01:00 PM
Connect Directly

Researchers Disrupt Angler Exploit Kit, Ransomware Operation

Cisco Talos Group estimates Angler is making $60 million per year from ransomware alone.

Cisco Talos Group has disrupted the operations and compromised the infrastructure used by the operators of the popular Angler Exploit Kit, "the most effective exploit kit that Talos has seen." Angler is principally delivering the TeslaCrypt and CryptoWall ransomware, and generating approximately $60 million per year on ransomware alone, researchers estimte. 

Talos, collaborating with OpenDNS and Level 3 Threat Research, investigated Angler's telemetry data and found that a large amount of its activity was being generated within a single provider, Limestone Networks. Working with Limestone Networks, the researchers obtained live disk images of Angler servers to watch the campaign in action.

Through July, they observed activity from one exploit server and one health monitoring server, which performed health checks on host machines and remotely erased log files on hosts. They discovered that Angler operators were extensively using proxy servers to hide their infrastructure from investigators -- the one health monitoring server monitored 147 proxies.

Another way Angler has managed to evade security teams is its use of referers. According to the report, researchers found "more than 15,000 unique sites pushing people into the exploit kit, 99.8% percent of which were used less than ten times, illustrating the low frequency. That means that the majority of referers were only active for a short period of time and were removed after a handful of users were targeted. This is one of the features that makes Angler so difficult to hunt."

One primary actor is responsible for 50 percent of Angler's activity, and making over $30 million per year from ransomware alone, according to researchers, who therefore estimate that Angler overall could be generating $60 million from ransomware.

In response to these findings, Cisco contacted affected hosting providers so they could shut down servers, updated its products to stop redirects to Angler proxies (thereby cutting off Anglers' access to Cisco customers), released Snort rules to detect and block checks from health monitoring servers, and published indicators of compromise.  

Sara Peters is Senior Editor at Dark Reading and formerly the editor-in-chief of Enterprise Efficiency. Prior that she was senior editor for the Computer Security Institute, writing and speaking about virtualization, identity management, cybersecurity law, and a myriad ... View Full Bio

Comment  | 
Print  | 
More Insights
Newest First  |  Oldest First  |  Threaded View
Government Shutdown Brings Certificate Lapse Woes
Curtis Franklin Jr., Senior Editor at Dark Reading,  1/11/2019
Register for Dark Reading Newsletters
White Papers
Cartoon Contest
Current Issue
The Year in Security 2018
This Dark Reading Tech Digest explores the biggest news stories of 2018 that shaped the cybersecurity landscape.
Flash Poll
How Enterprises Are Attacking the Cybersecurity Problem
How Enterprises Are Attacking the Cybersecurity Problem
Data breach fears and the need to comply with regulations such as GDPR are two major drivers increased spending on security products and technologies. But other factors are contributing to the trend as well. Find out more about how enterprises are attacking the cybersecurity problem by reading our report today.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
PUBLISHED: 2019-01-16
An issue was discovered in NTPsec before 1.1.3. Because of a bug in ctl_getitem, there is a stack-based buffer over-read in read_sysvars in ntp_control.c in ntpd.
PUBLISHED: 2019-01-16
An issue was discovered in NTPsec before 1.1.3. process_control() in ntp_control.c has a stack-based buffer over-read because attacker-controlled data is dereferenced by ntohl() in ntpd.
PUBLISHED: 2019-01-16
An issue was discovered in NTPsec before 1.1.3. An authenticated attacker can cause a NULL pointer dereference and ntpd crash in ntp_control.c, related to ctl_getitem.
PUBLISHED: 2019-01-16
An issue was discovered in NumPy 1.16.0 and earlier. It uses the pickle Python module unsafely, which allows remote attackers to execute arbitrary code via a crafted serialized object, as demonstrated by a numpy.load call.
PUBLISHED: 2019-01-16
An issue was discovered in NTPsec before 1.1.3. An authenticated attacker can write one byte out of bounds in ntpd via a malformed config request, related to config_remotely in ntp_config.c, yyparse in, and yyerror in ntp_parser.y.