Tag Archives: ddos extortion ransom demand

Botnet for Hire DDOS: What Defenders Should Do

A four minute outage on a Tuesday morning, an email quoting a cryptocurrency address, and a screenshot of a control panel with a countdown timer on it: for most mid-sized UK firms, that is what a botnet for hire DDoS attack looks like from the inside. It looks nothing like the terabit-per-second records that fill vendor datasheets. The attack is short, it is bought by the minute, and it is aimed at whichever part of the estate nobody bought protection for. Booters and stressers, the subscription websites that sell distributed denial-of-service (DDoS) capacity to anyone with a payment method, have turned what used to be a specialist capability into a consumer product with a pricing page.

What follows maps what the hire market realistically delivers against the three surfaces that need defending, and what a UK protection contract has to say in writing before it is worth signing.

What the DDoS-for-hire market actually sells today

The product is a subscription, not a hit. Buyers pay monthly for a tier that caps attack duration (often measured in minutes rather than hours), limits how many attacks can run concurrently, and unlocks particular attack methods on the higher plans. The National Crime Agency has repeatedly described these services as cheap and requiring almost no technical skill, which is why the volume of nuisance attacks against small and mid-sized targets stays stubbornly high. Cost is not the constraint. Duration is.

The firepower behind the panel has also changed. Classic Windows PC botnets have largely given way to compromised Internet of Things devices (routers, cameras, digital video recorders), hijacked cloud instances bought with stolen cards, open reflectors on the public internet, and rented residential proxy pools that route requests through real consumer broadband lines. That last category matters more than the raw node count, and the mitigation section below explains why.

The “stress testing”framing on these sites is a fig leaf. A legitimate load-testing service verifies domain ownership, requires written authorisation from the asset owner, and agrees a test window. Booters do none of that. You type in a hostname or IP address and press start.

Enforcement has changed the market without ending it. Operation PowerOFF, the international campaign run with Europol, the FBI and the NCA, has seized booter domains in successive waves since 2018, and in March 2023 the NCA disclosed that it had been running its own fake DDoS-for-hire sites to collect data on the people signing up. Takedowns compress supply for a while; new panels appear under new branding. What has genuinely shifted is buyer risk, because the paper trail now sometimes leads back through law enforcement infrastructure.

Four attack profiles a rented botnet actually delivers

Short volumetric bursts

Because the subscription pays for duration, the typical hired attack is a burst sized to fit the slot: a few minutes of packets-per-second aimed at your uplink, sometimes repeated on a loop through the working day. Against this profile, peak scrubbing capacity on a datasheet is close to irrelevant. If detection plus diversion takes fifteen minutes and the attack lasts five, the traffic has stopped before mitigation engaged, and you still took the outage, still fielded the customer complaints, and still have nothing useful in the incident report. Time-to-mitigate, with a defined clock start, is the number that decides the outcome.

Reflection and amplification

Reflection borrows other people’s bandwidth. The attacker spoofs your address and queries open services on the internet, which then send far larger replies to you. CISA’s alert TA14-017 on UDP-based amplification attacks lists indicative bandwidth amplification factors including roughly 556 times for Network Time Protocol (NTP) and up to 51,000 times for memcached, alongside Domain Name System (DNS) and Connection-less Lightweight Directory Access Protocol (CLDAP) vectors. The 1.35 Tbps memcached flood against GitHub in February 2018, documented publicly by Akamai, came from a modest number of reflectors. The practical consequence for a mid-sized firm is unpleasant: the botnet does not need to be large to saturate a 1 Gbps or 10 Gbps uplink.

HTTP floods through residential proxies

Layer 7 attacks skip the pipe and go for the expensive parts of the application: internal site search, cart and checkout, login, password reset, and any API endpoint that hits the database on every call. Delivered through residential proxy pools, the requests arrive from real UK consumer IP addresses with clean reputation scores. Blocklists and ASN filtering do very little here. A modest rate of well-shaped requests against a search endpoint can take down an origin that would shrug off a far larger volume of static page requests.

