[HN Gopher] FBI, partners dismantle Qakbot infrastructure
       ___________________________________________________________________
        
       FBI, partners dismantle Qakbot infrastructure
        
       Author : mvdwoord
       Score  : 187 points
       Date   : 2023-08-29 17:02 UTC (5 hours ago)
        
 (HTM) web link (www.fbi.gov)
 (TXT) w3m dump (www.fbi.gov)
        
       | dcow wrote:
       | Two questions:
       | 
       | 1. if someone installed Qakbot willingly, does the warrant apply
       | (the warrant has what looks to me like specific language limiting
       | it to unaware victim's machines)?
       | 
       | 2. if the FBI's justice.exe damaged data on a victim machine
       | because of an unexpected configuration, are they liable for
       | damages?
        
         | ipaddr wrote:
         | If they breakdown your door by mistake who pays the repair
         | damages? You do.
        
           | dcow wrote:
           | Do you have a citation for that? AFAIU breaking down the door
           | is only allowed with a knock-less warrant, in which case it's
           | not a mistake.
           | 
           | > An aggrieved citizen might also have a claim for civil
           | liability against the officer or the law enforcement agency
           | for certain unreasonable actions taken in the search. The
           | basis for such claims could include invasion of privacy,
           | trespass, or property damage.
        
             | masfuerte wrote:
             | A web search turns up loads of cases where the police
             | bashed in the wrong door simply because they are morons.
             | Here's one that was expensive for them (for the city
             | anyway): https://www.boston.com/news/local-
             | news/2021/01/13/brighton-f...
        
               | fnord77 wrote:
               | that came out of taxpayer's / insurance budget
               | 
               | that did not come out of the police budget
        
             | m4jor wrote:
             | Source: history of law enforcement being stupid
             | 
             | - https://ij.org/press-release/after-a-swat-team-destroyed-
             | a-t...
             | 
             | - https://www.kiro7.com/news/trending-now/court-rules-
             | homeowne...
             | 
             | - https://reason.com/2023/07/27/a-swat-team-destroyed-an-
             | innoc...
             | 
             | - etc etc etc thousands of times
        
         | 1970-01-01 wrote:
         | 1. Yes.
         | 
         | 2. No, but if they completely botched the module, possibly yes.
         | See 17:                    17. The FBI Supernode Module and the
         | Qakbot Uninstaller do not collect content from the infected
         | computers, nor do they alter the functionality of the infected
         | computers' operating systems, files, or software, except as
         | expressly provided in this affidavit.
         | 
         | Legally, hacking-back is a fairly new concept, and I'm not
         | aware of the FBI openly doing it at a 'supernode' scale.
         | 
         | https://en.wikipedia.org/wiki/Hacking_back
        
       | michaelaiello wrote:
       | Some more technical details on what we observed here.
       | https://www.secureworks.com/blog/law-enforcement-takes-down-...
       | 
       | https://www.secureworks.com/blog/qakbot-campaign-delivered-b...
        
       | 1970-01-01 wrote:
       | Qbot/Qakbot/Pinkslip/Whateveritsnowcalled has been morphing since
       | the very beginning, 2007/08:
       | 
       | https://www.blackberry.com/us/en/solutions/endpoint-security...
       | 
       | https://www.youtube.com/watch?v=DN9m27nhA00
       | 
       | https://en.wikipedia.org/wiki/BASHLITE
        
       | bdcp wrote:
       | Is this the ransomware as a service that was hitting hospitals
       | and multiple companies?
        
       | AugustoCAS wrote:
       | This is huge. Yesterday The Register published an article [1]
       | mentioning that Qakbot was responsible for 30% of recorded
       | intrusion attempts since the start of 2023.
       | 
       | [1]: https://www.theregister.com/2023/08/28/top_malware_loaders/
        
       | r3trohack3r wrote:
       | The warrant application is one of the coolest, cyberpunk,
       | warrants I've read in my lifetime:
       | https://www.justice.gov/d9/2023-08/23mj4244_application_reda...
       | 
       | Feels like one of those "in world messages" you find in games
       | like Cyberpunk 2077. Could have been written by NetWatch.
       | 
       | We live in amazing times.
        
         | 1970-01-01 wrote:
         | Thanks for the link, the fun reading starts on page 12.
         | 
         | I think I'll change my SSID to 'FBI Supernode'
        
         | skilled wrote:
         | Not going to lie, it felt pretty boring. When I read your
         | comment I thought it was going to be a GFX designed warrant
         | with an image of Morpheus offering Neo to take either of the
         | pills, while The Silence of the Lambs was playing in the
         | background.
        
           | r3trohack3r wrote:
           | Even in cyberpunk dystopias, I imagine bureaucracies are
           | still bureaucracies.
           | 
           | This just seems very cool to me:
           | 
           | > a. First, the FBI will identify the current Tier 1 servers
           | (which are also Qakbot infected victim computers) based on
           | information collected by the FBI.
           | 
           | > b. Second, an FBI-controlled computer will contact each of
           | those Tier 1 servers using commands built into the Qakbot
           | malware and Qakbot encryption keys known to the FBI. The FBI
           | will instruct each Tier 1 server to download and install an
           | FBI-created module that replaces the "supernode" module in
           | the already-installed Qakbot malware ("FBI Supernode
           | Module"). The FBI Supernode Module contains a new encryption
           | key that will make it impossible for the Qakbot
           | administrators to communicate with the Tier 1 servers. The
           | proposed warrant would authorize replacement of the
           | "supernode" module to allow the FBI to communicate with and
           | search infected computers that make up the botnet. The
           | proposed warrant therefore also authorizes law enforcement
           | officers to seize or copy from the infected computers
           | electronically stored information related to the Qakbot
           | malware, including encryption keys and server lists used by
           | the Qakbot administrators to communicate with computers that
           | are part of the Qakbot infrastructure.
           | 
           | > c. Third, the FBI will contact each of those Tier 1 servers
           | using commands built into the Qakbot malware. The FBI will
           | instruct those Tier 1 servers to communicate with an FBI-
           | controlled server (the "FBI Server") instead of the Qakbot
           | Tier 2 servers. At this point all communications from
           | infected botnet computers will be routed through the Tier 1
           | servers to the FBI Server, rather than to the Qakbot Tier 2
           | and Tier 3 servers.
           | 
           | > d. Fourth, infected computers subject to this warrant that
           | make up the botnet would then communicate with the FBI Server
           | instead of the Tier 3 server. As noted above, the Qakbot
           | malware instructs the infected computers to contact the Tier
           | 3 server every one to four minutes. When those infected
           | computers contact the FBI Server, the server will instruct
           | them to download a second file created by law enforcement
           | ("the Qakbot Uninstaller"). This warrant would authorize this
           | action, with the intent that computers in the United States
           | that are infected with the Qakbot malware will download the
           | Qakbot Uninstaller from the FBI Server via the FBI-controlled
           | Tier 1 servers. The proposed warrant therefore authorizes law
           | enforcement officers to seize or copy from the infected
           | computers electronically stored information related to the
           | Qakbot malware, including IP addresses and routing
           | information necessary to determine whether the infected
           | computer continues to be controlled by the Qakbot botnet.
        
