2 ms·
Considering the hacker's motive: https://x.com/Sn_darkmeta/status/1844358501952618976 https://x.com/Sn_darkmeta/status/1844358501952618976 Is it safe to assume
by firen777 2y ago
Considering the hacker's motive: https://x.com/Sn_darkmeta/status/1844358501952618976 https://x.com/Sn_darkmeta/status/1844358501952618976
Is it safe to assume the hacker want to erase the evidence?
Forcing the service offline also means they want to prevent people from archiving evidence in the next how-ever-long hours. Combining with the spoken language they used in that video, are they planning some online disinformation campaign?
----
Edit: some more info about this group: https://old.reddit.com/r/technology/comments/1g0kupb/hacktivists_claim_responsibility_for_taking_down/lr9kbmo/ https://old.reddit.com/r/technology/comments/1g0kupb/hacktiv...
----
This group claims to be pro palestinian and it's entirely based on Russia.
[https://therecord.media/middle-east-financial-institution-6-day-ddos-attack](https://therecord.media/middle-east-financial-institution-6-day-ddos-attack) https://therecord.media/middle-east-financial-institution-6-...
>SN\_BLACKMETA has operated its Telegram channel since November 2023, boasting of DDoS incidents and cyberattacks on infrastructure in Israel, the Palestinian Territories and elsewhere. While all of the group’s messages focus on the Palestinian Territories and perceived opponents to Palestine, many of its posts are written in Russian.
>The group’s account on X also shows that it was created by someone in Staraya, a town in Novgorod Oblast, Russia. The account’s initial language was also set to Russian.
>The researchers added that analysis of timestamps and activity patterns showed possible evidence that the actors within the group are operating in a timezone “close to Moscow Standard Time (MSK, UTC+3) or other Middle Eastern or Eastern European time zones (UTC+2 to UTC+4).”
~~Attacks include pro palestine sites and groups, so~~ take that "pro palestine" with a grain of salt.
EDIT: edited for clarity on what is actually in the article and not in outside anonymous sources. If you want to read more, [there's a clearer report on one of their attacks and their usual targets.](https://www.radware.com/security/threat-advisories-and-attack-reports/six-day-web-ddos-attack-campaign/ https://www.radware.com/security/threat-advisories-and-attac...)
- TZubiri 2y agoPossible false flag? How is someone stupid enough to post this? Warrant for the account's IP is probably already issued. I don't know how many proxies the guy is behind, but it's playing with fire. Also at some point the account of a malicious hacker has to be banned right?
- firen777 2y agoCheck my edited comment for more info on that account. In short, typical russian shenanigans. >Also at some point the account of a malicious hacker has to be banned right? You can try ask musk about it.