Tag Archives: ddos news

Obad Android Trojan distributed via mobile botnets

When first unearthed three months ago, the Obad Android Trojan has fascinated researchers with its sophistication. Difficult to analyze, using a bug in the Android OS to extend Device Administrato…

Original post:
Obad Android Trojan distributed via mobile botnets

Fraud and identity theft camouflaged by DDoS attacks

Prolexic shared attack signatures and details that are helpful to detect and stop DDoS attacks from the Drive DDoS toolkit, an attack tool often used as a source of distraction while criminals break i…

More:
Fraud and identity theft camouflaged by DDoS attacks

Largest DDoS attack ever disrupts China's Internet

The China Internet Network Information Center (CNNIC), which maintains the registry for the .cn, China's country code top-level domain, has notified the public that two massive DDoS attacks have been …

See the original article here:
Largest DDoS attack ever disrupts China's Internet

Popular Windows downloader has secret DDoS capability

Unbeknownst to its users and perhaps even to its developers, the popular Windows download manager Orbit Downloader has been outfitted with a DDoS component. The Orbit Downloader has been around s…

Continued here:
Popular Windows downloader has secret DDoS capability

Cybercrooks use DDoS attacks to mask theft of banks’ millions

Distributed denial of service attacks have been used to divert security personnel attention while millions of dollars were stolen from banks, according to a security researcher. At least three US banks in recent months have been plundered by fraudulent wire transfers while hackers deployed “low powered” DDoS attacks to mask their theft, Avivah Litan, an analyst at research firm Gartner, told SCMagazine.com. She declined to name the institutions affected but said the attacks appeared unrelated to the wave of DDoS attacks last winter and spring that took down Web sites belonging to JP Morgan , Wells Fargo, Bank of America, Chase, Citigroup, HSBC, and others. “It wasn’t the politically motivated groups,” she said. “It was a stealth, low-powered DDoS attack, meaning it wasn’t something that knocked their website down for hours.” Litan described the attack method in a blog post last week that warned banks’ losses could have been much greater. “Once the DDoS is underway, this attack involves takeover of the payment switch (eg, wire application) itself via a privileged user account that has access to it,” she wrote. “Now, instead of having to get into one customer account at a time, the criminals can simply control the master payment switch and move as much money from as many accounts as they can get away with until their actions are noticed.” Litan, an expert in financial fraud and banking security, did not describe how attackers gained access to the wire payment switch at banks, but she offered banks advice on how they might better protect themselves. “One rule that banks should institute is to slow down the money transfer system while under a DDoS attack,” she wrote. “More generally, a layered fraud prevention and security approach is warranted.” Security researchers have previously highlighted the growing trend of using DDoS attacks to hide fraudulent activity at banks. The Dell SecureWorks Counter Threat Unit issued a report (PDF) in April to warn that a popular DDoS toolkit called Dirt Jumper was being used to divert bank employees’ attention from attempted fraudulent wire transfers of up to $2.1 million. In a joint statement (PDF) issued last September with the Financial Services Information Sharing and Analysis Center and the Internet Crime Complaint Center, the FBI warned that the $200 Dirt Jumper toolkit was being used as a smokescreen to cover fraudulent wire transfers conducted with pilfered employee credentials. “In some of the incidents, before and after unauthorized transactions occurred, the bank or credit union suffered a distributed denial of service (DDoS) attack against their public Website(s) and/or Internet Banking URL,” the report said. “The DDoS attacks were likely used as a distraction for bank personnel to prevent them from immediately identifying a fraudulent transaction, which in most cases is necessary to stop the wire transfer.” Source: http://news.cnet.com/8301-1009_3-57599646-83/cybercrooks-use-ddos-attacks-to-mask-theft-of-banks-millions/

Read the article:
Cybercrooks use DDoS attacks to mask theft of banks’ millions

ZeroAccess developers continue to innovate

A while ago a group of researchers has analyzed and tested the resilience of P2P botnets, and has discovered that while Zeus and Sality botnets are highly resilient to sinkholing attacks, Kelihos and …

More:
ZeroAccess developers continue to innovate

Bank man: System’s down, let’s have coffee. Oh SNAP, where’s all the CASH?

Hackers use DDoSes to distract staffers… while nicking MILLIONS Cybercrooks are running distributed denial of service attacks as a smokescreen to distract bank security staff while they plunder online banking systems, according to a researcher.…

Read the original:
Bank man: System’s down, let’s have coffee. Oh SNAP, where’s all the CASH?

GitHub code repository rocked by ‘very large DDoS’ attack

Second attack this month sees hackers git GitHub San Francisco–based GitHub, the online repository popular among software developers, suffered a major service outage on Thursday morning due to what it characterizes as a “very large DDoS attack.”… Learn how to leverage change for better IT And win a top of the range HP Spectre Ultrabook courtesy of HP and The Register! Click here to enter!

Taken from:
GitHub code repository rocked by ‘very large DDoS’ attack

Regions Bank Hit with New DDoS Attack

Regions Bank was the victim of cyber attackers that shuttered the bank’s website and interrupted its customers’ debit cards, reported AL.com. The bank’s website was hit Friday with a distributed-denial-of-service attack. Customers may have also not been able to use their debit cards at ATMs and merchants, according to a statement released to the website. “Access to regions.com and online banking were disrupted intermittently today by a distributed denial of service (DDoS) attack,” a spokesman told AL.com on Friday. “Some customers may have also been unable to use their CheckCards at ATMs or at merchants. We apologize for the difficulties this has caused and are working to resolve the issues as quickly as possible.” The attack comes on the heels of recent threats by from the hactivist group Izz ad-Din al-Qassam Cyber Fighters. Since last September, al-Qassam has taken responsibility for a series of cyber assaults that have plagued some of the nation’s largest banks — shuttering the online banking operations of Wells Fargo, PNC and dozens of others. Regions Bank was among those hit in early October. The Regions outage and debit card issues that occurred Friday reportedly lasted for nearly two hours. Source: http://www.americanbanker.com/issues/178_145/regions-bank-hit-with-new-ddos-attack-1060942-1.html

Read more here:
Regions Bank Hit with New DDoS Attack