#ddosattacks
#Anonymous
Dark Storm hacktivist group claims to be behind DDoS attacks causing multiple #X worldwide outages on Monday, leading the company to enable DDoS protections from Cloudflare.
#DarkStormTeam #DDoSAttacks
www.bleepingcomputer.com/news/securit...
X hit by ‘massive cyberattack’ amid Dark Storm’s DDoS claims
The Dark Storm hacktivist group claims to be behind DDoS attacks causing multiple X worldwide outages on Monday, leading the company to enable DDoS protections from Cloudflare.
www.bleepingcomputer.com
March 10, 2025 at 9:43 PM
Israeli Gilat Satellite Company website taken Offline..
#TangoDown
gilat.com
by #MysteriousTeam
#OpIsrael
#Anonymous
#DDoSAttacks
check-host.net/check-report...
gilat.com
March 20, 2025 at 10:14 PM
#Anonymous 40 hacktivist groups united in cyberattacks against India after a terror attack in the Indian state of Jammu
#CyberSecurity #DDoSAttacks #India #Pakistan
cyble.com/blog/india-e...
India Experiences Hacktivist Group Activity Amid Military Tensions
40+ hacktivist groups united in cyberattacks against India after a terror attack in the Indian state of Jammu & Kashmir and India’s retaliatory strikes.
cyble.com
May 14, 2025 at 2:01 AM
#MysteriousTeam Bangladesh hacktivista csoport három napon át támadta Magyarország egyes kormányzati és infrastruktúrához kapcsolódó weboldalait az #OpRevenge kampány részeként. #CyberAttacks #Hackers #DDoSAttacks #Anonymous www.cyberthreat.report/p/oprevenge-...
OpRevenge: A Mysterious Team Magyarországot támadta
A támadások nemcsak technikai fenyegetést jelentettek, hanem politikai üzenetet is közvetítettek, emlékeztetve arra, hogy a hacktivista csoportok folyamatos tényezői maradnak a kibertérnek.
www.cyberthreat.report
March 3, 2025 at 8:45 PM
The FSF Faces Active 'Ongoing and Increasing' DDoS Attacks #Technology #Cybersecurity #DDoSattacks #FSF #CybersecurityThreats
The FSF Faces Active 'Ongoing and Increasing' DDoS Attacks
The Free Software Foundation's services face
puretech.news
July 6, 2025 at 7:45 PM
Dutch Authorities Dismantle Massive Botnet Network Linked to 17 Million Compromised Devices #Botnetattack #CyberSecurity #DDOSAttacks
Dutch Authorities Dismantle Massive Botnet Network Linked to 17 Million Compromised Devices
  Dutch authorities have shut down what is believed to be one of the largest botnet operations ever uncovered, disrupting a cybercrime network that compromised more than 17 million internet-connected devices globally. The affected devices reportedly included computers, smartphones, tablets, security cameras, and other connected hardware that were unknowingly used to facilitate large-scale cyberattacks. According to Dutch investigators, approximately 200 servers located in the Netherlands were seized as part of the operation. These servers allegedly formed the backbone of a sophisticated botnet infrastructure that transformed infected devices into components of a residential proxy network. A botnet is a collection of compromised devices that cybercriminals can remotely control after infecting them with malware. Such networks are commonly used to launch Distributed Denial of Service (DDoS) attacks, distribute phishing campaigns, send spam, commit fraud, and conceal the origins of malicious online activities. Dutch media outlet NL Times reported that cybercriminals targeted devices with weak security protections, converting them into nodes within a residential proxy service. Once infected, the devices were used to redirect internet traffic and allegedly help "launch large-scale cyberattacks" without the owners' knowledge. Authorities confirmed that the network has now been taken offline. The investigation began after a cybersecurity researcher working with the National Cyber Security Centre (NCSC) identified suspicious activity linked to the botnet. The NCSC, which operates under the Netherlands' Ministry of Justice and Security, subsequently partnered with Dutch law enforcement agencies to investigate the case. Their efforts led to the identification and seizure of the servers supporting the operation. While authorities have not disclosed the exact method used to infect more than 17 million devices, cybersecurity experts note that botnets are commonly spread through malicious applications, software vulnerabilities, phishing campaigns, and brute-force attacks. The dismantled network has reportedly been linked by NL Times to Asocks, a residential proxy service that has previously faced scrutiny over alleged connections to botnet-related activities. However, Dutch police have not officially confirmed any association. In 2024, cybersecurity company HUMAN reported that a botnet known as Proxylib had infected nearly 190,000 devices and integrated them into Asocks' proxy network. Researchers connected that operation to a discontinued VPN service and at least 28 Android applications. Residential proxy services route internet traffic through the IP addresses of ordinary users, making online activity appear to originate from legitimate