             | tgv wrote:
             | That does read a bit like Neal Stephenson.
        
       | kiddico wrote:
       | A 3 letter did a thing I like? Quick, someone pinch me.
        
       | firesteelrain wrote:
       | "To disrupt the botnet, the FBI redirected Qakbot traffic to
       | Bureau-controlled servers that instructed infected computers to
       | download an uninstaller file. This uninstaller--created to remove
       | the Qakbot malware--untethered infected computers from the botnet
       | and prevented the installation of any additional malware. "
       | 
       | That's pretty sweet that they healed hundreds of thousands of
       | computers
        
         | 1vuio0pswjnm7 wrote:
         | Sometimes I wonder why the American public has to be subject to
         | the all the evils of so-called "tech" companies when clearly
         | the US government has the personnel to write safe, reliable
         | software.
         | 
         | Unlike so-called "tech" companies that can smugly ignore
         | Americans' reasonable expectations of privacy in order to
         | generate obscene profits, there are laws that prohibit the US
         | government from engaging in similar shenangigans. (The
         | "shenangigans" should be crimes but money has intervened.)
         | 
         | Even if hypothetical government-issued software might be
         | "inferior" to whatever the so-called "tech" companies are
         | producing, it would still be "superior" from a legal/regulatory
         | standpoint. Americans would have some enforceable rights as
         | software users. (Other countries are making some progress.)
         | 
         | Someone is inevitably going to make a wise crack reply about
         | government contracting in the US. But I'm not referring to
         | contractors. I'm referring to government employees.
         | 
         | We'll also likely see some reply about the technical
         | superiority of so-called "tech" company software. But I'm not
         | referring to technical superiority, I'm referring to (a)
         | legal/regulatory limits on software authors and (b) software
         | user rights.
        
           | bredren wrote:
           | > there are laws that prohibit the US government from
           | engaging in similar shenangigans.
           | 
           | If the laws you're alluding to are steadfast, provide true
           | equal protection and are perfectly enforced I could see
           | greater reliance on government software tools.
           | 
           | However, history is littered with government agencies failing
           | to protect people. Not to pick on the FBI here but the
           | organization's own J. Edward Hoover wasn't the most privacy
           | focused person. The group's HQ is still named after this
           | person.
           | 
           | Perhaps other organizations could be relied on more. People
           | have wanted free tax filing software for a long time.
           | 
           | However, even the IRS has been shown vulnerable to take
           | actions based on pressure from political forces.
        
           | themagician wrote:
           | >"Sometimes I wonder why the American public has to be
           | subject to the all the evils of so-called "tech" companies
           | when clearly the US government has the personnel to write
           | safe, reliable software."
           | 
           | It's not just the American public, it's every computer user--
           | everywhere. The reason is because _it 's easy._
           | 
           | There's plenty of secure software and systems out there. It's
           | hard to use. The costs outweigh the benefits for most people
           | most of the time. We could all be running Qubes or openBSD
           | but we don't because it's hard. It's hard to do simple
           | things. Most of the world runs on Windows and people are
           | logged in as admin. It's a point and click world.
           | 
           | I don't know if the government needs to write software, but I
           | do think there is room for a vendor to step up, particularly
           | in the business world, with systems that offer ironclad
           | security.
           | 
           | IMO we are in an increasingly dangerous world. I'm surprised
           | the internet connected world hasn't collapsed yet. Every day
           | seems to be a new kind of scam or malware. It takes
           | incredible effort to safeguard systems today. One wrong click
           | and in 5 minutes your entire life can be destroyed. I'm
           | curious what the stats are on malware that has completely
           | destroyed businesses. Cyber insurance policies are almost
           | necessary now even if you consider yourself a skilled user.
        
           | TylerE wrote:
           | Government software is great if you have a decade and a
           | billion dollars to spend.
        
         | m_0x wrote:
         | Using malware to combat malware.
         | 
         | Hopefully they aren't lying.
        
           | debarshri wrote:
           | Anti viruses act like malware anyways
        
           | koolba wrote:
           | > Using malware to combat malware.
           | 
           | Though it's only legal when they do it. Pretty sure it'd
           | still be a crime if a good Samaritan tried it out.
        
             | paxys wrote:
             | Why are you making it sound like that's some profound
             | revelation? Law enforcement is allowed to run stings, serve
             | warrants and make arrests, you aren't. The military is
             | allowed to invade countries and drop nukes, you aren't. Yes
             | it is legal when they do it and not some average Joe who
             | wants to play hero. That's how the world works, and it is a
             | good thing.
        
               | fluoridation wrote:
               | I don't believe there's any laws that forbid individuals
               | from invading countries and using nuclear weapons.
        
               | glasshug wrote:
               | 18 U.S.C. 960
               | 
               | > Whoever, within the United States, knowingly begins or
               | sets on foot or provides or prepares a means for or
               | furnishes the money for, or takes part in, any military
               | or naval expedition or enterprise to be carried on from
               | thence against the territory or dominion of any foreign
               | prince or state, or of any colony, district, or people
               | with whom the United States is at peace, shall be fined
               | under this title or imprisoned not more than three years,
               | or both.
        
               | fluoridation wrote:
               | So what you're saying is that it's legal for an American
               | to nuke a country as long as the US is already at war
               | with that country.
        
               | glasshug wrote:
               | Ha! No, 42 U.S.C. 2122.
        
               | fluoridation wrote:
               | Nanny state.
        
               | KRAKRISMOTT wrote:
               | [flagged]
        
               | koolba wrote:
               | > Why are you making it sound like that's some profound
               | revelation?
               | 
               | I've never claimed any of my musings are profound
               | revelations. That's an exercise left to the reader.
               | 
               | > Law enforcement is allowed to run stings, serve
               | warrants and make arrests, you aren't.
               | 
               | Specifics matter. "The Government" is not some monolithic
               | entity. Even "law enforcement" could be local, State
               | level, FBI, CIA, or some other part of the executive
               | branch. Each has its own restrictions on when and how it
               | can operate.
               | 
               | > The military is allowed to invade countries and drop
               | nukes, you aren't.
               | 
               | The military is expressly disallowed from interfering in
               | civilian affairs:
               | https://en.wikipedia.org/wiki/Posse_Comitatus_Act
               | 
               | > Yes it is legal when they do it and not some average
               | Joe who wants to play hero.
               | 
               | It's an untested open question whether it's legal for
               | them to do it to US civilians or infrastructure that they
               | know is owned by US civilians.
               | 
               | It might be the right thing to do. The world might be
               | better for it. It might even be decided one day that they
               | do in fact have that power (there's a pretty clear
               | argument that stopping a botnet qualifies as "Hot
               | pursuit": https://en.wikipedia.org/wiki/Hot_pursuit).
               | 
               | > That's how the world works, and it is a good thing.
               | 
               | There's plenty of "ends justify the means" situations
               | involving the government that are not good things applied
               | more generally. Hence, specifics matter.
        
