Skip to main content

Hackers hijacked traffic through Amazon servers for two hours, undetected

The event, which only lasted about two hours on Tuesday, April 24, saw traffic to Amazon’s cloud web hosting servers redirected to malicious websites. Not all of the traffic, just a small slice of it, about 1,300 IP addresses, according to Oracle. The attack saw traffic to MyEtherWallet redirected a malicious version of itself, where the attackers could siphon cryptocurrency off of users who thought they were logging into their cryptocurrency wallets.

One such site, MyEtherWallet, was cloned by attackers but likely didn’t result in the kind of massive theft we’re used to seeing when cryptocurrency wallets or exchanges are attacked. According to Ars Technica, the cryptocurrency wallet into which the fake MyEtherWallet site was dumping its cryptocurrency already had about $27 million worth of cryptocurrency in it.

Recommended Videos

Details like this have led some to believe the attack could have been state-sponsored, potentially with ties to Russia.

“So far the only known website to have traffic redirected was to MyEtherWallet.com, a cryptocurrency website. This traffic was redirected to a server hosted in Russia, which served the website using a fake certificate — they also stole the cryptocoins of customers,” wrote security researcher Kevin Beaumont. “The attacks only gained a relatively small amount of currency from MyEtherWallet.com — however their wallets in total already contained over [20 million pounds] of currency. Whoever the attackers were are not poor.”

It may not have been the first time these hackers have staged such an attack either, according to Ars. There were a couple suspiciously similar attacks in 2013 when hackers hijacked internet traffic to a number of U.S. companies, routing the traffic through Russian ISPs. Affected companies included Visa, MasterCard, Apple, and Symantec. Eight months later, another set of U.S. companies saw their traffic hijacked with the same kind of exploit.

These 2013 attacks used the same “border gateway protocol” exploit as today’s attack. Beaumont elaborated that today’s attack requires access to sophisticated equipment, which leads him to believe MyEtherWallet was not likely the only target — just the one we happened to notice.

“Mounting an attack of this scale requires access to BGP routers are major ISPs and real computing resource to deal with so much DNS traffic. It seems unlikely MyEtherWallet.com was the only target, when they had such levels of access,” Beaumont wrote. “Additionally, the attackers failed to obtain an SSL certificate while man-in-the-middle attacking the traffic — a very easy process — which alerted people to the issue at scale.”

Jaina Grey
Former Digital Trends Contributor
Jaina Grey is a Seattle-based journalist with over a decade of experience covering technology, coffee, gaming, and AI. Her…
Kagi’s AI search assistant gives you access to all the big models in one place
Kagi search bar in light mode.

Kagi's "Assistant" feature, previously only available to Ultimate subscribers, is now rolling out to all tiers -- including the free trial tier. The feature gives you access to a range of different LLMs for both chatting and web-searching purposes.

If you don't know much about Kagi, it's a paid search engine that borrows its name from the Japanese word for "key." The concept is simple -- with Google, you pay for the service by allowing ads and data collection. With Kagi, you pay for the service with money to get a private and ad-free experience.

Read more
Leaked specs for AMD’s RX 9070 GRE reveal something gamers really need
The XFX logo on the RX 7900 GRE.

AMD's RX 9070 XT made it onto every ranking of the best graphics cards shortly after launch, but many gamers are waiting for more. With spotty availability and trouble finding a GPU at MSRP, we're left hoping that AMD will have new GPUs coming out soon. Good news: It looks like AMD has something up its sleeve, and we just learned the specs. Spoiler alert: One of the specs is something that gamers might love.

VideoCardz leaked the specs for the RX 9070 GRE, which stands for "Great Radeon Edition." In the previous generation, the RX 7900 GRE ended up being one of the top GPUs in terms of value for the money, and it did a good job of bridging the gap between the higher-end and the mainstream cards. It looks like that might be the case in this generation, too, although remember -- this is just a leak and nothing is certain until AMD says so.

Read more
Need new office furniture? Get up to 20% off from the Steelcase Spring Sale
Steelcase office furniture in a home office.

If you want to boost your productivity at your home office or small business, upgrading your devices with desktop computer deals is just the start. Your office furniture should also be designed specifically to meet your needs across long workdays, so that you can stay comfortable and remain focused the whole time. You'll get these benefits with Steelcase office furniture, and you're in luck because the brand just launched a Spring Sale for a 20% discount on office chair deals, standing desk deals, and more.

The Steelcase Spring Sale is an excellent source of savings, whether you're thinking of overhauling your office or you just need to replace one piece of furniture. Feel free to browse everything that's on sale through the link below, or check out our recommendations. Either way, you'll have to act fast because stocks of the brand's more popular items may sell out sooner than you expect.

Read more