HomeSecurityDid the admin of the DDoS WireX botnet attack a hotel chain?

Did the admin of the DDoS WireX botnet attack a hotel chain?

The US Department of Justice has charged the operator of the WireX Android botnet with targeting an American multinational hotel chain in a distributed denial-of-service (DDoS) attack.

WireX

See also: MikroTik: How to protect routers affected by the Mēris botnet

Izzet Mert Ozek, the defendant, used the botnet consisting of tens of thousands of enslaved Android devices – more than 120,000 based on unique IP addresses observed in some WireX attacks – to target the company’s online booking system website in August 2017.

Ozek was charged with intentionally causing damage to a protected computer, which carries a prison sentence of up to ten years. The defendant has not yet been arrested and no arrest warrant has been issued. He is believed to be residing in Turkey.

See also: Meris botnet attacks KrebsOnSecurity website

The WireX botnet was quickly taken down

While the Health Minister did not reveal whether Ozek was a WireX botnet customer or administrator, BleepingComputer was able to connect him to the infrastructure used by the botnet.

His LinkedIn page lists him as the founder of a company called AxClick, a term used for multiple sub-domains of a single root domain (axclick[.]store) part of the WireX command and control (C2) infrastructure used to direct the botnet to launch DDoS attacks against specific targets.

The WireX botnet emerged in mid-July 2017 and was created using hundreds of trojanized apps distributed through the Google Play Store and third-party app stores.

While the botnet attacks began in July, it appeared on security researchers' radars on August 17 when it was used in scale 7 (application layer) DDoS attacks.

See also: USA: Estonian national pleads guilty to operating botnet

According to researchers who analyzed these incidents in mid-August, the botnet launched DDoS attacks using bots from more than 100 countries – spreading to more than 120,000 simultaneous IP addresses.

Following these attacks, the botnet was taken down in late August 2017, with the combined efforts of researchers from Akamai, Cloudflare, Flashpoint, RiskIQ, Google, Oracle Dyn, Team Cymru, some of the DDoS targets, IT companies, and the FBI.

Information source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS