Categories: NewsSecurity

Malware Hunter Search Engine Sniffs out Malware Command-and-control Servers

It looks like security researchers have reached an important milestone in the ongoing war against malware. A new search engine has been revealed which can be used to sniff out malware command-and-control servers around the world. Under the Malware Hunter banner – not to be confused with the Malware Hunter software – this search engine looks to bring malware distribution to a halt in the near future.

Malware Hunter Is A Powerful Tool

It is not hard to see why security researchers around the globe are quite excited about the Malware Hunter search engine. Having a viable solution to discover command-and-control servers will provide to be useful when it comes to thwarting malware and ransomware attacks in the future. The tool is created by Shodan and Recorded Future, who are trying to become an industry leader in the fight against global cybercrime.

The way malware Hunter works is as follows: it uses search bots crawling the Internet for computers configured to act as a command-and-control server. It remains unclear if this will yield a lot of positive results, though, as C&C servers may very well reside on the darknet for all we know. Moreover, not every server will easily give up its location either, which could prove to be quite problematic.

The Malware Hunter search engine comes with a feature that will trick these servers into giving up their location, though. To be more specific, the search engine will pretend to be an infected computer reporting back to the server in question. Assuming the server will acknowledge the request and respond, the search engine will log its IP and update the Shodan interface in real time. This provides researchers with invaluable information when it comes to locating these servers and shutting them down as quickly as possible.

Related Post

What makes the search engine so powerful is how it is capable of probing virtually every IP address on the Internet today. This means the algorithm is constantly looking for new computers that may act as a malware command-and-control server. Quite an intriguing development, as it should reduce the amount of time during which malware remains a problem.

In most cases, once the C&C server is shut down, the malware will no longer cause harm. Then again, some newer types of malware have shown a way tor remains a big threat even when they fail to communicate with the central server. It remains unclear if Malware Hunter will be capable of doing anything about these attacks as well. For now, this search engine is a big step in the right direction, though.

It is important to note Malware Hunter is capable of identifying several dozen C&C servers used for Remote Access Trojans. Given the recent surge in Remote Access Trojan distribution, this is quite a positive development, to say the least. The team is hopeful Malware Hunter will detect other major threats in the future, including botnets, cryptominers, and backdoor trojans.

If you liked this article, follow us on Twitter @themerklenews and make sure to subscribe to our newsletter to receive the latest bitcoin, cryptocurrency, and technology news.

JP Buntinx

JP Buntinx is a FinTech and Bitcoin enthusiast living in Belgium. His passion for finance and technology made him one of the world's leading freelance Bitcoin writers, and he aims to achieve the same level of respect in the FinTech sector.

Share
Published by
JP Buntinx

Recent Posts

SkyAI’s Explosive 20x Surge Raises Red Flags As On-Chain Data Points To Possible Market Manipulation

The cryptocurrency market is in the crosshairs once again, an explosive price move in SkyAI…

10 hours ago

Bitget Launches OpenAI Pre-IPO Access As Crypto Exchanges Push Into Tokenized Equity Markets

Bitget officially launched pre-IPO access to OpenAI via its IPO Prime platform which deepens their…

1 day ago

Tether Expands Open-Source Push With New Developer Grants For AI And Payment Infrastructure

Tether's presence in decentralized tech space is growing due to the launch of its developer…

2 days ago

Huma Finance Exploit Hits Legacy Contracts As Platform Maintains Stability And Accelerates Transition To V2 System

While challenges remain, the decentralized finance sector is moving forward, and Huma Finance's exploit serves…

2 days ago

Chainlink Expands Cross-Chain Reach As Major Protocols And Institutions Deepen Adoption 

Chainlink is continuing its mission to be the most widely integrated infrastructure in crypto, adding…

3 days ago

Sui Network Hit Again: DeepBook Exploit Adds To Growing List As Token Defies Pressure With Bullish Breakout

A vulnerability in one of the core DeFi protocols on Sui Network exposes the ecosystem…

4 days ago