Monday , December 30 2024

US Seizes Domains of 13 DDoS-for-Hire Services

The FBI has been coordinating Operation PowerOFF since 2018, aiming to disrupt the DDoS-for-hire service infrastructures worldwide.

As part of this Operation, On May 8th, 2023, the FBI seized around 13 internet domains that offered DDos-for-hire services.

Look back; The Worst Hacks of 2024

In 2024, digital security experienced major breaches as cybercriminals and state-backed groups exploited vulnerabilities for large-scale attacks. These incidents were...
Read More
Look back; The Worst Hacks of 2024

HIPAA to be updated with new cybersecurity regulations, White House

Proposed new cybersecurity rules for healthcare institutions will focus on how they protect user data under HIPAA, as stated by...
Read More
HIPAA to be updated with new cybersecurity regulations, White House

New NGate Trojan Drains Bank Accounts via ATMs

Malware analysts at Doctor Web have identified new versions of the NGate banking trojan. This malware steals data from the...
Read More
New NGate Trojan Drains Bank Accounts via ATMs

CPE Seminar Held at ISACA Dhaka Chapter Office Premises

ISACA Dhaka chapter arranged a Continuing Professional Education (CPE) seminar for the community as its calendar work to develop the...
Read More
CPE Seminar Held at ISACA Dhaka Chapter Office Premises

Update Immediately
Palo Alto Releases Patch for PAN-OS DoS Flaw

Palo Alto Networks has revealed a high severity vulnerability in PAN-OS software that may lead to a denial-of-service (DoS) issue...
Read More
Update Immediately  Palo Alto Releases Patch for PAN-OS DoS Flaw

Cyberattack Hit Japan Airlines Systems, delaying flights

Japan Airlines reported a cyberattack on Thursday that delayed over 20 domestic flights. The airline managed to stop the attack...
Read More
Cyberattack Hit Japan Airlines Systems,  delaying flights

Hacker reportedly leak Indonesia Gov.t 82 GB data

Hackers claimed to have accessed and stolen 82 GB of sensitive data from Indonesia's Regional Financial Management Information System (SIPKD)....
Read More
Hacker reportedly leak Indonesia Gov.t 82 GB data

BCSI officially announce National Vulnerability Disclosure Program (NVDP)

Bangladesh Cyber Security Intelligence (BCSI) officially launch the National Vulnerability Disclosure Program (NVDP) to enhance the country's cybersecurity. This initiative...
Read More
BCSI officially announce National Vulnerability Disclosure Program (NVDP)

CVE-2024-9474
Researcher unveil sophisticated backdoor in Palo Alto Networks firewalls

Northwave Cyber Security has found a sophisticated backdoor, LITTLELAMB.WOOLTEA, targeting Palo Alto Networks firewalls. Northwave researcher claimed the backdoor was...
Read More
CVE-2024-9474  Researcher unveil sophisticated backdoor in Palo Alto Networks firewalls

New G-Door Vul Allow Hackers Bypass Microsoft 365 Security With Google Docs

A newly discovered vulnerability called "G-Door" enables malicious actors to bypass Microsoft 365 security by exploiting unmanaged Google Docs accounts....
Read More
New G-Door Vul Allow Hackers Bypass Microsoft 365 Security With Google Docs

The FBI has named them “Booter” services as these services result in “booting” or dropping the victim’s computers from the internet.

The seizure revealed data of hundreds of thousands of DDos-for-hire users responsible for millions of attacks against Schools, universities, financial institutions, and government websites, affecting millions of victims.

10 out of 13 domains seized were found to be a reincarnation of previously seized domains in December when the FBI targeted 48 booter service domains.

An example shown by the Dept of Justice stated that a domain named cyberstress.org was found to be a reincarnation of cyberstress[.]us, seized in December.

The investigation by the FBI

The FBI opened new accounts and renewed old accounts on these DDoS-for-hire service websites for further investigation. They paid for these services in cryptocurrency and launched an attack on FBI test systems.

As advertised by these websites, the services were able to affect the computers on a large scale severing internet connections from the systems and making them completely unavailable.

Additional investigation showed that these services could also disrupt other users’ internet connections if the attackers launched their attack on an internet service provider via a connection point.

Following these investigations, the FBI stated that four defendants arrested in Los Angeles in 2022 admitted to running these booter service operations.

  1. Jeremia Sam Evans Miller aka “John The Dev” from San Antonio, Texas ran the botter service named Royalstresser.com (formerly Supremesecurityteam.com).
  2. Angel Manuel Colon Jr., aka “Anonghost720” and “Anonghost1337,” from Belleview Florida who ran the booter service SecurityTeam.io
  3. Shamar Shattock from Margate, Florida, who ran the booter service “Astrostress.com”
  4. Cory Anthony Palmer, from Lauderhill, Florida, who ran the booter service Booter.sx

All these defendants are scheduled to be sentenced this summer, as mentioned by the Department of Justice.

Furthermore, the FBI has been coordinating this operation with international law enforcement agencies and is aiming to arrest administrators and users of these illegal services.

Check Also

Mastercard

For US$2.6bn, Mastercard acquires threat intelligence firm Recorded Future

Mastercard has completed its acquisition of Recorded Future, an AI-based threat intelligence provider. Mastercard has …

Leave a Reply

Your email address will not be published. Required fields are marked *