US bank website hackers used advanced botnets, diverse tools

Advertisement
By Reuters | Updated: 3 October 2012 14:47 IST
The hackers behind the cyber attacks on major U.S. banks have repeatedly disrupted online banking by using sophisticated and diverse tools that point to a carefully coordinated campaign, according to security researchers.

The hackers, believed to be activists in the Middle East, were highly knowledgeable about the defensive equipment used by the banks and likely spent months on reconnaissance, said several researchers interviewed by Reuters, who viewed the assaults as among the strongest and most complex the world has seen to date.

In the past two weeks, customers of top U.S. banks including Bank of America Corp, JPMorgan Chase & Co, Wells Fargo & Co, U.S. Bancorp and PNC Financial Services have reported having trouble accessing their websites, as unusually high traffic volumes appeared to crash or slow down the systems.

No thefts have been tied to hacked sites, but an untold number of customers were not able to pay bills or transfer money from their computers, leaving banks with remediation expenses and customer irritation as the biggest costs.

Advertisement

Researchers said the hackers used groups of compromised computers, known as botnets, which are inexpensive to rent for short periods. What made these botnets much more powerful was that they were made up of web servers that had been taken over, instead of mere personal computers.

Advertisement

"Tens of thousands" of servers are involved, said Tom Kellermann, vice president of major security vendor Trend Micro.

The FBI declined to comment on its investigation of the attacks. The banks either declined to comment or noted that most customers have been able to log into their accounts.

Advertisement

"It's fairly large, but it's something financial institutions are accustomed to dealing with," said Doug Johnson, vice president of the American Bankers Association trade group.

Sources familiar with the bank attacks have previously told Reuters that they could be part of a year-long cyber campaign waged by Iranian hackers against major U.S. financial institutions and other corporate entities.

Advertisement

Senator Joseph Lieberman, chairman of the Senate's Homeland Security and Governmental Affairs Committee, has also blamed Iran's much-improved cyber forces on the bank website outages.

A group that calls itself the Cyber Fighters of Izz ad-din Al Qassam has claimed credit for the recent bank attacks, declaring them a protest against the anti-Islam video posted on YouTube and stoked violent protests across the Muslim world.

The latest attacks against the banks have thrown as many as 30 million electronic packets per second at the websites, at times overwhelming both the banks and the additional technical resources being moved into place to counter the attacks.

That much volume "would overwhelm almost anyone, including large telecommunications companies," said Scott Hammack, chief executive of Prolexic Technologies, which specializes in warding off "denial of service" attacks. Prolexic's clients include several of the biggest banks, though Hammack declined to name which ones.

Experts said that high-volume denial-of-service attacks were becoming more common even before the latest bank assaults and would continue to increase in sophistication as well.

"This entire episode speaks to the need for banks, or any business operating online, to be prepared for this type of availability attack," said Dan Holden, director of research at security firm Arbor Networks.

Copyright Thomson Reuters 2012

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. YouTuber Shows Off Samsung Galaxy S26 Ultra Alongside the iPhone 17 Pro Max
  2. Apple Said to Plan Five Launches at March 'Special Experience' Event
  3. Who Is Asha Sharma, the New Xbox Chief Replacing Phil Spencer?
  4. iPhone 17, iPhone 16 Discounted in Croma Everything Apple Sale
  5. Samsung Galaxy S26 Ultra Leak Suggests It May Skip Battery, Camera Upgrades
  6. LG Gram 14 (2026) Launched With Up to Ryzen AI 7 450 Processor: See Price
  7. Apple's iPhone 18 Pro Models Could Come in a New Deep Red Colourway
  8. Galaxy S26 Ultra Retail Unit Leaks Before Launch, Showcasing Privacy Screen
  9. Croma Everything Apple Sale Brings Discount on MacBook Pro M5 (2025), iPad Pro, and More
  10. Apple's AI Pendant Said to Use In-House Visual Intelligence Models
  1. Samsung Galaxy S26 Ultra 'Privacy Display' Feature to Arrive on Other Flagship Android Phones, Tipster Claims
  2. Croma Everything Apple Sale Brings Discount on MacBook Pro M5 (2025), iPad Pro, and More
  3. iPhone 17, iPhone 16 and Other Models Discounted in Croma Everything Apple Sale: Best Deals, Offers
  4. Apple Reportedly Exploring Deep Red iPhone 18 Pro Colour; iPhone Fold to Have 'Utilitarian' Shades
  5. Apple Said to Be Developing Visual Intelligence Models for AI Pendant, Other Upcoming Wearables
  6. Nothing Headphone (a) Reportedly Listed on IMDA Certification Database Hinting at Imminent Global Launch
  7. Samsung Galaxy S26 Ultra Seen Alongside iPhone 17 Pro Max as YouTuber Purchases Handset Ahead of Galaxy Unpacked
  8. LG Gram 14 (2026) With Up to AMD Ryzen AI 7 450 Processor, 72Wh Battery Launched: Price, Features
  9. Samsung Galaxy S26 Ultra Retail Unit Surfaces Ahead of Unpacked Event, Highlighting Privacy Screen Feature
  10. Samsung Galaxy S26 Ultra Marketing Images Leaked; Could Arrive Without Battery, Camera Upgrades
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.