{"id":86807,"date":"2023-01-31T10:52:00","date_gmt":"2023-01-31T10:52:00","guid":{"rendered":"https:\/\/cloudnewshub.com\/?p=86807"},"modified":"2023-01-31T10:52:00","modified_gmt":"2023-01-31T10:52:00","slug":"russian-ddos-hacktivists-seen-targeting-western-hospitals","status":"publish","type":"post","link":"https:\/\/cloudnewshub.com\/?p=86807","title":{"rendered":"Russian DDoS hacktivists seen targeting western hospitals"},"content":{"rendered":"<div><img decoding=\"async\" src=\"http:\/\/cloudnewshub.com\/wp-content\/uploads\/2023\/01\/russian-ddos-hacktivists-seen-targeting-western-hospitals.jpg\" class=\"ff-og-image-inserted\"><\/div>\n<p>Healthcare organisations in countries aligned with the defence of Ukraine have been warned they may be at risk of cyber attack by Russian hacktivists after a series of attacks linked to the <a href=\"https:\/\/www.computerweekly.com\/news\/252527560\/Killnet-DDoS-hacktivists-target-Royal-Family-and-others\">infamous Killnet group<\/a> unfolded over the past few days.<\/p>\n<p>Killnet is a <a href=\"https:\/\/www.techtarget.com\/searchsecurity\/definition\/hacktivism\">hacktivist<\/a> group of politically motivated actors who have aligned themselves with Putin\u2019s war of aggression. It conducts widespread <a href=\"https:\/\/www.techtarget.com\/searchsecurity\/definition\/distributed-denial-of-service-attack\">distributed denial-of-service (DDoS) attacks<\/a> against targets that have attracted Russia\u2019s ire, and has become infamous since the war began <a href=\"https:\/\/www.computerweekly.com\/news\/252522092\/Russia-aligned-hacktivists-behind-Lithuania-DDoS-attack\">for its campaigns<\/a>.<\/p>\n<p>It ramped up its attacks again following the decision last week by the governments of Germany and the US to supply Ukraine with tanks, with Germany\u2019s federal cyber security agency, the BSI, <a href=\"https:\/\/www.darkreading.com\/ics-ot\/german-government-airports-banks-hit-killnet-ddos-attacks\">reporting incidents at multiple government bodies<\/a>.<\/p>\n<p>However, in recent days, it seems to have turned its attention to the healthcare sector, institutions for which network disruption, however temporary, could prove highly dangerous.<\/p>\n<p><a href=\"https:\/\/www.dailymail.co.uk\/health\/article-11692945\/Multiple-hospital-medical-websites-ongoing-cyberattack.html\">On Monday 30 January, it struck multiple hospital \u201csystems\u201d in the US<\/a>, but shortly prior to this, a list of potential targets in the healthcare sector, including multiple UK institutions, surfaced online.<\/p>\n<p>The list was shared via Twitter <a href=\"https:\/\/twitter.com\/Cyberknow20\/status\/1619307679549358080\">by an independent threat researcher<\/a> and subsequently shared with Computer Weekly. It names institutions in cities across the UK, including the <a href=\"https:\/\/www.chelsea-pensioners.co.uk\/\">Royal Hospital Chelsea<\/a>, a retirement and care home for veterans rather than a hospital involved in frontline NHS care. It also specifies healthcare providers in Germany, the Netherlands, Norway and the US.<\/p>\n<p>Deryck Mitchelson, field CISO at <a href=\"https:\/\/www.checkpoint.com\/\">Check Point Software<\/a>, said: \u201cWe know how crippling an attack can be on the NHS. We saw major IT outages last year <a href=\"https:\/\/www.computerweekly.com\/news\/252523700\/NHS-may-take-a-month-to-recover-from-supply-chain-attack\">as a result of a supply chain ransomware attack<\/a>, much of which continues to have an impact today.<\/p>\n<p>\u201cAs more services are delivered online, disruption from DDoS attacks could be even more damaging, potentially affecting emergency care, scheduled appointments and telehealth consultations.&nbsp;<\/p>\n<p>\u201cAlthough this latest campaign from Killnet is designed to cause disruption for maximum exposure rather than data theft, we should not take these threats lightly. It should be a reminder that we need to prioritise robust security measures in critical services to prevent any further successful breaches,\u201d said Mitchelson.<\/p>\n<section class=\"section main-article-chapter\" data-menu-title=\"A warning from cyber history\">\n<h3 class=\"section-title\"><i class=\"icon\" data-icon=\"1\"><\/i>A warning from cyber history<\/h3>\n<p>A <a href=\"https:\/\/www.techtarget.com\/searchsecurity\/definition\/distributed-denial-of-service-attack\">DDoS attack<\/a>, the group\u2019s modus operandi, is a relatively unsophisticated form of cyber attack that floods its targets\u2019 servers, website or network resources with junk messages, connection requests or malformed packets, causing them to slow or crash. They are generally intended more to cause temporary disruption than anything else, and were historically favoured \u2013 and still are \u2013 by hacktivists, <a href=\"https:\/\/www.computerweekly.com\/feature\/The-cyber-security-impact-of-Operation-Russia-by-Anonymous\">including groups like Anonymous<\/a>, for precisely this reason.