Last week, banks and other financial institutions in Australia were targeted by a global hacking campaign that appears to have been active since October 2019. Specifically, this hacking campaign had sent emails to potential victims threatening them with DDoS attacks if they did not pay large amounts cryptocurrency as ransom.
According to the ACSC, the hackers did not carry out their threats in all cases, since no DDoS attacks were observed. This is due to the fact that it was impossible to gather all the required DDoS resources to be able to attack all their targets. In addition, the ACSC issued some advice on protecting against this “hacking” campaign.
As reported by ZDNet, the hackers initially targeted banks and other financial institutions, but later expanded their threat to include industries. Specifically, they targeted banks in Singapore and South Africa, telecommunications companies in Turkey, internet service providers in South Africa, and online betting and gambling sites across Southeast Asia. The hacking campaign continued with threats of DDoS attacks, moving methodically against businesses and targeting countries around the world.
Additionally, the hackers behind this campaign often signed their threatening emails with a different name. Initially, they used the name Fancy Bear, the name of the notorious Russian government-linked hacking group known for hacking the White House in 2014 and the DNC in 2016. They later used Cozy Bear, the name of another well-known Russian government-linked hacking group also known for hacking the DNC in 2016. Other names they used included Anonymous, Carbanak , and Emotet. All are names of well-known hacking and cybercrime operations. Those behind this campaign hope that victims will search for these names online after receiving the threatening emails. Google , and hackers hope this will help potential victims believe and fear their threat and therefore pay the ransom demanded of them.
Now, these hackers are using the name Silence, which is associated with a hacking group known for stealing millions of dollars from banks in Eastern Europe, South and Central Asia, and more recently, Sub-Saharan Africa.
Radware, a company that provides DDoS protection advice, advised victims who received threatening messages to pay large amounts of Monero as ransom to avoid DDoS attacks, NOT to pay, but to contact a cybersecurity company. Finally, the ACSC recommended that organizations be prepared for attacks in advance to operate more effectively, as it can be very difficult to respond once the attack begins.