             | voz_ wrote:
             | Yeah, it's part of the social contract? This is a good
             | thing. It's the same reason I cant just grab a gun and
             | start arresting people as a "good Samaritan".
        
               | flutas wrote:
               | I mean, citizens arrest is a thing in many countries.[0]
               | Immunity varies, laws vary, but it's definitely a
               | thing...
               | 
               | [0]: https://en.wikipedia.org/wiki/Citizen%27s_arrest
        
         | anonym29 wrote:
         | There are a LOT of things I'd trust more than a closed-source
         | binary executable served by the FBI purporting to help me.
         | 
         | Gas station sushi, a drink from Bill Cosby, a childhood
         | sleepover at Michael Jackson's place, a cup of Kool Aid from
         | Jim Jones...
        
           | pjc50 wrote:
           | As compared to a closed source binary forcibly installed on
           | your machine by criminals?
        
             | [deleted]
        
             | micromacrofoot wrote:
             | To clarify a little, you mean criminals that _aren 't_ the
             | FBI? because otherwise we might get stuck in a loop here.
        
           | neovialogistics wrote:
           | I'd trust it a hell of a lot more than a binary originating
           | from any other USG letter agency, except maybe OSHA and the
           | NWS.
        
             | galleywest200 wrote:
             | NASA has a good set of open source projects available for
             | public use: https://code.nasa.gov/
        
               | anonym29 wrote:
               | Keyword: "open source", as in, you are
               | permitted/encouraged to understand what it's doing.
        
           | dcow wrote:
           | And the big question is what if your machine is configure in
           | a way that is incompatible with the FBI's justice.exe and you
           | lose irreplaceable data?
        
             | wutwutwat wrote:
             | [dead]
        
             | jstarfish wrote:
             | > And the big question is what if your machine is configure
             | in a way that is incompatible with the FBI's justice.exe
             | and you lose irreplaceable data?
             | 
             | Dude, this is just manufactured outrage. Come on:
             | 
             | > Qakbot delivered additional malware--including ransomware
             | --to their computer
             | 
             | Bemoaning the possibility of the cops trampling your
             | petunias while responding to the arsonist literally trying
             | to take-hostage-or-destroy every square inch of your
             | property is being petty.
        
               | dcow wrote:
               | I'm not outraged at all. I'm simply wondering.
               | 
               | You analogy isn't accurate. The bot net wasn't burning
               | down or bricking machines. It was leeching bandwidth and
               | cpu cycles. So a more apt analogy might be animal control
               | sniping bunnies off your petunias and hitting a window
               | with your family heirloom on display instead.
               | 
               | The only thing about this whole thing that makes me
               | double take is that it happened without permission or
               | notice. I really wouldn't be happy if I found out tue FBI
               | was rummaging around my machine removing files without my
               | consent. It's still my property and I'm sure I'd be happy
               | to cooperate if the FBI raised to my attention that there
               | was malicious software on my machine.
        
               | [deleted]
        
               | smaudet wrote:
               | The analogy is not apt.
               | 
               | In most cases the victims were not aware, meaning they
               | still had ample use of their proverbial property. This is
               | in fact the normally desired state of malware, to act
               | like a pest or a leech - your estate suffers but not in a
               | very noticeable way.
               | 
               | I think most people would object to their yard being
               | turned upside down because some e.g. illegal grasshoppers
               | were present...so in that sense yes they should provide
               | notice...if able.
               | 
               | Which is where the concept of "estate" falls apart a bit.
               | Unless you can positively map every node to a single
               | responsible actor, then it is unreasonable to provide
               | notice. Furthermore, there are so many components to
               | modern tech systems that it is not reasonable that anyone
               | would know or care the exact goings on of their systems
               | (usually).
               | 
               | That is, if you use the web and execute from it, in some
               | sense you cannot (or should not) hold fully liable any
               | one entity, in some small sense the malware has turned
               | your computer into public property anyways, so the
               | actions of the FBI are not entirely unreasonable.
               | 
               | If you cry foul this action then even more so you should
               | cry foul the actions of any public update service
               | etc...vendor updates always carry a similar risk.
               | 
               | What I could say, if there were some common message
               | format for indicating to the user what was to happen,
               | then it would be reasonable to require notification of
               | such. But likely there is no such thing so mainly this
               | argument is rhetorical.
        
             | shadowgovt wrote:
             | Legally speaking? While IANAL, looking at the warrant
             | issued and signed, the nature of such a loss would be akin
             | to any other loss incurred during a search and seizure.
             | 
             | In general, such losses are understood as incidental and
             | the searchee is not protected from them. If the police
             | smash your front door in, they aren't responsible for
             | paying to replace the lock; if they think you hid drugs in
             | your wall and take a Sawzall to it, they don't owe you
             | drywall. In the extreme, it's been found that if a
             | flashbang burns your house down during a raid, they aren't
             | liable to replace your house (even if the target of the
             | raid wasn't on that property). Warrants basically suspend
             | some civil rights temporarily; that's why they require a
             | judicial concurrence.
             | 
             | So I have no specific case citation for data loss due to a
             | digital search and seizure, but my guess from analogy is
             | that if you have an unusual configuration (cracked the
             | botnet control program open and stored your private Bitcoin
             | key in there?) and the FBI's counter-net wipes your data,
             | you will not prevail in a court of law, much as if your
             | front door was somehow load-bearing and the cops, upon
             | hitting it with the battering ram, knocked your house over.
             | But since I can't point to a _specific_ case to give
             | precedent, hey, whatever you and the lawyer you can afford
             | can argue, I guess. ;)
        
         | kvetching wrote:
         | "The FBI Supernode Module and the Qakbot Uninstaller DO NOT
         | remediate malware that was already installed on the infected
         | computer through Qakbot, such as ransomware or other malware
         | that steals financial credentials. However, the Qakbot
         | Uninstaller is designed to prevent additional malware from
         | being installed on the infected computer through the Qakbot
         | botnet by untethering the victim computer from the botnet. "
         | 
         | -https://www.justice.gov/d9/2023-08/23mj4244_application_reda..
         | .
        
