Established booter and stresser services offer a convenient means for malicious actors to conduct DDoS attacks by allowing such actors to pay for an existing network of infected devices, rather than creating their own. These services can be used legitimately to test the resilience of a network however, criminal actors use this capability to take down Web sites. Criminal actors running booter and stresser services sell access to DDoS botnets, a network of malware-infected computers exploited to make a victim server or network resource unavailable by overloading the device with massive amounts of fake or illegitimate traffic. These services are obtained through a monetary transaction, usually in the form of online payment services and virtual currency. Open source reports estimate the DNS provider lost approximately eight percent of its customers following the attack.īooter and stresser services are a form of DDoS-for-hire- advertised in forum communications and available on Dark Web marketplaces- offering malicious actors the ability to anonymously attack any Internet-connected target. The attack used a booter service and was attributed to infected Internet of Things (IoT) devices like routers, digital video recorders, and Webcams/security cameras to execute the DDoS attack 1. They also can cause businesses impacted by DDoS attacks to lose customers.įor example, in October 2016, one of the largest DDoS attacks to date targeted a domain name service (DNS) provider and impacted more than 80 Web sites primarily in the United States and Europe, causing them to become inaccessible to the public. These attacks prevent people from accessing online accounts, disrupt business activities, and induce significant remediation costs on victim companies.
The FBI investigates these services as a crime if they are used against a Web site without the owner’s permission (such as for a legitimate stress test).ĭDoS attacks are costly to victims and render targeted Web sites slow or inaccessible. These DDoS-for-hire services, also known as booters or stressers, are leveraged by malicious cyber actors, pranksters, and/or hacktivists to conduct largescale cyber attacks designed to prevent access to U.S. Booter and Stresser Services Increase the Scale and Frequency of Distributed Denial of Service AttacksĬriminal actors offer distributed denial of service (DDoS)-for-hire services in criminal forums and marketplaces.