Authoritative DNS floods

The fourth profile is the one that keeps working, because it is the one nobody bought protection for. Instead of attacking the website, the attacker floods the authoritative nameservers that answer queries for your domain. Resolve nothing, reach nothing: web, mail, VPN, API, all of it.

Which surfaces a hired botnet finds first

Network and transport. Ask your transit provider what it will absorb before your uplink saturates, and what it does when the flood exceeds that. Some will null-route your prefix to protect their own network, which achieves the attacker’s goal for them at no extra charge.

Application layer. A proxy tuned for volumetric traffic and a proxy tuned for bot behaviour are different products, sometimes from the same vendor at different price points. Absorbing 200 Gbps of UDP says nothing about whether the platform can separate a residential-proxy request flood from genuine Black Friday demand.

Authoritative DNS. This is the most common gap in UK estates: the web front end sits behind a paid proxy while authoritative DNS stays on the registrar’s free tier, unmonitored and unmentioned in the mitigation contract. A rented botnet pointed at those nameservers takes the whole estate offline without ever touching the protected site. Proper DNS DDoS attack protection means anycast authoritative service with query-rate controls, spread across more than one provider if the domain earns revenue, and it needs to be a named line item in the contract rather than an assumption.

Origin IP leakage. Proxy bypass is far more often a leak than a breakthrough. Historical DNS records in passive DNS databases, certificate transparency logs listing every subdomain you have ever issued a certificate for, outbound mail headers advertising the origin, and forgotten staging, webmail or cPanel hostnames all publish the address the proxy is meant to hide. Rotating the origin IP after onboarding and locking the origin firewall to the proxy’s published ranges costs an afternoon. Buying more capacity to compensate costs a great deal more and does not fix the hole.

Matching mitigation to the threat

Reverse proxy. Fastest to deploy, strongest at layer 7, and the right answer for HTTP floods. Worthless if the origin address is public and the origin firewall accepts traffic from anywhere.

BGP scrubbing. Diverts whole IP ranges, covers non-HTTP services such as SMTP, game protocols, VPN concentrators and RDP gateways, and is the only sensible model if you run your own address space. The trade-offs are route convergence time, the return path (GRE tunnel or dedicated link) and the fact that on-demand diversion has to be triggered before it does anything.

Hosting-level or transit filtering. Read the small print. Plenty of firms sold as a DDoS protected hosting provider include basic layer 3 and 4 filtering at the edge with everything meaningful, layer 7 rules, tuning, per-incident reporting, priced as an upsell. Ask for the mitigation capacity figure at the point of presence serving UK traffic, not the global aggregate.

On the always-on versus on-demand question, short bursts settle it. Detection plus diversion on an on-demand service frequently outlasts the attack, which is the whole argument for keeping traffic on-path permanently for revenue-generating assets. The trade-offs, latency, cost and change control, are set out in more detail in this comparison of always-on and on-demand protection models, and the SLA wording that decides when the clock starts is picked apart in this guide to what time-to-mitigate seconds really mean.

Extortion, hacktivism and the note that arrives with the traffic

The ransom DDoS pattern has been stable for years: a short demonstration burst against a production asset, an email naming a deadline and a cryptocurrency wallet, and a threat of something far larger if the deadline passes. Sometimes the demonstration is impressive. Often it is a few minutes of reflection traffic bought from a booter panel, which tells you the sender’s budget runs to a subscription rather than a serious campaign.

Read the demonstration attack as evidence. Vector, duration, sustained bit rate and packet rate from your provider’s incident report are a better guide to real capability than anything in the note itself. A three minute NTP reflection burst and a promise of 2 Tbps do not belong to the same actor.

Paying is the wrong move for reasons that have nothing to do with principle. Payment confirms a working email address, a solvent victim and a decision-maker who folds, which is exactly the profile that gets resold. Preserve the note with full headers, report to Action Fraud (serious incidents get escalated to the NCA), and tell your mitigation provider immediately so they can raise thresholds before the deadline. On communications, publish a status page acknowledging degraded service and nothing about which vendor is mitigating, which thresholds tripped or what the traffic is doing. The first hour of decisions is covered in more depth in this playbook for an ecommerce site under attack.

