U.S. and international law enforcement dismantled the Qakbot botnet by seizing control of key infrastructure, redirecting infected systems to FBI-controlled servers, and remotely pushing an uninstaller to compromised Windows hosts. Court records show the FBI obtained authority to use remote access techniques against U.S.-based computers communicating with Qakbot, a long-running malware platform also known as Qbot and Pinkslipbot, after identifying roughly 700,000 infected computers worldwide, including about 200,000 in the United States. The operation collected limited technical data such as IP and routing information, but did not capture communication content.
Researchers said the disruption also neutralized active infections by sending Qakbot’s own shutdown command through its named-pipe mechanism, preventing the malware from relaunching after a reboot. The takedown targeted a botnet widely used as an initial access platform for ransomware groups including Conti, REvil, Egregor, MegaCortex, ProLock, and Black Basta. Investigators linked Qakbot operators to fees associated with about $58 million in victim ransom payments between October 2021 and April 2023, underscoring the botnet’s central role in corporate intrusions and downstream ransomware attacks.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
8 events from the most recent confirmed update back to the earliest known activity.
As part of the multinational QakBot disruption, U.S. authorities seized nearly $9 million in cryptocurrency linked to the botnet's operators. The seizure was disclosed alongside the public announcement of Operation Duck Hunt.
On August 29, 2023, U.S. law enforcement publicly announced the dismantling of Qakbot infrastructure in a multinational operation. Reporting described the action as a takedown of the Qakbot criminal botnet following the earlier technical disruption.
Around the same time as the shutdown DLL was deployed, Secureworks observed GOLD LAGOON's backend infrastructure stop responding and some servers get replaced. The replacement systems required a certificate capable of signing messages, indicating coordinated control of botnet infrastructure during the takedown.
At 23:27 UTC on August 25, 2023, Qakbot distributed shellcode to infected devices that unpacked a custom DLL. The DLL used Qakbot's own named-pipe mechanism to send the QPCMD_BOT_SHUTDOWN command and terminate the malware process.
On August 23, 2023, the FBI applied in the Central District of California for a seizure warrant covering virtual assets in 20 cryptocurrency wallets allegedly controlled by the Qakbot organization. The affidavit tied the wallets to ransomware-derived Bitcoin payments and records recovered from Qakbot administrative infrastructure.
On August 21, 2023, the FBI submitted a sealed affidavit and search warrant application seeking authority to use remote access techniques against U.S.-based computers infected with Qakbot. The filing described the FBI's access to much of Qakbot's infrastructure and its plan to deploy a Supernode Module and Uninstaller to sever infected hosts from the botnet.
The FBI stated that between September 2022 and June 15, 2023, it identified approximately 700,000 computers worldwide with active Qakbot infections, including about 200,000 in the United States. This established the scale of the botnet ahead of the disruption effort.
On May 22, 2025, the U.S. Attorney’s Office for the Central District of California filed a forfeiture complaint against virtual currency and currency seized from Qakbot operators. The complaint alleged the assets were proceeds of and involved in money laundering tied to ransomware payments resulting from Qakbot-linked intrusions.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
10 references tracked. Mallory keeps watching after this page renders.
secureworks.com
Open sourceshadowserver.org
Open sourcefbi.gov
Open sourceshadowserver.org
Open sourcejustice.gov
Open sourcecybersecurity.att.com
Open sourcejustice.gov
Open sourcejustice.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.