Security News > 2022 > March > Hackers Abuse Mitel Devices to Amplify DDoS Attacks by 4 Billion Times
The attack vector - dubbed TP240PhoneHome - has been weaponized to launch significant DDoS attacks targeting broadband access ISPs, financial institutions, logistics companies, gaming firms, and other organizations.
"Attackers were actively leveraging these systems to launch reflection/amplification DDoS attacks of more than 53 million packets per second."
DDoS reflection attacks typically involve spoofing the IP address of a victim to redirect responses from a target such as DNS, NTP, or CLDAP server in such a manner that the replies sent to the spoofed sender are much bigger than the requests, leading to complete inaccessibility of the service.
First sign of the attacks is said to have been detected on February 18, 2022 using Mitel's MiCollab and MiVoice Business Express collaboration systems as DDoS reflectors, courtesy the inadvertent exposure of an unauthenticated test facility to the public internet.
"This particular attack vector differs from most UDP reflection/amplification attack methodologies in that the exposed system test facility can be abused to launch a sustained DDoS attack of up to 14 hours in duration by means of a single spoofed attack initiation packet, resulting in a record-setting packet amplification ratio of 4,294,967,296:1."
"The collateral impact of TP-240 reflection/amplification attacks is potentially significant for organizations with internet-exposed Mitel MiCollab and MiVoice Business Express collaboration systems that are abused as DDoS reflectors/amplifiers," the company said.
News URL
https://thehackernews.com/2022/03/hackers-abuse-mitel-devices-to-amplify.html
Related news
- Hackers increasingly use Winos4.0 post-exploitation kit in attacks (source)
- Iranian Hackers Use "Dream Job" Lures to Deploy SnailResin Malware in Aerospace Attacks (source)
- Iranian Hackers Deploy WezRat Malware in Attacks Targeting Israeli Organizations (source)
- Hackers breach US firm over Wi-Fi from Russia in 'Nearest Neighbor Attack' (source)
- North Korean Kimsuky Hackers Use Russian Email Addresses for Credential Theft Attacks (source)
- Russian hackers hijack Pakistani hackers' servers for their own attacks (source)
- Russian hackers hijack Pakistani hackers' servers for their own attacks (source)
- Europol Dismantles 27 DDoS Attack Platforms Across 15 Nations; Admins Arrested (source)
- 390,000 WordPress accounts stolen from hackers in supply chain attack (source)
- Hackers Use Microsoft MSC Files to Deploy Obfuscated Backdoor in Pakistan Attacks (source)