HomeSecurityFBI: International operation led to the shutdown of the Qakbot botnet

FBI: International operation led to the shutdown of Qakbot botnet

The FBI announced the shutdown of the notorious Qakbot (Qbot) botnet , which was achieved thanks to an international law enforcement operation. Authorities were able to seize the botnet's infrastructure and uninstall the malware from infected devices.

FBI Qakbot botnet

During the operation dubbed Operation Duck Hunt that took place over the weekend, the FBI redirected the botnet's network communications to servers under its control, allowing agents to locate approximately 700,000 infected devices (200,000 of which are located in the US).

After taking control of the botnet, the FBI devised a method to uninstall the malware from victims' computers

What is the Qakbot botnet?

Before we get into the details of how the FBI uninstalled the Qakbot botnet from infected computers, let's look at a few things about the botnet itself and how it operates.

Qakbot, also known as Qbot and Pinkslipbot, began as a banking trojan in 2008.It was used to steal banking credentials, website cookies, and credit cards.

However, over time, it evolved into a malware delivery service used by various cybercriminals to gain initial access to networks and to carry out ransomware attacks , data theft, and other malicious activities.

See also: P2PInfect malware: Attacks on SSH and Redis to create botnets

Qakbot is mainly distributed through phishing emails that use various baits (depending on the target) and contain malicious attachments or links to download malicious files that install the Qakbot malware on a user's device.

Attachments can be Word or Excel documents with malicious macros, OneNote files with embedded files, and ISO attachments with Windows executables and shortcuts. Some of these are also designed to exploit zero-day vulnerabilities in Windows.

Once the Qakbot botnet is installed on a computer, it will install itself into the memory of legitimate Windows processes, such as wermgr.exe or AtBroker.exe, to try to avoid detection by security software.

Once the malware is launched, it will scan for information it is interested in stealing. The stolen information is used for future phishing.

FBI Qakbot botnet

Cooperation with ransomware groups

The operators of the Qakbot malware have also collaborated with other hacking groups, including ransomware gangs.

They have, for example, collaborated with the ransomware gangs Conti, ProLock, Egregor, REvil, RansomExx, MegaCortex, Black Basta and BlackCat/ALPHV.

The FBI says that between October 2021 and April 2023, Qakbot operators earned approximately $58 million in ransomware payments.

How did the FBI destroy the Qakbot botnet?

The FBI said it was able to dismantle the botnet by taking over the attacker's server infrastructure and creating a special tool that uninstalled Qakbot from infected devices.

According to a search warrant applicationreleased by the Department of Justice, the FBI was able to gain access to Qakbot admin computers, allowing law enforcement to map the infrastructure used to operate the botnet.

See also: QakBot, SocGholish and Raspberry Robin: The most popular malware loaders of 2023

Based on its investigation, the FBI found that the Qakbot botnet used Tier-1, Tier-2, and Tier-3 command and control servers, which are used to issue commands for execution, install malware updates, and download additional malicious payloads.

Tier-1 servers are infected devices with a “supernode” module that acts as part of the botnet’s command and control infrastructure, with some of the victims located in the U.S. Tier-2 servers are also command and control servers, but Qakbot operators operate them, usually from rented servers outside the U.S.

The FBI says that both Tier-1 and Tier-2 servers are used to relay encrypted communication to Tier-3 servers.

These Tier-3 servers act as central command and control servers for issuing new commands for execution, new malicious software modules (for download), and malware (for installation by botnet partners, such as ransomware).

Every 1 to 4 minutes, the Qakbot malware on infected devices contacted a built-in list of Tier-1 servers to establish encrypted communication with a Tier-3 server and receive commands to execute or new payloads to install.

Qbot

However, after the FBI infiltrated Qakbot's infrastructure and the administrator's devices, it was able to gain access to the encryption keys used to communicate with these servers.

Using these keys, the FBI used an infected device under its control to contact each Tier-1 server and have it replace the already installed Qakbot “supernode” module with one created by law enforcement.

The new supernode module controlled by the FBI used different encryption keys that were unknown to the Qakbot operators, effectively cutting them off from their own command and control infrastructure, as they no longer had any way to communicate with Tier-1 servers.

The FBI then created a custom Windows DLL (or Qakbot module) [VirusTotal] that acted as a malware removal tool and was pushed to infected devices from Tier-1 servers.

This custom Windows DLL issued the QPCMD_BOT_SHUTDOWN to the Qakbot malware running on infected devices, causing the malware process to stop executing.

See also: MMRat: Learn everything about the new Android banking malware

The FBI says this tool was approved by a judge to remove the Qakbot botnet from infected devices.

At this time, the FBI is unsure of the total number of devices that have been “cleaned” in this way, but as the process began over the weekend, it expects more devices to be freed of the malware.

The FBI also shared a database containing stolen credentials with Have I Been Pwned and the Dutch National Police.

Qbot

Since no notifications will be displayed on infected devices when the malware is removed, users can use these services to see if their credentials have been stolen. This way, they can discover if they were infected by Qakbot at some point.

This law enforcement operation was certainly a great success, however it may not be the end of the operation as no arrests were made. Therefore, Qakbot operators may try to rebuild their infrastructure in the near future.

Qakbot was one of the most well-known and dangerous botnets. Thanks to its efficient architecture and high adaptability, it was able to survive for many years and become one of the most dangerous tools in the hands of cybercriminals. However, authorities managed to “clean up” thousands of infected computers.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS