/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← β†’ days Β· ↑ ↓ browse Β· Enter similar Β· o open

The FBI led an effort to dismantle the Qakbot botnet, which ransomware gangs used as an infection vector for years, on August 25 after infiltrating its network

It was live on 700k endpoints (!) which should give you an idea of the scale of cybersecurity woes at many orgs (it's still really, really bad out there). X: Nick Carr / @itsreallynick : payments.txt - seemed like a good idea at the time πŸ˜… [image] @abuse_ch : Quak πŸ¦†! Goodbye #Qakbot, I hope we won't see you ever again πŸ‘‹. And this is how it looks like from Feodo Tracker' perspective ⬇️. All #botnet C2s are offline πŸ›‘ https://feodotracker.abuse.ch/ ... Tango down! πŸ’ͺ [image] @usao_losangeles : United States Attorney Martin Estrada, accompanied by Donald Alway, the assistant director in charge of the FBI's Los Angeles Field Office, federal prosecutors and other law enforcement officials, addresses the media about the DOJ and FBI's Qakbot cybercrime takedown. [image] Florian Roth / @cyb3rops : I've added the hash of the Qakbot uninstaller & YARA rule for LOKI/THOR Lite users to check if systems were infected with #Qakbot &cleaned by the FBI/Dutch Police in the operation https://www.justice.gov/... on @virustotal you see that it was already uploaded from various countries [image] Will / @bushidotoken : 🎯#Qakbot Botnet Takedown in Operation Duck Hunt! πŸ’» 700,000 Victim Computers πŸ’° $8.6m in cryptocurrency seized by DOJ πŸ’° Qakbot has earned $58m in ransoms πŸ”’ Qakbot used by Conti, ProLock, Egregor, REvil, MegaCortex, and Black Basta ransomware groups https://www.justice.gov/... Eric Geller / @ericgeller : And here's the announcement: https://www.fbi.gov/... https://www.justice.gov/... β€œOne of the largest-ever U.S.-led enforcement actions against a botnet,” with activity in the U.S., the U.K., France, Germany, the Netherlands, Romania, and Latvia. [image] @neiltking : This is brilliant. Instead of it installing #Malware or #Ransomware as it was usually instructed, they tricked the botnet into running an uninstaller on itself. Nice. They basically did a β€œSuperman 2” to it πŸ˜‚ Preston Byrne / @prestonjbyrne : Actually amazing work by the FBI: not only did they take down a botnet, they also hijacked it and forced it to uninstall from all its victims' computers https://www.fbi.gov/... Nick Carr / @itsreallynick : Qakbot operators built their threat model around their moms finding their secret files. 🀣 [image] @fbi : Today, #FBI Director Christopher Wray announced a Bureau-led operation that crippled a long-running botnet. Just in the past year, this botnet infected approximately 700,000 computers. Learn how the FBI restored control to victims: https://www.fbi.gov/... [video] @usao_losangeles : Qakbot malware disrupted in international cyber takedown https://www.justice.gov/... Eric Geller / @ericgeller : A senior FBI official told CNN that Qakbot took β€œyears to put together” and β€œit would be difficult and time consuming” for cyber criminals to rebuild it. The official β€œestimated that Qakbot had caused hundreds of millions of direct or indirect losses to victims since 2008.” @k8em0 : The phenomenon of making a machine you don't own do something you want it to do is referred to as β€œhacking” or β€œpwning”. The FBI did this for defensive purposes to uninstall malware. In Wassenaar-defined export control, this exceeds the exemptions for defense. Can't pwn to re-own @anfam17 : Wow, that's a big win! πŸ† @haveibeenpwned : New sensitive breach: The FBI in conjunction with international law enforcement partners today announced the takedown of the Qakbot malware. The FBI subsequently provided 6.43M email addresses to @haveibeenpwned. 57% were already pwned. Read more: https://www.troyhunt.com/... Troy Hunt / @troyhunt : Very happy to see the Qakbot malware knocked offline! Also happy to be able to assist the @FBI by making the data searchable in @haveibeenpwned, here's the full story: https://www.troyhunt.com/... Lorenzo Franceschi-Bicchierai / @lorenzofb : NEW: The FBI shut down the infrastructure belonging to the infamous Qakbot malware. And in the process they also tricked the victim computers into removing the malware, with an uninstaller created for the FBI. https://techcrunch.com/... Waymon / @obnoxious4n6 : qakbot admins waking up this morning [video] @vxunderground : Today the Federal Bureau of Investigation announced they have dismantled the Qakbot botnet. Qakbot has been one of the longest standing botnets in history, dating back to 2011. FBI Director Christopher Wray made an announcement regarding the takedown: https://www.youtube.com/... Eric Geller / @ericgeller : Qakbot, which has been operating for ~15 years, recently became popular with ransomware gangs. The botnet infected roughly 700k victims worldwide, with 200k in the U.S. Officials removed the malware from β€œan unspecified number of infected computers,” per CNN. @max_mal_ : #Qakbot ❌ .... [image] @silascutler : Qakbot uninstaller from @FBI https://www.virustotal.com/... https://www.justice.gov/... LinkedIn: Ohad Zaidenberg : This is HUGE.Β  β€”Β  A significant step forward in global cybersecurity against ransomware threat:Β  β€”Β  The Qakbot botnet - a notable cyber threat … Forums: Hacker News : FBI, partners dismantle Qakbot infrastructure r/hacking : FBI, Partners Dismantle Qakbot Infrastructure in Multinational Cyber Takedown

