[HN Gopher] How the FBI took down the Qakbot botnet
       ___________________________________________________________________
        
       How the FBI took down the Qakbot botnet
        
       Author : pseudolus
       Score  : 53 points
       Date   : 2023-09-01 15:08 UTC (7 hours ago)
        
 (HTM) web link (techcrunch.com)
 (TXT) w3m dump (techcrunch.com)
        
       | playday wrote:
       | Due to some recently revealed corruption issues in the USA that
       | the fbi was covering up, there's more drama than usual regarding
       | funding. Expect to see lots of fbi fluff pieces until their
       | funding is secured.
        
       | mavamaarten wrote:
       | In my younger years I was very fascinated by malware, it's what
       | got me into IT eventually. Back then I was active on some forums
       | with marketplaces where one could easily buy and sell such
       | services. I didn't do anything serious besides some slightly gray
       | area stuff, but never sold or bought anything or compromised any
       | unwilling victim. I did know some people who were later caught by
       | the FBI and spent a long time in prison though.
       | 
       | In hindsight it's super crazy that this was a thing and probably
       | still is.
       | 
       | About these operations, I honestly think they're not that
       | spectacular even though they make it seem so. Anyone can buy a
       | license for a random botnet for a couple of bucks and reverse
       | engineer what's going on on compromised systems. I'm sure most of
       | these botnets are hacked together pieces of junk code, which
       | gathered a lot of installs through sheer luck and the fact that
       | the FBI was looking away for a while.
        
         | [deleted]
        
         | nahsra wrote:
         | The FBI took control of the botnet and re-purposed it to patch
         | the vulnerable machines. This sounds like a novel practice
         | addition to me?
         | 
         | I've done some limited consulting in this space in my career,
         | and I agree that the code (and architecture) I've seen is
         | pretty brittle junk. It's on par with the worst enterprise code
         | I've seen. It's a numbers game for them. And, it's just a
         | different work experience and skill tree that drives people to
         | create "great code" (as it would be measured in professional
         | software development circles.)
        
           | asynchronous wrote:
           | It's not novel at all - security researchers have been doing
           | the same thing for literally decades. Worms often have kill
           | switches built into them, that if the researchers can figure
           | out allow them to stop it globally.
        
       | coldcode wrote:
       | 200,000 Windows PCs in the US among the 600,000 total worldwide.
       | Are there really that many Windows PCs still running vulnerable
       | old OS versions, or were they zero-days in more modern OS
       | versions? These articles never say much about the details.
        
         | [deleted]
        
       | master_crab wrote:
       | I read this as Quakebot and thought "The government is finally
       | getting serious about these Quake hackers and cheaters."
        
       | gdcbe wrote:
       | [flagged]
        
         | [deleted]
        
       | what-no-tests wrote:
       | [flagged]
        
         | [deleted]
        
       | dang wrote:
       | Recent and related:
       | 
       |  _FBI, partners dismantle Qakbot infrastructure_ -
       | https://news.ycombinator.com/item?id=37310772 - Aug 2023 (171
       | comments)
        
       | charcircuit wrote:
       | Did the FBI get permission to run their software on all those
       | machines? This seems illegal.
        
         | yieldcrv wrote:
         | The FBI has broad authority from Congress to engage in
         | cyberwarfare extraterritoriality , and they also got a broad
         | warrant for anything that happened to be in the United States
         | 
         | You could probably challenge the warrant in court, fortunately
         | that won't reinstall the botnet but if you also feel this
         | causes you damages, you can further aim to get paid for those
         | damages
         | 
         | Good luck with that if you were an operator
        
         | ipython wrote:
         | You should read through the search warrant to see the lengths
         | that they went through to get permission from the courts to do
         | so.
         | 
         | Regardless I think it's an interesting question as well but my
         | position is that if these machines are already compromised I'd
         | rather have them run the "uninstaller" than the victims
         | continue to receive commands from the botnet controller and
         | cause additional collateral damage.
        
           | itake wrote:
           | They didn't know where all the machines were physically
           | located and thus did not have permission from the court
           | system in those countries.
        
             | ipython wrote:
             | The operation was performed in concert with other
             | governments. See https://www.justice.gov/opa/pr/qakbot-
             | malware-disrupted-inte.... I've worked with some of the
             | partners involved on previous operations and they are top
             | notch - while like I said I think this is a legitimate
             | argument either way (should governments have the ability to
             | actively disrupt malicious activity), I am on the side of
             | taking action as has been done here.
        
               | Ylpertnodi wrote:
               | So no problem if others break the law (in foreign
               | countries, too), then? "Top notch"? I wonder ifvthat
               | would apply to the feds in other countries 'fixing' US
               | computers. Nb. Not having a dog inbthe fight, I doverr
               | towards keeping anyone the fuck out of my pc. I could
               | appreciate a pop-up though, explaingvwhatcwas going on
               | and how to fix it.
        