         | adolph wrote:
         | > That's pretty sweet that they healed hundreds of thousands of
         | computers
         | 
         | The cynical part of me says that (1) they just installed an NSA
         | backdoor in hundreds of thousands of computers; (2) the FBI
         | probably didn't even realize it; (3) it'll all come to light
         | some years from now when the NSA tooling is leaked by a
         | careless contractor and used by various worse actors; (4) but
         | the "leak" was NSA's plan all along to spy on said various
         | worse actors.
         | 
         | The meta-cynical part of me says all that is way too convoluted
         | and I should take off the tin-foil fedora and tip it to m'lady.
        
         | georgeburdell wrote:
         | Imagine if a race condition in someone's backend was fixed by
         | being slowed down just a little bit by this malware, and then
         | the malware issue was surreptitiously fixed by the FBI and it
         | broke again
         | 
         | https://xkcd.com/1172/
        
         | pbronez wrote:
         | Pretty interesting. I bet there were a LOT of lawyer
         | conversations about that.
        
           | nickthegreek wrote:
           | FBI's been doing this for awhile now. So far no one has taken
           | them to court. I do wonder how that would end.
        
             | pfdietz wrote:
             | I wonder if the FBI could legally brick the machines
             | involved (particular if some were devices that had never
             | been patched.)
        
               | wutwutwat wrote:
               | [dead]
        
             | tw04 wrote:
             | Given the infected folks in question likely had their
             | machines involved in illegal activity, I'm not sure I'd
             | want to test it. If someone starts running a meth lab out
             | of your unlocked cellar, at what point do you become
             | culpable for not knowing?
             | 
             | And are you really going to try to sue the police for
             | shutting down the lab and locking the door on their way
             | out?
        
               | wutwutwat wrote:
               | [dead]
        
               | dcow wrote:
               | > And are you really going to try to sue the police for
               | shutting down the lab and locking the door on their way
               | out?
               | 
               | If the police enter your property without a warrant then
               | sure. The potential presence of illegal activity does not
               | grant the police special powers to skirt judicial process
               | (unless there's imminent danger to someone's life or
               | something, obviously). If the police unduly lock you out
               | of your own property on the way out then doubly sure.
               | 
               | Obviously most people will be relieved that their machine
               | no longer has malware on it (save willing participants,
               | which is a different question altogether...). What would
               | piss me off is not being notified, and not being given
               | the chance to remediate myself (what if the police damage
               | other pieces of property on the way and I could avoid the
               | damage if I'm simply made aware), etc.
               | 
               | So let's go back to the meth lab example: do you think
               | it's okay for the police to show up on your property
               | unannounced in the middle of the night while you're
               | sleeping to silently shut down the meth lab without
               | notifying you that they're trespassing and then slap a
               | lock on your basement door behind which you store your
               | emergency cash, medical supplies, prescription drug
               | refills, personal protection equipment, defensive
               | firearms, etc. without leaving the keys or so much as a
               | word?
               | 
               | Edit (two more things):
               | 
               | 1. It's possible someone might have been running a copy
               | of the botnet for research purposes, so presumably this
               | copy is not engaged in illicit activity and only
               | installed on lab hardware. I wonder if the FBI's program
               | considered this scenario. Maybe they only targeted IPs
               | involved in actual DDOS attacks? That'd be cool.
               | 
               | 2. You can question something without implying it's
               | wrong. One can both believe the FBI is acting in a
               | responsible and just way while also being curious how
               | this would play out in court. The fervor in your
               | responses seems slightly out of place considering the
               | comment you're responding to is simply raising a
               | question.
        
               | mandevil wrote:
               | Oh hey, look at that, the FBI did get a warrant
               | authorizing this action, and signed off by a United
               | States Magistrate Judge: https://www.justice.gov/d9/2023-
               | 08/23mj4244_application_reda...
               | 
               | Now, are judges sometimes too easy with warrants?
               | Certainly. But this is definitely not the same as
               | entering your house without a warrant, because the FBI
               | did get a warrant. The warrant involves them promising to
               | a judge under penalty of perjury that the Qakbot
               | Uninstaller they are using makes no further changes and
               | collects no additional data on any of the victim
               | computers they are running on.
               | 
               | So, the FBI is aware of your concerns and is taking steps
               | to alleviate them. Does that make you feel better?
        
               | dcow wrote:
               | > Oh hey, look at that (...) Does that make you feel
               | better?
               | 
               | What? Why such snide?
               | 
               | I am aware of what happened in this case. I was
               | responding rhetorically to GGP since they were presenting
               | an abstract scenario where the police show up and shut
               | down the meth lab in your basement and then lock you out
               | of your property on the way out... My goal was to
               | highlight the cases where it is and isn't okay for the
               | police to do whatever they want. It's not clear if GGP is
               | aware that there are in fact restrictions on what the
               | police can do on your private property in the US. And
               | that even with a warrant there are limits on how the
               | warrant is conducted.
        
               | networkchad wrote:
               | [dead]
        
               | tw04 wrote:
               | >If the police enter your property without a warrant then
               | sure. The potential presence of illegal activity does not
               | grant the police special powers to skirt judicial process
               | (unless there's imminent danger to someone's life or
               | something, obviously).
               | 
               | So like a computer system actively participating in ID
               | theft and DDoS attacks?
               | 
               | >If the police unduly lock you out of your own property
               | on the way out then doubly sure.
               | 
               | But patching a system doesn't lock the owner out...
               | 
               | >What would piss me off is not being notified, and not
               | being given the chance to remediate myself (what if the
               | police damage other pieces of property on the way and I
               | could avoid the damage if I'm simply made aware), etc.
               | 
               | So you're volunteering your tax dollars for the FBI to
               | track down hundreds of thousands of people across the
               | globe to let them know their systems were patched? I'm
               | not. If this upsets you: don't put unpatched systems on
               | the internet?
               | 
               | >So let's go back to the meth lab example: do you think
               | it's okay for the police to show up on your property
               | unannounced in the middle of the night while you're
               | sleeping to silently shut down the meth lab without
               | notifying you that they're trespassing and then slap a
               | lock on your basement door behind which you store your
               | emergency cash, medical supplies, prescription drug
               | refills, personal protection equipment, defensive
               | firearms, etc. without leaving the keys or so much as a
               | word?
               | 
               | You're taking the analogy to a place you know doesn't
               | exist. The police don't have a way to notify everyone
               | that's infected, expecting them to do so before shutting
               | down a major botnet is just silly and arguing for the
               | sake of arguing.
               | 
               | Nobody said they were adding a lock, I said they were
               | locking the door on their way out: the lock is already
               | there, you already have the key. When they patched these
               | systems it didn't somehow make the owner unable to login.
        
