Internet had a rough time as the weekend approached, and not because of the weather. Several major websites, including Twitter, Netflix, Reddit, and Spotify, began showing access errors, even though nothing was wrong with their own infrastructure. The new cyberattack had hit Dyn, one of the world's most important DNS distribution companies. The attack was particularly concentrated on the United States, and the data available in the last 72 hours points to a botnet based on a malware called Mirai.
The Attack Unfolds
It was already known that another cyberattack was about to hit the Internet infrastructure. No matter how big the recent events were, the feeling never disappeared that those responsible were 'training,' preparing for something huge. Well, apparently that 'something' happened last Friday, when half of the Internet in the United States and part of Europe simply disappeared. Dozens of high-profile sites were affected, covering all kinds of genres and services. Netflix, Amazon, Spotify, HBO, PayPal, Twitter, Reddit, The Elder Scrolls Online, Electronic Arts, Starbucks, Quora, news portals… the list goes on. The most striking thing is that the attack was not directed at those sites, but rather to compromise the system that allows us to access them. In other words, the target was the DNS distribution company Dyn, which many knew previously as DynDNS.
Mirai and the Botnet
According to the report published by Dyn itself, the DDoS attack began just before 11:10 (UTC/GMT) last Friday, and was declared 'resolved' eleven hours later. The attack was believed to have been mitigated twice, but the average pause was about three hours. The effects of the attack hit Dyn's servers on the East Coast of the United States, although in practice it affected almost all of that country and part of Europe. Over time, several security firms managed to determine that the botnet responsible for the cyberattack was based on the malware called Mirai. If the name sounds familiar, it's because it's the same malware used against the portal Krebs on Security, and in the record-breaking DDoS that took down the French provider OVH. Mirai's special ability is to turn devices like surveillance cameras, baby monitors, and other accessories of the famous Internet of Things into a zombie army capable of deploying devastating power. If that seems little, the person responsible for the Mirai malware, who goes by the pseudonym 'Anna-sempai', released its code in the last weeks of September. Although this does not mean that the same botnet participated in all three attacks, Mirai's involvement in all cases is very clear.
The security firm Flashpoint shared additional details about the 'zombies' that attacked Dyn. Although the possibility of multiple combined botnets participating in the attack was not ruled out, Flashpoint warned that devices based on hardware from a Chinese company, XiongMai Technologies, were the most affected. This reminds us of the lack of security and responsibility on the part of manufacturers who do not properly protect their products. All these accessories go on sale with an internal factory password (hardcoded) that cannot be changed by the user, and even worse, they leave access to them open via telnet or SSH, delicacies served on silver platters for malware. A simple scan for vulnerable hardware allowed Flashpoint to find more than half a million, and no one knows how many a persistent malware could find. It is exactly as Martin McKeay of Akamai anticipated after the OVH attack: Internet blackouts.
A Looming Threat
The hard truth is that this is not going to end. Once Mirai's capabilities are fully understood, it may be contained, but the people responsible for the attacks are very intelligent, and they only have to take its code to create something even more cunning. Perhaps it's time to put the Internet of Things on the stand and implement mandatory certifications that manufacturers must follow to ensure their products don't compromise what is already a very delicate infrastructure. Of course, that translates to higher costs. The idea of replacing defective and insecure hardware will be resisted from start to finish, however, the mechanics of "patches and mitigation" are reaching their limit.
Krebs on Security
Flashpoint