23-Year-Old Noboru Botnet Dismantled in Global Law Enforcement Operation
23-Year-Old Noboru Botnet Dismantled in Global Law Enforcement Operation
A massive botnet that had lurked in the shadows for more than two decades finally met its end through coordinated action by international law enforcement agencies and security researchers at CrowdStrike. π¨ The operation dismantled what authorities described as one of the longest-running cybercrime infrastructures ever discovered, a network that quietly amassed more than 15,000 compromised computers across dozens of countries while remaining largely undetected for 23 years.
The botnet, known internally among its operators as βNoboru,β relied on a sophisticated modular malware strain that first appeared in the early 2000s. π¦ Security teams at TechRadar reported that the infrastructure combined old-school command-and-control techniques with modern evasion methods, allowing it to survive multiple waves of antivirus updates, operating system upgrades, and law enforcement takedowns aimed at similar threats. Unlike many contemporary botnets that burn out after a few years of heavy abuse, Noboru maintained a low profile, focusing on steady data exfiltration and occasional ransomware deployment rather than noisy distributed denial-of-service attacks that draw immediate attention.
The successful disruption required close collaboration between private sector researchers and government agencies across multiple jurisdictions. π€ CrowdStrike provided detailed telemetry, including lists of command-and-control infrastructure and samples of the latest malware variants. Law enforcement teams then obtained court orders to seize domains and redirect traffic to sinkhole servers that logged remaining victim connections without allowing further malicious commands. Within 48 hours of the coordinated action, global infection numbers dropped by more than 90 percent according to independent monitoring systems.