The FBI led an effort to dismantle the Qakbot botnet, which ransomware gangs used as an infection vector for years, on August 25 after infiltrating its network
It was live on 700k endpoints (!) which should give you an idea of the scale of cybersecurity woes at many orgs (it's still really, really bad out there). X: Nick Carr / @itsreallynick : payments.txt - seemed like a good idea at the time π [image] @abuse_ch : Quak π¦! Goodbye #Qakbot, I hope we won't see you ever again π. And this is how it looks like from Feodo Tracker' perspective β¬οΈ. All #botnet C2s are offline π https://feodotracker.abuse.ch/ ... Tango down! πͺ [image] @usao_losangeles : United States Attorney Martin Estrada, accompanied by Donald Alway, the assistant director in charge of the FBI's Los Angeles Field Office, federal prosecutors and other law enforcement officials, addresses the media about the DOJ and FBI's Qakbot cybercrime takedown. [image] Florian Roth / @cyb3rops : I've added the hash of the Qakbot uninstaller & YARA rule for LOKI/THOR Lite users to check if systems were infected with #Qakbot &cleaned by the FBI/Dutch Police in the operation https://www.justice.gov/... on @virustotal you see that it was already uploaded from various countries [image] Will / @bushidotoken : π―#Qakbot Botnet Takedown in Operation Duck Hunt! π» 700,000 Victim Computers π° $8.6m in cryptocurrency seized by DOJ π° Qakbot has earned $58m in ransoms π Qakbot used by Conti, ProLock, Egregor, REvil, MegaCortex, and Black Basta ransomware groups https://www.justice.gov/... Eric Geller / @ericgeller : And here's the announcement: https://www.fbi.gov/... https://www.justice.gov/... βOne of the largest-ever U.S.-led enforcement actions against a botnet,β with activity in the U.S., the U.K., France, Germany, the Netherlands, Romania, and Latvia. [image] @neiltking : This is brilliant. Instead of it installing #Malware or #Ransomware as it was usually instructed, they tricked the botnet into running an uninstaller on itself. Nice. They basically did a βSuperman 2β to it π Preston Byrne / @prestonjbyrne : Actually amazing work by the FBI: not only did they take down a botnet, they also hijacked it and forced it to uninstall from all its victims' computers https://www.fbi.gov/... Nick Carr / @itsreallynick : Qakbot operators built their threat model around their moms finding their secret files. π€£ [image] @fbi : Today, #FBI Director Christopher Wray announced a Bureau-led operation that crippled a long-running botnet. Just in the past year, this botnet infected approximately 700,000 computers. Learn how the FBI restored control to victims: https://www.fbi.gov/... [video] @usao_losangeles : Qakbot malware disrupted in international cyber takedown https://www.justice.gov/... Eric Geller / @ericgeller : A senior FBI official told CNN that Qakbot took βyears to put togetherβ and βit would be difficult and time consumingβ for cyber criminals to rebuild it. The official βestimated that Qakbot had caused hundreds of millions of direct or indirect losses to victims since 2008.β @k8em0 : The phenomenon of making a machine you don't own do something you want it to do is referred to as βhackingβ or βpwningβ. The FBI did this for defensive purposes to uninstall malware. In Wassenaar-defined export control, this exceeds the exemptions for defense. Can't pwn to re-own @anfam17 : Wow, that's a big win! π @haveibeenpwned : New sensitive breach: The FBI in conjunction with international law enforcement partners today announced the takedown of the Qakbot malware. The FBI subsequently provided 6.43M email addresses to @haveibeenpwned. 57% were already pwned. Read more: https://www.troyhunt.com/... Troy Hunt / @troyhunt : Very happy to see the Qakbot malware knocked offline! Also happy to be able to assist the @FBI by making the data searchable in @haveibeenpwned, here's the full story: https://www.troyhunt.com/... Lorenzo Franceschi-Bicchierai / @lorenzofb : NEW: The FBI shut down the infrastructure belonging to the infamous Qakbot malware. And in the process they also tricked the victim computers into removing the malware, with an uninstaller created for the FBI. https://techcrunch.com/... Waymon / @obnoxious4n6 : qakbot admins waking up this morning [video] @vxunderground : Today the Federal Bureau of Investigation announced they have dismantled the Qakbot botnet. Qakbot has been one of the longest standing botnets in history, dating back to 2011. FBI Director Christopher Wray made an announcement regarding the takedown: https://www.youtube.com/... Eric Geller / @ericgeller : Qakbot, which has been operating for ~15 years, recently became popular with ransomware gangs. The botnet infected roughly 700k victims worldwide, with 200k in the U.S. Officials removed the malware from βan unspecified number of infected computers,β per CNN. @max_mal_ : #Qakbot β .... [image] @silascutler : Qakbot uninstaller from @FBI https://www.virustotal.com/... https://www.justice.gov/... LinkedIn: Ohad Zaidenberg : This is HUGE.Β βΒ A significant step forward in global cybersecurity against ransomware threat:Β βΒ The Qakbot botnet - a notable cyber threat β¦ Forums: Hacker News : FBI, partners dismantle Qakbot infrastructure r/hacking : FBI, Partners Dismantle Qakbot Infrastructure in Multinational Cyber Takedown
Context & Ripple Effects
This operation extends a law-enforcement playbook visible in the Hive network infiltration and seizure of its decryption keys: gain access to criminal infrastructure, then use that access to disrupt victimsβ exposure at scale. Here, the reach included an uninstaller on compromised machines and a large set of email addresses shared for breach notification.
Qakbot was a shared access layer for several ransomware groups rather than a single gangβs end product. That makes its removal consequential beyond its operators; the later DOJ case against an alleged Qakbot leader shows the campaignβs arc also moved from infrastructure disruption toward alleged operator accountability.
First-order effects
- Organizations with Qakbot-infected devices receive immediate remediation through the FBI-driven uninstaller, while Have I Been Pwned can help notify addresses associated with the operation.
- Ransomware groups named as Qakbot users lose an established infection vector, and Qakbot operators lose command-and-control infrastructure and cryptocurrency tied to the operation.
Second-order effects
- Affected organizations must still investigate whether Qakbot access was used for follow-on ransomware activity; removal of the loader does not by itself resolve any prior intrusion.
- Ransomware affiliates and access brokers are pushed to replace a disrupted delivery channel, while defenders can prioritize the indicators and exposed-address data released through the takedown.
Third-order effects
- The case reinforces ecosystem cyber defense: coordinated cross-border action can target reusable criminal infrastructure that serves multiple ransomware brands, not only individual extortion incidents.
- Disruption is not necessarily durable eradication: the earlier TrickBot disruption left some command-and-control servers online, underscoring that sustained operational and victim-side cleanup remains necessary if adversaries rebuild.
The trend: Ransomware defense is increasingly shifting toward multinational disruption of the shared botnet, proxy, and access infrastructure that enables many separate attacks.