Sunday , December 22 2024

Law Enforcement Lures Cybercriminals With Fake DDoS Services

That booter website you just paid $100 to launch a distributed denial-of-service attack – are you sure it’s not a front for the cops?

No, of course it’s not. Wait, is it? The National Crime Agency in Britain says it is running multiple, real-looking cybercrime service sites designed to identify suspects at home and abroad. But you’re not falling for it. Are you?

Eight New ICS Advisories released by CISA

CISA has released eight advisories on vulnerabilities in Industrial Control Systems (ICS). These vulnerabilities affect essential software and hardware in...
Read More
Eight New ICS Advisories released by CISA

Authority Denies
Hacker claim ransomware attack on Indonesia’s state bank BRI

Bank Rakyat Indonesia (BRI), the largest state bank by assets, has assured customers that their data and funds are secure...
Read More
Authority Denies  Hacker claim ransomware attack on Indonesia’s state bank BRI

London-based company “Builder.ai” reportedly exposed 1.2 TB data

Cybersecurity researcher Jeremiah Fowler reported to Website Planet that he found a non-password-protected 1.2 TB dataset containing over 3 million...
Read More
London-based company “Builder.ai” reportedly exposed 1.2 TB data

(CVE-2024-12727, CVE-2024-12728, CVE-2024-12729)
Sophos resolved 3 critical vulnerabilities in Firewall

Sophos has fixed three separate security vulnerabilities in Sophos Firewall.  The vulnerabilities CVE-2024-12727, CVE-2024-12728, and CVE-2024-12729 present major risks, such...
Read More
(CVE-2024-12727, CVE-2024-12728, CVE-2024-12729)  Sophos resolved 3 critical vulnerabilities in Firewall

“Workshop on Cybersecurity Awareness and Needs Analysis” held at BBTA

A time-demanding workshop on "Cybersecurity Awareness and Needs Analysis" was held on Thursday (December 19) at Bangladesh Bank Training Academy...
Read More
“Workshop on Cybersecurity Awareness and Needs Analysis” held at BBTA

CVE-2023-48788
Kaspersky reveals active exploitation of Fortinet Vulnerability

Kaspersky's Global Emergency Response Team (GERT) found that attackers are exploiting a patched SQL injection vulnerability (CVE-2023-48788) in Fortinet FortiClient...
Read More
CVE-2023-48788  Kaspersky reveals active exploitation of Fortinet Vulnerability

U.S. Weighs Ban on Chinese-Made Router TP-Link: WSJ reports

The US government is considering banning a well-known brand of Chinese-made home internet routers TP-Link due to concerns that they...
Read More
U.S. Weighs Ban on Chinese-Made Router TP-Link:  WSJ reports

Daily Security Update Dated: 18.12.2024

Every day a lot of cyberattack happen around the world including ransomware, Malware attack, data breaches, website defacement and so...
Read More
Daily Security Update Dated: 18.12.2024

CISA released best practices to secure Microsoft 365 Cloud environments

CISA has issued Binding Operational Directive (BOD) 25-01, requiring federal civilian agencies to improve the security of their Microsoft 365...
Read More
CISA released best practices to secure Microsoft 365 Cloud environments

Data breach! Ireland fines Meta $264 million, Australia $50m

The Irish Data Protection Commission fined Meta €251 million ($263.6 million) for GDPR violations related to a 2018 data breach...
Read More
Data breach! Ireland fines Meta $264 million, Australia $50m

That’s the mind game the U.K. counterpart to the FBI is after among the clientele of DDoS-for-hire, aka stresser/booter, services. These offer a simple, easy-to-use interface via which users can sign up, pay for credit and then order disruptions of specific websites, all in just a few minutes.

How many sites the NCA is running and what it offers aren’t exactly clear – a ploy at the heart of this newly disclosed effort, part of Operation PowerOff. Authorities say it’s designed to sow confusion and doubt and undermine trust in the criminal market. Paranoia, they hope, runs deep.

Call it an escalation in the never-ending fight against booter sites, which allow individuals with little technical ability to easily commit cybercrimes.

“Booter/stresser services are like grass: You can mow the lawn, but the grass will grow back,” Daniel Smith, head of research for cybersecurity firm Radware’s threat intelligence division, told me. “The problem with enforcement is the reaction. As law enforcement worldwide steps up their efforts to reduce crime, the criminals will escalate in lockstep, as there is too much profit involved in cybercrime for everyone to be scared away.”

Fostering uncertainty among customers is another way to attempt to reduce the proliferation of booter sites. Here’s what the NCA has confirmed: It’s running multiple fake booter websites “which have so far been accessed by around several thousand people.”

“Users based in the U.K. will be contacted by the National Crime Agency or police and warned about engaging in cybercrime. Information relating to those based overseas is being passed to international law enforcement,” the agency says.

Last December, the FBI, together with the NCA, Dutch police and Europol, collectively shuttered 48 big booter sites. One site alone is tied to more than 30 million attacks.

These services can pose a risk to public safety. “Such attacks have the potential to cause significant harm to businesses and critical national infrastructure and often prevent people from accessing essential public services,” the NCA said (see: Hacktivist Pleads ‘Not Guilty’ in Children’s Hospital DDoS Attack).

Individuals can always, of course, build their own botnet to launch DDoS attacks. Booter websites are a shortcut past that time-consuming and technically intensive task, often taken by low-level would-be hackers who might actually pause over disclosing payment card details if they thought police could be on the other side.

DDoS-for-hire services typically offer attractive price points, oftentimes “for as little as $30 per month,” DDoS mitigation firm Cloudflare reports. “The more you pay, the larger and longer of an attack you’re going to get.”

Behind the scenes, real stresser services can rely on several different strategies to fuel their disruptions. “Most booter/stresser services are powered by a combination of botnets comprised of IoT devices and cloud services as well as servers that allow spoofing, enabling operators to offer a wide variety of attack vectors to their clients,” Smith said.

Check Also

Telco

Global Telco Market expected reach a CAGR of 10.5%
Global Cyber Attack in Telecom Sector Market Synopsis

The Global Cyber Attack in Telecom Sector Market is projected to grow at a rate …

Leave a Reply

Your email address will not be published. Required fields are marked *