Posts

Showing posts with the label DDoS

Microsoft says massive Azure outage was caused by DDoS attack

Image
By Sergiu Gatlan,  Bleeping Computer Microsoft confirmed today that a nine-hour outage on Tuesday, which took down and disrupted multiple Microsoft 365 and Azure services worldwide, was triggered by a distributed denial-of-service (DDoS) attack. Redmond says the outage impacted Microsoft Entra, some Microsoft 365 and Microsoft Purview services (including Intune, Power BI, and Power Platform), as well as Azure App Services, Application Insights, Azure IoT Central, Azure Log Search Alerts, Azure Policy, and the Azure portal. The company confirmed in a mitigation statement published today that the root cause behind yesterday's outage was a DDoS attack, although it has yet to link it to a specific threat actor. "While the initial trigger event was a Distributed Denial-of-Service (DDoS) attack, which activated our DDoS protection mechanisms, initial investigations suggest that an error in the implementation of our defenses amplified the impact of the attack rather than mitigating i...

Why remote desktop tools are facing an onslaught of cyber threats

Image
By Solomon Klappholz, IT Pro Hackers are increasingly targeting remote desktop tools in their attacks, new research reveals, prompting warnings for enterprises globally In the era of hybrid work, remote desktop tools have become vital business enablers, but due to their pervasiveness on corporate networks they have become a popular entry point for cyber criminals. If successfully exploited, remote access tools can provide hackers with a direct pathway into a system or network, and once access is gained attackers can move laterally within the network, escalating privileges and maintaining persistence. In an investigation into which remote desktop tools are targeted the most, Jonathan Tanner, senior security researcher at Barracuda Networks, explained that remote desktop software poses a particular challenge to IT teams to secure. “Among the security challenges facing IT teams implementing remote desktop software is that there are many different tools available, each using different and ...

EU warns of Russian cyberattack spillover, escalation risks

By Sergiu Gatlan,  Bleeping Computer The Council of the European Union (EU) said today that Russian hackers and hacker groups increasingly attacking "essential" organizations worldwide could lead to spillover risks and potential escalation. "This increase in malicious cyber activities, in the context of the war against Ukraine, creates unacceptable risks of spillover effects, misinterpretation and possible escalation," the High Representative on behalf of the EU said Tuesday. "The latest distributed denial-of-service (DDoS) attacks against several EU Member States and partners claimed by pro-Russian hacker groups are yet another example of the heightened and tense cyber threat landscape that EU and its Member States have observed." In this context, the EU reminded Russia that all United Nations member states must adhere to the UN's Framework of responsible state behavior in cyberspace to ensure international security and peace. The EU urged all states ...

Lithuania warns of rise in DDoS attacks against government sites

By Bill Toulas,  Bleeping Computer The National Cyber Security Center (NKSC) of Lithuania has issued a public warning about a steep increase in distributed denial of service (DDoS) attacks directed against public authorities in the country. DDoS is a special type of cyberattack that causes internet servers to be overwhelmed by a large number of requests and garbage traffic, rendering the hosted sites and services inaccessible for legitimate visitors and users. According to NKSC, due to these cyberattacks, Lithuania's transportation agencies, financial institutions, and other large entities have experienced temporary service disruptions. “The NCSC urges all managers of critical information infrastructure and state information resources to take additional security measures and to follow the NCSC recommendations for protection against service disruption attacks,” advises the public notice. The agency provided a link to a PDF containing extensive guidance on defending against all types...

Cloudflare mitigates record-breaking HTTPS DDoS attack

By Sergiu Gatlan,  Bleeping Computer Internet infrastructure firm Cloudflare said today that it mitigated a 26 million request per second distributed denial-of-service (DDoS) attack, the largest HTTPS DDoS attack detected to date. The record-breaking attack occurred last week and targeted one of Cloudflare's customers using the Free plan. The threat actor behind it likely used hijacked servers and virtual machines seeing that the attack originated from Cloud Service Providers instead of weaker Internet of Things (IoT) devices from compromised Residential Internet Service Providers. According to Cloudflare, the attacker also used a rather small yet very powerful botnet of 5,067 devices, each capable of generating roughly 5,200 rps when peaking. "To contrast the size of this botnet, we've been tracking another much larger but less powerful botnet of over 730,000 devices," revealed Cloudflare Product Manager Omer Yoachimik. "The latter, larger botnet wasn't able...

