Skip to main content
  1. Home
  2. Computing
  3. Legacy Archives

FBI tackles Coreflood botnet infecting 2.3 million PCs

Add as a preferred source on Google
botnet
Image used with permission by copyright holder

The Department of Justice and FBI have scored a big victory against a major international cyber theft ring suspected of stealing more than $100 million.

The thieves used malware called Coreflood to form a network of 2.3 million remotely controlled zombie pcs, also known as a botnet. The botnet snagged banking credentials and other sensitive data, which was used to steal large amounts of funds through wire and bank fraud. The botnet’s growth spans over a decade.

Recommended Videos

More than half of those computers were located within the United States, though the culprits are thought to be from overseas, possibly Russia, according to the director of research at the SAN institute, Alan Paller. A Michigan real estate company and North Carolina investment company both lost over $100,000, but the extent of how widespread the losses are isn’t fully known yet due to the large quantity of data stolen.

The Coreflood botnet was taken down by U.S. government programmers yesterday. The Department of Justice and the FBI took control of five servers used for botnet command, and also seized 29 domains. Government programmers instructed the infected PCs to stop what they were doing and shut down.

Those worried about their own infection have little recourse but to wait it out. Government officials are working with service providers to determine which computers have been infected. The FBI and Department of Justice have stated law enforcement has no authority to access data on infected computers once identified.

This Coreflood botnet comes at the heels of the slightly larger Rustock botnet – said to be responsible for close to half of the global spam – gone silent in March.

Jeff Hughes
Former Digital Trends Contributor
I'm a SF Bay Area-based writer/ninja that loves anything geek, tech, comic, social media or gaming-related.
The Mac Pro nearly received an M3 Extreme chip twice as powerful as M3 Ultra
High production costs likely killed Apple’s M3 Extreme plans
Apple's Mac Pro on a table at a press event.

Apple discontinued the Mac Pro earlier this year, ending a 20-year run for a computer that once represented the very best of the company’s desktop lineup. However, Apple reportedly had much bigger plans for the machine before ultimately replacing it with the Mac Studio.

According to Bloomberg’s Mark Gurman, Apple developed an M3 Extreme chip that could have offered twice as many CPU and GPU cores as the M3 Ultra. The processor was intended to sit above the Ultra tier and could have finally given the Mac Pro the performance advantage it badly needed. Apple eventually abandoned the chip due to concerns over production costs and limited demand for such an expensive machine.

Read more
Hidden prompts can secretly rewrite an AI’s memory, and researchers say that’s a serious problem
Researchers discover AI attack that rewrites an assistant's long-term memory
Chatbot on a smartphone.

Large language models are getting better at remembering us. Whether it's your preferred writing style, recurring tasks, shopping habits or project deadlines, AI assistants are increasingly storing long-term memories to make future conversations feel more personal and useful. But according to new research, that same feature could become one of AI's biggest security vulnerabilities.

Researchers from New Mexico State University have demonstrated a new attack called GhostWriter, capable of secretly planting false memories inside AI agents. Rather than stealing information outright, the attack manipulates what an AI remembers, potentially causing it to make dangerous decisions long after the original attack has taken place.

Read more
This experiment shows how easy it is to poison an open-weight AI model for under $100
This research raises new doubts about trusting open weight AI models.
Computer, Electronics, Laptop

Open-weight AI models have been having a moment lately. Just this month, Moonshot's massive Kimi K3 model landed close behind Claude Fable 5 and GPT 5.6 Sol in several benchmarks, all while remaining fully open-weight and downloadable by anyone.

However, Katie Paxton-Fear, a cybersecurity lecturer at Manchester Metropolitan University and staff security advocate at Semgrep, managed to poison an open-weight model and proved how easily that openness can be turned against you (via The Register).

Read more