Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.


01:00 PM
Connect Directly

Researchers Disrupt Angler Exploit Kit, Ransomware Operation

Cisco Talos Group estimates Angler is making $60 million per year from ransomware alone.

Cisco Talos Group has disrupted the operations and compromised the infrastructure used by the operators of the popular Angler Exploit Kit, "the most effective exploit kit that Talos has seen." Angler is principally delivering the TeslaCrypt and CryptoWall ransomware, and generating approximately $60 million per year on ransomware alone, researchers estimte. 

Talos, collaborating with OpenDNS and Level 3 Threat Research, investigated Angler's telemetry data and found that a large amount of its activity was being generated within a single provider, Limestone Networks. Working with Limestone Networks, the researchers obtained live disk images of Angler servers to watch the campaign in action.

Through July, they observed activity from one exploit server and one health monitoring server, which performed health checks on host machines and remotely erased log files on hosts. They discovered that Angler operators were extensively using proxy servers to hide their infrastructure from investigators -- the one health monitoring server monitored 147 proxies.

Another way Angler has managed to evade security teams is its use of referers. According to the report, researchers found "more than 15,000 unique sites pushing people into the exploit kit, 99.8% percent of which were used less than ten times, illustrating the low frequency. That means that the majority of referers were only active for a short period of time and were removed after a handful of users were targeted. This is one of the features that makes Angler so difficult to hunt."

One primary actor is responsible for 50 percent of Angler's activity, and making over $30 million per year from ransomware alone, according to researchers, who therefore estimate that Angler overall could be generating $60 million from ransomware.

In response to these findings, Cisco contacted affected hosting providers so they could shut down servers, updated its products to stop redirects to Angler proxies (thereby cutting off Anglers' access to Cisco customers), released Snort rules to detect and block checks from health monitoring servers, and published indicators of compromise.  

Sara Peters is Senior Editor at Dark Reading and formerly the editor-in-chief of Enterprise Efficiency. Prior that she was senior editor for the Computer Security Institute, writing and speaking about virtualization, identity management, cybersecurity law, and a myriad ... View Full Bio

Comment  | 
Print  | 
More Insights
Newest First  |  Oldest First  |  Threaded View
Stop Defending Everything
Kevin Kurzawa, Senior Information Security Auditor,  2/12/2020
Small Business Security: 5 Tips on How and Where to Start
Mike Puglia, Chief Strategy Officer at Kaseya,  2/13/2020
Architectural Analysis IDs 78 Specific Risks in Machine-Learning Systems
Jai Vijayan, Contributing Writer,  2/13/2020
Register for Dark Reading Newsletters
White Papers
Cartoon Contest
Current Issue
6 Emerging Cyber Threats That Enterprises Face in 2020
This Tech Digest gives an in-depth look at six emerging cyber threats that enterprises could face in 2020. Download your copy today!
Flash Poll
How Enterprises Are Developing and Maintaining Secure Applications
How Enterprises Are Developing and Maintaining Secure Applications
The concept of application security is well known, but application security testing and remediation processes remain unbalanced. Most organizations are confident in their approach to AppSec, although others seem to have no approach at all. Read this report to find out more.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
PUBLISHED: 2020-02-17
Iteris Vantage Velocity Field Unit 2.3.1 and 2.4.2 devices have world-writable permissions for the /root/cleardata.pl (executed as root by crond) and /root/loadperl.sh (executed as root at boot time) scripts.
PUBLISHED: 2020-02-17
Iteris Vantage Velocity Field Unit 2.4.2 devices have multiple stored XSS issues in all parameters of the Start Data Viewer feature of the /cgi-bin/loaddata.py script.
PUBLISHED: 2020-02-17
ELTEX NTP-RG-1402G 1v10 devices allow OS command injection via the PING field of the resource ping.cmd. The NTP-2 device is also affected.
PUBLISHED: 2020-02-17
ELTEX NTP-RG-1402G 1v10 devices allow OS command injection via the TRACE field of the resource ping.cmd. The NTP-2 device is also affected.
PUBLISHED: 2020-02-17
Symmetricom SyncServer S100, S200 1.30, S250 1.25, S300 2.65.0, and S350 2.80.1 devices allow stored XSS via the newUserName parameter on the "User Creation, Deletion and Password Maintenance" screen (when creating a new user).