Subscribe to CIO Magazine »

Anonymous dupes users into joining Metaupload attack

Recruits accomplices by spreading links via Twitter that auto-starts attack tool

The Anonymous hacking group recruited unwitting accomplices in Thursday's attacks against U.S. government sites, a security researcher said today.

The distributed denial-of-service (DDoS) attacks began Thursday just hours after the U.S. Department of Justice announced arrests of four men associated with the popular Megaupload "cyberlocker" site on charges of copyright infringement, money laundering and racketeering.

Federal authorities shuttered and other sites, and seized assets belonging to the company, including hundreds of servers. Three of the seven men indicted remain at large, but four were arrested in New Zealand by local authorities and face extradition to the U.S.

Almost immediately, Anonymous retaliated with DDoS attacks against Justice's website, and those operated by Universal Music, the Recording Industry Association of America (RIAA), the Motion Picture Association of America (MPAA), and others. Some of those sites were inaccessible during parts of Thursday.

In a message on Twitter and in a blog post, Anonymous claimed Thursday's DDoS attacks were its largest ever, and said that 5,600 people collaborated in the assaults.

Previously, Anonymous had said that its followers were using the Low Orbit Ion Cannon (LOIC) tool, a favorite of the group since its first widespread DDoS attacks in December 2010.

But some of the 5,600 who participated may have done so unwittingly, said Graham Cluley, a senior technology consultant with U.K.-based antivirus vendor Sophos.

According to Cluley, members of Anonymous distributed links via Twitter and elsewhere that when clicked automatically launched a Web version of LOIC. The links pointed to a page on, a free HTML code-hosting site, which in turn executed some JavaScript to fire LOIC at Anonymous-designated targets.

Many of those messages said nothing about LOIC or that clicking the link shanghaied the user into the DDoS attack, Cluley said, noting several Twitter messages as examples.

In an email reply to questions today, Cluley said that while the links were launching LOIC against more than one website, "It's clear that is getting a lot of attention."

The Department of Justice's website was operating normally early Friday.

Anonymous is still recruiting people to its campaign. A quick search of Twitter using a string published on indicated that the link was being shared Friday morning at the rate of about 10 to 18 times per minute on the micro-blogging site.

On a Sophos blog , Cluley reminded readers that DDoS attacks were illegal, and cautioned users to be wary of clicking links.

"Anonymous might be hoping that participants could argue that they did not knowingly assist in the DDoS attack, and clicked on the link in innocence without realizing what it would do," said Cluley.

Gregg Keizer covers Microsoft, security issues, Apple, Web browsers and general technology breaking news for Computerworld. Follow Gregg on Twitter at @gkeizer , on Google+ or subscribe to Gregg's RSS feed . His e-mail address is .

See more articles by Gregg Keizer .

Read more about cybercrime and hacking in Computerworld's Cybercrime and Hacking Topic Center.

Join the CIO Australia group on LinkedIn. The group is open to CIOs, IT Directors, COOs, CTOs and senior IT managers.

More about: Apple, Department of Justice, DOJ, Google, Microsoft, Motion, Motion Picture Association of America, Recording Industry Association of America, Sophos, Topic
References show all
Comments are now closed.
Related Whitepapers
Latest Stories
Community Comments
Latest Blog Posts
  • How to Successfully Select an ERP System
    An Enterprise Resource Planning (ERP) system is a series of software applications that collect and compiles data from different departments to enhance collaboration and co-ordination within the business. If you’re looking to implement your first ERP system, or to upgrade from an existing system, this whitepaper offers eight simple steps for selection that will lead to long-term strategic success.
    Learn more »
  • Delphix and Pure Storage Team to Super-Charge Database Deployments
    This webcast presentation, prepared by Delphix and Pure storage, explores super-charge database deployments and how they can aid business strategy. The presentation details the main features of a new flash solution – high performance, inline data reduction, resilience and scalability, and the value of simplicity. Viewers can learn how to put an end to inefficient or delayed QA, Sharing DB environments, using DB subsets and slow environment builds.
    Learn more »
  • Top 20 Critical Security Controls - Compliance Guide
    Simply being compliant is not enough to mitigate attacks and protect critical information. Organizations can reduce chances of compromise by shifting away from a compliance-driven approach. This guide provides the Top 20 Critical Security Controls (CSCs) developed by the SANS Institute to address the need for a risk-based approach to security.
    Learn more »
All whitepapers
rhs_login_lockGet exclusive access to Invitation only events CIO, reports & analysis.
Latest Jobs
Salary Calculator

Supplied by

View the full Peoplebank ICT Salary & Employment Index

Recent comments