Some $8.6 million in stolen cryptocurrency associated to the community’s operations additionally was seized and can be returned to victims, the FBI mentioned.
“The FBI neutralized this far-reaching prison provide chain, reducing it off on the knees,” FBI Director Christopher A. Wray mentioned in an announcement.
Qakbot, first found in 2008, has ceaselessly focused victims’ computer systems via spam e-mail messages containing malicious hyperlinks or attachments. Sufferer machines would then develop into one other hyperlink within the community, surreptitiously below management of these searching for to make use of the community for cybercrime. Some 700,000 victims have been recognized worldwide, with 200,000 of them in the USA, in accordance with the Justice Division.
The botnet enabled the operations of variety of high-profile ransomware teams, together with Conti and REvil, that focused organizations equivalent to hospitals, faculties and municipal governments, holding their delicate knowledge hostage in alternate for a ransom fee. Victims have included an influence engineering agency based mostly in Illinois, a monetary providers firm in Alabama and a meals distribution firm in California, in accordance with authorities, who added that Qakbot directors obtained about $58 million in ransoms paid by victims between October 2021 and April 2023.
The FBI mentioned it disabled the infrastructure by tricking computer systems contaminated with the malware into distributing and downloading a file created that directed computer systems to uninstall the malware and untether themselves from the botnet.
Affected victims wouldn’t know that the uninstall mechanism was energetic, in accordance with senior FBI and Justice Division officers who spoke on the situation of anonymity to offer reporters with particulars in regards to the operation.
The senior officers declined to touch upon whether or not the Qakbot community was linked to anyone nation. The FBI didn’t announce any arrests and mentioned the investigation into who was behind the community is ongoing.