Russian banking and financial services company Sberbank is being targeted in a wave of unprecedented hacking attacks. Earlier this month, the bank fought off the largest distributed denial-of-service (DDoS) attack in its history.
See also: Microsoft: Huge increase in Linux XorDDoS malware activity

See also: Fronton botnet: It does much more than DDoS attacks
Sergei Lebed, vice president and director of cybersecurity at Sberbank, told the audience attending the Positive Hack Days conference that thousands of Internet have attacked the organization in recent months.
Sberbank is Russia's largest financial company and the third largest in Europe, with total assets exceeding $570 billion.
The entity was among the first to be sanctioned following the Russian invasion of Ukraine , and as a result activities on the European continent have been greatly restricted.
Hackers pro- Ukraine have been targeting Sberbank since the beginning of the conflict in February. According to the bank, this activity has not subsided.
Huge waves of attacks
On May 6, 2022, Sberbank says it repelled the largest DDoS attack it has ever seen, measuring 450 GB/sec.
DDoS are resource depletion attacks that aim to make online services unavailable to customers, leading to business disruption and financial losses .
The malicious traffic that supported the attack on Sberbank's main website was created by a botnet with 27,000 compromised devices located in the United States, the United Kingdom, Japan , and Taiwan.
As Lebed explained, cybercriminals used various tactics to carry out this cyberattack, including code injections in advertising scripts, malicious Chrome , and Docker containers armed with DDoS tools.

Lebed says it has identified over 100,000 internet users being attacked in the past two months, while in March, they recorded 46 simultaneous DDoS attacks on different Sberbank services.
Many of these attacks exploited traffic to online streaming and movie theater sites, similar to a tactic used by pro-Russian threat groups against key Ukrainian websites.
See also: Battle.net recovers from DDoS attacks after one hour
The web browsers of visitors to these compromised sites execute specially crafted code found in injected scripts that generate multiple requests to specific URLs ,in this case, the Sberbank domain.
DDoS attacks at this level are likely to continue and, as the Sberbank announcement concludes, may decrease in number but increase in power.
Information source: bleepingcomputer.com
