Now on Demand Ransomware Resilience & Recovery Summit - All Sessions Available
Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Network Security

DDoS Toolkit Being Used in Synchronized Attacks Against Banking, Hosting and Energy Firms

The denial-of-service toolkit used against financial institutions late last year has also been used against hosting and energy companies, DDoS protection firm Prolexic said in an advisory Thursday.

The denial-of-service toolkit used against financial institutions late last year has also been used against hosting and energy companies, DDoS protection firm Prolexic said in an advisory Thursday.

The “itsoknoproblembro” toolkit was behind the distributed denial-of-service attacks that dogged several banks in the United States last fall. The attacks against the banks were massive, with some peaking at 70 Gbps and more than 30 million pps. The toolkit has a two-tier command mode that can launch multiple high-bandwidth attack types simultaneously and has been used in coordinated campaigns against the energy, hosting provider, and banking industries, Scott Hammack, CEO of Prolexic, said in a statement.

itsoknoproblembro

Prolexic did not identify the specific companies that have been targeted.

“This toolkit, which was dangerous to begin with, has been evolving rapidly over the past year,” Hammack said.

The itsoknoproblemro toolkit poses a very effective, multi-level threat, Prolexic said. The toolkit targets known vulnerabilities in Web content management systems, including Joomla and WordPress, to infect Web servers with malicious PHP scripts, Prolexic said. It also relies on various attack vectors, including POST, GET, TCP, and UDP floods. A Kamikaze GET flood script repeatedly re-launches automated attacks.

Based on chatter in the hacker underground, Prolexic expects itsoknoproblembro DDoS campaigns to “grow in frequency.” The company did not say whether it expected attackers to expand to other industries or stick with the current three.

Past attacks relied on compromised servers in data centers. The itsoknoproblembro toolkit itself does not compromise the servers, as they are infected using other methods. Once the machines are under the attacker’s control, then the itsoknoproblembro kit launches simultaneous attacks.

The threat advisory included 11 different attack signatures and detailed SNORT rules organizations can use to mitigate potential DDoS attacks. Along with the threat advisory, Prolexic also released a suite of detection and mitigation rules and a log analysis tool.

Advertisement. Scroll to continue reading.

The detection rules identify infected Web servers (bRobots) within the organization that has been commandeered into taking part in the DDoS attacks. The log analysis tool (BroLog) pinpoints which scripts were access, by what IP address, for what target. Organizations can use the information to sanitize infected servers and prevent them from being used in the attacks.

“We want to support the security community by sharing our knowledge, so we can help eradicate this threat and remove these malicious scripts from infected machines before they do even more damage,” Hammack said.

Related: Recent Bank Cyber Attacks Originated From Hacked Data Centers, Not Large Botnet

Written By

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join the session as we discuss the challenges and best practices for cybersecurity leaders managing cloud identities.

Register

SecurityWeek’s Ransomware Resilience and Recovery Summit helps businesses to plan, prepare, and recover from a ransomware incident.

Register

People on the Move

Bill Dunnion has joined telecommunications giant Mitel as Chief Information Security Officer.

MSSP Dataprise has appointed Nima Khamooshi as Vice President of Cybersecurity.

Backup and recovery firm Keepit has hired Kim Larsen as CISO.

More People On The Move

Expert Insights

Related Content

Identity & Access

Zero trust is not a replacement for identity and access management (IAM), but is the extension of IAM principles from people to everyone and...

Malware & Threats

The NSA and FBI warn that a Chinese state-sponsored APT called BlackTech is hacking into network edge devices and using firmware implants to silently...

Cybersecurity Funding

Network security provider Corsa Security last week announced that it has raised $10 million from Roadmap Capital. To date, the company has raised $50...

Network Security

Attack surface management is nothing short of a complete methodology for providing effective cybersecurity. It doesn’t seek to protect everything, but concentrates on areas...

Application Security

Virtualization technology giant VMware on Tuesday shipped urgent updates to fix a trio of security problems in multiple software products, including a virtual machine...

Application Security

Fortinet on Monday issued an emergency patch to cover a severe vulnerability in its FortiOS SSL-VPN product, warning that hackers have already exploited the...

Identity & Access

Hackers rarely hack in anymore. They log in using stolen, weak, default, or otherwise compromised credentials. That’s why it’s so critical to break the...

Network Security

A zero-day vulnerability named HTTP/2 Rapid Reset has been exploited to launch some of the largest DDoS attacks in history.