residential locations. While such services can have lawful uses, including bypassing geographic restrictions, experts warn that they are increasingly being exploited by cybercriminals. Following the takedown, the NCSC updated its guidance on residential proxy networks and highlighted the risks they pose. In an updated statement, the agency said the enforcement action "demonstrates" how residential proxies pose "a threat to national and international cybersecurity." The agency further warned that the technique is "being deployed more and more frequently in digital attacks," enabling activities such as DDoS attacks, phishing campaigns, credential theft, brute-force attacks, malware distribution, and SMS pumping. The operation reflects a broader international effort to combat cybercrime infrastructure. In March, authorities from Germany, Canada, and the United States coordinated actions against two major botnets known as "Aisuru" and "Kimwolf," which were allegedly responsible for large-scale DDoS attacks. U.S. authorities reported that those networks had compromised more than three million devices. Earlier this year, Google disrupted the IPIDEA proxy network, whose development kits were reportedly used by the Kimwolf botnet. Separately, the Netherlands' Fiscal Information and Investigation Service (FIOD) seized more than 800 servers connected to an illegal hosting platform allegedly used for botnet and malware-related activities. Cybersecurity experts continue to advise users to strengthen their digital defenses by creating strong passwords, regularly updating software, monitoring network activity, enabling WPA2 or WPA3 Wi-Fi security protocols, and avoiding downloads from unverified sources. Users are also encouraged to carefully review application permissions and terms of service to ensure their devices are not unknowingly enrolled in proxy networks. Traditional antivirus protection remains an important layer of defense against evolving cyber threats.
dlvr.it
June 15, 2026 at 5:33 AM
Cloudflare sounds the alarm: DNS-based DDoS attacks surge by 80% YoY in Q1 2024 across its network. Shockingly, attacks on Sweden skyrocket by 466% following its NATO acceptance. Stay vigilant against escalating cybersecurity threats. #Cloudflare #DDoSAttacks #Cybersecurity #NATO
April 16, 2024 at 11:26 PM
FBI Seizes NightmareStresser DDoS-for-Hire Domains in Global Crackdown #CyberSecurity #DDOSAttacks #FBI
FBI Seizes NightmareStresser DDoS-for-Hire Domains in Global Crackdown
 The U.S. Department of Justice has announced the court-authorized seizure of internet domains linked to “NightmareStresser,” one of the world’s longest-running Distributed Denial of Service (DDoS) for-hire services. The operation, led by the FBI Anchorage Field Office with support from the Royal Canadian Mounted Police, targets so-called “booter” and “stresser” platforms that enable paying customers to launch powerful cyberattacks against individuals, organizations, and critical online infrastructure across Alaska and globally.  According to the seizure warrant affidavit, NightmareStresser was used to carry out hundreds of thousands of actual or attempted DDoS attacks worldwide since 2022. These services lower the barrier to entry for cybercrime by allowing users with minimal technical expertise to disrupt internet connections, knock targeted devices offline (“booting”), and degrade or completely interrupt access to websites and online services. Victims have included schools, government agencies, gaming platforms, and millions of everyday users whose connectivity was affected by these coordinated attacks. The takedown forms part of Operation PowerOFF, an ongoing international law enforcement initiative aimed at dismantling criminal DDoS-for-hire infrastructures and holding both administrators and users accountable. Over the past eight years, federal prosecutors and investigators in Anchorage and Los Angeles have charged twelve defendants involved in facilitating DDoS-for-hire services and seized more than 100 associated domains. This latest action expands on those efforts by targeting all known booter sites, shutting down as many as possible, and coupling enforcement with a public education campaign on the harms caused by illegal DDoS activity.  Assistant U.S. Attorneys Adam Alexander and Ainsley McNerney are prosecuting the case in the District of Alaska. The Justice Department emphasizes that booter and stresser services not only harm direct targets but also undermine broader internet reliability and safety. As digital dependence grows, such crackdowns signal a sustained push to disrupt the ecosystem enabling low-cost, high-impact cyberattacks—and to deter would-be offenders by removing the domains and infrastructure these services rely on to operate.
dlvr.it
September 18, 2026 at 2:36 PM
Researchers have uncovered two Mirai-based botnets harnessing Internet of Things (IoT) devices to DDoS target organizations around the world.

Read more: www.helpnetsecurity.com/2025/01/22/m...

