Microsoft has been attacking a major malware botnet and is winning

(Image credit: Pixabay)

As part of a coordinated effort that began around a week and a half ago, Microsoft and its partners have almost completely disabled an elusive botnet that has infected over a million computing devices since late 2016.

Called Trickbot, it is run by criminals and has been used to conduct a "wide range of nefarious activity," including the spread of ransomware, a type of malware that effectively prevents a victim from accessing their files by encrypting their data. The only way to unlock the files is with a decryption key. Typically what happens is the malware author demands a ransom, oftentimes in Bitcoin, in exchange for unlocking a victim's files. In some cases, there is a time limit to pay up, or else the data is permanently deleted.

"Adversaries can use ransomware to infect a computer system used to maintain voter rolls or report on election-night results, seizing those systems at a prescribed hour optimized to sow chaos and distrust," Microsoft explained earlier this week.

Microsoft obtained a court order to coordinate its efforts with telecommunication providers around the globe. According to Microsoft, Trickbot is particularly dangerous because its modular makeup allows it to constantly evolve, making detection and removal more difficult than static malware.

In the past four years, Trickbot has infected computers and IoT devices, including wireless routers. In addition to doling out ransomware, which in once instance crippled the IT network of a hospital in Germany, Trickbot has been used to hijack web browsers to swipe login information for banking sites, and conduct spam and spear phishing campaigns.

Microsoft said it initially discovered 69 servers that were core to Trickbot's various operation. In a short span, it has knocked 62 of them offline.

Perfect peripherals

(Image credit: Colorwave)

Best gaming mouse: the top rodents for gaming
Best gaming keyboard: your PC's best friend...
Best gaming headset: don't ignore in-game audio

"The seven remaining servers are not traditional command-and-control servers but rather internet of things (IoT) devices Trickbot infected and was using as part of its server infrastructure; these are in the process of being disabled. As expected, the criminals operating Trickbot scrambled to replace the infrastructure we initially disabled," Microsoft states in a new blog post.

Through ongoing tracking, Microsoft discovered 59 additional servers that Trickbot's operators attempted to add into the mix, and subsequently disabled 58 of them. So in total, Microsoft has killed 120 of the 128 Trickbot servers it has discovered.

This is an ongoing offensive, and Microsoft says the numbers will inevitably change. "This is challenging work, and there is not always a straight line to success," the company says. However, it has made a huge dent in Trickbot's operations and is optimistic it will stay ahead of things.

Paul Lilly

Paul has been playing PC games and raking his knuckles on computer hardware since the Commodore 64. He does not have any tattoos, but thinks it would be cool to get one that reads LOAD"*",8,1. In his off time, he rides motorcycles and wrestles alligators (only one of those is true).

Latest in Hardware
Crucial X9 external SSD on blue background
You can pick up the 2 TB version of my favorite budget external SSD for less than $0.06 per GB, transfers 300+ GB of data in 6 minutes
AMD Strix Point APU chip, held in a hand, with the reflected light showing the various processing blocks in the chip die
AMD's next-gen 'Gorgon Point' APU outted and seemingly sticks with RDNA 3.5 graphics which is disappointing for handheld gaming PCs if accurate
The Lenovo Legion LOQ gaming laptop on a blue background
Okay, so it's not technically in the Amazon Big Spring Sale, but this is the cheapest RTX 4070 gaming laptop you'll find today
A close-up photo of an Nvidia RTX 4070, with its heatsink removed, showing the AD104 GPU die and the surrounding Micron GDDR6X VRAM chips
With Nvidia Ace taking up 1 GB of VRAM in Inzoi, Team Green will need to up its memory game if AI NPCs take off in PC gaming
A collage of Radeon RX 9000 series graphics cards, as shown in AMD's promotional video for the launch of RDNA 4 at CES 2025
AMD's CEO claims 9070 XT sales are 10x higher than all previous Radeon generations but that's just for the first week of availability
Samsung 3D monitor
Samsung has a crack at ye olde glasses-free 3D monitor thing but its new cheaper 49-inch ultrawide OLED is far more interesting
Latest in News
Dwarf Fortress adventure mode art
After 23 years of making Dwarf Fortress, even its creator is still 'terrified' of drowning all his dwarves with heavy aquifers: 'Part of the problem is we are just not good at videogames'
A unique aspect of Japanese architecture turned out to be a key reason the Like a Dragon games can reuse assets so effectively—and deliver more compact, memorable open worlds than western cities
Pacific Drive Endless Expeditions spring 2025 update trailer still - a sexy, tricked-out 1980s station wagon being blasted with magic healing electricity
Pacific Drive developers change their mind: A year after refusing to give it mid-run saves, it's getting mid-run saves
Starfield's companion robot giving a thumbs-up
Former Bethesda dev who quit Starfield to go solo says it's 'much less stressful as an indie' without daily meetings or 'office politics': it's 'very refreshing to just care about the game'
Schedule I drug deal going down
Forget REPO, Monster Hunter Wilds and Assassin's Creed Shadows, Steam's current global top seller is an early access game about managing a drug empire
Kingdom Come: Deliverance 2 characters with their bodies replaced by skeletons, thanks to the KCD2 Skeleton mod.
Here's that Kingdom Come: Deliverance 2 mod that turns everyone into skeletons you asked for