• Local News
    • San Diego
    • North County
    • East County
    • South Bay
    • Northeastern
    • Temecula
  • Entertainment
    • Music
    • Television
    • Art
    • Theater
    • Film
    • Events
    • Theme Parks
    • Podcast/Radio
    • Museums
    • Books
  • Business
  • National
  • Politics
  • Sports
  • Health
    • Health Business
    • Health Education
    • Medical
  • Lifestyle
    • Travel
    • Food
    • Lifestyle
    • Senior Life
    • Society
  • Home

San Diego County News

Independent publication serving San Diego County

Qakbot malware disrupted in international cyber takedown

August 30, 2023 By sdcnews

Image: Shutterstock/ Rawpixel.com

By SDCN Editor

The Justice Department Tuesday announced a multinational operation involving actions in the United States, France, Germany, the Netherlands, the United Kingdom, Romania, and Latvia to disrupt the botnet and malware known as Qakbot and take down its infrastructure. 

The Qakbot malicious code is being deleted from victim computers, preventing it from doing any more harm. The department also announced the seizure of approximately $8.6 million in cryptocurrency in illicit profits.

The action represents the largest U.S.-led financial and technical disruption of a botnet infrastructure leveraged by cybercriminals to commit ransomware, financial fraud, and other cyber-enabled criminal activity.

“Cybercriminals who rely on malware like Qakbot to steal private data from innocent victims have been reminded today that they do not operate outside the bounds of the law,” said Attorney General Merrick Garland. “Together with our international partners, the Justice Department has hacked Qakbot’s infrastructure, launched an aggressive campaign to uninstall the malware from victim computers in the United States and around the world, and seized $8.6 million in extorted funds.”

Trending
Authorities seek information on two suspects involved in Baskin-Robbins burglaries

According to court documents, Qakbot, also known by various other names, including “Qbot” and “Pinkslipbot,” is controlled by a cybercriminal organization and used to target critical industries worldwide. The Qakbot malware primarily infects victim computers through spam email messages containing malicious attachments or hyperlinks. Once it has infected a victim computer, Qakbot can deliver additional malware, including ransomware, to the infected computer. Qakbot has been used as an initial means of infection by many prolific ransomware groups in recent years, including Conti, ProLock, Egregor, REvil, MegaCortex, and Black Basta. The ransomware actors then extort their victims, seeking ransom payments in bitcoin before returning access to the victim computer networks. These ransomware groups have caused significant harm to businesses, healthcare providers, and government agencies all over the world.

“The FBI led a worldwide joint, sequenced operation that crippled one of the longest-running cybercriminal botnets,” said FBI Director Christopher Wray. “With our federal and international partners, we will continue to systematically target every part of cybercriminal organizations, their facilitators, and their money – including by disrupting and dismantling their ability to use illicit infrastructure to attack us. Today’s success is yet another demonstration of how FBI’s capabilities and strategy are hitting cyber criminals hard, and making the American people safer.”

The victim computers infected with Qakbot malware are part of a botnet, which is a network of compromised computers, meaning the perpetrators can remotely control all the infected computers in a coordinated manner. The owners and operators of the victim computers are typically unaware of the infection.

“An international partnership led by the Justice Department and the FBI has resulted in the dismantling of Qakbot, one of the most notorious botnets ever, responsible for massive losses to victims around the world,” said U.S. Attorney Martin Estrada for the Central District of California. “Qakbot was the botnet of choice for some of the most infamous ransomware gangs, but we have now taken it out. This operation also has led to the seizure of almost 9 million dollars in cryptocurrency from the Qakbot cybercriminal organization, which will now be made available to victims.”

As part of the takedown, the FBI was able to gain access to Qakbot infrastructure and identify over 700,000 computers worldwide, including more than 200,000 in the United States, that appear to have been infected with Qakbot. To disrupt the botnet, the FBI was able to redirect Qakbot botnet traffic to and through servers controlled by the FBI, which in turn instructed infected computers in the United States and elsewhere to download a file created by law enforcement that would uninstall the Qakbot malware. This uninstaller was designed to untether the victim computer from the Qakbot botnet, preventing further installation of malware through Qakbot.

The scope of the law enforcement action was limited to information installed on the victim computers by the Qakbot actors. It did not extend to remediating other malware already installed on the victim computers and did not involve access to or modification of the information of the owners and users of the infected computers.

40

SHARES
Share on Facebook
Tweet
Follow us

Filed Under: National Tagged With: National

10% off Florsheim with code: LNK10
SodaStream USA, inc

Popular Stories

  • Man arrested for luring and sexually assaulting men in his apartment
  • CBP officers discover mixed meth, heroin load at Calexico port of entry
  • San Diego Airport collaborates with local businesses to release purified beers
  • 15-year-old juvenile arrested in connection with manufacturing ghost gun parts
  • Man arrested for possessing ghost gun during a traffic stop

School Sports




Fall Season! Don't wait for autumn to come! Enter code FALL25 for up to $25 off our fees on flights and plan your fall getaway today.

Categories

  • About Us
  • Archive
  • Checkout
  • Contact Us
  • Listing Form
  • Listings
  • My Account
  • Private Policy
  • Terms of Service
  • Things To Do

Follow @SanCounty

Privacy Policy

Terms of service

Copyright © 2023 San Diego County News