HomeSecurityRansom DDoS attacks hit record levels this year

Ransom DDoS attacks hit record levels this year

Ransomware denial-of-service attacks, also known as Ransom DDoS (Ransom Distributed Denial-of-service), have seen a decline in the first quarter of the year, according to recent statistics from Cloudflare.

See also: Borat malware: New RAT allows DDoS and ransomware attacks

Ransomware DDoS

These attacks mainly target companies with large amounts of data to cause disruption to their services. The malicious users then demand a ransom to stop the attack.

Cybercriminals have understood that causing downtime can be a powerful incentive for many companies to pay the ransom to get back up and running, especially for organizations at risk of significant financial impact.

It should be noted that Ransom DDoS attacks are launched by different types of threat actors than ransomware, which use DDoS to add more pressure on the victim in addition to encrypting files and threatening to publish the stolen data.

Cloudflare reports that Ransom DDoS attacks have decreased drastically in 2022, with only 17% of customers targeted by DDoS reporting extortion in January, 6% in February, and just 3% in March.

This is a 28% decrease from the previous year and a 52% decrease compared to the last quarter of 2021, when Ransom DDoS attacks increased by 28% in the last month.

See also: Hacked WordPress sites force visitors to launch DDoS attacks on Ukrainian sites

The reason for this decline remains unclear at present.

they fell

Regarding the upward trends reflected in Q1 2022 data, Cloudflare reports a massive 164% year-over-year increase in application-level DDoS attacks.

The most notable trends in this category are the 5,086% QoQ in application-level DDoS attacks against the consumer electronics industry and the 2,131% QoQ against online media companies.

Another worrying emerging trend is the method . Reflection attacks start with a small packet that is reflected within a closed network, its size amplified with each bounce. When you reach the potential ceiling, the resulting huge volume of traffic is funneled to the target.

Another interesting exploit presented in the Cloudflare report is that of the Lantronix Discovery Protocol which is used in a large number of IoT.

See also: Log4Shell exploits used to DDoS botnets and install cryptominers

Attackers use 4-byte requests to target publicly exposed Lantronix devices, generating a 30-byte response, reaching a 7.5x amplification ratio. By spoofing the victim's source IP, hackers can direct a large number of generated responses to a target, suddenly carrying out an indirect attack.

In recent years, DDoS attacks have not gone out of fashion, but they are changing form, methods and traffic mixing tricks and are returning to knock on the door of vulnerable, poorly protected and weak servers.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS