News

Mirai Botnet Launches Fresh 54-Hour DDoS Attack

A new variant of the Mirai botnet has launched a fresh distributed denial of service (DDoS) attack that lasted over three days. Mirai – run by a type of malware able to infect and take control of IoT devices – was used in October 2016 to conduct one of the biggest DDoS attacks on record, launched against DNS service provider Dyn, taking down majors sites such as Twitter, Reddit, Netflix, and Github in the process. The Mirai source code was made public soon after. This latest Mirai attack, which used a modified version of the code, targeted a US college for around 54 hours straight, according to DDoS protection service Incapsula.

“The attack, which started on February 28 and ran for 54 hours straight, targeted one of our customers, a US college,” reports security expert Dima Bekerman for Incapsula. “The average traffic flow came in at over 30,000 RPS and peaked at around 37,000 RPS—the most we’ve seen out of any Mirai botnet. In total, the attack generated over 2.8 billion requests.”

“Our research showed that the pool of attacking devices included those commonly used by Mirai, including CCTV cameras, DVRs and routers,” Bekerman explains. “While we don’t know for sure, open telnet (23) ports and TR-069 (7547) ports on these devices might indicate that they were exploited by known vulnerabilities.”

“We also noticed that the DDoS bots used in the attack were hiding behind different user-agents than the five hardcoded in the default Mirai version,” he adds. “This–and the size of the attack itself–led us to believe that we might be dealing with a new variant, which was modified to launch more elaborate application layer attacks.”

Incapsula expects further Mirai attacks in the coming months.

Ashley Allen

Disqus Comments Loading...

Recent Posts

Still Wakes the Deep 

LIVE THE HORROR: An immersive disaster story aboard a stunningly realised North Sea oil rig,…

12 mins ago

PHILIPS 275V8LA – 27 Inch QHD Monitor

The Philips VA LED display uses an advanced multi-domain vertical alignment technology that gives you…

13 mins ago

EPOMAKER Ajazz AK820 Pro 75% Gasket-mounted Mechanical Keyboard 

【TFT Screen: The Interactive Interface】This 75% mechanical keyboard comes equipped with a TFT Screen, serving…

14 mins ago

Funko Fusion

FANDOM FUSION Play as your favorite characters and wield their unique weapons and skills. Team…

14 mins ago

Shin Megami Tensei V: Vengeance Standard Edition

The Definitive Version of Shin Megami Tensei V - Fully evolved with stunning visuals for…

15 mins ago

Hand Warmers Rechargeable 2 Pack

【Unique Split Design】5200mAh hand warmers rechargeable together with double-sided heating function, split snap swivel design,…

17 mins ago