Category Archives: DDoS Criminals

Mystery hacker hijacks Dridex Trojan botnet… to serve antivirus installer

Ah, great. Ave AV Part of the distribution channel of the Dridex banking Trojan botnet may have been hacked, with malicious links replaced by installers for Avira Antivirus.…

Link:
Mystery hacker hijacks Dridex Trojan botnet… to serve antivirus installer

HSBC Calls In Cops To Chase DDoS Attackers Who Took Online Banking Down

HSBC said today it was working with local police to find those who disrupted its online banking services with a denial of service attack, as customers complained of not being able to access their accounts. The attack was made even more painful for customers as the last Friday of the month is a traditional payday in the UK, the home of HSBC. Little information was provided by HSBC other than a terse statement over Twitter: “HSBC UK internet banking was attacked this morning. We successfully defended our systems. “We are working hard to restore services, and normal service is now being resumed. We apologise for any inconvenience.” A spokesperson told the BBC a denial of service attack was the cause of the downtime. A subsequent tweet revealed the police had been contacted: “HSBC is working closely with law enforcement authorities to pursue the criminals responsible for today’s attack on our Internet banking.” HSBC was hit by a distributed denial of service (DDoS), where infected machines fire an overwhelming number of data packets at a server to stop it working, most recently in 2012. That time the Anonymous hacktivist crew was believed to have carried out the hit. DDoS attacks in general have been causing havoc in recent months, as criminals have tried to extort targets, threatening to knock businesses offline unless a ransom was paid. Encrypted email provider ProtonMail was criticised for paying a ransom of $6,000 in Bitcoin at the end of 2015 to a DDoS extortionist crew called the Armada Collective. That group targeted other secure email providers Hushmail, Runbox and VFEMail. Anti-DDoS provider Arbor Networks reported earlier this month that the record for DDoS power hit a new peak in 2015, hitting 500Gbps. Numerous organizations had reported attacks in the 400Gbps-500Gbps range throughout 2015, Arbor noted. With so much power, and such easy money to be made with extortion attacks, no business appears immune from DDoS downtime. Professor Alan Woodward, a security expert from the University of Surrey, said an attack capable of taking down an entity like HSBC would need to be big. “In addition we’re seeing the emergence of techniques that mean that these attacks are circumventing some of the systems put in place to mitigate agains these attacks,” Woodward said. He also warned DDoS has been used as a “smokescreen” for other malicious activity in the past. “They want to tie up the technical departments, of which there is obviously a finite number, so that they might miss some unusual activity that would give away the fact that the hackers are breaches the corporate boundary.” Source: http://www.forbes.com/sites/thomasbrewster/2016/01/29/hsbc-ddos-downtime/2/#4eea0f825126 http://www.forbes.com/sites/thomasbrewster/2016/01/29/hsbc-ddos-downtime/#109a8cc451c2

Taken from:
HSBC Calls In Cops To Chase DDoS Attackers Who Took Online Banking Down

Israeli academics claim they can predict botnet attacks

Isolated attacks can add up to concerted malbot action , say boffins Ben Gurion University researchers have developed a tool capable of predicting future botnet attacks while also distinguishing between human and automated campaigns.…

Read More:
Israeli academics claim they can predict botnet attacks

Irish government websites hit by widening DDoS attacks

First they came for the forums. Then the lottery. Now… A number of Irish government-related and public sector websites were knocked offline by an apparent DDoS attack on Friday morning.…

Read More:
Irish government websites hit by widening DDoS attacks

Irish lottery site and ticket machines hit by DDoS attack

Ireland’s National Lottery website and ticket machines were knocked offline after a distributed denial of service (DDoS) attack on Wednesday. Customers trying to buy tickets for the €12m (£9m) draw found themselves unable to do so for nearly two hours. The jackpot was the largest in 18 months. Premier Lotteries Ireland (PLI), the operator, has said the incident is under investigation. During a DDoS attack, a website or online service’s capacity to handle internet traffic is overloaded – usually by automated programs set to flood the site with requests. The attack began at 11:21 GMT on Wednesday and lasted for about two hours. Retail systems were brought back online by 12:45 GMT and the website by 13:25 GMT. “They said you couldn’t buy tickets from the ticket machines, which is really interesting, it’s not just the website – it would be quite interesting to understand why that happened,” said John Graham-Cumming at DDoS-protection company Cloudflare. ‘Under investigation’ “This incident is still under investigation,” a spokeswoman said. “However, we can confirm that at no point was the National Lottery gaming system or player data affected.” Given the large jackpot involved, the lottery was experiencing high demand for tickets on Wednesday lunchtime. The impact of the attack may well have been heightened by this, according to Igal Zeifman, senior digital strategist at cybersecurity company Imperva. “As a rule, record-setting prizes and jackpots result in traffic spikes on lottery sites, and it is very common for DDoS attackers to strike during such predictable peak traffic times, especially when going after big targets,” he said. Source: http://www.bbc.com/news/technology-35373890

See the original post:
Irish lottery site and ticket machines hit by DDoS attack

Bad luck, Ireland: DDoS attack disrupts isle’s National Lottery

Attack KO’d the website and ticket machines A DDoS attack disrupted the Irish National Lottery’s website and ticket machines on Wednesday (January 20).…

Read the article:
Bad luck, Ireland: DDoS attack disrupts isle’s National Lottery

Microsoft asks: We’ve taken down botnets for you. How about a kill switch?

It’s like pulling a smoking car off the road… Oh, hang on Last December, Microsoft intercepted traffic on users’ PCs and helped break up a botnet. And nobody complained. So the company very tentatively asked at a session on ethics and policy in Brussels this week whether it should do more.…

View post:
Microsoft asks: We’ve taken down botnets for you. How about a kill switch?

Microsoft: We’ve taken down the botnets. Europol: Would Sir like a kill switch, too?

It’s like pulling a smoking car off the road … hang on Last December, Microsoft intercepted traffic on users’ PCs and helped break up a botnet. And nobody complained. So the company very tentatively asked at a session on ethics and policy in Brussels this week whether it should do more.…

Link:
Microsoft: We’ve taken down the botnets. Europol: Would Sir like a kill switch, too?

DDoS Attack Hits Kickass Torrents, DNS Servers Crippled

Site goes down for most of the day on January 16 Kickass Torrents, the Internet’s biggest torrent portal has suffered downtime yesterday after an unknown attacker has pummeled the site with a DDoS attack. According to a statement given by the site’s administrators to TorrentFreak, a blog dedicated to piracy news, the attack was aimed at the website’s DNS servers. Because of this, both the main domain and the plethora of official site proxies were down as well. The brunt of the attack was registered yesterday, January 16, and had the site taken offline for almost all day. Previously, during the week, the site was also hit by smaller DDoS attacks. Everything seems to be up and running now, but expect future attacks as well. The attack fits the pattern of a DDoS extortion campaign, when small attacks are launched at first, and then a bigger one to force victims into paying the DDoS ransom. Earlier this week, Europol announced the capture of the famed DD4BC DDoS extortion group in Bosnia and Herzegovina. DD4BC is the first group known to launch DDoS attacks and then ask for payments in Bitcoin. The group’s actions have been copied by many other DDoSing outfits, and most DDoS attacks nowadays are launched for this reason. Kickass Torrents is one of Alexa’s top 100 sites on the Internet, meaning it’s an attractive target for DDoSing groups, thanks to its huge advertising revenue. Source: http://news.softpedia.com/news/ddos-attack-hits-kickass-torrents-dns-servers-crippled-499019.shtml

Read More:
DDoS Attack Hits Kickass Torrents, DNS Servers Crippled