Anonymous dupes users into joining Megaupload attack
Recruits accomplices by spreading links via Twitter that auto-starts attack tool
Computerworld - The Anonymous hacking group recruited unwitting accomplices in Thursday's attacks against U.S. government sites, a security researcher said today.
The distributed denial-of-service (DDoS) attacks began Thursday just hours after the U.S. Department of Justice announced arrests of four men associated with the popular Megaupload "cyberlocker" site on charges of copyright infringement, money laundering and racketeering.
Federal authorities shuttered Megaupload.com and other sites, and seized assets belonging to the company, including hundreds of servers. Three of the seven men indicted remain at large, but four were arrested in New Zealand by local authorities and face extradition to the U.S.
Almost immediately, Anonymous retaliated with DDoS attacks against Justice's website, and those operated by Universal Music, the Recording Industry Association of America (RIAA), the Motion Picture Association of America (MPAA), and others. Some of those sites were inaccessible during parts of Thursday.
In a message on Twitter and in a blog post, Anonymous claimed Thursday's DDoS attacks were its largest ever, and said that 5,600 people collaborated in the assaults.
Previously, Anonymous had said that its followers were using the Low Orbit Ion Cannon (LOIC) tool, a favorite of the group since its first widespread DDoS attacks in December 2010.
But some of the 5,600 who participated may have done so unwittingly, said Graham Cluley, a senior technology consultant with U.K.-based antivirus vendor Sophos.
Many of those messages said nothing about LOIC or that clicking the link shanghaied the user into the DDoS attack, Cluley said, noting several Twitter messages as examples.
In an email reply to questions today, Cluley said that while the links were launching LOIC against more than one website, "It's clear that justice.gov is getting a lot of attention."
The Department of Justice's website was operating normally early Friday.
Anonymous is still recruiting people to its campaign. A quick search of Twitter using a string published on Gawker.com indicated that the link was being shared Friday morning at the rate of about 10 to 18 times per minute on the micro-blogging site.
On a Sophos blog, Cluley reminded readers that DDoS attacks were illegal, and cautioned users to be wary of clicking links.
"Anonymous might be hoping that participants could argue that they did not knowingly assist in the DDoS attack, and clicked on the link in innocence without realizing what it would do," said Cluley.
Gregg Keizer covers Microsoft, security issues, Apple, Web browsers and general technology breaking news for Computerworld. Follow Gregg on Twitter at @gkeizer, on Google+ or subscribe to Gregg's RSS feed . His e-mail address is firstname.lastname@example.org.
Read more about Cybercrime and Hacking in Computerworld's Cybercrime and Hacking Topic Center.
- 15 Non-Certified IT Skills Growing in Demand
- How 19 Tech Titans Target Healthcare
- Twitter Suffering From Growing Pains (and Facebook Comparisons)
- Agile Comes to Data Integration
- Slideshow: 7 security mistakes people make with their mobile device
- iOS vs. Android: Which is more secure?
- 11 sure signs you've been hacked
- The 12 PCI DSS 3.0 requirements addressed by Peer 1 Hosting This handy quick reference outlines the 12 PCI DSS 3.0 requirements, who needs to be compliant and how Alert Logic solutions address the...
- Defense Throughout the Vulnerability Life Cycle This whitepaper provides insight into how to leverage threat and log management technologies to protect your IT assets throughout their vulnerability life cycle.
- Mobile Policy Checklist Here's what to consider when putting together a mobile policy designed to support a highly productive workforce.
- Securing BYOD Mobile computing is becoming so ubiquitous that people no longer bat an eye seeing someone working two devices simultaneously. Individuals and organizations are...
- Live Webcast On-demand webinar: "Mobility Mayhem: Balancing BYOD with Enterprise Security" Check out this on-demand webinar to hear Sophos senior security expert John Shier deep dive into how BYOD impacts your enterprise security strategy...
- Live Webcast Endpoint Backup & Restore: Protect Everyone, Everywhere Arek Sokol from the bleeding-edge IT team at Genentech/Roche explains how he leverages cross-platform enterprise endpoint backup in the public cloud as part...
- Streamline Software Asset Management, Compose a software Management Symphony Keeping track of your organization's software is easy with effective software management solutions from CDW. View the videos in our software solutions channel
- Druva inSync: Endpoint Data Protection & Governance CLICK HERE to watch this video about protecting corporate data on laptops and mobile devices, sponsored by Druva. All Security White Papers | Webcasts