HomeSecurityNew DDoS-as-a-Service platform Passion used in recent attacks on hospitals

New DDoS-as-a-Service platform Passion was used in recent attacks on hospitals

A new DDoS-as-a-Service (DDoSaaS) platform called “Passion” was used in recent attacks by pro-Russian hacktivists against medical institutions in the United States and Europe.

See also: InTheBox: Over 1,800 malicious phishing forms available

DDoSaaS Passion DDoS

A DDoS (distributed denial of service) attack is an act in which malicious actors flood a target server with numerous requests and invalid data, ultimately overloading the system to the point where it can no longer respond.

DDoSaaS platforms offer their abundant and destructive firepower to those seeking to wreak havoc on their targets, eliminating the need for individuals and organizations to personally build massive botnets or coordinate volunteer activities.

Typically, these botnets are created by exploiting vulnerable IoT components, such as routers and IP cameras, consolidating them into a massive swarm that sends malicious requests to a designated victim.

Radware investigated the Passion platform, although its source is unclear. Evidence shows connections between this malware and prominent Russian hacking groups, including Killnet, MIRAI, Venom, and Anonymous Russia.

Radware researchers reported that the “Passion Botnet” was used in a ruthless attack on January 27, targeting medical institutions from various countries including the US, Portugal, Spain, Germany , and others. This malicious act of cyberterrorism is believed to be an act of retaliation for the sending of tanks to support Ukrainian forces.

See also: HeadCrab malware: Infects 1,200 Redis servers for Monero mining

Passion DDoS

In early January 2023, the owners of Passion DDoS launched their platform through a series of website hijackings in Japan and South Africa.

DDoSaaS

Our service is provided on a subscription basis, allowing customers to choose the desired attack vector, duration , and intensity.

Passion offers a choice of ten attack vectors, allowing subscribers to tailor their attack as needed and even combine vectors to bypass mitigations implemented by the target.

We offer the following attack methods for your convenience:

  • HTTP Raw
  • Crypto
  • UAM Browser
  • HTTPS Mix
  • Browser
  • Bypass
  • DNS l4
  • Mixamp l4
  • OVH-TCP l4
  • TCP-Kill l4

For those who want access to the service, a seven-day subscription will cost you $30, while a full month of malicious activity is priced at $120. Unfortunately (or fortunately, depending on how you look at it), if you want longer-term access, then the threat actors are asked to pay $1,440 per year. As for payment methods, Bitcoin, Tether, and QIWI payments from Russia are all acceptable options.

In October 2022, the “DDOSIA” initiative was born, a pro-Russian DDoS crowdsourcing program that rewarded dedicated attackers with generous sums of money depending on how much firepower they could contribute.

See also: Google Fi: Data breach allows SIM swapping attacks

The already rich DDoS landscape is further complicated by the emergence of Passion, leading to more difficulties for global organizations that are the targets of these attacks.

Information source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS