ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews

FBI Charges 6, Seizes 48 Domains Linked to DDoS-for

criticalThreat actorimportance 60

Indicators of compromiseAll →

TypeIndicatorContext
domainastrostress.comservices, including RoyalStresser[.]com, SecurityTeam[.]io, Astrostress[.]com, Booter[.]sx, IPStresser[.]com, and TrueSecurityServices[
domainbooter.ninjacom, RageBooter[.]com, downthem[.]org, quantumstress[.]net, Booter[.]ninja, and Vbooter[.]org. An April 2018 exercise led by Europol
domainbooter.sxRoyalStresser[.]com, SecurityTeam[.]io, Astrostress[.]com, Booter[.]sx, IPStresser[.]com, and TrueSecurityServices[.]io. They ha
domaincritical-boot.come 15 domains that advertised computer attack platforms like Critical-boot[.]com, RageBooter[.]com, downthem[.]org, quantumstress[.]net, B
domaindownthem.orgttack platforms like Critical-boot[.]com, RageBooter[.]com, downthem[.]org, quantumstress[.]net, Booter[.]ninja, and Vbooter[.]org.
domainipstresser.comr[.]com, SecurityTeam[.]io, Astrostress[.]com, Booter[.]sx, IPStresser[.]com, and TrueSecurityServices[.]io. They have also been accus
domainquantumstress.netlike Critical-boot[.]com, RageBooter[.]com, downthem[.]org, quantumstress[.]net, Booter[.]ninja, and Vbooter[.]org. An April 2018 exercis
domainragebooter.comertised computer attack platforms like Critical-boot[.]com, RageBooter[.]com, downthem[.]org, quantumstress[.]net, Booter[.]ninja, and
domainroyalstresser.comth running various booter (or stresser) services, including RoyalStresser[.]com, SecurityTeam[.]io, Astrostress[.]com, Booter[.]sx, IPStr
domainsecurityteam.iooter (or stresser) services, including RoyalStresser[.]com, SecurityTeam[.]io, Astrostress[.]com, Booter[.]sx, IPStresser[.]com, and Tr
domaintruesecurityservices.io.]io, Astrostress[.]com, Booter[.]sx, IPStresser[.]com, and TrueSecurityServices[.]io. They have also been accused of violating the computer fr
domainvbooter.orgm, downthem[.]org, quantumstress[.]net, Booter[.]ninja, and Vbooter[.]org. An April 2018 exercise led by Europol likewise saw the d
domainwebstresser.org2018 exercise led by Europol likewise saw the disruption of Webstresser[.]org, which enabled registered users to pay as little as €15 a
Full article446 words · extracted from thehackernews.com · click to collapse

Ravie LakshmananDec 15, 2022Cyber Attack / DDoS-for-Hire

The U.S. Department of Justice (DoJ) on Wednesday announced the seizure of 48 domains that offered services to conduct distributed denial-of-service (DDoS) attacks on behalf of other threat actors, effectively lowering the barrier to entry for malicious activity.

It also charged six suspects – Jeremiah Sam Evans Miller (23), Angel Manuel Colon Jr. (37), Shamar Shattock (19), Cory Anthony Palmer (22), John M. Dobbs (32), and Joshua Laing (32) – for their alleged ownership in the operation.

The websites "allowed paying users to launch powerful distributed denial-of-service, or DDoS, attacks that flood targeted computers with information and prevent them from being able to access the internet," the DoJ said in a press statement.

The six defendants have been charged with running various booter (or stresser) services, including RoyalStresser[.]com, SecurityTeam[.]io, Astrostress[.]com, Booter[.]sx, IPStresser[.]com, and TrueSecurityServices[.]io. They have also been accused of violating the computer fraud and abuse act.

These websites, although claiming to provide testing services to assess the resilience of a paying customer's web infrastructure, are believed to have targeted several victims in the U.S. and elsewhere, such as educational institutions, government agencies, and gaming platforms.

The DoJ noted that millions of individuals were attacked using the DDoS-for-hire platforms. According to court documents, over one million registered users of IPStresser[.]com conducted or attempted to carry out more than 30 million DDoS attacks between 2014 and 2022.

An analysis of communications between the booter site administrators and their customers undertaken by the U.S. Federal Bureau of Investigation (FBI) showed that the services were obtained through a cryptocurrency payment.

"Established booter and stresser services offer a convenient means for malicious actors to conduct DDoS attacks by allowing such actors to pay for an existing network of infected devices, rather than creating their own," the FBI said. "Booter and stresser services may also obscure attribution of DDoS activity."

The development comes four years after the DoJ and FBI took similar steps in December 2018 to seize 15 domains that advertised computer attack platforms like Critical-boot[.]com, RageBooter[.]com, downthem[.]org, quantumstress[.]net, Booter[.]ninja, and Vbooter[.]org.

An April 2018 exercise led by Europol likewise saw the disruption of Webstresser[.]org, which enabled registered users to pay as little as €15 a month to rent out its services for launching DDoS attacks against banks, governments, and the gaming sector.

The domain takedowns are part of an ongoing coordinated law enforcement effort codenamed Operation PowerOFF in collaboration with authorities from the U.K., the Netherlands, Germany, Poland, and Europol aimed at dismantling criminal DDoS-for-hire infrastructures worldwide.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2022/12/fbi-charges-6-seizes-48-domains-linked.html