US Civilian Network Infrastructure Targeted by Pro-Russian Hacktivists


October 11, 2022 08:56 AM

Following a series of DDoS attacks targeting government websites in the United States last week, Killnet's founder KillMilk, announced via an interview with Russia Today, that the threat group would target civilian network infrastructure in the United States over the coming days.

Read the Complete Alert
 

Following a series of DDoS attacks targeting government websites in the United States last week, Killnet's founder KillMilk, announced via an interview with Russia Today, that the threat group would target civilian network infrastructure in the United States over the coming days. Less than 48 hours later, pro-Russian hacktivist groups Killnet, NoName057(16), and Anonymous Russia began listing targets and announcing outages related to their DDoS attacks on websites of U.S. airports.

National Hacktivist

Who is KILLNET?

Killnet is a pro-Russian threat group known for launching DoS attacks against those in public and private sectors that directly and indirectly support Ukraine or have in some way offended Russia. The group formed in January of 2022, selling DDoS services, but quickly transitioned into a hacktivist group following the Russian invasion of Ukraine.

Figure 1: Killnet.io website advertising DDoS services (January 2022) Figure 1: Killnet.io website advertising DDoS services (January 2022)

Figure 1: OpsBedil reloaded 2022 campaign flyer Figure 2: Killnet.io website advertising the Killnet botnet capabilities (January 2022)

Since the invasion, the group has gathered a following of nearly 100,000 subscribers on their main Telegram channel. KillMilk, the founder of the pro-Russian hacktivist group Killnet, claims that members of the group are ordinary people and denies any association with the Russian government. Threat actors associated with the underground marketplace Solaris have been supporting and rooting for Killnet, helping Killnet to acquire funding through donations for maintaining and growing their attack infrastructure.

Who is NONAME057(16)?

NoName057(16) is a pro-Russia threat group known for launching defacement and DDoS attacks against Ukraine and those that directly and indirectly support Ukraine. The group formed in March of 2022 on Telegram and became a notable threat group by June. Since then, the group has gathered a following of nearly 13,000 subscribers. Noname057(16) has been seen operating in support of Killnet operations. At the time of publication, there is no evidence to suggest that NoName057(16) is working under the direction of the Russian government.

Demolish America's Name

On Sunday evening, October 9th, Russia Today published an interview with KillMilk, the founder of Killnet. KillMilk announced during the interview that Killnet is the "echo of future problems for the United States" and that the primary motivation for Killnet is to "repel the enemy." According to KillMilk, Killnet went through all their planned countries, and America will be their ultimate stand.

"THE UNITED STATES BRAGS ABOUT ITS CYBER TRAINING, BUT WHAT IT REALLY LOOKS LIKE AND HOW MUCH EXPERIENCE IT HAS IN CYBER WARFARE — YOU WILL SEE SOON THROUGH OUR ACTIONS. FOR EIGHT MONTHS WE LEARNED AND BROKE EUROPE, WHILE THE UNITED STATES WAS PREPARING TO CONFRONT WITH US. WE ARE JUST BEGINNING TO CAUSE DISRUPTION IN AMERICA'S CYBERSPACE. KILLNET WILL ACHIEVE THE HIGHEST POSITION IN THE I.T. WORLD AND DEMOLISH AMERICA'S NAME BEFORE EVERYONE'S EYES. WHAT HAS BEEN HACKED NOW? IT'S TRIVIA. RATHER, ASK WHAT WILL HAPPEN NEXT WITH THE INFORMATION FIELD OF THE UNITED STATES." – KILLMILK

KillMilk noted that he is a law-abiding citizen of the Russian Federation and does not get involved in the affairs of the Russian government, nor does he condemn their actions, adding that he does not commit crimes on the territory of his homeland.

Figure 3: KillMilk interview with Russia Today Figure 3: KillMilk interview with Russia Today

In the same interview, KillMilk also revealed that Killnet is preparing a "huge package of evidence and revelations" that will implicate the United States in the creation of COVID-19.

Continue Reading...

Click here to read the full ERT Threat Alert.

Read the full threat alert now

 

与Radware销售部门接洽

我们的专家将回答您的问题、评估您的需求,并帮助您了解哪些产品最适合您的业务。

已经是客户?

无论您需要支持或更多服务,还是需要解答有关我们产品和解决方案的问题,我们都会随时提供帮助。

公司地点
马上从知识库获得答案
获得免费在线产品培训
联系Radware技术支持部
加入Radware客户计划

参与社交

联系专家并加入有关Radware技术的对话。

Blog
安全研究中心
CyberPedia