Close
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Logo
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Home Cloud
    • Cloud
    • Cybersecurity
    • Networking

    Cyber-Criminals, Not WikiLeaks Supporters, Hit Spamhaus with DDoS Attack

    Written by

    Fahmida Y. Rashid
    Published December 21, 2010
    Share
    Facebook
    Twitter
    Linkedin

      eWEEK content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More.

      A distributed denial-of-service attack against anti-spam group Spamhaus has provided evidence that cyber-criminals have found a new target: WikiLeaks supporters. The cyber-criminals have combined the intense interest over WikiLeaks with a misleading domain name to trick users into going to a fake site, security researchers said.

      Spamhaus was hit by DDoS attack on Dec. 18. Since the group had come under fire from WikiLeaks supporters for warning that wikileaks.info was under the control of a Russian host known for hosting malware and phishing sites, Spamhaus and other security researchers naturally thought it was a retaliatory attack from Anonymous.

      In a message to the North American Network Operators’ Group mailing list during the attack, Steve Linford, founder of Spamhaus wrote, “We’re not saying ‘Don’t go to WikiLeaks.’ We’re saying ‘Use the wikileaks.ch server instead.'”

      After further analysis of its logs on Dec. 20, Spamhaus corrected its earlier statement in an update, reporting the attacks were from a professional botnet and not from the point-and-click LOIC (Low Orbit Ion Cannon) tool that Anonymous uses for its DDoS attacks.

      The entire saga began Dec. 14 when Spamhaus issued a warning that the previously defunct wikileaks.org site was redirecting to a mirror on the wikileaks.info domain, which was actually being hosted by a Russian bullet-proof host Webalta. The host has often been associated with phishing, banking fraud, stolen credit card information and malware, according to Spamhaus. The main .org site has been offline ever since the site’s U.S.-based DNS provider withdrew services earlier this month.

      Chester Wisniewski, a senior security adviser at Sophos, wrote on the Naked Security blog that it was not clear how the Russian host had gotten control over that .org site.

      Spamhaus advised users to use a safer URL, such as the current official home of WikiLeaks, at wikileaks.ch, or one of the official mirrors listed on the site. The .info site was not listed as an official mirror even though it was displaying WikiLeaks documents and it could have become a “real threat” if the pages had actually hosted malicious content, wrote Wisniewski.

      Trend Micro also issued a similar warning, saying, “No matter what your political view is, this is rather disturbing.” The security firm assigned a low reputation score to wikileaks.info “not because of political controversy” but because of the “bad neighborhood” where the domain is hosted.

      Even though Sophos has not found any malware, it would be safer to use the wikileaks.ch site instead, said Wisniewski.

      On Dec. 15, a press release with a WikiLeaks logo on the main page of the .info site claimed the information from Spamhaus was “false” and “none of [Spamhaus’] business,” and called on supporters to “voice their concern” about the warnings, in a clear reference to Operation Payback, according to Linford.

      As the logs vindicate Anonymous, Spamhaus conceded that it identified the attacker but not the reasons for attack. The anti-spam outfit now believes the attacks came from the Russia-based Heihachi group, which resells Webalta services. Heihachi controls enough botnets for the attack and may have retaliated after being unmasked, said Spamhaus.

      The attack must have been fairly substantial to actually knock Spamhaus offline, as the organization faces DDoS attacks on an almost daily basis, most of which it is able to handle without trouble. That should have been the first clue this was not an Anonymous operation, as the group can’t come up with that kind of firepower.

      A “vigilante DDoS attack” of several hundreds of machines using LOIC can’t do a lot of damage to sites that are built to withstand attacks. Instead, a “botnet of millions of machines” would be needed, according to Jason Hoffman, co-founder and chief scientist at Joyent.

      After the DDoS attack, Anonymous also denied responsibility, according to a Spamhaus statement on its site. The statement also claimed many of the members were distancing themselves from those who had promoted the attack.

      “Our old domain name, AnonOps.net, did indeed reside on the Heihachi network; however, this does not mean that we are related in any way to an attack carried out by one of Heihachi’s partners or customers,” Anonymous said in a letter to Spamhaus.

      The other potential risk apart from malware is that the fake site can post “fake WikiLeaks documents” that could “mislead people into believe just about anything they like,” said Wisniewski.

      “Currently wikileaks.info is serving highly sensitive leaked documents to the world, from a server fully controlled by Russian malware cyber-criminals, to an audience that faithfully believes anything with a ‘Wikileaks’ logo on it,” Linford wrote.

      Fahmida Y. Rashid
      Fahmida Y. Rashid

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      MOST POPULAR ARTICLES

      Artificial Intelligence

      9 Best AI 3D Generators You Need...

      Sam Rinko - June 25, 2024 0
      AI 3D Generators are powerful tools for many different industries. Discover the best AI 3D Generators, and learn which is best for your specific use case.
      Read more
      Cloud

      RingCentral Expands Its Collaboration Platform

      Zeus Kerravala - November 22, 2023 0
      RingCentral adds AI-enabled contact center and hybrid event products to its suite of collaboration services.
      Read more
      Artificial Intelligence

      8 Best AI Data Analytics Software &...

      Aminu Abdullahi - January 18, 2024 0
      Learn the top AI data analytics software to use. Compare AI data analytics solutions & features to make the best choice for your business.
      Read more
      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Video

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2024 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.

      ×