BleepingComputer Sergiu Gatlan

Context & Ripple Effects

This operation extends a law-enforcement playbook visible in the Hive network infiltration and seizure of its decryption keys: gain access to criminal infrastructure, then use that access to disrupt victims’ exposure at scale. Here, the reach included an uninstaller on compromised machines and a large set of email addresses shared for breach notification.

Qakbot was a shared access layer for several ransomware groups rather than a single gang’s end product. That makes its removal consequential beyond its operators; the later DOJ case against an alleged Qakbot leader shows the campaign’s arc also moved from infrastructure disruption toward alleged operator accountability.

First-order effects

  • Organizations with Qakbot-infected devices receive immediate remediation through the FBI-driven uninstaller, while Have I Been Pwned can help notify addresses associated with the operation.
  • Ransomware groups named as Qakbot users lose an established infection vector, and Qakbot operators lose command-and-control infrastructure and cryptocurrency tied to the operation.

Second-order effects

  • Affected organizations must still investigate whether Qakbot access was used for follow-on ransomware activity; removal of the loader does not by itself resolve any prior intrusion.
  • Ransomware affiliates and access brokers are pushed to replace a disrupted delivery channel, while defenders can prioritize the indicators and exposed-address data released through the takedown.

Third-order effects

  • The case reinforces ecosystem cyber defense: coordinated cross-border action can target reusable criminal infrastructure that serves multiple ransomware brands, not only individual extortion incidents.
  • Disruption is not necessarily durable eradication: the earlier TrickBot disruption left some command-and-control servers online, underscoring that sustained operational and victim-side cleanup remains necessary if adversaries rebuild.

The trend: Ransomware defense is increasingly shifting toward multinational disruption of the shared botnet, proxy, and access infrastructure that enables many separate attacks.

