Akamai Releases Findings of Increased Attacks and More Aggressive Tactics from DD4BC Extortionist Group

Akamai Releases Findings of Increased Attacks and More Aggressive Tactics from DD4BC Extortionist Group

Akamai Technologies, Inc. (NASDAQ: AKAM), the global leader in content delivery network (CDN) services, published today, through the company's Prolexic Security Engineering & Research Team (PLXsert), a new cybersecurity case study.

Akamai shared details of an increase in distributed denial of service (DDoS) attacks from the Bitcoin extortionist group DD4BC, based on PLXsert's observation of attack traffic targeted at customers from September 2014 through August 2015. Since April 2015, the team identified 114 DD4BC attacks, including more aggressive measures that target brand reputation through social media.

The full report is available for download here: http://www.stateoftheinternet.com/dd4bc-case/

"DD4BC has been using the threat of DDoS attacks to secure Bitcoin payments from its victims for protection against future attacks," said Stuart Scholly, Senior Vice President & General Manager, Security Division at Akamai.

"The latest attacks – focused primarily on the financial service industry – involved new strategies and tactics intended to harass, extort and ultimately embarrass the victim publically."

What is the DD4BC Group, and How Does it Operate?

The DD4BC group has been responsible for a large number of Bitcoin extortion campaigns dating back to 2014. In the past year, the group expanded its extortion and DDoS campaigns to target a wider array of business sectors – including financial services, media and entertainment, online gaming and retailers. The group has used e-mail to inform its target that a low-level DDoS attack will be launched against the victim's website. From June through July 2015, the attacks increased from low-level to more than 20 Gbps in some cases. The group would then demand a Bitcoin ransom to protect the company from a larger DDoS attack designed to make its website inaccessible.

PLXsert released a history of the group's activities that can be found in Akamai's Security Bulletin: DD4BC Operation Profile, published in April 2015.

DD4BC Using Social Media to Exploit Organizations

According to research from PLXsert, DD4BC recently threatened to expose targeted organizations via social media, adding to the damage caused by the DDoS attack itself. The goal apparently is to garner more attention for the group's ability to create service disruptions by publicly embarrassing the target and tarnishing the company's reputation through these wide-reaching channels.

The group's methodology typically includes use of multi-vector DDoS attack campaigns, revisiting former targets and also incorporating Layer 7 DDoS in multi-vector attacks, specifically concentrating on the WordPress pingback vulnerability. This vulnerability is exploited to repeatedly send reflected GET requests to the target to overload the website. Akamai researchers have seen this attack method incorporated into DDoS booter suite frameworks.

Threat Mitigation

Since September 2014, the Akamai PLXsert has observed a total of 141 confirmed DD4BC attacks against Akamai customers. Of those attacks, the average bandwidth was 13.34 Gbps, with the largest DDoS attack reported at 56.2 Gbps.

To help protect against extortionist group DD4BC, and subsequent DDoS attacks, Akamai recommends the following defensive measures:

 - Deploy anomaly- and signature-based DDoS detection methods to identify attacks before a website becomes unavailable to users.

 - Distribute resources to increase resiliency and avoid single points of failure due to an attack.

 - Implement Layer 7 DDoS mitigation appliances on the network in strategic locations to reduce the threat for critical application servers.

Akamai and PLXsert will continue to monitor ongoing threats, campaigns and methodologies used by DD4BC. To learn more about the group and its specific threats and mitigation techniques, please download a complimentary copy of the threat advisory at www.stateoftheinternet.com.

About Akamai

As the global leader in Content Delivery Network (CDN) services, Akamai makes the Internet fast, reliable and secure for its customers. The company's advanced web performance, mobile performance, cloud security and media delivery solutions are revolutionizing how businesses optimize consumer, enterprise and entertainment experiences for any device, anywhere.

To learn how Akamai solutions and its team of Internet experts are helping businesses move faster forward, please visit http://www.akamai.com/ or http://blogs.akamai.com/, and follow @Akamai on Twitter.

Note: All product and company names are trademarks of their respective organizations.


Related News

Bitcoin Extortion Group DD4BC Now Targeting Financial Services

The extortion group known as DD4BC has stepped up the number of attacks this year and is now targeting the financial services industry, according to a new report. Akamai Technologies, a content delivery network and cloud services provider which produced the report, has identified 114 attacks carried out by DD4BC since April 2015. Stuart Scholly, senior vice president and general manager at Akamai's security division, said in a statement: "DD4BC has been using the threat of DDoS attacks to secure bitcoin payments from its victims for protection against future attacks ... The latest attacks....

Bitcoin Extortion Group DD4BC Prompts Warning from Swiss Government

Extortionist group DD4BC appears to be connected to a new wave of distributed denial of service (DDoS) attacks against organizations in Switzerland, New Zealand and Australia. With the new attacks, the group is seeking 25 BTC from affected parties in exchange for relinquishing the flood of inbound data is issues that renders recipient websites inaccessible. Most recently, DD4BC was named in an 8th May warning published by the Swiss Governmental Computer Emergency Response Team (GovCERT), a division of MELANI, a national agency focused on cybersecurity issues. The warning read: "In the past....

Cybercriminal Group Demands Bitcoin Ransoms from Financial Institutions

“DD4BC,” a cybercriminal group that has launched distributed denial of service (DDos) attacks on bitcoin mining companies, exchanges and Hong Kong Banks since mind-2014, have begun to target financial institutions including brokerages, banks and financial organization in Europe, Australia and U.S. According to Akamai, a Massachusetts based content delivery network, DD4BC has carried out 87 attacks specifically on financial institutions, and have shifted its focus from bitcoin startups to banks and financial organizations over the past few months. During the last three months, the hacking....

Know DD4BC - The Extortionist Group Demanding Bitcoin Ransoms

Cybercriminal group DD4BC, which stands for "DDoS for Bitcoin" (Distributed Denial of Service for Bitcoin) has been targeting financial institutions since the year 2014, demanding extortion in Bitcoin. The fugitive group threatens the financial institutions that if they fail to cough up a desired number of Bitcoin then they will take down their websites. The modus operandi of taking down a website is simple. DD4BC targets a website with traffic so heavy that the web server comes crashing down and the site goes offline. As per information analytics company Neustar, the cost of such a....

Bitcoin Extortionists DD4BC Targeting Scandinavian Companies

It is no secret that Bitcoin has become a favorite payment method for hoodlums and malicious individuals. Just a few weeks ago, a lot of companies around the world facing threats of ransomware, which would only decrypt files after the infected entity made a Bitcoin payment. And now DD4BC, a notorious group of extortionists, are targeting Scandinavian companies with complex Direct Denial of Service attacks. If you are a Scandinavian company using a centralized service for any of your business needs, you may be faced with a threat from DD4BC in the very near future. This group of hackers and....