Expert fingers DDoS toolkit used in bank cyberattacks

01.10.2012

The vendor, which declined to name the banks whose sites it tracked, said the attackers likely spent months probing the sites for the components most susceptible to a DDoS assault. They also were knowledgeable in the technology used to mitigate such attacks.

"From a DDoS perspective, they are on the level of a Stuxnet type of attack," said Scott Hammack, chief executive of Prolexic.

Stuxnet was the cyberespionage malware discovered in 2010 that damaged Iranian nuclear facilities. The New York Times that the U.S. and Israeli governments created Stuxnet.

Like the sophisticated Stuxnet, the DDoS attacks likely stem form a "well-funded" organization, Hammack said. Prolexic found evidence that several large networks of compromised computers, called botnets, were also used.

U.S. Sen. Joe Lieberman, chairman of the Senate Homeland Security committee, alleged recently that Iran was behind the attacks. Lieberman the Iranian Quds Force, a secretive military unit that has been accused of terrorist activity.