AGL 40.00 No Change ▼ 0.00 (0%)
AIRLINK 129.00 Decreased By ▼ -0.53 (-0.41%)
BOP 6.76 Increased By ▲ 0.08 (1.2%)
CNERGY 4.50 Decreased By ▼ -0.13 (-2.81%)
DCL 8.70 Decreased By ▼ -0.24 (-2.68%)
DFML 41.00 Decreased By ▼ -0.69 (-1.66%)
DGKC 81.30 Decreased By ▼ -2.47 (-2.95%)
FCCL 32.68 Decreased By ▼ -0.09 (-0.27%)
FFBL 74.25 Decreased By ▼ -1.22 (-1.62%)
FFL 11.75 Increased By ▲ 0.28 (2.44%)
HUBC 110.03 Decreased By ▼ -0.52 (-0.47%)
HUMNL 13.80 Decreased By ▼ -0.76 (-5.22%)
KEL 5.29 Decreased By ▼ -0.10 (-1.86%)
KOSM 7.63 Decreased By ▼ -0.77 (-9.17%)
MLCF 38.35 Decreased By ▼ -1.44 (-3.62%)
NBP 63.70 Increased By ▲ 3.41 (5.66%)
OGDC 194.88 Decreased By ▼ -4.78 (-2.39%)
PAEL 25.75 Decreased By ▼ -0.90 (-3.38%)
PIBTL 7.37 Decreased By ▼ -0.29 (-3.79%)
PPL 155.74 Decreased By ▼ -2.18 (-1.38%)
PRL 25.70 Decreased By ▼ -1.03 (-3.85%)
PTC 17.56 Decreased By ▼ -0.90 (-4.88%)
SEARL 78.71 Decreased By ▼ -3.73 (-4.52%)
TELE 7.88 Decreased By ▼ -0.43 (-5.17%)
TOMCL 33.61 Decreased By ▼ -0.90 (-2.61%)
TPLP 8.41 Decreased By ▼ -0.65 (-7.17%)
TREET 16.26 Decreased By ▼ -1.21 (-6.93%)
TRG 58.60 Decreased By ▼ -2.72 (-4.44%)
UNITY 27.51 Increased By ▲ 0.08 (0.29%)
WTL 1.41 Increased By ▲ 0.03 (2.17%)
BR100 10,450 Increased By 43.4 (0.42%)
BR30 31,209 Decreased By -504.2 (-1.59%)
KSE100 97,798 Increased By 469.8 (0.48%)
KSE30 30,481 Increased By 288.3 (0.95%)

WASHINGTON: The U.S. Federal Bureau of Investigation has wrested control of thousands of routers and firewall appliances away from Russian military hackers by hijacking the same infrastructure Moscow’s spies were using to communicate with the devices, U.S. officials said on Wednesday.

An unsealed redacted affidavit described the unusual operation as a pre-emptive move to stop Russian hackers from mobilizing the compromised devices into a “botnet” - a network of hacked computers that can bombard other servers with rogue traffic.

"Fortunately, we were able to disrupt this botnet before it could be used,” U.S. Attorney General Merrick Garland said.

The targeted botnet was controlled through malware called Cyclops Blink, which U.S. and UK cyberdefense agencies had publicly attributed in late February to “Sandworm,” allegedly one of the Russian military intelligence service’s hacking teams that has repeatedly been accused of carrying out cyberattacks.

Cyclops Blink was designed to hijack devices made by WatchGuard Technologies Inc and ASUSTeK Computer Inc, according to research by private cybersecurity firms.

Russia rejects claims it was responsible for cyberattack on Ukraine

It provides Russian services with access to those compromised systems, offering the ability to remotely exfiltrate or delete data or turn the devices against a third party.

FBI Director Chris Wray told reporters the FBI, with court approval, secretly reached into thousands of routers and firewall appliances to delete the malware and reconfigure the devices.

"We removed malware from devices used by thousands of mostly small businesses for network security all over the world," Wray said. "We shut the door the Russians had used to get into them."

The affidavit noted that U.S. officials launched an awareness campaign “to inform owners of WatchGuard devices of the steps they should take to remediate infections or vulnerabilities” and yet less than half the devices had been fixed to expel the hackers.

The affidavit noted that the FBI had carried out its work in cooperation with WatchGuard.

The announcement came amid a flurry of new sanctions announced against Russian banks and elites, days after grim images emerged of the bodies of civilians shot at close range in the town of Bucha.

Russia says its "special military operation" is aimed at demilitarizing and "denazifying" Ukraine, and it has denied targeting civilians.

Comments

Comments are closed.