3 ms·
Do you want more than a name and a organization? Would you like John’s home address? > Over a dozen airport websites were impacted by the "denial of service" a
by snake_doc 4y ago
Do you want more than a name and a organization? Would you like John’s home address?
> Over a dozen airport websites were impacted by the "denial of service" attack, John Hultquist, head of intelligence analysis at cybersecurity firm Mandian[t], told ABC News. That type of attack essentially overloads sites by jamming them with artificial users.
>” Killnet," a pro-Russian hacker group, is believed to be behind the attack, according to Hultquist. While similar groups have been found to be fronts for state-backed actors, Hultquist said there is no evidence the Russian government was involved in directing this attack.
- mkoryak 4y agoSerious question: How do they know that? I assume killnet does not have a static IP address and doesn't leave it's return address
- woodruffw 4y agoI don’t know about the details in this case, but hacking (particularly DDoS) groups can be remarkably childish: they sometimes intentionally leave their name in requests, knowing that it’ll show up in logs. The other identifying technique is correlation: if they’re using a network of hacked devices to create a flood of traffic, any previous attacks that saw traffic from those same devices are possibly from the same group. So it’s possible killnet has a public chronology here.
- Minor49er 4y agoThe former of these would easily open the possibility of a false flag. Same with the latter, though it would be harder to pull off
- woodruffw 4y agoThis would be a pretty strange false flag: why bother blaming some random group that hasn’t been linked to the Russian government? To my mind, the most likely explanation here is the simplest one: airport websites make good testing targets, and Russia doesn’t punish hackers who target non-military resources in the West.
- Minor49er 4y agoI was speaking generally, but in this case it would be used to simply say "the Russians," regardless of whether or not they are under the Russian government. Even then, using your own example: imagine you are testing a malicious system that you built that is hitting a public testing target. Wouldn't you want to link it to anyone other than yourself for when it is inevitably detected?
- NegativeK 4y agoPeople doing threat intelligence are generally on top of attribution and try to do appropriate, fact-based attribution. That said, the warnings about Russia interfering with US infrastructure were flowing a bit before the invasion of Ukraine. Russia would be the first suspect on the top of the list, even barring good threat intel.
- status200 4y agoHacking groups can have a recognizable fingerprint / strategy [0] Killnet has claimed responsibility for similar attacks in the past [1] [0] http://attack.mitre.org/ http://attack.mitre.org/ [1] https://www.cisa.gov/uscert/ncas/alerts/aa22-110a https://www.cisa.gov/uscert/ncas/alerts/aa22-110a
- kasey_junk 4y agohttps://www.mandiant.com/resources/blog/how-mandiant-tracks-uncategorized-threat-actors https://www.mandiant.com/resources/blog/how-mandiant-tracks-...
- laba 4y agokillnet spends a lot of time promoting themselves, 7 hours ago they announced in their telegram channel that they are going to start an attack on USA airport websites and asked everybody to join them They've also done similar attacks before so they were clearly under radar
- fit2rule 4y ago
- citilife 4y ago> Over a dozen airport websites were impacted by the "denial of service" attack, John Hultquist, head of intelligence analysis at cybersecurity firm Mandian, told ABC News. That type of attack essentially overloads sites by jamming them with artificial users. That's not a "senior official"; "official" implies government, that's a company. Yes, I would like to know the government agency official providing this information. >” Killnet," a pro-Russian hacker group, is believed to be behind the attack, according to Hultquist. While similar groups have been found to be fronts for state-backed actors, Hultquist said there is no evidence the Russian government was involved in directing this attack. What evidence supports this? IMO it's coming from that unspecified official. And yes, I think evidence needs to be provided before claims are made. They're just saying "I think it's these guys" ... because?
- kasey_junk 4y agoThe quote you embedded is attributed to a person and where they work? Perhaps you meant to quote something else? Mandiants attribution methodology is trivially found on their website: https://www.mandiant.com/resources/blog/how-mandiant-tracks-uncategorized-threat-actors https://www.mandiant.com/resources/blog/how-mandiant-tracks-...
- deleted 4y ago[deleted]
- citilife 4y agoRead the ABC article carefully (as one should always do) There's mention of a "senior official" > senior official briefed confirmed to ABC News. So a source in government confirmed this to ABC (who's that?). Was it just a "could be russia" type comment. There's a separate person, who's primarily sharing the story: > Over a dozen airport websites were impacted by the "denial of service" attack, John Hultquist, head of intelligence analysis at cybersecurity firm Mandian, told ABC News. ABC and many news outlets generally require multiple sources prior to publishing. There's been a lot of stories lately that have the same base source, but they decide to count as "multiple sources" because an official in the government leaks to two different people and those two people confirm. It's called "information laundering" Anyway, i'd really out of genuine curiosity know how they know this is from Russia. Which agencies are confirming this? IMO it seems petty and not something a government would do.
- laba 4y agothis killnet guys stated that they are starting USA airports DDOS in their telegram channel, they also provided list of airports and their urls they've done similar things before, most of their "hacking" consists of ddosing some sites that they randomly decide are an enemy to Russia