Atlanta Lawyer, Investigator Offer Lessons from the FBI's Disruption of North Korea's Botnet
Much like your company's IT team uses command-and-control software to fix your computer remotely, a botnet can give a single actor the power to control an army of infected computers. But the Joanap botnet comes with a unique twist.
February 20, 2019 at 12:00 PM
5 minute read
On Jan. 30, the U.S. Department of Justice revealed a secret operation to disrupt and uncover the Joanap botnet—one of North Korea's tools for inflicting technological mayhem around the world. The FBI's strategy, which in part turns on notifying users infected with the malware, underscores critical lessons about how cybersecurity awareness can serve U.S. national security goals and protect companies from damaging cyberattacks.
For at least a decade, the Joanap botnet, which North Korean actors propagated using a malware strain referred to as “Brambul,” has wreaked havoc around the world and in the United States. In 2018, US-CERT, a Department of Homeland Security entity responsible for disseminating cyberthreat information, warned that the malware combination had been targeting numerous industries, “including the media, aerospace, financial, and critical infrastructure sectors.” What's more, in a detailed criminal complaint filed against North Korean citizen Park Jin Hyok, U.S. authorities linked the Brambul malware to North Korean actors dubbed “Lazarus Group”—the same group associated with the hack of Sony, the WannaCry ransomware and massive financial thefts.
Generally, botnets are powerful tools in the hands of cybercriminals, and Joanap is no exception. Much like your company's IT team uses command-and-control software to fix your computer remotely, a botnet can give a single actor the power to control an army of infected computers. But the Joanap botnet comes with a unique twist. That is, according to affidavits submitted in support of the operation, instead of controlling infected computers through one centralized command and control server, North Korean threat actors can use infected computers to control other infected computers in the same network. So a victim computer ensnared by Joanap doesn't just risk having its information stolen by North Korean attackers, it risks becoming a part of the infrastructure that attackers can use to victimize other computer users around the world.
How the FBI Began to Identify Infected Computers
In 2018, the FBI obtained court approval to conduct a technical operation designed to identify and pinpoint infected computers that comprised the Joanap botnet. Using a relatively new change to Federal Rule of Criminal Procedure 41 that authorizes “remote access to search electronic storage media” outside of a particular district in certain narrow circumstances, the FBI operated servers that acted like computers infected with Joanap; it then collected metadata sent by other infected computers trying to communicate with the FBI-controlled servers. That data flow gave the FBI critical insight into the location and identity of infected computers around the world. Using that information, the FBI intends to notify computer users about the North Korean malware sitting on their computers.
Historically, the FBI has proactively reached out to victims to notify them of them of infections, known data breaches and other malicious activity on corporate networks. But waiting for the FBI to notify you of a cyber incident is a poor strategy for reducing your company's cyberrisk. Companies should be taking a number of steps to proactively assess their cybersecurity posture before any FBI notice. Regular cybersecurity assessments by third parties can go a long way toward identifying existing vulnerabilities, quantifying cyberrisks and helping organizations determine whether they have blind spots that allow pernicious cyberthreats such as Joanap to go unnoticed. And, depending on the circumstances, working with outside counsel to obtain such assessments as part of a comprehensive legal strategy may help to ensure that certain aspects of the assessments remain confidential. Fortunately, according to the Department of Justice, infected users can take steps to mitigate and contain the Joanap malware. There are a number of programs capable of removing the malware and remediating infections and maintaining up-to-date anti-virus can prevent reinfection.
Of course, the FBI's notice campaign may put organizations in a precarious position with customers, shareholders and other third parties. The mere receipt of the notice may raise questions about a company's existing cybersecurity measures and invite skepticism about a company's ability to unilaterally address problems hosted on its own network. But the best way to avoid being notified about a persistent threat on your network is to proactively prevent such infections from flourishing in the first place. Although there's no such thing as perfect security, organizations that take proactive measures such as assessments, cybersecurity awareness campaigns and the deployment of security solutions will greatly reduce the risk and impact of cyberthreats like Joanap and Brambul.
Kamal Ghali is a former deputy chief of the cybercrime section at the U.S. Attorney's Office in Atlanta and leads the cybersecurity and privacy practice at Bondurant, Mixson & Elmore, an Atlanta-based litigation and investigations firm.
Mark Ray is a former FBI special agent and the global head of digital investigations and cyber defense at Nardello & Co.
This content has been archived. It is available through our partners, LexisNexis® and Bloomberg Law.
To view this content, please continue to their sites.
Not a Lexis Subscriber?
Subscribe Now
Not a Bloomberg Law Subscriber?
Subscribe Now
NOT FOR REPRINT
© 2025 ALM Global, LLC, All Rights Reserved. Request academic re-use from www.copyright.com. All other uses, submit a request to [email protected]. For more information visit Asset & Logo Licensing.
You Might Like
View AllCFPB Proposes Rule to Regulate Data Brokers Selling Sensitive Information
5 minute readTrending Stories
Who Got The Work
J. Brugh Lower of Gibbons has entered an appearance for industrial equipment supplier Devco Corporation in a pending trademark infringement lawsuit. The suit, accusing the defendant of selling knock-off Graco products, was filed Dec. 18 in New Jersey District Court by Rivkin Radler on behalf of Graco Inc. and Graco Minnesota. The case, assigned to U.S. District Judge Zahid N. Quraishi, is 3:24-cv-11294, Graco Inc. et al v. Devco Corporation.
Who Got The Work
Rebecca Maller-Stein and Kent A. Yalowitz of Arnold & Porter Kaye Scholer have entered their appearances for Hanaco Venture Capital and its executives, Lior Prosor and David Frankel, in a pending securities lawsuit. The action, filed on Dec. 24 in New York Southern District Court by Zell, Aron & Co. on behalf of Goldeneye Advisors, accuses the defendants of negligently and fraudulently managing the plaintiff's $1 million investment. The case, assigned to U.S. District Judge Vernon S. Broderick, is 1:24-cv-09918, Goldeneye Advisors, LLC v. Hanaco Venture Capital, Ltd. et al.
Who Got The Work
Attorneys from A&O Shearman has stepped in as defense counsel for Toronto-Dominion Bank and other defendants in a pending securities class action. The suit, filed Dec. 11 in New York Southern District Court by Bleichmar Fonti & Auld, accuses the defendants of concealing the bank's 'pervasive' deficiencies in regards to its compliance with the Bank Secrecy Act and the quality of its anti-money laundering controls. The case, assigned to U.S. District Judge Arun Subramanian, is 1:24-cv-09445, Gonzalez v. The Toronto-Dominion Bank et al.
Who Got The Work
Crown Castle International, a Pennsylvania company providing shared communications infrastructure, has turned to Luke D. Wolf of Gordon Rees Scully Mansukhani to fend off a pending breach-of-contract lawsuit. The court action, filed Nov. 25 in Michigan Eastern District Court by Hooper Hathaway PC on behalf of The Town Residences LLC, accuses Crown Castle of failing to transfer approximately $30,000 in utility payments from T-Mobile in breach of a roof-top lease and assignment agreement. The case, assigned to U.S. District Judge Susan K. Declercq, is 2:24-cv-13131, The Town Residences LLC v. T-Mobile US, Inc. et al.
Who Got The Work
Wilfred P. Coronato and Daniel M. Schwartz of McCarter & English have stepped in as defense counsel to Electrolux Home Products Inc. in a pending product liability lawsuit. The court action, filed Nov. 26 in New York Eastern District Court by Poulos Lopiccolo PC and Nagel Rice LLP on behalf of David Stern, alleges that the defendant's refrigerators’ drawers and shelving repeatedly break and fall apart within months after purchase. The case, assigned to U.S. District Judge Joan M. Azrack, is 2:24-cv-08204, Stern v. Electrolux Home Products, Inc.
Featured Firms
Law Offices of Gary Martin Hays & Associates, P.C.
(470) 294-1674
Law Offices of Mark E. Salomone
(857) 444-6468
Smith & Hassler
(713) 739-1250