<\/p>\n<p>Indeed, according to Alexander Heid, chief research and development officer at security rating and risk management specialist <a href=\"https:\/\/securityscorecard.com\/\">SecurityScorecard<\/a>, much of Killnet\u2019s methodology could be said to be inspired by Anonymous.<\/p>\n<p>According to Heid, Killnet has two main attack vectors. Its chief weapon is known as the CC-Attack toolkit, which consists of very few tools and requires limited skills to deploy. It generates three different Layer 7 attack types \u2013 <a href=\"https:\/\/security.stackexchange.com\/questions\/29220\/what-are-http-get-post-flood-attacks\">Get flood, Head flood and Post flood<\/a> \u2013 which are terms related to the specific requests with which the target infrastructure is deluged.<\/p>\n<p>It also makes use of a tool known as the <a href=\"https:\/\/www.computerweekly.com\/photostory\/2240164370\/Five-DDoS-attack-tools-that-you-should-know-about\/4\/LOIC-Low-Orbit-Ion-Cannon\">Low Orbit Ion Cannon<\/a> (LOIC), a venerable hacking tool popularised by Anonymous, which Heid said was frequently discussed on the encrypted Telegram channel where Killnet organises. Again, it is simple and easy to use, appealing to entry-level threat actors. While easily mitigated, rendering its attacks usually ineffective, the LOIC is still capable of generating a lot of noise.<\/p>\n<p> [embedded content] <\/p>\n<\/section>\n<section class=\"section main-article-chapter\" data-menu-title=\"Prominent supporters\">\n<h3 class=\"section-title\"><i class=\"icon\" data-icon=\"1\"><\/i>Prominent supporters<\/h3>\n<p>Although it most likely operates at the explicit behest of the Kremlin, Killnet is also known to have some prominent supporters within Russia, according to recent intelligence <a href=\"https:\/\/blog.radware.com\/security\/threat-intelligence\/2023\/01\/exploring-killnets-social-circles\/\">published by Radware\u2019s head of threat intelligence, Daniel Smith<\/a>.<\/p>\n<p>In his piece, <em>Exploring Killnet\u2019s social circles<\/em>, Smith explores how Killnet is attracting support and, crucially, funding. Some of the backers he found included a Russian rapper, Kazhe Oboyma, who released a track last year called <em>Killnet Flow (Anonymous diss)<\/em>.<\/p>\n<p>Smith also explores how it has also garnered support from a company called HooliganZ, a Moscow-based jewellery business, which has produced a line of Killnet-inspired signet rings and has been donating half the profits from its sales of gang merchandise to the operation. This was first reported by Norwegian newspaper <em><a href=\"https:\/\/www.dagbladet.no\/nyheter\/vi-jaktet-hacker-pengene-dra-til-helvete\/77167375\">Dagbladet<\/a><\/em>.<\/p>\n<p>Meanwhile, the denizens of the Solaris dark web marketplace supposedly clubbed together to have a whip-round for Killnet, <a href=\"https:\/\/hub.elliptic.co\/analysis\/friday-the-13th-on-the-dark-web-150-million-russian-drug-market-solaris-hacked-by-rival-market-kraken\/\">according to another report<\/a>, and donated over $40,000 in bitcoin to the gang.<\/p>\n<\/section>\n","protected":false},"excerpt":{"rendered":"<p>Healthcare organisations in countries aligned with the defence of Ukraine have been warned they may be at risk of cyber attack by Russian hacktivists after a series of attacks linked to the infamous Killnet group unfolded over the past few days. Killnet is a hacktivist group of politically motivated actors who have aligned themselves with [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":86808,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[533],"tags":[],"class_list":["post-86807","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-it"],"_links":{"self":[{"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/posts\/86807","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=86807"}],"version-history":[{"count":0,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/posts\/86807\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/media\/86808"}],"wp:attachment":[{"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=86807"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=86807"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=86807"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}