{"id":29991,"date":"2020-10-12T20:28:57","date_gmt":"2020-10-12T17:28:57","guid":{"rendered":"https:\/\/forklog.com\/en\/?p=29991"},"modified":"2025-08-27T20:01:25","modified_gmt":"2025-08-27T17:01:25","slug":"cybersecurity-specialists-launch-hunt-for-trickbot-botnet-which-could-threaten-us-elections","status":"publish","type":"post","link":"https:\/\/forklog.com\/en\/cybersecurity-specialists-launch-hunt-for-trickbot-botnet-which-could-threaten-us-elections\/","title":{"rendered":"Cybersecurity specialists launch hunt for Trickbot botnet, which could threaten US elections"},"content":{"rendered":"<p><span style=\\\"font-weight: 400;\\\">An international group of specialists carried out an operation to neutralize the Trickbot botnet, which has infected more than a million computers since 2016.<\/span><!--more--><\/p>\n<p><span style=\\\"font-weight: 400;\\\">KrebsonSecurity was the first to report attempts to neutralize the botnet. However, at the time, the identity of those behind it was not known.<\/span><\/p>\n<p><span style=\\\"font-weight: 400;\\\">According to the Washington Post, the operation to dismantle the botnet involved the U.S. military. In their view, Trickbot is controlled by \u201cRussian-speaking criminals\u201d and could potentially threaten the US elections.<\/span><\/p>\n<p><span style=\\\"font-weight: 400;\\\">The campaign to neutralize the botnet does not entail its full shutdown, but aims to exert a sustained impact on the adversary, the publication cites anonymous sources.<\/span><\/p>\n<p><span style=\\\"font-weight: 400;\\\">Later, Microsoft published a <a href=\\\"https:\/\/blogs.microsoft.com\/on-the-issues\/2020\/10\/12\/trickbot-ransomware-cyberthreat-us-elections\/\\\" target=\\\"_blank\\\" rel=\\\"noopener noreferrer\\\">statement<\/a> about conducting the operation to disrupt Trickbot in cooperation with an international group of partners.<\/span><\/p>\n<p><span style=\\\"font-weight: 400;\\\">In addition to Microsoft&#8217;s Digital Crimes Unit, the group includes ESET, NTT, Black Lotus Labs and others.<\/span><\/p>\n<blockquote>\n<p><span style=\\\"font-weight: 400;\\\">\u201cWe have disabled key infrastructure so that Trickbot operators could not initiate new infections or activate ransomware programs already loaded on computer systems,\u201d says Microsoft.<\/span><\/p>\n<\/blockquote>\n<p><span style=\\\"font-weight: 400;\\\">Jean\u2011Yan Boutin, head of ESET&#8217;s Threat Research, stressed that Trickbot is one of the largest and longest-running botnets:<\/span><\/p>\n<blockquote>\n<p><span style=\\\"font-weight: 400;\\\">\u201cThis is one of the most widespread families of banking malware threatening internet users worldwide. The banking Trojan steals credentials from online accounts and attempts to execute fraudulent transfers.\u201d<\/span><\/p>\n<\/blockquote>\n<p><span style=\\\"font-weight: 400;\\\">ForkLog, citing ESET representatives, said that recently researchers observed a string of Trickbot attacks on systems already compromised by another major botnet\u2014Emotet.<\/span><\/p>\n<p><span style=\\\"font-weight: 400;\\\">In a conversation with Bleeping Computer, Boutin noted that during the operation cybersecurity specialists had contacted law enforcement, but he was unaware of any link to the U.S. military campaign against Trickbot.<\/span><\/p>\n<p><span style=\\\"font-weight: 400;\\\">In a Black Lotus Labs post, it is stated that the efforts will hinder hackers and raise the costs of restoring part of the damaged infrastructure. They note that this may not fully eliminate the threat.<\/span><\/p>\n<p><span style=\\\"font-weight: 400;\\\">Originally known as the banking Trojan Trickbot, it later came to be used not only to steal personal data and credentials but also to spread Ryuk ransomware.<\/span><\/p>\n<p>Subscribe to ForkLog news on Telegram: <a href=\\\"https:\/\/t.me\/forklogfeed\\\" target=\\\"_blank\\\" rel=\\\"nofollow noopener noreferrer\\\">ForkLog Feed<\/a> \u2014 the full news feed, <a href=\\\"https:\/\/telegram.me\/forklog\\\" target=\\\"_blank\\\" rel=\\\"nofollow noopener noreferrer\\\">ForkLog<\/a> \u2014 the most important news and polls.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>An international group of specialists carried out an operation to neutralize the Trickbot botnet, which has infected more than a million computers since 2016.<\/p>\n","protected":false},"author":1,"featured_media":29992,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"select":"1","news_style_id":"","cryptorium_level":"","_short_excerpt_text":"","creation_source":"","_metatest_mainpost_news_update":false,"footnotes":""},"categories":[3],"tags":[1573,1916,15,1630,26],"class_list":["post-29991","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news-and-analysis","tag-botnet","tag-eset","tag-microsoft","tag-trickbot","tag-usa"],"aioseo_notices":[],"amp_enabled":true,"views":"19","promo_type":"1","layout_type":"","short_excerpt":"","is_update":"","_links":{"self":[{"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/posts\/29991","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/comments?post=29991"}],"version-history":[{"count":1,"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/posts\/29991\/revisions"}],"predecessor-version":[{"id":29993,"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/posts\/29991\/revisions\/29993"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/media\/29992"}],"wp:attachment":[{"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/media?parent=29991"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/categories?post=29991"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/tags?post=29991"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}