Cyber Crime

Law enforcement take down 15 DDoS-for-Hire services

U.S. Authorities Take Down 15 DDoS-for-Hire Websites

The Department of Justice (DoJ) announced that the FBI seized 15 domains associated with DDoS-for-hire services.

The FBI has seized 15 domains associated with DDoS-for-hire services (aka booters or stressers) that were used by their customers to launch powerful DDoS attacks.

The U.S. District Court for the Central District of California ordered the seizure of the platforms (including critical-boot(.)com, ragebooter(.)com, downthem(.)org and quantumstress(.)net) on Dec. 19.

The authorities charged three individuals who operated the DDoS-for-hire services, most of the victims hit by the malicious traffic generated by the platforms were in the United States and abroad.

The platforms were used to carry out attacks against universities, government systems, financial institutions, Internet service providers, and gaming platforms.

The platforms were very cheap and provided anything necessary to launch a DDoS attack, they also implemented various payment options, including virtual currencies such as Bitcoin.

“On Dec. 19, pursuant to seizure warrants issued by the U.S. District Court for the Central District of California, the FBI seized the domains of 15 booter services, which represent some of the world’s leading DDoS-for-hire services.  Among these sites were critical-boot.com, ragebooter.com, downthem.org and quantumstress.net.” reads the Press Release published by DoJ.

“According to the affidavit in support of the warrant authorizing the seizure of the 15 websites, these services offered easy access to attack infrastructure, payment options that included Bitcoin, and were relatively low cost.  Each of the services was tested by the FBI, which verified those DDoS attack services offered through each of the seized websites.  While testing the various services, the FBI determined that these types of services can and have caused disruptions of networks at all levels.”

In conjunction with the seizure warrants, the U.S. Attorney’s Office charged Matthew Gatrel (30) and Juan Martinez (25) with conspiring to violate the Computer Fraud and Abuse Act. The duo operated the DDoS-for-hire services known as Downthem and Ampnode. 

While Downthem offered DDoS services to its users, Ampnode provided resources needed to arrange a standalone DDoS services

It has been determined that between Oct. 2014 and Nov. 2018, Downthem had over 2,000 customer subscriptions and launched over 200,000 DDoS attacks.

On Dec. 12, the U.S. Attorney’s Office for the District of Alaska charged David Bukoski (23) with aiding and abetting computer intrusions. Bukoski operated Quantum Stresser, one of the longest-running DDoS services in operation.  It has been estimated that as of Nov. 29, Quantum had over 80,000 customer subscriptions and in 2018 alone, the platform was used to launch over 50,000 attacks targeting victims worldwide.

DoJ praised collaboration among Districts and coordination with public sector partners.

“DDoS for hire services such as these pose a significant national threat,” said U.S. Attorney Schroder.  “Coordinated investigations and prosecutions such as these demonstrate the importance of cross-District collaboration and coordination with public sector partners.” concludes the press release,

“The attack-for-hire websites targeted in this investigation offered customers the ability to disrupt computer networks on a massive scale, undermining the internet infrastructure on which we all rely,” said U.S. Attorney Hanna.

Even if the crackdown operated by the FBI have a significant impact on this cybercriminal ecosystem, many other websites continue to offer DDoS-for-hire services.

[adrotate banner=”9″] [adrotate banner=”12″]

Pierluigi Paganini

(SecurityAffairs –malware, memes)

[adrotate banner=”5″] [adrotate banner=”13″]

The U.S. District Court for the Central District of California ordered the seizure of the platforms (including critical-boot(.)com, ragebooter(.)com, downthem(.)org and quantumstress(.)net) on Dec. 19.

The authorities charged three individuals who operated the DDoS-for-hire services, most of the victims hit by the malicious traffic generated by the platforms were in the United States and abroad.

The platforms were used to carry out attacks against universities, government systems, financial institutions, Internet service providers, and gaming platforms.

The platforms were very cheap and provided anything necessary to launch a DDoS attack, they also implemented various payment options, including virtual currencies such as Bitcoin.

“On Dec. 19, pursuant to seizure warrants issued by the U.S. District Court for the Central District of California, the FBI seized the domains of 15 booter services, which represent some of the world’s leading DDoS-for-hire services.  Among these sites were critical-boot.com, ragebooter.com, downthem.org and quantumstress.net.” reads the Press Release published by DoJ.

