Cyber Affairs
No Result
View All Result
  • Login
  • Register
[gtranslate]
  • Home
  • Live Threat Map
  • Books
  • Careers
  • Latest
  • Podcast
  • Popular
  • Press Release
  • Reports
  • Tech Indexes
  • White Papers
  • Contact
Social icon element need JNews Essential plugin to be activated.
  • AI
  • Cyber Crime
  • Intelligence
  • Laws & Regulations
  • Cyber Warfare
  • Hacktivism
  • More
    • Digital Influence Mercenaries
    • Digital Diplomacy
    • Electronic Warfare
    • Emerging Technologies
    • ICS-SCADA
    • Books
    • Careers
    • Cyber Crime
    • Cyber Intelligence
    • Cyber Laws & Regulations
    • Cyber Warfare
    • Digital Diplomacy
    • Digital Influence Mercenaries
    • Electronic Warfare
    • Emerging Technologies
    • Hacktivism
    • ICS-SCADA
    • News
    • Podcast
    • Reports
    • Tech Indexes
    • White Papers
COMMUNITY
NEWSLETTER
  • AI
  • Cyber Crime
  • Intelligence
  • Laws & Regulations
  • Cyber Warfare
  • Hacktivism
  • More
    • Digital Influence Mercenaries
    • Digital Diplomacy
    • Electronic Warfare
    • Emerging Technologies
    • ICS-SCADA
    • Books
    • Careers
    • Cyber Crime
    • Cyber Intelligence
    • Cyber Laws & Regulations
    • Cyber Warfare
    • Digital Diplomacy
    • Digital Influence Mercenaries
    • Electronic Warfare
    • Emerging Technologies
    • Hacktivism
    • ICS-SCADA
    • News
    • Podcast
    • Reports
    • Tech Indexes
    • White Papers
NEWSLETTER
No Result
View All Result
Cyber Affairs
No Result
View All Result
  • Cyber Crime
  • Cyber Intelligence
  • Cyber Laws & Regulations
  • Cyber Warfare
  • Digital Diplomacy
  • Digital Influence Mercenaries
  • Electronic Warfare
  • Emerging Technologies
  • Hacktivism
  • ICS-SCADA
  • Reports
  • White Papers

Russian Hackers “NoName057(16)” Planning Massive DDoS Attack

admin by admin
Mar 5, 2024
in News
A A
0

The Russia-Ukraine war has provoked several threat groups who were identified as “nationalist hactivists” that targeted most of the NATO member states with multiple attack vectors.

One of the most notable ones was the pro-Russian group NoName057(16), which gained a reputation due to Project DDoSia, which was used to conduct large-scale distributed denial-of-service (DDoS) attacks.

However, the threat group released a newer version of Project DDoSia in November 2023 without any prior announcements.

This new version includes additional processor compatibility and support for 32-bit and FreeBSD operating systems and several changes have been made to the software, C2 servers, and others.

With the ANY RUN malware sandbox, you can analyze malware files, networks, modules, and registry activity. It also lets you interact with the OS directly from the browser.  

Technical Analysis

According to reports shared with Cyber Security News, the new project DDoSia ZIP archive contains two folders, one named d_eu and the other d_ru, specified for users in different geographical locations.

Moreover, this new version’s users have also been advised to use a VPN if they are located inside Russia.

There are also speculations that the threat group is attributed to the Russian state but there is no evidence to prove the claim.

However, the new version also encrypted C2 server traffic between the user and the server.

Attack chain of Project DDoSia (Source: Sekoia)

Their top targeted sectors include Government, Banking, Transportation, Defense, Technology, Energy and other industries.

Top targeted sectors of Project DDoSia (Source: Sekoia)

Project DDoSia – Shortcomings And Workarounds

Though the new version has several data transmission capabilities, the C2 servers were changed more frequently, stating that threat actors faced several challenges in running the DDoS operations and maintaining the stability of the C2 servers.

For every new configuration, the users of DDoSia must download and install the new version to establish a seamless DDoS attack against their targets.

On a side note, the new version also includes FAQs and training materials to educate users.

This FAQ has a second question, which states, “Does the provider see my actions or law enforcement agencies see my IP?” to which the answer replies as 

“If the computer is located on the territory of the Russian Federation, then even without using a VPN, it is doubtful that there will be any problems with the law since the software is designed for stress testing.

At least that’s what we think. If the computer is located outside the Russian Federation, it is strongly recommended to use a VPN to change the IP address. You can check the change in IP address, for example, on myip.com.

Monitoring the VPN in action is recommended to avoid being disabled or use a VPN with an Internet killswitch option.”

Victimology Analysis

The threat actors primarily targeted Ukraine for almost a quarter of the DDoSia attacks.

However, in January and February 2024, Finland and Italy were targeted and impacted, as Finland had presidential elections, and the Italian prime minister speculatively helped fund Ukraine.

Targeted countries of Project DDoSia (Source: Sekoia)

Additionally, Japan-related entities were targeted at the end of February 2024 due to the 15.8 billion yen aid proposed at the Japan-Ukrainian Conference for post-war reconstruction.

The threat actors continuously target countries that help Ukraine. Furthermore, the indicators of compromise can be found in this GitHub project.

You can block malware, including Trojans, ransomware, spyware, rootkits, worms, and zero-day exploits, with Perimeter81 malware protection. All are incredibly harmful, can wreak havoc, and damage your network.

Read the full article here

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

[mc4wp_form id=”387″]

Recent News

  • Understanding the Implications & Guarding Privacy- Axios Security Group
  • Hackers Actively Using Pupy RAT to Attack Linux Systems
  • Buckle Up_ BEC and VEC Attacks Target Automotive Industry

Topics

  • AI
  • Books
  • Careers
  • Cyber Crime
  • Cyber Intelligence
  • Cyber Laws & Regulations
  • Cyber Warfare
  • Digital Diplomacy
  • Digital Influence Mercenaries
  • Electronic Warfare
  • Emerging Technologies
  • Hacktivism
  • ICS-SCADA
  • News
  • Podcast
  • Reports
  • Tech Indexes
  • Uncategorized
  • White Papers

Get Informed

[mc4wp_form id=”387″]

Social icon element need JNews Essential plugin to be activated.

Copyright © 2022 Cyber Affairs. All rights reserved.

No Result
View All Result
  • Home
  • Cyber Crime
  • Cyber Intelligence
  • Cyber Laws & Regulations
  • Cyber Warfare
  • Digital Diplomacy
  • Digital Influence Mercenaries
  • Electronic Warfare
  • Emerging Technologies
  • Hacktivism
  • ICS-SCADA
  • Reports
  • White Papers

Copyright © 2022 Cyber Affairs. All rights reserved.

Welcome Back!

Login to your account below

Forgotten Password? Sign Up

Create New Account!

Fill the forms below to register

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In
This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.