Showing posts with label criminal network of worldwide computer servers known as Avalanche. Show all posts
Showing posts with label criminal network of worldwide computer servers known as Avalanche. Show all posts

Tuesday, December 6, 2016

FBI: Joint Cyber Operation Takes Down Avalanche Criminal Network


The FBI released the below report:

It was a highly secure infrastructure of servers that allegedly offered cyber criminals an unfettered platform from which to conduct malware campaigns and “money mule” money laundering schemes, targeting victims in the U.S. and around the world.

But the Avalanche network, which was specifically designed to thwart detection by law enforcement, turned out to be not so impenetrable after all. And late last week, the FBI took part in a successful multi-national operation to dismantle Avalanche, alongside our law enforcement partners representing 40 countries and with the cooperation of private sector partners. The investigation involved arrests and searches in four countries, the seizing of servers, and the unprecedented effort to sinkhole more than 800,000 malicious domains associated with the network.

It’s estimated that Avalanche was responsible for as many as 500,000 malware-infected computers worldwide on a daily basis and dollar losses at least in the hundreds of millions as a result of that malware.

“Cyber criminals can victimize millions of users in a moment from anywhere in the world,” according to Scott Smith, assistant director of the FBI’s Cyber Division. “This takedown highlights the importance of collaborating with our international law enforcement partners against this evolution of organized crime in the virtual.”

The investigation into the highly sophisticated Avalanche network, initiated four years ago by German law enforcement authorities and prosecutors, uncovered numerous phishing and spam campaigns that resulted in malware being unwittingly downloaded onto thousands of computers internationally after their users opened bad links in e-mails or downloaded malicious attachments. Once the malware was installed, online banking passwords and other sensitive information were stolen from victims’ computers and redirected through the intricate network of Avalanche servers to back-end servers controlled by the cyber criminals, who wasted no time in using this information to help themselves to other people’s money.

One type of malware distributed by Avalanche was ransomware, which encrypted victims’ computer files until the victim paid a ransom to the criminal perpetrator. Other types of malware stole victims' sensitive banking credentials, which were used to initiate fraudulent wire transfers. And in terms of the money laundering schemes, highly organized networks of money mules purchased goods with the stolen funds, enabling the cyber criminals to launder the illicit proceeds of their malware attacks.

How did these cyber criminals hear about the Avalanche network in the first place? Access to the network was advertised through postings—similar to advertisements—on exclusive underground online criminal forums.

“Cyber criminals can victimize millions of users in a moment from anywhere in the world.”
Scott Smith, assistant director, FBI Cyber Division

Because most cyber schemes cross national borders, an international law enforcement response is absolutely critical to identifying not just the technical infrastructure that facilitate these crimes, but also the administrators who run the networks and the cyber criminals who use these networks to carry out their crimes.

The FBI—with its domestic and international partners—will continue to target the most egregious cyber criminals and syndicates. But U.S. businesses, other organizations, and the general public need to do their part by protecting their computers and networks from malware and other insidious cyber threats. Don’t click on links embedded inside e-mails. Don’t open e-mail attachments without verifying who they’re from. Use strong passwords. Enable your pop-up blocker. Only download software from sites you trust. And make sure your anti-virus software is up to date.

Each of us securing our own devices—coupled with a coordinated law enforcement effort to combat ongoing cyber threats—will go a long way toward protecting all of us in cyberspace. 

Monday, December 5, 2016

Avalanche Network Dismantled In International Cyber Operation


The U.S. Justice Department released the below information:

