Back Uk.Pcmag Pro-Iran Hackers Hit Ubuntu's Canonical With DDoS, Float Extortion Demand
If you’re having trouble accessing websites for the Linux distribution Ubuntu , an ongoing DDoS attack is to blame.
On Friday, Ubuntu developer Canonical confirmed the DDoS, which involves hackers summoning a burst of internet traffic to overwhelm and take down a website or server. “Canonical’s web infrastructure is under a sustained, cross-border attack and we are working to address it,” it tweeted . “We will provide more information in our official channels as soon as we are able to.”
The attack appears to have shut down access to Canonical’s main site and the Ubuntu.com domain, though PCMag was able to load some related pages. A pro-Iranian hacking group, the Islamic Cyber Resistance in Iraq, also known as the 313 Team, has claimed responsibility for the DDoS assault, which began on Thursday.
“The attack on all Ubuntu servers remains ongoing,” the group wrote on the chat app Telegram, while issuing an extortion demand. “As a reminder, our communication channels remain open for Ubuntu to us so that we may agree on a ceasefire.” X appears to have suspended the group's account since then.
Team 313 also claims to be using a relatively new DDoS-for-hire service called Beamed to target as many as 14 Ubuntu-related domains. Since then, a few Ubuntu users have reported trouble updating their systems. The DDoS occurs at an inconvenient time; Canonical issued an advisory a newly disclosed high-severity Linux flaw, dubbed “ Copyfail ,” which can allow a local user to gain root privileges on a Linux-based OS.
All Linux distributions published since 2017 are affected, although the vulnerability doesn’t affect PC users as much as cloud providers that host multiple users on a single Linux server, effectively sharing access.
Due to the ongoing DDoS, Canonical’s blog post on Copyfail, with mitigations, has remained down, although users can still access it via the Internet Archive. "Linux kernel packages which implement the proposed patch will be released," the company adds.
The DDoS occurs amid the ongoing US-Iran conflict, which has led to an increase in Iranian-linked hacking efforts, including an attack that wiped devices at a medical equipment provider, Stryker. The FBI later attributed the attack to Iran’s Ministry of Intelligence and Security. It's unclear if 313 Team is directly tied to the Iranian government, but the hacktivist group has engaged in anti-Israel and anti-US rhetoric. That said, Canoncial is a UK-based company.
Team 313 also says it was behind DDoS attacks on eBay this past weekend and the social media platform Bluesky earlier this month. EBay didn’t confirm the DDoS, merely telling PCMag it was aware of “intermittent technical issues.” However, Bluesky attributed its outage to a DDoS attack, which forced employees to work through the night to restore services.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
