
What Is a Ransom DDoS Attack?
A ransom DDoS (RDDoS) attack is when malicious parties attempt to extort money from an individual or organization by threatening them with a distributed denial-of-service (DDoS) attack. The malicious party may carry out a DDoS attack and then follow up with a ransom note demanding payment to stop the attack, or they may send the ransom note threatening a DDoS attack first. In the second case, the attacker may not actually be capable of carrying out the attack — although it is not wise to assume they are making an empty threat.
The best protection against DDoS ransom attacks is a strong DDoS mitigation service. It is never a good idea to pay the ransom to the person or group making the threats.
What Is a DDoS Attack?
A DDoS attack is an attempt to exhaust the resources of an application, website, or network so that legitimate users cannot receive service. DDoS attacks send a flood of junk network traffic to their targets — much like a traffic jam clogging up a freeway. DDoS attacks are “distributed,” meaning they send traffic from a variety of sources (often spoofed sources), making them more difficult to block than a denial-of-service (DoS) attack from a single source.
DDoS attackers use a number of different networking protocols. Read about different types of DDoS attacks here.
DDoS attacks can have a major impact on an organization’s operations. For many businesses, any downtime means a loss of revenue. Organizations may also lose credibility if they are offline for an extended period of time.
How Does a Ransom DDoS Attack Work?
Most DDoS ransom attacks start with a ransom note sent to the target in which the attacker threatens the business or organization. In some cases, an attacker may carry out a small demonstration attack to illustrate their seriousness before sending the ransom note. If the threat is genuine and the attacker decides to follow through, the attack unfolds as follows:
- Attack traffic begins. The attacker starts sending attack traffic to the target, using their own botnet, a hired DDoS service, or DDoS tools operated by multiple collaborators. Attack traffic can target layers 3, 4, or 7 in the OSI model.
- The target is overwhelmed. The targeted application or service becomes overwhelmed by the attack traffic, causing it to slow to a crawl or crash altogether.
- The attack continues until stopped. The attack persists until the attacker’s resources are exhausted, they shut it down for another reason, or the target successfully mitigates it. Mitigation methods include rate limiting, IP blocking, blackhole routing, or a dedicated DDoS protection service — the first three are difficult to implement against highly distributed attacks.
- Demands may escalate. The attacker may renew their demands for payment, carry out subsequent attacks, or both.
What Goes Into a Typical DDoS Ransom Note?
A DDoS ransom note is a message sent from a malicious party to a business demanding money — or else the malicious party will carry out a DDoS attack. These messages are often sent via email. Sometimes the attacker will send multiple messages, with each one revealing more details about their specific threats or demands. A typical ransom note contains some or all of the following elements:
The Threat
The threat contained in a DDoS ransom note can take a few different forms:
- The malicious party may take credit for a previous DDoS attack and threaten another one.
- They may take credit for a DDoS attack that is currently in progress against the target.
- They may threaten a future DDoS attack, either at a specific time or at an undefined time.
Details of the Threatened Attack
To make the threat sound more dangerous, the attacker may claim to be capable of carrying out a DDoS attack of a certain size and duration. These claims are not necessarily true: just because someone claims to be capable of a 3 Tbps attack lasting 24 hours does not mean they actually have the resources to follow through with it.
Group Affiliation
To add credibility to their threats, the attacker may claim affiliation with well-known hacker groups such as Fancy Bear, Cozy Bear, the Lazarus Group, the Armada Collective, or others. These claims might be true but are difficult to verify — they may represent a bluff or a copycat attempt on the part of the attacker.
Demand for Payment and Delivery Instructions
The ransom note will demand payment in some form. Payment in Bitcoin is a common request, but the attacker may also ask for payment in another cryptocurrency or a state-sanctioned currency (dollars, euros, etc.). At a certain point they will typically ask for a specific amount and provide instructions for delivering it.
Time Limit or Deadline
To give their demand urgency and increase the likelihood that the targeted party will comply, the ransom note will typically include a hard deadline for delivering payment. This time pressure is a deliberate tactic to discourage victims from seeking professional help or notifying authorities before paying.
Simple, Transparent Plans
No contracts. No hidden fees. Cancel anytime.
Call Forwarding
- 1 toll-free number with your choice of prefix
- 100 free inbound minutes per month
- Additional minutes at 5.9¢/min
- Auto attendant and voicemail included
- Call recording and virtual fax
- Interactive voice response (IVR)
- AI receptionist — no monthly fee, just 15¢/min
eBizLine Lite
- 1 toll-free number per user
- Unlimited inbound and outbound calling
- Call forwarding at just 2¢/min
- Mobile and desktop softphone apps
- Auto attendant, voicemail, and call recording
- Lead management tools
- SMS text messaging and IVR
- AI receptionist — no monthly fee, just 13¢/min
Business Phone Basic
- 1 toll-free number per user
- Everything in eBizLine Lite
- Call forwarding at 1.2¢/min
- Email, SMS, and workflow automation
- Microsoft Teams integration
- Advanced call analytics and reporting
- Priority support
- AI receptionist — no monthly fee, just 10¢/min