FBI dismantles Qakbot community utilized in main ransomware assaults


U.S. authorities on Tuesday introduced a multinational operation that they mentioned took down a community that had contaminated lots of of hundreds of computer systems with malware and brought on lots of of thousands and thousands of {dollars} in damages from cyberattacks worldwide.

The FBI known as the motion that disabled the notorious Qakbot malware “one of many largest U.S.-led disruptions of a botnet infrastructure utilized by cybercriminals to commit ransomware, monetary fraud, and different cyber-enabled prison exercise.” The Justice Division mentioned regulation enforcement businesses in France, Germany, the Netherlands, the UK, Romania and Latvia additionally participated within the operation, which it mentioned was code-named “Duck Hunt.”

Some $8.6 million in stolen cryptocurrency associated to the community’s operations additionally was seized and can be returned to victims, the FBI mentioned.

“The FBI neutralized this far-reaching prison provide chain, reducing it off on the knees,” FBI Director Christopher A. Wray mentioned in an announcement.

Qakbot, first found in 2008, has ceaselessly focused victims’ computer systems via spam e-mail messages containing malicious hyperlinks or attachments. Sufferer machines would then develop into one other hyperlink within the community, surreptitiously below management of these searching for to make use of the community for cybercrime. Some 700,000 victims have been recognized worldwide, with 200,000 of them in the USA, in accordance with the Justice Division.

The botnet enabled the operations of variety of high-profile ransomware teams, together with Conti and REvil, that focused organizations equivalent to hospitals, faculties and municipal governments, holding their delicate knowledge hostage in alternate for a ransom fee. Victims have included an influence engineering agency based mostly in Illinois, a monetary providers firm in Alabama and a meals distribution firm in California, in accordance with authorities, who added that Qakbot directors obtained about $58 million in ransoms paid by victims between October 2021 and April 2023.

The FBI mentioned it disabled the infrastructure by tricking computer systems contaminated with the malware into distributing and downloading a file created that directed computer systems to uninstall the malware and untether themselves from the botnet.

Affected victims wouldn’t know that the uninstall mechanism was energetic, in accordance with senior FBI and Justice Division officers who spoke on the situation of anonymity to offer reporters with particulars in regards to the operation.

The senior officers declined to touch upon whether or not the Qakbot community was linked to anyone nation. The FBI didn’t announce any arrests and mentioned the investigation into who was behind the community is ongoing.

Related Articles

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Latest Articles