#EdgeLive: DDoS Attacks Are Evolving into Extortion-Led RDoS Campaigns

#EdgeLive: DDoS Attacks Are Evolving into Extortion-Led RDoS Campaigns

Speaking as part of the Akamai Edge Live virtual conference, Akamai CEO Tom Leighton said cybersecurity may have become less of a consideration during the pandemic, but the level of attack the company has witnessed suggests the threat has not abated.

Leighton spoke of “an enormous increase in the number of attacks, the size of the attacks and the sophistication of the attacks.” In particular, Leighton highlighted the increased size of DDoS attacks, with one case reaching 1.5Tbps.

He said: “An attack of that volume is enough to saturate links into most countries; that is enormous, and big enough to take out any cloud data center.” Leighton also said a large number of financial services are being hit, with one example of 800 million packets per second “and you can imagine trying to fend off an attack of that scale, there is no way you can do that on your own, and no way your carrier is going to do that for you.”

He went on to highlight what he called “ransom DDoS attacks, or extortion attacks” where a demand requires you to pay some cryptocurrency, or you will be hit with a massive DDoS attack.

Roger Barranco, vice-president of global security operations at Akamai, explained that these types of attacks are different from ransomware. “Many businesses did receive extortion letters, and these letters are typically not shared publicly,” he said, showing one redacted example threatening an attack.

“Once a business is hit with a multi-vector threat campaign, particularly where the attack patterns match those used by several well-known extortion groups, it is clearly cause for alarm.”

Barranco said, in the case highlighted, the attackers had identified which company they were going after and who to the send extortion letter to, and went beyond traditional internet services and also targeted customer office buildings. “Typically any site that had a router connected to the internet was at risk,” he said.

“The fact is, there is no way for 99.9% of the world’s enterprises to defend against a determined attacker once the malicious traffic reaches their infrastructure. These attacks must be effectively fought near the attacker, far away from your network.”

Barranco also said that RDoS attack vectors are not unique, so attributing them to a campaign is difficult.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

The Security Failures of Online Exam Proctoring

Proctoring an online exam is hard. It’s hard to be sure that the student isn’t cheating, maybe by having reference materials at hand, or maybe by substituting someone else to take the exam for them. There are a variety of companies that provide online proctoring services, but they’re uniformly mediocre:

The remote proctoring industry offers a range of services, from basic video links that allow another human to observe students as they take exams to algorithmic tools that use artificial intelligence (AI) to detect cheating.

But asking students to install software to monitor them during a test raises a host of fairness issues, experts say.

“There’s a big gulf between what this technology promises, and what it actually does on the ground,” said Audrey Watters, a researcher on the edtech industry who runs the website Hack Education.

“(They) assume everyone looks the same, takes tests the same way, and responds to stressful situations in the same way.”

The article discusses the usual failure modes: facial recognition systems that are more likely to fail on students with darker faces, suspicious-movement-detection systems that fail on students with disabilities, and overly intrusive systems that collect all sorts of data from student computers.

I teach cybersecurity policy at the Harvard Kennedy School. My solution, which seems like the obvious one, is not to give timed closed-book exams in the first place. This doesn’t work for things like the legal bar exam, which can’t modify itself so quickly. But this feels like an arms race where the cheater has a large advantage, and any remote proctoring system will be plagued with false positives.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Hacker Sells Access to Pakistani Airlines’ Network

Hacker Sells Access to Pakistani Airlines’ Network

Access to Pakistan International Airlines’ network is being offered for sale on the cyber underground, according to threat researchers in Israel. 

A team at dark net threat intelligence firm KELA spotted a threat actor touting domain admin access to the airline for $4,000 on two Russian-speaking illegal online forums and one English-speaking forum that they had been monitoring. 

From their headquarters in Tel Aviv, the team had been tracking ransomware trends, exploring how initial access brokers in the cybercrime community play a role in the supply chain of this popularly deployed malware.

On November 9, a KELA spokesperson told Infosecurity Magazine: “We’ve been tracking a threat actor that just last week published domain access for sale to Pakistan International Airlines’ network. 

“Most of the time we’re seeing cyber-criminals purchase these initial accesses to gain an initial foothold into the victim’s network, from which they can then perform lateral movement to advance their access privileges and potentially employ ransomware or some other type of attack.”

A week after putting access to the airline’s network on the black market, the cyber-criminal announced that they were also selling all the databases that exist in the airline’s network. 

The threat actor published a sample of the allegedly stolen data, which they claim contains “all people information who use Pakistan Airline includ[ing] name, last name, phone number, passport.”

“The actor mentions that what he is selling includes around 15 databases all with different amounts of records—some around 500k records and some around 60k–50k records—but that all records stored in their network are included,” said KELA.

If the threat actor’s claims are genuine, then they have hit the same victim twice, leveraging the network access that they obtained to the airline’s network to exfiltrate the company’s data. 

“What’s interesting is that this actor takes two different approaches to try and monetize,” said KELA.

KELA’s researchers have been tracking the threat actor since July 2020, during which time the actor has offered 38 accesses for sale at a cumulative price of at least $118,700.

“We know he has more accesses that he offers in private,” said KELA.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk