Tech

FBI dismantles Qakbot community utilized in main ransomware assaults

[ad_1]

U.S. authorities on Tuesday introduced a multinational operation that they mentioned took down a community that had contaminated lots of of hundreds of computer systems with malware and triggered lots of of thousands and thousands of {dollars} in damages from cyberattacks worldwide.

The FBI referred to as the motion that disabled the notorious Qakbot malware “one of many largest U.S.-led disruptions of a botnet infrastructure utilized by cybercriminals to commit ransomware, monetary fraud, and different cyber-enabled prison exercise.” The Justice Division mentioned legislation enforcement businesses in France, Germany, the Netherlands, the UK, Romania and Latvia additionally participated within the operation, which it mentioned was code-named “Duck Hunt.”

Some $8.6 million in stolen cryptocurrency associated to the community’s operations additionally was seized and can be returned to victims, the FBI mentioned.

“The FBI neutralized this far-reaching prison provide chain, slicing it off on the knees,” FBI Director Christopher A. Wray mentioned in an announcement.

Qakbot, first found in 2008, has often focused victims’ computer systems by means of spam e mail messages containing malicious hyperlinks or attachments. Sufferer machines would then grow to be one other hyperlink within the community, surreptitiously beneath management of these looking for to make use of the community for cybercrime. Some 700,000 victims have been recognized worldwide, with 200,000 of them in the US, in keeping with the Justice Department.

The botnet enabled the operations of variety of high-profile ransomware teams, together with Conti and REvil, that focused organizations akin to hospitals, colleges and municipal governments, holding their delicate information hostage in alternate for a ransom cost. Victims have included an influence engineering agency based mostly in Illinois, a monetary companies firm in Alabama and a meals distribution firm in California, in keeping with authorities, who added that Qakbot directors obtained about $58 million in ransoms paid by victims between October 2021 and April 2023.

The FBI mentioned it disabled the infrastructure by tricking computer systems contaminated with the malware into distributing and downloading a file created that directed computer systems to uninstall the malware and untether themselves from the botnet.

Affected victims wouldn’t know that the uninstall mechanism was lively, in keeping with senior FBI and Justice Division officers who spoke on the situation of anonymity to offer reporters with particulars in regards to the operation.

The senior officers declined to touch upon whether or not the Qakbot community was linked to anybody nation. The FBI didn’t announce any arrests and mentioned the investigation into who was behind the community is ongoing.

[ad_2]

Source

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button