Hackers use DDoS attacks to distract you
Low-level persistent DDoS masks the real attack, warns report


Cybercriminals are using low-level DDoS attacks to mask malware injections, according to a report from information security services firm Neustar.
Half of the 800 executives surveyed for the report, titled North America and EMEA: The Continual Threat to Digital Brands for 2015, said they had suffered a DDoS attack in 2014 and early 2015, of which 80 per cent said they had suffered multiple attacks.
While 60 per cent of DDoS attacks still use heavy traffic to try and knock websites offline, 40 per cent are relatively small, at less than 5 Gbps, according to the report.
A total 36 per cent of executives surveyed said that, following a DDoS attack, they found malware installed in their systems. In the financial services sector, this rose to 54 per cent experiencing a DDoS of 4Gbps or less in strength and 43 per cent of all DDoS attacks leaving behind malware.
The results also show that companies in EMEA seem to be at greater risk both of DDoS attacks and subsequent malware injections. Of the almost 300 EMEA executives surveyes, 80 per cent said they had suffered a DDoS attack, of which 92 per cent reported a coinciding breach. Of that 92 per cent, two thirds experienced theft.
"These results really point to targeted attacks targeting a specific organisation for a specific purpose," Margee Abrams, director of security services product marketing at Neustar told IT Pro.
Abrams said this also represents a particular, and recent, change of tactics.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
"At the beginning of 2014, when we first did the report, we saw larger volumes of data in DDoS attacks and they would take the devices offline. Now what we're seeing is, with these smaller volumes, they can keep the devices online so that they can do other things - they don't want to totally saturate the device," she said.
Mitigating an attack involves more than just the IT team as well, now.
"When a DDoS attack occurs, everyone, including the communications, marketing, risk and compliance teams are all mobilised, as well as IT, to mitigate it," said Abrams. This is, potentially, in recognition of the brand damage an attack of this kind can do.
Businesses are continuing to fight back against the attackers at a technical level as well, though, with 73 per cent of those surveyed saying they are investing more in DDoS-specific protection and 46 per cent in hybrid technologies and counter-measures, which use both on-premise and cloud-based DDoS mitigation technologies to overcome attacks.

Jane McCallion is Managing Editor of ITPro and ChannelPro, specializing in data centers, enterprise IT infrastructure, and cybersecurity. Before becoming Managing Editor, she held the role of Deputy Editor and, prior to that, Features Editor, managing a pool of freelance and internal writers, while continuing to specialize in enterprise IT infrastructure, and business strategy.
Prior to joining ITPro, Jane was a freelance business journalist writing as both Jane McCallion and Jane Bordenave for titles such as European CEO, World Finance, and Business Excellence Magazine.
-
Enterprises face delicate balancing act with data center sustainability goals
News High energy consumption, raw material requirements, and physical space constraints are holding back data center sustainability efforts, according to new research from Seagate.
By Emma Woollacott
-
Cleo attack victim list grows as Hertz confirms customer data stolen
News Hertz has confirmed it suffered a data breach as a result of the Cleo zero-day vulnerability in late 2024, with the car rental giant warning that customer data was stolen.
By Ross Kelly
-
UK crime fighters wrangle “several thousand” potential cyber criminals in DDoS-for-hire honeypot
News The sting follows a recent crackdown on DDoS-for-hire services globally
By Ross Kelly
-
US begins seizure of 48 DDoS-for-hire services following global investigation
News Six people have been arrested who allegedly oversaw computer attacks launched using booters
By Zach Marzouk
-
Will triple extortion ransomware truly take off?
In-depth Operators are now launching attacks with three extortion layers, but there are limitations to this model
By Connor Jones
-
GoDaddy web hosting review
Reviews GoDaddy web hosting is backed by competitive prices and a beginner-friendly dashboard, and while popular, beware of hidden prices
By Daniel Blechynden
-
Japan investigates potential Russian Killnet cyber attacks
News The hacker group has said it’s revolting against the country’s militarism and that it’s “kicking the samurai”
By Zach Marzouk
-
LockBit hacking group to be 'more aggressive' after falling victim to large-scale DDoS attack
News The ransomware group is currently embroiled in a battle after it leaked data belonging to cyber security company Entrust
By Connor Jones
-
Record for the largest ever HTTPS DDoS attack smashed once again
News The DDoS attack lasted 69 minutes and surpassed the previous record of 26 million RPS
By Praharsha Anand
-
Cloudflare unveils new One Partner Program with zero trust at its core
News Cloudflare CEO Matthew Prince says the initiative aims to take the complexity out of zero trust architecture
By Daniel Todd