Discussion

  • @silascutler @silascutler on x
    Qakbot uninstaller from @FBI https://www.virustotal.com/... https://www.justice.gov/...
  • @cyb3rops Florian Roth on x
    I've added the hash of the Qakbot uninstaller & YARA rule for LOKI/THOR Lite users to check if systems were infected with #Qakbot &cleaned by the FBI/Dutch Police in the operation https://www.justice.gov/... on @virustotal you see that it was already uploaded from various countri…
  • @itsreallynick Nick Carr on x
    payments.txt - seemed like a good idea at the time πŸ˜… [image]
  • @abuse_ch @abuse_ch on x
    Quak πŸ¦†! Goodbye #Qakbot, I hope we won't see you ever again πŸ‘‹. And this is how it looks like from Feodo Tracker' perspective ⬇️. All #botnet C2s are offline πŸ›‘ https://feodotracker.abuse.ch/ ... Tango down! πŸ’ͺ [image]
  • @usao_losangeles @usao_losangeles on x
    United States Attorney Martin Estrada, accompanied by Donald Alway, the assistant director in charge of the FBI's Los Angeles Field Office, federal prosecutors and other law enforcement officials, addresses the media about the DOJ and FBI's Qakbot cybercrime takedown. [image]
  • @bushidotoken Will on x
    🎯#Qakbot Botnet Takedown in Operation Duck Hunt! πŸ’» 700,000 Victim Computers πŸ’° $8.6m in cryptocurrency seized by DOJ πŸ’° Qakbot has earned $58m in ransoms πŸ”’ Qakbot used by Conti, ProLock, Egregor, REvil, MegaCortex, and Black Basta ransomware groups https://www.justice.gov/...
  • @ericgeller Eric Geller on x
    And here's the announcement: https://www.fbi.gov/... https://www.justice.gov/... β€œOne of the largest-ever U.S.-led enforcement actions against a botnet,” with activity in the U.S., the U.K., France, Germany, the Netherlands, Romania, and Latvia. [image]
  • @neiltking @neiltking on x
    This is brilliant. Instead of it installing #Malware or #Ransomware as it was usually instructed, they tricked the botnet into running an uninstaller on itself. Nice. They basically did a β€œSuperman 2” to it πŸ˜‚
  • @prestonjbyrne Preston Byrne on x
    Actually amazing work by the FBI: not only did they take down a botnet, they also hijacked it and forced it to uninstall from all its victims' computers https://www.fbi.gov/...
  • @itsreallynick Nick Carr on x
    Qakbot operators built their threat model around their moms finding their secret files. 🀣 [image]
  • @fbi @fbi on x
    Today, #FBI Director Christopher Wray announced a Bureau-led operation that crippled a long-running botnet. Just in the past year, this botnet infected approximately 700,000 computers. Learn how the FBI restored control to victims: https://www.fbi.gov/... [video]
  • @usao_losangeles @usao_losangeles on x
    Qakbot malware disrupted in international cyber takedown https://www.justice.gov/...
  • @ericgeller Eric Geller on x
    A senior FBI official told CNN that Qakbot took β€œyears to put together” and β€œit would be difficult and time consuming” for cyber criminals to rebuild it. The official β€œestimated that Qakbot had caused hundreds of millions of direct or indirect losses to victims since 2008.”
  • @k8em0 @k8em0 on x
    The phenomenon of making a machine you don't own do something you want it to do is referred to as β€œhacking” or β€œpwning”. The FBI did this for defensive purposes to uninstall malware. In Wassenaar-defined export control, this exceeds the exemptions for defense. Can't pwn to re-own
  • @anfam17 @anfam17 on x
    Wow, that's a big win! πŸ†
  • @haveibeenpwned @haveibeenpwned on x
    New sensitive breach: The FBI in conjunction with international law enforcement partners today announced the takedown of the Qakbot malware. The FBI subsequently provided 6.43M email addresses to @haveibeenpwned. 57% were already pwned. Read more: https://www.troyhunt.com/...
  • @troyhunt Troy Hunt on x
    Very happy to see the Qakbot malware knocked offline! Also happy to be able to assist the @FBI by making the data searchable in @haveibeenpwned, here's the full story: https://www.troyhunt.com/...
  • @lorenzofb Lorenzo Franceschi-Bicchierai on x
    NEW: The FBI shut down the infrastructure belonging to the infamous Qakbot malware. And in the process they also tricked the victim computers into removing the malware, with an uninstaller created for the FBI. https://techcrunch.com/...
  • @obnoxious4n6 Waymon on x
    qakbot admins waking up this morning [video]
  • @vxunderground @vxunderground on x
    Today the Federal Bureau of Investigation announced they have dismantled the Qakbot botnet. Qakbot has been one of the longest standing botnets in history, dating back to 2011. FBI Director Christopher Wray made an announcement regarding the takedown: https://www.youtube.com/...
  • @ericgeller Eric Geller on x
    Qakbot, which has been operating for ~15 years, recently became popular with ransomware gangs. The botnet infected roughly 700k victims worldwide, with 200k in the U.S. Officials removed the malware from β€œan unspecified number of infected computers,” per CNN.
  • @max_mal_ @max_mal_ on x
    #Qakbot ❌ .... [image]
  • r/hacking r on reddit
    FBI, Partners Dismantle Qakbot Infrastructure in Multinational Cyber Takedown