Although DDoS attacks are generally considered to be less sophisticated, over the past year, some
attackers aimed to carry out stronger and longer lasting DDoS attacks to deny the availability
of services for as long as possible. They did so by circumventing the usual mitigation measures
and by using multiple DDoS attack techniques simultaneously. In the case of the aforementioned
pro-Russian hacktivist groups, DDoS attacks also served as a propaganda tool. Despite their
minimal impact, DDoS attacks were often heavily publicized domestically, with groups like Killnet
and Anonymous Russia sharing the stories and promoting them to their domestic audiences on
the social network Telegram to exaggerate their real impact. The excessive media coverage of
the attacks in the attacked countries thus paradoxically aided the goals of the attackers.
Malware as a Service: Growing Opportunities for Cybercrime Actors
Another growing threat monitored by the NÚKIB during the past year is the so-called
cybercrime-as-a-service model: the sale of tools for carrying out cyberattacks. Cybercriminal
actors offer their services on black markets (especially on the so-called darkweb), which can
then be purchased by actors without any deeper technical knowledge or resources. These tools
include ransomware and other types of malwares, access to already compromised systems, and
complex services for phishing or vishing campaigns.
Vishing-as-a-service
Offers rental of voice systems
intended for carrying out of
vishing attacks.
Access-as-a-service
Offers access
to compromised accounts
or systems.
Phishing-as-a-service
Malware-as-a-service
Offers malware
for further use in
cyberattacks.
DDoS-as-a-service
Offers complex phishing services
starting with detailed tutorials to
e-mail templates or legitimate
looking malicious websites.
Offers access to infected devices
connected to the Internet (so-called
botnet) in order to carry out DDoS
attacks.
Cybercrime-as-a-service is therefore a business model enabling virtually any person with
sufficient funds to exploit tools or services for cyberattacks. This makes malicious cyber activity
more easily available even for relatively unexperienced attackers. Due to the growing popularity
of this model, which is capable of generating big profits, the competition within the market is
growing, resulting in a wider offering of products and better affordability. That, in return, makes
the provided services available to an even wider group of potential clients.
16