We use cookies to provide you with a better experience. If you continue to use this site, we'll assume you're happy with this. Alternatively, click here to find out how to manage these cookies

hide cookie message
80,259 News Articles

Massive botnet targets US govt websites

Powerful cyberattack also attacks South Korea

The US government has been the victim of a cyber attack of unusual veracity.

A botnet comprised of about 50,000 infected computers has been waging a war against US government websites and causing headaches for businesses in the US and South Korea.

The attack started Saturday, and security experts have credited it with knocking the US Federal Trade Commission's (FTC's) website offline for parts of Monday and Tuesday. Several other government websites have also been targeted, including the US Department of Transportation (DOT).

PC security news and advice

"The DOT has been experiencing network incidents since this past weekend. We are working with the US Computer Emergency Readiness Team [US-CERT] at this time," a DOT spokeswoman said Tuesday.

A spokeswoman for the US Department of the Treasury confirmed that the Treasury's website had been hit with a denial-of-service attack. "We're working with our service provider to mitigate the impact," she said.

A spokeswoman for the FTC could not say what caused the outage at that agency's website, and the US-CERT did not return calls seeking comment.

Other targets have included banking websites in Korea, US Bancorp, the US Secret Service, the US Department of Homeland Security, the US Department of State, the White House, the US Department of Defense, the New York Stock Exchange, the Nasdaq and the Washington Post, according to security researchers studying the incident.

The attack, while powerful, is not particularly sophisticated and appears to be more of a nuisance than a threat to security. It uses a variety of well-known distributed denial of service (DDoS) attacks that try to overwhelm websites with useless requests and make them unavailable for legitimate users, security experts say. Most of the targeted sites appeared to be working normally on Tuesday.

Such DDoS attacks are relatively common, but a few things make this week's incident unusual. The botnet code behind the attack does not use typical antivirus evasion techniques and does not appear to have been written by a professional malware writer, according to Joe Stewart, a researcher with SecureWorks who has looked at the code.

On Saturday and Sunday the attack was consuming 20 to 40 gigabytes of bandwidth per second, about 10 times the rate of a typical DDoS attack, one security expert said after being briefed by the US-CERT on Tuesday. "It's the biggest I've seen," said the expert, who asked not to be identified because he was not authorised to discuss the matter. By Tuesday it was averaging about 1.2 gibabytes per second, he said.

Security experts estimate the size of the botnet at somewhere between 30,000 and 60,000 computers.

It is also unusual to see relatively low-profile government websites being hit. "Who goes around targeting a site like the FAA or the US Treasury? It's not something that most people would think to attack," Stewart said.

The FTC in the past has brought actions against spammers and internet fraudsters. Last month it shut down an internet service provider called Pricewert, which had been associated with botnets, spam and child pornography.

No one knows who is behind the attack, although Stewart said it could have been launched by a single person. "It just seems to me that somebody is mad for some reason at capitalist governments," he said. Security experts say most of the infected machines are located in South Korea, but that doesn't mean the attack originated there.

The fact that the DDoS attack took down government computers is an embarrassment to the US, which is working to strengthen the country's cyber-security defences under President Barack Obama.

"These are very basic attacks and stuff we've seen for a very long time. The scale of these isn't very huge either," said one security expert, who spoke on condition of anonymity because he wasn't authorised to discuss the matter publicly. "It's embarrassing that these sites have been hit for four or five days and they're still being affected. Think of the money that eBay and Amazon would lose in four to five days of this."

(Grant Gross in Washington and Nancy Gohring in Seattle contributed to this story.)


IDG UK Sites

Best Christmas 2014 UK tech deals, Boxing Day 2014 UK tech deals & January sales 2015 UK tech...

IDG UK Sites

Chromebooks: ready for the prime time (but not for everybody)

IDG UK Sites

Hands-on with Sony's latest smartglasses

IDG UK Sites

The 13 most inspirational Tim Cook quotes