Categories: SecurityWorkspace

Hackers Shift From Child’s Play To Serious Business

Cyber-attacks have dominated headlines this summer as government agencies, large organisations and small businesses have been hit by malware, distributed-denial-of-service attacks and network intrusions. On the personal front, individuals’ email and social networking accounts have been hijacked.

Most cyber-attackers are motivated by money, whether it’s by looting bank accounts or selling stolen information to other criminals, said Josh Shaul, CTO of Application Security. However, there’s been a surge in politically motivated attacks in the past few months as a number of groups—including the notorious hacker collective Anonymous—turned to cyber-attacks as a form of protest.

PandaLabs researchers predicted last December that the cyber-protests that have added the word “hacktivism” to the English language will continue to grow in frequency because it’s been so effective in getting attention.

In the past few months, even hacktivism has been transformed as tactics and motivations have evolved. In the past, cyber-protesters generally defaced Websites or launched DDoS attacks to express their discontent.

In these DDoS attacks, Websites were overwhelmed with large volumes of server and database requests and became inaccessible to legitimate site visitors. For the most part, the majority of hacktivism relied on low-tech techniques for its activities, Shaul said.

Anonymous encouraged supporters to download the Low Orbit Ion Cannon tool and to “fire” millions of packets at the targeted site. The program didn’t do anything overly complex other than to use an automated script to repeatedly send a simple request to the target Web server in a very short period of time.

Some of their past targets included “anti-piracy groups,” such as the Motion Picture Association of America and the Recording Industry Association of America; businesses that cut off ties with WikiLeaks; or even the totalitarian regimes in North Africa facing pro-democracy demonstrations.

Provoking the beast

Things changed when Aaron Barr, then-CEO of HBGary Federal, bragged about having unmasked the identities of several Anonymous members. Some members breached HBGary Federal’s email server in February and posted stolen emails and sensitive documents onto a wiki, WikiLeaks-style.

Several researchers told eWEEK Europe UK that the attack on HBGary Federal was a sign of hacktivists adopting new and more aggressive tactics to express their displeasure.

Continued on page 2

Page: 1 2 3

Fahmida Y Rashid eWEEK USA 2014. Ziff Davis Enterprise Inc. All Rights Reserved.

View Comments

  • "In contrast, cyber-criminals want to stay unnoticed so that they can keep stealing."

    This is absolutely correct. The one defining characteristic of Anonymous/Lulzsec is that they give media interviews about their attacks the next day. This desire for media, especially using a criminal act to draw attention, is very similar to terrorism. If there is such a thing, Anonymous/Lulzsec is the "harbringer of cyber-terrorism.

Share
Published by
Fahmida Y Rashid eWEEK USA 2014. Ziff Davis Enterprise Inc. All Rights Reserved.

Recent Posts

Apple Slashes iPhone Prices In China

Amid intense competition from Huawei and others, Apple has again slashed the price of its…

12 hours ago

Bitcoin ‘Creator’ Craig Wright Repeatedly Lied, Rules UK Judge

Damning ruling by British judge, after he rules that self-proclaimed bitcoin inventor lied 'repeatedly' to…

13 hours ago

Julian Assange Granted Right To Challenge US Extradiction Order

High Court rules Wikileaks founder Julian Assange can appeal against extradition to the US, despite…

14 hours ago

Tesla Layoffs Continue With Another 600 Jobs In California

Regulatory filing last week shows Elon Musk's Tesla is cutting another 600 jobs in California,…

15 hours ago

UK Regulator Declines To Investigate Microsoft’s Mistral AI Deal

Weeks after seeking feedback on Microsoft's partnership with Mistral AI, UK regulator says it does…

19 hours ago

UK AI Safety Institute To Open Office In US

Seeking collaboration on AI regulation, UK's AI Safety Institute to cross Atlantic and will open…

19 hours ago