               | dcow wrote:
               | > You're taking the analogy to a place you know doesn't
               | exist. The police don't have a way to notify everyone
               | that's infected, expecting them to do so before shutting
               | down a major botnet is just silly and arguing for the
               | sake of arguing.
               | 
               | I don't think I am. If the FBI can remotely execute code
               | on my machine then they could certainly drop a
               | notification with a link to a page explaining the
               | situation and how to remediate. Or they could use any
               | number of emergency alert systems to make people aware of
               | a potentially harmful botnet. Or they could email the
               | owner of the machine instead of running their own
               | malware.
               | 
               | Anyway as I've stated I don't really disagree with the
               | outcome here. I just don't think your "let the police do
               | whatever they want to people's property it's for the
               | greater good" mentality is healthy, especially not in the
               | US where we very carefully limit the power we grant over
               | violence because we recognize property and privacy
               | rights.
               | 
               | I'm not arguing for the sake of arguing. I think it's
               | fair to ask: "could this have been conducted in a manner
               | where people were aware and could have provided consent
               | or intervened if necessary and still achieved a similar
               | result"?
               | 
               | (Misunderstood you about the lock part, thought you were
               | saying they were locking the premises because it was a
               | crime scene or something and not notifying you.)
        
               | tw04 wrote:
               | >I don't think I am. If the FBI can remotely execute code
               | on my machine then they could certainly drop a
               | notification with a link to a page explaining the
               | situation and how to remediate.
               | 
               | You're making a ton of leaps of faith that a user is
               | going to both read and follow the instructions.
               | 
               | >Or they could use any number of emergency alert systems
               | to make people aware of a potentially harmful botnet.
               | 
               | So... you want the FBI to reach out to all of the world's
               | governments and have them issue an "emergency alert" to
               | get people to patch their computers? And you think that's
               | a reasonable stance to take?
               | 
               | >Or they could email the owner of the machine instead of
               | running their own malware.
               | 
               | And they're getting these email addresses how?
               | 
               | >I just don't think your "let the police do whatever they
               | want to people's property it's for the greater good"
               | mentality is healthy, especially not in the US where we
               | very carefully limit the power we grant over violence
               | because we recognize property and privacy rights.
               | 
               | And I think you're arguing for the sake of arguing.
               | Literally nobody said "let the police do whatever they
               | want with people's property". The machines in question
               | were ACTIVELY PARTICIPATING IN ILLEGAL ACTIVITIES. This
               | isn't some philosophical debate.
        
               | nradov wrote:
               | Police can legally enter private property unannounced and
               | shut down a meth lab if it presents an imminent safety
               | hazard. This isn't trespassing. They will not be liable
               | for any loss you suffer as a result as long as their
               | actions are judged to be "reasonable". There is an
               | extensive body of case law on this (at least regarding
               | physical places, not computers).
        
               | [deleted]
        
               | reaperducer wrote:
               | _If the police enter your property without a warrant then
               | sure. The potential presence of illegal activity does not
               | grant the police special powers to skirt judicial process
               | (unless there's imminent danger to someone's life or
               | something, obviously)._
               | 
               | I guess you've never heard of "probable cause."
        
               | dcow wrote:
               | I have, in fact. _Probable cause_ is what police need to
               | have in order for a judge to issue a warrant.
        
               | hinkley wrote:
               | Probably at the moment you try to sue them for taking
               | away your volunteer meth lab.
        
               | airstrike wrote:
               | > If someone starts running a meth lab out of your
               | unlocked cellar, at what point do you become culpable for
               | not knowing?
               | 
               | The problem with analogies is that they assume they are
               | correctly "analogous" but 9/10 times they really describe
               | an entirely different situation, making them unhelpful if
               | not misleading
        
               | ToValueFunfetti wrote:
               | The problem with analogies is that people who disagree
               | tend to just say "X is not Y" instead of "X is different
               | from Y in this context due to Z". I'm not sure whether
               | that is just a social behavior or if saying the second
               | thing is especially hard.
        
               | rzzzt wrote:
               | A duck is not a horse due to... it not being a horse. You
               | can macroexpand Z to "not having four legs", etc., but
               | incomparable things will end up being different just
               | based on their very essence.
        
               | ToValueFunfetti wrote:
               | "Why can't I pull a small wagon with a team of ducks? I
               | can pull a large wagon with a team of horses."
               | 
               | Useful answers: Ducks are not as intelligent as horses
               | and aren't as easy to train. There is not a good way to
               | strap a harness onto a duck for this task. Ducks waddle
               | and this introduces turbulence. Ducks have substantially
               | less pulling power. etc.
               | 
               | Useless answer: A duck is not a horse because a duck is
               | different from a horse.
               | 
               | The person making the analogy knows that it is an
               | analogy; it is not the source of confusion.
        
               | airstrike wrote:
               | It's not especially hard -- the burden of proof just
               | isn't on the listener. Saying "X is not Y" is just saying
               | "I'm not convinced, you must do better with your
               | analogies". With enough context, one can infer as much
               | 
               | Letting someone run a meth lab in your cellar is pretty
               | obviously not the same as "letting" some malware run on
               | your box, for crying out loud
        
               | anonym29 wrote:
               | >If someone starts running a meth lab out of your
               | unlocked cellar, at what point do you become culpable for
               | not knowing?
               | 
               | Are you implying that the property owner is liable
               | because they neglected to lock the cellar, or because
               | they weren't aware a crime was taking place there?
               | 
               | If the former, isn't that as clear an example of victim
               | blaming as telling people to carry firearms/protection if
               | they don't want to be sexually assaulted?
               | 
               | In a civil society, it is not the responsibility or duty
               | of the victim to set up security measures to prevent
               | themselves from being victimized. It is the
               | responsibility and duty of the culprit to not commit
               | those unlawful crimes in the first place.
               | 
               | Bringing the analogy back to security - who is guilty of
               | a crime when a ransomware attack happens, the victim, or
               | the criminal (who obtained unauthorized access, and used
               | that access to perform extortion)?
        
               | shkkmo wrote:
               | Landlords can indeed be liable is many ways for some
               | kinds of illegal activity that take place on their
               | property (especially if it involves drugs.) There are a
               | variety of local and federal laws that enable this.
        