The Justice Department today announced a multinational operation involving arrests and searches in four countries to dismantle a complex and sophisticated network of computer servers known as “Avalanche.”  The Avalanche network allegedly hosted more than two dozen of the world’s most pernicious types of malicious software and several money laundering campaigns. 
Assistant Attorney General Leslie R. Caldwell of the Justice Department’s Criminal Division, Acting U.S. Attorney Soo C. Song of the Western District of Pennsylvania and Assistant Director Scott S. Smith of the FBI’s Cyber Division made the announcement.
“For years, sophisticated cyber criminals have used our own technology against us—but as their networks have grown more complex and widespread, criminals increasingly rely on an international infrastructure as well,” said Assistant Attorney General Caldwell.  “Avalanche is just one example of a criminal infrastructure dedicated to facilitating privacy invasions and financial crimes on a global scale.  And now a multinational law enforcement coalition has turned the tables on the criminals, by targeting not just individual actors, but the entire Avalanche infrastructure.  Successful operations like this one can disrupt an entire criminal ecosystem in one strike.” 
“The takedown of Avalanche was unprecedented in its scope, scale, reach and cooperation among 40 countries,” said Acting U.S. Attorney Song.  “This is the first time that we have aimed to and achieved the destruction of a criminal cyber infrastructure while disrupting all of the malware systems that relied upon it to do harm.”
“We are committed to halting cybercriminal activity against the United States,” said Assistant Director Smith.  “Cybercriminals can victimize millions of users in a moment from anywhere in the world.  This takedown highlights the importance of collaborating with our international law enforcement partners against this evolution of organized crime in the virtual.”
The Avalanche network offered cybercriminals a secure infrastructure, designed to thwart detection by law enforcement and cyber security experts, over which the criminals conducted malware campaigns as well as money laundering schemes known as “money mule” schemes.  Online banking passwords and other sensitive information stolen from victims’ malware-infected computers was redirected through the intricate network of Avalanche servers and ultimately to backend servers controlled by the cybercriminals.  Access to the Avalanche network was offered to the cybercriminals through postings on exclusive, underground online criminal forums. 
The operation also involved an unprecedented effort to seize, block and sinkhole – meaning, redirect traffic from infected victim computers to servers controlled by law enforcement instead of the servers controlled by cybercriminals – more than 800,000 malicious domains associated with the Avalanche network.  Such domains are needed to funnel information, such as sensitive banking credentials, from the victims’ malware-infected computers, through the layers of Avalanche servers and ultimately back to the cybercriminals.  This was accomplished, in part, through a temporary restraining order obtained by the United States in the Western District of Pennsylvania.      
The types of malware and money mule schemes operating over the Avalanche network varied.  Ransomware such as Nymain, for example, encrypted victims’ computer files until the victim paid a ransom (typically in a form of electronic currency) to the cybercriminal.  Other malware, such as GozNym, was designed to steal victims’ sensitive banking credentials and use those credentials to initiate fraudulent wire transfers.  The money mule schemes operating over Avalanche involved highly organized networks of “mules” who purchased goods with stolen funds, enabling cybercriminals to launder the money they acquired through the malware attacks or other illegal means. 
The Avalanche network, which has been operating since at least 2010, was estimated to serve clients operating as many as 500,000 infected computers worldwide on a daily basis.  The monetary losses associated with malware attacks conducted over the Avalanche network are estimated to be in the hundreds of millions of dollars worldwide, although exact calculations are difficult due to the high number of malware families present on the network.
Several victims of Avalanche-based malware attacks are located in the Western District of Pennsylvania.  A local governmental office was the victim of a Nymain malware attack in which computer files were encrypted until the victims paid a Bitcoin ransom in exchange for decrypting the files.  Two companies, based in New Castle and Carnegie, Pennsylvania, and their respective banks were victims of GozNym malware attacks.  In both attacks, employees received phishing emails containing attachments designed to look like legitimate business invoices.  After clicking on the links, GozNym malware was installed on the victims’ computers.  The malware stole the employees’ banking credentials which were used to initiate unauthorized wire transfers from the victims’ online bank accounts.  
The U.S. Attorney’s Office of the Western District of Pennsylvania, the FBI and the Criminal Division’s Computer Crime and Intellectual Property Section (CCIPS) conducted the operation in close cooperation with the Public Prosecutor’s Office Verden; the Luneburg Police of Germany; Europol; and Eurojust, located in The Hague, Netherlands; and investigators and prosecutors from more than 40 jurisdictions, including India, Singapore, Taiwan and Ukraine.     
Other agencies and organizations partnering in this effort include the Department of Homeland Security’s U.S.-Computer Emergency Readiness Team (US-CERT), the Shadowserver Foundation, Fraunhofer Institute for Communication, Registry of Last Resort, ICANN and domain registries from around the world.  The Criminal Division’s Office of International Affairs also provided significant assistance.  
Assistant U.S. Attorney Charles Eberle of the Western District of Pennsylvania and CCIPS Senior Trial Attorney Richard D. Green are prosecuting the case.  Assistant U.S. Attorney Michael A. Comber of the Western District of Pennsylvania and CCIPS Senior Trial Attorney Green are handling the civil action to disrupt the malware operating over the Avalanche network.  
Individuals who believe that they may have been victims of malware operating over the Avalanche network may use the following webpage created by US-CERT for assistance in removing the malware: www.us-cert.gov/avalanche
Anyone claiming an interest in any of the property seized or actions enjoined pursuant to the court orders described in this release is advised to visit the following website for notice of the full contents of the orders:https://www.justice.gov/opa/documents-and-resources-december-5-2016-announcement-takedown-international- 

Saturday, December 3, 2016

Joint Statement On Dismantling Of International Cyber Criminal Infrastructure Known As Avalanche


The U.S. Justice Department released the below information:

Assistant Attorney General Leslie R. Caldwell of the Justice Department’s Criminal Division, Acting U.S. Attorney Soo C. Song of the Western District of Pennsylvania and Special Agent in Charge of the Federal Bureau of Investigation’s Pittsburgh Division Robert Johnson issued the following statement today:
“November 30 began the start of a multi-national operation to dismantle a complex, criminal network of worldwide computer servers known as Avalanche. This network hosted more than two dozen of the world’s most pernicious types of malware and several money laundering campaigns. 
“The operation is being conducted by the United States Attorney’s Office for the Western District of Pennsylvania, the FBI – Pittsburgh Division, and the Computer Crime and Intellectual Property Section of the United States Department of Justice, in close cooperation with the Public Prosecutor’s Office Verden and the Luneburg Police of Germany, Europol and Eurojust, located in The Hague, Netherlands, and investigators and prosecutors from more than 40 countries. 
“The operation involves an unprecedented and ongoing effort to seize, block and sinkhole more than 800,000 malicious domains associated with the Avalanche network. 
“The operation involves arrests and searches in five countries.  More than 50 Avalanche servers worldwide were taken offline. 
“The Avalanche network, which has been operating since at least 2010, is estimated to involve hundreds of thousands of infected computers worldwide.  The monetary losses associated with malware attacks conducted over the Avalanche network are estimated to be in the hundreds of millions of dollars worldwide, although exact calculations are difficult due to the high number of malware families present on the network.
“Additional information on the dismantling of Avalanche and several Western Pennsylvania victims of Avalanche-based malware attacks will be provided early next week.”