In a court-authorized March operation, the FBI cut off the servers of the Cyclops Blink botnet, tied to Russia's Sandworm, from Asus and WatchGuard routers
TechCrunch Zack Whittaker
Related Coverage
- Justice Department Announces Court-Authorized Disruption of Botnet Controlled by the Russian Federation's Main Intelligence Directorate (GRU) U.S. Department of Justice
- U.S. Says It Secretly Removed Malware Worldwide, Pre-empting Russian Cyberattacks New York Times
- WatchGuard failed to explicitly disclose critical flaw exploited by Russian hackers Ars Technica
- The FBI silently removed Russian malware to thwart global cyberattacks Engadget
- US dismantled the Russia-linked Cyclops Blink botnet Security Affairs
- US disrupts Russian Cyclops Blink botnet before being used in attacks BleepingComputer
- Cyclops Blink FAQs techsearch.watchguard.com
- The Cyclops Blink botnet has been disrupted Help Net Security
- US Action Disrupts Russian Botnet Cyclops Blink Infosecurity
- Massive Russian Botnet Targeting Asus Routers Disrupted Before It Could Attack, FBI Says Gizmodo
- FBI secretly took down massive Russian botnet last month TechRadar
- FBI Shut Down Russia-linked “Cyclops Blink” Botnet That Infected Thousands of Devices The Hacker News
- Feds take down Kremlin-backed Cyclops Blink botnet The Register
- U.S. FBI says it foiled a cyberattack by Russian hackers Reuters
Discussion
-
@malwaretechblog
Marcus Hutchins
on x
A decade ago you'd have gotten shouted out of the room for suggesting hacking systems to remove malware. I guess at some point people realized having philosophical debates on ethics doesn't actually stop the bad guys. https://www.justice.gov/...
-
@b_judah
Ben Judah
on x
Is Russia also losing the cyberwar? https://www.nytimes.com/...
-
@ericgarland
Eric Garland
on x
AMAZING: DOJ indicts *Russian military intelligence* for running a botnet 🤣🔥⚖️ https://www.justice.gov/...
-
@zackwhittaker
Zack Whittaker
on x
I recast my earlier incorrect tweet, which stated that compromised devices themselves were targeted by the operation — similar to how the FBI removed backdoors from Exchange servers last year. Apologies for the error.
-
@zackwhittaker
Zack Whittaker
on x
According to the court order, only about 39% of compromised routers were fixed in the weeks that followed the initial advisory on February 23, which the DOJ used to justify the mass-removal operation (https://t.co/...). Here's the full court order: https://www.documentcloud.org/ …
-
@profwoodward
Alan Woodward
on x
The real fight against Russian cyber aggression looks more like this story by @zackwhittaker than the “cyberwar” predicted elsewhere https://techcrunch.com/...
-
@zackwhittaker
Zack Whittaker
on x
FBI said it mass-removed the “Cyclops Blink” malware from devices but that device owners still need to take action to prevent re-infection. Cyclops Blink is part of a huge botnet run by Sandworm, known for launching destructive cyberattacks. https://techcrunch.com/...
-
@campuscodi
Catalin Cimpanu
on x
The DOJ said that together with international partners it has disrupted a botnet operated by Russian's GRU military intelligence service. No names or confirmation yet, but this appears to have been Sandworm's Cyclops Blink (?) Presser from an hour ago: https://www.justice.gov/liv…