A family afternoon watching TV and doing some online shopping, when going to make a payment through a well-known payment platform it wasn't working... strange... I tried to log into Twitter and although it didn't crash, it wasn't loading properly, this looked like a DDoS attack. This is just my case but similarly millions of users were affected yesterday by the DDoS attack on Dyn.com. Services such as Twitter, Spotify, Github, as well as thousands of other websites were inaccessible for hours.
The attack that affected, as we said, the DNS services, began at 1:10 PM ECT, through a massive DDoS attack against Dyn's DNS infrastructure in the Eastern United States region, this began to cause resolution failures and high latency rates. In the map below, from Level 3, we see the scope of the attack

A couple of hours later Dyn engineers managed to mitigate the attack and the service was restored. While analyzing this attack and checking the services, the second attack arrived (5:50 PM ECT) again focused on DNS services but this time more geographically distributed, as you can see in the map below. A little over an hour later the attack decreased in intensity again and they managed to start restoring services once more.

As you can understand, the attacks and their consequences are having a huge global impact due to the targets achieved. An average user may not be very aware of the importance of cybersecurity, or even underestimate it, but if their Spotify doesn't work, for example, they can get annoyed. At this moment, both Dyn's own researchers, as well as the FBI, the Department of Homeland Security or other security companies like Level 3, continue to investigate based on the data monitored during the attacks to determine who may be responsible and the means used.
Initial reports point to cybercriminals based in third countries who have again used a Mirai IoT botnet (the malware used to compromise and coordinate the devices) as the main attack weapon. As we mentioned in a previous article, these botnets continue to grow exponentially due to negligence from both users and manufacturers. As we are seeing from the damage it can cause, this and other botnets have become one of the biggest threats on the Internet, due to the enormous difficulty in responding to DDoS attacks of this magnitude.
In Dyn's own DNS blog, a post from a couple of days ago discussed the effects and dangers of attacks carried out by this type of botnet, although at this time it is not known if the attack had anything to do with the post as a sort of "show-off."
Do you want to protect your website from attacks? Q2B has the solution, click here for more information





