Israeli firm Bright Data named as enabler of Philippines government DDOS attacks on opposition groups
- Reference: 1629950408
- News link: https://www.theregister.co.uk/2021/08/26/qurium_bright_data_philippines_ddos/
- Source link:
In July, Qurium [1]reported that the Philippines Department of Science and Technology and Army had conducted DDOS attacks on local media critical of the nation's government, and targeted Karapatan.
Last week, Qurium [2]reported a new wave of attacks on Karapatan, detailing a three-week campaign felt to be aimed at derailing efforts to protest extra-judicial killings – including the death of a Karapatan member.
[3]
Now the organisation has [4]published analysis of the latest DDOS attacks, in which it alleges Israeli firm Bright Data aided the effort.
[5]
[6]
The organisation's analysis suggests that most of the DDOS traffic it detected came from mobile carriers in Russia and the Ukraine. Qurium also detected action coming from servers hosted by Digital Ocean and US-based cloud Choopa.
Qurium's analysis suggests that some of the servers used in the attacks employ proxies offered by Bright Data, which offers proxies-as-a-service.
[7]
Such services have legitimate uses to speed traffic, but can also allow creepy observation of traffic and lead to privacy abuses. Bright Data, formerly known as Luminati Networks, was accused of such creepiness in a 2018 [8]report by security vendor Trend Micro.
That report noted that a VPN called HolaVPN had been [9]observed – by none other than 8Chan owner Fredrick Brennan – leaking user info to Bright Data.
Trend Micro alleged that HolaVPN users became exit nodes for Bright/Luminati's services.
[10]
"If the user's machine happens to be part of a corporate network, its being an exit node may provide unknown third parties possible entry to company systems," Trend stated. "HolaVPN could enable attackers to circumvent corporate firewalls and allow them to explore the internal network of a company for nefarious purposes.
"Aside from this, HolaVPN users' bandwidths are being sold via Luminati and could end up being part of botnet activity facilitated by the network. It could also enable cybercriminals to perform different illegal or unauthorized activities on users' machines."
[11]Facebook and Amazon take over Philippines-to-USA sub cable after China Mobile quits
[12]Philippines national ID registration portal opens, glitches out in first hour
[13]30 percent of world agrees not to require onshore storage for e-commerce customer data
[14]Big Tech’s Asian lobby says nations shouldn’t go it alone on tech taxes
Back to the Philippines, and Qurium alleges that the government employed Bright Data to provide rapidly-changing IP addresses – up to 100 an hour – to target Karapatan.
"At the beginning of our research, we speculated that this behavior could be the result of a 'pay as you go' stress-testing service that allowed a maximum of one hour attack time," Qurium's post states. "After several days monitoring the web site we could determine that the traffic patterns were the result of Luminati automatically rotating their residential and mobile proxies in an hourly basis."
Qurium states it asked Bright Data for an explanation and received a response that included the following:
The IPs from the list you have attached (attaching it again) belong to Bright Data, however we did not find any of them in the requests that were sent to the reported domain.
Bright Data claims it is an ethical organisation and vets all peers, partners, and customers to ensure they use its services appropriately.
But that's just what another Israeli outfit – NSO Group – said before it was [15]accused by Amnesty International of not doing enough to prevent abuse of its spyware.
Qurium's naming of another Israeli firm as a player in state-run naughtiness throws a little more fuel on the fire.
The Register has approached Bright Data for comment, and will update this story if substantial information becomes available. ®
UPDATE 0700 UTC August 26th - Bright Data has sent The Register the following statement.
"Bright Data had absolutely no connection to the reported incident, and the Qurium report is categorically false, unprofessional, and unethical. Qurium approached Bright Data just before they published the false report, and even though Bright Data showed Quirum’s researchers that their report was blatantly wrong, they chose to ignore Bright Data and the facts.
Qurium acted recklessly, if not intentionally, without any effort to look into the facts Bright Data presented. Moreover, they did not even sign up for Bright Data's service to see how it works. One example: the report mentions servers that are not Bright Data's and communication ports that were always blocked on Bright Data's platform. Make no mistake, their report constitutes actionable defamatory content.
