How the FBI took down the Qakbot botnet
techcrunch.com
techcrunch.com
It's also an important censorship apparatus, but that just needs to be "good enough," and is more dependent on domestic companies (the same who benefited from the degradation of Western services) following regulations to remove content on their websites.
FBI, partners dismantle Qakbot infrastructure - https://news.ycombinator.com/item?id=37310772 - Aug 2023 (171 comments)
Regardless I think it’s an interesting question as well but my position is that if these machines are already compromised I’d rather have them run the “uninstaller” than the victims continue to receive commands from the botnet controller and cause additional collateral damage.
That said, I would imagine the pop up would be where this is going over time.
If an autonomous driving car is taken over by a hacker, and starts running people over, how fast would you expect the police to block it/shoot its tires?
https://www.justice.gov/d9/2023-08/23mj4244_warrant_redacted...
impossible is the wrong word here, its just unnecessary. The Feds can (and do) definitely contact domestic & international ISPs to perform near 100% accurate lookups.
do you have a better analogy thats not an appeal to authority? we’re not in grade school anymore and so not every authority is deputized for every thing
Edit: doesn’t Ford and others with the constant connectivity already have something like this?
You could probably challenge the warrant in court, fortunately that won’t reinstall the botnet but if you also feel this causes you damages, you can further aim to get paid for those damages
Good luck with that if you were an operator
In hindsight it's super crazy that this was a thing and probably still is.
About these operations, I honestly think they're not that spectacular even though they make it seem so. Anyone can buy a license for a random botnet for a couple of bucks and reverse engineer what's going on on compromised systems. I'm sure most of these botnets are hacked together pieces of junk code, which gathered a lot of installs through sheer luck and the fact that the FBI was looking away for a while.
I've done some limited consulting in this space in my career, and I agree that the code (and architecture) I've seen is pretty brittle junk. It's on par with the worst enterprise code I've seen. It's a numbers game for them. And, it's just a different work experience and skill tree that drives people to create "great code" (as it would be measured in professional software development circles.)
The question isn’t “is this possible and has anyone ever done it” - it was was “has the FBI ever used a botnet’s existing C&C patch all the infected hosts”?
It doesn’t seem like it, but I don’t track this stuff closely so I’m happy to be corrected.
Win10 69.46%
Win11 26.74%
Win7 2.42%
Win8.1 0.72%
Win8 0.35%
WinXP 0.18%
This means 3.67% run an unsupported Windows OS.If we estimate one Windows computer per person in the USA on average (~ 331.9 mil.), this means that more than 12 mil. computers run an unsupported Windows OS. (Or use your own estimate.)