The Justice Department Took Down the 911 S5 Botnet

The US Justice Department has dismantled an enormous botnet:

According to an indictment unsealed on May 24, from 2014 through July 2022, Wang and others are alleged to have created and disseminated malware to compromise and amass a network of millions of residential Windows computers worldwide. These devices were associated with more than 19 million unique IP addresses, including 613,841 IP addresses located in the United States. Wang then generated millions of dollars by offering cybercriminals access to these infected IP addresses for a fee.

[…]

This operation was a coordinated multiagency effort led by law enforcement in the United States, Singapore, Thailand, and Germany. Agents and officers searched residences, seized assets valued at approximately $30 million, and identified additional forfeitable property valued at approximately $30 million. The operation also seized 23 domains and over 70 servers constituting the backbone of Wang’s prior residential proxy service and the recent incarnation of the service. By seizing multiple domains tied to the historical 911 S5, as well as several new domains and services directly linked to an effort to reconstitute the service, the government has successfully terminated Wang’s efforts to further victimize individuals through his newly formed service Clourouter.io and closed the existing malicious backdoors.

The creator and operator of the botnet, YunHe Wang, was arrested in Singapore.

Three news articles.

Posted on June 7, 2024 at 7:04 AM4 Comments

Comments

What price common sense? June 7, 2024 7:17 AM

@ALL

Yes it all sounds very impressive etc etc.

But the two questions people should ask are

1 How come they could get into all those computers?

  1. How come they apparently got away with it for nearly a decade?

Or to put it another way,

“If Microsoft et al had produced a merchantable product in the first place instead of bells and whistles would we be reading this?

And I suspect the answer is “NO” to that.

Erdem Memisyazici June 7, 2024 10:14 AM

The real question is, “was it unofficially known as ‘Operation Who Want Some Wang?'”

Greg Standforth June 8, 2024 9:37 AM

To follow on what the first commenter said, it is well past time for Microsoft to simply keep redecorating the walls, rearranging the furniture for Windows.

Use some of the horsepower routinely available, and use the new wave of AI enthusiasm, and point it at an actual, useful, funtional purpose. Let every PC be a node actively fighting botnets, malware, scammers. Use the available resources for something besides fluff.

It’s also well past time for blue screens to stop using hexadecimsl codes to refer to error messages, and use actual English. It’s well past time to make the OS smarter, and rid itself of error messages which are the moral equivalent of “I dunno.” Diagnostic appliances for cars are decades old. Come on, Microsoft. Get your head out; get the lead out.

War is Not the Answer June 9, 2024 10:02 PM

It’s nice to see some good news for a change.
Sometimes it feels like most of the internet and computer industry is actually run by criminal syndicates and nobody else.

As for people here talking about Microsoft, really, don’t blame a perpetraitor for being bad. They never cared about anything meaningful. They seem to be criminal organization through and through, but so are their collaborators.

Military and government people, meanwhile, stop shoving us closer to armageddon, please.
Agitating V. Putin with actual weapons proliferation makes us much less secure. All that money spent to make us more likely to kill and be killed is just not kosher. There’s no way around it. Security is political; there’s no neutrality while worldwide security is being attacked. Work it out. Opinions and facts overlap.

The ones actually messing up our wurvivalism–are they satannic? who knows?

Leave a comment

Blog moderation policy

Login

Allowed HTML <a href="URL"> • <em> <cite> <i> • <strong> <b> • <sub> <sup> • <ul> <ol> <li> • <blockquote> <pre> Markdown Extra syntax via https://michelf.ca/projects/php-markdown/extra/

Sidebar photo of Bruce Schneier by Joe MacInnis.