A global botnet responsible for a record-breaking DDoS attack of 31.4 Tbps has been dismantled thanks to an international operation.
The law enforcement forces of the United States, Germany, and Canada acted against the command and control (C2) infrastructure, virtual servers, and Internet domains used to infect Internet of Things (IoT) devices.
The U.S. Department of Justice stated that the infrastructure was being used by Aisuru, KimWolf, JackSkid, and Mossad, and that it contained more than three million infected devices worldwide.
Now the world has fewer bots and, therefore, it is safer
The Department of Justice explained that the operation was carried out simultaneously, with partners in Canada and Germany focusing on the individuals responsible for operating the bot networks.
“Some of these attacks reached approximately 30 terabits per second, which set a historical record,” added the Department of Justice.
The Aisuru botnet has been used in numerous record-breaking DDoS attacks, including a 15.72 Tbps attack against Microsoft Azure. The KimWolf botnet operated over 1.8 million Android devices, while the Department of Justice stated that the lesser-known JackSkid group has “launched over 90,000 DDoS attack commands.” The Mossad botnet launched over 1,000 attack commands.
DDoS bot networks are usually made up of “smart” devices (the typical IoT) connected to the Internet, such as digital video recorders, webcams, or Wi-Fi routers, but almost any device connected to the Internet can be used as part of a bot network.
The companies responsible for creating these Internet-connected devices often do not release regular software updates, leaving the devices exposed to the risk of being hijacked. For example, the KimWolf botnet was largely composed of smart TVs and multimedia devices.
“Today, the United States has joined its international law enforcement partners in coordinated actions to dismantle the DDoS threats affecting the residents of Alaska and victims around the world,” said federal prosecutor Michael J. Heyman of the District of Alaska.
A name that will sound familiar to you
The name Aisuru will be familiar to anyone closely following large-scale DDoS attack activity. This botnet has been behind a series of recent high-volume attacks, and Cloudflare had already warned that it could unleash traffic avalanches of several terabits.
The interruption itself focused on confiscating domains and backend systems used to coordinate the botnets, effectively cutting off the instructions that tell infected devices where and when to send traffic. As in similar operations, the devices remain infected, but without an operational command infrastructure, they are much less useful to their operators.
The authorities described the operation as a blow against some of the most powerful botnets, but the usual problem persists. Millions of insecure devices remain connected to the Internet, many of them with outdated firmware or default passwords, which provides a ready recruitment pool for the next wave of botnet creators.
For now, at least, some of the loudest sources of junk traffic on the Internet have diminished, but the conditions that allowed them to thrive have not disappeared. We are still in danger.