What a Global Botnet Attack Teaches Malaysian SMEs

What a Global Botnet Attack Teaches Malaysian SMEs — featured image

by

Why a Distant Cyberattack Should Matter to Your Business

You may run a workshop in Johor, a trading company in Penang, or a professional services firm in Kuala Lumpur. A large cyberattack involving American government agencies can feel far removed from your daily operations. You may assume attackers only pursue governments, banks, or large corporations.

That assumption can leave a smaller business exposed. Criminal groups often look for poorly protected routers, cameras, computers, cloud accounts, and websites because these devices can be used quietly as stepping stones. Your business may not be the final target, but your systems could still become part of someone else’s attack.

The reported seizure of domains linked to the QTFY botnet shows how attackers can operate through thousands of compromised internet-connected devices. The botnet was allegedly used against organisations including NASA, the Federal Reserve, and several United States departments, with activity dating back to 2018. Source: TechCrunch

TL;DR

A botnet is a network of hacked devices controlled remotely. Even a small Malaysian business can be affected if its devices are outdated, exposed online, or poorly managed.

Your practical response is to map every connected device, strengthen account access, update systems, back up important information, and prepare a simple incident plan.

What This Means

A botnet is a group of computers, servers, routers, cameras, or other connected devices infected with malicious software. Once compromised, the devices can receive instructions from an attacker without the owner realising it.

In the reported case, prosecutors alleged that a Chinese company operated a botnet containing thousands of compromised internet-connected devices. The network acted as an obfuscation or hiding layer. In plain language, attackers could route harmful activity through other people’s devices, making the original source more difficult to identify. Source: TechCrunch

The botnet depended on domains and command-and-control servers to communicate with infected devices. According to the United States Department of Justice statement reported by TechCrunch, the seized domains made the botnet inoperable because those domain addresses were built into the malware and were essential for communication. Source: TechCrunch

This is important for you because cyber risk is not limited to a direct attack on your company. Your business can face at least three forms of exposure:

  • Your device becomes part of a botnet: An infected router, computer, camera, or server may send traffic or perform tasks for an attacker.
  • Your business becomes a target: Attackers may steal customer information, access email accounts, or disrupt operations.
  • Your supplier becomes the entry point: A compromised software provider, outsourced IT account, or shared login may provide access to your systems.

How This Applies to Malaysian SMEs

Many Malaysian SMEs operate with a mixture of office computers, staff laptops, Wi-Fi routers, point-of-sale devices, cloud applications, CCTV systems, printers, and mobile phones. These systems are often added over time, sometimes by different people. If nobody keeps a complete list, you may not know which device is still using an old password or unsupported software.

Consider a small wholesaler with a warehouse and office. Staff may use a cloud accounting platform, email, barcode scanners, a Wi-Fi router, and remote access for the owner. If the router still uses its default administrator password, or if remote access is open to the internet without multi-factor authentication, an attacker may gain a foothold. The business might first notice something unusual through slow internet, failed logins, or strange outbound traffic.

A retail outlet faces a different concern. Its payment terminals may be managed by a payment provider, while its staff use shared tablets for stock checks and customer enquiries. The owner should confirm which systems are managed by the provider and which remain the company’s responsibility. A device that is no longer supported, rarely updated, or shared without individual accounts deserves attention.

Professional firms such as accountants, agencies, clinics, and engineering consultancies hold valuable documents even when they are small. Client contracts, identity documents, payroll files, drawings, and correspondence can be attractive to attackers. If one employee’s email account is taken over, the attacker may impersonate that person, search for sensitive attachments, or request changes to supplier bank details.

Malaysian SMEs also commonly depend on outsourced IT support. That arrangement can be helpful, but you should know how the provider accesses your systems, who approves changes, whether access is logged, and how quickly access is removed when a technician leaves. A shared administrator password creates uncertainty during an incident and makes accountability difficult.

Useful numbers to track

Area Practical target Why it matters
Device inventory Review every 3 months Helps identify unknown or forgotten devices
Critical software updates Apply within 14 days where practical Reduces exposure to known weaknesses
Backup checks Test at least once every 3 months Confirms that recovery is possible, not merely assumed
Security training Brief staff every 6 months Keeps phishing and reporting procedures familiar
Administrator accounts Use individual accounts, not shared logins Improves control and investigation

These are management targets rather than legal requirements. Adjust them according to your systems, industry, and advice from your IT provider. The key is to make security a repeatable business process rather than a one-time technical project.

Your business does not need to be famous to be useful to an attacker; it only needs to be connected, accessible, and overlooked.

Practical Takeaways for Your Business

  • List all connected devices. Include routers, laptops, desktops, cameras, printers, servers, tablets, and remote-access tools.
  • Change default passwords immediately. Use long, unique passwords for routers, administrator accounts, cloud services, and devices.
  • Turn on multi-factor authentication. Start with email, accounting, file storage, payroll, and administrator accounts.
  • Remove unused access. Close old staff accounts, former supplier access, unused remote desktop tools, and inactive applications.
  • Update or replace unsupported devices. If a router, camera, or operating system no longer receives security updates, ask your IT provider for a replacement plan.
  • Separate important systems. Keep guest Wi-Fi away from office computers, payment devices, and business servers.
  • Back up critical information. Keep more than one copy, protect backups from ordinary user access, and test restoration.
  • Teach staff how to report concerns. They should know where to send suspicious emails, unexpected login alerts, and unusual payment requests.
  • Prepare an incident contact list. Include your IT provider, software vendors, management, bank contact, insurer if applicable, and relevant authorities.
  • Review supplier responsibilities. Ask who monitors security, who applies updates, and how quickly incidents will be communicated.

A Simple 30-Day Action Plan

During the first week, identify your most important operations: customer communication, order processing, payroll, accounting, inventory, and document storage. Record the systems used for each one and name the person responsible for them.

During the second week, secure the highest-risk accounts. Enable multi-factor authentication, change administrator passwords, remove former users, and confirm that email forwarding rules have not been created without approval.

During the third week, review devices and network settings. Update the router, check remote access, separate guest Wi-Fi, and ask your IT provider whether any device is end-of-life or exposed directly to the internet.

During the fourth week, test recovery. Choose one important file or system and confirm that you can restore it. Then run a short staff exercise: explain what they should do if a suspicious link is clicked or an unexpected payment instruction arrives.

The Bigger Picture

The botnet case illustrates a long-term change in cyber risk. Attackers no longer need to depend on one compromised organisation or one obvious server. They can use a distributed network of ordinary devices and commercial services to hide activity, test targets, and maintain access.

For you, this means cybersecurity belongs in normal business administration. It should be discussed alongside supplier management, continuity planning, data handling, and staff onboarding. You do not need a large security department to improve your position. You need visibility, consistent access controls, timely updates, tested backups, and a clear response process.

Government action such as domain seizures can disrupt an attacker’s infrastructure, but it does not automatically clean an infected device or protect a business from the next campaign. Your own systems still need monitoring and maintenance.

Make one practical improvement this week: create your device list, enable multi-factor authentication on your main email account, or schedule a backup restoration test. Small, documented steps give you a clearer picture of your risk and make it easier for your team to respond before a minor warning becomes a serious interruption.

Ready to Streamline Your Operations?

Your business should run itself. AutoRunBiz deploys AI agents to automate your daily operations — WhatsApp orders, invoicing, customer follow-ups, and accounting. Book a free 15-min ops audit to see where automation fits your business →