Hackers 'weaponised' Malware To Mount Massive Assault

The huge attack on global Internet access on Friday 21st October, which blocked some of the world’s most popular websites, is believed to have been unleashed by hackers using common devices like webcams and digital recorders.

Among the sites targeted recently were Twitter, PayPal and Spotify. All were customers of Dyn, an infrastructure company in New Hampshire in the US that acts as a switchboard for Internet traffic.

Outages were intermittent and varied by geography, but reportedly began in the eastern US before spreading to other parts of the country and Europe.

Users complained they could not reach dozens of Internet destinations, including Mashable, CNN, the New York Times, the Wall Street Journal, Yelp and some businesses hosted by Amazon.

Hackers used hundreds of thousands of internet-connected devices that had previously been infected with a malicious code – known as a “botnet” or, jokingly, a “zombie army” – to force an especially potent distributed denial of service (DDoS) attack.

The aim of a DDoS attack is to overwhelm an online service with traffic from multiple sources, rendering it unavailable. Dyn said attacks were coming from millions of Internet addresses, making it one of the largest attacks ever seen.

Dyn said it had resolved one attack, which disrupted operations for about two hours, but disclosed a second a few hours later that was causing further disruptions. By the evening it was fighting a third.

At least some of the malicious traffic was coming from connected devices, including webcams and digital video recorders. 

Security researchers working with Dyn to investigate the attack have linked it to a network of web-enabled CCTV cameras made by a single Chinese company, XiongMai Technologies.

Allison Nixon, director of research at the security firm Flashpoint, said its web-enabled CCTV cameras and digital video recorders were forcibly networked together using the sophisticated malware program Mirai to direct the crushing number of connection requests to Dyn’s customers. “It’s remarkable that virtually an entire company’s product line has just been turned into a botnet that is now attacking the United States,” she told security researcher Brian Krebs.

The same Mirai malware was used in September to launch what was then described as the biggest DDoS attack ever on Krebs’ website, Krebs on Security. His reporting on cybercrime has made him a target in the past.

Hackers released the source code for Mirai earlier this month, inspiring a significant number of copycats. Experts had warned of increasingly sophisticated botnets, in essence, a weaponised combination of malware and as many as 100,000 hijacked individual devices, just days before the attack.

Researchers at Level 3 Communications, a global communications company focused on managed security, warned earlier this week that “the threat from these botnets is growing” as more and more devices were connected to the web.
The US Department of Homeland Security had issued a warning the previous week.

Mirai was the most sophisticated botnet malware Level 3 had seen yet, able to rotate the IP addresses (likely to avoid detection) about three times as often as had been observed with other botnets. More worryingly still, it was “becoming still more sophisticated”.

Mirai targeted household and everyday devices, such as DVRs, cameras and even kettles, that were connected to the internet, a concept of connectivity commonly referred to as “the internet of things” (IoT). Many were devised without particular mind to security.

Level 3 researchers said the majority, as many as 80%, of botnets were networked DVRs, with the rest routers and other miscellaneous devices such as IP cameras and Linux servers. “The devices are often operated with the default passwords, which are simple for bot herders to guess.”

Michael Mimoso, of cybersecurity research group Kaspersky Lab, estimated that the number of compromised devices had reached 493,000, with most in the US. “But Brazil and Colombia are also high on the list”. 

Dyn categorized the attack as “resolved” shortly after 6pm New York time, but it is still not known who deployed the botnet, and why. “The complexity of the attacks is what’s making it very challenging for us,” the company’s chief strategy officer, Kyle York, told Reuters. Homeland Security and the Federal Bureau of Investigation said they were investigating.

A tweet from WikiLeaks implied that its supporters were behind the attack. “Mr. Assange is still alive and WikiLeaks is still publishing. We ask supporters to stop taking down the US Internet. You proved your point.”  

