Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - News & Analysis - FBI Dismantles QakBot Botnet In Largest-Ever Cybercrime Operation
News & Analysis Attacks Threat Intelligence Threats and Vulnerabilities

FBI Dismantles QakBot Botnet In Largest-Ever Cybercrime Operation

ISBuzz TeamBy ISBuzz TeamAugust 31, 2023Updated:August 24, 20243 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
botnet
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Operation Duck Hunt Seizes 52 Servers, Over $8.6 Million in Cryptocurrency

In a groundbreaking achievement that marks a significant win for global cybersecurity, the FBI, leading a multinational law enforcement coalition, has dismantled QakBot, a notorious malware loader heavily exploited by cybercriminals.

Inside Operation Duck Hunt

Code-named “Operation Duck Hunt,” the FBI gained privileged access to the administrative systems of QakBot, mapping its complex server architecture. The operation led to the seizure of 52 servers, effectively crippling the botnet infrastructure and redirecting its traffic to FBI-controlled servers. The U.S. Department of Justice (DoJ) confirmed that this action will permanently dismantle the QakBot botnet.

Key Stats:

– Over 700,000 infected computers worldwide identified

– More than 200,000 infected systems in the U.S.

– $8.6 million in cryptocurrency seized

Multinational Partnerships Yield Success

This operation is the culmination of collective efforts from law enforcement agencies across France, Germany, the Netherlands, Romania, Latvia, and the UK. Technical partnerships included the U.S. Cybersecurity and Infrastructure Security Agency (CISA), Microsoft’s Digital Crimes Unit, and the National Cyber Forensics and Training Alliance (NCFTA), among others. Private firms like Have I Been Pwned and Zscaler also aided in victim notification and remediation.

Financial Impact and Scope of Operation

Donald Alway, Assistant Director in Charge of the FBI’s Los Angeles Field Office, mentioned that the operation will thwart countless cyberattacks, thereby safeguarding both personal and critical infrastructure. The financial toll exacted by QakBot is enormous; the malware’s administrators are said to have accrued fees approximating $58 million in ransoms from October 2021 to April 2023.

The Evolution of QakBot

Originating as a banking trojan in 2008, QakBot evolved to become a leading malware delivery service used for ransomware attacks, data theft, and other malicious activities. Employing spam emails for initial deployment, QakBot was instrumental in a variety of ransomware attacks, serving as a primary enabler for high-profile ransomware groups like Conti, ProLock, Egregor, REvil, and others.

A Historical Context

The joint effort builds on the precedent set by the takedown of Emotet in 2020, another notorious malware family. However, the current operation is distinct for its scale, described as the “largest U.S.-led financial and technical disruption of a botnet infrastructure.”

Future Implications

With QakBot servers now offline, as corroborated by data from Abuse.ch, this marks a significant milestone in the battle against global cybercrime. Yet, the ever-adaptive nature of cybercriminal tactics, as seen in QakBot’s evolution, signifies an ongoing challenge for law enforcement agencies and cybersecurity experts alike.

Keep an eye on our information security news updates as we continue to monitor FBI Dismantles QakBot Botnet In Largest-Ever Cybercrime Operation and check how the security experts respond to this news.

Industry Reactions

Below are the industry reactions that sent us comments on this information security news:

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Foxconn confirms cyberattack following Nitrogen ransomware claims

May 14, 20263 Mins Read

Lazarus Group Turns to Medusa Ransomware in Escalating Global Extortion Campaign

February 26, 20263 Mins Read

The Cyberattack That Exposed the Fragility of Digital Heritage

February 11, 20268 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}