DDoS denied: law enforcement takes down attacks for hire platforms in major bust

Itโ€™s all too easy to think of cybersecurity in terms of defending against headline-generating risks: ransomware, zero-day vulnerabilities, credential-stealing malware and socially-engineered hack attacks.

But, in my best Morpheus from the Matrix voice, what if I were to tell you that one of the oldest threats to your organisation remains as active as ever? That it has evolved to incredible new heights and can cost you dearly in terms of both reputation and bottom line? What could this attack on security steroids possibly be?

The answer: distributed denial of service. DDoS to its frenemies. The good news is that law enforcement has just had significant success in taking down some of the platforms that rent the attack itself out to anyone for any reason.

Attacks on DDoS

The latest Group-IB intelligence insights report confirmed my suspicions that DDoS should be higher on the cyber-defender priority schedule.

Ransomware incidents were down 4%, initial access credentials broker sales down 20% and DDoS attacks up by a whacking 88%. That’s almost double, people.

And the threat is evolving, as evidenced by a Windows denial of service vulnerability for which Microsoft doesnโ€™t yet have a fix.

Zhiniang Peng, an Associate Professor at Huazhong University of Science and Technology, discovered the denial-of-service attack exploiting a vulnerability patternโ€‹โ€‹ in User Datagram Protocol remote services that are employing Windows Deployment Services.

But the biggest danger is from the ready-made, ready-to-roll, attacks-as-a-service platforms that literally rent out DDoS by the hour.

DDoS attacks for hire

Europol has confirmed that is has arrested four people thought to be behind the operation of such DDoS for hire platforms. โ€œThe suspects are believed to be behind six separate stresser/booter services that enabled paying customers to flood websites and servers with malicious traffic – knocking them offline for as little as EUR 10,โ€ Europol said in a statement.

The law enforcement takedown resulted from a global investigation, with action in four countries (including the US) where nine domains associated with the platforms were seized.

Itโ€™s vital to note here that the platforms in question didnโ€™t require any technical ability other than being able to fill in a form. Yes, really. An attacker simply needed to enter the target IP address, select the duration of the attack, and pay the fee. Thatโ€™s it.

Europol said that the resulting fully automated attacks could โ€œoverwhelm even well-defended websites.โ€

The good news is that this is just part of the global Operation PowerOFF action being taken against DDoS for hire platforms; further arrests and takedowns can be expected. In the meantime, organisations are advised to take mitigating action now.

How to protect yourself from DDoS attacks now

โ€œThere are several protections companies can implement, many of which they should already have in place,โ€ said Randolph Barr, CISO at Cequence Security.

โ€œCloud-based solutions from providers like AWS and Google Cloud offer tools to help mitigate these attacks. Additionally, AI/ML-powered solutions can detect abnormal traffic patterns and differentiate between bots and real users.”

He added: “Rate limiting is another mitigation method, but it has its limits when dealing with large traffic volumes.โ€

The key takeaway, according to Barr, is that DDoS is becoming increasingly sophisticated.

โ€œBad actors are refining their strategies, targeting not only network infrastructures but also application layers and, most critically, APIs.”

Donโ€™t say you havenโ€™t been warned.

Avatar photo
Davey Winder

With four decades of experience, Davey is one of the UK's most respected cybersecurity writers and a contributing editor to PC Pro magazine. He is also a senior contributor at Forbes. You can find him at TechFinitive covering all things cybersecurity.