Healthcare hit by Killnet-linked DDoS wave

Cloudflare has observed a spike in DDoS attacks against healthcare organizations, with a pro-Russian hacktivist group claiming to be Killnet as the suspected perpetrator. The U.S. Department of Health and Human Services has issued an Analyst Note detailing the threat to the healthcare industry. Attacks have been directed at multiple healthcare organizations on Cloudflare's network, which have been mitigated automatically by its systems. No single botnet appears to be responsible, and the variety of methods and sources suggests either multiple actors operating under the Killnet banner or a more coordinated operation.

The current threat landscape is influenced by rising political tensions and the ongoing conflict in Ukraine. Unlike traditional warfare, the internet lets distributed groups launch targeted attacks from anywhere. DDoS attacks are particularly accessible because they don't require an intrusion or a foothold in the target network. IP addresses and domain names are publicly discoverable, just like physical addresses, which means any internet-connected network must be prepared to defend against attacks at both the application layer (layer 7) and the network layer (layers 3 and 4). While DDoS is not a new threat, attacks have grown larger, more sophisticated, and more frequent in recent years.

Uptick in healthcare organizations experiencing targeted DDoS attacks

Who is Killnet?

Killnet is a pro-Russian group that organizes on Telegram, where sympathizers volunteer to participate in cyberattacks against Western interests. In the fourth quarter of 2022, the group called for attacks on U.S. airport websites.

While Cloudflare's systems have been automatically detecting and mitigating these attacks, healthcare customers are advised to take additional precautionary steps to harden their security posture:

  1. Ensure all DDoS Managed Rules remain at default settings (High sensitivity level and mitigation actions) for optimal DDoS activation.
  2. Cloudflare Enterprise customers with Advanced DDoS should consider enabling Adaptive DDoS Protection, which mitigates traffic that deviates from established traffic profiles.
  3. Deploy firewall rules and rate-limiting rules to enforce a combined positive and negative security model, reducing allowed traffic to match known usage.
  4. Keep your origin server off the public Internet, allowing access only from Cloudflare IP addresses.
  5. If you have access to Managed IP Lists, consider using them in firewall rules.
  6. Enable caching as much as possible to reduce strain on origin servers; when using Workers, avoid overwhelming your origin with more subrequests than needed.
  7. Enable DDoS alerting to improve response times.

Although attacks are launched by humans, they are executed by bots. Defenders who rely solely on manual response are at a disadvantage. Automated defenses are essential to keep pace with the volume and velocity of modern DDoS campaigns, and Cloudflare continues to support healthcare organizations in preparing for and responding to these threats.