2 min read

Colorado State Website Attacked by Russian Hacktivists

Colorado State Website Attacked by Russian Hacktivists

Originally published 10/19/2022

I. Targeted Entities

  • Colorado’s official website

II. Introduction

Colorado state officials say that on Wednesday, October 5, 2022, Colorado’s website was rendered unusable after an apparent cyberattack following a Telegram post by a known Russia-based hacker group announcing it would target U.S. state websites. While the U.S. election system is largely disconnected from the Internet, state websites are prime targets for hackers who want to undermine confidence in elections.

III. Background Information

The cyberattack flooded the state’s website with traffic, and it is a common, simple way to disable websites. There is no indication that any of Colorado’s internal systems were accessed or that its election systems were compromised.[1] However, given how close this attack is to the U.S. midterms, experts say it could give the false impression that U.S. elections are vulnerable to foreign interference.[1]

Killnet, the group responsible for the attack, is a Russian-aligned collective that claims to be composed of amateur hacktivists who support Russia’s international interests. Killnet adheres to the same model as Ukraine’s IT Army (a Ukrainian government-affiliated movement that frequently posts lists of Russian websites on Telegram for supporters around the globe to try to overwhelm them with traffic). The tactic Killnet uses to overwhelm websites with traffic is known as a distributed denial of service, or DDoS.[1] On Wednesday, KillNet posted a list of 12 target states to its Telegram channel: Alabama, Alaska, Colorado, Connecticut, Delaware, Florida, Hawaii, Idaho, Indiana, Kansas, Kentucky, and Mississippi.[1]

It is unclear if other states were affected, but federal officials have repeatedly stated that they do not expect a cyberattack to affect the midterm elections. The Cybersecurity and Infrastructure Security Agency (CISA), which oversees federal cybersecurity support for election infrastructure, released a joint announcement with the FBI saying, “any attempts by cyber actors to compromise election infrastructure are unlikely to result in large-scale disruptions or prevent voting.”[2]

Because DDoS attacks are easy to carry out and don’t cause lasting damage or grant criminals access to sensitive information, cybersecurity professionals and other hackers generally regard them as unimpressive. However, Killnet has started becoming more effective at making websites unreachable and has the potential to cause significant disruptions.[1]

IV. MITRE ATT&CK

  • T1498 – Network Denial of Service
    Killnet performed a DDoS attack to degrade and block the availability of targeted websites. Network DoS can be performed by exhausting the network bandwidth services that services rely on.

V. Recommendations

  • Set antivirus programs to conduct regular scans
    Ensure that antivirus and antimalware programs are scanning assets using up-to-date signatures
  • Monitor malware
    Continuously monitor current and new types of malware. Stay up to date on intel and advancements to prevent, defend, and mitigate these types of threats.
  • Turn on endpoint protection
    Enable endpoint detection and response (EDR) to stop unknown malware in the product you’re using.

VI. Indicators of Compromise (IOCs)

Because of the nature of this threat advisory, there are no IOCs. However, it is important that businesses and entities create a business continuity and disaster recovery plan in case a DDoS attack occurs.

VII. References

(1) Collier, Kevin. “Cyberattack on Colorado State Website Follows Russian Hacktivist Threat.” NBCNews.com. NBCUniversal News Group, October 6, 2022. https://www.nbcnews.com/tech/security/colorado-state-websites-struggle-russian-hackers-vow-attack-rcna51012.

(2) “Malicious Cyber Activity Against Election Infrastructure Unlikely to Disrupt or Prevent Voting.” FBI & CISA Public Service Announcement, October 4, 2022. https://www.cisa.gov/uscert/sites/default/files/publications/PSA_cyber-activity_508.pdf.

Contributing Security Analysts: Dorian Pope, Sreten Dedic, EJ Bulut, and Uday Bilakhiya.

Other posts of interest...

Microsoft Releases Workaround for Zero-Day Flaw

1 min read

Microsoft Releases Workaround for Zero-Day Flaw

Originally published: 06/16/2022 I. Targeted Entities Microsoft Office users II. Introduction Microsoft has recently established a workaround for a...

Read More
Phishing Attacks Increase as Facebook and Microsoft are Most Abused

1 min read

Phishing Attacks Increase as Facebook and Microsoft are Most Abused

Published 8/1/2022 I. Targeted Entities Microsoft, Facebook, and other large tech brands II. Introduction Phishing attacks exploiting the Microsoft...

Read More
REvil is Back and Executes DDoS Attacks

1 min read

REvil is Back and Executes DDoS Attacks

Originally published 06/06/2022 I. Targeted Entities Akami Technologies Incorporated and customers II. Introduction A recent denial-of-service...

Read More