U.S. Says It Removed Malware Worldwide, Pre-Empting Russian Cyberattack
nytimes.com
nytimes.com
The court orders allowed the F.B.I. to go into domestic corporate networks and remove the malware, sometimes without the company’s knowledge.
This is actually extremely freaky.Russian botnets and cyberattacks are a legitimate threat to Western countries, especially right now, but a legitimate threat also makes a perfect cover.
The C&C takeover can happen a number of ways, from DGA reverse engineering (where you register a bunch of domains that the DGA will eventually pick to communicate with, a common way for non-government entities to do it), all the way up to state-level DNS or BGP hijacking.
A lot of malware that’s distributed is pretty flexible, as it is rarely intended for a single purpose. Today data exfiltration is as lucrative in ransom as destructive encryption, and some other way of extorting companies may get popular tomorrow, so the bad guys like to keep their options open. The small bright side to this is that if you can get control of the C&C channels, you can use that flexibility to tell the malware to remove itself. In the past this technique has even been used to patch vulnerabilities…
Maybe someday the HN comment section will realize that U.S. intelligence is actually competent.
Maybe they just cut a few key networking pipes to stop the connections to Russia?
Not that I'm against them you know, fighting or defending in the cyberwar, but still feels fishy.