Google Sues to Shutter Cryptojacking Botnet That Infected 1M+ Computers

The botnet used the Bitcoin blockchain to evade cybersecurity officials and remain online, Google alleged.

AccessTimeIconDec 7, 2021 at 10:27 p.m. UTC
Updated May 11, 2023 at 7:03 p.m. UTC
10 Years of Decentralizing the Future
May 29-31, 2024 - Austin, TexasThe biggest and most established global hub for everything crypto, blockchain and Web3.Register Now

Google on Tuesday moved to shut down a sophisticated cryptojacking botnet that used the Bitcoin blockchain to evade cybersecurity officials.

Known as “Glupteba,” the botnet has infected more than 1 million machines worldwide, Google said in a civil complaint filed Tuesday against Dmitry Staroviko and Alexander Filippov, as well as 15 unknown individuals. Google alleged the defendants utilized this botnet to mine cryptocurrencies on victims’ computers, steal victims’ account information to sell to third parties, purchase goods and services using credit cards with insufficient funds and sell access to compromised machines to third parties.

  • EU Metaverse Policy Should Consider Nondiscrimination, User Safety, Data Privacy: Commission Official
    05:43
    EU Metaverse Policy Should Consider Nondiscrimination, User Safety, Data Privacy: Commission Official
  • Gonzalez vs. Google Supreme Court Case Could Shape Future of the Internet
    05:42
    Gonzalez vs. Google Supreme Court Case Could Shape Future of the Internet
  • Exploring Crypto's Relationship With AI as ChatGPT Interest Grows
    05:34
    Exploring Crypto's Relationship With AI as ChatGPT Interest Grows
  • Google to Launch Cloud-Based Node Engine for Ethereum
    07:32
    Google to Launch Cloud-Based Node Engine for Ethereum
  • Moreover, the botnet itself leveraged blockchain technology in a unique manner as an effort to secure it against traditional tools meant to disrupt these types of malicious activities. It effectively turned Bitcoin’s decentralization into an asset that made it “much harder to shut down,” Google executives wrote in a blog post.

    The botnet weaponized the Bitcoin blockchain, according to Chainalysis, which said it helped Google’s investigation. By embedding command-and-control server addresses in the blockchain and then having the botnet turn to that data whenever an infected server was shuttered, it stays a step ahead of the cybersecurity whack-a-mole.

    “This is the first known case of a botnet using this approach,” representatives for Chainalusis said in an email.

    Google’s complaint went into more detail, saying that the “Glupteba Enterprise,” the entity controlled by the defendants, would use this method to direct the malware to new servers.

    The botnet looked at three specific bitcoin addresses, according to a Google blog post.

    Google said that while it has already taken some action to disrupt the botnet, the fact that it uses the Bitcoin blockchain means the operators can resurrect the network at any time.

    “The Glupteba botnet cannot be eradicated entirely without neutralizing its blockchain-based infrastructure,” the complaint said.

    Google filed fraud and racketeering allegations against the defendants in its suit.

    Disclosure

    Please note that our privacy policy, terms of use, cookies, and do not sell my personal information has been updated.

    CoinDesk is an award-winning media outlet that covers the cryptocurrency industry. Its journalists abide by a strict set of editorial policies. In November 2023, CoinDesk was acquired by the Bullish group, owner of Bullish, a regulated, digital assets exchange. The Bullish group is majority-owned by Block.one; both companies have interests in a variety of blockchain and digital asset businesses and significant holdings of digital assets, including bitcoin. CoinDesk operates as an independent subsidiary with an editorial committee to protect journalistic independence. CoinDesk employees, including journalists, may receive options in the Bullish group as part of their compensation.

    Nikhilesh De

    Nikhilesh De is CoinDesk's managing editor for global policy and regulation. He owns marginal amounts of bitcoin and ether.

    Danny Nelson

    Danny is CoinDesk's Managing Editor for Data & Tokens. He owns BTC, ETH and SOL.


    Learn more about Consensus 2024, CoinDesk's longest-running and most influential event that brings together all sides of crypto, blockchain and Web3. Head to consensus.coindesk.com to register and buy your pass now.