NATIONAL NEWS

FBI and European partners seize major malware network in blow to global cybercrime

Aug 29, 2023, 1:35 PM

U.S. Attorney Martin Estrada announces in Los Angeles on Tuesday, Aug. 29, 2023 the multinational t...

U.S. Attorney Martin Estrada announces in Los Angeles on Tuesday, Aug. 29, 2023 the multinational take down operation of Qakbot malware. In their latest disruption of global cybercrime, the FBI and partners in Europe infiltrated and seized control of a major malware network that was used for more than 15 years to commit a gamut of online crimes including crippling ransomware attacks. (Sarah Reingewirtz/The Orange County Register via AP)
Credit: ASSOCIATED PRESS

(Sarah Reingewirtz/The Orange County Register via AP)

LOS ANGELES (AP) — U.S. officials said Tuesday that the FBI and its European partners infiltrated and seized control of a major malware network used for more than 15 years to commit a gamut of online crimes including crippling ransomware attacks.

They then remotely removed the malicious software agent — known as Qakbot — from thousands of infected computers.

Cybersecurity experts said they were impressed by the deft dismantling of the network but cautioned that any setback to cybercrime would likely be temporary.

“Nearly ever sector of the economy has been victimized by Qakbot,” Martin Estrada, the U.S. attorney in Los Angeles, said Tuesday in announcing the takedown. He said the criminal network had facilitated about 40 ransomware attacks alone over 18 months that investigators said netted Qakbot administrators about $58 million.

Qakbot’s ransomware victims included an Illinois-based engineering firm, financial services organizations in Alabama and Kansas, along with a Maryland defense manufacturer and a Southern California food distribution company, Estrada said.

Officials said $8.6 million in cybercurrency was seized or frozen but no arrests were announced.

Estrada said the investigation is ongoing. He would not say where administrators of the malware, which could be marshaled into a botnet of zombie computers, were located. Cybersecurity researchers say they are believed to be in Russia and/or other former Soviet states.

Officials estimated the so-called malware loader, also known as Pinkslipbot and Qbot, was leveraged to cause hundreds of millions of dollars in damage since first appearing in 2008 as an information-stealing bank trojan. They said millions of people in nearly every country in the world have been affected.

Typically delivered via phishing email infections, Qakbot gave criminal hackers initial access to violated computers. They could then deploy additional payloads including ransomware, steal sensitive information or gather intelligence on victims to facilitate financial fraud and crimes such as tech support and romance scams.

The Qakbot network was “literally feeding the global cybercrime supply chain,” said Donald Alway, assistant director in charge of the FBI’s Los Angeles office, calling it “one of the most devastating cybercriminal tools in history.”

In the first half of 2023, Qakbot accounted for about 30% of such attacks globally, according to one cybersecurity firm’s study. Such “initial access” tools allow extortionist ransomware gangs to skip the initial step of penetrating computer networks, making them major facilitators for the far-flung mostly Russian-speaking criminals who have wreaked havoc by stealing data and disrupting schools, hospitals, local governments and businesses worldwide.

Beginning Friday in an operation officials dubbed “Duck Hunt,” the FBI along with Europol and law enforcement and justice partners in France, the United Kingdom, Germany, the Netherlands, Romania and Latvia seized more than 50 Qakbot servers and identified more than 700,000 infected computers, more than 200,000 of them in the U.S. — effectively cutting off criminals from their quarry.

The FBI then used the seized Qakbot infrastructure to remotely dispatch updates that deleted the malware from thousands of infected computers. A senior FBI official, briefing reporters on condition he not be further identified, called that number “fluid” and cautioned that other malware may have remained on machines liberated from Qakbot.

It was the FBI’s biggest success against cybercrooks since it “hacked the hackers” with the January takedown of the prolific Hive ransomware gang.

“It is an impressive takedown. Qakbot was the largest botnet” in number of victims, said Alex Holden, founder of Milwaukee-based Hold Security. But he said it may have been a victim of its own success in its staggering growth over the past few years. “Large botnets today tend to implode as too many threat actors are mining this data for various types of abuse.”

Cybersecurity expert Chester Wisniewski at Sophos agreed that while there could be a temporary drop in ransomware attacks, the criminals can be expected to either revive infrastructure elsewhere or move to other botnets.

