Want to read Slashdot from your mobile device? Point it at m.slashdot.org and keep reading!

 



Forgot your password?
typodupeerror
Botnet Crime The Internet

Oregon Man Accused of Operating One of Most Powerful Attack 'Botnets' Ever Seen (msn.com) 23

A 22-year-old Oregon man has been charged with operating one of the most powerful botnets ever recorded. The network, known as Rapper Bot, launched over 370,000 DDoS attacks worldwide, including against X, DeepSeek, U.S. tech firms, and even Defense Department systems. It was allegedly operated by Ethan Foltz of Eugene, Oregon. The Wall Street Journal reports: Foltz faces a maximum of 10 years in prison on a charge of abetting computer intrusions, the Justice Department said in a news release. Rapper Bot was made up of tens of thousands of hacked devices and was capable of flooding victims' websites with enough junk internet traffic to knock them offline, an attack known as a distributed denial of service, or DDoS.

In February, the networking company Nokia measured a Rapper Bot attack against a gaming platform at 6.5 trillion bits per second, well above the several hundred million bits a second of the average high-speed internet connection. "This would place Rapper Bot among the most powerful DDoS botnets to have ever existed," said a criminal complaint that the prosecutors filed Tuesday in a federal court in Alaska. Investigators said Rapper Bot's attacks were so powerful that they were able to overwhelm all but the most robust networks.

Foltz allegedly rented out Rapper Bot to paying customers, including gambling website operators who would use the network in extortion attempts, according to the complaint. The botnet was used to launch more than 370,000 attacks in 80 countries, including China, Japan and the U.S., prosecutors said. It launched its attacks from hacked routers, digital video recorders and cameras, not from computers. [...] "At its height, it mobilized tens of thousands of devices, many with no prior role in DDoS," said Jerome Meyer, a researcher with Nokia's Deepfield network-analysis division. "Taking it down removes a major source of the largest attacks we see."

This discussion has been archived. No new comments can be posted.

Oregon Man Accused of Operating One of Most Powerful Attack 'Botnets' Ever Seen

Comments Filter:
  • by ndsurvivor ( 891239 ) on Wednesday August 20, 2025 @08:06PM (#65603842) Journal
    Second thought... is to get the manufacturers to force users to set up a more secure password and to disallow the use of the "master password" after a few days. Well, you know what I mean.
    • Came here to say the same thing. It's the utter lack of security on IoT devices that allow this kind of nonsense. Companies that create these insecure IoT devices that are included in the bot-nets need to be held accountable too. Perhaps that will be the incentive they need to make devices more robust and force owners to actually set up security in the first place before the device will operate.

    • First, hang him by his balls.
  • Looks can deceive.

  • Only ten years? (Score:3, Insightful)

    by Inoshiro ( 71693 ) on Wednesday August 20, 2025 @11:03PM (#65604056) Homepage

    "The botnet was used to launch more than 370,000 attacks in 80 countries, including China, Japan and the U.S., prosecutors said."

    And no one was harmed or killed? Normally manslaughter to murder 1 (in the USA) is 10 years to life. A third of a million attacks targeting 37% of all nations on this panet gets at most TEN years? What the fuck is wrong with the US justice system?!?

    They might as well start pardoning the criminals in DC (oh, right, they did that in January). What a banana republic

  • by JustAnotherOldGuy ( 4145623 ) on Wednesday August 20, 2025 @11:47PM (#65604088) Journal

    Was it DamnOregonian [slashdot.org] up to his old tricks again??

  • by registrations_suck ( 1075251 ) on Thursday August 21, 2025 @01:41AM (#65604194)

    Gambling site operators were using a botnet to DDoS targets that they would extort.

    Interesting. I would like to know more.

    Did the extortion have anything to do with the gambling?

    Were the gambling site operators DDoSing their own customers, or customers of competing websites?

    Was the extortion just some new side business by the gambling sites?

    Did the gambling sites make more money from gambling or extortion?

    I'm so confused.

  • by misnohmer ( 1636461 ) on Thursday August 21, 2025 @02:15AM (#65604216)
    When I see news articles that count trillions of bit per second, I immediately think "click bait, highest possible representation of a number to make something more sensational". I spent over 100 quadrillions of femtoseconds posting this.
  • by DrXym ( 126579 ) on Thursday August 21, 2025 @05:38AM (#65604400)
    Big networks have mitigations against bot attacks. At best they suffer some minor disruption or slow down for a bit, at worst they don't work at all. Somebody in possession of all those hacked machines is wasting the potential of their botnet doing something so overt.
  • by kackle ( 910159 ) on Thursday August 21, 2025 @12:23PM (#65605266)
    Posting to undo mistaken moderation.
  • He's gonna enjoy prison...

If A = B and B = C, then A = C, except where void or prohibited by law. -- Roy Santoro

Working...