               | smilespray wrote:
               | If they can display a pop-up, they're already in your
               | computer running code.
        
               | ipython wrote:
               | In this case there is someone already "the fuck in your
               | pc". It's just a group of cyber criminals looking to
               | monetize said pc with mostly illicit activity. As the
               | sibling pointed out, the pop up would require code
               | execution so ... they would necessarily be in your pc
               | already.
               | 
               | That said, I would imagine the pop up would be where this
               | is going over time.
        
         | flextheruler wrote:
         | There is a link in the article to the multiple warrants the FBI
         | were able to get. I'm guessing that most likely has the answer.
        
         | shmatt wrote:
         | They did, though they really shouldn't need to
         | 
         | If an autonomous driving car is taken over by a hacker, and
         | starts running people over, how fast would you expect the
         | police to block it/shoot its tires?
        
           | munchler wrote:
           | This is a poor analogy. Most of the infected computers that
           | the FBI accessed aren't even located in the US. The FBI has
           | no jurisdiction in those countries.
        
             | Rewrap3643 wrote:
             | Correct, which is why the warrant was limited to computers
             | in the United States (I don't know how they went about this
             | in practice).
             | 
             | https://www.justice.gov/d9/2023-08/23mj4244_warrant_redacte
             | d...
        
               | mulmen wrote:
               | To go back to the car analogy this is like the police
               | getting approval to shoot the tires and then closing
               | their eyes when they pull the trigger.
        
               | parl_match wrote:
               | They said they retrieved IP addresses and "routing
               | information", doing fine grained geo ip lookups is
               | impossible, but the accuracy of country of origin is very
               | high, especially in the US
        
           | yieldcrv wrote:
           | Right the municipal police would be the authority to do that,
           | not the FBI
           | 
           | do you have a better analogy thats not an appeal to
           | authority? we're not in grade school anymore and so not every
           | authority is deputized for every thing
        
           | bozhark wrote:
           | If AI vehicles don't have a kill switch they should be sued
           | into oblivion.
        
             | what-no-tests wrote:
             | This kind of thinking only works when you can trust the
             | folks who have access to that switch.
        
               | bozhark wrote:
               | The manufacturer?
               | 
               | Edit: doesn't Ford and others with the constant
               | connectivity already have something like this?
        
       | kunwon1 wrote:
       | [flagged]
        
         | [deleted]
        
       | JohnMakin wrote:
       | I don't really see from this explanation what prevents a new wave
       | of infected machines from contacting the Tier 2 layer. It seems
       | like they just cut off Tier 1 access of existing infections. Yes,
       | they took over the cloud account, but I don't see what's really
       | stopping the bad actors from starting over (with lessons learned
       | probably as to what got them caught the first time).
        
       | [deleted]
        
       | SeanAnderson wrote:
       | It's surprising how much publicity this is getting without making
       | any arrests. I would've thought they'd have arrested people
       | before publishing anything. I wonder if they've been able to
       | identify the people, or if they were just able to undo the
       | technical maliciousness?
        
         | dralley wrote:
         | If it's like the last half a dozen botnets that the FBI has
         | taken down, it's being managed from China or Russia, and thus
         | their chances of arresting anyone are close to nil.
        
           | zirgs wrote:
           | If those botnets can be controlled through the Great Firewall
           | - does that mean that they're sanctioned by the Chinese
           | government?
        
             | e40 wrote:
             | No way to know, since regular citizens (even ones not that
             | technical) can get through the Great Firewall.
        
               | chatmasta wrote:
               | The GFW is mostly a protectionist racket. By degrading
               | the services of Western companies, the GFW gave their
               | Chinese counterparts an opportunity to catch up to them,
               | despite starting later (e.g. Google leaves China, creates
               | opportunity for Baidu, etc.).
               | 
               | It's also an important censorship apparatus, but that
               | just needs to be "good enough," and is more dependent on
               | domestic companies (the same who benefited from the
               | degradation of Western services) following regulations to
               | remove content on their websites.
        
       | intrasight wrote:
       | Great article. Also I just gotta share this. The story, if
       | transported back in time a few decades and written as a sci-fi
       | book would make a great read. Truth is stranger than fiction.
        
         | [deleted]
        
       | boredumb wrote:
       | I was using a browser earlier this week that didn't have ad block
       | on (testing things). I was inundated with ads for a job at FBI.
       | Weird coincidence but sure is a lot of FBI related marketing all
       | of a sudden.
        
       | vuln wrote:
       | [flagged]
        
         | [deleted]
        
       | bigfryo wrote:
       | [flagged]
        
         | [deleted]
        
       ___________________________________________________________________
       (page generated 2023-09-01 23:01 UTC)