Disrupting Cybercrime Operations
Hundreds of domains and servers have been taken over in an international operation to cripple the infrastructure used by cybercriminals to deploy ransomware, commit financial fraud, and attack critical infrastructure. Europol and Microsoft announced the operation, which targeted 'cybercrime as a service' infrastructure belonging to gangs distributing SocGholish, Amadey, and StealC malware.
According to a Europol press release, 326 servers and 142 domains were dismantled by law enforcement, with investigators also finding crypto assets of 'criminal origin' valued at €41 million ($47 million). Additionally, about 27 million stolen login credentials were reclaimed.
Cybercrime as a Service
The operation reflects a new approach to combating cybercrime, targeting the cyberattack supply chain, not just individual services. Microsoft said in a blog post that this action goes after the cybercrime 'assembly line,' where coordinated tools drive ransomware, financial fraud, and disruptions to public services.
Infostealers like StealC have long been a problem, quietly capturing passwords, cookies, and session tokens and playing a primary role in other intrusions. SocGholish and Amadey are typically used as droppers, or malware intended to allow access to networks for other malicious code.
Malware Strains
Microsoft researchers used artificial intelligence to find that Amadey and StealC depend on the same infrastructure. They're often used together because Amadey is primarily a tool for breaking in, while StealC purloins passwords and other sensitive data. Taking down both at once will have an exponential effect, according to the Microsoft blog post.
The other disrupted malware, SocGholish, lets people break into systems by sending phony browser updates using websites that have been compromised. Europol said it found 14,971 infected websites belonging to everyday retailers that were infected by the variant. SocGholish is tied to Evil Corp., a Russian cybercrime gang, which has been linked to several 'large-scale' money laundering and ransomware activities.
Impact of the Operation
'When multiple parts of an operation are disrupted together, attacks are harder to launch, scale, and recover from,' the Microsoft post said. 'The result: fewer disrupted services, fewer opportunities for cybercriminals to profit, and more friction when they try to rebuild.'
The Amadey and StealC malware strains were tied to more than 140,000 infected computers worldwide in the first two weeks of May alone. The operation turned up 18,000 victims' computers. 'Modular, pay-as-you-go models like StealC and Amadey allow threat actors to use a single initial infection to quickly escalate into multiple other threats,' Microsoft said.
Microsoft's Efforts
Microsoft has long worked to fight malware and cybercrime in general, but the scale of the action announced is unusual. The company also posted new research on Amadey and StealC, providing more insights into the threats and how to combat them.
The operation is a significant step forward in the fight against cybercrime, and it demonstrates the importance of collaboration between law enforcement and private companies like Microsoft. By targeting the infrastructure used by cybercriminals, authorities can disrupt their operations and make it harder for them to launch attacks.
- 326 servers taken down
- 142 domains dismantled
- €41 million in crypto assets seized
- 27 million stolen login credentials reclaimed
The operation is a reminder that cybercrime is a complex and evolving threat, and it requires a coordinated effort to combat. By working together, law enforcement and private companies can make a significant impact and help to keep people and organizations safe online.
Source: The Record