Security researcher Bruce Schneier caused waves when he wrote in September that someone, probably a country, was “learning how to take down the Internet”. He wrote that “a large nation state” (“China or Russia would be my first guesses”) had been testing increasing levels of DDoS attacks against unnamed core Internet infrastructure providers in what seemed like a test of capability. 

Guardian
 

« FBI Using Big Data To Predict Terrorism
Media Vulnerable To Election Night Cyber-Attack »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

LockLizard

LockLizard

Locklizard provides PDF DRM software that protects PDF documents from unauthorized access and misuse. Share and sell documents securely - prevent document leakage, sharing and piracy.

DigitalStakeout

DigitalStakeout

DigitalStakeout enables cyber security professionals to reduce cyber risk to their organization with proactive security solutions, providing immediate improvement in security posture and ROI.

ManageEngine

ManageEngine

As the IT management division of Zoho Corporation, ManageEngine prioritizes flexible solutions that work for all businesses, regardless of size or budget.

NordLayer

NordLayer

NordLayer is an adaptive network access security solution for modern businesses — from the world’s most trusted cybersecurity brand, Nord Security. 

CSI Consulting Services

CSI Consulting Services

Get Advice From The Experts: * Training * Penetration Testing * Data Governance * GDPR Compliance. Connecting you to the best in the business.

RKH Specialty

RKH Specialty

RKH Specialty, part of the Hyperion Insurance Group, is a provider of specialty insurance services including Cyber Risk cover.

Applied Risk

Applied Risk

Applied Risk is an established leader in Industrial Control Systems security, focused on critical infrastructure security and combating security breaches that pose a significant threat.

Wolfpack Information Risk

Wolfpack Information Risk

Wolfpack specialise in information and cyber threat management covering the full spectrum of prevention, detection, incident response and business resilience capabilities.

Truepic

Truepic

Truepic provides technologies that prevent fraud, identity theft, misinformation, and disinformation caused by generative, manipulated, or deepfake digital content.

Oznet Cyber Security

Oznet Cyber Security

Oznet Cyber Security is dedicated to offering integral solutions oriented to the support and security of information.

Irish National Accreditation Board (INAB)

Irish National Accreditation Board (INAB)

INAB is the national accreditation body for Ireland. The directory of members provides details of organisations offering certification services for ISO 27001.

Fly Ventures

Fly Ventures

Fly Ventures is a seed-stage venture capital fund for outstanding teams building Enterprise and Deep Tech startups in Europe.

Informer

Informer

Informer provides an Attack Surface Management SaaS platform alongside penetration testing services. We combine machine learning and human intelligence to reduce cyber risk.

Hunton Andrews Kurth

Hunton Andrews Kurth

Hunton Andrews Kurth LLP serves clients across a broad range of complex transactional, litigation and regulatory matters. Practice areas include Privacy and Cybersecurity.

Terralogic

Terralogic

Terralogic is a software and IT services company, an expert in IoT, Cloud, DevOps, App development and Cybersecurity.

Cyber Security for Europe (CyberSec4Europe)

Cyber Security for Europe (CyberSec4Europe)

CyberSec4Europe is designing, testing and demonstrating potential governance structures for a European Cybersecurity Competence Network.

Udacity

Udacity

Udacity's mission is to train the world’s workforce in the careers of the future. Our programs range from beginner to expert levels and deliver the hands-on skills for real-world expertise.

FoxTech

FoxTech

FoxTech is an independent, friendly and deeply specialised cyber security company in the UK, with expertise spanning decades of Public Sector and Government services.

Harbottle & Lewis

Harbottle & Lewis

Harbottle & Lewis is a leading UK-based law firm focused on the Private Client and Technology, Media and Entertainment sectors.

Guardian Angel Cyber

Guardian Angel Cyber

Guardian Angel Cyber, is your trusted ally in safeguarding your digital assets and online presence.

Endari

Endari

Endari specializes in building cybersecurity maturity within the operational DNA of early-stage startups and SMBs.