#cybersecurity #cybersecuritynews #DDoSAttacks
@cloudflare.social
Mirai botnet behind the largest DDoS attack to date - Help Net Security
Researchers have uncovered two Mirai-based botnets harnessing IoT devices to DDoS target organizations around the world.
www.helpnetsecurity.com
January 22, 2025 at 3:00 PM
Evooo1Bot Hijacks Linux Routers for Proxying, Credential Theft and DDoS Attacks #Atlassian #DDOSAttacks #Evooo1Bot
Evooo1Bot Hijacks Linux Routers for Proxying, Credential Theft and DDoS Attacks
A new Linux botnet named Evooo1Bot is turning internet-facing routers and other gateway devices into SOCKS5 traffic relay nodes, giving attackers a way to route malicious connections through compromised systems while retaining the ability to steal credentials, brute-force SSH accounts, exploit vulnerable devices and launch DDoS attacks. FortiGuard Labs said it has been tracking the Mirai-based malware since at least July 2026, with activity observed against devices from Alcatel, NETGEAR, Tenda, Mitsubishi Electric, Telesquare and D-Link across multiple regions. Rather than relying on a single attack function, Evooo1Bot combines several capabilities within a modular Linux malware framework. The malware retains the DDoS engine from the publicly leaked Mirai source code, but expands on the older botnet's approach with encrypted command-and-control communications, an SSH brute-force scanner, a SOCKS5 relay, a credential sniffer and an exploitation module targeting known vulnerabilities. Mirai's original success was closely tied to internet-connected devices such as routers, cameras and DVRs, many of which were exposed with weak or default credentials. Fortinet previously documented how Mirai could scan for vulnerable systems, brute-force credentials and recruit them into a remotely controlled botnet. Evooo1Bot takes that model further by adding more ways to use a compromised device after the initial infection. Its exploit arsenal covers a wide range of internet-facing technologies. Newer builds have been found with modules targeting Hikvision cameras, Atlassian Confluence, Zyxel firewalls, TP-Link routers, D-Link NAS devices, WSO2 products, Kubernetes ingress-nginx and vulnerable PHP-CGI installations. FortiGuard noted, however, that some of the embedded exploits are incorrectly implemented and fail to compromise their intended targets. When exploitation succeeds, the malware downloads a build suited to the victim's CPU architecture. FortiGuard identified 12 available builds, allowing the operators to target different Linux-based hardware rather than relying on a single binary. The malware then attempts to make the compromise harder to trace. It clears Bash history and establishes persistence through mechanisms including systemd, SysV init, shell profiles and "rc.local". A cron job also attempts to download the payload again every five minutes, providing another way to restore the malware if it is removed. Evooo1Bot also checks its surroundings before fully activating. It searches for debuggers, security software, sandboxes, virtual machines, containers and honeypots, indicating that the operators are attempting to distinguish ordinary victims from environments where the malware could be analyzed. Its encrypted C2 communications operate over port 443, while an interactive shell gives operators direct control over infected systems. The malware also supports file uploads and downloads and uses a 28-command interface for remote operations. The SOCKS5 component is where Evooo1Bot moves beyond the conventional DDoS-botnet model. A SOCKS5 proxy can relay network connections through another system. In this case, the infected router becomes the intermediary, allowing attackers to send traffic through the victim's connection. Evooo1Bot supports both direct-listening and reverse-relay modes, which could help operators conceal the origin of malicious traffic, bypass geographic restrictions or reach networks accessible through compromised devices. Multiple proxy sessions can operate independently, raising another possibility if the botnet expands: monetizing compromised residential connections as proxy infrastructure. The malware also monitors "/proc/net/tcp" for network activity and attempts to capture HTTP Basic Authentication and Cookie headers. Alongside its shell and file-transfer functions, this gives operators additional opportunities to obtain information from systems positioned behind the compromised gateway. SSH provides another route into vulnerable systems. Evooo1Bot uses 150 username and password combinations aimed at enterprise-oriented accounts and performs checks after successful authentication to identify possible honeypots. DDoS remains part of the malware's toolkit, with 16 flood methods inherited from Mirai, including UDP, DNS, SYN, ACK, GRE, fragmented TCP and customizable HTTP floods. The result is a botnet in which a compromised router can serve several purposes at once: it can participate in DDoS attacks, relay traffic, collect authentication material, provide remote shell access and help operators compromise additional vulnerable systems. For users and organizations, securing these devices starts with applying firmware and security updates, replacing default administrator credentials and disabling unnecessary remote-access interfaces. Unsupported equipment that no longer receives security updates should also be replaced. Network defenders should additionally watch for unexpected outbound connections, unusual proxy traffic and unauthorized changes to cron jobs, startup services or shell profiles. Evooo1Bot shows why internet-facing routers and gateways cannot be treated simply as passive networking equipment. Once compromised, they can become operational infrastructure for an attacker, extending the intrusion far beyond the device itself.
