Anonymous dupes users into joining Megaupload attack
Recruits accomplices by spreading links via Twitter that auto-starts attack tool
Computerworld - The Anonymous hacking group recruited unwitting accomplices in Thursday's attacks against U.S. government sites, a security researcher said today.
The distributed denial-of-service (DDoS) attacks began Thursday just hours after the U.S. Department of Justice announced arrests of four men associated with the popular Megaupload "cyberlocker" site on charges of copyright infringement, money laundering and racketeering.
Federal authorities shuttered Megaupload.com and other sites, and seized assets belonging to the company, including hundreds of servers. Three of the seven men indicted remain at large, but four were arrested in New Zealand by local authorities and face extradition to the U.S.
Almost immediately, Anonymous retaliated with DDoS attacks against Justice's website, and those operated by Universal Music, the Recording Industry Association of America (RIAA), the Motion Picture Association of America (MPAA), and others. Some of those sites were inaccessible during parts of Thursday.
In a message on Twitter and in a blog post, Anonymous claimed Thursday's DDoS attacks were its largest ever, and said that 5,600 people collaborated in the assaults.
Previously, Anonymous had said that its followers were using the Low Orbit Ion Cannon (LOIC) tool, a favorite of the group since its first widespread DDoS attacks in December 2010.
But some of the 5,600 who participated may have done so unwittingly, said Graham Cluley, a senior technology consultant with U.K.-based antivirus vendor Sophos.
According to Cluley, members of Anonymous distributed links via Twitter and elsewhere that when clicked automatically launched a Web version of LOIC. The links pointed to a page on PasteHTML.com, a free HTML code-hosting site, which in turn executed some JavaScript to fire LOIC at Anonymous-designated targets.
Many of those messages said nothing about LOIC or that clicking the link shanghaied the user into the DDoS attack, Cluley said, noting several Twitter messages as examples.
In an email reply to questions today, Cluley said that while the links were launching LOIC against more than one website, "It's clear that justice.gov is getting a lot of attention."
The Department of Justice's website was operating normally early Friday.
Anonymous is still recruiting people to its campaign. A quick search of Twitter using a string published on Gawker.com indicated that the link was being shared Friday morning at the rate of about 10 to 18 times per minute on the micro-blogging site.
On a Sophos blog, Cluley reminded readers that DDoS attacks were illegal, and cautioned users to be wary of clicking links.
"Anonymous might be hoping that participants could argue that they did not knowingly assist in the DDoS attack, and clicked on the link in innocence without realizing what it would do," said Cluley.
Gregg Keizer covers Microsoft, security issues, Apple, Web browsers and general technology breaking news for Computerworld. Follow Gregg on Twitter at
@gkeizer, on Google+ or subscribe to Gregg's RSS feed
. His e-mail address is gkeizer@computerworld.com.
See more articles by Gregg Keizer.
Read more about Cybercrime and Hacking in Computerworld's Cybercrime and Hacking Topic Center.


- Excel 2010 Cheat Sheet
- Register for this Computerworld Insider Cheat Sheet and gain access to hundreds of premium content articles, guides, product reviews and more.
- Practice Management: Double Billing Rate and Improve Patient Services
- Would you like to double your billing rate and achieve faster payment for services?
Download this customer success story to see how One Health... - Mission Critical Data Explosion and Customer Case Study
- Would you like to double your tier 1 storage capacity while simultaneously reducing your storage footprint?
Download this customer success story to see how... - Protecting Against Database Attacks and Insider Threats: Top 5 Scenarios
- Read this new eBook to learn the top five scenarios and essential best practices for preventing database attacks and insider threats.
- Database Activity Monitoring Is Evolving
- Read the analyst report and learn how you can leverage the core capabilities of a DAP solution for better database security.
- Establishing a Strategy for Database Security is No Longer Optional
- The options for securing increasingly valuable databases are very broad and deep, and can be confusing. This research provides an overview of three... All Cybercrime and Hacking White Papers
- Distributed Database Security with Real-time Monitoring
- View this demo and learn how IBM InfoSphere Guardium database activity monitoring can help protect your sensitive data in distributed DBMS environments with...
- InfoSphere Warehouse Packs Demo
- These flash modules make warehousing more tangible and relevant to business users through detailed explanations of the InfoSphere Warehouse Packs.
- Delivery Management -- Extending Lifecycle Management
- Date: Wednesday, June 20, 2012, 1:00 PM EDT
Siloed organizations continue doing the wrong things and doing things wrong, leading to increased costs,... - Leverage automation today to reduce IT complexity
- Date: Tuesday, June 5, 2012, 2:00 PM EDT
Whether your B2B complexity is caused by multiple technologies due to M&A, business or application specific... - Redefine Expectations in the Data Center
- Need to do more with less? Watch this video to learn how HP ProLiant Gen8 servers can help your business deploy servers three... All Cybercrime and Hacking Webcasts