The Times Australia
Small Business News

.
The Times Real Estate

.

Pro-Russian Hacker Group Targeting Sites in Ukraine and Supporting Countries with DDoS Attacks


The group performs politically motivated attacks on websites belonging to governments, utilities, telecommunications, and transportation companies

Avast, a global leader in digital security and privacy, has been tracking the activity of a pro-Russian hacker group called NoName057(16) since June 1, 2022. The group reacts to evolving political situations, targeting pro-Ukrainian companies and institutions in Ukraine and neighbouring countries, like Estonia, Lithuania, Norway, and Poland. According to Avast’s research, the group has a 40% success rate, and companies with well-protected infrastructure can withstand attack attempts. The research also found that 20% of the successes claimed by the group may not be their doing. 

NoName057(16)’s targets

NoName057(16) exclusively carry out DDoS attacks. At the beginning of June, the group targeted Ukrainian news servers. Then, they focused on websites within Ukraine belonging to cities, local governments, utility companies, armament manufacturers, transportation companies, and postal offices. 

By mid-June, the attacks became more politically motivated. Baltic states (Lithuania, Latvia, and Estonia) are significantly targeted. Following a ban on the transit of goods subject to EU sanctions through their territory to Kaliningrad, the group targeted Lithuanian transportation companies, local railway, and bus transportation companies. On July 1, 2022, the transportation of goods destined to reach miners employed by the Russian government-owned coal mining company, Arktikugol, was stopped by Norwegian authorities. In response, the group retaliated by attacking Norwegian transportation companies (Kystverket, Helitrans, Boreal), the Norwegian postal service (Posten), and Norwegian financial institutions (Sbanken, Gjensidige). In early August, after Finland announced their intention of joining NATO, NoName057(16) went after Finnish government institutions, like the Parliament of Finland (Eduskunta), State Council, and Finish police. 

40% success rate

NoName057(16) actively boast about their successful DDoS attacks to their more than 14K followers on Telegram. Their channel was created on March 11, 2022. The group only reports successful DDoS attacks.  

“Although the group’s reported number of successful attacks seems large, statistical information indicates the contrary,” explains Martin Chlumecky, malware researcher at Avast.

“The group’s success rate is 40%. We compared the list of targets the C&C server sends to the Bobik bots to what the group posts to their Telegram channel. Websites hosted on well-secured servers can withstand the attacks. Around 20% of the attacks the group claims to be responsible for did not match the targets listed in their configuration files.” 

Bobik bots act as soldiers

The group controls unprotected PCs around the world infected with malware called Bobik, which act as bots. Bobik first emerged in 2020 and was used as a remote access tool in the past. The malware is distributed by a dropper called Redline Stealer, which botnet-as-a-service cybercriminals pay for to spread their malware of choice. Avast has protected a few hundred PCs from Bobik. Avast researcher Martin Chlumecky, however, estimates there are several thousand Bobik bots in the wild, considering the effectiveness and frequency of attacks. 

The group sends commands to its bots via a C&C server located in Romania. Formerly, the group had two additional servers in Romania and Russia, but these are no longer active. The bots receive lists of targets to DDoS, in the form of XML configuration files, which are updated three times a day. They attempt to overload login pages, password recovery sites, and site searches. The attacks last a few hours to a few days. 

Impact of the attacks

The group's most successful attacks leave sites down for several hours to a few days. To handle the attacks, smaller and local site operators often resort to blocking queries from outside their country. In extreme cases, some site owners targeted by the group unregistered their domains. 

“The power of the DDoS attacks performed by NoName057(16) is debatable, to say the least. At one time, they can effectively strike about thirteen URL addresses at once, judging by configuration history, including subdomains,” continues Martin Chlumecky. “Furthermore, one XML configuration often includes a defined domain as a set of subdomains, so Bobik effectively attacks five different domains within one configuration. Consequently, they cannot focus on more domains for capacity and efficiency reasons.” 

The DDoS attacks carried out were more difficult to handle for some site operators of prominent and significant domains, such as banks, governments, and international companies. After a successful attack, Avast researchers noticed larger companies implementing enterprise solutions, such as Cloudflare or BitNinja, which can filter incoming traffic and detect DDoS attacks in most cases. On the other hand, most large, international companies expect heavier traffic and run their web servers in the Cloud with anti-DDoS solutions, making them more resilient to attacks. For example, the group was unsuccessful in taking down sites belonging to Danish bank, Danske Bank (attacked June 19 - 21, 2022), and Lithuanian bank, SEB (attacked July 12 - 13, 2022 and July 20 - 21, 2022). 

NoName057(16)’s more successful attacks affected companies with simple, informational sites, including just an about, mission, and a contact page, for example. The servers of sites like these are not typically designed to be heavily loaded and often do not implement anti-DDoS techniques, making them an easy target. 

How businesses and consumers can protect themselves

Businesses can protect their sites from DDoS attacks with specialized software and cloud protection.  

Consumers can prevent their devices from being used as part of a botnet by using reliable antivirus software, like Avast One, which detects and blocks malware like Bobik. Further steps consumers can take to protect their devices include avoiding clicking on suspicious links or attachments in emails and updating software on a regular basis to patch vulnerabilities. It is very difficult to recognize if a device is being used to facilitate a DDoS attack, but an indication could be high network traffic going to an unknown destination. 

