TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

FBI, partners dismantle Qakbot infrastructure

229 点作者 mvdwoord超过 1 年前

14 条评论

AugustoCAS超过 1 年前
This is huge. Yesterday The Register published an article [1] mentioning that Qakbot was responsible for 30% of recorded intrusion attempts since the start of 2023.<p>[1]: <a href="https:&#x2F;&#x2F;www.theregister.com&#x2F;2023&#x2F;08&#x2F;28&#x2F;top_malware_loaders&#x2F;" rel="nofollow noreferrer">https:&#x2F;&#x2F;www.theregister.com&#x2F;2023&#x2F;08&#x2F;28&#x2F;top_malware_loaders&#x2F;</a>
firesteelrain超过 1 年前
&quot;To disrupt the botnet, the FBI redirected Qakbot traffic to Bureau-controlled servers that instructed infected computers to download an uninstaller file. This uninstaller—created to remove the Qakbot malware—untethered infected computers from the botnet and prevented the installation of any additional malware. &quot;<p>That&#x27;s pretty sweet that they healed hundreds of thousands of computers
评论 #37314003 未加载
评论 #37314410 未加载
评论 #37314470 未加载
评论 #37311179 未加载
评论 #37312545 未加载
评论 #37311991 未加载
评论 #37312181 未加载
评论 #37313749 未加载
评论 #37311743 未加载
评论 #37311528 未加载
评论 #37314308 未加载
r3trohack3r超过 1 年前
The warrant application is one of the coolest, cyberpunk, warrants I&#x27;ve read in my lifetime: <a href="https:&#x2F;&#x2F;www.justice.gov&#x2F;d9&#x2F;2023-08&#x2F;23mj4244_application_redacted.pdf" rel="nofollow noreferrer">https:&#x2F;&#x2F;www.justice.gov&#x2F;d9&#x2F;2023-08&#x2F;23mj4244_application_reda...</a><p>Feels like one of those &quot;in world messages&quot; you find in games like Cyberpunk 2077. Could have been written by NetWatch.<p>We live in amazing times.
评论 #37311684 未加载
评论 #37314842 未加载
1970-01-01超过 1 年前
Qbot&#x2F;Qakbot&#x2F;Pinkslip&#x2F;Whateveritsnowcalled has been morphing since the very beginning, 2007&#x2F;08:<p><a href="https:&#x2F;&#x2F;www.blackberry.com&#x2F;us&#x2F;en&#x2F;solutions&#x2F;endpoint-security&#x2F;ransomware-protection&#x2F;qakbot" rel="nofollow noreferrer">https:&#x2F;&#x2F;www.blackberry.com&#x2F;us&#x2F;en&#x2F;solutions&#x2F;endpoint-security...</a><p><a href="https:&#x2F;&#x2F;www.youtube.com&#x2F;watch?v=DN9m27nhA00">https:&#x2F;&#x2F;www.youtube.com&#x2F;watch?v=DN9m27nhA00</a><p><a href="https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;BASHLITE" rel="nofollow noreferrer">https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;BASHLITE</a>
评论 #37315640 未加载
autoexec超过 1 年前
If it&#x27;s really finally fully down that&#x27;s great, but it took forever and replacements can be churned out and new networks grown in a very short amount of time.<p>I&#x27;m glad the FBI invested 15+ years and who knows how much money to rid the world of QBot, but this isn&#x27;t a scalable solution to the botnet problem.
评论 #37313162 未加载
michaelaiello超过 1 年前
Some more technical details on what we observed here. <a href="https:&#x2F;&#x2F;www.secureworks.com&#x2F;blog&#x2F;law-enforcement-takes-down-qakbot" rel="nofollow noreferrer">https:&#x2F;&#x2F;www.secureworks.com&#x2F;blog&#x2F;law-enforcement-takes-down-...</a><p><a href="https:&#x2F;&#x2F;www.secureworks.com&#x2F;blog&#x2F;qakbot-campaign-delivered-black-basta-ransomware" rel="nofollow noreferrer">https:&#x2F;&#x2F;www.secureworks.com&#x2F;blog&#x2F;qakbot-campaign-delivered-b...</a>
badrabbit超过 1 年前
I wouldn&#x27;t make a big deal out of this, unlike worms, &quot;bots&quot; like this will come back after weeks&#x2F;months because of the number of people involved and the spread of the malware &quot;kit&quot; (including server side stuff). They are constantly adapting anyways, there isn&#x27;t a fixed set if domains and IPs you can block to stop it permanently.<p>They took down emotet as well but it&#x27;s had a resurgence.<p>Qakbot in recent years has shifted to a initial access broker monetization scheme where it sells access (cobaltrsike,etc...) to more serious actors who will pay the access fee instead of hiring talent themselves to do the hacking. So they have a strong community of customers. They will need to arrest a lot of people at once and hope they got all the people needed to revive it.
dcow超过 1 年前
Two questions:<p>1. if someone installed Qakbot willingly, does the warrant apply (the warrant has what looks to me like specific language limiting it to unaware victim’s machines)?<p>2. if the FBI’s justice.exe damaged data on a victim machine because of an unexpected configuration, are they liable for damages?
评论 #37312390 未加载
评论 #37314975 未加载
yafbum超过 1 年前
Cool use of the botnet&#x27;s capabilities against itself<p>But no arrests announced? I wish the people responsible for this were made an example of, as opposed to being basically free to start over (it seems).
评论 #37312367 未加载
评论 #37313037 未加载
评论 #37313386 未加载
评论 #37313758 未加载
behindai超过 1 年前
Faced a &quot;wtf&quot; that damages your subjects? Name it &quot;Russian&quot; backed. ???? PROFIT
bdcp超过 1 年前
Is this the ransomware as a service that was hitting hospitals and multiple companies?
kiddico超过 1 年前
A 3 letter did a thing I like? Quick, someone pinch me.
coldblues超过 1 年前
&gt; To disrupt the botnet, the FBI redirected Qakbot traffic to Bureau-controlled servers that instructed infected computers to download an uninstaller file. This uninstaller—created to remove the Qakbot malware—untethered infected computers from the botnet and prevented the installation of any additional malware.<p>So the FBI used unauthorized access to the computers to uninstall the malware? Scary if you think about it. I&#x27;m sure they could have used that access any way they wanted.
评论 #37311243 未加载
评论 #37311861 未加载
评论 #37311529 未加载
评论 #37311462 未加载
评论 #37311293 未加载
评论 #37311238 未加载
评论 #37312384 未加载
评论 #37312923 未加载
评论 #37311692 未加载
评论 #37311505 未加载
jscipione超过 1 年前
If the FBI doesn’t like them, Qakbot can’t be that bad.