Some malware incidents will go down in history. The IT industry remembers 2006, for example, as the year of Stuxnet, an infamous worm that drew public attention to the insecurity of supervisory control and data acquisition (SCADA) and programmable logic controller (PLC) systems. I’m quite sure that 2016 will be similarly defined as the year of the distributed denial-of-service (DDoS) attack.

A New Breed of DDoS Attack

DDoS isn’t new. In fact, it has been a common cybercriminal tool for decades. And although this type of attack took down many popular websites in 2016, that’s not why DDoS defined the year in cybersecurity. Rather, 2016 will go down as the year cybercriminals began incorporating the Internet of Things (IoT) into DDoS campaigns on a wide scale.

This new breed of malware is designed to infect millions of IoT-connected devices — not to damage them directly, but to create massive botnets through phishing campaigns, ransomware and other ploys. These botnets facilitated many high-profile attacks that knocked out several prominent websites this past year. The method is not entirely new, but the scale and success of these campaigns are quite impressive.

DDoS Best Practices for 2017

Let’s look at it from the perspective of the owner of a device used to facilitate a DDoS attack. All kinds of connected devices, from cameras, smartphones and sensors to refrigerators, light fixtures and washing machines, are fair game. Many enterprises have proper mobile security controls in place to protect their devices, but regular users, in general, are not as well-prepared. When shopping for a refrigerator, for example, consumers rarely consider what operating system it runs or whether it has a virtual private network (VPN).

It is time for consumers and businesses to change this behavior for 2017. Users should educate themselves about the consequences of DDoS attacks and vendors should be held responsible for building effective security measures into their devices. Increased awareness is the key across the board.

Read the X-Force Research report: Extortion by distributed denial of service attack

More from X-Force

Strela Stealer: Today’s invoice is tomorrow’s phish

12 min read - As of November 2024, IBM X-Force has tracked ongoing Hive0145 campaigns delivering Strela Stealer malware to victims throughout Europe - primarily Spain, Germany and Ukraine. The phishing emails used in these campaigns are real invoice notifications, which have been stolen through previously exfiltrated email credentials. Strela Stealer is designed to extract user credentials stored in Microsoft Outlook and Mozilla Thunderbird. During the past 18 months, the group tested various techniques to enhance its operation's effectiveness. Hive0145 is likely to be…

Hive0147 serving juicy Picanha with a side of Mekotio

17 min read - IBM X-Force tracks multiple threat actors operating within the flourishing Latin American (LATAM) threat landscape. X-Force has observed Hive0147 to be one of the most active threat groups operating in the region, targeting employee inboxes at scale, with a primary focus on phishing and malware distribution. After a 3-month break, Hive0147 returned in July with even larger campaign volumes, and the debut of a new malicious downloader X-Force named "Picanha,” likely under continued development, deploying the Mekotio banking trojan. Hive0147…

FYSA – Critical RCE Flaw in GNU-Linux Systems

2 min read - Summary The first of a series of blog posts has been published detailing a vulnerability in the Common Unix Printing System (CUPS), which purportedly allows attackers to gain remote access to UNIX-based systems. The vulnerability, which affects various UNIX-based operating systems, can be exploited by sending a specially crafted HTTP request to the CUPS service. Threat Topography Threat Type: Remote code execution vulnerability in CUPS service Industries Impacted: UNIX-based systems across various industries, including but not limited to, finance, healthcare,…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today