French Police Dismantle Massive Cryptomining Botnet With Avast's Help

French authorities successfully hijack and neutralize a cryptocurrency mining botnet that infects close to a million computers worldwide. Security researchers exploit a server flaw to dismantle the operation without pushing code directly to victims.

French police successfully neutralize a massive cryptocurrency mining botnet that controls close to a million infected computers worldwide. The notorious Retadup malware hijacks computer processors to mine digital currency and possesses wormable properties that allow it to spread rapidly across networks. Although the operators currently use the malware to generate passive income, they easily could deploy ransomware or spyware through the same infrastructure.

Security firm Avast discovers a critical design flaw in the malware's command and control server that allows for the complete removal of the malware without pushing any code to the affected computers. Because the researchers lack the legal authority to exploit this flaw themselves, they contact French police since most of the malicious infrastructure resides in France. After receiving approval from prosecutors in July, the police secretly obtain a server snapshot from the web host to prepare their counterattack.

The operation requires extreme caution to avoid alerting the malware operators, who might deploy ransomware to hundreds of thousands of computers if they detect the takedown. Using the copied server data, the researchers build a replica that forces the malware to self-destruct instead of causing infections. The police replace the malicious server with this disinfection server, effectively dismantling what they call one of the largest networks of hijacked computers in the world.

Read More at the original source →