Vital Pandemic Industries Foster Unprecedented DDoS Attack Activity


Netscout today announced findings from its bi-annual Threat Intelligence Report, punctuated by a record-setting 10,089,687 Distributed Denial of Service (DDoS) attacks observed during 2020. Cybercriminals exploited vulnerabilities exposed by massive internet usage shifts since many users were no longer protected by enterprise-grade security.

Attackers paid particular attention to vital pandemic industries such as eCommerce, streaming services, online learning, and healthcare generating a 20% year-over-year increase in attack frequency over 2019 plus a 22% increase in the last six months of 2020.

In August, a threat actor Netscout dubbed Lazarus Bear Armada (LBA) launched one of the most sustained and extensive DDoS extortion campaigns yet seen, taking down the New Zealand stock exchange and targeting organizations involved in COVID-19 testing and vaccine development. 

According to Netscout’s Worldwide Infrastructure Security Report (WISR), which helps inform the Threat Intelligence Report findings, the number of enterprise respondents reporting DDoS extortion attacks increased by 125%. Overloaded firewalls and virtual private network (VPN) concentrators, crucial technologies used during the pandemic lockdown, contributed to the outages in 83% of the enterprises that suffered DDoS attacks. This finding represents a 21% increase over 2019 figures. 

“Cybercriminals set multiple records in 2020, taking advantage of the shift towards remote work across the globe,” says Richard Hummel, threat intelligence lead at Netscout. “The second half of last year witnessed a huge upsurge in DDoS attacks, brute-forcing of access credentials, and malware targeting internet-connected devices. As the COVID-19 pandemic continues, it will be imperative for security professionals to remain vigilant to protect critical infrastructure.”

Other key findings from the Netscout 2H2020 Threat Intelligence Report include:

Netscout’s Threat Intelligence Report covers the latest trends and activities in the DDoS threat landscape. It covers data secured from NETSCOUT’s Active Level Threat Analysis System (ATLAS) coupled with Netscout’s ATLAS Security Engineering & Response Team (ASERT) insights. 

The visibility and analysis represented in the Threat Intelligence Report and Cyber Threat Horizon fuel the ATLAS Intelligence Feed used across Netscout’s Arbor security product portfolio to detect and block threat activity for enterprises and service providers worldwide.

Staff writer

LEAVE A REPLY