www.lesswrong.com/posts/gutiw8MBrYDiD2u5z/models-finding-software-vulnerabilitie...
1 correction found
It used to be that the worst thing these people could do was launch DDoS attacks against a particular target, or send spam email, or scrape for crypto and credit cards.
This understates what botnets were already doing years ago. Long before current AI concerns, major botnets were stealing banking credentials, enabling wire fraud, and delivering ransomware—not just DDoS, spam, cryptomining, or credit-card theft.
Full reasoning
U.S. government sources describe historical botnets as having much broader and more damaging uses than the sentence suggests.
- In a June 2, 2014 FBI press release, GameOver Zeus is described as malware whose principal purpose was to capture banking credentials and use them to initiate or redirect wire transfers; the FBI estimated it caused more than $100 million in losses. The same release also discusses the linked CryptoLocker ransomware operation.
- In CISA/FBI's August 30, 2023 advisory on QakBot, the malware is described as existing since at least 2008, first as a banking trojan, and later as a botnet used for reconnaissance, lateral movement, data exfiltration, and delivering ransomware.
- In CISA/FBI's May 20, 2021 advisory on TrickBot, the malware is described as originally a banking trojan that evolved into a platform for many illegal activities, including stealing credentials and dropping Ryuk and Conti ransomware.
So the historical record shows botnet operators were already using botnets for bank fraud, credential theft, account compromise, data exfiltration, and ransomware delivery well before the present discussion. That makes the quoted claim materially inaccurate as a description of what botnets "used to" be capable of.
3 sources
- U.S. Leads Multi-National Action Against GameOver Zeus Botnet and Cryptolocker Ransomware, Charges Botnet Administrator - FBI
The principal purpose of the botnet is to capture banking credentials from infected computers... The FBI estimates that GameOver Zeus is responsible for more than $100 million in losses. In the same operation, officials targeted Cryptolocker, a form of ransomware.
- Identification and Disruption of QakBot Infrastructure | CISA
QakBot was originally used as a banking trojan to steal banking credentials... Since its initial inception as a banking trojan, QakBot has evolved into a multi-purpose botnet... including performing reconnaissance, engaging in lateral movement, gathering and exfiltrating data, and delivering other malicious payloads, including ransomware.
- TrickBot Malware | CISA
Originally designed as a banking Trojan to steal financial data, TrickBot has evolved into highly modular, multi-stage malware that provides its operators a full suite of tools to conduct a myriad of illegal cyber activities... Attackers can use TrickBot to drop other malware, such as Ryuk and Conti ransomware.