Mirai botnet did not knock Liberia's internet offline, say security experts

West African country didn't suffer nationwide outage last week, contrary to reports

Security experts have dismissed last week's reports that Liberia's entire internet infrastructure was taken down by a DDoS attack, stating that this story was "simply not true".

Despite widespread coverage, the claims were debunked by security expert Brian Krebs who found that contrary to reports, the attack did not cause a nationwide outage. He spoke to Daniel Brewer, general manager for the Cable Consortium of Liberia, who told him that "we have no knowledge of a national internet outage and there are [sic] no data to [substantiate] that."

The reports stemmed from security architect Kevin Beaumont, who noticed attacks on Liberian telecoms infrastructure while monitoring the activity of the Mirai botnet. He apparently spoke to an anonymous source withing a local telco, who supposedly confirmed that the country's single submarine internet cable - which Beaumont pointed to a "single point of failure" - was under 500Gbps attacks.

"From monitoring, we can see websites hosted in country going offline during the attacks," he wrote. "Additionally, a source in country at a Telco has confirmed to a journalist they are seeing intermittent internet connectivity, at times which directly match the attack."

Many news outlets (including IT Pro) took this to mean that the internet connection for the whole country was under threat, but Brewer emphatically confirmed that this was not the case, stating "both our ACE submarine cable monitoring systems and servers hosted (locally) in LIXP (Liberia Internet Exchange Point) show no downtime in the last 3 weeks."

It appears that the attacks observed by Beaumont were in fact mounted against a mobile telco; one that had a DDoS mitigation service in place to minimise the effects of the attack. While local web performance may have been intermittent, it was decidedly not a nationwide issue.

This was confirmed by cloud and security company Akamai as well as Dyn, the DNS provider that was hit by a much bigger DDoS last month. The company's director of internet analysis tweeted that there was no evidence of any widespread problems.

However, security expert Graham Cluley cautioned that although the Liberian incident was not as bad as initially thought, Mirai and other IoT-based malware still poses a significant threat.

"None of this is to say Mirai that is not a serious threat, of course," he wrote, "and that new botnets based upon its leaked code don't pose a significant threat to internet infrastructure as they exploit poorly-protected IoT devices."

Featured Resources

Navigating the new normal: A fast guide to remote working

A smooth transition will support operations for years to come

Download now

Leading the data race

The trends driving the future of data science

Download now

How to create 1:1 customer experiences at scale

Meet the technology capable of delivering the personalisation your customers crave

Download now

How to achieve daily SAP releases

Accelerate the pace of SAP change to support your digital strategy

Download now

Recommended

8 most secure web browsers
web browser

8 most secure web browsers

25 Sep 2020
Your essential guide to internet security
Security

Your essential guide to internet security

23 Sep 2020
How to enable private browsing on any device
privacy

How to enable private browsing on any device

22 Sep 2020
Third-party apps are tracking your WhatsApp activity
social media

Third-party apps are tracking your WhatsApp activity

21 Sep 2020

Most Popular

Unilever adopts Google Cloud’s complex data processing for conservation drive
big data analytics

Unilever adopts Google Cloud’s complex data processing for conservation drive

22 Sep 2020
16 ways to speed up your laptop
Laptops

16 ways to speed up your laptop

16 Sep 2020
16 ways to speed up your laptop
Laptops

16 ways to speed up your laptop

16 Sep 2020