In conjunction with #OpIcarus2018, hacker “SHIZEN” of Pryzraky has launched a series of web attacks and DDoS against central banks worldwide. Chief among them was an attack on the Central Bank of the Bahamas, which was downed for well over 24 hours between the dates of December 12th to 14th, 2018. As of 9 a.m. Friday morning the banks official website appears to be back up and running again, but the sites administrators have had to install Cloudflare just to make this happen.
Upon investigating the website further, the sites theme manager and developer, Thyme Online, has still yet to even install an active SSL certificate for the website and its front-end still suffers from a lack of basic and fundamental security measures. According to their web page, the Central Bank of the Bahamas currently manages over 55 million dollars in assets, but it remains unclear how much a financial impact the latest cyber attack has had on their business.
According to SHIZEN, “The Central Bank Of Bahamas it’s an easy target, the website is protected by Cloudflare but as long as the DDoS doesn’t exceed the 1 TBPS limit. I have attacked with a Python Script named: http://leet.py & http://blastaered.pl The website has been taken down for 28 hours before it was changed over to Cloudflare, now if you make an check-host you can see an error “503 (Service Temporarily Unavailable)”, the website works because he have changed the Cloudflare, so I think I’ll try to take down it with an IRC Botnet or an MIRAI next.” Rogue Security Labs has reached out to the Bahamas Central Bank for comment on the incident, but as of December 15th 2018 the bank has declined to respond.
Website Hit: hxxp://centralbankbahamas.com
American Bank Proxy: 18.104.22.168
Target Behind Cloudflare: 22.214.171.124
New attack for the OpIcarus:
* Target: The Central Bank of Bahamas ~ https://t.co/r3k76Lo35v #Offline
* #Down: https://t.co/m9ZaWZHO9c
—————————————————————————————–#TangoDown – #Pryzraky – #OpIcarus2018 – @LorianSynaro pic.twitter.com/FFajUuCdYN
— SHIZ3N 🇵🇸 aka ToXiCBoY (@zglobal_) December 13, 2018
— LulzSec Argentina (@LulzSeguridad) December 14, 2018
~*~ 000.Tak3dD0wn ~*~
Central Bank Of Bahamas Down Since 24 hours !!
* URL: https://t.co/r3k76Lo35v
* Check-Report: https://t.co/W3ZEdqIEGo@LorianSynaro – @zataz – @Mecz1nho – @Pryzraky – @LabDefCon – @Rogu3_Labs @M1r0x__ pic.twitter.com/iaiSVVwJse
— SHIZ3N 🇵🇸 aka ToXiCBoY (@zglobal_) December 14, 2018
Categories: Hacking News