{"id":2380,"date":"2024-01-18T17:13:00","date_gmt":"2024-01-18T17:13:00","guid":{"rendered":"https:\/\/www.darkreading.com\/ics-ot-security\/bangladeshi-elections-ddos-crosshairs"},"modified":"2024-01-18T17:13:00","modified_gmt":"2024-01-18T17:13:00","slug":"bangladeshi-elections-come-into-ddos-crosshairs","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/01\/18\/bangladeshi-elections-come-into-ddos-crosshairs\/","title":{"rendered":"Bangladeshi Elections Come into DDoS Crosshairs"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/bltad38caa427202d6d\/64f17978edca011e8c7e2e2d\/bangladesh_flag_Muhammad_Toqeer_alamy.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/01\/bangladeshi-elections-come-into-ddos-crosshairs.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/01\/bangladeshi-elections-come-into-ddos-crosshairs.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The end of 2023 saw an uptick in distributed denial-of-service (DDoS) traffic across major industries in Bangladesh, and it may have been geared to disrupt the latest national elections.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Last week, it came to light that a <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/bangladesh-election-app-crashes-amid-suspected-cyberattack\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">mobile app providing critical information to Bangladeshi voters<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> ahead of those elections was targeted by cyberattackers. As Dark Reading reported at the time, the Bangladeshi Election Commission claimed it was one of the latest victims of a DDoS attack. It turns out, the disruption effort could have been part of a much more widespread campaign to meddle with the national vote.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">According to exclusive data provided to Dark Reading by Cloudflare, the end of 2023 in Bangladesh, running up to the vote, saw a 33% quarter-over-quarter jump in HTTP DDoS attack traffic. More than half of that was directed at the telecommunications industry, with the rest spread among other crucial sectors; media and newspapers was the next most-targeted industry, with banking, financial services, and insurance following closely behind.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;Telecommunication companies might be targeted by DDoS attacks before elections to disrupt communication channels, thereby hindering the dissemination of information and potentially impacting voter communication and coordination,&#8221; a representative of Cloudflare writes in an email to Dark Reading. &#8220;Such attacks could be politically motivated to create confusion, suppress voter turnout, or undermine the credibility of the electoral process.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Cloudflare&#8217;s spokesperson also says that media production and newspaper companies may have been targeted by DDoS attacks before elections to disrupt the flow of information and influence public opinion, often driven by political motivations or to undermine trust in key institutions: &#8220;These attacks can also serve as a tactic to test defenses, spread misinformation, or serve economic interests through extortion.&#8221;<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\">Did European DDoSers Affect an Election App in Bangladesh?<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/play.google.com\/store\/apps\/details?id=com.electioncommissionsecretariat.sembd&amp;hl=en_US&amp;pli=1\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">Smart Election Management BD<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> is a government-run app providing Bangladeshi citizens with all kinds of election-related information \u2014 about voting locations, political parties, candidates, vote totals, and so on \u2014 though it is not a means of electronic voting. It has more than 500,000 downloads on Google Play. The Smart Election app remained live throughout Election Day on Jan. 7, in which the incumbent prime minister Sheikh Hasina Wazed won her fourth straight term. However, voters reported performance issues, including slowdowns, according to <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/www.dhakatribune.com\/bangladesh\/336109\/ec-secretary-cyber-attack-on-smart-ec-app-from-2\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">reporting by the Dhaka Tribune<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Mohammed Jahangir Alam, secretary of the Bangladesh Election Commission announced that the app had been struck by a cyberattack. But more curiously, he claimed the bad traffic originated in Germany and Ukraine.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The origination data often provides clues as to the motivations and actors behind politically motivated hacks \u2014 though there&#8217;s no obvious geopolitical tension that would explain why Western European or Ukrainian assailants would be involved in the politics of Bangladesh. And according to Cloudflare data, Bangladesh&#8217;s DDoS problem is well dispersed. Around 15% of Q4 2023 attack traffic came from the US, and 9% from Indonesia, with Brazil, Japan, India, Germany, and Russia following behind with around 4-5% apiece.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;In many cases, we see one main source country for DDoS attacks targeting another. For example, more than 80% of HTTP DDoS attack traffic targeting Taiwan [last year] originated from China,&#8221; says the spokesperson. &#8220;But in the case with Bangladesh &#8230; the source country list seems to be quite distributed, perhaps indicating the use of globally distributed botnets.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Dark Reading reached out to the office of the Bangladesh Election Commission Secretary for further evidence to support Alam&#8217;s assertion, but did not receive a reply by the time of publishing.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\">The DDoS Threat to Elections<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">When it comes to election malfeasance, the firm&#8217;s contact says, &#8220;we expect to see a continuation of <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/www.darkreading.com\/threat-intelligence\/ddos-attack-targets-uk-labour-party-weeks-ahead-of-election\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">what we have seen in previous years<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">. There will likely be ongoing online cyberattacks against entities in the election space \u2014 not only candidates and campaigns, but vulnerable nonprofits and other groups that help encourage voting and monitor elections.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">That said, DDoS might be a bigger player in global elections from now on than it has been, according to Cloudflare. The person adds, &#8220;The threat of DDoS attacks are evolving quickly, and are far from a low-level annoyance that they used to be thought of as. New emerging tech will only work to amplify the attack tactics of nation-states and affiliated groups. Threat actors will rely not only on the tried-and-true phishing tactics deployed in previous elections but also more widespread use of new tools that leverage emerging tech \u2014 like AI-optimized DDoS attacks.&#8221;<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/ics-ot-security\/bangladeshi-elections-ddos-crosshairs\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>The end of 2023 saw an uptick in distributed denial-of-service<\/p>\n","protected":false},"author":12,"featured_media":2381,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-2380","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/01\/bangladeshi-elections-come-into-ddos-crosshairs-scaled.jpg?fit=2560%2C1440&ssl=1",2560,1440,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/01\/bangladeshi-elections-come-into-ddos-crosshairs-scaled.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/01\/bangladeshi-elections-come-into-ddos-crosshairs-scaled.jpg?fit=300%2C169&ssl=1",300,169,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/01\/bangladeshi-elections-come-into-ddos-crosshairs-scaled.jpg?fit=640%2C360&ssl=1",640,360,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/01\/bangladeshi-elections-come-into-ddos-crosshairs-scaled.jpg?fit=640%2C360&ssl=1",640,360,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/01\/bangladeshi-elections-come-into-ddos-crosshairs-scaled.jpg?fit=1536%2C864&ssl=1",1536,864,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/01\/bangladeshi-elections-come-into-ddos-crosshairs-scaled.jpg?fit=2048%2C1152&ssl=1",2048,1152,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/01\/bangladeshi-elections-come-into-ddos-crosshairs-scaled.jpg?fit=1024%2C576&ssl=1",1024,576,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/01\/bangladeshi-elections-come-into-ddos-crosshairs-scaled.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/01\/bangladeshi-elections-come-into-ddos-crosshairs-scaled.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/01\/bangladeshi-elections-come-into-ddos-crosshairs-scaled.jpg?fit=2560%2C1440&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/2380","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=2380"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/2380\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/2381"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=2380"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=2380"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=2380"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}