               | wutwutwat wrote:
               | [dead]
        
               | tw04 wrote:
               | >or because they weren't aware a crime was taking place
               | there?
               | 
               | If someone is running a meth lab out of your cellar for a
               | year, and you don't notice the smell, the power bill, the
               | people coming and going, at what point are you no longer
               | able to claim ignorance? If your answer is: you can claim
               | ignorance indefinitely, what is preventing someone from
               | just letting a meth lab be run from their basement and
               | taking cash on the side? If the police can't find the
               | cash, you're just not guilty?
               | 
               | >It is not the responsibility of the victim to set up
               | security measures to prevent themselves from being
               | victimized.
               | 
               | It is ABSOLUTELY the responsibility of the "victim" to
               | not create an environment that FACILITATES crime. If you
               | leave a gun unsupervised and unlocked on your front step,
               | and a neighbor kid "steals" the gun off your front steps
               | and proceeds to shoot and kill their friend, you are
               | going to jail despite you being the "victim" of theft.
               | Your internet connection in this instance is the loaded
               | gun when your systems are being used in DDoS attacks.
        
               | AndrewKemendo wrote:
               | Yes, and there's plenty of case law to support that -
               | 
               | In fact, one of the most popular TV shows of all time had
               | its finale specifically addressing the fact that a law
               | needed to be made to discourage "bystanders" from
               | actively ignoring crime.
        
               | lelanthran wrote:
               | Which show was this?
        
               | kevinh wrote:
               | Probably Seinfeld.
        
               | nirvdrum wrote:
               | Seinfeld.
        
               | dcow wrote:
               | > and taking cash on the side
               | 
               | With this statement you're arguing past the person you're
               | responding to. If you are taking cash on the side to
               | feign ignorance when the DEA comes squawking about the
               | meth lab in your basement then you are clearly in the
               | know.
               | 
               | Nobody is talking about negligence here. Your rebuttal is
               | essentially "well victims can be blamed if they're being
               | negligent". Yeah, sure, by definition they're not just a
               | victim, they're a negligent individual. (I mean I'd even
               | argue they can be blamed for less--I'm not one of those
               | 100% the victim is always innocent types, but that's a
               | different topic.)
               | 
               | The original question is if you are _honestly unaware
               | (and not negligent)_ that your property is being used to
               | commit a crime, are you culpable for the crime? The
               | answer is a resounding "no".
               | 
               | If someone hacks your PC and installs botnet software,
               | and it evades your OS antivirus heuristics and
               | protections because it's a sophisticated root-kit, then
               | no, you're not culpable.
        
               | tw04 wrote:
               | >With this statement you're arguing past the person
               | you're responding to. If you are taking cash on the side
               | to feign ignorance when the DEA comes squawking about the
               | meth lab in your basement then you are clearly in the
               | know.
               | 
               | Ironic that you're doing what you accused me of. I didn't
               | say the person was taking cash, I asked WHEN op would
               | consider the person to be culpable. You literally took an
               | entire discussion and clipped four words then made up a
               | bunch of stuff I didn't actually say or even imply.
               | 
               | >The original question is if you are honestly unaware
               | (and not negligent) that your property is being used to
               | commit a crime, are you culpable for the crime? The
               | answer is a resounding "no".
               | 
               | That was NOT the original question. The original question
               | was whether or not someone could sue the police for
               | removing malware and patching their system. My example
               | was the cops shutting down a meth lab and locking the
               | door.
               | 
               | Be my guest attempting to sue, and be prepared to have to
               | defend yourself in a court of law that you were truly
               | unaware. That's going to be a VERY expensive proposition
               | - so who in their right mind would even start down that
               | path?
        
           | ip_addr wrote:
           | Here's the application and search warrant.
           | 
           | https://www.justice.gov/d9/2023-08/23mj4244_application_reda.
           | ..
           | 
           | https://www.justice.gov/d9/2023-08/23mj4244_warrant_redacted.
           | ..
        
             | libraryatnight wrote:
             | This was really interesting to read, thank you for the
             | links.
        
             | doakes wrote:
             | I'm getting 403'd on these links
        
               | AtomicOrbital wrote:
               | Links work
        
           | hanniabu wrote:
           | It's the government, since when are they concerned about
           | legality
        
             | revscat wrote:
             | More often than you'd think.
        
           | verve_rat wrote:
           | My question: how does a US warrant apply to computers outside
           | US jurisdiction?
        
             | paxys wrote:
             | They didn't access any random computers outside of their
             | jurisdiction, only Qakbot servers.
        
               | paganel wrote:
               | I must have missed it, but does the article mention that
               | those servers were all located inside the US? (where I
               | supposed FBI has jurisdiction for stuff like this).
        
               | [deleted]
        
               | paxys wrote:
               | > As part of the operation, the FBI gained lawful access
               | to Qakbot's infrastructure and identified over 700,000
               | infected computers worldwide--including more than 200,000
               | in the U.S.
               | 
               | "Lawful access" is doing a lot of heavy lifting, but at
               | least they specified it.
        
               | wutwutwat wrote:
               | [dead]
        
         | jagged-chisel wrote:
         | Having been around during the 90s Cryptowars (and related
         | culture and counterculture) I do wonder if in a few years we'll
         | hear that NSA piggybacked some "fun" toys on this uninstaller.
        
         | jszymborski wrote:
         | Am I missing something or wouldn't the author(s) of Qakbot be
         | able to avoid this attack by cryptographically signing commands
         | and having clients check them?
        
           | paxys wrote:
           | It doesn't matter. If you gain access to their servers you
           | can sign the commands yourself.
        
             | rcxdude wrote:
             | Depends on where the key is. Command and control servers
             | don't need to have the keys for the commands they are
             | relaying.
        
           | datadeft wrote:
           | I am pretty sure that is not their top priority.
        
           | chilmers wrote:
           | From https://www.secureworks.com/blog/law-enforcement-takes-
           | down-...
           | 
           | "To interact with infected hosts, the replacement servers
           | required a certificate that can sign messages. It appears
           | that the certificates were obtained and used for good
           | intentions."
        
         | shadowgovt wrote:
         | One of my favorite tricks in dealing with botnets: if you can
         | access the control plane, you can convince the network to do
         | most anything... Including self-terminate.
        
           | 1-6 wrote:
           | Until bot operators learn to encrypt the control plane
           | network.
        
             | apstls wrote:
             | This was the case here as well.
        
         | [deleted]
        
       | cynicalsecurity wrote:
       | [flagged]
        
         | soligern wrote:
         | Why? Windows is not inherently less secure than MacOS or Linux.
        
         | psd1 wrote:
         | Absolutely false.
         | 
         | If all the world's grannies used Ubuntu, malware writers would
         | target Ubuntu, and the spam would include links to Ubuntu
         | malware. Same for any arbitrary other OS.
        
         | joemazerino wrote:
         | Tell me you haven't worked in an Enterprise environment without
         | telling me
        
           | cynicalsecurity wrote:
           | My whole life. That's why I'm begging to kill it.
        
             | maximinus_thrax wrote:
             | You need to read up on how Pwn2Own came into existence.
        