The UK legal position for buyers, sellers and victims

Two provisions of the Computer Misuse Act 1990 do the work. Section 3 covers unauthorised acts intended to impair the operation of a computer, which is what a DDoS attack is. Section 3A covers making, supplying or obtaining articles for use in such offences, and it is the provision that reaches booter operators and, in some cases, their customers.

Buying an attack is an offence even if the buyer never touches the target. Payments leave records, panels keep logs, and seized infrastructure has produced customer lists more than once. Prosecutions of the people behind botnets do happen, as in the case of the Florida man charged over a botnet attack on Akamai, though attribution more often stalls at spoofed source addresses, bulletproof hosting and jurisdictions that do not answer requests.

Victims should log the mitigation provider’s attack report with vector breakdown and timestamps, netflow or sampled traffic from the edge, application logs showing failed transactions, and a defensible estimate of lost revenue. Do that before assuming anyone will be arrested, because the evidence file has value for insurance and for the contract review regardless.

Buying protection that holds up: what to ask before you sign

Most UK contracts in this space are resale to some degree, which is not automatically a problem. Not knowing is the problem. Three questions separate a real service from a reseller dashboard:

  • Whose scrubbing network sits behind the invoice, and what is the contracted capacity at the point of presence serving UK traffic?
  • During an attack, does escalation reach an engineer at the underlying network operator, or does it stop at a first-line desk that raises a ticket?
  • Is a named human empowered to change policy at 03:00 without your sign-off? If not, you have bought monitoring, not management.

“Managed”should mean onboarding and initial rule tuning, traffic baselining before the first incident, alerting to named contacts, out-of-hours cover with a defined response target, a written escalation matrix and a per-incident attack report afterwards. Ask for a time-to-mitigate SLA with the clock start defined in the contract, and rehearse the failover at least once with the provider on the call. Typical structures and price bands are broken down in this guide to managed DDoS protection in the UK.

Build the business case on the real threat model, not a hypothetical record breaker. Work it through with your own figures: a retailer turning over £40,000 an hour at peak would, on a straight pro-rata basis, lose in the region of £2,700 for every four minute burst that lands in the wrong window. Four of those a year, plus the support cost and the customers who bounce to a competitor, is the number to put next to the annual protection fee. Short repeated outages are what the hire market delivers, and they are what the budget line has to be justified against.

Frequently Asked Questions

What does a botnet for hire DDoS attack actually cost the attacker?

Booter and stresser plans are sold as low-cost monthly subscriptions with tiered attack duration limits and concurrent attack slots, rather than per-attack pricing. The NCA has consistently described these services as cheap and requiring little technical skill. The practical point for defenders is that the cost of launching a nuisance attack is trivially low compared with the cost of absorbing one.

Is buying a DDoS-for-hire or booter service illegal in the UK?

Yes. Section 3 of the Computer Misuse Act 1990 covers unauthorised acts intended to impair the operation of a computer, and section 3A covers obtaining or supplying articles for use in such offences. Paying someone else to run the attack does not put a buyer outside the Act, and the NCA’s March 2023 disclosure that it ran fake booter sites shows enforcement is aimed at customers as well as operators.

Can a rented botnet get past Cloudflare or another reverse proxy?

Usually by going around it rather than through it. Origin IP addresses leak through historical DNS records, certificate transparency logs, outbound mail headers and forgotten staging or webmail subdomains, and traffic sent straight to the origin never meets the proxy. Rotate the origin address after onboarding and restrict the origin firewall to the proxy’s published IP ranges.

Should we pay a ransom DDoS demand?

No. Payment identifies you as a target that pays and tends to invite repeat demands, sometimes from different actors. Preserve the note with full headers, report it to Action Fraud, notify your mitigation provider so they can tighten thresholds before the stated deadline, and treat the demonstration burst as evidence of what the sender can actually do.

How do we tell a hired-botnet attack from a traffic spike or a bad crawler?

Genuine demand and legitimate crawlers follow the shape of your site: varied paths, referrers, session progression and a plausible geographic mix. A hired layer 7 flood concentrates on a small number of expensive endpoints, shows near-identical request timing and header patterns, and produces no conversions or downstream page views. Baselining traffic before an incident is what makes that comparison possible on the day.