One can only wonder what lies behind Qurium’s motivation to make such false accusations. We demand that Qurium retract the report and issue a public apology. We expect it to happen immediately, and we will not hesitate to go to great lengths to make this happen."
Get our [16]Tech Resources
[1] https://www.theregister.com/2021/07/02/ddos_attack_philippines_dost/
[2] https://www.qurium.org/alerts/philippines/human-rights-alliance-karapatan-under-long-lasting-ddos-attack/
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YSdmZoS4iJ2ZVLZAlfARXwAAANQ&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[4] https://www.qurium.org/alerts/philippines/israeli-firm-bright-data-luminati-networks-enabled-the-attacks-against-karapatan/
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YSdmZoS4iJ2ZVLZAlfARXwAAANQ&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YSdmZoS4iJ2ZVLZAlfARXwAAANQ&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YSdmZoS4iJ2ZVLZAlfARXwAAANQ&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[8] https://www.trendmicro.com/vinfo/hk-en/security/news/cybercrime-and-digital-threats/shining-a-light-on-the-risks-of-holavpn-and-luminati
[9] https://web.archive.org/web/20150716000554/https://8ch.net/hola.html
[10] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YSdmZoS4iJ2ZVLZAlfARXwAAANQ&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[11] https://www.theregister.com/2021/08/16/china_mobile_quits_cap_1_submarine_cable/
[12] https://www.theregister.com/2021/05/04/philsys_online_registration_portal/
[13] https://www.theregister.com/2020/11/16/regional_comprehensive_economic_partnership_data_sharing/
[14] https://www.theregister.com/2020/10/14/asia_internet_coalition_tax_argument/
[15] https://www.theregister.com/2021/07/19/mass_misuse_of_nso_pegasus_spyware_alleged/
[16] https://whitepapers.theregister.com/
I hate to say this, but
It's time for Governments to get involved. There are too many networks claiming high standards of operation while taking in money to host craploads of illegal network abuse. It's at the regional networks, the hosting providers, and all the way up to the Tier 1 transit networks providing hostile networks with connectivity. Their attitude right now is that they absolutely don't care. No working abuse contact of any kind. Criminals pay money, victims don't.
I know the Internet is supposed to be self-healing but there's a practical limit to just how many firewall rules one can maintain. DDoS are difficult to block when there's a crime-friendly network one or two hops upstream. Companies pay CloudFlare or Akamai for protection while they serve the carders, phishers, and C&C systems helping to fund the attacks.
Yeah, the Internet is bad enough that I think Government intervention will make it better. Sad times.
https://www.abuseipdb.com/statistics
https://www.spamhaus.org/news/article/813/spamhaus-botnet-threat-update-q2-2021
Re: I hate to say this, but
Read the article. A government certainly did get involved. Perhaps not in the way you are alluding to, but a much more realistic picture of how governments actually get involved.
Don't count on any government to react with anything but 'good idea, how do we exploit it' while also informing the media that they are trying to pass legislation forbidding the exact thing they are currently implementing.
Also, when it comes right down to it, which country gets to legislate anything on a global network that anyone outside that country would listen to? And how well do you trust that country?
You know you're in for some fun and games...
...and human rights abuses when the headline begins with "Israeli firm..."
Re: You know you're in for some fun and games...
The infosec equivalent to "Florida Man"?
Re: You know you're in for some fun and games...
Well it could equally well have been a French, British, or US company. In fact, I am sure that bad actors in all three countries would have been happy to be paid....
When a government attacks local human rights organisations, it can be considered as a bad actor.
Surprisingly, I didn't hear about any sanction against the Philippines .
"formerly known as Luminati Networks"
Oh, the conspiracy theories you could spin out of that !
Re: "formerly known as Luminati Networks"
That name looks designed to entice Apple into buying them.
What a surprise!
Yet another Israeli firm caught acting on behalf of despots and tyrants around the world and most likely supported by huge chunks of US cash and technical resources.
Fake DDOS = Fake anti-DDOS
If the DDOS attacks are fake, then so are the man-in-the-middle companies that defend against said fake DDOS attacks.
Do you imagine they just sell your connection data and not the content aswell?
https://www.vice.com/en/article/jg84yy/data-brokers-netflow-data-team-cymru
Yet so much effort is put in, to putting these companies in between you and your customers.