             | politelemon wrote:
             | I wish you a longer life then. There is a lot to learn
             | about security, and your conclusions are not among them.
        
         | mvdwoord wrote:
         | [flagged]
        
           | codeslave13 wrote:
           | Personal attacks arent really called for. I disagree with op
           | but really?
        
           | Madmallard wrote:
           | he's right in that windows is horrible spyware cancer made
           | continually worse by an insanely anti-consumer corporation
           | and would be better off gone at this point had it not won the
           | capitalism game
        
             | capableweb wrote:
             | He's also wrong thinking that malware is more possible on
             | Windows than other OSes, rather than that Windows is a more
             | popular target because it's the most popular OS in the
             | world.
        
             | psd1 wrote:
             | That's valid, but the thrust of the top-level comment is
             | that the computers are infected because they were windows
             | (sounds plausible) with the implication that if windows
             | were not the dominant desktop OS, malware would not exist
             | (which is improbable).
             | 
             | Malware is only rare for MacOS and Linux because those are
             | niche OSes, not because of inherently higher resistance.
        
         | nickthegreek wrote:
         | Ahhh yes, there is no way windows could be targeted because it
         | is the most popular OS (especially in Business). Removing
         | Windows would allow us to live a malware free utopia...
        
         | nilsherzig wrote:
         | There already are pretty advanced Linux viruses and I would
         | assume that they would be even more advanced and wide spread if
         | Linux was the primary desktop os
        
       | coldblues wrote:
       | > To disrupt the botnet, the FBI redirected Qakbot traffic to
       | Bureau-controlled servers that instructed infected computers to
       | download an uninstaller file. This uninstaller--created to remove
       | the Qakbot malware--untethered infected computers from the botnet
       | and prevented the installation of any additional malware.
       | 
       | So the FBI used unauthorized access to the computers to uninstall
       | the malware? Scary if you think about it. I'm sure they could
       | have used that access any way they wanted.
        
         | Angostura wrote:
         | What would have been a better alternative?
        
           | nicechianti wrote:
           | [dead]
        
         | acdha wrote:
         | Say I left my car unlocked and it starts spewing smoke - is it
         | scary if the fire department break in to put it out? Or if my
         | abandoned building is housing rats, is it okay for the city to
         | break in and deal with them?
         | 
         | The FBI is far from perfect but this is the kind of thing they
         | _should_ be doing, using their unique privileges to help with
         | public menaces. Anyone on the internet could compromise them,
         | too, so I'd prefer a public cleanup.
        
           | willnonya wrote:
           | The problem may be we'll within the FBI domain but their
           | resolution crosses some boundaries that are meant to be
           | protected. To pull this off the FBI would need to use a
           | general warrant rather than a specific warrant as required by
           | law.
           | 
           | In your examples none of them invole solving problems that
           | you would not be unaware of, in ways that you're not aware of
           | without telling you they were there and oh btw they had to
           | rifle through your undwrware drawer to fix it.
        
             | acdha wrote:
             | > In your examples none of them invole solving problems
             | that you would not be unaware of, in ways that you're not
             | aware of without telling you they were there and oh btw
             | they had to rifle through your undwrware drawer to fix it.
             | 
             | It's pretty common for there to be problems the owner can't
             | be reached for - people travel, get hospitalized, die, etc.
             | - but that doesn't prevent action. What it can do is limit
             | what they're allowed to bring charges for - in your
             | example, if they said they were pursuing reports of
             | squatters in your house they couldn't search inside your
             | dresser since that's not in plain sight.
             | 
             | In this case, I would expect that courts would give the FBI
             | considerable leeway for neutralizing a system which is
             | being actively used to commit crimes but not to check your
             | private data to see if you were cheating on your taxes.
        
           | cool_dude85 wrote:
           | It's context dependent. If I'm filming a movie and want to
           | get a scene where a car is spewing smoke, and the FD runs up
           | while I'm filming to put it out, that is troublesome to me.
           | 
           | It seems like this might be the case here where some
           | minuscule portion of the botnet base is security research
           | firms / etc. who have a reason to have the botnet software
           | installed and don't want it deleted; in fact, it may even
           | affect their livelihood to delete it.
        
             | Teever wrote:
             | That's a very contrived example.
             | 
             | It's Also why people normally get a permit or at least
             | contact officials to tell them that they're going to do
             | staging a scene that looks exactly like an accident/crime
             | scene.
             | 
             | It isn't a strike against emergency responders for
             | responding to a situation that someone has staged to look
             | as close to the real thing as possible.
        
             | acdha wrote:
             | > It seems like this might be the case here where some
             | minuscule portion of the botnet base is security research
             | firms / etc. who have a reason to have the botnet software
             | installed and don't want it deleted; in fact, it may even
             | affect their livelihood to delete it.
             | 
             | This doesn't make any sense to me: no ethical security firm
             | is going to allow their resources to be used to attack
             | other people, or complain if the FBI shut down the people
             | attacking their clients.
        
             | Loughla wrote:
             | We have to call the local FD if we want to do a controlled
             | burn of a field or fence row. If we don't, nobody is
             | surprised when they show up to put out the fire.
             | 
             | I have to imagine this is similar. If your livelihood
             | relies on a botnet, and you don't at least let authorities
             | know, my guess is you're not a researcher. . .
        
             | [deleted]
        
             | WoahNoun wrote:
             | The mythbuster's didn't blow stuff up or set things on fire
             | without having the FD there.
        
               | mrguyorama wrote:
               | Most of the time they had to have explicit "Bomb Squad"
               | presence, and did things explicitly at bomb ranges.
               | 
               | One time they still managed to damage something outside
               | of the vast location (an abandoned airport I believe)
               | they were working within, and were banned from that
               | location.
        
             | bastardoperator wrote:
             | Your example doesn't make sense though given the context.
             | You can't just light a car on fire for filming purposes.
             | You're going to need to at the very least petition the
             | local government, get a permit, and follow safety protocols
             | that will likely include the presence of the fire
             | department.
             | 
             | This reminds me of frivolous lawsuits. A doctor sees
             | someone needing medical attention. The doctor performs CPR,
             | break some ribs in the process, but ultimately saves their
             | life. The person who would have otherwise died, sues the
             | doctor for breaking their ribs while completely ignoring
             | the good will that saved them from certain death.
        
         | codedokode wrote:
         | Today they clean your computer from botnet, tomorrow from
         | bitcoin.
        
           | riversflow wrote:
           | Yup, and people actually think crypto is viable.
        
