FBI confirms it issued remote kill command to blow out Volt Typhoon's botnet
(2024/01/31)
- Reference: 1706729091
- News link: https://www.theregister.co.uk/2024/01/31/volt_typhoon_botnet/
- Source link:
China's Volt Typhoon attackers used "hundreds" of outdated Cisco and NetGear routers infected with malware in an attempt to break into US critical infrastructure facilities, according to the Justice Department.
On Tuesday [1]news broke that the Feds had blocked the malicious network that was set up on end-of-life, US-based small office/home office routers. Now more details have come out about how an FBI team infiltrated the attack and harvested the key data before remotely wiping the KV Botnet, according to four warrants ( [2]5018 , [3]5530 , [4]5451 and [5]5432 ) filed by the FBI in the Southern District Court of Texas last month and released today.
"China's hackers are targeting American civilian critical infrastructure, pre-positioning to cause real-world harm to American citizens and communities in the event of conflict," FBI Director Christopher Wray said in a [6]statement . "Volt Typhoon malware enabled China to hide as they targeted our communications, energy, transportation, and water sectors."
[7]
The Feds claim the Middle Kingdom keyboard warriors downloaded a virtual private network module to the vulnerable routers and set up an encrypted communication channel to control the botnet and hide their illegal activities. Specifically: Volt Typhoon used the US-based routers and IP addresses to [8]target US critical infrastructure, we're told.
[9]US shorts China's Volt Typhoon crew targeting America's criticals
[10]Five Eyes and Microsoft accuse China of attacking US infrastructure again
[11]We know nations are going after critical systems, but what happens when crims join in?
[12]Ivanti releases patches for VPN zero-days, discloses two more high-severity vulns
The warrants allowed law enforcement to remotely install software on the routers to search for, and then seize or copy, information about the illicit activity before wiping the malware from the compromised devices.
To do this — and to limit the cops' search to routers infected with the botnet — the FBI sent specific KV Botnet commands to compromised routers to collect "non-content information about those nodes," according to the warrants.
[13]
This includes the IP address, port numbers used by infected routers to communicate with other nodes, as well as IP addresses and ports used by each node's parent, and data on the command-and-control nodes.
"A router that is not infected by the KV Botnet malware would not receive or respond to this command," court documents claim.
[14]
The Feds, along with foreign agency partners in Five Eyes nations, [15]first warned about this threat in May 2023.
Also today, the US Cybersecurity Agency and FBI [16]issued an alert urging manufacturers to eliminate defects in SOHO router web management interfaces. This, according to the agencies, includes automating update capabilities, locating the web management interface on LAN-side ports, and requiring a manual override to remove security settings. ®
Get our [17]Tech Resources
[1] https://www.theregister.com/2024/01/30/fbi_china_volt/
[2] https://lnks.gd/l/eyJhbGciOiJIUzI1NiJ9.eyJidWxsZXRpbl9saW5rX2lkIjoxMDIsInVyaSI6ImJwMjpjbGljayIsInVybCI6Imh0dHBzOi8vd3d3Lmp1c3RpY2UuZ292L29wYS9tZWRpYS8xMzM2NDIxL2RsP2lubGluZT0mdXRtX21lZGl1bT1lbWFpbCZ1dG1fc291cmNlPWdvdmRlbGl2ZXJ5IiwiYnVsbGV0aW5faWQiOiIyMDI0MDEzMS44OTQzMDk5MSJ9.4LRHVZyUDYfMnRWC7s_-GUsAOhl4SewCG7GXGj4tAX8/s/3078670442/br/236285728656-l
[3] https://lnks.gd/l/eyJhbGciOiJIUzI1NiJ9.eyJidWxsZXRpbl9saW5rX2lkIjoxMDMsInVyaSI6ImJwMjpjbGljayIsInVybCI6Imh0dHBzOi8vd3d3Lmp1c3RpY2UuZ292L29wYS9tZWRpYS8xMzM2NDE2L2RsP2lubGluZT0mdXRtX21lZGl1bT1lbWFpbCZ1dG1fc291cmNlPWdvdmRlbGl2ZXJ5IiwiYnVsbGV0aW5faWQiOiIyMDI0MDEzMS44OTQzMDk5MSJ9.8vmYc17z664gSNfykf8ncM2yRyRspFYF6SCIHiTZhb8/s/3078670442/br/236285728656-l
