Alert (TA16-336A)

Avalanche (crimeware-as-a-service infrastructure)

 
 
Systems Affected:
 
Microsoft Windows
 
Be AWARE:
 

“Avalanche” refers to a large global network hosting infrastructure used by cyber criminals to conduct phishing and malware distribution campaigns and money mule schemes. The United States Department of Homeland Security (DHS), in collaboration with the Federal Bureau of Investigation (FBI), is releasing this Technical Alert to provide further information about Avalanche.

 

Cyber criminals utilized Avalanche botnet infrastructure to host and distribute a variety of malware variants to victims, including the targeting of over 40 major financial institutions. Victims may have had their sensitive personal information stolen (e.g., user account credentials). Victims’ compromised systems may also have been used to conduct other malicious activity, such as launching denial-of-service (DoS) attacks or distributing malware variants to other victims’ computers. In addition, Avalanche infrastructure was used to run money mule schemes where criminals recruited people to commit fraud involving transporting and laundering stolen money or merchandise. Avalanche used fast-flux DNS, a technique to hide the criminal servers, behind a constantly changing network of compromised systems acting as proxies.

 

 

 

Impact:

 

A system infected with Avalanche-associated malware may be subject to malicious activity including the theft of user credentials and other sensitive data, such as banking and credit card information. Some of the malware had the capability to encrypt user files and demand a ransom be paid by the victim to regain access to those files. In addition, the malware may have allowed criminals unauthorized remote access to the infected computer. Infected systems could have been used to conduct distributed denial-of-service (DDoS) attacks.

 

Solution:

 

Users are advised to take the following actions to remediate malware infections associated with Avalanche:

  • Use and maintain anti-virus software – Anti-virus software recognizes and protects your computer against most known viruses. Even though parts of Avalanche are designed to evade detection, security companies are continuously updating their software to counter these advanced threats. Therefore, it is important to keep your anti-virus software up-to-date. If you suspect you may be a victim of an Avalanche malware, update your anti-virus software definitions and run a full-system scan. (call your managed IT Service provider.)

  • Avoid clicking links in email – Attackers have become very skilled at making phishing emails look legitimate. Users should ensure the link is legitimate by typing the link into a new browser.

  • Change your passwords – Your original passwords may have been compromised during the infection, so you should change them.

  • Keep your operating system and application software up-to-date – Install software patches so that attackers cannot take advantage of known problems or vulnerabilities. You should enable automatic updates of the operating system if this option is available. (call your managed IT Service provider for more information.)

  • Use anti-malware tools – Using a legitimate program that identifies and removes malware can help eliminate an infection. Users should consider employing a trusted Managed IT Service Provider.

 

For more information please call Miller Technologies at 503-474-4724

https://www.us-cert.gov/ncas/alerts/TA16-336A 

 

Please reload

Featured Posts

Lessons Learned

May 6, 2020

1/10
Please reload

Recent Posts

May 6, 2020

Please reload

Archive