Showing posts with label ddos attack. Show all posts
Showing posts with label ddos attack. Show all posts

Thursday, August 22, 2013

Cybercriminals use DDoS Attacks to make Millions


DDoS attack

Millions of dollars have been lost to a new tactic being used by cybercriminals call DDoS.  DDoS attacks or distributed denial-of-service attack is an attempt to make a machine or network service unavailable.  These attacks typically target high-profile web servers, banks, credit card companies, and even root nameservers.
DDoS attacks are more frequently hitting banking systems, by defrauding their system and diverting their security staffs attention while the account is being taken over.
These distributed denial of service attacks have been used to divert security personnel attention when there are millions of dollars stolen from accounts.  At least three US banks in recent months have been ransacked by fraudulent wire transfers while hackers set up a “low powered” DDoS attack.  Many websites including JP Morgan, Wells Fargo, Bank of America, Chase, and Citigroup have been hit.

Attack on your website

DDOS-Attack-Structure
Extortion threats are being made against numerous websites, including Cryptome which just released an “Opsecure DDoS Extortion” letter.  The letter stated that unless funds were transferred to the Bitcoin address, the Cryptome website “will be undergoing a distributed denial of service’ attack conducted by ’1 & 0 Logic Security Group.’”  The criminal demanded 1Bitcoin as payment, which is around $102.
DDoS attacks are illegal in many countries including the United States, they sustain because they are free.  With enough infected malware and control over their PCs or servers, these attackers can defeat almost any unprotected website.
Criminal operations are behind many of these DDoS disruptions.  BetaBot’s are a relatively new and economical piece of malware that’s built to deactivate information security software.  Smoke Loader is malware that is used to load addition malware such as crimeware toolkits.  These both remotely control DDoS tools – onto infected systems.
DDoS attack tools, have been a favorite of hacktivist.  In the run-up to the Anonymous backed attacks against North Korea, hacktivist recommended participants to get into one of the DDoS attack tools like Loris for Pythin and Windows.

DDoS attack worldwide

Vulnerabilities

Izz ad-Din al-Qassam Cyber Fighters, launched the Operation Ababil attacks against U.S. banks last year, favored the “itsoknoproblembro” toolkit, which is also known as Brobot.  These have entered into thousands of legitimate sites due to exploitation of a vulnerability in a WordPress plug-in.
In South Korea in October 2011, the DDoS attack was used to Disrupt the country’s Nation Election Commission website on teh day of a Seoul mayoral by-election.  “inofrmation on polling stations was made unavailable during morning hours when a large proportion of young, liberal-leaning constituents were expected to vote en route to work,” according to a Freedom House report.
Security researchers have recognized the trend of using DDoS attacks.  The Dell SecureWorks Center Threat Unit issued a report in April to warn about the toolkit.  Wire transfers of up to $2.1million have been spotted.  A layered fraud prevention and security approach is now assured.
References:
Cybercriminals use DDoS attacks as “smokescreens” for major cyber thefts – WeLiveSecurity
http://www.welivesecurity.com/2013/08/22/cybercriminals-use-ddos-attacks-as-smokescreens-for-major-cyber-thefts/
August 22, 2013
Cybercriminals Expand DDOS Extortion Demands – Information Week
http://www.informationweek.com/security/vulnerabilities/cybercriminals-expand-ddos-extortion-dem/240157366
June 26, 2013
Cybercrooks use DDoS attacks to mask theft of banks’ millions – CNet
http://news.cnet.com/8301-1009_3-57599646-83/cybercrooks-use-ddos-attacks-to-mask-theft-of-banks-millions/

Don’t miss out on the latest tech news and computer security alerts! Follow us on Twitter at @hyphenet,  “Like” us on Facebook or add us to your circle on Google+.

Friday, November 11, 2011

What is a Botnet, Drive-by-Download, or DDoS Attack? Familiarize yourself with more PC security terms.

What is a botnet, drive-by-download, DDoS attack, keylogger or rootkit?You may have heard about the recent DDoS attack carried out by the well-known hacktivist group Anonymous or that humongous botnet consisting of over 4,000,000 computers that the FBI just brought down.  However, as you’re reading the articles you may be thinking to yourself, “What the heck is a botnet or DDoS attack?!”

Well, here’s your answer – along with the definitions of a few other tech terms you’re likely to encounter:

Botnet


A botnet is a collection of PCs that are infected with malware allowing a hacker to control them remotely. Typically botnet operators use their army of zombie computers to carry out DDoS attacks and send out spam.

You may have heard of the Rustock and Kelihos botnets that were dismantled earlier this year?

Drive-by-Download


A drive-by –download takes place when a user visits a website that hosts one or more exploits targeting potential vulnerabilities within the visiting machine - whether it’s the web browser or a browser add-on like Java.

If the visiting computer is vulnerable, malware will be downloaded onto their machine, usually without the end-user’s knowledge.

DDoS (Denial-of-Service) Attack


Imagine it’s Black Friday and a huge mob of shoppers are all rushing to the door at the same time to get in. The huge group of flailing arms and limbs, kicking and screaming as they all try to squeeze through prevent anyone else from gaining entry.

That pretty much sums up what a DDoS attack is – a denial of service (or website, in this case). The bad guys usually carry out DDoS attacks with the help of botnets.

Keylogger


A keylogger does exactly what its name implies, which is to log any keystrokes typed by the user of an infected machine. Keyloggers typically come bundled with Trojan Horses and are used by cybercrooks to harvest sensitive information like account logins and banking details from infected computers.

Rootkit


The term ‘rootkit’ stems from a combination of “root”, which refers to the all-powerful Admin account on Unix systems and “kit”, which refers to a set of programs that allow someone to maintain root-level access on a PC.

Rootkits are often used by malware authors to gain admin privileges on a computer and evade detection, whether it’s from the end-user or any residing antivirus protection software.

Great, now I'm afraid to do anything on my PC. Now what?


Now that you’ve familiarized yourself with more of the dangers lurking around every mouse-click and keystroke, you can take the steps necessary to make sure your PC is safe and secure.

Thankfully keeping your computer safe from malware isn’t difficult. However it does require the use of a few tools and a dash of common sense.

  1. Make sure you’re running up-to-date anti-virus and anti-malware software that offers must-have features like real-time scanning, a personal firewall and email filtering.

  2. Minimize the chances of your computer having any vulnerabilities that can be exploited by malware by ensuring that all system and program updates are downloaded and installed.

  3. Refrain from opening any email attachments that appear to be suspicious and make sure you manually scan any email attachments you do wish to download prior to opening them.

  4. Think twice about following any links that your gut instinct tells you not to, especially if it’s on a social networking site as that’s one of the favorite ways for cybercrooks to spread malware.

  5. Opt to download software from their legitimate vendors vs. using pirated copies as the bad guys are known for tacking malware onto software they then share via P2P networks.

  6. Set system restore points and back up all of your precious data as you never know when they’ll come in handy.


Be sure to follow us, “like” us or circle us to stay up-to-date on the latest tech news and security threats.