Article Details

Scrape Timestamp (UTC): 2024-01-15 05:59:12.190

Source: https://thehackernews.com/2024/01/ddos-attacks-on-environmental-services.html

Original Article Text

Click to Toggle View

DDoS Attacks on the Environmental Services Industry Surge by 61,839% in 2023. The environmental services industry witnessed an "unprecedented surge" in HTTP-based distributed denial-of-service (DDoS) attacks, accounting for half of all its HTTP traffic. This marks a 61,839% increase in DDoS attack traffic year-over-year, web infrastructure and security company Cloudflare said in its DDoS threat report for 2023 Q4 published last week. "This surge in cyber attacks coincided with COP 28, which ran from November 30th to December 12th, 2023," security researchers Omer Yoachimik and Jorge Pacheco said, describing it as a "disturbing trend in the cyber threat landscape." The uptick in HTTP attacks targeting environmental services websites is part of a larger trend observed annually over the past few years, specifically during COP 26 and COP 27, as well as other United Nations environment-related resolutions or announcements. "This recurring pattern underscores the growing intersection between environmental issues and cyber security, a nexus that is increasingly becoming a focal point for attackers in the digital age," the researchers said. Despite the environmental services sector becoming a new target in Q4 2023, the cryptocurrency industry continues to be the primary casualty in terms of the volume of HTTP DDoS attack requests. With more than 330 billion HTTP requests targeting it, the attack traffic represents more than 4% of all HTTP DDoS traffic for the quarter. Gaming and gambling and telecommunications emerged as the second and third most attacked industries. On the other end of the spectrum are the U.S. and China, acting as the main sources of HTTP DDoS attack traffic. It's worth noting that the U.S. has been the largest source of HTTP DDoS attacks for five consecutive quarters since Q4 2022. "Together, China and the U.S. account for a little over a quarter of all HTTP DDoS attack traffic in the world," the researchers said. "Brazil, Germany, Indonesia, and Argentina account for the next 25%." The development comes amid a heavy onslaught of DDoS attacks targeting Palestinian banking, information technology (IT), and internet platforms following the onset of the Israel-Hamas War and Israel's counteroffensive codenamed Operation Iron Swords. The percentage of DDoS attack traffic targeting Palestinian websites grew by 1,126% quarter-over-quarter, Cloudflare said, adding DDoS attack traffic targeting Taiwan registered a 3,370% growth amidst the Taiwanese presidential elections and rising tensions with China. Akamai, which also published its own retrospective on DDoS Trends in 2023, said "DDoS attacks became more frequent, longer, highly sophisticated (with multiple vectors), and focused on horizontal targets (attacking multiple IP destinations in the same attack event)." The findings also follow a report from Cloudflare about the increasing threat posed by unmanaged or unsecured API endpoints, which could enable threat actors to exfiltrate potentially sensitive information. "HTTP anomalies — the most frequent threat toward APIs — are common signals of malicious API requests," the company said. "More than half (51.6%) of traffic errors from API origins comprised '429' error codes: 'Too Many Requests.'" Report: Unveiling the Threat of Malicious Browser Extensions Download the Report to learn the Risks of Malicious Extensions and How to Mitigate Them. Firewalls vs. Zero Trust: Minimize Your Attack Surface Learn latest trends in the attack landscape, attacker strategies, and how to implement Zero Trust Security.

Daily Brief Summary

DDOS // Environmental Services Industry Hit by Massive DDoS Attack Surge

A massive 61,839% increase in HTTP DDoS attacks on the environmental services industry was reported in 2023.

The surge in cyberattacks coincided with the COP 28 climate conference, underscoring the nexus between environmental issues and cybersecurity.

Cryptocurrency remains the most targeted sector, while the environmental services sector is becoming a new focus for attackers.

The United States and China are the main sources of HTTP DDoS attack traffic, jointly accounting for over a quarter of global traffic.

In Q4 2023, the gaming and gambling and telecommunications industries were the second and third most attacked sectors, respectively.

The Palestinian banking and IT sectors saw a 1,126% quarter-over-quarter increase in DDoS attacks amidst regional conflict and online operations.

Akamai reports that DDoS attacks are becoming more frequent, sophisticated, and focused, with attackers targeting multiple IP destinations in the same event.

Cloudflare highlights the threat of unmanaged or unsecured API endpoints, as they may allow potential data exfiltration and are commonly targeted by malicious actors.