[HN Gopher] How the FBI took down the Qakbot botnet
___________________________________________________________________
How the FBI took down the Qakbot botnet
Author : pseudolus
Score : 53 points
Date : 2023-09-01 15:08 UTC (7 hours ago)
(HTM) web link (techcrunch.com)
(TXT) w3m dump (techcrunch.com)
| playday wrote:
| Due to some recently revealed corruption issues in the USA that
| the fbi was covering up, there's more drama than usual regarding
| funding. Expect to see lots of fbi fluff pieces until their
| funding is secured.
| mavamaarten wrote:
| In my younger years I was very fascinated by malware, it's what
| got me into IT eventually. Back then I was active on some forums
| with marketplaces where one could easily buy and sell such
| services. I didn't do anything serious besides some slightly gray
| area stuff, but never sold or bought anything or compromised any
| unwilling victim. I did know some people who were later caught by
| the FBI and spent a long time in prison though.
|
| In hindsight it's super crazy that this was a thing and probably
| still is.
|
| About these operations, I honestly think they're not that
| spectacular even though they make it seem so. Anyone can buy a
| license for a random botnet for a couple of bucks and reverse
| engineer what's going on on compromised systems. I'm sure most of
| these botnets are hacked together pieces of junk code, which
| gathered a lot of installs through sheer luck and the fact that
| the FBI was looking away for a while.
| [deleted]
| nahsra wrote:
| The FBI took control of the botnet and re-purposed it to patch
| the vulnerable machines. This sounds like a novel practice
| addition to me?
|
| I've done some limited consulting in this space in my career,
| and I agree that the code (and architecture) I've seen is
| pretty brittle junk. It's on par with the worst enterprise code
| I've seen. It's a numbers game for them. And, it's just a
| different work experience and skill tree that drives people to
| create "great code" (as it would be measured in professional
| software development circles.)
| asynchronous wrote:
| It's not novel at all - security researchers have been doing
| the same thing for literally decades. Worms often have kill
| switches built into them, that if the researchers can figure
| out allow them to stop it globally.
| coldcode wrote:
| 200,000 Windows PCs in the US among the 600,000 total worldwide.
| Are there really that many Windows PCs still running vulnerable
| old OS versions, or were they zero-days in more modern OS
| versions? These articles never say much about the details.
| [deleted]
| master_crab wrote:
| I read this as Quakebot and thought "The government is finally
| getting serious about these Quake hackers and cheaters."
| gdcbe wrote:
| [flagged]
| [deleted]
| what-no-tests wrote:
| [flagged]
| [deleted]
| dang wrote:
| Recent and related:
|
| _FBI, partners dismantle Qakbot infrastructure_ -
| https://news.ycombinator.com/item?id=37310772 - Aug 2023 (171
| comments)
| charcircuit wrote:
| Did the FBI get permission to run their software on all those
| machines? This seems illegal.
| yieldcrv wrote:
| The FBI has broad authority from Congress to engage in
| cyberwarfare extraterritoriality , and they also got a broad
| warrant for anything that happened to be in the United States
|
| You could probably challenge the warrant in court, fortunately
| that won't reinstall the botnet but if you also feel this
| causes you damages, you can further aim to get paid for those
| damages
|
| Good luck with that if you were an operator
| ipython wrote:
| You should read through the search warrant to see the lengths
| that they went through to get permission from the courts to do
| so.
|
| Regardless I think it's an interesting question as well but my
| position is that if these machines are already compromised I'd
| rather have them run the "uninstaller" than the victims
| continue to receive commands from the botnet controller and
| cause additional collateral damage.
| itake wrote:
| They didn't know where all the machines were physically
| located and thus did not have permission from the court
| system in those countries.
| ipython wrote:
| The operation was performed in concert with other
| governments. See https://www.justice.gov/opa/pr/qakbot-
| malware-disrupted-inte.... I've worked with some of the
| partners involved on previous operations and they are top
| notch - while like I said I think this is a legitimate
| argument either way (should governments have the ability to
| actively disrupt malicious activity), I am on the side of
| taking action as has been done here.
| Ylpertnodi wrote:
| So no problem if others break the law (in foreign
| countries, too), then? "Top notch"? I wonder ifvthat
| would apply to the feds in other countries 'fixing' US
| computers. Nb. Not having a dog inbthe fight, I doverr
| towards keeping anyone the fuck out of my pc. I could
| appreciate a pop-up though, explaingvwhatcwas going on
| and how to fix it.
