Security News > 2024 > June > The Justice Department Took Down the 911 S5 Botnet

The Justice Department Took Down the 911 S5 Botnet
2024-06-07 11:04

According to an indictment unsealed on May 24, from 2014 through July 2022, Wang and others are alleged to have created and disseminated malware to compromise and amass a network of millions of residential Windows computers worldwide.

These devices were associated with more than 19 million unique IP addresses, including 613,841 IP addresses located in the United States.

Wang then generated millions of dollars by offering cybercriminals access to these infected IP addresses for a fee.

Agents and officers searched residences, seized assets valued at approximately $30 million, and identified additional forfeitable property valued at approximately $30 million.

The operation also seized 23 domains and over 70 servers constituting the backbone of Wang's prior residential proxy service and the recent incarnation of the service.

By seizing multiple domains tied to the historical 911 S5, as well as several new domains and services directly linked to an effort to reconstitute the service, the government has successfully terminated Wang's efforts to further victimize individuals through his newly formed service Clourouter.io and closed the existing malicious backdoors.


News URL

https://www.schneier.com/blog/archives/2024/06/the-justice-department-took-down-the-911-s5-botnet.html