<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Taking apart a botnet ... in Industry News</title>
    <link>https://community.isc2.org/t5/Industry-News/Taking-apart-a-botnet/m-p/18639#M2196</link>
    <description>&lt;P&gt;The &lt;A href="https://nakedsecurity.sophos.com/2019/02/04/fbi-burrowing-into-north-koreas-big-bad-botnet/" target="_blank" rel="noopener"&gt;FBI is messing with Joanap&lt;/A&gt;, a botnet run by a major North Korean blackhat group.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Joanap itself is fairly complicated, with infections being started by an SMB worm, which then installs the Joanap RAT (Remote Access Trojan).&amp;nbsp; Command and control is done via a peer-to-peer distributed network.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Which is where the FBI comes in.&amp;nbsp; A court in the US granted them permission to set up fake servers pretending to be controllers on Joanap.&amp;nbsp; As such, they could spy on individual machines, collect information, or even install software (possibly to remove the infections and patch vulnerabilities).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In examining the &lt;A href="https://community.isc2.org/t5/Chapters/Vancouver-Chapter-Ethics-of-Active-Defence-Feb-8/m-p/18596" target="_blank" rel="noopener"&gt;ethics of active defence&lt;/A&gt;, I find this fascinating.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm pretty sure than in Canadian law the FBI action would actually be illegal, which is possibly why they are contacting host governments in the cases of non-US victims.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;(Oh, and remember to patch your systems, which is the only reason the blackhats were able to build Joanap in the first place ...)&lt;/P&gt;</description>
    <pubDate>Mon, 09 Oct 2023 09:06:14 GMT</pubDate>
    <dc:creator>rslade</dc:creator>
    <dc:date>2023-10-09T09:06:14Z</dc:date>
    <item>
      <title>Taking apart a botnet ...</title>
      <link>https://community.isc2.org/t5/Industry-News/Taking-apart-a-botnet/m-p/18639#M2196</link>
      <description>&lt;P&gt;The &lt;A href="https://nakedsecurity.sophos.com/2019/02/04/fbi-burrowing-into-north-koreas-big-bad-botnet/" target="_blank" rel="noopener"&gt;FBI is messing with Joanap&lt;/A&gt;, a botnet run by a major North Korean blackhat group.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Joanap itself is fairly complicated, with infections being started by an SMB worm, which then installs the Joanap RAT (Remote Access Trojan).&amp;nbsp; Command and control is done via a peer-to-peer distributed network.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Which is where the FBI comes in.&amp;nbsp; A court in the US granted them permission to set up fake servers pretending to be controllers on Joanap.&amp;nbsp; As such, they could spy on individual machines, collect information, or even install software (possibly to remove the infections and patch vulnerabilities).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In examining the &lt;A href="https://community.isc2.org/t5/Chapters/Vancouver-Chapter-Ethics-of-Active-Defence-Feb-8/m-p/18596" target="_blank" rel="noopener"&gt;ethics of active defence&lt;/A&gt;, I find this fascinating.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm pretty sure than in Canadian law the FBI action would actually be illegal, which is possibly why they are contacting host governments in the cases of non-US victims.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;(Oh, and remember to patch your systems, which is the only reason the blackhats were able to build Joanap in the first place ...)&lt;/P&gt;</description>
      <pubDate>Mon, 09 Oct 2023 09:06:14 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Taking-apart-a-botnet/m-p/18639#M2196</guid>
      <dc:creator>rslade</dc:creator>
      <dc:date>2023-10-09T09:06:14Z</dc:date>
    </item>
  </channel>
</rss>