| smilespray wrote:
| If they can display a pop-up, they're already in your
| computer running code.
| ipython wrote:
| In this case there is someone already "the fuck in your
| pc". It's just a group of cyber criminals looking to
| monetize said pc with mostly illicit activity. As the
| sibling pointed out, the pop up would require code
| execution so ... they would necessarily be in your pc
| already.
|
| That said, I would imagine the pop up would be where this
| is going over time.
| flextheruler wrote:
| There is a link in the article to the multiple warrants the FBI
| were able to get. I'm guessing that most likely has the answer.
| shmatt wrote:
| They did, though they really shouldn't need to
|
| If an autonomous driving car is taken over by a hacker, and
| starts running people over, how fast would you expect the
| police to block it/shoot its tires?
| munchler wrote:
| This is a poor analogy. Most of the infected computers that
| the FBI accessed aren't even located in the US. The FBI has
| no jurisdiction in those countries.
| Rewrap3643 wrote:
| Correct, which is why the warrant was limited to computers
| in the United States (I don't know how they went about this
| in practice).
|
| https://www.justice.gov/d9/2023-08/23mj4244_warrant_redacte
| d...
| mulmen wrote:
| To go back to the car analogy this is like the police
| getting approval to shoot the tires and then closing
| their eyes when they pull the trigger.
| parl_match wrote:
| They said they retrieved IP addresses and "routing
| information", doing fine grained geo ip lookups is
| impossible, but the accuracy of country of origin is very
| high, especially in the US
| yieldcrv wrote:
| Right the municipal police would be the authority to do that,
| not the FBI
|
| do you have a better analogy thats not an appeal to
| authority? we're not in grade school anymore and so not every
| authority is deputized for every thing
| bozhark wrote:
| If AI vehicles don't have a kill switch they should be sued
| into oblivion.
| what-no-tests wrote:
| This kind of thinking only works when you can trust the
| folks who have access to that switch.
| bozhark wrote:
| The manufacturer?
|
| Edit: doesn't Ford and others with the constant
| connectivity already have something like this?
| kunwon1 wrote:
| [flagged]
| [deleted]
| JohnMakin wrote:
| I don't really see from this explanation what prevents a new wave
| of infected machines from contacting the Tier 2 layer. It seems
| like they just cut off Tier 1 access of existing infections. Yes,
| they took over the cloud account, but I don't see what's really
| stopping the bad actors from starting over (with lessons learned
| probably as to what got them caught the first time).
| [deleted]
| SeanAnderson wrote:
| It's surprising how much publicity this is getting without making
| any arrests. I would've thought they'd have arrested people
| before publishing anything. I wonder if they've been able to
| identify the people, or if they were just able to undo the
| technical maliciousness?
| dralley wrote:
| If it's like the last half a dozen botnets that the FBI has
| taken down, it's being managed from China or Russia, and thus
| their chances of arresting anyone are close to nil.
| zirgs wrote:
| If those botnets can be controlled through the Great Firewall
| - does that mean that they're sanctioned by the Chinese
| government?
| e40 wrote:
| No way to know, since regular citizens (even ones not that
| technical) can get through the Great Firewall.
| chatmasta wrote:
| The GFW is mostly a protectionist racket. By degrading
| the services of Western companies, the GFW gave their
| Chinese counterparts an opportunity to catch up to them,
| despite starting later (e.g. Google leaves China, creates
| opportunity for Baidu, etc.).
|
| It's also an important censorship apparatus, but that
| just needs to be "good enough," and is more dependent on
| domestic companies (the same who benefited from the
| degradation of Western services) following regulations to
| remove content on their websites.
| intrasight wrote:
| Great article. Also I just gotta share this. The story, if
| transported back in time a few decades and written as a sci-fi
| book would make a great read. Truth is stranger than fiction.
| [deleted]
| boredumb wrote:
| I was using a browser earlier this week that didn't have ad block
| on (testing things). I was inundated with ads for a job at FBI.
| Weird coincidence but sure is a lot of FBI related marketing all
| of a sudden.
| vuln wrote:
| [flagged]
| [deleted]
| bigfryo wrote:
| [flagged]
| [deleted]
___________________________________________________________________
(page generated 2023-09-01 23:01 UTC)