Get the App
SLTechnology News&Howtos  ›  IT Information  › 

Us FBI teamed up to destroy Qakbot, wiping out one of the world's most notorious botnets

Shulou Source: shulou.com Published: 2023-11-24 19:06:37 10月04日 Update

CTOnews.com, August 30 (Xinhua)-- according to the Federal Bureau of investigation (FBI), a U.S.-led multinational operation destroyed Qakbot, malware that infected more than 700000 computers around the world.

Hackers usually attack Qakbot victims by sending spam with malicious attachments or links. Once the victim downloads the attachment or clicks on the link, Qakbot infects their computer, making it a botnet (botnet)-an infected computer network remotely controlled by hackers. Lawbreakers can then install more malware, such as blackmail, on the victim's device.

To destroy the network, FBI routes Qakbot to servers controlled by FBI and instructs infected computers in the United States and elsewhere to download and uninstall Qakbot malware. The installer also separates the infected computer from the botnet to "prevent more malware from being installed through Qakbot". The U.S. Department of Justice (DOJ) noted that the action was limited to malware installed by Qakbot participants and "did not extend to repairing other malware that had been installed on the victim's computer."

In addition to the United States, Operation Duck Hunt also involved Europol, France, Germany, the Netherlands, the United Kingdom, Romania and Latvia. The United States says the botnet caused hundreds of millions of dollars in damage and infected more than 200000 computers in the United States.

Qakbot has been in existence since 2008 and has been used by some notorious blackmail software gangs, including Conti, REvil, MegaCortex and so on. As part of the operation, the Justice Department confiscated $8.6 million worth of cryptocurrency (CTOnews.com Note: currently about 62.694 million yuan) to extort funds.

FBI has provided Have I Been Pwned with leaked vouchers found during the operation, allowing netizens to enter email on the site to check if it is affected, and the Dutch National Police added the affected vouchers to its Check Your Hack website.

Tags: Software US malicious computer Internet victim Action Zombie 10 000 credential more website email Link attachment Hacker Holland Department of Justice United States Department of Justice influence Apple Docker Huawei Linux macOS MariaDB Microsoft MySQL NVidia OPPO Reno Shulou Technology Linux Microsoft Huawei OPPO Reno