[4] https://lnks.gd/l/eyJhbGciOiJIUzI1NiJ9.eyJidWxsZXRpbl9saW5rX2lkIjoxMDQsInVyaSI6ImJwMjpjbGljayIsInVybCI6Imh0dHBzOi8vd3d3Lmp1c3RpY2UuZ292L29wYS9tZWRpYS8xMzM2NDA2L2RsP2lubGluZT0mdXRtX21lZGl1bT1lbWFpbCZ1dG1fc291cmNlPWdvdmRlbGl2ZXJ5IiwiYnVsbGV0aW5faWQiOiIyMDI0MDEzMS44OTQzMDk5MSJ9.d-xmdG8esN2ZFRwqLXHNvwIo6ZpVS-2HQ5js3wwfJo8/s/3078670442/br/236285728656-l
[5] https://lnks.gd/l/eyJhbGciOiJIUzI1NiJ9.eyJidWxsZXRpbl9saW5rX2lkIjoxMDUsInVyaSI6ImJwMjpjbGljayIsInVybCI6Imh0dHBzOi8vd3d3Lmp1c3RpY2UuZ292L29wYS9tZWRpYS8xMzM2NDExL2RsP2lubGluZT0mdXRtX21lZGl1bT1lbWFpbCZ1dG1fc291cmNlPWdvdmRlbGl2ZXJ5IiwiYnVsbGV0aW5faWQiOiIyMDI0MDEzMS44OTQzMDk5MSJ9.xD5SrU9r17bUh7t5QaI4TWGGTTTlIfn6D8a3QecwFJY/s/3078670442/br/236285728656-l
[6] https://www.justice.gov/usao-sdtx/pr/us-government-disrupts-botnet-peoples-republic-china-used-conceal-hacking-critical
[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZbrRFhmsAApIVysfyA8QVwAAAZg&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[8] https://www.theregister.com/2024/01/31/critical_infrastructure_hacking/
[9] https://www.theregister.com/2024/01/30/fbi_china_volt/
[10] https://www.theregister.com/2023/05/25/china_volt_typhoon_attacks/
[11] https://www.theregister.com/2024/01/31/critical_infrastructure_hacking/
[12] https://www.theregister.com/2024/01/31/ivanti_patches_zero_days/
[13] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZbrRFhmsAApIVysfyA8QVwAAAZg&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[14] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZbrRFhmsAApIVysfyA8QVwAAAZg&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[15] https://www.theregister.com/2023/05/25/china_volt_typhoon_attacks/
[16] https://www.cisa.gov/news-events/alerts/2024/01/31/cisa-and-fbi-release-secure-design-alert-urging-manufacturers-eliminate-defects-soho-routers
[17] https://whitepapers.theregister.com/
On Tuesday [1]news broke that the Feds had blocked the malicious network that was set up on end-of-life, US-based small office/home office routers. Now more details have come out about how an FBI team infiltrated the attack and harvested the key data before remotely wiping the KV Botnet, according to four warrants ( [2]5018 , [3]5530 , [4]5451 and [5]5432 ) filed by the FBI in the Southern District Court of Texas last month and released today.
"China's hackers are targeting American civilian critical infrastructure, pre-positioning to cause real-world harm to American citizens and communities in the event of conflict," FBI Director Christopher Wray said in a [6]statement . "Volt Typhoon malware enabled China to hide as they targeted our communications, energy, transportation, and water sectors."
[7]
The Feds claim the Middle Kingdom keyboard warriors downloaded a virtual private network module to the vulnerable routers and set up an encrypted communication channel to control the botnet and hide their illegal activities. Specifically: Volt Typhoon used the US-based routers and IP addresses to [8]target US critical infrastructure, we're told.
[9]US shorts China's Volt Typhoon crew targeting America's criticals
[10]Five Eyes and Microsoft accuse China of attacking US infrastructure again
[11]We know nations are going after critical systems, but what happens when crims join in?
[12]Ivanti releases patches for VPN zero-days, discloses two more high-severity vulns
The warrants allowed law enforcement to remotely install software on the routers to search for, and then seize or copy, information about the illicit activity before wiping the malware from the compromised devices.
To do this — and to limit the cops' search to routers infected with the botnet — the FBI sent specific KV Botnet commands to compromised routers to collect "non-content information about those nodes," according to the warrants.
[13]
This includes the IP address, port numbers used by infected routers to communicate with other nodes, as well as IP addresses and ports used by each node's parent, and data on the command-and-control nodes.
"A router that is not infected by the KV Botnet malware would not receive or respond to this command," court documents claim.
[14]
The Feds, along with foreign agency partners in Five Eyes nations, [15]first warned about this threat in May 2023.
