That booter website you just paid $100 to launch a distributed denial-of-service attack – are you sure it’s not a front for the cops?
No, of course it’s not. Wait, is it? The National Crime Agency in Britain says it is running multiple, real-looking cybercrime service sites designed to identify suspects at home and abroad. But you’re not falling for it. Are you?
That’s the mind game the U.K. counterpart to the FBI is after among the clientele of DDoS-for-hire, aka stresser/booter, services. These offer a simple, easy-to-use interface via which users can sign up, pay for credit and then order disruptions of specific websites, all in just a few minutes.
How many sites the NCA is running and what it offers aren’t exactly clear – a ploy at the heart of this newly disclosed effort, part of Operation PowerOff. Authorities say it’s designed to sow confusion and doubt and undermine trust in the criminal market. Paranoia, they hope, runs deep.
Call it an escalation in the never-ending fight against booter sites, which allow individuals with little technical ability to easily commit cybercrimes.
“Booter/stresser services are like grass: You can mow the lawn, but the grass will grow back,” Daniel Smith, head of research for cybersecurity firm Radware’s threat intelligence division, told me. “The problem with enforcement is the reaction. As law enforcement worldwide steps up their efforts to reduce crime, the criminals will escalate in lockstep, as there is too much profit involved in cybercrime for everyone to be scared away.”
Fostering uncertainty among customers is another way to attempt to reduce the proliferation of booter sites. Here’s what the NCA has confirmed: It’s running multiple fake booter websites “which have so far been accessed by around several thousand people.”
“Users based in the U.K. will be contacted by the National Crime Agency or police and warned about engaging in cybercrime. Information relating to those based overseas is being passed to international law enforcement,” the agency says.
Last December, the FBI, together with the NCA, Dutch police and Europol, collectively shuttered 48 big booter sites. One site alone is tied to more than 30 million attacks.
These services can pose a risk to public safety. “Such attacks have the potential to cause significant harm to businesses and critical national infrastructure and often prevent people from accessing essential public services,” the NCA said (see: Hacktivist Pleads ‘Not Guilty’ in Children’s Hospital DDoS Attack).
Individuals can always, of course, build their own botnet to launch DDoS attacks. Booter websites are a shortcut past that time-consuming and technically intensive task, often taken by low-level would-be hackers who might actually pause over disclosing payment card details if they thought police could be on the other side.
DDoS-for-hire services typically offer attractive price points, oftentimes “for as little as $30 per month,” DDoS mitigation firm Cloudflare reports. “The more you pay, the larger and longer of an attack you’re going to get.”
Behind the scenes, real stresser services can rely on several different strategies to fuel their disruptions. “Most booter/stresser services are powered by a combination of botnets comprised of IoT devices and cloud services as well as servers that allow spoofing, enabling operators to offer a wide variety of attack vectors to their clients,” Smith said.