“Downthem” DDoS-for-Hire Boss Gets 2 Years in Prison

By  Krebs On Security A 33-year-old Illinois man was sentenced to two years in prison today following his conviction last year for operating services that allowed paying customers to launch powerful distributed denial-of-service (DDoS) attacks against hundreds of thousands of Internet users and websites. Matthew Gatrel of St. Charles, Ill. was found guilty for violations of the Computer Fraud and Abuse Act (CFAA) related to his operation of downthem[.]org and ampnode[.]com, two DDoS-for-hire services that had thousands of customers who paid to launch more than 200,000 attacks. Despite admitting to FBI agents that he ran these so-called “booter” services (and turning over plenty of incriminating evidence in the process), Gatrel opted to take his case to trial, defended the entire time by public defenders. Gatrel’s co-defendant and partner in the business, Juan “Severon” Martinez of Pasadena, Calif., pleaded guilty just before the trial. After a nine-day trial in the Central District...

FBI seizes domains used to sell stolen data, DDoS services

By Sergiu Gatlan, Bleeping Computer The Federal Bureau of Investigation (FBI) and the U.S. Department of Justice announced today the seizure of three domains used by cybercriminals to sell personal info stolen in data breaches and provide DDoS attack services. WeLeakInfo.to was selling subscriptions allowing its users to search a database containing information stolen in more than 10,000 data breaches. The roughly 7 billion records contained various personally identifiable information (PII), including names, email addresses, usernames, phone numbers, and passwords for online accounts. Two other domains, ipstress.in and ovh-booter.com, were used to provide booter or stressor attack services where clients could ask for a website or web platform of their choice to be taken down in large-scale Distributed Denial of Service (DDoS) attacks. "Today, the FBI and the Department stopped two distressingly common threats: websites trafficking in stolen personal information and sites which att...

Microsoft detects massive surge in Linux XorDDoS malware activity

Image
By Sergiu Gatlan, Bleeping Computer A stealthy and modular malware used to hack into Linux devices and build a DDoS botnet has seen a massive 254% increase in activity during the last six months, as Microsoft revealed today. This malware (active since at least 2014) is known as XorDDoS (or XOR DDoS) due to its use of XOR-based encryption when communicating with command-and-control (C2) servers and being employed to launch distributed denial-of-service (DDoS) attacks. As the company revealed, the botnet's success is likely due to its extensive use of various evasion and persistence tactics which allow it to remain stealthy and hard to remove. "Its evasion capabilities include obfuscating the malware's activities, evading rule-based detection mechanisms and hash-based malicious file lookup, as well as using anti-forensic techniques to break process tree-based analysis," Microsoft 365 Defender Research Team said. "We observed in recent campaigns that XorDdos hides m...

Eurovision cyberattack: pro-Russian hackers declared 'war' on ten states

Image
A pro-Russian hacker group that targeted the Eurovision song contest declared 'war' against Italy and ten other countries. By Vilius Petkauskas, Cybernews Killnet, a pro-Russian hacker group, was not happy the Italian police announced successfully blocking distributed denial-of-service (DDoS) attacks on the Eurovision song contest hosted by Italy. The Italian police announced that hackers had unsuccessfully tried to infiltrate the opening night and the finals of the song contest. Ukrainian folk-rap band Kalush Orchestra (pictured in the lead photo) performed on both nights of the attacks. Despite the attempted attacks, however, Ukraine went on to win the Eurovision song contest. In contrast, Russia was barred from the event, boasting a viewership of 200 million, due to Moscow's invasion of Ukraine on 24 February. The Italian authorities claim that over 100 officers monitored the event, thus preventing attempts to hinder the contest that most European nations took part in. ...

Phishing Campaign by Russian Hackers Uses Trello, Dropbox to Target Diplomats

By Scott Ikeda, CPO Magazine A newly-uncovered phishing campaign is targeting diplomats by presenting malicious messages as official embassy communications, and basing out of legitimate cloud-based services such as DropBox and Trello to aid in evading detection and remediation. The scheme was uncovered by security firm Mandiant , who believe that state-backed Russian hackers are behind it. Embassies targeted by Russian hackers The phishing campaign is just one element of a rash of recent activity by advanced persistent threat group 29 (APT 29), probably better known to the general public as “Cozy Bear.” Believed to be backed by Russian intelligence, the group conducted a similar operation in 2021 that focused on compromising diplomats via legitimate-looking Constant Contact emails. Mandiant says that the current phishing campaign makes use of legitimate email addresses that have been previously compromised, and opens with what appears to be an administrative notice from an embassy. The...

Pro-Ukraine hackers use Docker images to DDoS Russian sites

Image
By Bill Toulas,       Bleeping Computer Docker images with a download count of over 150,000 have been used to run distributed denial-of-service (DDoS) attacks against a dozen Russian and Belarusian websites managed by government, military, and news organizations. Behind the incidents are believed to be pro-Ukrainian actors such as hacktivists, likely backed by the country's IT Army. DDoS cyberattacks aim to cripple operations of by sending out more requests than the target can handle and becomes unavailable to legitimate clients. Targeting Docker APIs Among the 24 domains targeted include that of the Russian government, the Russian military, and Russian media like the TASS news agency. Two Docker images involved in the attacks were spotted by threat researchers at cybersecurity company CrowdStrike, who observed them being deployed between February and March 2022. Targeting exposed Docker APIs isn’t anything novel, as cryptocurrency mining gangs like Lemon_Duck and Te...

