The last quarter of 2020 saw a wave of web application attacks that have used ransom notes to target businesses across industries. According to research from Akamai, the largest of these attacks sent over 200Gbps of traffic to cybercriminal targets, as part of a sustained campaign of higher Bits Per Second (BPS) and Packets Per Second (PPS) than similar DDoS attacks had seen just a few weeks earlier.
Before August, these attacks focused on the gaming. However, since August, these attacks have begun to target financial institutions and other industries.

According to Akamai, none of the actors involved in these attacks were new, as most of the traffic was generated by reflectors and systems used to amplify the traffic. The company said that using a common set of protocols to amplify a DDoS campaign is an indication of the use of new tools and configurations by cybercriminals, rather than an indication of an extortion.
However, many organizations began receiving targeted emails threatening DDoS attacks if potential victims refused to pay the ransom .Richard Meeus, director of technology and security strategy at Akamai, said the hackers were carrying out a small-scale DDoS attack against the targeted organization and threatening to launch a 1Tbps attack if the target did not pay the ransom.
Furthermore, Meeus noted that many DDoS campaigns start with the sending of threatening letters to prospective victims, without however proceeding to corresponding actions. In contrast, this campaign has demonstrated in many cases that hackers can make the life of an organization – target difficult.

While Akamai said many of the extortion messages were caught by spam filters , not all targets are willing to admit they received emails from the attackers. The company said this DDoS extortion campaign is not over, but the cybercriminals behind it are modifying and evolving their attacks to make them harder to detect for both victims and law enforcement .
Richard Meeus said last week in an online seminar that Akamai had seen an increase in daily attacks – from one million in January of the current year to three million in September – with the majority of them targeting financial services.
This campaign peaked in August and September and reached its climax, perhaps when the attackers thought they had been mitigated and began to change their tactics. This included the execution of three- and four-stage attacks, which usually target data centers, site and APIs.
Meeus also emphasized that there was a 200% increase in attacks against web application firewalls. Finally, he noted that DDoS attacks come in waves and ransom attacks have been ongoing for several years, with Akamai researchers successfully confronting the attackers, yet they return again as a ransom technique operates.