         | gwright wrote:
         | There are many situations where law enforcement is authorized
         | (by law) to do something that would normally be illegal. For
         | example here is some language from 18 U.S. Code SS 1030 - Fraud
         | and related activity in connection with computers:
         | 
         | > This section does not prohibit any lawfully authorized
         | investigative, protective, or intelligence activity of a law
         | enforcement agency of the United States, a State, or a
         | political subdivision of a State, or of an intelligence agency
         | of the United States.
         | 
         | I'm not sure if this is the relevant code for this Qakbot
         | incident, I'm just trying to clarify that the law generally
         | accepts that law enforcement officials get special dispensation
         | from the regular requirements of the law in order to carry out
         | their function or to protect the public.
        
         | waihtis wrote:
         | They wouldn't need to do any redirecting if they had direct
         | access to the computer, they could just directly install the
         | patch/fix.
         | 
         | Sounds like they hijacked a malware proxy server and had it
         | forward the traffic to their own server.
        
           | poyu wrote:
           | Perhaps those computers count as evidence and they don't want
           | to mess with it?
        
             | waihtis wrote:
             | perhaps, but more likely it's a bit dubious for the FBI to
             | penetrate into computers unauthorized, even if the
             | intentions are good
        
         | r3trohack3r wrote:
         | > So the FBI used unauthorized access to the computers to
         | uninstall the malware? Scary if you think about it. I'm sure
         | they could have used that access any way they wanted.
         | 
         | The access was always possible. Not just by the FBI. In fact,
         | it was already being accessed by the botnet operators. The
         | issue here is _permission_ and _precedent_. The government gave
         | itself permission to go into these computers and cleanup the
         | botnet. What explicit permission did they grant themselves and
         | what precedent does that set?
         | 
         | I'm pretty hesitant/paranoid about the U.S. government and the
         | powers we (citizens) grant them. But this one surprisingly sits
         | right with me. It looks thoughtfully applied and constrained -
         | a very tactical operation to go in and cleanup a botnet without
         | accessing any unnecessary data in the process.
         | 
         | https://www.justice.gov/d9/2023-08/23mj4244_application_reda...
        
           | ipaddr wrote:
           | The access was possible but not legal but they gave
           | themselves legal access. It's a slippy slope. They have
           | placed an unknown file as well on your computer.
        
         | pjc50 wrote:
         | Police have huge amounts of leeway to wreck stuff and kill
         | people, which do not appear to have happened in this case
         | compared to the mere _possibility_ of abuse.
         | 
         | Meanwhile in the physical world
         | https://reason.com/volokh/2021/11/30/federal-court-rules-tak...
        
         | apstls wrote:
         | This was clearly a large-scale coordinated effort spanning
         | multiple countries, multiple organizations within the US
         | including DOJ lawyers, named and unnamed industry partners,
         | etc. This is not a context in which a single group could do
         | unethical clandestine things without the knowledge and buy-in
         | of other parties, nor would it be something the FBI team
         | working this case would have any incentive to do. They were
         | tasked with dismantling this botnet and removing the malware
         | from victim machines, and that is what they did.
        
         | [deleted]
        
         | mzs wrote:
         | They got a warrant to run the uninstaller and gather evidence:
         | https://www.justice.gov/d9/2023-08/23mj4244_application_reda...
        
           | hanniabu wrote:
           | _this_ time they got a warrant
        
       | jordana36 wrote:
       | [flagged]
        
       | jordana36 wrote:
       | [flagged]
        
       | jordana36 wrote:
       | [flagged]
        
       | jordana36 wrote:
       | [flagged]
        
       | jordana36 wrote:
       | [flagged]
        
       | yafbum wrote:
       | Cool use of the botnet's capabilities against itself
       | 
       | But no arrests announced? I wish the people responsible for this
       | were made an example of, as opposed to being basically free to
       | start over (it seems).
        
         | 0xDEF wrote:
         | Most of the large-scale botnet and ransomware activities are
         | operating out of Russia. Not exactly a country that is going to
         | collaborate with US law enforcement.
        
         | hnburnsy wrote:
         | Yes where are the arrests or elimiation of the threat. There
         | are 17 three letter agencies listed in Wikipedia entry for DNI.
         | Couldn`t one of them worked to `take care` of this botnet
         | operator?
        
           | paxys wrote:
           | > Couldn`t one of them worked to `take care` of this botnet
           | operator?
           | 
           | Unless they want to start a war with Russia, probably not.
        
         | whimsicalism wrote:
         | They are probably outside of US jursidiction and also seizing
         | servers is much easier than catching a cybercriminal who
         | actually knows how to cover their tracks.
        
           | hnburnsy wrote:
           | This feels like the fire department congratulating it self
           | for putting out fires instead of capturing the arsonist.
        
             | simpleuser27 wrote:
             | Isn't that exactly what the fire department should be
             | doing?
             | 
             | I don't understand the criticism, could you explain why you
             | view this in a negative light?
        
               | rurp wrote:
               | Arresting people is a pretty core part of the FBI's job.
        
               | I_Am_Nous wrote:
               | I think the point they are trying to make is that there
               | will still be fires started by the arsonist, so
               | celebrating a single fire being put out while the
               | arsonist is likely busy trying to start another fire
               | looks bad. Even though, as you point out, the Fire
               | Department isn't going to be making any arrests for
               | arson, that's the Police Department's job.
               | 
               | I'm not sure the analogy applies perfectly anyway, since
               | it was "only" a single "fire" in which "only" 700,000
               | victims were affected.
        
         | mrguyorama wrote:
         | Russia, North Korea, Iran, and the other places that harbor
         | cybercrime enterprises rarely agree to extradition.
        
       | autoexec wrote:
       | If it's really finally fully down that's great, but it took
       | forever and replacements can be churned out and new networks
       | grown in a very short amount of time.
       | 
       | I'm glad the FBI invested 15+ years and who knows how much money
       | to rid the world of QBot, but this isn't a scalable solution to
       | the botnet problem.
        
         | ryukoposting wrote:
         | I don't think it's the FBI's job to figure out a scalable
         | solution to botnets. That's our job.
        
       | badrabbit wrote:
       | I wouldn't make a big deal out of this, unlike worms, "bots" like
       | this will come back after weeks/months because of the number of
       | people involved and the spread of the malware "kit" (including
       | server side stuff). They are constantly adapting anyways, there
       | isn't a fixed set if domains and IPs you can block to stop it
       | permanently.
       | 
       | They took down emotet as well but it's had a resurgence.
       | 
       | Qakbot in recent years has shifted to a initial access broker
       | monetization scheme where it sells access (cobaltrsike,etc...) to
       | more serious actors who will pay the access fee instead of hiring
       | talent themselves to do the hacking. So they have a strong
       | community of customers. They will need to arrest a lot of people
       | at once and hope they got all the people needed to revive it.
        
       ___________________________________________________________________
       (page generated 2023-08-29 23:00 UTC)