More information about the group, Bobik malware, and the DDoS attacks can be found on the Avast Decoded blog: https://decoded.avast.io/martinchlumecky/bobik/

SME Business News

How Virtual Team Building Is Reshaping Modern Business Dynamics

In the past years, virtual team building has established itself as one of the cornerstones in building modern business strategy. With more organizations now switching to a model of remote or ...

How digital loyalty programs drive engagement in a value-conscious economy

Ongoing economic pressures are driving Australian retail businesses to rethink how they engage with increasingly value-conscious consumers. Rising living costs have shifted spending habits, p...

How Ofload and Logistics Tech Power Australia’s Biggest Shopping Month

Black Friday has evolved from a single day event into "Black November," overtaking December as Australia’s biggest shopping month. This shopping phenomenon, expected to drive $6.7 billion [1...

Kimberly-Clark Australia and Woolworths set to reduce plastic waste

Kimberly-Clark Australia, one of the nation’s leading personal care product manufacturers, has partnered with Woolworths on a packaging trial that’s set to remove tonnes of plastic waste from...

Property Times

What Does Buying in the Flood Zone Mean for Property Values in Brisbane?

Due to the floods Brisbane has been experiencing semi-regularly, many properties in flood zones have been selling for much cheaper prices. Within a year of flooding, the median valuation of flood-impacted properties has dropped below that of unim...

Enhancing Your Real Estate Investment with a Trusted Buyers Agency

Unlocking the potential of your real estate investment is an exciting but challenging journey. Partnering with a trusted buyers agency can make this process smoother, helping you maximise profits while securing your financial future. The real esta...

Sluggishness at the top imperils Australia’s housing shortage

Australia is lagging behind its target of building 1.2 million new homes by 2029, hindered by insufficient government intervention amid economic uncertainty and a volatile housing market. Since the target was announced last year, only 163,836 new...

Gold Coast Prestige Agent Hanan Cawley Joins Highland

Highland announces the merger with Hanan Cawley and his team. Mr. Cawley will take on the role of Managing Director of Highland Gold Coast, bringing his expertise and leadership to the forefront of the brand’s expansion in Queensland. Mr Cawley is ...

Food & Dining

How the Aussie summer has a profound effect on 'Climate Cravings’

Weather whiplash describes the rollercoaster-like shifts in weather we’ve experienced this summer —a blazing hot day one moment, followed by an unexpectedly chilly or rainy turn.  As a result, Aussies are experiencing ‘Climate Cravings’ - a shif...

The Foods You Should Avoid When Drinking Rose Wine

Rose wine has been synonymous with romance, and it’s easy to know why. This light and fruity drink invites you to relax, let loose, and just enjoy life’s simple pleasures.  But drinking such a delicate type of wine can also be tricky sometimes. In...

LaManna at Essendon Fields is transforming into a festive wonderland

This festive season, LaManna is decking its halls with an incredible range of goodies to meet all your Christmas needs and ensure your next holiday feast is one to remember.  With an extensive selection of Panettone, a variety of hampers and gift o...

For the foodie or home chef, look no further than premium pizza oven brand, Gozney

Founder and designer, Tom Gozney, wanted to bring a different way of cooking to as many people as possible and has led a movement of unforgettable cooking experiences inspired by fire.   Renowned for their design ethos, Gozney ovens are sleek ...

The Times Features

Exploring Hybrid Heating Systems for Modern Homes

Consequently, energy efficiency as well as sustainability are two major considerations prevalent in the current market for homeowners and businesses alike. Hence, integrated heat...

Are Dental Implants Right for You? Here’s What to Think About

Dental implants are now among the top solutions for those seeking to replace and improve their teeth. But are dental implants suitable for you? Here you will find out more about ...

Sunglasses don’t just look good – they’re good for you too. Here’s how to choose the right pair

Australians are exposed to some of the highest levels[1] of solar ultraviolet (UV) radiation in the world. While we tend to focus on avoiding UV damage to our skin, it’s impor...

How to Style the Pantone Color of the Year 2025 - Mocha Mousse

The Pantone Color of the Year never fails to set the tone for the coming year's design, fashion, and lifestyle trends. For 2025, Pantone has unveiled “Mocha Mousse,” a rich a...

How the Aussie summer has a profound effect on 'Climate Cravings’

Weather whiplash describes the rollercoaster-like shifts in weather we’ve experienced this summer —a blazing hot day one moment, followed by an unexpectedly chilly or rainy tur...

The heart research that could save fit and healthy Australians

Australians are now one step closer to being able to check that their heart is in working condition with a simple blood test. Leading scientists at the Heart Research Institu...

Business Times

How Virtual Team Building Is Reshaping Modern Business Dynamics

In the past years, virtual team building has established itself as one of the cornerstones in building modern business st...

How digital loyalty programs drive engagement in a value-consciou…

Ongoing economic pressures are driving Australian retail businesses to rethink how they engage with increasingly value-co...

How Ofload and Logistics Tech Power Australia’s Biggest Shopping …

Black Friday has evolved from a single day event into "Black November," overtaking December as Australia’s biggest shoppi...

LayBy Shopping