dlvr.it
August 16, 2026 at 4:04 PM
Geopolitical Conflicts and the World Cup Drive Surge in DDoS Attacks on Media Outlets

🤖 IA: It's clickbait ⚠️
👥 Users: It's clickbait ⚠️

#ddosattacks #geopoliticalconflict #mediasecurity

View full AI summary:
Geopolitical Conflicts and the World Cup Drive Surge in DDoS Attacks on Media Outlets
A recent report highlights a significant increase in distributed denial-of-service (DDoS) attacks targeting media publishers, driven by geopolitical tensions and global events. The article cites data from Cloudflare, which notes a 519% surge in such attacks, attributed to conflicts in Ukraine and Iran, as well as the World Cup. These attacks, often orchestrated by state-sponsored actors or hacktivist groups, aim to disrupt media operations, spread disinformation, and undermine public trust. The article explains how the scale of these attacks has grown due to the availability of botnet networks and the strategic use of social media to amplify their impact. Experts warn that media organizations must invest in robust cybersecurity measures, including traffic filtering, real-time monitoring, and collaboration with cybersecurity firms. The piece also discusses the broader implications of these attacks on democratic discourse, emphasizing the need for international cooperation to address cyber threats. While the article acknowledges the challenges faced by publishers, it also highlights efforts to mitigate risks through technological innovation and policy reforms.
en.killbait.com
August 11, 2026 at 8:22 PM
Buy Ddos Traffic News: DDoS attacks have become a real and persistent threat in today’s digital landscape. But what exactly is DDoS? DDoS stands for Distributed Denial of Service, and it refers to a type of cyber attack… #DDosAttacks #CyberSecurity #DigitalThreats #OnlineSafety #NetworkSecurity
Buy Ddos Traffic News
DDoS attacks have become a real and persistent threat in today’s digital landscape. But what exactly is DDoS? DDoS stands for Distributed Denial of Service, and it refers to a type of cyber attack where multiple compromised computers are used to flood a…
froggyads.com
February 18, 2025 at 6:19 PM
DanaBot Malware Network Disrupted After Researchers Discover Key Flaw #cryptocurrency #DanaBot #DDOSAttacks
DanaBot Malware Network Disrupted After Researchers Discover Key Flaw
  In a major breakthrough, cybersecurity experts uncovered a major weakness in the DanaBot malware system that ultimately led to the disruption of its operations and criminal charges against its operators. DanaBot, which has been active since 2018, is known for being sold as a service to carry out cybercrimes like banking fraud, stealing personal information, carrying out remote attacks, and launching distributed denial-of-service (DDoS) attacks. The malware remained a persistent threat until recent enforcement actions successfully targeted its infrastructure. Discovery of the DanaBot Weakness Researchers from Zscaler’s ThreatLabz team identified a serious flaw in DanaBot’s system in a version released in June 2022. This flaw, later called "DanaBleed," exposed the internal workings of the malware to security professionals without the attackers realizing it. The issue stemmed from changes made to DanaBot’s communication system, known as the command and control (C2) protocol. The updated system failed to properly handle random data in its responses, accidentally revealing leftover information stored in the malware’s memory. Because of this memory leak, security experts were able to repeatedly collect sensitive fragments from DanaBot’s servers over time. This flaw is similar to the infamous HeartBleed vulnerability that affected OpenSSL in 2014 and caused serious security concerns worldwide. What the Flaw Exposed Through careful analysis, researchers were able to access highly valuable information, including: • Details about the malware operators, such as usernames and IP addresses • Locations of DanaBot’s servers and websites • Stolen victim data, including login credentials • Records of malware updates and internal changes • Private cryptographic keys used for security • Internal system logs and SQL database activity • Parts of the malware’s management dashboard For more than three years, DanaBot continued to operate with this hidden security hole, giving investigators a rare opportunity to quietly monitor the criminals and gather detailed evidence. Law Enforcement Action After collecting enough proof, international law enforcement teams launched a coordinated operation called "Operation Endgame" to shut down DanaBot’s network. This effort led to the takedown of key servers, the seizure of over 650 domains connected to the malware, and the recovery of nearly $4 million in cryptocurrency. While the core group of attackers, mainly located in Russia, has been formally charged, no arrests have been reported so far. However, the removal of DanaBot’s infrastructure has significantly reduced the threat. Final Thoughts This case highlights the importance of careful cybersecurity monitoring and how even well-established criminal groups can be exposed by overlooked technical mistakes. Staying updated on the latest security research is essential, as malware groups often release new versions and fixes that may change the threat landscape quickly.
