Some malware incidents will go down in history. The IT industry remembers 2006, for example, as the year of Stuxnet, an infamous worm that drew public attention to the insecurity of supervisory control and data acquisition (SCADA) and programmable logic controller (PLC) systems. I’m quite sure that 2016 will be similarly defined as the year of the distributed denial-of-service (DDoS) attack.

A New Breed of DDoS Attack

DDoS isn’t new. In fact, it has been a common cybercriminal tool for decades. And although this type of attack took down many popular websites in 2016, that’s not why DDoS defined the year in cybersecurity. Rather, 2016 will go down as the year cybercriminals began incorporating the Internet of Things (IoT) into DDoS campaigns on a wide scale.

This new breed of malware is designed to infect millions of IoT-connected devices — not to damage them directly, but to create massive botnets through phishing campaigns, ransomware and other ploys. These botnets facilitated many high-profile attacks that knocked out several prominent websites this past year. The method is not entirely new, but the scale and success of these campaigns are quite impressive.

DDoS Best Practices for 2017

Let’s look at it from the perspective of the owner of a device used to facilitate a DDoS attack. All kinds of connected devices, from cameras, smartphones and sensors to refrigerators, light fixtures and washing machines, are fair game. Many enterprises have proper mobile security controls in place to protect their devices, but regular users, in general, are not as well-prepared. When shopping for a refrigerator, for example, consumers rarely consider what operating system it runs or whether it has a virtual private network (VPN).

It is time for consumers and businesses to change this behavior for 2017. Users should educate themselves about the consequences of DDoS attacks and vendors should be held responsible for building effective security measures into their devices. Increased awareness is the key across the board.

Read the X-Force Research report: Extortion by distributed denial of service attack

More from X-Force

SoaPy: Stealthy enumeration of Active Directory environments through ADWS

10 min read - Introduction Over time, both targeted and large-scale enumeration of Active Directory (AD) environments have become increasingly detected due to modern defensive solutions. During our internship at X-Force Red this past summer, we noticed FalconForce’s SOAPHound was becoming popular for enumerating Active Directory environments. This tool brought a new perspective to Active Directory enumeration by performing collection via Active Directory Web Services (ADWS) instead of directly through Lightweight Directory Access Protocol (LDAP) as other AD enumeration tools had in the past.…

Smoltalk: RCE in open source agents

26 min read - Big shoutout to Hugging Face and the smolagents team for their cooperation and quick turnaround for a fix! Introduction Recently, I have been working on a side project to automate some pentest reconnaissance with AI agents. Just after I started this project, Hugging Face announced the release of smolagents, a lightweight framework for building AI agents that implements the methodology described in the ReAct paper, emphasizing reasoning through iterative decision-making. Interestingly, smolagents enables agents to reason and act by generating…

Being a good CLR host – Modernizing offensive .NET tradecraft

14 min read - The modern red team is defined by its ability to compromise endpoints and take actions to complete objectives. To achieve the former, many teams implement their own custom command-and-control (C2) or use an open-source option. For the latter, there is a constant stream of post-exploitation tooling being released that takes advantage of various features in Windows, Active Directory and third-party applications. The execution mechanism for this tooling has, for the last several years, relied heavily on executing .NET assemblies in…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today