Also today, the US Cybersecurity Agency and FBI [16]issued an alert urging manufacturers to eliminate defects in SOHO router web management interfaces. This, according to the agencies, includes automating update capabilities, locating the web management interface on LAN-side ports, and requiring a manual override to remove security settings. ®
Get our [17]Tech Resources
[1] https://www.theregister.com/2024/01/30/fbi_china_volt/
[2] https://lnks.gd/l/eyJhbGciOiJIUzI1NiJ9.eyJidWxsZXRpbl9saW5rX2lkIjoxMDIsInVyaSI6ImJwMjpjbGljayIsInVybCI6Imh0dHBzOi8vd3d3Lmp1c3RpY2UuZ292L29wYS9tZWRpYS8xMzM2NDIxL2RsP2lubGluZT0mdXRtX21lZGl1bT1lbWFpbCZ1dG1fc291cmNlPWdvdmRlbGl2ZXJ5IiwiYnVsbGV0aW5faWQiOiIyMDI0MDEzMS44OTQzMDk5MSJ9.4LRHVZyUDYfMnRWC7s_-GUsAOhl4SewCG7GXGj4tAX8/s/3078670442/br/236285728656-l
[3] https://lnks.gd/l/eyJhbGciOiJIUzI1NiJ9.eyJidWxsZXRpbl9saW5rX2lkIjoxMDMsInVyaSI6ImJwMjpjbGljayIsInVybCI6Imh0dHBzOi8vd3d3Lmp1c3RpY2UuZ292L29wYS9tZWRpYS8xMzM2NDE2L2RsP2lubGluZT0mdXRtX21lZGl1bT1lbWFpbCZ1dG1fc291cmNlPWdvdmRlbGl2ZXJ5IiwiYnVsbGV0aW5faWQiOiIyMDI0MDEzMS44OTQzMDk5MSJ9.8vmYc17z664gSNfykf8ncM2yRyRspFYF6SCIHiTZhb8/s/3078670442/br/236285728656-l
[4] https://lnks.gd/l/eyJhbGciOiJIUzI1NiJ9.eyJidWxsZXRpbl9saW5rX2lkIjoxMDQsInVyaSI6ImJwMjpjbGljayIsInVybCI6Imh0dHBzOi8vd3d3Lmp1c3RpY2UuZ292L29wYS9tZWRpYS8xMzM2NDA2L2RsP2lubGluZT0mdXRtX21lZGl1bT1lbWFpbCZ1dG1fc291cmNlPWdvdmRlbGl2ZXJ5IiwiYnVsbGV0aW5faWQiOiIyMDI0MDEzMS44OTQzMDk5MSJ9.d-xmdG8esN2ZFRwqLXHNvwIo6ZpVS-2HQ5js3wwfJo8/s/3078670442/br/236285728656-l
[5] https://lnks.gd/l/eyJhbGciOiJIUzI1NiJ9.eyJidWxsZXRpbl9saW5rX2lkIjoxMDUsInVyaSI6ImJwMjpjbGljayIsInVybCI6Imh0dHBzOi8vd3d3Lmp1c3RpY2UuZ292L29wYS9tZWRpYS8xMzM2NDExL2RsP2lubGluZT0mdXRtX21lZGl1bT1lbWFpbCZ1dG1fc291cmNlPWdvdmRlbGl2ZXJ5IiwiYnVsbGV0aW5faWQiOiIyMDI0MDEzMS44OTQzMDk5MSJ9.xD5SrU9r17bUh7t5QaI4TWGGTTTlIfn6D8a3QecwFJY/s/3078670442/br/236285728656-l
[6] https://www.justice.gov/usao-sdtx/pr/us-government-disrupts-botnet-peoples-republic-china-used-conceal-hacking-critical
[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZbrRFhmsAApIVysfyA8QVwAAAZg&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[8] https://www.theregister.com/2024/01/31/critical_infrastructure_hacking/
[9] https://www.theregister.com/2024/01/30/fbi_china_volt/
[10] https://www.theregister.com/2023/05/25/china_volt_typhoon_attacks/
[11] https://www.theregister.com/2024/01/31/critical_infrastructure_hacking/
[12] https://www.theregister.com/2024/01/31/ivanti_patches_zero_days/
[13] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZbrRFhmsAApIVysfyA8QVwAAAZg&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[14] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZbrRFhmsAApIVysfyA8QVwAAAZg&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[15] https://www.theregister.com/2023/05/25/china_volt_typhoon_attacks/
[16] https://www.cisa.gov/news-events/alerts/2024/01/31/cisa-and-fbi-release-secure-design-alert-urging-manufacturers-eliminate-defects-soho-routers
[17] https://whitepapers.theregister.com/
Thanks for nothing
The Man Who Fell To Earth
So, is there a list of vulnerable routers published anywhere? If not, why not?
Re: Thanks for nothing
RedGreen925
"So, is there a list of vulnerable routers published anywhere? If not, why not?"
No need, pick up and look at any router going if it has been manufactured and in use it is vulnerable. The piss poor attention to detail by the parasite corporation only interested in getting your money means they do not spend anywhere near close enough attention to or enough money on security. They are all vulnerable if subject to concerted effort to find the openings to get in.
So I bought 2nd hand Netgear Aircard 763S "LTE" wi-fi hotspot device, for $3, because at least the premise is cool.
However, the router is in a reboot loop which is not unheard of for these devices. In fact I got two, and they both do it.
Somebody, way back when, posted about how somebody figured out the router had become Infected With Virus and that's causing the issue.
I read about this "virus" yesterday, and thought it sounded ridiculous, and now I read about this today, and I wonder..?
How can I find out if I have infected routers? Maybe there's a way to figure it out.