“This will cause a lot of disruption to some gangs in the short term, but it will do nothing from it being rebooted,” he said. “Albeit it takes a long time to recruit 700,000 PCs.”

___

Bajak reported from Boston.

National News

FILE - A passenger disembarks from Amtrak's Sunset Limited at its final stop in New Orleans, Nov. 2...

Associated Press

Biden administration announces $1.4 billion to improve rail safety and boost capacity in 35 states

WASHINGTON (AP) — The Biden administration announced Monday that it has awarded more than $1.4 billion to projects that improve railway safety and boost capacity, with much of the money coming from the 2021 infrastructure law. “These projects will make American rail safer, more reliable, and more resilient, delivering tangible benefits to dozens of communities […]

35 minutes ago

FILE - Sweat covers the face of Juan Carlos Biseno after dancing to music from his headphones as af...

Associated Press

After summer’s extreme weather, more Americans see climate change as a culprit, AP-NORC poll shows

Kathleen Maxwell has lived in Phoenix for more than 20 years, but this summer was the first time she felt fear, as daily high temperatures soared to 110 degrees or hotter and kept it up for a record-shattering 31 consecutive days. “It’s always been really hot here, but nothing like this past summer,” said Maxwell, […]

3 hours ago

Hudson, 7, left, Callahan, 13, middle, and Keegan Pruente, 10, right, stand outside their school on...

Associated Press

More schools are adopting 4-day weeks. For parents, the challenge is day 5

INDEPENDENCE, Mo. (AP) — It’s a Monday in September, but with schools closed, the three children in the Pruente household have nowhere to be. Callahan, 13, contorts herself into a backbend as 7-year-old Hudson fiddles with a balloon and 10-year-old Keegan plays the piano. Like a growing number of students around the U.S, the Pruente […]

5 hours ago

FILE - Sydney Carney walks through her home, which was destroyed by a wildfire on Aug. 11, 2023, in...

Associated Press

Residents prepare to return to sites of homes demolished in Lahaina wildfire 7 weeks ago

HONOLULU (AP) — From just outside the burn zone in Lahaina, Jes Claydon can see the ruins of the rental home where she lived for 13 years and raised three children. Little remains recognizable beyond the jars of sea glass that stood outside the front door. On Monday, officials are expected to begin lifting restrictions […]

5 hours ago

Associated Press

Kidnapped teen rescued from Southern California motel room after 4 days of being held hostage

SANTA MARIA, Calif. (AP) — Authorities rescued a 17-year-old boy in Southern California after he was kidnapped and held hostage for four days by captors who threatened to harm him if his family did not pay a $500,000 ransom. The teen was rescued Friday after law enforcement tracked him and his three kidnappers to a […]

10 hours ago

FILE - A hiring sign is displayed at a retail store in Vernon Hills, Ill., Thursday, Aug. 31, 2023....

Associated Press

Why the US job market has defied rising interest rates and expectations of high unemployment

WASHINGTON (AP) — Last year’s spike in inflation, to the highest level in four decades, was painful enough for American households. Yet the cure — much higher interest rates, to cool spending and hiring — was expected to bring even more pain. Grim forecasts from economists had predicted that as the Federal Reserve jacked up […]

11 hours ago

Sponsored Articles

Swedish Cyberknife...

September is Prostate Cancer Awareness Month

September is a busy month on the sports calendar and also holds a very special designation: Prostate Cancer Awareness Month.

Ziply Fiber...

Dan Miller

The truth about Gigs, Gs and other internet marketing jargon

If you’re confused by internet technologies and marketing jargon, you’re not alone. Here's how you can make an informed decision.

Education families...

Education that meets the needs of students, families

Washington Virtual Academies (WAVA) is a program of Omak School District that is a full-time online public school for students in grades K-12.

Emergency preparedness...

Emergency planning for the worst-case scenario

What would you do if you woke up in the middle of the night and heard an intruder in your kitchen? West Coast Armory North can help.

Innovative Education...

The Power of an Innovative Education

Parents and students in Washington state have the power to reimagine the K-12 educational experience through Insight School of Washington.

Medicare fraud...

If you’re on Medicare, you can help stop fraud!

Fraud costs Medicare an estimated $60 billion each year and ultimately raises the cost of health care for everyone.

FBI and European partners seize major malware network in blow to global cybercrime