Connect with us

Hi, what are you looking for?

HEADLINES

Profit margin of a DDoS attack can reach 95%

Kaspersky Lab’s experts have studied the DDoS services available on the black market and determined just how far this illegal business has advanced, as well as the extent of its popularity and profitability. The worrying news is that arranging an attack costs as little as $7 an hour, while the targeted company can end up losing thousands, if not millions, of dollars.

Kaspersky Lab’s experts have studied the DDoS services available on the black market and determined just how far this illegal business has advanced, as well as the extent of its popularity and profitability. The worrying news is that arranging an attack costs as little as $7 an hour, while the targeted company can end up losing thousands, if not millions, of dollars.

The level of service involved when arranging a DDoS attack on the black market is not very different from that of a legal business. The only difference is that there’s no direct contact between the provider and the customer.

Kaspersky Lab_DDoS Economics 1.png

Example of a web service for ordering DDoS attacks that looks more like the web page of an IT startup than a cybercriminal operation

The ‘service providers’ offer a convenient site where customers, after registering, can select the service they need, pay for it, and receive a report about the attacks. In some cases there is even a customer loyalty program, with clients receiving rewards or bonus points for each attack.

Advertisement. Scroll to continue reading.

There are a number of factors that affect the cost for the customer. One is the type of attack and its source: for example, a botnet made up of popular IoT devices is cheaper than a botnet of servers. However, not all those providing attack services are ready to specify such details.

Another factor is the duration of the attack (measured in seconds, hours and days), and the client’s location. DDoS attacks on English-language websites, for example, are usually more expensive than similar attacks on Russian-language sites.

Another big factor affecting the cost is the type of victim. Attacks on government websites and resources protected by dedicated anti-DDoS solutions are much more expensive, as the former are high risk, while the latter are more difficult to attack.

For instance, on one DDoS-as-a-service website, the cost of an attack on an unprotected website ranges from $50 to $100, while an attack on a protected site costs $400 or more.

It means a DDoS attack can cost anything from $5 for a 300-second attack, to $400 for 24 hours. The average price for an attack is around $25 per hour.

Advertisement. Scroll to continue reading.

Kaspersky Lab_DDoS Economics 2.png

Various tariffs of an English-language service that varies its pricing according to the number of seconds a DDoS attack lasts

Kaspersky Lab’s experts were also able to calculate that an attack using a cloud-based botnet of 1000 desktops is likely to cost the providers about $7 per hour. That means the cybercriminals organizing DDoS attacks are making a profit of around $18 per hour.

There is, however, yet another scenario that offers greater profitability for cybercriminals – it involves the attackers demanding a ransom from a target in return for not launching a DDoS attack, or to call off an ongoing attack. The ransom can be the bitcoin equivalent of thousands of dollars, meaning the profitability of a single attack can exceed 95%. In fact, those carrying out the blackmail don’t even need to have the resources to launch an attack – sometimes the mere threat is enough.

“Cybercriminals are constantly on the lookout for new and cheaper ways of organizing botnets, as well as coming up with ever more ingenious attack scenarios that security solutions will have difficulty dealing with,” says Denis Makrushin, Security Researcher at Kaspersky Lab. “That’s why, as long as there are vulnerable servers, computers and IoT devices connected to the Internet, and many companies prefer not to invest in security against DDoS attacks, we can expect the profitability of DDoS attacks to continue growing, along with their complexity and frequency.”

Interestingly, some cybercriminals have no scruples about selling DDoS attacks alongside protection from them. Kaspersky Lab’s experts, however, do not recommend using criminal services.

Advertisement. Scroll to continue reading.

Advertisement
Advertisement
Advertisement

Like Us On Facebook

You May Also Like

HEADLINES

The new graphics cards feature 16GB of memory and extensive improvements designed for high-quality gaming graphics, including re-vamped raytracing accelerators and powerful AI accelerators...

HEADLINES

ZTE will promote the deep integration of AI and connectivity, accelerating intelligent innovation and jointly shaping a future that is highly efficient, intelligent and...

HEADLINES

The new single identity comes from a 36-year legacy of leadership in innovation and excellence in forward-thinking technology.

HEADLINES

Watsons is actively utilizing renewable energy as a total of ninety-five Watsons stores nationwide, along with all of Watsons’ distribution centers in Luzon and...

HEADLINES

This latest innovation is set to bring high-speed, fiber-like connectivity to businesses and communities in underserved and unserved areas across the Philippines.

HEADLINES

It is open-sourcing four models of its 14-billion(B)-parameter and 1.3-billion(B)-parameter versions of Wan2.1 series, the latest iteration of its video foundation model Tongyi Wanxiang...

HEADLINES

This achievement reflects PLDT’s commitment to driving innovation, security, and digital transformation as it enhances network API capabilities to help businesses thrive in an...

COMPUTERS

Powered by the Intel Core Ultra processor with an integrated NPU, the ThinkSmart Core Gen 2 is ready for AI-heavy meeting room workloads, delivering...

Advertisement