FBI disrupts cybercrime operation by wiping malicious programs from hundreds of thousands of computers

Well, gee, ummm, thanks but. Hmmm… :face_with_raised_eyebrow:


NBC News
NBC News

Follow

FBI disrupts cybercrime operation by wiping malicious programs from hundreds of thousands of computers

Story by Kevin Collier •1h

The FBI quietly wiped malicious programs from more than 700,000 computers around the world in recent days, the agency said Tuesday, part of an operation to take down a major component of the cybercrime ecosystem.

The operation’s goal was to disrupt a long-running botnet, a network of computers linked together by the same malicious programs, called Qakbot. Qakbot is a versatile tool that has long been available for rent to cybercriminals who use it to gain initial access to a victim’s computers or files.

Botnets often rely heavily on hacking and exploiting computers that belong to individuals or companies who usually have no idea that their devices are moonlighting as an accomplice to cybercriminals. It is rare and often legally complicated, though not unprecedented, for the FBI to convince a court to let it kick hackers out of victims’ computers without their knowledge.

The FBI got a court’s permission to proceed with the operation on Aug. 21, according to a copy of the warrant. Agents proceeded to hack into Qakbot’s central computer infrastructure four days later, the FBI announced, and forced it to tell the computers in its botnet to stop listening to Qakbot.

Keith Jarvis, a senior researcher at the Atlanta cybersecurity company Secureworks, which was monitoring the botnet and its takedown, told NBC News that most computers infected with Qakbot were likely effectively fixed in the first few hours of the FBI operation.

In a media call after the announcement, an FBI official who requested not to be identified, said that the FBI developed a particular removal tool for the operation. Victims will not be notified that their devices had been fixed or that they had ever been compromised, he said.

However, the FBI gave the names and email addresses of some of the people who had been hacked to Have I Been Pwned, a website that allows anyone to check if they appear in certain major data breaches. Have I Been Pwned added 6.4 million email accounts tied to Qakbot to its database on Tuesday.

The FBI’s announcement said that law enforcement agencies in France, Germany, the Netherlands, the United Kingdom, Romania and Latvia all participated in the Qakbot takedown. The FBI official declined to say whether anyone was arrested as part of the Qakbot takedown or if any governments were part of the cybercriminal operations.

Bradley Duncan, a researcher at Palo Alto Networks, said that while some of the largest cybercrime gangs use Qakbot to infect companies, schools and hospitals with disruptive ransomware, the FBI’s action was unlikely to translate into a major reduction in cyberattacks. Hackers have plenty of other ways to break in, he said.

“Although any disruption is good, Qakbot’s disruption may not make a massive dent in ransomware operations,” Duncan said.

6 Likes

Umm yeah. I don’t remember being asked for permission to search my computer or being handed a warrant saying I have to let them in.

11 Likes

So, what does that have to do with anything. They don’t care about any of that mildewy musty old document called The Constitution of The United States or the Bill of Rights. To them that’s just an old, in the way arcane way of thinking.

9 Likes

“We’re from the government and we are here to help” Whether you want it or not. :face_with_raised_eyebrow:

8 Likes

We can always count on “BIG BROTHER” watching over us. :stuck_out_tongue_winking_eye:

6 Likes

The story states they hacked Qakbot, which was infiltrating computers, so they did not hack the victims’ computers, just had Qakbot to have the victims’ computers to stop getting instructions from Qakbot.

3 Likes

But you know they only did this so they could get the program for themselves

6 Likes

This story would be more believable if it said the FBI had secretly installed spyware on the computers of 700,090 gun owners.

8 Likes

Interesting …

The FBI can access 700,000 computers and install software that removes Qakbot malware, but can’t identify, catch and prosecute the folks who developed Qakbot or shut down the Qakbot server.

5 Likes

Or, who left the pipe bombs in DC. More surveillance there than you can shake a stick at.

6 Likes

The way I read the article it sounded like they told the individual computers to stop accepting commands from the virus.

I’d rather not have the government telling my computer what to do. If they have reason to believe my computer is infected they can let me know and I’ll decide if I want to accept the government’s fix. What’s to stop the government from looking at other things while they are in there? More likely I’ll choose to take it to an actual professional to get rid of the virus all together.

4 Likes

Is that not just crazy? government officials not carrying about the constitution? the glowies like the fbi, atf, Trump, Clark. It is sickening.

2 Likes

I contacted my bank a cpl days ago about a checking withdrawal to “VideoThePhil.com”. Went to the web, there actually was one believe it or not, and it was one of those “we’re here to help “ BS pages. I told the bank to report it to the police and got my $50 back.

6 Likes

Someone used my CC number to order several thousand dollars worth of concert tickets. Fortunately I get notifications for all transactions so I was able to shut the card down and cancel the bogus charges. But I’m still stuck without my primary card until they send a new one and I have to reset most of my recurring charges to the new number:(

These people almost never get caught and on the rare occasions they do they end up pleading guilty to 1 minor charge instead of serving time for thousands of individual cases of ID fraud and theft they commit.

7 Likes

That’s where I’m at right now.

5 Likes
3 Likes

That still sounds like the FBI giving orders to my computer even if they used the virus makers servers to do it.

I’d still rather be told my computer had the virus so I could choose best how to get rid of it completely. I would have no faith that the FBI wasn’t doing other illegal stuff to my computer while they are in there supposedly taking care of the virus.

4 Likes

Like setting you up to be a patsy in a mass shooting? :thinking:

7 Likes

Well, so much for Norton Life Lock, Anti-Theft Protection, Anti-virus Protection, Firefox. :frowning_with_open_mouth:

7 Likes

My thoughts exactly and exactly why I posted the topic. Trust is in short supply. :us:

7 Likes