Russian hacktivists launch DDoS attacks on Romanian govt sites

Image
By Bill Toulas, Bleeping Computer The Romanian national cyber security and incident response team, DNSC , has issued a statement about a series of distributed denial-of-service (DDoS) attacks targeting several public websites managed by the state entities. The attack has been claimed by a pro-Russian group calling themselves Killnet . They targeted servers that host public sites with a high number of requests or high volumes of data, essentially depleting their processing resources and causing them to become unavailable. All websites are currently working. According to the DNSC announcement, attackers targeted the following websites: gov.ro (official website of Romania's Government) mapn.ro (official website of Romania's Ministry of Defense) politiadefrontiera.ro (official of Romanian Border Police) cfrcalatori.ro (official website of Romania's National Railway Transport Company) otpbank.ro (site of a commercial bank operating in Romanian)  DNSC is now collaborating with ot...

Ukraine targeted by DDoS attacks from compromised WordPress sites

Image
By Bill Toulas, Bleeping Computer Ukraine's computer emergency response team (CERT-UA) has published an announcement warning of ongoing DDoS (distributed denial of service) attacks targeting pro-Ukraine sites and the government web portal. The threat actors, who at this time remain unknown, are compromising WordPress sites and injecting malicious JavaScript code to perform the attacks. These scripts are placed in the HTML structure of the main files of the website and are base64-encoded to evade detection. The code runs on the website visitor's computer and directs their available computational resources to generate an abnormal number of requests to attack objects (URLs) defined in the code. The result is that some of the target websites are overwhelmed by the requests and, as a result, rendered inaccessible to their regular visitors. This all happens without the owners or the visitors of the compromised sites ever realizing it, except for maybe some barely noticeable performan...

Hackers Claim to Target Russian Institutions in Barrage of Cyberattacks and Leaks

Image
By Kate Conger and David E. Sanger, New York Times Hackers claim to have broken into dozens of Russian institutions over the past two months, including the Kremlin's internet censor and one of its primary intelligence services, leaking e-mails and internal documents to the public in an apparent hack-and-leak campaign that is remarkable in its scope. The hacking operation comes as the Ukrainian government appears to have begun a parallel effort to punish Russia by publishing the names of purported Russian soldiers who operated in Bucha, Ukraine, the site of a massacre of civilians, and agents of the FSB, a major Russian intelligence agency, along with identifying information like dates of birth and passport numbers. It is unclear how the Ukrainian government obtained those names or whether they were part of the hacks. Much of the data released by the hackers and the Ukrainian government is by its nature impossible to verify. As an intelligence agency, the FSB would never confirm a l...

Five Eyes Alert Warns of Heightened Risk of Russian Cyber Attacks

Image
By John Besley, Bloomberg Critical infrastructure organizations within the UK have been urged to ramp up their cyber security defenses as they face a heightened risk of Russian state-sponsored cyber attacks. An alert issued by the Five Eyes intelligence alliance, which consists of the UK, Australia, Canada, New Zealand and the United States, has warned the Russian government is exploring options for potential cyberattacks against critical organizations such as the NHS, nuclear power stations and parts of the civil service. According to the alert, "evolving intelligence" suggests hackers within the Russian government are seeking to engage in "malicious cyber activity" in response to the "unprecedented economic sanctions" imposed on Russia following its invasion of Ukraine. There is also concern that hackers are targeting critical infrastructure in countries that have provided "materiel support" to Ukrainian forces. There are also risks posed by nu...

Free decryptor released for Yanluowang ransomware victims

Image
By Sergiu Gatlan, Bleeping Computer Kaspersky today revealed it found a vulnerability in Yanluowang ransomware's encryption algorithm, which makes it possible to recover files it encrypts. The Russian cybersecurity firm has added support for decrypting files locked by the Yanluowang ransomware strain to its RannohDecryptor utility. "Kaspersky experts have analyzed the ransomware and found a vulnerability that allows decrypting files of affected users via a known-plaintext attack," the company said today . This ransomware strain encrypts files bigger than 3GB and those smaller than 3GB using different methods: larger ones are partially encrypted in 5MB stripes after every 200MB, while smaller ones are entirely encrypted from start to end. Because of this, "if the original file is larger than 3 GB, it is possible to decrypt all files on the infected system, both big and small. But if there is an original file smaller than 3 GB, then only small files can be decrypted....