Turkish hacking group offers cyber criminals rewards for successful DDoS attacks
Points are logged on a scoreboard that can be cashed in for free access to other hacking tools

A gang of Turkish hackers has turned web attacks into a game by offering hackers rewards for taking down chosen pages.
The group is giving loyalty points to hackers for every attack they mount against websites that are run by organisations that oppose Turkey's government; the points can later be swapped for free access to some hacking tools.
Security firm Forcepoint is responsible for discovering the site, called "Surface Defence", and said that the service is offered on the Tor dark web network, using a software tool named Sledgehammer.
Forcepoint said in a report that the tool seeks to knock websites offline via a Distributed Denial of Service (DDoS) attack. Once an attack is successfully completed, a reward of one point is given for every 10 minutes of an attack directed at one of the targets.
Other security experts have been keen to comment on the discovery, such as Tripwire's senior security research engineer, Travis Smith.
"Even though the gamification of the DDoS tool allows individuals from around the world to participation in the attack, the targets are controlled by a centralized command and control server," he said.
Marc Gaffan, general manager for the Incapsula service at Imperva, described the discovery as not only a game changer but a natural evolution of hackers learning and improving on how to monetise their assets and use them for ad hoc purposes, in this case DDoSing a select group of targets.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
"The novel part of this is the platform that has been developed to solicit and monitor those that participate in the DDoS activities to ensure they are doing what the masterminds want them to do and in the way they want them to execute the attacks (down to the precise technology they want them to use)," he said.
"The platform itself, if redistributed, could become the new standard for crowdsourcing DDoS attackers."
-
AI is helping bad bots take over the internet
News Automated bot traffic has surpassed human activity for the first time in a decade, according to Imperva
By Bobby Hellard
-
Two years on from its Series B round, Hack the Box is targeting further growth
News Hack the Box has grown significantly in the last two years, and it shows no signs of slowing down
By Ross Kelly
-
UK crime fighters wrangle “several thousand” potential cyber criminals in DDoS-for-hire honeypot
News The sting follows a recent crackdown on DDoS-for-hire services globally
By Ross Kelly
-
US begins seizure of 48 DDoS-for-hire services following global investigation
News Six people have been arrested who allegedly oversaw computer attacks launched using booters
By Zach Marzouk
-
Will triple extortion ransomware truly take off?
In-depth Operators are now launching attacks with three extortion layers, but there are limitations to this model
By Connor Jones
-
GoDaddy web hosting review
Reviews GoDaddy web hosting is backed by competitive prices and a beginner-friendly dashboard, and while popular, beware of hidden prices
By Daniel Blechynden
-
Japan investigates potential Russian Killnet cyber attacks
News The hacker group has said it’s revolting against the country’s militarism and that it’s “kicking the samurai”
By Zach Marzouk
-
LockBit hacking group to be 'more aggressive' after falling victim to large-scale DDoS attack
News The ransomware group is currently embroiled in a battle after it leaked data belonging to cyber security company Entrust
By Connor Jones
-
Record for the largest ever HTTPS DDoS attack smashed once again
News The DDoS attack lasted 69 minutes and surpassed the previous record of 26 million RPS
By Praharsha Anand
-
Cloudflare unveils new One Partner Program with zero trust at its core
News Cloudflare CEO Matthew Prince says the initiative aims to take the complexity out of zero trust architecture
By Daniel Todd