dlvr.it
June 17, 2025 at 5:13 PM
Russian Hacktivists Disrupt Dutch Institutions with DDoS Attacks #CyberAttacks #DDoS #DDOSAttacks
Russian Hacktivists Disrupt Dutch Institutions with DDoS Attacks
 Several Dutch public and private organizations have experienced significant service outages this week following a wave of distributed denial-of-service (DDoS) attacks linked to pro-Russian hacktivists. The Netherlands’ National Cyber Security Center (NCSC), part of the Ministry of Justice, confirmed that the attacks affected multiple sectors and regions across the country.   The NCSC disclosed that both government and private entities were targeted in what it described as large-scale cyber disruptions. While the full scope is still being assessed, municipalities and provinces including Groningen, Noord-Holland, Drenthe, Overijssel, Zeeland, Noord-Brabant, and cities like Nijmegen, Apeldoorn, Breda, and Tilburg reported that public portals were intermittently inaccessible.  A pro-Russian threat group calling itself NoName057(16) has claimed responsibility for the cyberattacks through its Telegram channel. Though the NCSC did not confirm the motive, the group posted that the attacks were a response to the Netherlands’ recent €6 billion military aid commitment to Ukraine, as well as future support amounting to €3.5 billion expected in 2026. Despite the widespread disruptions, authorities have stated that no internal systems or sensitive data were compromised.  The issue appears confined to access-related outages caused by overwhelming traffic directed at the affected servers — a hallmark of DDoS tactics. NoName057(16) has been a known actor in the European cybersecurity landscape since early 2022. It has targeted various Western governments and institutions, often in retaliation for political or military actions perceived as anti-Russian. The group also operates DDoSIA, a decentralized platform where users can participate in attacks in exchange for cryptocurrency payments.  This model has enabled them to recruit thousands of volunteers and sustain persistent campaigns against European targets. While law enforcement in Spain arrested three alleged DDoSIA participants last year and confiscated their devices, key figures behind the platform remain unidentified and at large. The lack of major indictments has allowed the group to continue its operations relatively unimpeded.  The NCSC has urged organizations to remain vigilant and maintain strong cybersecurity protocols to withstand potential follow-up attacks. With geopolitical tensions remaining high, experts warn that such politically motivated cyber operations are likely to increase in frequency and sophistication.  As of now, restoration efforts are ongoing, and the government continues to monitor the digital landscape for further signs of coordinated threats.
dlvr.it
May 9, 2025 at 3:55 PM
310: CI You Later, Manual Testing “Not today, Satan” - Cloudflare blocked a 7.3 Tbps DDoS attack. 37.4 TB in 45 seconds? That’s not a cyberattack; that’s the internet trying to yeet itself into oblivion. Want to hear about it? Episode 310 of The Cloud Pod, out now! #thecloudpod #ddosattacks […]
Original post on tcp.fm
tcp.fm
July 4, 2025 at 9:44 PM
Pro-Russian hacktivist group NoName057(16) has launched 1,500+ DDoS attacks since 2022 targeting global governments and infrastructure. Despite Operation Eastwood arrests, attacks resumed with AI and Tor plans. #NoName05716 #Russia #DDoSAttacks
NoName057(16) Exclusive Interview: The Pro-Russian Hacker Group Behind 1,500+ DDoS Attacks Speaks Out
Since March 2022 the pro‑Russian hacktivist group NoName057(16) has coordinated thousands of volunteers via its custom DDoS platform DDoSia to carry out over 1,500 DDoS attacks against governments, financial institutions, transportation networks, and critical infrastructure worldwide. Despite a multinational law enforcement disruption in Operation Eastwood (July 2025) that led to arrests...
www.hendryadrian.com
March 25, 2026 at 2:40 PM
🚨 Frustrated by ChatGPT outages? 😠 DDoS attacks are to blame! 💻 But what are they, and how can you keep your business safe? 🛡️ Our latest blog post reveals the truth and shares 15 tips to fortify your digital defenses. 🏰 #CyberSecurity #DDoSAttacks #ChatGPT
wp.me/peSvjo-v5
Frustrated by ChatGPT Outages? DDoS Attacks Explained
Discover the shocking truth behind DDoS attacks causing ChatGPT outages. Learn how to protect your business from these frustrating attacks.
wp.me
April 16, 2024 at 4:49 AM