The Andromeda Botnet Takedown

No ratings

Presented at FirstConferenceKualaLumpur 2018 by

On 29 November 2017, a public-private team worked to take down Andromeda aka Gamarue, one of the longest running malware families in existence.This widely distributed malware created a network of infected computers known as the Andromeda botnet, whose main goal was to distribute other malware families. Over its seven year lifespan, Andromeda was associated with 80 malware families and, in the previous six months, it was detected or blocked on an average of over 1 million machines every month. Andromeda was also distributed by the infamous Avalanche network, which was dismantled by the same team in a major operation in 2016.To take down Andromeda required simultaneously seizing servers, suspending domain names across forty different countries, and arresting a suspect, all under conditions of secrecy. Overall, 180,000 domains were sinkholed and a further 640,000 DGA domains blocked. During 48 hours of sinkholing, we observed approximately 2 million unique Andromeda victim IP addresses from almost every country.In this talk I will describe how this unprecedented co-operation took place, and propose a solution to reduce the complexity of future botnet takedowns.