Saturday, October 12, 2024
HomeCyber AttackProject DDoSia - Russian Hackers Planning a Massive DDoS Attack

Project DDoSia – Russian Hackers Planning a Massive DDoS Attack

Published on

Malware protection

Hackers launch large-scale DDoS attacks to disrupt and make online services inaccessible, driven by motives like revenge or protest, flooding targets with massive amounts of traffic to disable websites.

Recently, the cybersecurity researchers at Sekoia identified that the Russian hacker group “NoName057(16)” has been actively planning to conduct massive DDoS attacks.

Since the Ukraine conflict began, the nationalist hacktivist groups, notably the “NoName057(16),” have risen and are found to be launching Project DDoSia. 

- Advertisement - SIEM as a Service

They target pro-Ukraine entities, mostly NATO members.

Sekoia actively tracks its C2 infrastructure, which is automated for target collection and real-time monitoring.

Document
Integrate ANY.RUN in your company for Effective Malware Analysis

Are you from SOC and DFIR teams? – Join With 400,000 independent Researchers

Malware analysis can be fast and simple. Just let us show you the way to:

  • Interact with malware safely
  • Set up virtual machine in Linux and all Windows OS versions
  • Work in a team
  • Get detailed reports with maximum data
  • If you want to test all these features now with completely free access to the sandbox: ..


Project DDoSia: Massive DDoS Attack

The Project DDoSia’s Telegram channel recently, on 11 November 2023, dropped a surprise update by expanding processor support to 32-bit and adding FreeBSD compatibility. 

While the prior versions had AMD64, ARM, and ARM64 covered. Main ZIP has two folders (d_eu, d_ru) for location-based execution.

Executing shows a warning, suggesting VPN for users in Russia.

Warning message (Source – Sekoia)

No VPN mandate in Russia hints at the NoName057(16) group’s possible ties with the state despite no public acknowledgment. 

The latest version alters encryption for user-C2 server data exchange. The operating diagram for DDoSia project initiation is provided as a reminder.

Attack Chain (Source – Sekoia)

The latest update adds encryption for data in HTTP POST requests which is a new feature absent in previous versions.

C value, a GUID identifying the user’s machine, is encrypted and extracted from \HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\MachineGuid on Windows. 

The U value is from the client_id.txt file via DDoSia’s Telegram Bot. Besides this, the JSON table “inf” tracks seven elements under Windows, likely for statistical analysis, enhancing transmission sophistication.

The latest software version improved data transmission, but DDoSia admins changed the C2 servers frequently in 2024, facing stability challenges, read the Sekoia report.

NoName057(16) updated the Telegram channel with each server config change which requires users to download and install for continued attacks. 

Besides this, DDoSia lacks automated IP address change despite frequent C2 changes. Infrastructure interruptions didn’t hamper NoName057(16) group’s daily attacks.

DDoSia likely uses its servers to actively participate in attacks.

Top Countries Targeted

Here below we have mentioned all the top targeted countries:-

  • Ukraine
  • Finland
  • Italy
  • Spain
  • Germany
  • Lithuania
  • France
  • Poland
  • Switzerland
  • Romania
  • Netherlands
  • Estonia
  • Sweden
  • Latvia
  • Greece
  • United Kingdom
  • Czech Republic
  • Belgium

Top Sectors Targeted

Here below, we have mentioned all the sectors that are targeted most:-

  • Government
  • Banking
  • Transportation
  • Technology
  • Energy
  • Defence

The DDoSia’s Telegram project nears 20,000 users, while NoName057(16) channels surpass 60,000, doubling since 2023. 

The growth represents a politically and economically motivated community.

NoName057(16) collaborates with hacktivist groups, forming alliances against Italian infrastructures. 

Despite DDoSia’s ever-changing infrastructure, it consistently claims attacks.

Not only that even, it also provides daily software updates and a 2024 version with enhanced encryption.

You can block malware, including Trojans, ransomware, spyware, rootkits, worms, and zero-day exploits, with Perimeter81 malware protection. All are incredibly harmful, can wreak havoc, and damage your network.

Stay updated on Cybersecurity news, Whitepapers, and Infographics. Follow us on LinkedIn & Twitter

Tushar Subhra
Tushar Subhra
Tushar is a Cyber security content editor with a passion for creating captivating and informative content. With years of experience under his belt in Cyber Security, he is covering Cyber Security News, technology and other news.

Latest articles

Threat Actor ProKYC Selling Tools To Bypass Two-Factor Authentication

Threat actors are leveraging a newly discovered deepfake tool, ProKYC, to bypass two-factor authentication...

Mozilla Warns Of Firefox Zero-Day Actively Exploited In Cyber Attacks

A critical use-after-free vulnerability affecting Firefox and Firefox Extended Support Release (ESR) is being...

SpyCloud Embeds Identity Analytics in Cybercrime Investigations Solution to Accelerate Insider and Supply Chain Risk Analysis & Threat Actor Attribution

IDLink, SpyCloud’s new automated digital identity correlation capability, is now core to its industry-leading...

Abusix and Red Sift Form New Partnership, Leveraging Automation to Mitigate Cyber Attacks

The agreement has marked over 600,000 fraudulent domains for takedown in just two months...

Free Webinar

Protect Websites & APIs from Malware Attack

Malware targeting customer-facing websites and API applications poses significant risks, including compliance violations, defacements, and even blacklisting.

Join us for an insightful webinar featuring Vivek Gopalan, VP of Products at Indusface, as he shares effective strategies for safeguarding websites and APIs against malware.

Discussion points

Scan DOM, internal links, and JavaScript libraries for hidden malware.
Detect website defacements in real time.
Protect your brand by monitoring for potential blacklisting.
Prevent malware from infiltrating your server and cloud infrastructure.

More like this

Dark Angels Ransomware Attacking Windows And Linux/ESXi Systems

The sophisticated ransomware group Dark Angels, active since 2022, targets large companies for substantial...

LemonDuck Malware Exploiting SMB Vulnerabilities To Attack Windwos Servers

The attackers exploited the EternalBlue vulnerability to gain initial access to the observatory farm,...

Likho Hackers Using MeshCentral For Remotely Managing Victim Systems

The Awaken Likho APT group launched a new campaign in June of 2024 with...