US Civilian Network Infrastructure Targeted by Pro-Russian Hacktivists


October 11, 2022 08:56 AM

Following a series of DDoS attacks targeting government websites in the United States last week, Killnet's founder KillMilk, announced via an interview with Russia Today, that the threat group would target civilian network infrastructure in the United States over the coming days.

Read the Complete Alert
 

Following a series of DDoS attacks targeting government websites in the United States last week, Killnet's founder KillMilk, announced via an interview with Russia Today, that the threat group would target civilian network infrastructure in the United States over the coming days. Less than 48 hours later, pro-Russian hacktivist groups Killnet, NoName057(16), and Anonymous Russia began listing targets and announcing outages related to their DDoS attacks on websites of U.S. airports.

National Hacktivist

Who is KILLNET?

Killnet is a pro-Russian threat group known for launching DoS attacks against those in public and private sectors that directly and indirectly support Ukraine or have in some way offended Russia. The group formed in January of 2022, selling DDoS services, but quickly transitioned into a hacktivist group following the Russian invasion of Ukraine.

Figure 1: Killnet.io website advertising DDoS services (January 2022) Figure 1: Killnet.io website advertising DDoS services (January 2022)

Figure 1: OpsBedil reloaded 2022 campaign flyer Figure 2: Killnet.io website advertising the Killnet botnet capabilities (January 2022)

Since the invasion, the group has gathered a following of nearly 100,000 subscribers on their main Telegram channel. KillMilk, the founder of the pro-Russian hacktivist group Killnet, claims that members of the group are ordinary people and denies any association with the Russian government. Threat actors associated with the underground marketplace Solaris have been supporting and rooting for Killnet, helping Killnet to acquire funding through donations for maintaining and growing their attack infrastructure.

Who is NONAME057(16)?

NoName057(16) is a pro-Russia threat group known for launching defacement and DDoS attacks against Ukraine and those that directly and indirectly support Ukraine. The group formed in March of 2022 on Telegram and became a notable threat group by June. Since then, the group has gathered a following of nearly 13,000 subscribers. Noname057(16) has been seen operating in support of Killnet operations. At the time of publication, there is no evidence to suggest that NoName057(16) is working under the direction of the Russian government.

Demolish America's Name

On Sunday evening, October 9th, Russia Today published an interview with KillMilk, the founder of Killnet. KillMilk announced during the interview that Killnet is the "echo of future problems for the United States" and that the primary motivation for Killnet is to "repel the enemy." According to KillMilk, Killnet went through all their planned countries, and America will be their ultimate stand.

"THE UNITED STATES BRAGS ABOUT ITS CYBER TRAINING, BUT WHAT IT REALLY LOOKS LIKE AND HOW MUCH EXPERIENCE IT HAS IN CYBER WARFARE — YOU WILL SEE SOON THROUGH OUR ACTIONS. FOR EIGHT MONTHS WE LEARNED AND BROKE EUROPE, WHILE THE UNITED STATES WAS PREPARING TO CONFRONT WITH US. WE ARE JUST BEGINNING TO CAUSE DISRUPTION IN AMERICA'S CYBERSPACE. KILLNET WILL ACHIEVE THE HIGHEST POSITION IN THE I.T. WORLD AND DEMOLISH AMERICA'S NAME BEFORE EVERYONE'S EYES. WHAT HAS BEEN HACKED NOW? IT'S TRIVIA. RATHER, ASK WHAT WILL HAPPEN NEXT WITH THE INFORMATION FIELD OF THE UNITED STATES." – KILLMILK

KillMilk noted that he is a law-abiding citizen of the Russian Federation and does not get involved in the affairs of the Russian government, nor does he condemn their actions, adding that he does not commit crimes on the territory of his homeland.

Figure 3: KillMilk interview with Russia Today Figure 3: KillMilk interview with Russia Today

In the same interview, KillMilk also revealed that Killnet is preparing a "huge package of evidence and revelations" that will implicate the United States in the creation of COVID-19.

Continue Reading...

Click here to read the full ERT Threat Alert.

Read the full threat alert now

 

Contact Radware Sales

Our experts will answer your questions, assess your needs, and help you understand which products are best for your business.

Already a Customer?

We’re ready to help, whether you need support, additional services, or answers to your questions about our products and solutions.

Locations
Get Answers Now from KnowledgeBase
Get Free Online Product Training
Engage with Radware Technical Support
Join the Radware Customer Program

Get Social

Connect with experts and join the conversation about Radware technologies.

Blog
Security Research Center
CyberPedia