Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Vulnerabilities / Threats

12/5/2017
01:45 PM
Connect Directly
Twitter
LinkedIn
RSS
E-Mail
50%
50%

Bitcoin Sites Become Hot Targets for DDoS Attacks

The Bitcoin industry is now one of the top 10 most-targeted industries for DDoS campaigns. Price manipulation could be one goal, Imperva says.

The massive surge in Bitcoin prices in recent months suddenly has made online cryptocurrency exchanges and services popular targets for distributed denial-of-service (DDoS) attacks.

This Monday, Bitfinex, one of the largest US dollar Bitcoin exchanges in the world, said it was the victim of a DDoS attack that knocked it offline for a short period of time. The company reported a similar incident just a few days earlier, and at least one other incident in June affected withdrawals and deposits of the then newly launched IOTA cryptocurrency.

In a report released Tuesday, security vendor Imperva said that nearly three in four of the 27 enterprise Bitcoin sites that are using the company's services were hit with DDoS attacks in the last quarter. From being hardly a blip on the radar of most cybercriminals earlier this year, the Bitcoin industry emerged as one of the top 10 most-targeted industries for denial-of-service campaigns in the third quarter of 2017. 

Online gambling and gaming sites continued to be the most heavily targeted, as usual, and accounted for 34.5% and 14.4% of all DDoS attacks last quarter, respectively. Internet service providers, financial companies, the retail sector, and software vendors also were seriously affected by DDoS attacks, in keeping with previous trends, Imperva's report said. But with 3.6% of all DDoS attacks aimed against it last quarter, the Bitcoin sector suddenly found itself thrust into the list of most-attacked industries for the first time, says Igal Zeifman, director and security evangelist at Imperva.

The attacks are a textbook example of cybercrooks following the money, Zeifman says. With Bitcoin trading at near-record highs, attackers may be attempting to shake down sites dealing with the cryptocurrency by threatening to disrupt services or to take them offline totally via DDoS attacks. It is also conceivable that cybercriminals and their hired guns are trying to manipulate Bitcoin prices through such disruption, Ziefman says.

In recent months, it has taken little to cause big fluctuations in Bitcoin pricing. In September, for instance, Bitcoin prices fell by as much as 24% in a little over a week after JP Morgan chief executive Jamie Dimon called Bitcoin a fraud.

Financially motivated entities have also taken advantage of the unregulated nature of the Bitcoin ecosystem to drive sudden changes in Bitcoin prices by showing intent to buy or sell very large volumes and then canceling the transaction before it is executed. Given the relative ease with which some have manipulated Bitcoin prices, it is possible that cybercriminals are trying to trigger and profit from price fluctuations via outages at big exchanges.

"I believe that the reported sharp increase in DDoS attacks on Bitcoin and cryptocurrency sites during the last quarter is an attempt at manipulation of cryptocurrency prices, rather than an attempt at extortion," says Martin McKeay, global security advocate at Akamai, which released its own DDoS quarterly update last week.

"There is much more money to be made in casting the stability of a cryptocurrency site and affecting a change in cryptocurrency prices than there is to be made in a simple extortion scam," he says. If attackers can predict or control the timing of a surge or a drop in prices, they can make significantly more money than they could get from a single company in a ransom, he says.

Another option is that the attacks could be directed by a competing type of cryptocurrency network or by a competing system, McKeay says. "When users find themselves unable to quickly and reliably access their currency, it is not unusual for them to switch to a more reliable service." Small organizations in other sectors have shown a tendency to fund DDoS attacks on a competitor to slow them down, he says. "We may be seeing a similar tactic playing out with cryptocurrencies."

Ilia Kolochenko, CEO of High-Tech Bridge, says that while a single DDoS attack is unlikely to produce tangible results for cybercriminals, a well-planned one could create damage. For example, if a major proponent or Bitcoin trade platform were suddenly to go offline accompanied with fake news about the government seizing its servers, a large-scale panic could ensue and undermine Bitcoin exchange rates, Kolochenko says.

But such attacks would require rigorous preparation and significant resources for execution. "If a dozen Bitcoin exchanges simultaneously go offline at a time of a major negative announcement concerning Bitcoin or cryptocurrency in general, and sellers [aren't] able to sell their Bitcoins, a huge depreciation [could happen]," Kolochenko says.

Related Content:

 

Jai Vijayan is a seasoned technology reporter with over 20 years of experience in IT trade journalism. He was most recently a Senior Editor at Computerworld, where he covered information security and data privacy issues for the publication. Over the course of his 20-year ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Why Cyber-Risk Is a C-Suite Issue
Marc Wilczek, Digital Strategist & CIO Advisor,  11/12/2019
Unreasonable Security Best Practices vs. Good Risk Management
Jack Freund, Director, Risk Science at RiskLens,  11/13/2019
Breaches Are Inevitable, So Embrace the Chaos
Ariel Zeitlin, Chief Technology Officer & Co-Founder, Guardicore,  11/13/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
Navigating the Deluge of Security Data
In this Tech Digest, Dark Reading shares the experiences of some top security practitioners as they navigate volumes of security data. We examine some examples of how enterprises can cull this data to find the clues they need.
Flash Poll
Rethinking Enterprise Data Defense
Rethinking Enterprise Data Defense
Frustrated with recurring intrusions and breaches, cybersecurity professionals are questioning some of the industrys conventional wisdom. Heres a look at what theyre thinking about.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-14345
PUBLISHED: 2019-11-15
TemaTres 3.0 allows remote unprivileged users to create an administrator account
CVE-2019-14343
PUBLISHED: 2019-11-15
TemaTres 3.0 has stored XSS via the value parameter to the vocab/admin.php?vocabulario_id=list URI.
CVE-2019-14869
PUBLISHED: 2019-11-15
A flaw was found in all versions of ghostscript 9.x before 9.28, where the `.charkeys` procedure, where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. An attacker could abuse this flaw by creating a specially crafted PostScript file that could esc...
CVE-2019-18987
PUBLISHED: 2019-11-15
An issue was discovered in the AbuseFilter extension through 1.34 for MediaWiki. Once a specific abuse filter has (accidentally or otherwise) been made public, its previous versions can be exposed, thus potentially disclosing private or sensitive information within the filter's definition.
CVE-2019-18986
PUBLISHED: 2019-11-15
Pimcore before 6.2.2 allow attackers to brute-force (guess) valid usernames by using the 'forgot password' functionality as it returns distinct messages for invalid password and non-existing users.