In a massive global crackdown, a cybercriminal botnet known as Qakbot has been disrupted by a multinational operation involving actions in the United States, France, Germany, the Netherlands, the United Kingdom, Romania, and Latvia.
The Justice Department announced the takedown, which represents the largest U.S.-led financial and technical disruption of a botnet infrastructure leveraged by cybercriminals to commit ransomware, financial fraud, and other cyber-enabled criminal activity.
According to court documents, Qakbot, also known by various other names, including “Qbot” and “Pinkslipbot,” is controlled by a cybercriminal organization and used to target critical industries worldwide.
The Qakbot malware primarily infects victim computers through spam email messages containing malicious attachments or hyperlinks. Once it has infected a victim computer, Qakbot can deliver additional malware, including ransomware, to the infected computer.
“Cybercriminals who rely on malware like Qakbot to steal private data from innocent victims have been reminded today that they do not operate outside the bounds of the law,” said Attorney General Merrick B. Garland. “Together with our international partners, the Justice Department has hacked Qakbot’s infrastructure, launched an aggressive campaign to uninstall the malware from victim computers in the United States and around the world, and seized $8.6 million in extorted funds.”
The FBI led a worldwide joint, sequenced operation that crippled one of the longest-running cybercriminal botnets, said FBI Director Christopher Wray. “With our federal and international partners, we will continue to systematically target every part of cybercriminal organizations, their facilitators, and their money – including by disrupting and dismantling their ability to use illicit infrastructure to attack us. Today’s success is yet another demonstration of how FBI’s capabilities and strategy are hitting cyber criminals hard, and making the American people safer.”
The victim computers infected with Qakbot malware are part of a botnet, which is a network of compromised computers, meaning the perpetrators can remotely control all the infected computers in a coordinated manner. The owners and operators of the victim computers are typically unaware of the infection.
The action also marked a significant blow to cybercriminals, who have used Qakbot as an initial means of infection by many prolific ransomware groups in recent years, including Conti, ProLock, Egregor, REvil, MegaCortex, and Black Basta.
Related Federal Cases
- GozNym Hacker Ring Busted in Global Cybercrime Takedown · South Carolina
- Olusegun Arowolo, Nigerian Cyber Scammers Plead Guilty to $1M+ Frau… · Ohio
- No Defendant Names Found, Export Violations, Global, 2023 · North Carolina
- Olalekan Jacob Ponle Sentenced to 8+ Years for $8M Cyber Scam, UAE,… · California
- Cameron Curry, Cyber Extortion, Charlotte NC, 2023 · North Carolina
Key Facts
- State: Federal
- Category: Cybercrime
- Source: DOJ Press Release â†â€â€
ðŸâ€Â’ Get the grimiest stories delivered weekly. Subscribe free →

