Ooni Koda
  1. Home
  2. /
  3. Newsfeed
  4. /
  5. Romanian prosecutors, police at US demand dismantled part...

Romanian prosecutors, police at US demand dismantled part of Qakbot malware infrastructure

September 28, 2023

The Directorate for the Investigation of Organized Crime and Terrorism prosecutors and the police have dismantled, at the request of the US authorities, part of the infrastructure of the Qakbot malware computer program, informs DIICOT in a statement sent on Wednesday.On Saturday, the DIICOT prosecutors, together with the Romanian Police, executed a request for international legal assistance, issued by the US authorities, which aimed to dismantle part of the infrastructure of the Qakbot malware computer program (Qbot).Active since 2007, this prolific malware (also known as QBot or Pinkslipbot) has evolved, using various techniques to infect users and compromise computer systems, the source said, adding that the Qakbot malware was infiltrating victims' computers through spam e-mails, which contained malicious attachments or hyperlinks, and once installed on the targeted computer, the malware aimed to infect it with computer programmes such as Cobalt Strike or other types of ransomware.In addition, investigators say, the infected computer became part of a botnet (a network of compromised computers) simultaneously controlled by cybercriminals, usually without the victims' knowledge.Prosecutors state that Qakbot's main objective was to steal financial data and login credentials from web browsers.Well-known ransomware families such as Conti, ProLock, Egregor, REvil, MegaCortex and Black Basta allegedly used Qakbot to carry out a large number of ransomware attacks on critical infrastructures or on several commercial companies, the investigators say.The administrators of the bot network offered these ransomware groups access to the infected networks, for a fee, this method being also known as maas (malware as a service), prosecutors add."The investigations carried out showed that, between October 2021 and April 2023, the administrators would have received almost 54 million euros from the ransoms that were paid by the victims. The analysis of the confiscated infrastructure showed that the malware would have infected more than 700,000 of computers around the world, and the authorities have detected servers infected with Qakbot in almost 30 countries in Europe, South and North America, Asia and Africa, enabling the malware's activity on a global scale," DIICOT says.  

Read in full - click here
Romania’s magistracy council signals fierce resistance to PM’s plan to curtail  magistrates’ privileges  

Romanian PM Ilie Bolojan operates outside of the legal procedures when initiating consultations on a proposal for amending the legislation on the service pensions in the field of Justice, the Romanian Superior Council of Magistracy (CSM) said in a press release on July 30. ...

Romania currently “rebuilding trust” with the US to rejoin Visa Waiver program, minister says

Romania is currently rebuilding its bilateral relations with the United States with the aim of rejoining the Visa Waiver program after the Trump administration removed it from the list of partner countries, according to foreign minister Oana Ţoiu. During an interview given on Wednesday, July 30, the minister noted that efforts are being made for […]

Romanian Justice Minister backs magistrates' pensions reform  

Justice Minister Radu Marinescu (Social Democratic Party) stated, in an intervention on Digi24, that the ministry he heads supports the special pension reform, proposed by Prime Minister Ilie Bolojan, but "the set of proposals communicated by the prime minister will...

Bucharest mayoral elections expected in November after presidential win left seat vacant

Romania’s governing coalition agreed on July 30 to hold local elections for Bucharest Mayor in November, although the exact date has not yet been set, Ziarul Financiar reported. The mayoral seat became vacant after former mayor Nicuşor Dan won the presidential election in May. On the same day, president...

Romgaz reports 13% y/y higher sales in H1 despite stagnating output

State-owned Romgaz (BVB: SNG) sold 2.52 billion cubic meters of natural gas from domestic production in the first six months of the year, 12.55% above the level of the same period in 2024, according to the operational report from the Bucharest Stock Exchange. The company's financial report will be published on August 14. Hydrocarbon production […]

Hidroelectrica’s power output down 27% y/y

Hidroelectrica (BVB: H2O), the largest energy producer controlled by the Romanian state, announced on the Bucharest Exchange that its net electricity production decreased by 27% in the first half of the year, to  6,068 GWh, while purchased energy increased by 62%, to  674 GWh. The company’s financial results for the first 6 months of the […]