The second quarter of 2017 was proof that long-running DDoS attacks are back in action. The largest attack of the quarter was active for 277 hours (more than 11 days) – a 131% increase compared to the first quarter. This is a record for the year so far, according to Kaspersky Lab’s expert report on botnet DDoS attacks for the second quarter of 2017.
Duration was not the only characteristic of DDoS attacks between April and June. There was also a dramatic change in the geography of incidents, with organizations with electronic resources in 86 countries being attacked in the second quarter (compared to 72 countries in the first quarter). The 10 countries with the most attacks were China, South Korea, the US, Hong Kong, the UK, Italy, the Netherlands, Canada and France – with Italy and the Netherlands replacing Vietnam and Denmark.
The targets of the DDoS attacks included one of the largest news agencies, Al Jazeera, the websites of the newspapers Le Monde and Figaro, and, allegedly, Skype servers. In the second quarter of 2017, the rise in the proportions of cryptocurrencies also led cybercriminals to try to manipulate prices via DDoS. Bitfinex, the largest Bitcoin exchange, was attacked at the same time as it launched trading in a new cryptocurrency, the so-called IOTA token. Earlier, the BTC-E exchange reported slowdowns due to a powerful DDoS attack.
The interest of organizers of DDoS attacks in cash goes beyond manipulating the proportions of cryptocurrencies. Using this type of attack to extort money can be profitable, as the trend of Ransom DDoS or RDoS shows. Cybercriminals typically send a message to the victim demanding a ransom ranging from 5 to 200 bitcoins. If the company refuses to pay, the attackers threaten to organize a DDoS attack on a critical and important online resource of the victim. Such messages can be accompanied by short-term DDoS attacks to confirm that the threats are indeed real. In late June, a long-lasting RDoS attack was carried out by the Armada Collective group, which demanded approximately $315,000 from seven South Korean banks.
However, there is always another way, which has become more popular in the last quarter – Ransom DDoS without any DDoS at all. Scammers send threatening messages to a large number of companies in the hope that someone will decide to be safe rather than regret it later. Demonstration attacks may never happen, but if just one company decides to pay, it will bring cybercriminals a profit with minimal effort.
“Today, it is not only experienced hi-tech cybercriminal groups that can attack with Ransom DDoS. Any crook who has neither the technical knowledge nor the ability to organize a full-scale DDoS attack can buy a demonstration of the attack for blackmail purposes. These people mostly choose companies that do not protect their resources from DDoS in any way and, therefore, can easily be convinced to pay a ransom with a simple demonstration,” comments Kirill Ilganaev, Head of Kaspersky DDoS Protection at Kaspersky Lab.
Kaspersky Lab experts warn that if a victim company decides to pay, it can cause long-term damage in addition to immediate monetary losses. The reputation of the “payer” spreads quickly through networks and can provoke further attacks from other cybercriminals.
Kaspersky DDoS Protection combines Kaspersky Lab's extensive expertise in combating digital threats with unique in-house developments. The solution protects against all types of attacks , regardless of their complexity, strength or duration.
*The DDoS Intelligence system (part of Kaspersky DDoS Protection) is designed to monitor and analyze commands sent to bots from command and control servers (C&C) and does not need to wait until user devices are “infected” or until cybercriminals’ data collection commands are executed. It is important to note that DDoS Intelligence statistics are limited to botnets detected and analyzed by Kaspersky Lab.
