He’s back, and he’s ready to talk botnet takeovers.
Tillmann Werner, VP of Intelligence Production at CrowdStrike, returns to the podcast to discuss CrowdStrike’s coordinated takeover of the Glassworm botnet. Glassworm was a global threat targeting software developers through the open-source supply chain. This infection vector stood out — open-source ecosystems are based on trust, and adversaries are learning they can reach a vast pool of victims by compromising the supply chain. Some open-source libraries get 100 million downloads per week.
Glassworm was described as an “unkillable” botnet. Resilience was built into its design, which relied on four different command-and-control channels. This made the takeover complicated because a botnet can’t be taken over until all command-and-control mechanisms are suppressed.
“Once it’s down, you gotta make sure it’s down,” said Adam, who calls Tillmann the “bot slayer.”
In this episode, they get into the details: what Glassworm was after, how its unknown operators strengthened its infrastructure, and the planning and execution behind the takeover. Tillmann and his team facilitated the process by conducting extensive technical analysis, understanding Glassworm’s evolution, and spotting the opportunity to disrupt it. They worked with partners across the private and public sectors, as well as internally at CrowdStrike, to do it safely and avoid disrupting critical systems.
Come for the behind-the-scenes details, and stay for the debate around baking the perfect pizza in this episode of the Adversary Universe podcast.
Learn more in our blog: https://www.crowdstrike.com/en-us/blog/inside-crowdstrike-takedown-of-a-developer-targeting-botnet/.