3 ms·
The article isn’t clear about what actually happened here, but this isn’t all that unheard of (aside from the secret court orders and fbi part). The way this ty
by djrogers 4y ago
The article isn’t clear about what actually happened here, but this isn’t all that unheard of (aside from the secret court orders and fbi part). The way this typically works is the good guys co-opt the Command and Control channels and/or servers, and send commands from that C&C to remove/patch/disinfect the malware.
The C&C takeover can happen a number of ways, from DGA reverse engineering (where you register a bunch of domains that the DGA will eventually pick to communicate with, a common way for non-government entities to do it), all the way up to state-level DNS or BGP hijacking.
A lot of malware that’s distributed is pretty flexible, as it is rarely intended for a single purpose. Today data exfiltration is as lucrative in ransom as destructive encryption, and some other way of extorting companies may get popular tomorrow, so the bad guys like to keep their options open. The small bright side to this is that if you can get control of the C&C channels, you can use that flexibility to tell the malware to remove itself. In the past this technique has even been used to patch vulnerabilities…