Feeds

DDoS botnet attacks gold miners and wine makers

Malware with posh taste

SANS - Survey on application security programs

Security researchers have discovered a strain of DDoS botnet agent that launches an attack against large corporate investment groups and mining-related interests.

The technically unremarkable JKDDOS botnet launches packet-flooding attacks on targeted websites from malware-infected zombie PCs. Targets over the months have included gaming sites and online stores as well as more obscure and unusual targets.

For example, an investment firm was repeatedly targeted for attack, DDoS mitigation tool firm Arbor Networks reports.

"A well-known investment company based in New York City was attacked by a JKDDOS botnet on six separate occasions during the 10-day period starting on October 21, 2010, with the shortest and longest attacks lasting approximately three and 33 hours, respectively," Jeff Edwards, a security researcher at Arbor, writes.

"Three different victims have some connection to the gold mining industry, and one victim was a manganese miner."

The botnet, seeded from exploit-serving websites in China and the US and controlled through a command infrastructure in China, has also attacked a "a corporate holding company that invests in major wineries".

It may be that JKDDOS is a tool in an underground denial of service for hire service, at least that is the most obvious explanation that springs to mind, but there is nothing to either prove or disprove this theory in the code itself, as a detailed write-up of the malware by Arbor demonstrates. ®

High performance access to file storage

More from The Register

next story
Obama allows NSA to exploit 0-days: report
If the spooks say they need it, they get it
Putin tells Snowden: Russia conducts no US-style mass surveillance
Gov't is too broke for that, Russian prez says
Snowden-inspired crypto-email service Lavaboom launches
German service pays tribute to Lavabit
Mounties always get their man: Heartbleed 'hacker', 19, CUFFED
Canadian teen accused of raiding tax computers using OpenSSL bug
Heartbleed exploit, inoculation, both released
File under 'this is going to hurt you more than it hurts me'
Arts and crafts store Michaels says 3 million credit cards exposed in breach
Meanwhile, Target investigators prepare for long process in nabbing hackers
Canadian taxman says hundreds pierced by Heartbleed SSL skewer
900 social insurance numbers nicked, says revenue watchman
prev story

Whitepapers

SANS - Survey on application security programs
In this whitepaper learn about the state of application security programs and practices of 488 surveyed respondents, and discover how mature and effective these programs are.
Combat fraud and increase customer satisfaction
Based on their experience using HP ArcSight Enterprise Security Manager for IT security operations, Finansbank moved to HP ArcSight ESM for fraud management.
The benefits of software based PBX
Why you should break free from your proprietary PBX and how to leverage your existing server hardware.
Top three mobile application threats
Learn about three of the top mobile application security threats facing businesses today and recommendations on how to mitigate the risk.
3 Big data security analytics techniques
Applying these Big Data security analytics techniques can help you make your business safer by detecting attacks early, before significant damage is done.