Feeds

Zombies are attacking America – researchers

Banking sector DDoSers 'used botnets', say security boffins

Security for virtualized datacentres

Hackers responsible for an ongoing series of attacks against US banks over the past week may be tapping into botnets to power their assaults, according to security researchers. Meanwhile, the Financial Services ISAC (Information Sharing and Analysis Center) continues to advise banks to be prepared for attack.

Bank of America, Citigroup, US Bancorp, JPMorgan Chase, Wells Fargo and PNC have all been hit by DDoS attacks for which hacker group the Izz ad-Din al-Qassam Cyber Fighters took credit via a series of posts to PasteBin. The hacktivist group claimed its actions had been prompted by indignation over the Innocence of Muslims, an amateur anti-Islamic film whose trailer had appeared on YouTube. The same film has also provoked riots and attacks on Western diplomatic missions across the world.

The DDoS attacks have been responsible for intermittent disruption and slowdowns for bank customers trying to use the targeted websites.

The group has rallied for more hacktivists to back the cause. One of the posts calls for volunteers to visit sites which then generate attacks from visitors' PCs which are directed at targeted US banking sites. Jaime Blasco, a security researcher at AlienVault, told The New York Times that this attack method alone doesn't account for the severity of cyber assaults that have been directed against US banks.

Blasco said attackers "must have had help from other sources" such as someone with access to botnet networks of compromised PCs or contacts in a well-resourced group, such as a nation state. One of the members of infamous hacktivist crew LulzSec allegedly owned a botnet used in its attacks, providing a zombie attack precedent of sorts.

Independent US Senator Joe Lieberman told NBC during a television interview that he believed Iranian government sponsored hackers were involved in the attacks, suggesting the country's involvement was motivated by a desire to retaliate against Stuxnet and related attacks against Iran's nuclear programme. Gholam Reza Jalali, the head of Iran’s Passive Defense Organization, who is in charge of the country's cyber programme, has denied these claims, which remain unsubstantiated.

Hacktivist statements associated with the ongoing attacks on US banks demand the erasure of the Innocence of Muslims from the interwebs.

The Financial Services ISAC raised its cyber threat level to "high" on 19 September, around the time of the first attacks targeting Bank of America, and the net attack risk outlook remains at the organisation's second-highest state of alert.

Dan Holden, director of research at Arbor's Security Engineering and Response Team (ASERT), said the attacks were almost certainly powered by botnets.

"This attack has generated enormous amount of attention because it was telegraphed in advance, putting these firms on notice," Holden told El Reg. "That has led to great media interest and frankly, some pretty wild speculation about motives and attack techniques.

"Arbor does not believe that this was an opt-in only attack, but one driven heavily by botnets as well. This incident shows the need for businesses to take a proactive approach to the issue of network availability. Trying to fix your roof when it's raining is not pleasant experience." ®

Secure remote control for conventional and virtual desktops

More from The Register

next story
NASTY SSL 3.0 vuln to be revealed soon – sources (Update: It's POODLE)
So nasty no one's even whispering until patch is out
Russian hackers exploit 'Sandworm' bug 'to spy on NATO, EU PCs'
Fix imminent from Microsoft for Vista, Server 2008, other stuff
Forget passwords, let's use SELFIES, says Obama's cyber tsar
Michael Daniel wants to kill passwords dead
FBI boss: We don't want a backdoor, we want the front door to phones
Claims it's what the Founding Fathers would have wanted – catching killers and pedos
Kill off SSL 3.0 NOW: HTTPS savaged by vicious POODLE
Pull it out ASAP, it is SWISS CHEESE
Facebook slurps 'paste sites' for STOLEN passwords, sprinkles on hash and salt
Zuck's ad empire DOESN'T see details in plain text. Phew!
Admins! Never mind POODLE, there're NEW OpenSSL bugs to splat
Four new patches for open-source crypto libraries
prev story

Whitepapers

Forging a new future with identity relationship management
Learn about ForgeRock's next generation IRM platform and how it is designed to empower CEOS's and enterprises to engage with consumers.
Why cloud backup?
Combining the latest advancements in disk-based backup with secure, integrated, cloud technologies offer organizations fast and assured recovery of their critical enterprise data.
Win a year’s supply of chocolate
There is no techie angle to this competition so we're not going to pretend there is, but everyone loves chocolate so who cares.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
Intelligent flash storage arrays
Tegile Intelligent Storage Arrays with IntelliFlash helps IT boost storage utilization and effciency while delivering unmatched storage savings and performance.