“According to the affidavit in support of the warrant authorizing the seizure of the 15 websites, these services offered easy access to attack infrastructure, payment options that included Bitcoin, and were relatively low cost.  Each of the services was tested by the FBI, which verified those DDoS attack services offered through each of the seized websites.  While testing the various services, the FBI determined that these types of services can and have caused disruptions of networks at all levels.”

In conjunction with the seizure warrants, the U.S. Attorney’s Office charged Matthew Gatrel (30) and Juan Martinez (25) with conspiring to violate the Computer Fraud and Abuse Act. The duo operated the DDoS-for-hire services known as Downthem and Ampnode. 

While Downthem offered DDoS services to its users, Ampnode provided resources needed to arrange a standalone DDoS services

It has been determined that between Oct. 2014 and Nov. 2018, Downthem had over 2,000 customer subscriptions and launched over 200,000 DDoS attacks.

On Dec. 12, the U.S. Attorney’s Office for the District of Alaska charged David Bukoski (23) with aiding and abetting computer intrusions. Bukoski operated Quantum Stresser, one of the longest-running DDoS services in operation.  It has been estimated that as of Nov. 29, Quantum had over 80,000 customer subscriptions and in 2018 alone, the platform was used to launch over 50,000 attacks targeting victims worldwide.

DoJ praised collaboration among Districts and coordination with public sector partners.

“DDoS for hire services such as these pose a significant national threat,” said U.S. Attorney Schroder.  “Coordinated investigations and prosecutions such as these demonstrate the importance of cross-District collaboration and coordination with public sector partners.” concludes the press release,

“The attack-for-hire websites targeted in this investigation offered customers the ability to disrupt computer networks on a massive scale, undermining the internet infrastructure on which we all rely,” said U.S. Attorney Hanna.

Even if the crackdown operated by the FBI will have a significant impact on this burgeoning criminal industry, there are other sites offering these services.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

[adrotate banner=”9″] [adrotate banner=”12″]

Pierluigi Paganini

(SecurityAffairs –DDoS-for-hire services, hacking)

[adrotate banner=”5″] [adrotate banner=”13″]

Pierluigi Paganini

Pierluigi Paganini is member of the ENISA (European Union Agency for Network and Information Security) Threat Landscape Stakeholder Group and Cyber G7 Group, he is also a Security Evangelist, Security Analyst and Freelance Writer. Editor-in-Chief at "Cyber Defense Magazine", Pierluigi is a cyber security expert with over 20 years experience in the field, he is Certified Ethical Hacker at EC Council in London. The passion for writing and a strong belief that security is founded on sharing and awareness led Pierluigi to find the security blog "Security Affairs" recently named a Top National Security Resource for US. Pierluigi is a member of the "The Hacker News" team and he is a writer for some major publications in the field such as Cyber War Zone, ICTTF, Infosec Island, Infosec Institute, The Hacker News Magazine and for many other Security magazines. Author of the Books "The Deep Dark Web" and “Digital Virtual Currency and Bitcoin”.

Recent Posts

SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 84

Security Affairs Malware newsletter includes a collection of the best articles and research on malware…

2 hours ago

Security Affairs newsletter Round 563 by Pierluigi Paganini – INTERNATIONAL EDITION

A new round of the weekly Security Affairs newsletter has arrived! Every week, the best…

2 hours ago

Fintech firm Figure disclosed data breach after employee phishing attack

Fintech firm Figure confirmed a data breach after hackers used social engineering to trick an…

22 hours ago

U.S. CISA adds a flaw in BeyondTrust RS and PRA to its Known Exploited Vulnerabilities catalog

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a flaw in BeyondTrust RS and…

24 hours ago

Suspected Russian hackers deploy CANFAIL malware against Ukraine

A new alleged Russia-linked APT group targeted Ukrainian defense, government, and energy groups, with CANFAIL…

1 day ago

New threat actor UAT-9921 deploys VoidLink against enterprise sectors

A new threat actor, UAT-9921, uses the modular VoidLink framework to target technology and financial…

2 days ago

This website uses cookies.