0)203 88 020 88

Menu

Search

Cyber Security News & Articles

 

Cyber Security
News & Articles

Trusted Cyber Security Experts
25+ Years Industry Experience
Ethical, Professional & Pragmatic

Google tackles Glupteba botnet

The Glupteba botnet targets Windows computers to steal passwords or commit fraud through the infected computer and is thought to include about a million compromised devices. It is growing at a rate of thousands of new systems every day.

According to Google:

Glupteba is notorious for stealing users’ credentials and data, mining cryptocurrencies on infected hosts, and setting up proxies to funnel other people’s internet traffic through infected machines and routers.

The scale of the Glupteba operation is eye opening. In the last year, Google says they have identified and terminated 63 million Google Docs used to distribute the malware and 870 Google Ads accounts used as a malvertising platform to deliver the malware or commit payment fraud on Google Ads.  3 ½ million users were warned before downloading a malicious file through the Safe Browsing warnings supplied by Google.  In addition, Google has started legal proceedings against the individuals they believe are behind the botnet.

However, Google admits that one of Glupteba’s technical innovations will make it hard to completely shut down the botnet.

Usually a botnet searches out Command & Control (C2) servers which are hard coded into the client software or published on a domain or server controlled by the criminals.  This can leave the botnet vulnerable to law enforcement action as they can either seize the C2 servers or block access to them from the internet.

Glupteba’s innovation is the ability to publish the details of new C2 servers in a public and immutable location that cannot be blocked – that is the bitcoin blockchain itself.

The very first bitcoin transaction (held in the Genesis Block) included the short text message “The Times 03/Jan/2009 Chancellor on brink of second bailout for banks”.  As the blockchain grew the ability to store arbitrary text was moved to a scripting operator called OP_RETURN which allows 80 bytes of arbitrary data to be stored in an unspendable transaction that is permanently etched into the block chain.

Glupteba makes use of this feature by watching certain bitcoin wallet addresses and decoding the OP_RETURN code in order to receive the details of a new C2 server.

 

 

 

Subscribe to our monthly newsletter today

If you’d like to stay up-to-date with the latest cyber security news and articles from our technical team, you can sign up to our monthly newsletter. 

We hate spam as much as you do, so we promise not to bombard you with emails. We’ll send you a single, curated email each month that contains all of our cyber security news and articles for that month.

Why Choose SecureTeam?

CREST
CCS
ISO9001
ISO27001
CE-PLUS

Customer Testimonials

“We were very impressed with the service, I will say, the vulnerability found was one our previous organisation had not picked up, which does make you wonder if anything else was missed.”

Aim Ltd Chief Technology Officer (CTO)

"Within a very tight timescale, SecureTeam managed to deliver a highly professional service efficiently. The team helped the process with regular updates and escalation where necessary. Would highly recommend"

IoT Solutions Group Limited Chief Technology Officer (CTO) & Founder

“First class service as ever. We learn something new each year! Thank you to all your team.”

Royal Haskoning DHV Service Delivery Manager

“We’ve worked with SecureTeam for a few years to conduct our testing. The team make it easy to deal with them; they are attentive and explain detailed reports in a jargon-free way that allows the less technical people to understand. I wouldn’t work with anyone else for our cyber security.”

Capital Asset Management Head of Operations

“SecureTeam provided Derbyshire's Education Data Hub with an approachable and professional service to ensure our schools were able to successfully certify for Cyber Essentials. The team provided a smooth end-to-end service and were always on hand to offer advice when necessary.”

Derbyshire County Council Team Manager Education Data Hub

“A very efficient, professional, and friendly delivery of our testing and the results. You delivered exactly what we asked for in the timeframe we needed it, while maintaining quality and integrity. A great job, done well.”

AMX Solutions IT Project Officer

“We were very pleased with the work and report provided. It was easy to translate the provided details into some actionable tasks on our end so that was great. We always appreciate the ongoing support.”

Innovez Ltd Support Officer

Get in touch today

If you’d like to see how SecureTeam can take your cybersecurity posture to the next level, we’d love to hear from you, learn about your requirements and then send you a free quotation for our services.

Our customers love our fast-turnaround, “no-nonsense” quotations – not to mention that we hate high-pressure sales tactics as much as you do.

We know that every organisation is unique, so our detailed scoping process ensures that we provide you with an accurate quotation for our services, which we trust you’ll find highly competitive.

Get in touch with us today and a member of our team will be in touch to provide you with a quotation. 

0

No products in the basket.

No products in the basket.